mech
New Helpee
Posts: 18
|
Post by mech on Apr 30, 2016 0:52:26 GMT -8
Hi. I think there is a malware in my PC. Would you like to help me to clean it up. Above is the screenshot of my antvirus, Norton.
|
|
dbrisen
Malware Removalists
Posts: 3,688
|
Post by dbrisen on Apr 30, 2016 22:03:20 GMT -8
Yes, that is malware. You will have to provide some scanned logs for the malware to be removed. Please follow the steps in this thread ( I think I am infected. What do I do? ). Once you have provided the logs required, I will assist you as best we can. Thank you. Note: If Norton deletes the FRST download, you may have to disable Norton for a short period to run the FRST scanner.
|
|
mech
New Helpee
Posts: 18
|
Post by mech on May 1, 2016 2:24:08 GMT -8
"Save All tools that I have you download should be placed on the desktop unless otherwise stated".
There are different partitions in my HDD and there different .exe files in these partitions. So should I carry all of them to the desktop? What's if I carry them in a folder in the desktop? Do tools refer to the .exe files?
Thank you.
P.S Attacks have been finished and everything seems O.K and I have made a scan with Emsisoft Anti-Malware. Does it mean malware started to sleep but will be active in the future?
|
|
dbrisen
Malware Removalists
Posts: 3,688
|
Post by dbrisen on May 1, 2016 20:12:45 GMT -8
WE actually needed the FRST scanner to be loaded to the desktop (saved there when you downloaded the file from BleepingComputer). This also would have concerned any other tools I would have asked you to download.
HOWEVER, Norton may have adjusted their definitions to stop the attacks in the meantime. Did Emsisoft Anti-Malware find any malware? (If you go to Logs > Scan and double click on the scan log for this scan you mentioned, the log will open in notepad and you can either copy and paste it here or save the log as a .txt file and attach it.)
|
|
mech
New Helpee
Posts: 18
|
Post by mech on May 7, 2016 11:42:19 GMT -8
This is result of quick scan:
Emsisoft Anti-Malware - Version 11.7.0.6394 Last update: 7.5.2016 21:55:22 Initiated by: hp_\hp
Scan settings:
Scan type: Quick Scan Objects: Rootkits, Memory, Traces
Detect PUPs: Off Scan archives: Off ADS Scan: On File extension filter: Off Advanced caching: On Direct disk access: Off
Scan start: 7.5.2016 22:26:11
Scanned 62318 Found 0
Scan end: 7.5.2016 22:27:12 Scan time: 0:01:01
and this is result of malware scan:
Emsisoft Anti-Malware - Version 11.7.0.6394 Last update: 7.5.2016 21:55:22 Initiated by: hp_\hp
Scan settings:
Scan type: Malware Scan Objects: Rootkits, Memory, Traces, Files
Detect PUPs: Off Scan archives: Off ADS Scan: On File extension filter: Off Advanced caching: On Direct disk access: Off
Scan start: 7.5.2016 22:03:18
Scanned 121671 Found 0
Scan end: 7.5.2016 22:19:47 Scan time: 0:16:29
I feel and perceive that there is a suspicious and secret activity in my PC.
1) Norton gives a high disk notification but in this notification norton requires to connect internet but it cannot connect. But there is internet connection so I cannot monitor what is causing high disk usage.
2) The content of my harddisk drive C is changing by itself. There was 20 GB free and then it lowered to 13 GB now it is still 20 GB free. I really would like to find that malware Thank you.
|
|
dbrisen
Malware Removalists
Posts: 3,688
|
Post by dbrisen on May 8, 2016 20:30:37 GMT -8
I have seen this malware before and need the FRST scan logs to remove the culprit.
|
|
mech
New Helpee
Posts: 18
|
Post by mech on May 13, 2016 1:21:37 GMT -8
Here is the scan. I think because it is too long website gives an error. I will divide the FRST.txt into two parts and I will copy paste it. I cannot even send it as an attachment.
Part 1
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:09-05-2016 Ran by hp (administrator) on HP_ (13-05-2016 12:14:56) Running from C:\Users\hp\Desktop Loaded Profiles: hp (Available Profiles: hp & Administrator) Platform: Windows 8.1 Single Language (X64) Language: English (United Kingdom) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RTKAUDIOSERVICE64.EXE (Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2service.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe () C:\Program Files\Everything\Everything.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\nis.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (AMD) C:\Windows\System32\atieclxx.exe (CyberLink) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\nis.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2guard.exe () C:\Program Files\Everything\Everything.exe () C:\Program Files (x86)\Greenshot\Greenshot.exe (WordWeb Software) C:\Program Files (x86)\WordWeb\wweb32.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\idman.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Emsisoft Ltd) C:\Program Files\Emsisoft Anti-Malware\a2start.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Internet Download Manager, Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\idmBroker.exe (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7191768 2013-06-18] (Realtek Semiconductor) HKLM\...\Run: [emsisoft anti-malware] => c:\program files\emsisoft anti-malware\a2guard.exe [9405904 2016-04-26] (Emsisoft Ltd) HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [1441792 2014-08-06] () HKLM\...\Run: [BCSSync] => C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2994928 2013-06-05] (Synaptics Incorporated) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-07-04] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [77088 2013-03-01] (Hewlett-Packard Company) HKLM-x32\...\Run: [YouCam Service] => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [267224 2013-05-22] (CyberLink Corp.) HKLM-x32\...\Run: [HPMessageService] => C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPMSGSVC.exe [1045304 2013-05-03] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [937920 2011-06-06] (Adobe Systems Incorporated) HKU\S-1-5-21-1508925376-3250446775-450008754-1002\...\Run: [Greenshot] => C:\Program Files (x86)\Greenshot\Greenshot.exe [548864 2010-07-12] () HKU\S-1-5-21-1508925376-3250446775-450008754-1002\...\Run: [WordWeb] => C:\Program Files (x86)\WordWeb\wweb32.exe [65216 2009-11-08] (WordWeb Software) HKU\S-1-5-21-1508925376-3250446775-450008754-1002\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3907152 2016-05-01] (Tonec Inc.) ShellIconOverlayIdentifiers: [ IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll [2015-08-14] (Tonec Inc.) ShellIconOverlayIdentifiers: [ OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Internet Security\Engine64\22.6.0.142\buShell.dll [2016-02-18] (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Internet Security\Engine64\22.6.0.142\buShell.dll [2016-02-18] (Symantec Corporation) ShellIconOverlayIdentifiers: [ OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Internet Security\Engine64\22.6.0.142\buShell.dll [2016-02-18] (Symantec Corporation) ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => No File ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => No File
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{18CE6280-65FD-4616-9E30-8B96F5EA8C04}: [NameServer] 8.8.8.8,8.8.4.4 Tcpip\..\Interfaces\{18CE6280-65FD-4616-9E30-8B96F5EA8C04}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{9D187217-0971-4FF3-90E6-EFBD4DB41440}: [DhcpNameServer] 40.21.1.201 40.21.1.202
