Beyler birsey anlamadim yardimci olur musunuz? ComboFix 16-01-07.01 - Kemal 09/01/2016 13:37:09.6.2 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1254.90.1033.18.3062.1993 [GMT 2:00] Running from: c:\users\Kemal\Downloads\ComboFix.exe AV: AVG AntiVirus Free Edition *Disabled/Updated* {4D41356F-32AD-7C42-C820-63775EE4F413} SP: AVG AntiVirus Free Edition *Disabled/Updated* {F620D48B-1497-73CC-F290-58052563BEAE} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\1451588727.1152.bin c:\programdata\1451588727.3020.bin c:\programdata\1451588727.3072.bin c:\programdata\1451588727.3084.bin c:\programdata\1451588727.4284.bin c:\programdata\1451588727.4352.bin c:\programdata\1451588727.4868.bin c:\programdata\1451588727.5236.bin c:\programdata\1451588727.5944.bin c:\programdata\1451588727.6028.bin c:\programdata\1451588727.924.bin c:\programdata\1451589560.1012.bin c:\programdata\1451589560.1388.bin c:\programdata\1451589560.2080.bin c:\programdata\1451589560.2584.bin c:\programdata\1451589560.2944.bin c:\programdata\1451589560.3388.bin c:\programdata\1451589560.3600.bin c:\programdata\1451589560.4032.bin c:\programdata\1451589560.432.bin c:\programdata\1451589560.512.bin c:\programdata\1451589560.940.bin c:\programdata\1451590007.bdinstall.bin c:\programdata\1451681004.bdinstall.bin . . ((((((((((((((((((((((((( Files Created from 2015-12-09 to 2016-01-09 ))))))))))))))))))))))))))))))) . . 2016-01-09 11:50 . 2016-01-09 11:50 -------- d-----w- c:\users\Kemal\AppData\Local\temp 2016-01-09 11:50 . 2016-01-09 11:50 -------- d-----w- c:\users\Public\AppData\Local\temp 2016-01-09 11:50 . 2016-01-09 11:50 -------- d-----w- c:\users\Default\AppData\Local\temp 2016-01-09 06:43 . 2016-01-09 06:54 -------- d-----w- c:\users\Kemal\AppData\Local\Opera Software 2016-01-09 06:43 . 2016-01-09 06:54 -------- d-----w- c:\users\Kemal\AppData\Roaming\Opera Software 2016-01-09 06:41 . 2016-01-09 06:54 -------- d-----w- c:\program files\Opera 2016-01-09 03:25 . 2003-09-03 00:28 724992 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iKernel.dll 2016-01-09 03:25 . 2003-09-03 00:27 69715 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\ctor.dll 2016-01-09 03:25 . 2003-09-03 00:26 266240 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iscript.dll 2016-01-09 03:25 . 2003-09-03 00:26 192512 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iuser.dll 2016-01-09 03:25 . 2003-09-03 00:25 5632 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\DotNetInstaller.exe 2016-01-09 03:25 . 2016-01-09 03:25 311428 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\Setup.dll 2016-01-09 03:25 . 2016-01-09 03:25 184452 ----a-w- c:\program files\Common Files\InstallShield\Professional\RunTime\09\00\Intel32\iGdi.dll 2016-01-03 23:12 . 2016-01-03 23:12 -------- d-----w- c:\program files\Common Files\Java 2016-01-03 23:12 . 2016-01-03 23:12 -------- d-----w- c:\users\Kemal\.oracle_jre_usage 2016-01-03 21:34 . 2016-01-03 21:34 -------- d-----w- c:\users\Kemal\AppData\Roaming\java 2016-01-01 21:58 . 2016-01-01 21:58 -------- d-----w- c:\users\Kemal\AppData\Roaming\AVG 2016-01-01 21:10 . 2016-01-01 21:55 -------- d-----w- c:\programdata\Avg 2016-01-01 21:10 . 2016-01-01 21:54 -------- d-----w- c:\program files\AVG 2016-01-01 20:56 . 