Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

windows 8.1 possible virus removal [Solved]


  • This topic is locked This topic is locked

#1
ihocan

ihocan

    Member

  • Member
  • PipPip
  • 17 posts

Hi,

İ have a issues on my laptop, one or two week ago my computer began run slow, froze and slowed internet speed, i think its maybe malware is injected on my pc, i scanned my laptop with Emsisoft Internet Security but it didn't found any malwere or viruses and i already running Total 360 security on my pc, its getting very bored please help,(sorry for my english),OTL log file
 

OTL logfile created on: 1.2.2015 23:08:36 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\ihsan\Desktop
64bit- Professional  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17498)
Locale: 0000041f | Country: Türkiye | Language: TRK | Date Format: d.M.yyyy
 
7,92 Gb Total Physical Memory | 3,70 Gb Available Physical Memory | 46,76% Memory free
9,56 Gb Paging File | 3,13 Gb Available in Paging File | 32,74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 488,61 Gb Total Space | 250,90 Gb Free Space | 51,35% Space Free | Partition Type: NTFS
Drive D: | 442,38 Gb Total Space | 132,43 Gb Free Space | 29,94% Space Free | Partition Type: NTFS
 
Computer Name: IHOCAN | User Name: ihsan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
[color=#E56717]========== Processes (SafeList) ==========[/color]
 
PRC - [2015.02.01 22:55:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\ihsan\Desktop\OTL.exe
PRC - [2015.02.01 20:27:09 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Users\ihsan\Downloads\HijackThis.exe
PRC - [2014.12.31 14:48:14 | 004,920,104 | ---- | M] (Emsisoft GmbH) -- C:\Program Files (x86)\Emsisoft Internet Security\a2service.exe
PRC - [2014.12.15 13:29:58 | 005,426,448 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
PRC - [2014.12.13 02:13:07 | 002,531,472 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
PRC - [2014.12.13 02:13:04 | 001,701,520 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
PRC - [2014.12.12 11:10:32 | 001,818,736 | ---- | M] () -- C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
PRC - [2014.12.12 11:10:31 | 000,707,184 | ---- | M] () -- C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
PRC - [2014.11.16 16:28:40 | 000,076,888 | ---- | M] () -- C:\Windows\SysWOW64\PnkBstrA.exe
PRC - [2014.10.10 15:03:38 | 001,771,560 | ---- | M] (pdfforge GmbH) -- C:\Program Files (x86)\PDF Architect 2\ws.exe
PRC - [2014.09.03 10:20:58 | 003,878,480 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IDMan.exe
PRC - [2014.08.04 08:49:10 | 000,320,360 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
PRC - [2014.08.04 08:49:10 | 000,016,232 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
PRC - [2014.02.22 10:00:27 | 000,514,560 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\WWAHost.exe
PRC - [2013.11.07 13:17:30 | 000,269,848 | ---- | M] (Tonec Inc.) -- C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
PRC - [2013.09.26 12:58:58 | 000,160,768 | ---- | M] (Micro-Star International Co., Ltd.) -- C:\Program Files (x86)\SCM\MSIService.exe
PRC - [2013.08.08 12:26:26 | 000,390,616 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
PRC - [2013.08.08 12:25:38 | 000,169,432 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
PRC - [2012.11.29 10:25:54 | 000,711,680 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
 
 
[color=#E56717]========== Modules (No Company Name) ==========[/color]
 
