I was using avast for a long time and it slows down my system so I decided to get a new AV.
When I installed AVG I run a Anti-Rootkit scan and it has found 30 malicious.
It allways fails to remove and it says "unable to remove data not vaild"
I have posted AVG log.
Note:Please forgive my grammar mistakes.
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: BrowserJavaVersion: 10.51.2
Run by [removed] at 20:33:35 on 2014-03-20
Microsoft Windows 7 Home Basic 6.1.7601.1.1254.90.1055.18.4044.1677 [GMT 2:00]
.
AV: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: ZoneAlarm Free Firewall Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\ezSharedSvcHost.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.tr
uSearch Bar = Preserve
uDefault_Page_URL = about:blank
mWinlogon: Userinit = C:\Windows\System32\userinit.exe
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Oturum Açma Yardım Aracı: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: HideFastUserSwitching = dword:0
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{DB481297-64D7-4BC0-9488-BB8AE43F4931} : DHCPNameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{DB481297-64D7-4BC0-9488-BB8AE43F4931}\37D696C656164637C6F513230333 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{DB481297-64D7-4BC0-9488-BB8AE43F4931}\6656E65627 : DHCPNameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{DB481297-64D7-4BC0-9488-BB8AE43F4931}\A5455475330303 : DHCPNameServer = 192.168.2.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
IFEO: taskmgr.exe - "C:\Program Files\Process Hacker 2\ProcessHacker.exe"
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - <orphaned>
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-IFEO: taskmgr.exe - "C:\Program Files\Process Hacker 2\ProcessHacker.exe"
Hosts: 127.0.0.1 http://www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Batu\AppData\Roaming\Mozilla\Firefox\Profiles\b3233y40.default\
FF - prefs.js: browser.search.selectedEngine - Startpage HTTPS - Turkce
FF - prefs.js: network.proxy.gopher - 85.175.217.151
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2013-10-24 194872]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2013-10-31 294712]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2013-10-1 123704]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2013-9-10 31544]
R1 Avgdiska;AVG Disk Driver;C:\Windows\System32\drivers\avgdiska.sys [2013-11-5 150808]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2013-11-4 240920]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2013-10-31 212280]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2013-8-1 251192]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-4-7 203776]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [2013-11-11 3478544]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [2013-9-24 348008]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-2-28 821664]
R2 ezSharedSvc;Easybits Services for Windows;C:\Windows\System32\ezSharedSvcHost.exe --> C:\Windows\System32\ezSharedSvcHost.exe [?]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2014-2-26 2224976]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-11-9 26680]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-5-22 13336]
R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [2014-2-26 377616]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-2 483688]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-5-22 2656280]
R3 huawei_enumerator;huawei_enumerator;C:\Windows\System32\drivers\ew_jubusenum.sys [2012-9-13 87040]
R3 IntcDAud;Intel(R) Ekran İçin Ses;C:\Windows\System32\drivers\IntcDAud.sys [2010-10-15 317440]
R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2011-1-8 12262688]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2009-12-2 721768]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2009-12-2 269672]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2009-12-2 25960]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2009-12-2 22376]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-2 209768]
RUnknown aswMonFlt;aswMonFlt; [x]
RUnknown aswRvrt;aswRvrt; [x]
RUnknown aswSnx;aswSnx; [x]
RUnknown aswSP;aswSP; [x]
RUnknown aswStm;aswStm; [x]
RUnknown aswVmm;aswVmm; [x]
S2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-8-5 291896]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S2 ZAPrivacyService;ZoneAlarm Privacy Service;C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [2013-10-15 50704]
S3 InputFilter_Hid_FlexDef2b;Siliten HID Devices(FlexDef2b) Driver Service;C:\Windows\System32\drivers\InputFilter_FlexDef2b.sys [2010-6-18 17920]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-24 19456]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2011-2-15 335464]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-14 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-14 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-14 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-3-2 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-11-24 30208]
S3 usbUDisc;usbUDisc;C:\Windows\System32\drivers\USBDrv_AMD64.sys [2014-3-11 17280]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== File Associations ===============
.
FileExt: .inf: inffile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
FileExt: .vbs: VBSFile="C:\Windows\System32\WScript.exe" "%1" %* [UserChoice]
.
=============== Created Last 30 ================
.