2016-01-01 21:16 -------- d-----w- c:\users\Kemal\AppData\Local\AvgSetupLog 2015-12-31 20:05 . 2015-12-31 20:05 -------- d-----w- c:\programdata\bdch 2015-12-31 19:34 . 2016-01-01 13:24 -------- d-----w- c:\programdata\BDLogging 2015-12-31 19:34 . 2015-12-31 20:08 26624 ----a-w- c:\windows\system32\bdsandboxuh.dll 2015-12-31 19:34 . 2015-12-31 20:07 74000 ----a-w- c:\windows\system32\bdsandboxuiskin.dll 2015-12-31 19:34 . 2007-04-11 09:11 511328 ----a-w- c:\windows\capicom.dll 2015-12-31 18:55 . 2016-01-01 20:45 -------- d-----w- c:\program files\Common Files\Bitdefender 2015-12-11 20:03 . 2015-12-11 20:03 -------- d-----w- c:\users\Kemal\AppData\Local\CEF . . . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2016-01-03 23:11 . 2015-05-20 17:45 95840 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2015-11-20 18:34 . 2015-12-08 22:45 93696 ----a-w- c:\windows\system32\wudriver.dll 2015-11-20 18:34 . 2015-12-08 22:45 35840 ----a-w- c:\windows\system32\wups2.dll 2015-11-20 18:34 . 2015-12-08 22:45 30208 ----a-w- c:\windows\system32\wups.dll 2015-11-20 18:34 . 2015-12-08 22:45 2956800 ----a-w- c:\windows\system32\wucltux.dll 2015-11-20 18:34 . 2015-12-08 22:45 2062848 ----a-w- c:\windows\system32\wuaueng.dll 2015-11-20 18:34 . 2015-12-08 22:45 174080 ----a-w- c:\windows\system32\wuwebv.dll 2015-11-20 18:34 . 2015-12-08 22:45 573440 ----a-w- c:\windows\system32\wuapi.dll 2015-11-20 18:34 . 2015-12-08 22:45 73728 ----a-w- c:\windows\system32\WinSetupUI.dll 2015-11-20 18:33 . 2015-12-08 22:45 11776 ----a-w- c:\windows\system32\wu.upgrade.ps.dll 2015-11-20 18:33 . 2015-12-08 22:45 35328 ----a-w- c:\windows\system32\wuapp.exe 2015-11-20 18:33 . 2015-12-08 22:45 136192 ----a-w- c:\windows\system32\wuauclt.exe 2015-11-20 06:05 . 2015-11-20 06:05 31664 ----a-w- c:\windows\system32\drivers\avgidsshimx.sys 2015-11-12 09:50 . 2015-11-25 02:11 27040 ---ha-w- c:\windows\system32\hamachi.sys 2015-11-11 18:39 . 2015-12-08 22:49 1242624 ----a-w- c:\windows\system32\comsvcs.dll 2015-11-11 18:39 . 2015-12-08 22:49 487936 ----a-w- c:\windows\system32\catsrvut.dll 2015-11-10 18:39 . 2015-12-08 22:49 909824 ----a-w- c:\windows\system32\FntCache.dll 2015-11-10 18:39 . 2015-12-08 22:49 1251328 ----a-w- c:\windows\system32\DWrite.dll 2015-11-10 18:39 . 2015-12-08 22:49 811520 ----a-w- c:\windows\system32\user32.dll 2015-11-10 17:40 . 2015-12-08 22:49 2386944 ----a-w- c:\windows\system32\win32k.sys 2015-11-10 00:24 . 2015-12-08 22:48 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2015-11-10 00:24 . 2015-12-08 22:48 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2015-11-10 00:13 . 2015-12-08 22:48 496640 ----a-w- c:\windows\system32\vbscript.dll 2015-11-10 00:13 . 2015-12-08 22:48 62464 ----a-w- c:\windows\system32\iesetup.dll 2015-11-10 00:12 . 2015-12-08 22:49 47616 ----a-w- c:\windows\system32\ieetwproxystub.dll 2015-11-10 00:12 . 2015-12-08 22:48 341504 ----a-w- c:\windows\system32\html.iec 2015-11-10 00:11 . 2015-12-08 22:48 64000 ----a-w- c:\windows\system32\MshtmlDac.dll 2015-11-10 00:03 . 2015-12-08 22:49 102912 ----a-w- c:\windows\system32\ieetwcollector.exe 2015-11-10 00:03 . 2015-12-08 22:48 115712 ----a-w- c:\windows\system32\ieUnatt.exe 2015-11-10 00:02 . 2015-12-08 22:48 620032 ----a-w- c:\windows\system32\jscript9diag.dll 2015-11-09 23:57 . 