MOD - [2015.01.31 05:29:32 | 000,392,704 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\e7ccb24aea5ef58ec5b0ee64f948c2ce\System.Xml.Linq.ni.dll
MOD - [2015.01.31 05:29:31 | 007,495,168 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\31f4567903d18352754d24a32ba9f73d\System.Xml.ni.dll
MOD - [2015.01.31 05:29:28 | 001,879,040 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\ddaa553c22018fc914efa9bea4277866\System.Xaml.ni.dll
MOD - [2015.01.31 05:29:26 | 012,911,104 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\20e6b7ce07d693b037b36272aa8f54c2\System.Windows.Forms.ni.dll
MOD - [2015.01.31 05:29:03 | 019,319,808 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\854f75d056bab8f6bb3c313575bc49d7\System.ServiceModel.ni.dll
MOD - [2015.01.31 05:28:48 | 002,772,480 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runteb92aa12#\c28406f465758c1e3d923b69f721012c\System.Runtime.Serialization.ni.dll
MOD - [2015.01.31 05:28:44 | 000,523,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Net.Http\9d15b9fba50c620a8f1e9c067bd8456d\System.Net.Http.ni.dll
MOD - [2015.01.31 05:28:42 | 001,611,776 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\a336ca17f2bf3318ccbed93fa72452ee\System.Drawing.ni.dll
MOD - [2015.01.31 05:28:39 | 007,273,472 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Data\5c8b74377e8b56f8a49b1837cc309b3f\System.Data.ni.dll
MOD - [2015.01.31 05:28:34 | 000,969,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\d3d6fc4a5f1270ab50540677b16ffc22\System.Configuration.ni.dll
MOD - [2015.01.31 05:28:31 | 000,463,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatioaec034ca#\f066b6342cb04327d6110e76309ee496\PresentationFramework.Aero2.ni.dll
MOD - [2015.01.31 05:28:30 | 018,691,072 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Presentatio5ae0f00f#\68136c3c80d09e62cbe65f6078ebd52a\PresentationFramework.ni.dll
MOD - [2015.01.31 05:28:19 | 011,037,696 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\9ccdae67676f8e7271913c8f02a0c14a\PresentationCore.ni.dll
MOD - [2015.01.31 05:28:12 | 003,911,680 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\aeb260729c8b6d947daff79435949cdb\WindowsBase.ni.dll
MOD - [2015.01.15 12:26:04 | 007,041,536 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\f1beb7a13590d2dbc343e1ce1760a730\System.Core.ni.dll
MOD - [2015.01.15 12:23:53 | 009,957,888 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System\d2138757ab295b0915156dda2b2d2fd0\System.ni.dll
MOD - [2015.01.15 12:23:41 | 017,717,248 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\66a936efa8a1f3afbf370dfe101b2394\mscorlib.ni.dll
MOD - [2014.12.29 05:19:41 | 000,681,472 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Net\9fa4a766a4519d8d74ef61393e73e18a\System.Net.ni.dll
MOD - [2014.12.25 04:17:29 | 000,009,216 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Thre7bb2aad0#\44943a646bf7e80a1ee5777bf554a9e9\System.Threading.Tasks.ni.dll
MOD - [2014.12.25 04:17:28 | 000,018,944 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime\54359fe508cf88fd6174d9f8f6b0cb5e\System.Runtime.ni.dll
MOD - [2014.12.25 04:12:46 | 000,423,936 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Serv30e99c02#\dada1b8009198578f403994cea13cea7\System.ServiceModel.Channels.ni.dll
MOD - [2014.12.25 04:12:43 | 001,073,152 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servf73e6522#\a8ddab9d05648816ed861074ec68e426\System.ServiceModel.Web.ni.dll
MOD - [2014.12.25 04:12:36 | 002,054,144 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Newtonsoft.Json\4fc6e46c86c8a22924a81c35fbeb15c5\Newtonsoft.Json.ni.dll
MOD - [2014.12.25 04:12:35 | 000,601,600 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Net.95c62f1e#\09d05a474743de7247b8109f5569d5e1\System.Net.Http.Formatting.ni.dll
MOD - [2014.12.25 04:12:15 | 000,514,560 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\Microsoft.Vf87aed9a#\097c82e934ddce96d95bd275f06b613a\Microsoft.VisualStudio.Telemetry.ni.dll
MOD - [2014.12.25 04:06:03 | 002,931,200 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\9ccdbd5e2dc50f2d1ff68c3d59bdd5ce\System.IdentityModel.ni.dll
MOD - [2014.12.23 18:42:50 | 000,264,192 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Comp46f2b404#\87ae4c988afbd1942eb543717835e607\System.ComponentModel.DataAnnotations.ni.dll
MOD - [2014.12.23 18:42:50 | 000,147,456 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Numerics\d628943f3a2ebc0c1dfa1eb38506ea31\System.Numerics.ni.dll
MOD - [2014.12.23 18:42:48 | 000,783,360 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Servd1dec626#\cefed77c0607f4a38e452e9c75014103\System.ServiceModel.Internals.ni.dll
MOD - [2014.12.23 18:42:47 | 000,115,712 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\659850c9b09960a079f6ba62daa85e69\SMDiagnostics.ni.dll
MOD - [2014.12.23 18:42:44 | 013,535,232 | ---- | M] () -- C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Web\bfdebdea85a516389ae814bff549c921\System.Web.ni.dll
MOD - [2014.12.12 11:10:32 | 001,818,736 | ---- | M] () -- C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
MOD - [2014.11.04 02:04:30 | 000,010,952 | ---- | M] () -- C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
 
 
[color=#E56717]========== Services (SafeList) ==========[/color]
 