Internet Explorer: ================== HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com?pc=HPNTDFJS HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.bing.com?pc=HPNTDFJS HKU\S-1-5-21-1508925376-3250446775-450008754-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com?pc=HPNTDFJS HKU\S-1-5-21-1508925376-3250446775-450008754-1002\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.bing.com?pc=HPNTDFJS SearchScopes: HKLM -> {46FE6CF5-1C1C-460D-B435-502BA857D956} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 -> {46FE6CF5-1C1C-460D-B435-502BA857D956} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKU\S-1-5-21-1508925376-3250446775-450008754-1002 -> {46FE6CF5-1C1C-460D-B435-502BA857D956} URL = hxxp://www.amazon.co.uk/s/ref=azs_osd_ieauk?ie=UTF-8&tag=hp-uk3-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} BHO: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll [2015-07-08] (Internet Download Manager, Tonec Inc.) BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine64\22.6.0.142\coIEPlg.dll [2016-02-21] (Symantec Corporation) BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: IDM integration (IDMIEHlprObj Class) -> {0055C089-8582-441B-A0BF-17B458C2A3A8} -> C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll [2015-07-08] (Internet Download Manager, Tonec Inc.) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-06-06] (Adobe Systems Incorporated) BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\coIEPlg.dll [2016-02-21] (Symantec Corporation) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\IPS\IPSBHO.DLL => No File BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation) BHO-x32: QUICKfind BHO Object -> {C08DF07A-3E49-4E25-9AB0-D3882835F153} -> C:\Program Files (x86)\IDM\QUICKfind\PlugIns\IEHelp.dll [2007-02-16] (IDM) BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2012-07-09] (Hewlett-Packard) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\22.6.0.142\coIEPlg.dll [2016-02-21] (Symantec Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\coIEPlg.dll [2016-02-21] (Symantec Corporation) Toolbar: HKU\S-1-5-21-1508925376-3250446775-450008754-1002 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\22.6.0.142\coIEPlg.dll [2016-02-21] (Symantec Corporation)
FireFox: ======== FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll [2013-04-03] (Adobe Systems, Inc.) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3505.0912 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-09-12] (Microsoft Corporation) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2011-06-06] (Adobe Systems Inc.) FF HKLM\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.5.4.24\coFFAddon FF Extension: Norton Identity Safe - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.5.4.24\coFFAddon [2016-05-08] FF HKLM-x32\...\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_22.5.4.24\coFFAddon FF HKU\S-1-5-21-1508925376-3250446775-450008754-1002\...\SeaMonkey\Extensions: [mozilla_cc@internetdownloadmanager.com] - C:\Users\hp\AppData\Roaming\IDM\idmmzcc5 FF Extension: IDM CC - C:\Users\hp\AppData\Roaming\IDM\idmmzcc5 [2016-05-13] [not signed]
Chrome: ======= CHR HKLM\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\Exts\Chrome.crx [2016-05-06] CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-08-14] CHR HKLM-x32\...\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\Exts\Chrome.crx [2016-05-06] CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2015-08-14]
==================== Services (Whitelisted) ========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [11341584 2016-04-26] (Emsisoft Ltd) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed] R2 CyberLink PowerDVD 12 Media Server Monitor Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSMonitorServicePDVD12.exe [77576 2013-06-26] (CyberLink) R2 CyberLink PowerDVD 12 Media Server Service; C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe [294664 2013-06-26] (CyberLink) R2 Everything; C:\Program Files\Everything\Everything.exe [1441792 2014-08-06] () [File not signed] S2 HP Support Assistant Service; C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe [92160 2013-06-07] (Hewlett-Packard Company) [File not signed] R2 HPWMISVC; C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPWMISVC.exe [1039160 2013-05-03] (Hewlett-Packard Development Company, L.P.) R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\22.6.0.142\NIS.exe [289080 2016-02-26] (Symantec Corporation) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [246488 2013-06-19] (Realtek Semiconductor) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-11-21] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-11-21] (Microsoft Corporation)
===================== Drivers (Whitelisted) ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [37472 2013-02-14] (Advanced Micro Devices, Inc.) S2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98744 2013-04-24] (Advanced Micro Devices) R1 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.4.24\Definitions\BASHDefs\20160502.001\BHDrvx64.sys [1766640 2016-05-02] (Symantec Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1606000.08E\ccSetx64.sys [173808 2015-09-24] (Symantec Corporation) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-05] (CyberLink) S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [497392 2016-05-04] (Symantec Corporation) R1 epp; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp.sys [126280 2016-04-07] (Emsisoft Ltd) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [156912 2016-05-04] (Symantec Corporation) R1 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.4.24\Definitions\IPSDefs\20160510.005\IDSvia64.sys [876248 2016-05-11] (Symantec Corporation) R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.4.24\Definitions\VirusDefs\20160512.051\ENG64.SYS [138488 2016-05-04] (Symantec Corporation) R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\22.5.4.24\Definitions\VirusDefs\20160512.051\EX64.SYS [2148080 2016-05-04] (Symantec Corporation) R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [288840 2013-04-11] (Realtek Semiconductor Corp.) R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [2715208 2013-05-28] (Realtek Semiconductor Corporation ) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [29424 2013-06-05] (Synaptics Incorporated) S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [33008 2013-06-05] (Synaptics Incorporated) R1 SRTSP; C:\Windows\System32\Drivers\NISx64\1606000.08E\SRTSP64.SYS [928504 2016-02-24] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1606000.08E\SRTSPX64.SYS [50936 2015-09-24] (Symantec Corporation) R0 SymEFASI; C:\Windows\System32\drivers\NISx64\1606000.08E\SYMEFASI64.SYS [1621232 2016-02-24] (Symantec Corporation) S0 SymELAM; C:\Windows\System32\drivers\NISx64\1606000.08E\SymELAM.sys [24192 2015-09-24] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [111344 2016-05-02] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1606000.08E\Ironx64.SYS [295664 2016-02-24] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1606000.08E\SYMNETS.SYS [577768 2016-02-24] (Symantec Corporation) S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [35856 2014-11-21] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [257880 2014-11-21] (Microsoft Corporation) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-11-21] (Microsoft Corporation) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20800 2012-08-31] (Hewlett-Packard Development Company, L.P.)