2015-12-08 22:48 667648 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2015-11-09 23:50 . 2015-12-08 22:49 60416 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2015-11-09 23:46 . 2015-12-08 22:48 4514816 ----a-w- c:\windows\system32\jscript9.dll 2015-11-09 23:36 . 2015-12-08 22:48 2050560 ----a-w- c:\windows\system32\inetcpl.cpl 2015-11-09 23:35 . 2015-12-08 22:48 1155072 ----a-w- c:\windows\system32\mshtmlmedia.dll 2015-11-09 23:17 . 2015-12-08 22:48 2011136 ----a-w- c:\windows\system32\wininet.dll 2015-11-06 13:48 . 2015-11-06 13:48 255920 ----a-w- c:\windows\system32\drivers\avgidsdriverx.sys 2015-11-06 13:48 . 2015-11-06 13:48 193968 ----a-w- c:\windows\system32\drivers\avgmfx86.sys 2015-11-06 13:48 . 2015-11-06 13:48 149936 ----a-w- c:\windows\system32\drivers\avgdiskx.sys 2015-11-05 19:02 . 2015-12-08 22:44 14848 ----a-w- c:\windows\system32\wshrm.dll 2015-11-05 19:00 . 2015-12-08 22:45 2048 ----a-w- c:\windows\system32\tzres.dll 2015-11-05 09:48 . 2015-12-08 22:44 117760 ----a-w- c:\windows\system32\drivers\rmcast.sys 2015-11-03 18:56 . 2015-12-08 22:44 627712 ----a-w- c:\windows\system32\usp10.dll 2015-11-03 18:55 . 2015-12-08 22:45 179712 ----a-w- c:\windows\system32\els.dll 2015-10-29 17:50 . 2015-11-21 01:12 5120 ----a-w- c:\windows\system32\shimeng.dll 2015-10-29 17:49 . 2015-11-21 01:12 295936 ----a-w- c:\windows\system32\apphelp.dll 2015-10-29 17:49 . 2015-11-21 01:12 62464 ----a-w- c:\windows\system32\aelupsvc.dll 2015-10-29 17:49 . 2015-11-21 01:12 562176 ----a-w- c:\windows\apppatch\AcLayers.dll 2015-10-29 17:49 . 2015-11-21 01:12 470528 ----a-w- c:\windows\apppatch\AcSpecfc.dll 2015-10-29 17:49 . 2015-11-21 01:12 2178560 ----a-w- c:\windows\apppatch\AcGenral.dll 2015-10-29 17:49 . 2015-11-21 01:12 211968 ----a-w- c:\windows\apppatch\AcXtrnal.dll 2015-10-29 17:49 . 2015-11-21 01:12 20992 ----a-w- c:\windows\system32\sdbinst.exe 2015-10-29 17:39 . 2015-11-21 01:12 2560 ----a-w- c:\windows\apppatch\AcRes.dll 2015-10-26 09:15 . 2015-10-26 09:15 27040 ---ha-w- c:\windows\system32\drivers\hamachi.sys 2015-10-21 14:24 . 2015-10-21 14:24 229296 ----a-w- c:\windows\system32\drivers\avgldx86.sys 2015-10-20 00:52 . 2015-11-23 04:49 3991488 ----a-w- c:\windows\system32\ntkrnlpa.exe 2015-10-20 00:52 . 2015-11-23 04:49 3935680 ----a-w- c:\windows\system32\ntoskrnl.exe 2015-10-20 00:52 . 2015-11-23 04:49 138176 ----a-w- c:\windows\system32\drivers\ksecpkg.sys 2015-10-20 00:52 . 2015-11-23 04:49 67520 ----a-w- c:\windows\system32\drivers\ksecdd.sys 2015-10-20 00:48 . 2015-11-23 04:49 1308160 ----a-w- c:\windows\system32\ntdll.dll 2015-10-20 00:45 . 2015-11-23 04:49 172032 ----a-w- c:\windows\system32\wdigest.dll 2015-10-20 00:45 . 2015-11-23 04:49 65536 ----a-w- c:\windows\system32\TSpkg.dll 2015-10-20 00:45 . 2015-11-23 04:49 400896 ----a-w- c:\windows\system32\srcore.dll 2015-10-20 00:45 . 2015-11-23 04:49 100352 ----a-w- c:\windows\system32\sspicli.dll 2015-10-20 00:45 . 2015-11-23 04:49 43008 ----a-w- c:\windows\system32\srclient.dll 2015-10-20 00:45 . 2015-11-23 04:49 15872 ----a-w- c:\windows\system32\sspisrv.dll 2015-10-20 00:45 . 2015-11-23 04:49 251392 ----a-w- c:\windows\system32\schannel.dll 2015-10-20 00:45 . 2015-11-23 04:49 22016 ----a-w- c:\windows\system32\secur32.dll 2015-10-20 00:45 . 