SRV:[b]64bit:[/b] - [2014.12.23 16:33:13 | 013,401,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\vmms.exe -- (vmms)
SRV:[b]64bit:[/b] - [2014.12.23 16:15:19 | 000,005,632 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe -- (c2wts)
SRV:[b]64bit:[/b] - [2014.12.13 02:13:04 | 001,148,560 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe -- (GfExperienceService)
SRV:[b]64bit:[/b] - [2014.12.13 02:13:03 | 019,823,248 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe -- (NvStreamSvc)
SRV:[b]64bit:[/b] - [2014.12.06 03:35:00 | 000,229,888 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\AudioEndpointBuilder.dll -- (AudioEndpointBuilder)
SRV:[b]64bit:[/b] - [2014.10.31 06:51:25 | 000,114,688 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:[b]64bit:[/b] - [2014.09.22 05:05:56 | 000,368,632 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\NisSrv.exe -- (WdNisSvc)
SRV:[b]64bit:[/b] - [2014.09.22 05:05:56 | 000,023,792 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MsMpEng.exe -- (WinDefend)
SRV:[b]64bit:[/b] - [2014.08.16 05:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV:[b]64bit:[/b] - [2014.08.16 02:58:35 | 000,287,744 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\SystemEventsBrokerServer.dll -- (SystemEventsBroker)
SRV:[b]64bit:[/b] - [2014.08.16 02:45:51 | 000,267,776 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\bisrv.dll -- (BrokerInfrastructure)
SRV:[b]64bit:[/b] - [2014.08.04 08:49:10 | 000,016,232 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe -- (IAStorDataMgrSvc)
SRV:[b]64bit:[/b] - [2014.07.24 09:28:58 | 001,600,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\workfolderssvc.dll -- (workfolderssvc)
SRV:[b]64bit:[/b] - [2014.03.14 08:26:25 | 000,491,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\GeofenceMonitorService.dll -- (lfsvc)
SRV:[b]64bit:[/b] - [2014.03.12 03:16:00 | 000,282,096 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Windows\SysNative\igfxCUIService.exe -- (igfxCUIService1.0.0.0)
SRV:[b]64bit:[/b] - [2014.03.08 07:41:25 | 001,306,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppXDeploymentServer.dll -- (AppXSvc)
SRV:[b]64bit:[/b] - [2014.03.06 09:02:13 | 000,834,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\netlogon.dll -- (Netlogon)
SRV:[b]64bit:[/b] - [2014.02.22 17:53:10 | 003,394,384 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\WSService.dll -- (WSService)
SRV:[b]64bit:[/b] - [2014.02.22 11:57:16 | 000,710,656 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsm.dll -- (LSM)
SRV:[b]64bit:[/b] - [2014.02.22 11:26:58 | 000,366,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wcmsvc.dll -- (Wcmsvc)
SRV:[b]64bit:[/b] - [2014.02.22 11:25:39 | 000,399,872 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\das.dll -- (DeviceAssociationService)
SRV:[b]64bit:[/b] - [2014.02.22 11:23:58 | 001,576,960 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\wlidsvc.dll -- (wlidsvc)
SRV:[b]64bit:[/b] - [2013.12.10 09:35:18 | 000,530,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\AppReadiness.dll -- (AppReadiness)
SRV:[b]64bit:[/b] - [2013.08.23 10:00:18 | 000,099,632 | ---- | M] (ELAN Microelectronics Corp.) [Auto | Running] -- C:\Program Files\Elantech\ETDService.exe -- (ETDService)
SRV:[b]64bit:[/b] - [2013.08.23 00:54:44 | 000,183,296 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:[b]64bit:[/b] - [2013.08.23 00:54:44 | 000,090,464 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysNative\KeyboardFilterSvc.dll -- (MsKeyboardFilter)
SRV:[b]64bit:[/b] - [2013.08.22 13:32:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wephostsvc.dll -- (WEPHOSTSVC)
SRV:[b]64bit:[/b] - [2013.08.22 13:31:43 | 000,040,448 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\efssvc.dll -- (EFS)
SRV:[b]64bit:[/b] - [2013.08.22 13:22:45 | 000,066,048 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\wiarpc.dll -- (WiaRpc)
SRV:[b]64bit:[/b] - [2013.08.22 13:21:15 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\svsvc.dll -- (svsvc)
SRV:[b]64bit:[/b] - [2013.08.22 13:16:57 | 000,118,272 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\fhsvc.dll -- (fhsvc)
SRV:[b]64bit:[/b] - [2013.08.22 12:25:28 | 000,164,352 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\NcaSvc.dll -- (NcaSvc)
SRV:[b]64bit:[/b] - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicvss)
SRV:[b]64bit:[/b] - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmictimesync)
SRV:[b]64bit:[/b] - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicshutdown)
SRV:[b]64bit:[/b] - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicrdv)
SRV:[b]64bit:[/b] - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmickvpexchange)
SRV:[b]64bit:[/b] - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicheartbeat)
SRV:[b]64bit:[/b] - [2013.08.22 12:19:28 | 000,517,120 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\icsvc.dll -- (vmicguestinterface)
SRV:[b]64bit:[/b] - [2013.08.22 12:02:47 | 000,013,312 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\smphost.dll -- (smphost)
SRV:[b]64bit:[/b] - [2013.08.22 11:57:25 | 000,130,560 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ScDeviceEnum.dll -- (ScDeviceEnum)
SRV:[b]64bit:[/b] - [2013.08.22 11:54:59 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\keyiso.dll -- (KeyIso)