2014-03-20 17:44:33 -------- d-----w- C:\Program Files (x86)\Common Files\Merge Modules
2014-03-20 17:00:22 -------- d-----w- C:\Users\Batu\AppData\Roaming\AVG2014
2014-03-20 16:58:02 -------- d-----w- C:\Users\Batu\AppData\Roaming\TuneUp Software
2014-03-20 16:56:49 -------- d--h--w- C:\$AVG
2014-03-20 16:56:49 -------- d-----w- C:\ProgramData\AVG2014
2014-03-20 16:56:23 -------- d-----w- C:\Program Files (x86)\AVG
2014-03-20 16:49:00 -------- d-----w- C:\Users\Batu\AppData\Local\Avg2014
2014-03-20 16:47:47 -------- d-s---w- C:\Windows\SysWow64\Microsoft
2014-03-18 18:49:33 -------- d-----w- C:\Users\Batu\AppData\Local\{3C8521B0-3248-4726-A7E4-0F17360A2D4A}
2014-03-18 15:01:38 10521840 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B7A66AFC-78FC-49DF-8DB2-0ACC03DB451A}\mpengine.dll
2014-03-16 12:49:02 -------- d-----w- C:\Program Files (x86)\LogMeIn Hamachi
2014-03-16 12:48:42 -------- d-----w- C:\Users\Batu\AppData\Local\LogMeIn Hamachi
2014-03-16 10:26:08 -------- d-----w- C:\Users\Batu\AppData\Local\{5B8DB6CC-2AFC-4FD6-820F-8D0E8FD0BBE8}
2014-03-16 10:17:41 -------- d-----w- C:\Users\Batu\AppData\Local\VS Revo Group
2014-03-16 10:17:30 -------- d-----w- C:\ProgramData\VS Revo Group
2014-03-16 10:13:35 -------- d-----w- C:\Users\Batu\AppData\Local\{661E8134-D521-4DA0-9C43-8E32D6576AB7}
2014-03-16 08:05:02 -------- d-----w- C:\Users\Batu\AppData\Local\Skype
2014-03-16 08:04:41 -------- d-----r- C:\Program Files (x86)\Skype
2014-03-14 16:35:30 -------- d-----w- C:\ProgramData\InstallMate
2014-03-12 16:39:02 -------- d-----w- C:\Users\Batu\AppData\Local\WinTestGear
2014-03-12 16:38:18 484864 ----a-w- C:\Windows\System32\wer.dll
2014-03-12 16:38:18 381440 ----a-w- C:\Windows\SysWow64\wer.dll
2014-03-12 16:38:18 228864 ----a-w- C:\Windows\System32\wwansvc.dll
2014-03-12 16:38:17 624128 ----a-w- C:\Windows\System32\qedit.dll
2014-03-12 16:38:17 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2014-03-12 16:38:17 3156480 ----a-w- C:\Windows\System32\win32k.sys
2014-03-12 16:38:17 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2014-03-12 16:38:16 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2014-03-12 16:33:00 -------- d-----w- C:\Users\Batu\AppData\Local\Windows Live
2014-03-12 16:32:26 -------- d-----w- C:\Users\Batu\AppData\Local\{AF4709ED-9BAB-462D-9E0C-AB56E879AC58}
2014-03-11 06:05:09 17280 ----a-w- C:\Windows\System32\drivers\USBDrv_AMD64.sys
2014-03-10 16:10:02 -------- d-----w- C:\Users\Batu\AppData\Roaming\hpqLog
2014-03-09 13:46:55 -------- d-----w- C:\ProgramData\LogMeIn
2014-03-06 17:55:32 -------- d-----w- C:\Users\Batu\AppData\Roaming\skyz
2014-03-05 17:11:06 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-03-04 16:08:39 -------- d-----w- C:\Users\Batu\AppData\Roaming\Blackboard
2014-03-03 18:54:19 6574592 ----a-w- C:\Windows\System32\mstscax.dll
2014-03-03 18:54:19 5694464 ----a-w- C:\Windows\SysWow64\mstscax.dll
2014-03-02 16:49:19 792576 ----a-w- C:\Windows\SysWow64\TSWorkspace.dll
2014-03-02 16:49:19 1030144 ----a-w- C:\Windows\System32\TSWorkspace.dll
2014-02-28 18:26:37 -------- d-----w- C:\Users\Batu\AppData\Roaming\FastStone
2014-02-28 08:26:43 -------- d-----w- C:\Users\Batu\AppData\Local\{648DB31E-C55A-438D-A4D2-449765D529A5}
2014-02-28 07:47:39 -------- d-----w- C:\Users\Batu\AppData\Local\Downloaded Installations
2014-02-27 16:33:44 -------- d-----w- C:\Users\Batu\AppData\Roaming\RenPy
2014-02-27 16:23:17 -------- d-----w- C:\Users\Batu\AppData\Roaming\Process Hacker 2
2014-02-27 16:23:06 -------- d-----w- C:\Program Files\Process Hacker 2
2014-02-24 19:09:38 -------- d-----w- C:\Users\Batu\AppData\Roaming\PunkBuster
.
==================== Find3M ====================
.
2014-02-23 08:13:41 2241536 ----a-w- C:\Windows\System32\wininet.dll
2014-02-23 08:11:59 3960320 ----a-w- C:\Windows\System32\jscript9.dll
2014-02-23 08:11:52 67072 ----a-w- C:\Windows\System32\iesetup.dll
2014-02-23 08:11:52 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2014-02-23 06:54:46 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-02-23 06:53:22 2877952 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-02-23 06:53:18 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-02-23 06:53:18 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2014-02-23 06:35:36 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2014-02-23 06:31:25 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-02-06 16:49:09 43152 ----a-w- C:\Windows\avastSS.scr
2013-12-24 23:09:41 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2013-12-24 22:48:32 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2013-12-21 09:39:33 600064 ----a-w- C:\Windows\System32\vbscript.dll
2013-12-21 07:56:10 523776 ----a-w- C:\Windows\SysWow64\vbscript.dll
.