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2016-05-13 12:13 - 2016-05-13 12:15 - 00019749 _____ C:\Users\hp\Desktop\FRST.txt 2016-05-13 12:13 - 2016-05-13 12:10 - 02381312 _____ (Farbar) C:\Users\hp\Desktop\FRST64.exe 2016-05-13 12:10 - 2016-05-13 12:14 - 00000000 ____D C:\FRST 2016-05-13 01:57 - 2016-05-13 01:57 - 00037515 _____ C:\Users\hp\Desktop\In the Internet or On the internet.htm 2016-05-12 10:32 - 2016-05-12 10:33 - 166592252 _____ C:\Users\hp\Downloads\Kim Milyoner Olmak İster- - 567.Bölüm - ATV.ts 2016-05-12 10:30 - 2016-05-12 10:32 - 180116596 _____ C:\Users\hp\Downloads\Kim Milyoner Olmak İster- - 568.Bölüm - ATV.ts 2016-05-12 10:29 - 2016-05-12 10:31 - 161425260 _____ C:\Users\hp\Downloads\Kim Milyoner Olmak İster- - 569.Bölüm - ATV.ts 2016-05-12 10:27 - 2016-05-12 10:29 - 171197876 _____ C:\Users\hp\Downloads\Kim Milyoner Olmak İster- - 570.Bölüm - ATV.ts 2016-05-12 00:22 - 2016-05-12 00:22 - 00001236 _____ C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PolyLingua.lnk 2016-05-12 00:20 - 2016-05-12 00:22 - 00001036 _____ C:\Users\hp\Desktop\PolyLingua.LNK 2016-05-12 00:20 - 2016-05-12 00:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PolyLingua 2016-05-08 13:39 - 2016-05-10 22:47 - 00000000 ___DC C:\WINDOWS\Panther 2016-05-08 13:38 - 2016-05-13 01:15 - 00000000 ____D C:\Windows.old 2016-05-08 13:38 - 2016-05-08 13:38 - 00262144 _____ C:\WINDOWS\system32\config\userdiff 2016-05-08 13:35 - 2016-05-08 13:35 - 00000000 ____D C:\Program Files\Reference Assemblies 2016-05-08 13:35 - 2016-05-08 13:35 - 00000000 ____D C:\Program Files\MSBuild 2016-05-08 13:35 - 2016-05-08 13:35 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies 2016-05-08 13:35 - 2016-05-08 13:35 - 00000000 ____D C:\inetpub 2016-05-08 13:35 - 2016-05-08 11:03 - 00000000 ____D C:\Program Files (x86)\MSBuild 2016-05-08 13:34 - 2016-05-08 13:34 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\sdbinst.exe 2016-05-08 13:34 - 2016-05-08 13:34 - 00021504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sdbinst.exe 2016-05-08 13:34 - 2013-08-03 07:48 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll 2016-05-08 13:34 - 2013-08-03 07:48 - 00124112 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll 2016-05-08 13:34 - 2013-08-03 07:48 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe 2016-05-08 13:34 - 2013-08-03 07:41 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll 2016-05-08 13:34 - 2013-08-03 07:41 - 00102608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll 2016-05-08 13:34 - 2013-08-03 07:41 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe 2016-05-08 11:47 - 2016-05-08 11:47 - 00000000 __SHD C:\Users\hp\AppData\LocalLow\EmieUserList 2016-05-08 11:47 - 2016-05-08 11:47 - 00000000 __SHD C:\Users\hp\AppData\LocalLow\EmieBrowserModeList 2016-05-08 11:46 - 2016-05-13 09:50 - 00003894 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{27436C2C-5D18-41D7-917C-F01D6E05C581} 2016-05-08 11:46 - 2016-05-08 11:47 - 00000000 __SHD C:\Users\hp\AppData\LocalLow\EmieSiteList 2016-05-08 11:46 - 2016-05-08 11:46 - 00000000 __SHD C:\Users\hp\AppData\Local\EmieUserList 2016-05-08 11:46 - 2016-05-08 11:46 - 00000000 __SHD C:\Users\hp\AppData\Local\EmieSiteList 2016-05-08 11:46 - 2016-05-08 11:46 - 00000000 __SHD C:\Users\hp\AppData\Local\EmieBrowserModeList 2016-05-08 11:37 - 2016-05-08 11:37 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf 2016-05-08 11:33 - 2016-05-08 11:34 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton Internet Security 2016-05-08 11:27 - 2016-05-08 11:27 - 00001442 _____ C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2016-05-08 11:25 - 2016-05-08 11:25 - 00003236 _____ C:\WINDOWS\System32\Tasks\Norton WSC Integration 2016-05-08 11:25 - 2016-05-08 11:25 - 00000020 ___SH C:\Users\hp\ntuser.ini 2016-05-08 11:21 - 2016-05-08 11:21 - 00022744 _____ C:\WINDOWS\system32\emptyregdb.dat 2016-05-08 11:09 - 2016-05-08 11:22 - 00000000 ____D C:\Users\Public\Documents\CyberLink 2016-05-08 11:01 - 2016-05-08 11:01 - 00001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2016-05-08 11:01 - 2016-05-08 11:01 - 00000000 ____D C:\Users\Default\Documents\hp.system.package.metadata 2016-05-08 11:01 - 2016-05-08 11:01 - 00000000 ____D C:\Users\Default\Documents\hp.applications.package.appdata 2016-05-08 11:01 - 2016-05-08 11:01 - 00000000 ____D C:\Users\Default\AppData\Local\Microsoft Help 2016-05-08 11:01 - 2016-05-08 11:01 - 00000000 ____D C:\Users\Default User\Documents\hp.system.package.metadata 2016-05-08 11:01 - 2016-05-08 11:01 - 00000000 ____D C:\Users\Default User\Documents\hp.applications.package.appdata 2016-05-08 11:01 - 2016-05-08 11:01 - 00000000 ____D C:\Users\Default User\AppData\Local\Microsoft Help 2016-05-08 10:55 - 2016-05-08 10:55 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate 2016-05-08 10:53 - 2016-05-12 11:26 - 00000000 ____D C:\Users\hp 2016-05-08 10:53 - 2016-05-08 11:22 - 00032388 _____ C:\WINDOWS\diagwrn.xml 2016-05-08 10:53 - 2016-05-08 11:22 - 00032388 _____ C:\WINDOWS\diagerr.xml 2016-05-08 10:53 - 2016-05-08 11:16 - 00000000 ____D C:\Users\Administrator 2016-05-08 10:53 - 2014-11-21 05:57 - 00000369 _____ C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk 2016-05-08 10:53 - 2014-11-21 05:57 - 00000369 _____ C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk 2016-05-08 10:53 - 2014-11-21 05:57 - 00000369 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk 2016-05-08 10:53 - 2014-11-21 05:57 - 00000369 _____ C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk 2016-05-08 10:48 - 2016-05-08 10:48 - 00922144 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI 2016-05-08 10:44 - 2016-05-08 10:59 - 00000000 ____D C:\ProgramData\AMD 2016-05-08 10:44 - 2016-05-08 10:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center 2016-05-08 10:44 - 2016-05-08 10:44 - 00000000 ____D C:\Program Files\ATI Technologies 2016-05-08 10:43 - 2016-05-08 10:59 - 00000000 ____D C:\Program Files (x86)\ATI Technologies 2016-05-08 10:43 - 2016-05-08 10:43 - 00000000 ____D C:\WINDOWS\SysWOW64\RTCOM 2016-05-08 10:43 - 2016-05-08 10:43 - 00000000 ____D C:\WINDOWS\system32\SRSLabs 2016-05-08 10:43 - 2016-05-08 10:43 - 00000000 ____D C:\ProgramData\Package Cache 2016-05-08 10:43 - 2016-05-08 10:43 - 00000000 ____D C:\Program Files\Realtek 2016-05-08 10:43 - 2016-05-08 10:43 - 00000000 _____ C:\WINDOWS\ativpsrm.bin 2016-05-08 10:42 - 2016-05-08 10:42 - 00000264 _____ C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job 2016-05-08 10:42 - 2016-05-08 10:42 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf 2016-05-08 10:42 - 2016-05-08 10:42 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2016-05-08 10:42 - 2016-05-08 10:42 - 00000000 ____D C:\Program Files\Synaptics 2016-05-08 10:42 - 2016-05-08 10:42 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies 2016-05-08 10:42 - 2016-05-08 10:42 - 00000000 ____D C:\Program Files\AMD 2016-05-08 10:42 - 2016-05-08 10:42 - 00000000 ____D C:\AMD 2016-05-08 09:58 - 2016-05-08 09:58 - 06652696 _____ C:\Users\hp\Downloads\Ed Skoudis, Lenny Zeltser-Malware_ Fighting Malicious Code-Prentice Hall PTR (2003).chm 2016-05-08 09:38 - 2016-05-08 09:38 - 02747365 _____ C:\Users\hp\Downloads\Matt Bishop-Computer Security_ Art and Science-Addison-Wesley Professional (2002) (1).chm 2016-05-08 09:36 - 2016-05-08 09:36 - 02747365 _____ C:\Users\hp\Downloads\Matt Bishop-Computer Security_ Art and Science-Addison-Wesley Professional (2002).chm 2016-05-07 13:17 - 2016-05-07 13:17 - 00046451 _____ C:\Users\hp\Desktop\admire - respect WordReference Forums.htm 2016-05-06 19:48 - 2016-05-06 19:48 - 00000000 ____D C:\Program Files\Common Files\DESIGNER 2016-05-06 18:16 - 2016-05-08 09:24 - 00000000 ____D C:\Users\hp\Desktop\New folder (3) 2016-05-05 07:45 - 2016-05-05 07:45 - 00000299 _____ C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Recycle Bin.lnk 2016-05-05 06:31 - 2016-05-08 11:25 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security 2016-05-05 06:17 - 2016-05-08 20:45 - 00000000 ____D C:\WINDOWS\system32\AutoUpdateLicense 2016-05-05 05:07 - 2015-03-04 10:26 - 00011105 ____N C:\WINDOWS\system32\AutoconfigV2.cab 2016-05-04 06:29 - 2016-05-13 01:11 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1508925376-3250446775-450008754-1002 2016-05-04 06:11 - 2016-05-04 06:11 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform 2016-05-04 06:10 - 2016-05-08 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SharePoint 