SRV:[b]64bit:[/b] - [2013.08.22 11:50:59 | 000,245,760 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\TimeBrokerServer.dll -- (TimeBroker)
SRV:[b]64bit:[/b] - [2013.08.22 11:50:00 | 000,525,312 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofmsvc.dll -- (netprofm)
SRV:[b]64bit:[/b] - [2013.08.22 11:45:59 | 000,151,040 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\ncbservice.dll -- (NcbService)
SRV:[b]64bit:[/b] - [2013.08.22 11:40:49 | 000,248,832 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\vaultsvc.dll -- (VaultSvc)
SRV:[b]64bit:[/b] - [2013.08.22 11:31:03 | 000,201,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\DeviceSetupManager.dll -- (DsmSvc)
SRV:[b]64bit:[/b] - [2013.08.22 11:15:54 | 000,073,728 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\NcdAutoSetup.dll -- (NcdAutoSetup)
SRV:[b]64bit:[/b] - [2013.05.11 16:45:54 | 000,822,232 | ---- | M] (Intel(R) Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe -- (Intel(R)
SRV:[b]64bit:[/b] - [2013.05.11 16:45:38 | 000,733,696 | ---- | M] (Intel(R) Corporation) [Auto | Running] -- C:\Program Files\Intel\iCLS Client\HeciServer.exe -- (Intel(R)
SRV - [2015.01.28 22:46:30 | 001,910,128 | ---- | M] (Electronic Arts) [On_Demand | Stopped] -- C:\Program Files (x86)\Origin\OriginClientService.exe -- (Origin Client Service)
SRV - [2015.01.24 22:18:32 | 000,267,440 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2015.01.24 00:33:44 | 000,834,752 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)
SRV - [2015.01.19 02:17:31 | 000,174,624 | ---- | M] (EasyAntiCheat Ltd) [On_Demand | Stopped] -- C:\Windows\SysWOW64\EasyAntiCheat.exe -- (EasyAntiCheat)
SRV - [2014.12.31 14:48:14 | 004,920,104 | ---- | M] (Emsisoft GmbH) [Auto | Running] -- C:\Program Files (x86)\Emsisoft Internet Security\a2service.exe -- (a2AntiMalware)
SRV - [2014.12.15 13:29:58 | 005,426,448 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe -- (TeamViewer)
SRV - [2014.12.13 02:13:04 | 001,701,520 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe -- (NvNetworkService)
SRV - [2014.12.12 11:10:31 | 000,707,184 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe -- (QHActiveDefense)
SRV - [2014.12.11 10:30:48 | 000,315,496 | R--- | M] (Skype Technologies) [On_Demand | Stopped] -- C:\Program Files (x86)\Skype\Updater\Updater.exe -- (SkypeUpdate)
SRV - [2014.11.26 18:40:36 | 000,114,800 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)
SRV - [2014.11.16 16:28:40 | 000,076,888 | ---- | M] () [Auto | Running] -- C:\Windows\SysWOW64\PnkBstrA.exe -- (PnkBstrA)
SRV - [2014.11.10 00:57:20 | 000,147,664 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe -- (VSStandardCollectorService140)
SRV - [2014.11.10 00:57:20 | 000,089,240 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\Packages\Debugger\Services\VsEtwService.exe -- (VsEtwService140)
SRV - [2014.10.10 15:03:38 | 001,771,560 | ---- | M] (pdfforge GmbH) [On_Demand | Running] -- C:\Program Files (x86)\PDF Architect 2\ws.exe -- (PDF Architect 2)
SRV - [2014.10.10 15:03:38 | 000,861,736 | ---- | M] (pdfforge GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe -- (pdfforge CrashHandler)
SRV - [2014.10.10 15:03:38 | 000,738,856 | ---- | M] (pdfforge GmbH) [Disabled | Stopped] -- C:\Program Files (x86)\PDF Architect 2\creator-ws.exe -- (PDF Architect 2 Creator)
SRV - [2014.08.16 05:29:38 | 002,899,968 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll -- (PrintNotify)
SRV - [2014.07.14 17:21:46 | 001,390,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe -- (c2cautoupdatesvc)
SRV - [2014.07.14 17:21:06 | 001,767,520 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe -- (c2cpnrsvc)
SRV - [2014.03.14 08:10:16 | 000,357,376 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\GeofenceMonitorService.dll -- (lfsvc)
SRV - [2014.03.12 03:16:04 | 000,279,024 | ---- | M] (Intel Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\IntelCpHeciSvc.exe -- (cphs)
SRV - [2014.02.20 00:18:06 | 000,142,336 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe -- (fussvc)
SRV - [2013.09.26 12:58:58 | 000,160,768 | ---- | M] (Micro-Star International Co., Ltd.) [Auto | Running] -- C:\Program Files (x86)\SCM\MSIService.exe -- (Micro Star SCM)
SRV - [2013.08.28 11:35:44 | 000,056,832 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe -- (BTDevManager)
SRV - [2013.08.22 05:55:35 | 000,018,944 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\StorSvc.dll -- (StorSvc)
SRV - [2013.08.22 04:53:34 | 000,011,776 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\smphost.dll -- (smphost)
SRV - [2013.08.22 04:21:36 | 000,119,808 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe -- (Te.Service)
SRV - [2013.08.08 12:26:26 | 000,390,616 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2013.08.08 12:25:38 | 000,169,432 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe -- (jhi_service)
SRV - [2008.09.26 19:03:48 | 000,265,216 | ---- | M] (Atheros Communications, Inc.) [Auto | Running] -- C:\Program Files (x86)\Jumpstart\jswpbapi.exe -- (jswpbapi)
SRV - [2008.09.26 19:02:28 | 000,954,368 | ---- | M] (Atheros Communications, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Jumpstart\jswpsapi.exe -- (jswpsapi)
 