2015-11-23 04:49 655360 ----a-w- c:\windows\system32\rpcrt4.dll 2015-10-20 00:45 . 2015-11-23 04:49 223232 ----a-w- c:\windows\system32\ncrypt.dll 2015-10-20 00:45 . 2015-11-23 04:49 259584 ----a-w- c:\windows\system32\msv1_0.dll 2015-10-20 00:45 . 2015-11-23 04:49 1061376 ----a-w- c:\windows\system32\lsasrv.dll 2015-10-20 00:45 . 2015-11-23 04:49 552960 ----a-w- c:\windows\system32\kerberos.dll 2015-10-20 00:45 . 2015-11-23 04:49 38912 ----a-w- c:\windows\system32\csrsrv.dll 2015-10-20 00:45 . 2015-11-23 04:49 36864 ----a-w- c:\windows\system32\cryptbase.dll 2015-10-20 00:45 . 2015-11-23 04:49 17408 ----a-w- c:\windows\system32\credssp.dll 2015-10-20 00:45 . 2015-11-23 04:49 69632 ----a-w- c:\windows\system32\smss.exe 2015-10-20 00:45 . 2015-11-23 04:49 262656 ----a-w- c:\windows\system32\rstrui.exe 2015-10-20 00:44 . 2015-11-23 04:49 22528 ----a-w- c:\windows\system32\lsass.exe 2015-10-20 00:44 . 2015-11-23 04:49 50176 ----a-w- c:\windows\system32\auditpol.exe 2015-10-20 00:39 . 2015-11-23 04:49 60416 ----a-w- c:\windows\system32\msobjs.dll 2015-10-20 00:39 . 2015-11-23 04:49 146432 ----a-w- c:\windows\system32\msaudite.dll 2015-10-20 00:35 . 2015-11-23 04:49 6656 ----a-w- c:\windows\system32\apisetschema.dll 2015-10-20 00:35 . 2015-11-23 04:49 686080 ----a-w- c:\windows\system32\adtschema.dll 2015-10-19 23:29 . 2015-11-23 04:49 225792 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys 2015-10-19 23:28 . 2015-11-23 04:49 98304 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys 2015-10-19 23:28 . 2015-11-23 04:49 124416 ----a-w- c:\windows\system32\drivers\mrxsmb.sys 2015-10-13 16:31 . 2015-11-21 01:12 338944 ----a-w- c:\windows\system32\drivers\afd.sys 2015-10-13 16:31 . 2015-11-21 01:12 74752 ----a-w- c:\windows\system32\drivers\tdx.sys 2015-10-13 04:50 . 2015-11-21 01:12 712640 ----a-w- c:\windows\system32\drivers\ndis.sys 2015-10-12 23:29 . 2015-10-12 23:29 875720 ----a-w- c:\windows\system32\msvcr120_clr0400.dll . . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "DAEMON Tools Lite Automount"="c:\program files\DAEMON Tools Lite\DTAgent.exe" [2015-06-18 3576664] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2009-09-24 141848] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2009-09-24 173592] "Persistence"="c:\windows\system32\igfxpers.exe" [2009-09-24 150552] "AvgUi"="c:\program files\AVG\Framework\Common\avguix.exe" [2015-12-08 1139112] "AVG_UI"="c:\program files\AVG\Av\avgui.exe" [2015-12-09 3855272] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2015-11-09 596528] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "iCloud"="c:\program files\Common Files\Apple\Internet Services\iCloud.exe" [2015-10-21 60688] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2015-10-28 16:49 1067736 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ApplePhotoStreams] 2015-10-21 09:35 61200 ----a-w- c:\program files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BCSSync] 2012-11-05 13:27 89184 ----a-w- c:\program files\Microsoft Office\Office14\BCSSync.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iCloudServices] 2015-10-21 09:36 60688 ----a-w- c:\program files\Common Files\Apple\Internet Services\iCloudServices.