2016-05-04 06:10 - 2016-05-08 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016-05-04 06:07 - 2016-05-04 06:07 - 00000000 ____D C:\Program Files\Microsoft Synchronization Services 2016-05-04 06:06 - 2016-05-04 06:06 - 00000000 ____D C:\Program Files\Microsoft Sync Framework 2016-05-04 06:06 - 2016-05-04 06:06 - 00000000 ____D C:\Program Files\Microsoft SQL Server Compact Edition 2016-05-04 06:04 - 2016-05-04 06:04 - 00000000 ____D C:\Program Files\Microsoft Analysis Services 2016-05-04 06:04 - 2016-05-04 06:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 8 2016-05-04 06:04 - 2016-05-04 06:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services 2016-05-04 06:03 - 2016-05-04 06:06 - 00000000 ____D C:\Program Files\Microsoft Office 2016-05-04 06:03 - 2016-05-04 06:03 - 00000000 ____D C:\Users\hp\AppData\Local\Microsoft Help 2016-05-03 23:00 - 2016-05-03 23:00 - 00000000 ____D C:\Users\hp\Desktop\batman knightfall 2016-05-03 17:22 - 2016-05-08 11:03 - 00000000 ____D C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Everything 2016-05-01 21:34 - 2016-05-08 10:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mirkes.de 2016-05-01 21:34 - 2016-05-01 21:34 - 00000000 ____D C:\Program Files (x86)\mirkes.de 2016-05-01 21:31 - 2016-05-08 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Easy Duplicate Finder 2016-05-01 21:31 - 2016-05-01 21:31 - 00000000 ____D C:\Users\hp\AppData\Roaming\Easy Duplicate Finder 2016-05-01 21:31 - 2016-05-01 21:31 - 00000000 ____D C:\ProgramData\Easy Duplicate Finder 2016-05-01 21:31 - 2016-05-01 21:31 - 00000000 ____D C:\Program Files (x86)\Easy Duplicate Finder 2016-05-01 21:30 - 2016-05-08 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dup Scout 2016-05-01 21:30 - 2016-05-01 21:30 - 00000000 ____D C:\Users\hp\AppData\Local\Dup Scout 2016-05-01 21:29 - 2016-05-01 21:30 - 00000000 ____D C:\Program Files (x86)\Dup Scout 2016-05-01 21:28 - 2016-05-08 10:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SoftByte Labs 2016-05-01 21:28 - 2016-05-01 21:28 - 00000000 ____D C:\Program Files (x86)\SoftByte Labs 2016-05-01 21:26 - 2016-05-01 21:26 - 00001021 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Anti-Twin.lnk 2016-05-01 21:26 - 2016-05-01 21:26 - 00001009 _____ C:\Users\Public\Desktop\Anti-Twin.lnk 2016-05-01 21:26 - 2016-05-01 21:26 - 00000000 ____D C:\Program Files (x86)\AntiTwin 2016-05-01 21:21 - 2016-05-01 22:33 - 00000000 ____D C:\Users\hp\AppData\Roaming\AllDup 2016-05-01 21:11 - 2016-05-08 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AllDup 2016-05-01 21:11 - 2016-05-01 21:11 - 00000979 _____ C:\Users\Public\Desktop\AllDup.lnk 2016-05-01 21:11 - 2016-05-01 21:11 - 00000000 ____D C:\ProgramData\AllDup 2016-05-01 21:11 - 2010-08-20 21:53 - 00086016 _____ (Michael Thummerer Software Design) C:\WINDOWS\SysWOW64\mtSplitter.ocx 2016-05-01 21:11 - 2010-06-11 10:50 - 00089888 _____ (Michael Thummerer Software Design) C:\WINDOWS\SysWOW64\mtFrame.ocx 2016-05-01 21:11 - 2010-03-25 10:33 - 00171752 _____ (Michael Thummerer Software Design) C:\WINDOWS\SysWOW64\mtRTF2.ocx 2016-05-01 21:11 - 2009-12-29 18:00 - 01000992 _____ (Bennet-Tec Information Systems, Inc) C:\WINDOWS\SysWOW64\TList8.ocx 2016-05-01 21:11 - 2009-10-29 11:34 - 02344880 _____ (Codejock Software) C:\WINDOWS\SysWOW64\Codejock.CommandBars.v13.2.1.ocx 2016-05-01 21:11 - 2009-10-13 00:02 - 00044736 _____ (Michael Thummerer Software Design) C:\WINDOWS\SysWOW64\mtSubclass.dll 2016-05-01 21:11 - 2009-10-13 00:01 - 00077504 _____ (Michael Thummerer Software Design) C:\WINDOWS\SysWOW64\mtScrollContainer.ocx 2016-05-01 21:11 - 2008-01-29 07:57 - 00450560 _____ (LogicNP Software (hxxp://www.ssware.com)) C:\WINDOWS\SysWOW64\fldrvw90.ocx 2016-05-01 21:10 - 2016-05-01 21:13 - 00000000 ____D C:\Program Files (x86)\AllDup 2016-05-01 21:10 - 2004-03-09 00:00 - 01081616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCOMCTL.OCX 2016-05-01 19:59 - 2016-05-01 19:59 - 00000000 ____D C:\Users\hp\AppData\Roaming\CyberLink 2016-05-01 19:57 - 2016-05-01 19:57 - 00000000 ____D C:\Users\hp\AppData\LocalLow\Adobe 2016-05-01 19:57 - 2016-05-01 19:57 - 00000000 ____D C:\Users\hp\AppData\Local\Adobe 2016-05-01 19:41 - 2016-05-01 19:41 - 00001102 _____ C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware Guard.lnk 2016-05-01 17:10 - 2016-05-01 21:52 - 00000295 _____ C:\Users\hp\Desktop\çç.txt 2016-05-01 17:06 - 2016-05-01 21:47 - 00075594 _____ C:\Users\hp\Desktop\Top Inventions and Discoveries by Scientists - A to Z List [First Model of electric washer].htm 2016-05-01 17:06 - 2016-05-01 21:46 - 00351998 _____ C:\Users\hp\Desktop\System Volume Information Virüsü.htm 2016-05-01 17:06 - 2016-05-01 21:46 - 00073833 _____ C:\Users\hp\Desktop\To issue a patent [word meaning question] [To be issued under a patent] [Receive].htm 2016-05-01 17:05 - 2016-05-01 21:46 - 01034074 _____ C:\Users\hp\Desktop\New Microsoft PowerPoint Presentation.pptx 2016-05-01 17:05 - 2016-05-01 21:46 - 00099139 _____ C:\Users\hp\Desktop\Raylı Sistem Mühendisliği - Railway Engineering Demir Yolu Terimleri.htm 2016-05-01 17:05 - 2016-05-01 21:46 - 00091064 _____ C:\Users\hp\Desktop\Pamuk Prenses Ve Yedi Cüceler - Bilgievi [bezgin, bilgiç, çalışkan, neşeli, obur, sinirli, şakacı].htm 2016-05-01 17:05 - 2016-05-01 21:46 - 00071357 _____ C:\Users\hp\Desktop\pertain to be WordReference Forums.htm 2016-05-01 17:05 - 2016-05-01 21:46 - 00059163 _____ C:\Users\hp\Desktop\Pub Quiz 100 - Pauls Free Quiz Questions Trivia Quiz Resources Pub Quiz Questions Trivia Quiz [First marketed under the name].htm 2016-05-01 17:05 - 2016-05-01 21:46 - 00057261 _____ C:\Users\hp\Desktop\pertaining to vs pertain to WordReference Forums.htm 2016-05-01 17:05 - 2016-05-01 21:46 - 00053295 _____ C:\Users\hp\Desktop\pertain to vs_ relate to WordReference Forums.htm 2016-05-01 17:05 - 2016-05-01 21:46 - 00048902 _____ C:\Users\hp\Desktop\Notable Inventions of the 1900s - Pauls Free Quiz Questions Trivia Quiz Resources Pub Quiz Questions Trivia Quiz [alva fisher, thor, quiz].htm 2016-05-01 17:05 - 2016-05-01 21:46 - 00048073 _____ C:\Users\hp\Desktop\person who was negative, and no longer believed [comma] [There occurd].htm 2016-05-01 17:05 - 2016-05-01 21:46 - 00020360 _____ C:\Users\hp\Desktop\Questionnaires for stakeholders and beneficiaries SGSCC (okuma).htm 2016-05-01 17:05 - 2016-05-01 21:46 - 00003972 _____ C:\Users\hp\Desktop\Run History.csv 2016-05-01 17:05 - 2016-05-01 21:46 - 00000394 _____ C:\Users\hp\Desktop\sanki her gün vize var.txt 2016-05-01 17:05 - 2016-05-01 21:45 - 00997600 _____ C:\Users\hp\Desktop\muhammed.pptx 2016-05-01 16:54 - 2016-05-01 21:27 - 23135746 _____ C:\Users\hp\Desktop\documents-export-2015-10-29.zip 2016-05-01 16:54 - 2016-05-01 21:27 - 20704669 _____ C:\Users\hp\Desktop\idioms.pdf 2016-05-01 16:54 - 2016-05-01 21:26 - 00476256 _____ C:\Users\hp\Desktop\combustion.htm 2016-05-01 16:54 - 2016-05-01 21:26 - 00048480 _____ C:\Users\hp\Desktop\Are you A Washing Machine - Quiz Quotev.htm 2016-05-01 16:54 - 2016-05-01 21:26 - 00036878 _____ C:\Users\hp\Desktop\Bound to Türkçe, çeviri, örnek cümleler, Sözlük İngilizce-Türkçe [3].htm 2016-05-01 16:54 - 2016-05-01 21:26 - 00016881 _____ C:\Users\hp\Desktop\15_6 Muddiest points on Chapter 15.htm 2016-05-01 16:36 - 2016-05-02 00:08 - 13630924 _____ C:\RannohDecryptor.1.9.0.0_01.05.2016_16.36.52_log.txt 2016-05-01 16:34 - 2016-05-07 22:28 - 00000000 ____D C:\Users\hp\Desktop\New folder 2016-05-01 15:57 - 2016-05-01 16:24 - 00000000 ____D C:\WINDOWS\System32\Tasks\Remediation 2016-05-01 15:57 - 2016-05-01 15:57 - 00000000 ____D C:\Program Files\Common Files\AV 2016-05-01 15:42 - 2016-05-01 15:42 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2016-05-01 15:42 - 2016-05-01 15:42 - 00000000 ____D C:\Program Files (x86)\Adobe 