 
[color=#E56717]========== Driver Services (SafeList) ==========[/color]
 
DRV:[b]64bit:[/b] - [2015.01.01 21:36:44 | 000,491,632 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\fwndis64.sys -- (fwndis)
DRV:[b]64bit:[/b] - [2014.12.23 16:34:02 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\passthruparser.sys -- (passthruparser)
DRV:[b]64bit:[/b] - [2014.12.23 16:33:56 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lunparser.sys -- (lunparser)
DRV:[b]64bit:[/b] - [2014.12.23 16:33:51 | 000,068,960 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\hvservice.sys -- (hvservice)
DRV:[b]64bit:[/b] - [2014.12.23 16:33:42 | 000,018,944 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vhdparser.sys -- (vhdparser)
DRV:[b]64bit:[/b] - [2014.12.23 16:33:02 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pvhdparser.sys -- (pvhdparser)
DRV:[b]64bit:[/b] - [2014.12.13 02:13:03 | 000,019,600 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys -- (NvStreamKms)
DRV:[b]64bit:[/b] - [2014.12.12 11:10:31 | 000,305,736 | ---- | M] (360.cn) [File_System | System | Running] -- C:\Windows\SysNative\drivers\360Box64.sys -- (360Box64)
DRV:[b]64bit:[/b] - [2014.12.12 11:10:31 | 000,077,896 | ---- | M] (360.cn) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\360AvFlt.sys -- (360AvFlt)
DRV:[b]64bit:[/b] - [2014.12.12 02:51:20 | 000,075,776 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\ahcache.sys -- (ahcache)
DRV:[b]64bit:[/b] - [2014.11.22 12:46:30 | 000,038,032 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvvad64v.sys -- (nvvad_WaveExtensible)
DRV:[b]64bit:[/b] - [2014.11.04 02:04:30 | 000,032,576 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\nvpciflt.sys -- (nvpciflt)
DRV:[b]64bit:[/b] - [2014.10.30 20:00:23 | 000,283,064 | ---- | M] (Disc Soft Ltd) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\dtsoftbus01.sys -- (dtsoftbus01)
DRV:[b]64bit:[/b] - [2014.10.13 04:43:17 | 000,238,912 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:[b]64bit:[/b] - [2014.10.13 04:43:17 | 000,086,336 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\pdc.sys -- (pdc)
DRV:[b]64bit:[/b] - [2014.10.13 04:43:17 | 000,039,744 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\intelpep.sys -- (intelpep)
DRV:[b]64bit:[/b] - [2014.10.10 03:58:57 | 000,027,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:[b]64bit:[/b] - [2014.09.23 12:41:05 | 000,312,400 | ---- | M] (Qihu 360 Software Co., Ltd.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\360fsflt.sys -- (360FsFlt)
DRV:[b]64bit:[/b] - [2014.09.23 12:41:04 | 000,180,816 | ---- | M] (Qihu 360 Software Co., Ltd.) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\BAPIDRV64.SYS -- (BAPIDRV)
DRV:[b]64bit:[/b] - [2014.09.23 12:41:04 | 000,100,424 | ---- | M] (360.cn) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\360AntiHacker64.sys -- (360AntiHacker)
DRV:[b]64bit:[/b] - [2014.09.23 12:41:04 | 000,040,520 | ---- | M] (360.cn) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\360Camera64.sys -- (360Camera)
DRV:[b]64bit:[/b] - [2014.09.22 05:06:16 | 000,258,368 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdFilter.sys -- (WdFilter)
DRV:[b]64bit:[/b] - [2014.09.22 05:06:16 | 000,114,496 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdNisDrv.sys -- (WdNisDrv)
DRV:[b]64bit:[/b] - [2014.09.22 04:49:43 | 000,035,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WdBoot.sys -- (WdBoot)
DRV:[b]64bit:[/b] - [2014.08.26 04:22:49 | 000,690,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmswitch.sys -- (VMSVSP)
DRV:[b]64bit:[/b] - [2014.08.26 04:22:49 | 000,690,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmswitch.sys -- (VMSVSF)
DRV:[b]64bit:[/b] - [2014.08.26 04:22:49 | 000,690,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmswitch.sys -- (VMSP)
DRV:[b]64bit:[/b] - [2014.08.26 04:22:49 | 000,690,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmswitch.sys -- (VMSMP)
DRV:[b]64bit:[/b] - [2014.08.15 02:36:55 | 000,146,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpioclx.sys -- (GPIOClx0101)
DRV:[b]64bit:[/b] - [2014.08.04 08:49:06 | 000,670,568 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStorA.sys -- (iaStorA)