============= FINISH: 20:33:52,49 ===============
Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Basic
Boot Device: \Device\HarddiskVolume1
Install Date: 21.06.2012 16:26:37
System Uptime: 20.03.2014 18:43:11 (2 hours ago)
.
Motherboard: Hewlett-Packard | | 1670
Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz | CPU1 | 2100/1333mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 451 GiB total, 393,042 GiB free.
D: is FIXED (NTFS) - 15 GiB total, 1,6 GiB free.
E: is CDROM (UDF)
G: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Description: Generic Bluetooth Adapter
Device ID: USB\VID_0A5C&PID_21B4\CC52AFA242AD
Manufacturer: GenericAdapter
Name: Generic Bluetooth Adapter
PNP Device ID: USB\VID_0A5C&PID_21B4\CC52AFA242AD
Service: BTHUSB
.
==== System Restore Points ===================
.
RP309: 20.03.2014 18:46:28 - avast! antivirus system restore point
RP310: 20.03.2014 18:55:45 - Installed AVG 2014
RP311: 20.03.2014 18:56:30 - Installed AVG 2014
RP312: 20.03.2014 18:59:58 - Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi Kaldırıldı
RP313: 20.03.2014 20:08:38 - Windows Modül Yükleyicisi
RP314: 20.03.2014 20:16:20 - Windows Modül Yükleyicisi
.
==== Installed Programs ======================
.
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.7) MUI
Adobe Shockwave Player 12.0
ATI Catalyst Install Manager
AVG 2014
Broadcom 802.11 Wireless LAN Adapter
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
Catalyst Control Center Profiles Mobile
ccc-core-static
ccc-utility64
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCleaner
CDBurnerXP
D3DX10
Empire: Total War
ESU for Microsoft Windows 7
Hotfix for Microsoft Visual C# 2010 Express - ENU (KB2635973)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2280741)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2284668)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2295689)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2420513)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2452649)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2455033)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2485545)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB982517)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB982721)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB983233)
HP Auto
HP Client Services
HP Customer Experience Enhancements
HP Documentation
HP On Screen Display
HP Power Manager
HP Quick Launch
HP Software Framework
HUAWEI DataCard Driver 4.23.13.00
IDT Audio
Intel(R) Display Audio Driver
Intel(R) Management Engine Components
Intel(R) Rapid Storage Technology
Java 7 Update 51
Java Auto Updater
Junk Mail filter update
LogMeIn Hamachi
Mesh Runtime
Microsoft .NET Framework 4 Multi-Targeting Pack
Microsoft .NET Framework 4.5.1
Microsoft .NET Framework 4.5.1 (Türkçe)
Microsoft .NET Framework 4.5.1 (TRK)
Microsoft Application Error Reporting
Microsoft Help Viewer 1.1
Microsoft Office 2010
Microsoft Office Starter 2010 - Türkçe
Microsoft Office Tıkla-Çalıştır 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server 2008 R2 Management Objects
Microsoft SQL Server 2012 Transact-SQL ScriptDom
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft SQL Server Compact 3.5 SP2 x64 ENU
Microsoft SQL Server Compact 4.0 SP1 x64 ENU
Microsoft SQL Server System CLR Types
Microsoft Visual C# 2010 Express - ENU
Microsoft Visual C++ Compilers 2010 Standard - enu - x86
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219
Microsoft Visual C++ 2010 Express - ENU
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU
Microsoft Visual Studio 2010 Service Pack 1
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
Microsoft XNA Framework Redistributable 4.0
Mount & Blade: Warband
Mount & Blade: With Fire and Sword
Mozilla Firefox 27.0.1 (x86 tr)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
Process Hacker 2.33 (r5590)
PX Profile Update
Realtek Ethernet Controller Driver
Recovery Manager
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Skype™ 6.14
Steam
swMSM
Synaptics TouchPad Driver
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
Visual Studio 2010 x64 Redistributables
Visual Studio 2012 x64 Redistributables
Visual Studio 2012 x86 Redistributables
Windows Live Communications Platform
Windows Live Essentials
Windows Live Fotoğraf Galerisi
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Temel Parçalar
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinPatrol
WinRAR 4.10 (32-bit)
ZoneAlarm Firewall
ZoneAlarm Security
.