2016-05-01 15:41 - 2016-05-04 19:58 - 00000000 ____D C:\ProgramData\Adobe 2016-05-01 15:27 - 2016-05-01 15:33 - 00003040 _____ C:\RannohDecryptor.1.9.0.0_01.05.2016_15.27.30_log.txt 2016-05-01 15:22 - 2016-05-01 15:22 - 00000000 ____D C:\Users\hp\AppData\Roaming\wordwise 2016-05-01 15:22 - 2016-05-01 15:22 - 00000000 ____D C:\Users\hp\AppData\Local\wordwise 2016-05-01 15:04 - 2016-05-01 15:05 - 160636224 _____ C:\Users\hp\Downloads\Kim Milyoner Olmak İster- 565. Bölüm İzle - Atv.ts 2016-05-01 14:59 - 2016-05-13 02:08 - 00000000 ____D C:\Users\hp\AppData\Roaming\DMCache 2016-05-01 14:59 - 2016-05-10 23:06 - 00000000 ____D C:\Program Files (x86)\Internet Download Manager 2016-05-01 14:59 - 2016-05-08 11:03 - 00000000 ____D C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Download Manager 2016-05-01 14:59 - 2016-05-08 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Internet Download Manager 2016-05-01 14:59 - 2016-05-03 15:31 - 00000000 ____D C:\Users\hp\AppData\Roaming\IDM 2016-05-01 14:59 - 2016-05-01 14:59 - 00000000 ____D C:\ProgramData\IDM 2016-05-01 14:58 - 2016-05-08 10:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Longman 2016-05-01 14:58 - 2016-05-08 10:55 - 00000000 ____D C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Longman 2016-05-01 14:58 - 2016-05-01 14:58 - 00000000 ____D C:\Program Files (x86)\IDM 2016-05-01 14:57 - 2016-05-01 14:57 - 00000000 ____D C:\Program Files (x86)\Longman 2016-05-01 14:56 - 2016-05-01 14:56 - 00001493 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Newbury House Dictionary.lnk 2016-05-01 14:56 - 2016-05-01 14:56 - 00000060 _____ C:\WINDOWS\heinle.ini 2016-05-01 14:56 - 1997-12-17 18:33 - 00304128 _____ (InstallShield Software Corporation) C:\WINDOWS\IsUninst.exe 2016-05-01 14:55 - 2016-05-12 00:20 - 00000814 _____ C:\Users\Administrator\Desktop\PolyLingua.LNK 2016-05-01 14:55 - 2016-05-12 00:20 - 00000123 _____ C:\WINDOWS\DEINST.INI 2016-05-01 14:55 - 2016-05-12 00:20 - 00000000 ____D C:\WINDOWS\msagent 2016-05-01 14:55 - 2016-05-12 00:20 - 00000000 ____D C:\WINDOWS\GPPSOFT 2016-05-01 14:55 - 2016-05-12 00:20 - 00000000 ____D C:\Program Files\PolyLingua 2016-05-01 14:55 - 2016-05-01 14:55 - 00001948 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WordWeb.lnk 2016-05-01 14:55 - 2016-05-01 14:55 - 00000000 ____D C:\WINDOWS\lhsp
|
|
mech
New Helpee
Posts: 18
|
Post by mech on May 13, 2016 1:29:51 GMT -8
Part 2
2016-05-01 14:55 - 2001-04-05 21:43 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSSTDFMT.DLL 2016-05-01 14:55 - 2000-05-23 04:58 - 00647872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSCOMCT2.OCX 2016-05-01 14:55 - 2000-05-22 17:58 - 00608448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\COMCTL32.OCX 2016-05-01 14:54 - 2016-05-10 23:06 - 00000000 ____D C:\Program Files (x86)\WordWeb 2016-05-01 14:54 - 2016-05-08 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2016-05-01 14:54 - 2016-05-08 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Greenshot 2016-05-01 14:54 - 2016-05-08 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DjVuLibre 2016-05-01 14:54 - 2016-05-01 14:57 - 00000000 ____D C:\Users\hp\AppData\Roaming\WinRAR 2016-05-01 14:54 - 2016-05-01 14:54 - 00001133 _____ C:\Users\Administrator\Desktop\DjView.lnk 2016-05-01 14:54 - 2016-05-01 14:54 - 00000000 ____D C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DjVuLibre 2016-05-01 14:54 - 2016-05-01 14:54 - 00000000 ____D C:\Users\hp\AppData\Roaming\Greenshot 2016-05-01 14:54 - 2016-05-01 14:54 - 00000000 ____D C:\Program Files (x86)\Greenshot 2016-05-01 14:54 - 2016-05-01 14:54 - 00000000 ____D C:\Program Files (x86)\DjVuZone 2016-05-01 14:54 - 2010-02-17 21:34 - 01192128 _____ (WordWeb Software) C:\WINDOWS\wweb32.dll 2016-05-01 14:53 - 2016-05-08 11:03 - 00000000 ____D C:\Users\hp\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2016-05-01 14:53 - 2016-05-01 14:53 - 00000000 ____D C:\Program Files (x86)\WinRAR 2016-05-01 14:48 - 2016-05-01 14:48 - 00631752 _____ (Kaspersky Lab ZAO) C:\Users\hp\Downloads\rannohdecryptor.exe 2016-05-01 14:14 - 2016-05-01 14:15 - 00000000 ____D C:\Users\hp\Downloads\bakılacak web siteleri 2016-05-01 14:11 - 2016-05-01 14:11 - 00000000 ____D C:\Users\hp\Downloads\autocad video ve kitapları 2016-05-01 14:10 - 2016-05-01 14:10 - 00000000 ____D C:\Users\hp\Downloads\videolar 2016-05-01 14:09 - 2016-05-01 22:28 - 00000000 ____D C:\Users\hp\Downloads\mekanik kitapları, notları ve videoları (vids) 2016-05-01 14:09 - 2016-05-01 14:09 - 00000000 ____D C:\Users\hp\Downloads\sözlükler 2016-05-01 12:58 - 2016-05-01 12:58 - 00000000 ____D C:\ProgramData\Emsisoft 2016-05-01 12:39 - 2016-05-08 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Anti-Malware 2016-04-30 21:18 - 2016-05-01 21:59 - 00000000 ____D C:\Users\hp\AppData\Local\CrashDumps 2016-04-30 21:08 - 2016-04-30 21:08 - 00000000 ____D C:\Users\hp\Downloads\+mücevher 2016-04-30 21:08 - 2016-04-30 21:08 - 00000000 ____D C:\Users\hp\Downloads\+chip 2016-04-30 21:08 - 2016-04-30 21:08 - 00000000 ____D C:\Users\hp\Downloads\+Avatar 2016-04-30 21:08 - 2016-04-30 21:08 - 00000000 ____D C:\Users\hp\Downloads\+anlamadıklarım 2016-04-30 21:08 - 2015-01-12 20:48 - 16205488 _____ C:\Users\hp\Downloads\Sugarman S. C. HVAC Fundementals 2007.pdf 2016-04-30 21:08 - 2015-01-07 20:58 - 06187026 _____ C:\Users\hp\Downloads\Peter Scott Curtiss, Newton Breth HVAC Instant Answers 2002.pdf 2016-04-30 21:08 - 2015-01-07 13:08 - 81690516 _____ C:\Users\hp\Downloads\Pat-McGee-C-A-Beginners-20141212.rar 2016-04-30 21:08 - 2015-01-06 20:50 - 12822691 _____ C:\Users\hp\Downloads\Linux_All-in-One_Desk_Reference_For_Dummies_by_Emmett_Dulaney.pdf 2016-04-30 21:08 - 2014-12-31 21:34 - 35723651 _____ C:\Users\hp\Downloads\PracticalReptilJanuary2015.pdf 2016-04-30 21:08 - 2014-12-10 18:32 - 08809711 _____ C:\Users\hp\Downloads\W. J. Youden Experimentation and Measurement 1998.pdf 2016-04-30 21:08 - 2014-08-24 11:59 - 00000000 ____D C:\Users\hp\Downloads\=yedeği 4 te; yazın fazla dosyaları bulup silen programla bu klasör taranıp tekrar yedeklenecek 2016-04-30 21:08 - 2014-03-14 21:20 - 00009501 _____ C:\Users\hp\Downloads\ptcsetup.bak 2016-04-30 21:08 - 2013-11-12 03:00 - 00000317 _____ C:\Users\hp\Downloads\notlar.txt 2016-04-30 21:08 - 2011-10-31 14:02 - 00048422 _____ C:\Users\hp\Downloads\Yeni OpenDocument Çizim.odg 2016-04-30 21:08 - 2010-06-20 15:16 - 10595516 _____ C:\Users\hp\Downloads\Mehmet Katar-Dinler Tarihi.pdf 2016-04-30 21:08 - 2009-07-31 23:30 - 94567834 _____ C:\Users\hp\Downloads\Lecture - 35 Introduction to Mass Transfer - 3.avi 2016-04-30 21:08 - 2009-07-31 23:10 - 94644758 _____ C:\Users\hp\Downloads\Lecture - 33 Introduction to Mass Transfer - 1.avi 2016-04-30 21:08 - 2009-07-31 23:09 - 87903610 _____ C:\Users\hp\Downloads\Lecture - 34 Introduction to Mass Transfer - 2.avi 2016-04-30 21:08 - 2009-07-30 23:33 - 103902368 _____ C:\Users\hp\Downloads\Lecture - 1 Introduction on Heat and Mass Transfer.avi 2016-04-30 21:07 - 2016-04-30 21:07 - 00000000 ____D C:\Users\hp\Downloads\zantac 2016-04-30 21:07 - 2015-01-16 20:34 - 00000000 ____D C:\Users\hp\Downloads\Youcam 2016-04-30 21:07 - 2015-01-07 21:34 - 13340706 _____ C:\Users\hp\Downloads\[]_Better_Duct_Systems_for_Home_Heating_and_Coolin(BookFi.org).pdf 2016-04-30 21:07 - 2015-01-07 21:22 - 02663588 _____ C:\Users\hp\Downloads\[Russell_B._DeVore]_Practical_Problems_in_Mathemat(BookFi.org).pdf 2016-04-30 21:07 - 2015-01-07 20:39 - 30776404 _____ C:\Users\hp\Downloads\Jan F. Kreider Handbook of Heating, Ventilation, and Air Conditioning (Handbook Series for Mechanical Engineering) 2000.pdf 2016-04-30 21:07 - 2015-01-07 18:55 - 15050407 _____ C:\Users\hp\Downloads\1607745291DDG.epub.kanpb7o.partial 2016-04-30 21:07 - 2015-01-07 18:42 - 04102642 _____ C:\Users\hp\Downloads\Kevin