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] 2015-10-16 01:47 157456 ----a-w- c:\program files\iTunes\iTunesHelper.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Download Assistant] 2012-09-20 14:02 1425208 ----a-w- c:\windows\System32\LogiLDA.DLL . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2015-11-09 10:52 596528 ----a-w- c:\program files\Common Files\Java\Java Update\jusched.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] 2008-08-14 07:40 1348904 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe . R2 AVGIDSAgent;AVGIDSAgent;c:\program files\AVG\Av\avgidsagent.exe [2015-12-09 3857272] R3 AvgAMPS;AvgAMPS;c:\program files\AVG\Av\avgamps.exe [2015-12-09 615584] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [2013-08-20 84248] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464] R3 ew_hwusbdev;Huawei MobileBroadband USB PNP Device;c:\windows\system32\DRIVERS\ew_hwusbdev.sys [x] R3 ew_usbenumfilter;huawei_CompositeFilter;c:\windows\system32\DRIVERS\ew_usbenumfilter.sys [x] R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [x] R3 hasplms;Sentinel HASP License Manager;c:\windows\system32\hasplms.exe -run [x] R3 HTCAND32;HTC Device Driver;c:\windows\system32\Drivers\ANDROIDUSB.sys [2009-10-26 25088] R3 huawei_enumerator;huawei_enumerator;c:\windows\system32\DRIVERS\ew_jubusenum.sys [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2015-11-10 102912] R3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\DRIVERS\netaapl.sys [2015-01-16 18944] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [2014-01-22 184192] R3 taphss6;Anchorfree HSS VPN Adapter;c:\windows\system32\DRIVERS\taphss6.sys [x] R3 Te.Service;Te.Service;c:\program files\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [2013-08-21 91136] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2013-10-02 49152] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-20 27264] R3 VsEtwService120;Visual Studio ETW Event Collection Service;d:\visual studio\Common7\Packages\Debugger\Services\VsEtwService.exe [2014-07-22 73360] R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-10-16 1343400] R4 KMService;KMService;c:\windows\system32\srvany.exe [2013-01-06 8192] S0 AVGIDSHX;AVGIDSHX;c:\windows\system32\DRIVERS\avgidshx.sys [2015-08-20 231344] S0 Avglogx;AVG Logging Driver;c:\windows\system32\DRIVERS\avglogx.sys [2015-08-14 308656] S0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\DRIVERS\avgrkx86.sys [2015-08-10 36784] S1 Avgdiskx;AVG Disk Driver;c:\windows\system32\DRIVERS\avgdiskx.sys [2015-11-06 149936] S1 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\DRIVERS\avgidsdriverx.sys [2015-11-06 255920] S1 AVGIDSShim;AVGIDSShim;c:\windows\system32\DRIVERS\avgidsshimx.sys [2015-11-20 31664] S1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\DRIVERS\avgldx86.sys [2015-10-21 229296] S1 Avgtdix;AVG TDI Driver;c:\windows\system32\DRIVERS\avgtdix.sys [2015-10-08 231856] S2 avgsvc;AVG Service;c:\program files\AVG\Framework\Common\avgsvcx.exe [2015-12-08 866216] S2 avgwd;AVG WatchDog;c:\program files\AVG\Av\avgwdsvcx.exe [2015-12-09 579776] S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe [2009-07-14 20992] S2 IpOverUsbSvc;Windows Phone IP over USB Transport (IpOverUsbSvc);c:\program files\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [2014-10-15 22744] S3 Disc Soft Lite Bus Service;Disc Soft Lite Bus Service;c:\program files\DAEMON Tools Lite\DiscSoftBusService.exe [2015-06-18 1034584] S3 dtlitescsibus;DAEMON Tools Lite Virtual SCSI Bus;c:\windows\system32\DRIVERS\dtlitescsibus.sys [2015-07-08 25016] S3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt86win7.sys [2011-06-10 394856] . . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] utcsvc REG_MULTI_SZ DiagTrack . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2015-12-16 01:28 1000264 ----a-w- c:\program files\Google\Chrome\Application\47.0.2526.106\Installer\chrmstp.exe . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}] 2015-11-18 16:22 286904 ----a-w- c:\program files\Adobe\Acrobat Reader DC\Esl\AiodLite.dll . Contents of the 'Scheduled Tasks' folder . 2016-01-09 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-11-26 22:37] . 2016-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-10-14 21:13] . 2016-01-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2012-10-14 21:13] . . ------- Supplementary Scan ------- . uInternet Settings,ProxyOverride = *.local IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~1\Office14\EXCEL.EXE/3000 IE: Se&nd to OneNote - c:\progra~1\MICROS~1\Office14\ONBttnIE.dll/105 TCP: DhcpNameServer = 172.20.10.1 TCP: Interfaces\{0A848263-C5DC-442D-9234-EFE54C0650CC}: NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{0A848263-C5DC-442D-9234-EFE54C0650CC}\03D2B41445: NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{0A848263-C5DC-442D-9234-EFE54C0650CC}\14942545945435F51405D2330323: NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{0A848263-C5DC-442D-9234-EFE54C0650CC}\2416B696023416E602960586F6E6567257: NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{0A848263-C5DC-442D-9234-EFE54C0650CC}\3555055425F4E4C494E454D275966496F523034303: NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{0A848263-C5DC-442D-9234-EFE54C0650CC}\B41647D223D297F6C6: NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{0A848263-C5DC-442D-9234-EFE54C0650CC}\D656E656B63756: NameServer = 8.8.8.8,8.8.4.4 TCP: Interfaces\{3444B944-5A30-4A43-AD00-E407B7DDF061}: NameServer = 208.67.222.222,208.67.220.220 TCP: Interfaces\{64F2BF5F-D06E-4BAB-8B2B-F367F4787370}: NameServer = 208.67.220.220,208.67.222.222 TCP: Interfaces\{BF75EC2C-11C5-4D20-95D9-21681EE989BA}: NameServer = 4.2.2.2,4.2.2.1 . - - - - ORPHANS REMOVED - - - - . MSConfigStartUp-Bitdefender Wallet Agent - c:\program files\Bitdefender\Bitdefender 2015\bdwtxag.exe MSConfigStartUp-InstallerLauncher - c:\program files\Common Files\Bitdefender\SetupInformation\{6F57816A-791A-4159-A75F-CFD0C7EA4FBF}\setuplauncher.exe . . . --------------------- LOCKED REGISTRY KEYS --------------------- . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 "MSCurrentCountry"=dword:000000b5 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Completion time: 2016-01-09 13:53:07 ComboFix-quarantined-files.txt 2016-01-09 11:53 ComboFix2.txt 2015-12-29 21:15 ComboFix3.txt 2015-12-04 20:36 ComboFix4.txt 2015-06-29 16:10 ComboFix5.txt 2016-01-09 11:16 . Pre-Run: 73,314,975,744 bytes free Post-Run: 73,089,056,768 bytes free . - - End Of File - - 544FBE0B5970FD4AC7EA37D6BAF05267 A36C5E4F47E84449FF07ED3517B43A31