==== End Of File ===========================
AVG Scan Log (Turkish)
Anti-Rootkit tarama
"Orta öncelik;""30"";""0"";""30"""
"Başlangıç:;""20.03.2014, 19:52:45"""
"Bitiş:;""20.03.2014, 19:54:28"""
"Taranan toplam nesne:;""158267"""
"Taramayı başlatan kullanıcı:;""Batu"""
"Adı;""Açıklama"";""Sonuç"";""Durum"";""Öncelik"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0xBE64 -> aswSnx.sys +0x2D8A8"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x8548 -> aswSnx.sys +0x2D620"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngSetPointerTag+0x194 -> aswSnx.sys +0x30100"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x5A00 -> aswSnx.sys +0x2E3A8"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x45D4 -> aswSnx.sys +0x2D0F0"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngRestoreFloatingPointState+0x1120 -> aswSnx.sys +0x2F4D8"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x12E7C -> aswSnx.sys +0x2E264"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x14830 -> aswSnx.sys +0x2DB50"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys XLATEOBJ_hGetColorTransform+0x15C48 -> aswSnx.sys +0x2F538"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0xE144 -> aswSnx.sys +0x2E4D8"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x90A0 -> aswSnx.sys +0x2E62C"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x6304 -> aswSnx.sys +0x2D6D0"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys XLATEOBJ_hGetColorTransform+0x63DC -> aswSnx.sys +0x2FA98"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngRestoreFloatingPointState+0x3EA8 -> aswSnx.sys +0x2D4E0"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys STROBJ_fxBreakExtra+0x1E00 -> aswSnx.sys +0x2FF7C"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0xE2C0 -> aswSnx.sys +0x2E37C"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x2568 -> aswSnx.sys +0x2DE74"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x7BE4 -> aswSnx.sys +0x2E504"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngFntCacheLookUp+0x12488 -> aswSnx.sys +0x2D300"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngCopyBits+0x16AC -> aswSnx.sys +0x2F470"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x5694 -> aswSnx.sys +0x2DC30"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys XLATEOBJ_hGetColorTransform+0xF2C -> aswSnx.sys +0x2F584"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0xBCF8 -> aswSnx.sys +0x2D92C"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngBitBlt+0x6054 -> aswSnx.sys +0x2E0E4"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0xB7D8 -> aswSnx.sys +0x2E100"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x24D4 -> aswSnx.sys +0x2DD60"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x8104 -> aswSnx.sys +0x2DA70"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x6A64 -> aswSnx.sys +0x2E350"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngFntCacheLookUp+0x8F08 -> aswSnx.sys +0x2F2FC"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngPaint+0x914 -> aswSnx.sys +0x2FE00"";""Bulaşmış"";""Bulaşmış"";""Orta"""
When I installed AVG I run a Anti-Rootkit scan and it has found 30 malicious.
It allways fails to remove and it says "unable to remove data not vaild"
I have posted AVG log.
Note:Please forgive my grammar mistakes.
DDS.txt
DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: BrowserJavaVersion: 10.51.2
Run by [removed] at 20:33:35 on 2014-03-20
Microsoft Windows 7 Home Basic 6.1.7601.1.1254.90.1055.18.4044.1677 [GMT 2:00]
.
AV: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {0E9420C4-06B3-7FA0-3AB1-6E49CB52ECD9}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: AVG AntiVirus Free Edition 2014 *Enabled/Updated* {B5F5C120-2089-702E-0001-553BB0D5A664}
FW: ZoneAlarm Free Firewall Firewall *Enabled* {E6380B7E-D4B2-19F1-083E-56486607704B}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files (x86)\CheckPoint\ZoneAlarm\vsmon.exe
C:\Windows\system32\WLANExt.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\SysWOW64\ezSharedSvcHost.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\WUDFHost.exe
C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
C:\Windows\system32\svchost.exe -k SDRSVC
C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe
C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe
C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe
C:\Program Files (x86)\AVG\AVG2014\avgui.exe
C:\Windows\system32\svchost.exe -k bthsvcs
C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe
C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com.tr
uSearch Bar = Preserve
uDefault_Page_URL = about:blank
mWinlogon: Userinit = C:\Windows\System32\userinit.exe
BHO: Java(tm) Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: Windows Live ID Oturum Açma Yardım Aracı: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
uRun: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe -expressboot
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [ZoneAlarm] "C:\Program Files (x86)\CheckPoint\ZoneAlarm\zatray.exe"
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [AVG_UI] "C:\Program Files (x86)\AVG\AVG2014\avgui.exe" /TRAYONLY
uPolicies-Explorer: NoDriveTypeAutoRun = dword:145
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: HideFastUserSwitching = dword:0
.
INFO: HKCU has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
.
INFO: HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
TCP: NameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{DB481297-64D7-4BC0-9488-BB8AE43F4931} : DHCPNameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{DB481297-64D7-4BC0-9488-BB8AE43F4931}\37D696C656164637C6F513230333 : DHCPNameServer = 192.168.1.1
TCP: Interfaces\{DB481297-64D7-4BC0-9488-BB8AE43F4931}\6656E65627 : DHCPNameServer = 192.168.1.1 0.0.0.0
TCP: Interfaces\{DB481297-64D7-4BC0-9488-BB8AE43F4931}\A5455475330303 : DHCPNameServer = 192.168.2.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck - <orphaned>
IFEO: taskmgr.exe - "C:\Program Files\Process Hacker 2\ProcessHacker.exe"
x64-BHO: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - <orphaned>
x64-TB: avast! Online Security: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [IgfxTray] C:\Windows\System32\igfxtray.exe
x64-Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe
x64-Run: [Persistence] C:\Windows\System32\igfxpers.exe
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
.
INFO: x64-HKLM has more than 50 listed domains.
If you wish to scan all of them, select the 'Force scan all domains' option.
.