Pennycook, D. Churcher, D. Bleicher A Guide to HVAC Building Services Calculations 2007.pdf 2016-04-30 21:07 - 2015-01-07 17:46 - 184852241 _____ C:\Users\hp\Downloads\Bill (Bill Whitman) Whitman, Bill Johnson, John Tomczyk, Eugene Silberstein Refrigeration and Air Conditioning Technology 2008.pdf 2016-04-30 21:07 - 2015-01-07 17:46 - 13954967 _____ C:\Users\hp\Downloads\1439862028__Water.pdf 2016-04-30 21:07 - 2015-01-07 17:45 - 04613690 _____ C:\Users\hp\Downloads\A. R. Trott, T C Welch Refrigeration and Air Conditioning 2000.pdf 2016-04-30 21:07 - 2015-01-07 17:37 - 12348437 _____ C:\Users\hp\Downloads\Hundy G.H., Trott A.R., Welch T.C. Refrigeration and Air-Conditioning 2008.pdf 2016-04-30 21:07 - 2015-01-07 13:29 - 07356856 _____ C:\Users\hp\Downloads\148420008X.pdf 2016-04-30 21:07 - 2015-01-07 13:25 - 35393501 _____ C:\Users\hp\Downloads\3319067753Scala.pdf 2016-04-30 21:07 - 2015-01-07 12:49 - 01678126 _____ C:\Users\hp\Downloads\1783982845.pdf 2016-04-30 21:07 - 2015-01-07 12:46 - 01091957 _____ C:\Users\hp\Downloads\1484207645orac.epub 2016-04-30 21:07 - 2015-01-07 12:39 - 34269237 _____ C:\Users\hp\Downloads\HTML_CSS_Programming_Guide_For_Beginners_Learn_how_to_create_Visually_Stunning_Web_Pages.rar 2016-04-30 21:07 - 2015-01-07 12:27 - 12289454 _____ C:\Users\hp\Downloads\JavaScript_for_Absolute_Beginners_by_Terry_McNavage.pdf 2016-04-30 21:07 - 2015-01-07 12:24 - 19924887 _____ C:\Users\hp\Downloads\Java_Programming_for_the_Absolute_Beginner_by_Joseph_P._Russell.pdf 2016-04-30 21:07 - 2015-01-07 12:24 - 10368590 _____ C:\Users\hp\Downloads\How_to_Hack_Hacking_Secrets_Exposed_A_Beginner-s_Guide.rar 2016-04-30 21:07 - 2015-01-06 21:01 - 02886406 _____ C:\Users\hp\Downloads\0131861506.chm 2016-04-30 21:07 - 2015-01-05 15:00 - 04076663 _____ C:\Users\hp\Downloads\.NET_Security.epub 2016-04-30 21:07 - 2015-01-05 14:56 - 07194406 _____ C:\Users\hp\Downloads\0273793276.pdf 2016-04-30 21:07 - 2015-01-05 14:53 - 04611468 _____ C:\Users\hp\Downloads\Computer_Sicuro_-_Guida_per_Principianti.rar 2016-04-30 21:07 - 2015-01-05 14:51 - 04287885 _____ C:\Users\hp\Downloads\CompTIA_Security-_Get_Certified_Get_Ahead_SY0-301_Study_Guide.pdf 2016-04-30 21:07 - 2015-01-05 14:47 - 09836423 _____ C:\Users\hp\Downloads\Hardening_Linux_by_John_Terpstra.chm 2016-04-30 21:07 - 2014-12-31 21:48 - 00516420 _____ C:\Users\hp\Downloads\[Donald_V._Coers]_John_Steinbeck_as_propagandist_(Bokos-Z1).zip 2016-04-30 21:07 - 2014-12-31 21:34 - 00616391 _____ C:\Users\hp\Downloads\[John_Steinbeck]_The_Short_Novels_of_John_Steinbec(Bokos-Z1).zip 2016-04-30 21:07 - 2014-12-31 21:26 - 03823885 _____ C:\Users\hp\Downloads\Τζων Στάινμπεκ (John Steinbeck) Το κόκκινο πουλάÏι 1991.pdf 2016-04-30 21:07 - 2014-12-30 23:04 - 00881077 _____ C:\Users\hp\Downloads\Barbara A. Heavilin A John Steinbeck Reader_ Essays in Honor of Stephen K. George 2009.pdf 2016-04-30 21:07 - 2014-12-30 22:42 - 00025336 _____ C:\Users\hp\Downloads\Comparison and Analysis of Plato and Aristotle on the Virtue(s) in the Eudaimonism Ethical System.htm 2016-04-30 21:07 - 2014-12-30 18:23 - 41592297 _____ C:\Users\hp\Downloads\1451188307Histolog.pdf 2016-04-30 21:07 - 2014-12-30 18:00 - 00727008 _____ C:\Users\hp\Downloads\0874219280.pdf 2016-04-30 21:07 - 2014-12-29 12:35 - 00362662 _____ C:\Users\hp\Downloads\1419257947_Final_Programı_2014-2015_Güz_ver2.0.pdf 2016-04-30 21:07 - 2014-12-22 15:04 - 00041863 _____ C:\Users\hp\Downloads\Kopyası sonuçlar.mht 2016-04-30 21:07 - 2014-12-11 15:08 - 28560176 _____ C:\Users\hp\Downloads\EE2014.part1.rar 2016-04-30 21:07 - 2014-04-28 23:39 - 00000000 ____D C:\Users\hp\Downloads\WWT Collections 2016-04-30 21:07 - 2014-03-27 07:55 - 00033982 _____ C:\Users\hp\Downloads\greenline.dwg 2016-04-30 21:07 - 2014-03-26 20:30 - 00034822 _____ C:\Users\hp\Downloads\deneme.dwg 2016-04-30 21:07 - 2014-03-14 23:37 - 00202240 _____ C:\Users\hp\Downloads\Copy of Cam Machine Virtual Lab Data.xls 2016-04-30 21:07 - 2013-12-31 21:06 - 00000949 _____ C:\Users\hp\Downloads\hosts.txt 2016-04-30 21:07 - 2012-05-11 17:54 - 00000243 _____ C:\Users\hp\Downloads\key.txt 2016-04-30 21:07 - 2010-12-04 23:44 - 00002456 _____ C:\Users\hp\Downloads\{46579580-41EC-4EDE-823D-B4093A1BE8D0} 2016-04-30 21:07 - 2010-02-17 00:20 - 00000243 _____ C:\Users\hp\Downloads\hukuk.txt 2016-04-30 21:07 - 2009-08-02 19:24 - 105248176 _____ C:\Users\hp\Downloads\Lec 2 _ MIT 18.03 Differential Equations, Spring 2006.avi 2016-04-30 21:05 - 2016-05-13 11:46 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware 2016-04-30 21:03 - 2016-04-30 21:05 - 00000000 ____D C:\Users\hp\Downloads\vid lec 2016-04-30 21:03 - 2016-04-30 21:03 - 00000000 ____D C:\Users\hp\Downloads\verify that 2016-04-30 21:03 - 2016-04-30 21:03 - 00000000 ____D C:\Users\hp\Downloads\üniversite ders içeriği ve programları 2016-04-30 21:02 - 2016-04-30 21:02 - 00000000 ____D C:\Users\hp\Downloads\türkçe 2016-04-30 21:02 - 2016-04-30 21:02 - 00000000 ____D C:\Users\hp\Downloads\tmt dosyaları 2016-04-30 21:02 - 2016-04-30 21:02 - 00000000 ____D C:\Users\hp\Downloads\tıp kitapları 2016-04-30 21:02 - 2016-04-30 21:02 - 00000000 ____D C:\Users\hp\Downloads\TERMİNOLOJİ 2016-04-30 21:02 - 2016-04-30 21:02 - 00000000 ____D C:\Users\hp\Downloads\tarih kitapları 2016-04-30 21:02 - 2016-04-30 21:02 - 00000000 ____D C:\Users\hp\Downloads\şiirler 2016-04-30 21:02 - 2014-11-13 19:33 - 00000000 ____D C:\Users\hp\Downloads\Total Overdose 2016-04-30 21:01 - 2016-05-01 22:29 - 00000000 ____D C:\Users\hp\Downloads\şarkı 2016-04-30 21:01 - 2016-04-30 21:01 - 00000000 ____D C:\Users\hp\Downloads\SparkNotes Nicomachean Ethics Quiz_files 2016-04-30 21:01 - 2016-04-30 21:01 - 00000000 ____D C:\Users\hp\Downloads\sözlük 2016-04-30 21:01 - 2016-04-30 21:01 - 00000000 ____D C:\Users\hp\Downloads\Sounds 2016-04-30 20:57 - 2016-04-30 21:01 - 00000000 ____D C:\Users\hp\Downloads\sosyal bilimler 2016-04-30 20:57 - 2016-04-30 20:57 - 00000000 ____D C:\Users\hp\Downloads\SolidWorks Downloads 2016-04-30 20:53 - 2016-04-30 20:53 - 00000000 ____D C:\Users\hp\Downloads\Seagate 2016-04-30 20:53 - 2016-04-30 20:53 - 00000000 ____D C:\Users\hp\Downloads\sayısal 2016-04-30 20:53 - 2016-04-30 20:53 - 00000000 ____D C:\Users\hp\Downloads\satranç kitapları 2016-04-30 20:53 - 2016-04-30 20:53 - 00000000 ____D C:\Users\hp\Downloads\samples 2016-04-30 20:53 - 2016-04-30 20:53 - 00000000 ____D C:\Users\hp\Downloads\rothschild 2016-04-30 20:53 - 2016-04-30 20:53 - 00000000 ____D C:\Users\hp\Downloads\refrigeration 2016-04-30 20:52 - 2016-04-30 20:53 - 00000000 ____D C:\Users\hp\Downloads\quiz 2016-04-30 20:52 - 2016-04-30 20:52 - 00000000 ____D C:\Users\hp\Downloads\psp 2016-04-30 20:50 - 2016-04-30 20:50 - 00000000 ____D C:\Users\hp\Downloads\politik 2016-04-30 20:50 - 2016-04-30 20:50 - 00000000 ____D C:\Users\hp\Downloads\pendulum 2016-04-30 20:50 - 2016-04-30 20:50 - 00000000 ____D C:\Users\hp\Downloads\örümcek adam 2016-04-30 20:50 - 2012-04-10 10:10 - 00000000 ____D C:\Users\hp\Downloads\phonetic alphabet 2016-04-30 20:47 - 2016-05-01 22:07 - 00000000 ____D C:\Users\hp\Downloads\oyun videoları 2016-04-30 20:47 - 2016-05-01 14:23 - 00000000 ____D C:\Users\hp\Downloads\notlar 2016-04-30 20:47 - 2016-04-30 20:47 - 00000000 ____D C:\Users\hp\Downloads\Outlook Files 2016-04-30 20:47 - 2016-04-30 20:47 - 00000000 ____D C:\Users\hp\Downloads\otomobil ve dergileri 2016-04-30 20:47 - 2016-04-30 20:47 - 00000000 ____D C:\Users\hp\Downloads\otomobil ders notları 2016-04-30 20:46 - 2016-04-30 20:47 - 00000000 ____D C:\Users\hp\Downloads\n95 2016-04-30 20:46 - 2016-04-30 20:46 - 00000000 ____D C:\Users\hp\Downloads\My RoboForm Data 2016-04-30 20:46 - 2016-04-30 20:46 - 00000000 ____D C:\Users\hp\Downloads\My Digital Editions 2016-04-30 20:43 - 2016-04-30 20:46 - 00000000 ____D C:\Users\hp\Downloads\mühendislik 2016-04-30 20:42 - 2016-04-30 