DRV:[b]64bit:[/b] - [2014.07.24 17:28:38 | 000,468,288 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBHUB3.SYS -- (USBHUB3)
DRV:[b]64bit:[/b] - [2014.07.24 17:28:38 | 000,412,992 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\spaceport.sys -- (spaceport)
DRV:[b]64bit:[/b] - [2014.07.24 13:42:22 | 000,126,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NdisImPlatform.sys -- (NdisImPlatform)
DRV:[b]64bit:[/b] - [2014.06.09 10:41:00 | 000,180,136 | ---- | M] (Tonec Inc.) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\idmwfp.sys -- (IDMWFP)
DRV:[b]64bit:[/b] - [2014.05.01 15:31:39 | 000,055,328 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wpcfltr.sys -- (wpcfltr)
DRV:[b]64bit:[/b] - [2014.04.24 13:12:18 | 000,031,160 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\PerformanceTest\DirectIo64.sys -- (DIRECTIO)
DRV:[b]64bit:[/b] - [2014.03.20 05:41:20 | 000,376,152 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\clfs.sys -- (CLFS)
DRV:[b]64bit:[/b] - [2014.03.13 14:35:24 | 000,157,016 | ---- | M] (Microsoft Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\wof.sys -- (Wof)
DRV:[b]64bit:[/b] - [2014.03.08 22:40:16 | 000,136,024 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\wfplwfs.sys -- (WFPLWFS)
DRV:[b]64bit:[/b] - [2014.03.07 18:26:42 | 000,450,520 | ---- | M] (Intel(R) Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:[b]64bit:[/b] - [2014.03.07 18:18:23 | 003,729,920 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:[b]64bit:[/b] - [2014.03.01 22:32:31 | 000,038,296 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\intelaud.sys -- (intaud_WaveExtensible)
DRV:[b]64bit:[/b] - [2014.03.01 22:32:31 | 000,027,032 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\iwdbus.sys -- (iwdbus)
DRV:[b]64bit:[/b] - [2014.02.22 17:49:51 | 000,325,464 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\USBXHCI.SYS -- (USBXHCI)
DRV:[b]64bit:[/b] - [2014.02.22 17:49:49 | 000,189,784 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\UCX01000.SYS -- (UCX01000)
DRV:[b]64bit:[/b] - [2014.02.22 17:49:49 | 000,079,192 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\sdstor.sys -- (sdstor)
DRV:[b]64bit:[/b] - [2014.02.22 17:44:13 | 000,924,504 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\refs.sys -- (ReFS)
DRV:[b]64bit:[/b] - [2014.02.22 14:14:02 | 000,033,280 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicRender.sys -- (BasicRender)
DRV:[b]64bit:[/b] - [2014.01.22 07:52:10 | 000,206,080 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm)
DRV:[b]64bit:[/b] - [2014.01.22 07:52:10 | 000,108,800 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus)
DRV:[b]64bit:[/b] - [2013.12.04 20:41:54 | 000,226,304 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthLEEnum.sys -- (BthLEEnum)
DRV:[b]64bit:[/b] - [2013.10.26 03:54:32 | 000,146,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx2.sys -- (SerCx2)
DRV:[b]64bit:[/b] - [2013.10.05 17:25:54 | 000,057,176 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stornvme.sys -- (stornvme)
DRV:[b]64bit:[/b] - [2013.09.14 16:06:57 | 000,175,960 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\VerifierExt.sys -- (VerifierExt)
DRV:[b]64bit:[/b] - [2013.08.23 10:00:22 | 000,382,768 | ---- | M] (ELAN Microelectronics Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ETD.sys -- (ETD)
DRV:[b]64bit:[/b] - [2013.08.23 00:54:45 | 000,022,272 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\kbldfltr.sys -- (kbldfltr)
DRV:[b]64bit:[/b] - [2013.08.23 00:54:38 | 000,037,216 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\terminpt.sys -- (terminpt)
DRV:[b]64bit:[/b] - [2013.08.23 00:54:37 | 000,220,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Vid.sys -- (Vid)
DRV:[b]64bit:[/b] - [2013.08.23 00:54:37 | 000,129,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vmbusr.sys -- (vmbusr)
DRV:[b]64bit:[/b] - [2013.08.23 00:54:37 | 000,068,608 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\storvsp.sys -- (storvsp)
DRV:[b]64bit:[/b] - [2013.08.23 00:54:37 | 000,065,536 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcivsp.sys -- (vpcivsp)
DRV:[b]64bit:[/b] - [2013.08.22 15:25:40 | 000,043,008 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\condrv.sys -- (condrv)