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: igfxcui - igfxdev.dll
x64-SSODL: WebCheck - <orphaned>
x64-IFEO: taskmgr.exe - "C:\Program Files\Process Hacker 2\ProcessHacker.exe"
Hosts: 127.0.0.1 http://www.spywareinfo.com
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Batu\AppData\Roaming\Mozilla\Firefox\Profiles\b3233y40.default\
FF - prefs.js: browser.search.selectedEngine - Startpage HTTPS - Turkce
FF - prefs.js: network.proxy.gopher - 85.175.217.151
FF - prefs.js: network.proxy.gopher_port - 8080
FF - prefs.js: network.proxy.type - 0
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll
.
============= SERVICES / DRIVERS ===============
.
R0 AVGIDSHA;AVGIDSHA;C:\Windows\System32\drivers\avgidsha.sys [2013-10-24 194872]
R0 Avgloga;AVG Logging Driver;C:\Windows\System32\drivers\avgloga.sys [2013-10-31 294712]
R0 Avgmfx64;AVG Mini-Filter Resident Anti-Virus Shield;C:\Windows\System32\drivers\avgmfx64.sys [2013-10-1 123704]
R0 Avgrkx64;AVG Anti-Rootkit Driver;C:\Windows\System32\drivers\avgrkx64.sys [2013-9-10 31544]
R1 Avgdiska;AVG Disk Driver;C:\Windows\System32\drivers\avgdiska.sys [2013-11-5 150808]
R1 AVGIDSDriver;AVGIDSDriver;C:\Windows\System32\drivers\avgidsdrivera.sys [2013-11-4 240920]
R1 Avgldx64;AVG AVI Loader Driver;C:\Windows\System32\drivers\avgldx64.sys [2013-10-31 212280]
R1 Avgtdia;AVG TDI Driver;C:\Windows\System32\drivers\avgtdia.sys [2013-8-1 251192]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-4-7 203776]
R2 AVGIDSAgent;AVGIDSAgent;C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [2013-11-11 3478544]
R2 avgwd;AVG WatchDog;C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [2013-9-24 348008]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
R2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE [2010-2-28 821664]
R2 ezSharedSvc;Easybits Services for Windows;C:\Windows\System32\ezSharedSvcHost.exe --> C:\Windows\System32\ezSharedSvcHost.exe [?]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2014-2-26 2224976]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2010-11-9 26680]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2011-5-22 13336]
R2 LMIGuardianSvc;LMIGuardianSvc;C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe [2014-2-26 377616]
R2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [2009-12-2 483688]
R2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2011-5-22 2656280]
R3 huawei_enumerator;huawei_enumerator;C:\Windows\System32\drivers\ew_jubusenum.sys [2012-9-13 87040]
R3 IntcDAud;Intel(R) Ekran İçin Ses;C:\Windows\System32\drivers\IntcDAud.sys [2010-10-15 317440]
R3 intelkmd;intelkmd;C:\Windows\System32\drivers\igdpmd64.sys [2011-1-8 12262688]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]
R3 Sftfs;Sftfs;C:\Windows\System32\drivers\Sftfslh.sys [2009-12-2 721768]
R3 Sftplay;Sftplay;C:\Windows\System32\drivers\Sftplaylh.sys [2009-12-2 269672]
R3 Sftredir;Sftredir;C:\Windows\System32\drivers\Sftredirlh.sys [2009-12-2 25960]
R3 Sftvol;Sftvol;C:\Windows\System32\drivers\Sftvollh.sys [2009-12-2 22376]
R3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [2009-12-2 209768]
RUnknown aswMonFlt;aswMonFlt; [x]
RUnknown aswRvrt;aswRvrt; [x]
RUnknown aswSnx;aswSnx; [x]
RUnknown aswSP;aswSP; [x]
RUnknown aswStm;aswStm; [x]
RUnknown aswVmm;aswVmm; [x]
S2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-8-5 291896]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S2 ZAPrivacyService;ZoneAlarm Privacy Service;C:\Program Files (x86)\CheckPoint\ZoneAlarm\ZAPrivacyService.exe [2013-10-15 50704]
S3 InputFilter_Hid_FlexDef2b;Siliten HID Devices(FlexDef2b) Driver Service;C:\Windows\System32\drivers\InputFilter_FlexDef2b.sys [2010-6-18 17920]
S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\System32\drivers\rdpvideominiport.sys [2012-11-24 19456]
S3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2011-2-15 335464]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-14 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-14 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-14 740864]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2014-3-2 56832]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2012-11-24 30208]
S3 usbUDisc;usbUDisc;C:\Windows\System32\drivers\USBDrv_AMD64.sys [2014-3-11 17280]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== File Associations ===============
.
FileExt: .inf: inffile=C:\Windows\System32\NOTEPAD.EXE %1 [UserChoice]
FileExt: .vbs: VBSFile="C:\Windows\System32\WScript.exe" "%1" %* [UserChoice]
.
=============== Created Last 30 ================
.