20:43 - 00000000 ____D C:\Users\hp\Downloads\ms office 2016-04-30 20:42 - 2016-04-30 20:42 - 00000000 ____D C:\Users\hp\Downloads\motorlar ders notları [fazlalıklar için düzenlenecek] 2016-04-30 20:42 - 2014-02-03 16:39 - 00000000 ____D C:\Users\hp\Downloads\Mobogenie 2016-04-30 20:39 - 2016-04-30 20:41 - 00000000 ____D C:\Users\hp\Downloads\mit dif 2016-04-30 20:37 - 2016-05-01 14:09 - 00000000 ____D C:\Users\hp\Downloads\matematik kitapları 2016-04-30 20:37 - 2016-04-30 20:39 - 00000000 ____D C:\Users\hp\Downloads\mit thermo 2016-04-30 20:37 - 2016-04-30 20:37 - 00000000 ____D C:\Users\hp\Downloads\microsoft forums 2016-04-30 20:37 - 2016-04-30 20:37 - 00000000 ____D C:\Users\hp\Downloads\Mercedes CLC Dream Test Drive 2016-04-30 20:37 - 2016-04-30 20:37 - 00000000 ____D C:\Users\hp\Downloads\MATLAB videoları 2016-04-30 20:37 - 2016-04-30 20:37 - 00000000 ____D C:\Users\hp\Downloads\malware 2016-04-30 20:37 - 2016-04-30 20:37 - 00000000 ____D C:\Users\hp\Downloads\LDW 2016-04-30 20:37 - 2016-04-30 20:37 - 00000000 ____D C:\Users\hp\Downloads\kur 2016-04-30 20:37 - 2016-04-30 20:37 - 00000000 ____D C:\Users\hp\Downloads\klima, hvac; vids, pdf 2016-04-30 20:37 - 2016-04-30 20:37 - 00000000 ____D C:\Users\hp\Downloads\kişisel gelişim 2016-04-30 20:37 - 2016-04-30 20:37 - 00000000 ____D C:\Users\hp\Downloads\kimya kitapları 2016-04-30 20:37 - 2016-04-30 20:37 - 00000000 ____D C:\Users\hp\Downloads\kimya 2016-04-30 20:37 - 2011-04-20 18:34 - 00000000 ____D C:\Users\hp\Downloads\milli bakiye sistemi 2016-04-30 20:35 - 2016-05-01 22:06 - 00000000 ____D C:\Users\hp\Downloads\kim milyoner olmak ister 2016-04-30 20:35 - 2016-04-30 20:35 - 00000000 ____D C:\Users\hp\Downloads\ısı transferi videoları 2016-04-30 20:35 - 2016-04-30 20:35 - 00000000 ____D C:\Users\hp\Downloads\Inventor Server SDK ACAD 2013 2016-04-30 20:35 - 2016-04-30 20:35 - 00000000 ____D C:\Users\hp\Downloads\inventor 2016-04-30 20:35 - 2016-04-30 20:35 - 00000000 ____D C:\Users\hp\Downloads\ilk dersimiz türkçe 2016-04-30 20:35 - 2016-04-30 20:35 - 00000000 ____D C:\Users\hp\Downloads\how it works 2016-04-30 20:35 - 2016-04-30 20:35 - 00000000 ____D C:\Users\hp\Downloads\history revealed 2016-04-30 20:35 - 2011-10-08 01:24 - 00000000 ____D C:\Users\hp\Downloads\justin mccarthy 2016-04-30 20:35 - 2011-03-25 11:39 - 00000000 ____D C:\Users\hp\Downloads\kavaklıdere şarabı 2016-04-30 20:34 - 2016-05-01 22:31 - 00000000 ____D C:\Users\hp\Downloads\heat transfer 2016-04-30 20:34 - 2016-04-30 23:00 - 00000000 ____D C:\Users\hp\Downloads\görseller 2016-04-30 20:34 - 2016-04-30 20:34 - 00000000 ____D C:\Users\hp\Downloads\geometry kitapları 2016-04-30 20:34 - 2016-04-30 20:34 - 00000000 ____D C:\Users\hp\Downloads\gemicilik tabirleri 2016-04-30 20:34 - 2016-04-30 20:34 - 00000000 ____D C:\Users\hp\Downloads\gazeteler ve gazeteciler 2016-04-30 20:34 - 2016-04-30 20:34 - 00000000 ____D C:\Users\hp\Downloads\gazeteler 2016-04-30 20:34 - 2016-04-30 20:34 - 00000000 ____D C:\Users\hp\Downloads\free planar body 2016-04-30 20:34 - 2011-03-25 11:40 - 00000000 ____D C:\Users\hp\Downloads\gemilerde talim var 2016-04-30 20:27 - 2016-04-30 20:39 - 235485016 _____ (Emsisoft Ltd. ) C:\Users\hp\Downloads\EmsisoftAntiMalwareSetup.exe 2016-04-30 20:16 - 2016-05-08 20:51 - 00000000 ____D C:\Users\hp\Downloads\fizik kitapları 2016-04-30 20:16 - 2016-04-30 20:34 - 00000000 ____D C:\Users\hp\Downloads\fotolar (hepsi tek bir kaynağa taşınmalı) 2016-04-30 20:15 - 2016-04-30 20:16 - 00000000 ____D C:\Users\hp\Downloads\finans 2016-04-30 20:15 - 2016-04-30 20:15 - 00000000 ____D C:\Users\hp\Downloads\fethullah 2016-04-30 20:15 - 2016-04-30 20:15 - 00000000 ____D C:\Users\hp\Downloads\fenomenoloji 2016-04-30 20:14 - 2016-04-30 20:15 - 00000000 ____D C:\Users\hp\Downloads\felsefe 2016-04-30 20:14 - 2016-04-30 20:14 - 00000000 ____D C:\Users\hp\Downloads\ENSC 2016-04-30 20:14 - 2016-04-30 20:14 - 00000000 ____D C:\Users\hp\Downloads\enerji 2016-04-30 20:13 - 2016-04-30 20:13 - 00000000 ____D C:\Users\hp\Downloads\elektronik 2016-04-30 20:13 - 2016-04-30 20:13 - 00000000 ____D C:\Users\hp\Downloads\elektrik-genel fizik 2016-04-30 20:13 - 2016-04-30 20:13 - 00000000 ____D C:\Users\hp\Downloads\elektrik kitapları 2016-04-30 20:13 - 2016-04-30 20:13 - 00000000 ____D C:\Users\hp\Downloads\ekitap 2016-04-30 20:12 - 2016-04-30 20:13 - 00000000 ____D C:\Users\hp\Downloads\divan edebiyatı 2016-04-30 20:12 - 2016-04-30 20:12 - 00000000 ____D C:\Users\hp\Downloads\din 2016-04-30 20:02 - 2016-05-01 14:05 - 00000000 ____D C:\Users\hp\Desktop\akışkanlar mekaniği [Taşınacak] 2016-04-30 20:02 - 2016-05-01 14:03 - 00000000 ____D C:\Users\hp\Desktop\mec 2016-04-30 20:02 - 2016-04-30 20:33 - 00000000 ____D C:\Users\hp\Desktop\ısı 2016-04-30 20:01 - 2016-04-30 20:29 - 00000000 ____D C:\Users\hp\Desktop\mat 2016-04-30 19:51 - 2016-04-30 19:59 - 00000000 ____D C:\Users\hp\Downloads\çizgi roman 2016-04-30 19:51 - 2016-04-30 19:51 - 00000000 ____D C:\Users\hp\Downloads\CyberLink [inclendi] 2016-04-30 19:51 - 2016-04-30 19:51 - 00000000 ____D C:\Users\hp\Downloads\Comparison and Analysis of Plato and Aristotle on the Virtue(s) in the Eudaimonism Ethical System_files 2016-04-30 19:43 - 2016-04-30 19:43 - 00000000 ____D C:\Users\hp\Downloads\cilt [fazlalıklar için düzenlenecek] 2016-04-30 19:42 - 2016-04-30 19:43 - 00000000 ____D C:\Users\hp\Downloads\bilgisayar kitapları [fazlalıklar için düzenlenecek] 2016-04-30 17:53 - 2016-04-30 17:55 - 00000000 ____D C:\WINDOWS\system32\MRT 2016-04-30 17:53 - 2016-04-30 17:53 - 135176864 _____ (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe 2016-04-30 16:08 - 2016-04-02 21:50 - 00046784 ____N (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe 2016-04-30 13:52 - 2013-05-04 07:51 - 00014848 ____N (Microsoft) C:\WINDOWS\system32\rars.rs 2016-04-30 13:52 - 2013-05-04 07:10 - 00014848 _____ (Microsoft) C:\WINDOWS\SysWOW64\rars.rs 2016-04-30 13:31 - 2015-07-23 01:09 - 00984448 ____N (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00901264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00066400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00063840 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-private-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00022368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00020832 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-math-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00019808 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00019808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00017760 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-string-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00017760 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-stdio-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00017760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00016224 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-runtime-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00016224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00015712 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-convert-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00015712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00014176 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-time-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00014176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00013664 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00013664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00012640 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-process-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00012640 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-heap-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00012640 