DRV:[b]64bit:[/b] - [2013.08.22 15:25:40 | 000,030,048 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:[b]64bit:[/b] - [2013.08.22 14:50:19 | 000,057,696 | ---- | M] (Microsoft Corporation) [Kernel | System | Stopped] -- C:\Windows\SysNative\drivers\dam.sys -- (dam)
DRV:[b]64bit:[/b] - [2013.08.22 14:49:54 | 000,079,712 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\acpiex.sys -- (acpiex)
DRV:[b]64bit:[/b] - [2013.08.22 14:49:33 | 000,159,584 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\tpm.sys -- (TPM)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:49 | 000,063,840 | ---- | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\mvumis.sys -- (mvumis)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:48 | 000,041,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\msgpiowin32.sys -- (msgpiowin32)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:45 | 003,357,024 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:45 | 000,093,536 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:45 | 000,082,784 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sss.sys -- (LSI_SSS)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:45 | 000,064,352 | ---- | M] (Hewlett-Packard Company) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:44 | 000,081,760 | ---- | M] (LSI Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas3.sys -- (LSI_SAS3)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:41 | 000,782,176 | ---- | M] (PMC-Sierra) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\adp80xx.sys -- (ADP80XX)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:41 | 000,531,296 | ---- | M] (Broadcom Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:41 | 000,259,424 | ---- | M] (AMD Technologies Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:41 | 000,108,896 | ---- | M] (LSI) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\3ware.sys -- (3ware)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:41 | 000,079,200 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:40 | 000,114,016 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorTcgDrv.sys -- (EhStorTcgDrv)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:40 | 000,082,784 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\EhStorClass.sys -- (EhStorClass)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:40 | 000,025,952 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:34 | 000,305,504 | ---- | M] (VIA Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\VSTXRAID.SYS -- (VSTXRAID)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:33 | 000,074,080 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\uaspstor.sys -- (UASPStor)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:32 | 000,031,072 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:31 | 000,107,872 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\storahci.sys -- (storahci)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:31 | 000,072,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SpbCx.sys -- (SpbCx)
DRV:[b]64bit:[/b] - [2013.08.22 14:43:31 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\SerCx.sys -- (SerCx)
DRV:[b]64bit:[/b] - [2013.08.22 14:39:15 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\uefi.sys -- (UEFI)
DRV:[b]64bit:[/b] - [2013.08.22 14:37:27 | 000,069,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vpci.sys -- (vpci)
DRV:[b]64bit:[/b] - [2013.08.22 14:36:12 | 000,026,976 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WpdUpFltr.sys -- (WpdUpFltr)
DRV:[b]64bit:[/b] - [2013.08.22 13:39:31 | 000,050,688 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BasicDisplay.sys -- (BasicDisplay)
DRV:[b]64bit:[/b] - [2013.08.22 13:39:20 | 000,022,016 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HyperVideo.sys -- (HyperVideo)
DRV:[b]64bit:[/b] - [2013.08.22 13:39:06 | 000,009,728 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mshidumdf.sys -- (mshidumdf)
DRV:[b]64bit:[/b] - [2013.08.22 13:38:58 | 000,010,752 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpitime.sys -- (acpitime)
DRV:[b]64bit:[/b] - [2013.08.22 13:38:48 | 000,010,240 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\acpipagr.sys -- (acpipagr)
DRV:[b]64bit:[/b] - [2013.08.22 13:38:39 | 000,036,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthAvrcpTg.sys -- (BthAvrcpTg)