2014-03-20 17:44:33 -------- d-----w- C:\Program Files (x86)\Common Files\Merge Modules
2014-03-20 17:00:22 -------- d-----w- C:\Users\Batu\AppData\Roaming\AVG2014
2014-03-20 16:58:02 -------- d-----w- C:\Users\Batu\AppData\Roaming\TuneUp Software
2014-03-20 16:56:49 -------- d--h--w- C:\$AVG
2014-03-20 16:56:49 -------- d-----w- C:\ProgramData\AVG2014
2014-03-20 16:56:23 -------- d-----w- C:\Program Files (x86)\AVG
2014-03-20 16:49:00 -------- d-----w- C:\Users\Batu\AppData\Local\Avg2014
2014-03-20 16:47:47 -------- d-s---w- C:\Windows\SysWow64\Microsoft
2014-03-18 18:49:33 -------- d-----w- C:\Users\Batu\AppData\Local\{3C8521B0-3248-4726-A7E4-0F17360A2D4A}
2014-03-18 15:01:38 10521840 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{B7A66AFC-78FC-49DF-8DB2-0ACC03DB451A}\mpengine.dll
2014-03-16 12:49:02 -------- d-----w- C:\Program Files (x86)\LogMeIn Hamachi
2014-03-16 12:48:42 -------- d-----w- C:\Users\Batu\AppData\Local\LogMeIn Hamachi
2014-03-16 10:26:08 -------- d-----w- C:\Users\Batu\AppData\Local\{5B8DB6CC-2AFC-4FD6-820F-8D0E8FD0BBE8}
2014-03-16 10:17:41 -------- d-----w- C:\Users\Batu\AppData\Local\VS Revo Group
2014-03-16 10:17:30 -------- d-----w- C:\ProgramData\VS Revo Group
2014-03-16 10:13:35 -------- d-----w- C:\Users\Batu\AppData\Local\{661E8134-D521-4DA0-9C43-8E32D6576AB7}
2014-03-16 08:05:02 -------- d-----w- C:\Users\Batu\AppData\Local\Skype
2014-03-16 08:04:41 -------- d-----r- C:\Program Files (x86)\Skype
2014-03-14 16:35:30 -------- d-----w- C:\ProgramData\InstallMate
2014-03-12 16:39:02 -------- d-----w- C:\Users\Batu\AppData\Local\WinTestGear
2014-03-12 16:38:18 484864 ----a-w- C:\Windows\System32\wer.dll
2014-03-12 16:38:18 381440 ----a-w- C:\Windows\SysWow64\wer.dll
2014-03-12 16:38:18 228864 ----a-w- C:\Windows\System32\wwansvc.dll
2014-03-12 16:38:17 624128 ----a-w- C:\Windows\System32\qedit.dll
2014-03-12 16:38:17 509440 ----a-w- C:\Windows\SysWow64\qedit.dll
2014-03-12 16:38:17 3156480 ----a-w- C:\Windows\System32\win32k.sys
2014-03-12 16:38:17 1424384 ----a-w- C:\Windows\System32\WindowsCodecs.dll
2014-03-12 16:38:16 1230336 ----a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2014-03-12 16:33:00 -------- d-----w- C:\Users\Batu\AppData\Local\Windows Live
2014-03-12 16:32:26 -------- d-----w- C:\Users\Batu\AppData\Local\{AF4709ED-9BAB-462D-9E0C-AB56E879AC58}
2014-03-11 06:05:09 17280 ----a-w- C:\Windows\System32\drivers\USBDrv_AMD64.sys
2014-03-10 16:10:02 -------- d-----w- C:\Users\Batu\AppData\Roaming\hpqLog
2014-03-09 13:46:55 -------- d-----w- C:\ProgramData\LogMeIn
2014-03-06 17:55:32 -------- d-----w- C:\Users\Batu\AppData\Roaming\skyz
2014-03-05 17:11:06 96168 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-03-04 16:08:39 -------- d-----w- C:\Users\Batu\AppData\Roaming\Blackboard
2014-03-03 18:54:19 6574592 ----a-w- C:\Windows\System32\mstscax.dll
2014-03-03 18:54:19 5694464 ----a-w- C:\Windows\SysWow64\mstscax.dll
2014-03-02 16:49:19 792576 ----a-w- C:\Windows\SysWow64\TSWorkspace.dll
2014-03-02 16:49:19 1030144 ----a-w- C:\Windows\System32\TSWorkspace.dll
2014-02-28 18:26:37 -------- d-----w- C:\Users\Batu\AppData\Roaming\FastStone
2014-02-28 08:26:43 -------- d-----w- C:\Users\Batu\AppData\Local\{648DB31E-C55A-438D-A4D2-449765D529A5}
2014-02-28 07:47:39 -------- d-----w- C:\Users\Batu\AppData\Local\Downloaded Installations
2014-02-27 16:33:44 -------- d-----w- C:\Users\Batu\AppData\Roaming\RenPy
2014-02-27 16:23:17 -------- d-----w- C:\Users\Batu\AppData\Roaming\Process Hacker 2
2014-02-27 16:23:06 -------- d-----w- C:\Program Files\Process Hacker 2
2014-02-24 19:09:38 -------- d-----w- C:\Users\Batu\AppData\Roaming\PunkBuster
.
==================== Find3M ====================
.