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-conio-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00012640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00012128 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-utility-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00012128 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-locale-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00012128 ____N (Microsoft Corporation) C:\WINDOWS\system32\api-ms-win-crt-environment-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2016-04-30 13:31 - 2015-07-23 01:09 - 00012128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2016-04-30 12:06 - 2016-04-30 12:06 - 00559133 _____ C:\Users\hp\Downloads\Everything-1.3.4.686.x64.zip 2016-04-29 19:24 - 2016-04-29 19:24 - 00000000 ____D C:\Users\hp\AppData\Roaming\Macromedia 2016-04-29 19:22 - 2016-04-29 19:22 - 00000000 ____D C:\Users\hp\AppData\Roaming\hpqlog 2016-04-29 19:17 - 2016-04-29 19:17 - 00000000 _____ C:\WINDOWS\RTKRunSetup.ini 2016-04-29 19:08 - 2016-04-29 19:08 - 00003082 _____ C:\WINDOWS\System32\Tasks\{C9B575A6-54BD-42EE-9ECF-11376AFCACA3} 2016-04-29 19:07 - 2013-05-28 14:41 - 02715208 _____ (Realtek Semiconductor Corporation ) C:\WINDOWS\system32\Drivers\rtwlane.sys 2016-04-29 19:07 - 2012-02-14 19:37 - 00594432 _____ (Realtek Semiconductor Corp. ) C:\WINDOWS\system32\Rtlihvs.dll 2016-04-29 19:07 - 2010-12-01 09:31 - 00451072 _____ C:\WINDOWS\SysWOW64\ISSRemoveSP.exe 2016-04-28 22:50 - 2016-04-30 05:25 - 00000000 ___HD C:\$SysReset 2016-04-28 22:28 - 2016-05-05 10:42 - 00000000 ____D C:\Users\hp\Desktop\çalışma günlükleri 2016-04-28 22:16 - 2016-04-28 22:16 - 00000000 ____D C:\Users\hp\AppData\Local\HP Quick Start 2016-04-28 22:06 - 2016-05-01 22:26 - 00000000 ____D C:\Users\hp\Desktop\+all about history 2016-04-28 12:46 - 2016-04-28 12:54 - 00000000 ____D C:\Users\hp\AppData\Roaming\Hewlett-Packard 2016-04-28 12:38 - 2016-05-13 02:08 - 00000000 ____D C:\Users\hp\AppData\Roaming\Everything 2016-04-28 12:38 - 2016-05-03 17:22 - 00000000 ____D C:\Program Files\Everything 2016-04-28 12:38 - 2016-05-01 18:38 - 00000000 ____D C:\Users\hp\AppData\Local\CyberLink 2016-04-28 12:38 - 2016-04-29 19:19 - 00000000 ____D C:\Users\hp\AppData\Local\Hewlett-Packard 2016-04-28 12:38 - 2016-04-28 12:38 - 00000000 ____D C:\Users\hp\AppData\Local\AMD 2016-04-28 12:37 - 2016-04-28 12:37 - 00000000 ____D C:\Users\hp\AppData\Roaming\ATI 2016-04-28 12:37 - 2016-04-28 12:37 - 00000000 ____D C:\Users\hp\AppData\Local\ATI 2016-04-28 12:35 - 2016-04-28 12:35 - 00019060 _____ C:\Users\hp\Desktop\Removed Applications.html 2016-04-28 12:35 - 2016-04-28 12:35 - 00000000 ____D C:\WINDOWS\System32\Tasks\WPD 2016-04-28 12:33 - 2016-04-28 12:33 - 00000000 ____D C:\Users\hp\AppData\Roaming\Synaptics 2016-04-28 12:32 - 2016-05-01 19:57 - 00000000 ____D C:\Users\hp\AppData\Roaming\Adobe 2016-04-28 12:30 - 2016-04-28 12:30 - 00000000 ____D C:\Users\hp\AppData\Local\Power2Go8 2016-04-28 12:27 - 2016-05-07 12:22 - 00000000 ____D C:\Users\hp\AppData\Local\VirtualStore 2016-04-28 12:25 - 2016-04-28 12:25 - 00004691 _____ C:\Users\Administrator\AppData\Local\Application.xml 2016-04-28 12:24 - 2016-04-28 12:25 - 00000000 ___HD C:\Users\hp\Documents\hp.system.package.metadata 2016-04-28 12:24 - 2013-07-22 11:46 - 00000000 ___HD C:\Users\hp\Documents\hp.applications.package.appdata 2016-04-28 12:20 - 2016-04-28 12:20 - 00002300 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1508925376-3250446775-450008754-500 2016-04-24 16:12 - 2016-04-24 16:27 - 11610161 _____ C:\Users\hp\Downloads\[James_Stewart]_Calculus_Concepts_and_Contexts(BookZZ.org).djvu 2016-04-24 10:22 - 2016-04-24 10:22 - 00000000 ____D C:\Users\hp\Downloads\Norman Bates 2016-04-21 18:44 - 2016-04-21 18:44 - 193180716 _____ C:\Users\hp\Downloads\Kim Milyoner Olmak İster- 559. Bölüm İzle - Atv.ts [15. dakikadan] 2016-04-21 13:21 - 2016-04-21 13:46 - 177042044 _____ C:\Users\hp\Downloads\Kim Milyoner Olmak İster- 563. Bölüm İzle - Atv.ts 2016-04-21 13:20 - 2016-04-21 13:45 - 184024176 _____ C:\Users\hp\Downloads\Kim Milyoner Olmak İster- 561. Bölüm İzle - Atv.ts 2016-04-21 13:20 - 2016-04-21 13:45 - 170168200 _____ C:\Users\hp\Downloads\Kim Milyoner Olmak İster- 562. Bölüm İzle - Atv.ts 2016-04-15 11:16 - 2016-04-15 11:20 - 169076484 _____ C:\Users\hp\Downloads\Kim Milyoner Olmak İster- 560. Bölüm İzle - Atv.ts 2016-04-15 11:15 - 2016-04-15 11:20 - 179904908 _____ C:\Users\hp\Downloads\Kim Milyoner Olmak İster- 558. Bölüm İzle - Atv.ts 2016-04-15 11:14 - 2016-04-15 11:19 - 193299344 _____ C:\Users\hp\Downloads\Kim Milyoner Olmak İster- 557. Bölüm İzle - Atv.ts 2016-04-15 01:58 - 2016-04-15 01:58 - 01005174 _____ C:\Users\hp\Desktop\head loss and gradual expansion.bmp
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
|
|
mech
New Helpee
Posts: 18
|
Post by mech on May 13, 2016 1:37:42 GMT -8
Part 3 [Last one]
2016-05-01 21:47 - 2015-12-31 11:58 - 00000000 ____D C:\Users\hp\Desktop\wordreference 2016-05-01 21:46 - 2015-02-17 23:50 - 00000000 ____D C:\Users\hp\Desktop\sistem dinamiği(dinamik sistemler) 2016-05-01 21:37 - 2012-11-29 18:15 - 00000000 ____D C:\Users\hp\Desktop\masa 2016-05-01 21:28 - 2013-07-22 12:03 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2016-05-01 21:27 - 2016-04-07 20:06 - 00000000 ____D C:\Users\hp\Desktop\kodlar 2016-05-01 21:27 - 2015-12-29 06:29 - 00000000 ____D C:\Users\hp\Desktop\idm 2016-05-01 19:59 - 2015-10-30 01:35 - 00000000 ____D C:\Users\hp\Documents\CyberLink 2016-05-01 18:38 - 2013-08-08 14:41 - 00000000 ____D C:\ProgramData\CyberLink 2016-04-30 21:01 - 2014-03-09 02:02 - 00000000 ____D C:\Users\hp\Downloads\steinbeck 2016-04-30 20:11 - 2013-05-04 23:12 - 00000000 ____D C:\Users\hp\Downloads\dergi 2016-04-30 09:53 - 2015-03-05 14:53 - 00000000 ____D C:\Users\hp\Downloads\Compressed 2016-04-30 09:53 - 2013-05-04 22:59 - 00000000 ____D C:\Users\hp\Downloads\mühendislik kitapları 2016-04-30 01:33 - 2013-07-27 18:25 - 00000000 ____D C:\Users\hp\Downloads\programlar 2016-04-29 19:08 - 2013-08-08 14:21 - 00000000 ____D C:\Program Files (x86)\Realtek 2016-04-29 19:00 - 2012-08-04 03:02 - 00000000 ____D C:\SWSetup 2016-04-28 23:07 - 2015-11-29 17:40 - 00000000 ____D C:\Users\hp\Desktop\greenhouse 2016-04-28 12:32 - 2013-07-22 12:00 - 00000000 ___RD C:\Program Files (x86)\Online Services 2016-04-28 12:31 - 2012-08-04 03:02 - 00000000 ___HD C:\SYSTEM.SAV 2016-04-27 23:23 - 2016-01-27 23:09 - 61309485 _____ C:\Users\hp\Desktop\studiesinenglish00bracrich_abbyy.xml.crypt 2016-04-27 22:20 - 2015-11-22 11:02 - 00096637 _____ C:\Users\hp\Desktop\A mechanical engineering student hating mechanical design.htm. (yeniden indiricek) 2016-04-19 10:05 - 2015-11-04 12:28 - 00000000 ____D C:\Users\hp\Documents\MATLAB
==================== Bamital & volsnap =================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed C:\WINDOWS\system32\wininit.exe => File is digitally signed C:\WINDOWS\explorer.exe => File is digitally signed C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed C:\WINDOWS\system32\svchost.exe => File is digitally signed C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed C:\WINDOWS\system32\services.exe => File is digitally signed C:\WINDOWS\system32\User32.dll => File is digitally signed C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed C:\WINDOWS\system32\userinit.exe => File is digitally signed C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed C:\WINDOWS\system32\rpcss.dll => File is digitally signed C:\WINDOWS\system32\dnsapi.dll => File is digitally signed C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2016-05-08 10:40
==================== End of FRST.txt ============================
|
|
dbrisen
Malware Removalists
Posts: 3,688
|
Post by dbrisen on May 13, 2016 19:54:11 GMT -8
Please post the Addition.txt log file also.
|
|