2014-02-23 08:13:41 2241536 ----a-w- C:\Windows\System32\wininet.dll
2014-02-23 08:11:59 3960320 ----a-w- C:\Windows\System32\jscript9.dll
2014-02-23 08:11:52 67072 ----a-w- C:\Windows\System32\iesetup.dll
2014-02-23 08:11:52 136704 ----a-w- C:\Windows\System32\iesysprep.dll
2014-02-23 06:54:46 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-02-23 06:53:22 2877952 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-02-23 06:53:18 61440 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-02-23 06:53:18 109056 ----a-w- C:\Windows\SysWow64\iesysprep.dll
2014-02-23 06:35:36 2706432 ----a-w- C:\Windows\System32\mshtml.tlb
2014-02-23 06:31:25 2706432 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-02-06 16:49:09 43152 ----a-w- C:\Windows\avastSS.scr
2013-12-24 23:09:41 1987584 ----a-w- C:\Windows\SysWow64\d3d10warp.dll
2013-12-24 22:48:32 2565120 ----a-w- C:\Windows\System32\d3d10warp.dll
2013-12-21 09:39:33 600064 ----a-w- C:\Windows\System32\vbscript.dll
2013-12-21 07:56:10 523776 ----a-w- C:\Windows\SysWow64\vbscript.dll
.
============= FINISH: 20:33:52,49 ===============
Attach.txt
.
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
.
DDS (Ver_2012-11-20.01)
.
Microsoft Windows 7 Home Basic
Boot Device: \Device\HarddiskVolume1
Install Date: 21.06.2012 16:26:37
System Uptime: 20.03.2014 18:43:11 (2 hours ago)
.
Motherboard: Hewlett-Packard | | 1670
Processor: Intel(R) Core(TM) i3-2310M CPU @ 2.10GHz | CPU1 | 2100/1333mhz
.
==== Disk Partitions =========================
.
C: is FIXED (NTFS) - 451 GiB total, 393,042 GiB free.
D: is FIXED (NTFS) - 15 GiB total, 1,6 GiB free.
E: is CDROM (UDF)
G: is Removable
.
==== Disabled Device Manager Items =============
.
Class GUID: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Description: Generic Bluetooth Adapter
Device ID: USB\VID_0A5C&PID_21B4\CC52AFA242AD
Manufacturer: GenericAdapter
Name: Generic Bluetooth Adapter
PNP Device ID: USB\VID_0A5C&PID_21B4\CC52AFA242AD
Service: BTHUSB
.
==== System Restore Points ===================
.
RP309: 20.03.2014 18:46:28 - avast! antivirus system restore point
RP310: 20.03.2014 18:55:45 - Installed AVG 2014
RP311: 20.03.2014 18:56:30 - Installed AVG 2014
RP312: 20.03.2014 18:59:58 - Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi Kaldırıldı
RP313: 20.03.2014 20:08:38 - Windows Modül Yükleyicisi
RP314: 20.03.2014 20:16:20 - Windows Modül Yükleyicisi
.
==== Installed Programs ======================
.
Adobe Flash Player 11 ActiveX
Adobe Flash Player 11 Plugin
Adobe Reader X (10.1.7) MUI
Adobe Shockwave Player 12.0
ATI Catalyst Install Manager
AVG 2014
Broadcom 802.11 Wireless LAN Adapter
Catalyst Control Center - Branding
Catalyst Control Center Graphics Previews Common
Catalyst Control Center InstallProxy
Catalyst Control Center Localization All
Catalyst Control Center Profiles Mobile
ccc-core-static
ccc-utility64
CCC Help Chinese Standard
CCC Help Chinese Traditional
CCC Help Czech
CCC Help Danish
CCC Help Dutch
CCC Help English
CCC Help Finnish
CCC Help French
CCC Help German
CCC Help Greek
CCC Help Hungarian
CCC Help Italian
CCC Help Japanese
CCC Help Korean
CCC Help Norwegian
CCC Help Polish
CCC Help Portuguese
CCC Help Russian
CCC Help Spanish
CCC Help Swedish
CCC Help Thai
CCleaner
CDBurnerXP
D3DX10
Empire: Total War
ESU for Microsoft Windows 7
Hotfix for Microsoft Visual C# 2010 Express - ENU (KB2635973)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2280741)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2284668)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2295689)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2420513)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2452649)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2455033)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB2485545)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB982517)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB982721)
Hotfix for Visual C++ Standard 2010 Beta 1 - ENU (KB983233)
HP Auto
HP Client Services
HP Customer Experience Enhancements
HP Documentation
HP On Screen Display
HP Power Manager
HP Quick Launch
HP Software Framework
HUAWEI DataCard Driver 4.23.13.00
IDT Audio
Intel(R) Display Audio Driver
Intel(R) Management Engine Components
Intel(R) Rapid Storage Technology
Java 7 Update 51
Java Auto Updater
Junk Mail filter update
LogMeIn Hamachi
Mesh Runtime
Microsoft .NET Framework 4 Multi-Targeting Pack
Microsoft .NET Framework 4.5.1
Microsoft .NET Framework 4.5.1 (Türkçe)
Microsoft .NET Framework 4.5.1 (TRK)
Microsoft Application Error Reporting
Microsoft Help Viewer 1.1
Microsoft Office 2010
Microsoft Office Starter 2010 - Türkçe
Microsoft Office Tıkla-Çalıştır 2010
Microsoft Silverlight
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft SQL Server 2008 R2 Management Objects
Microsoft SQL Server 2012 Transact-SQL ScriptDom
Microsoft SQL Server Compact 3.5 SP2 ENU
Microsoft SQL Server Compact 3.5 SP2 x64 ENU
Microsoft SQL Server Compact 4.0 SP1 x64 ENU
Microsoft SQL Server System CLR Types
Microsoft Visual C# 2010 Express - ENU
Microsoft Visual C++ Compilers 2010 Standard - enu - x86
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219
Microsoft Visual C++ 2010 Express - ENU
Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools
Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU
Microsoft Visual Studio 2010 Service Pack 1
Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
Microsoft XNA Framework Redistributable 4.0
Mount & Blade: Warband
Mount & Blade: With Fire and Sword
Mozilla Firefox 27.0.1 (x86 tr)
Mozilla Maintenance Service
MSVCRT
MSVCRT_amd64
Process Hacker 2.33 (r5590)
PX Profile Update
Realtek Ethernet Controller Driver
Recovery Manager
Security Update for Microsoft .NET Framework 4.5.1 (KB2898869)
Security Update for Microsoft .NET Framework 4.5.1 (KB2901126)
Skype™ 6.14
Steam
swMSM
Synaptics TouchPad Driver
Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU
Visual Studio 2010 x64 Redistributables
Visual Studio 2012 x64 Redistributables
Visual Studio 2012 x86 Redistributables
Windows Live Communications Platform
Windows Live Essentials
Windows Live Fotoğraf Galerisi
Windows Live ID Sign-in Assistant
Windows Live Installer
Windows Live Language Selector
Windows Live Mail
Windows Live Mesh
Windows Live Mesh ActiveX Control for Remote Connections
Windows Live Messenger
Windows Live MIME IFilter
Windows Live Movie Maker
Windows Live Photo Common
Windows Live Photo Gallery
Windows Live PIMT Platform
Windows Live Remote Client
Windows Live Remote Client Resources
Windows Live Remote Service
Windows Live Remote Service Resources
Windows Live SOXE
Windows Live SOXE Definitions
Windows Live Temel Parçalar
Windows Live UX Platform
Windows Live UX Platform Language Pack
Windows Live Writer
Windows Live Writer Resources
WinPatrol
WinRAR 4.10 (32-bit)
ZoneAlarm Firewall
ZoneAlarm Security
.
==== End Of File ===========================
AVG Scan Log (Turkish)
Anti-Rootkit tarama
"Orta öncelik;""30"";""0"";""30"""
"Başlangıç:;""20.03.2014, 19:52:45"""
"Bitiş:;""20.03.2014, 19:54:28"""
"Taranan toplam nesne:;""158267"""
"Taramayı başlatan kullanıcı:;""Batu"""
"Adı;""Açıklama"";""Sonuç"";""Durum"";""Öncelik"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0xBE64 -> aswSnx.sys +0x2D8A8"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x8548 -> aswSnx.sys +0x2D620"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngSetPointerTag+0x194 -> aswSnx.sys +0x30100"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x5A00 -> aswSnx.sys +0x2E3A8"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x45D4 -> aswSnx.sys +0x2D0F0"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngRestoreFloatingPointState+0x1120 -> aswSnx.sys +0x2F4D8"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x12E7C -> aswSnx.sys +0x2E264"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x14830 -> aswSnx.sys +0x2DB50"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys XLATEOBJ_hGetColorTransform+0x15C48 -> aswSnx.sys +0x2F538"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0xE144 -> aswSnx.sys +0x2E4D8"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x90A0 -> aswSnx.sys +0x2E62C"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x6304 -> aswSnx.sys +0x2D6D0"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys XLATEOBJ_hGetColorTransform+0x63DC -> aswSnx.sys +0x2FA98"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngRestoreFloatingPointState+0x3EA8 -> aswSnx.sys +0x2D4E0"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys STROBJ_fxBreakExtra+0x1E00 -> aswSnx.sys +0x2FF7C"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0xE2C0 -> aswSnx.sys +0x2E37C"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x2568 -> aswSnx.sys +0x2DE74"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x7BE4 -> aswSnx.sys +0x2E504"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngFntCacheLookUp+0x12488 -> aswSnx.sys +0x2D300"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngCopyBits+0x16AC -> aswSnx.sys +0x2F470"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x5694 -> aswSnx.sys +0x2DC30"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys XLATEOBJ_hGetColorTransform+0xF2C -> aswSnx.sys +0x2F584"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0xBCF8 -> aswSnx.sys +0x2D92C"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngBitBlt+0x6054 -> aswSnx.sys +0x2E0E4"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0xB7D8 -> aswSnx.sys +0x2E100"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x24D4 -> aswSnx.sys +0x2DD60"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x8104 -> aswSnx.sys +0x2DA70"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys W32pArgumentTable+0x6A64 -> aswSnx.sys +0x2E350"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngFntCacheLookUp+0x8F08 -> aswSnx.sys +0x2F2FC"";""Bulaşmış"";""Bulaşmış"";""Orta"""
"C:\Windows\system32\drivers\aswSnx.sys;""Satır için kanca win32k.sys EngPaint+0x914 -> aswSnx.sys +0x2FE00"";""Bulaşmış"";""Bulaşmış"";""Orta"""