DRV:[b]64bit:[/b] - [2013.08.22 13:38:26 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\kdnic.sys -- (kdnic)
DRV:[b]64bit:[/b] - [2013.08.22 13:38:23 | 000,011,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\vmgencounter.sys -- (gencounter)
DRV:[b]64bit:[/b] - [2013.08.22 13:38:22 | 000,023,040 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\npsvctrig.sys -- (npsvctrig)
DRV:[b]64bit:[/b] - [2013.08.22 13:38:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BthhfHid.sys -- (bthhfhid)
DRV:[b]64bit:[/b] - [2013.08.22 13:37:49 | 000,013,824 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hyperkbd.sys -- (hyperkbd)
DRV:[b]64bit:[/b] - [2013.08.22 13:37:46 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:[b]64bit:[/b] - [2013.08.22 13:37:42 | 000,057,856 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bthhfenum.sys -- (BthHFEnum)
DRV:[b]64bit:[/b] - [2013.08.22 13:37:28 | 000,056,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:[b]64bit:[/b] - [2013.08.22 13:37:28 | 000,041,472 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hidi2c.sys -- (hidi2c)
DRV:[b]64bit:[/b] - [2013.08.22 13:37:14 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:[b]64bit:[/b] - [2013.08.22 13:36:43 | 000,087,040 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netvsc63.sys -- (netvsc)
DRV:[b]64bit:[/b] - [2013.08.22 13:36:25 | 000,016,384 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NdisVirtualBus.sys -- (NdisVirtualBus)
DRV:[b]64bit:[/b] - [2013.08.22 13:36:07 | 000,066,560 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\mslldp.sys -- (MsLldp)
DRV:[b]64bit:[/b] - [2013.08.22 13:35:42 | 000,103,424 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\Ndu.sys -- (Ndu)
DRV:[b]64bit:[/b] - [2013.08.22 10:46:33 | 000,027,136 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fxppm.sys -- (FxPPM)
DRV:[b]64bit:[/b] - [2013.08.21 11:42:32 | 002,944,216 | ---- | M] (Realtek Semiconductor Corporation                           ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtwlane.sys -- (RTWlanE)
DRV:[b]64bit:[/b] - [2013.08.13 01:25:46 | 000,017,624 | ---- | M] (Windows (R) Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bcmfn2.sys -- (bcmfn2)
DRV:[b]64bit:[/b] - [2013.08.10 02:39:30 | 000,651,248 | ---- | M] (Intel Corporation) [Kernel | Boot | Stopped] -- C:\Windows\SysNative\drivers\iaStorAV.sys -- (iaStorAV)
DRV:[b]64bit:[/b] - [2013.08.08 22:25:14 | 000,099,288 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\TeeDriverx64.sys -- (MEIx64)
DRV:[b]64bit:[/b] - [2013.07.30 20:47:35 | 000,024,568 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_GPIO.sys -- (iaLPSSi_GPIO)
DRV:[b]64bit:[/b] - [2013.07.25 21:05:39 | 000,099,320 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\iaLPSSi_I2C.sys -- (iaLPSSi_I2C)
DRV:[b]64bit:[/b] - [2013.07.18 07:55:42 | 000,130,248 | ---- | M] (Qualcomm Atheros Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\L1C63x64.sys -- (L1C)
DRV:[b]64bit:[/b] - [2013.07.09 07:58:32 | 000,263,896 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtsUStor.sys -- (RSUSBSTOR)
DRV:[b]64bit:[/b] - [2013.07.04 10:22:00 | 000,547,032 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\RtkBtfilter.sys -- (RtkBtFilter)
DRV:[b]64bit:[/b] - [2013.03.01 03:49:12 | 000,036,600 | ---- | M] (Riverbed Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\npf.sys -- (NPF)
DRV:[b]64bit:[/b] - [2012.02.11 06:59:34 | 000,334,936 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\RsFx0200.sys -- (RsFx0200)
DRV:[b]64bit:[/b] - [2009.12.30 10:21:26 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
DRV:[b]64bit:[/b] - [2009.11.18 07:12:00 | 000,032,344 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MBfilt64.sys -- (MBfilt)
DRV:[b]64bit:[/b] - [2008.05.15 03:28:52 | 000,026,624 | ---- | M] (Atheros Communications, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\jswpslwfx.sys -- (JSWPSLWF)
DRV - [2015.01.01 21:36:44 | 000,414,936 | ---- | M] () [Kernel | System | Stopped] -- C:\Program Files (x86)\Emsisoft Internet Security\fwwfp764.sys -- (fwwfp)
DRV - [2014.05.12 17:43:58 | 000,071,472 | ---- | M] (Emsisoft GmbH) [File_System | On_Demand | Running] -- C:\PROGRAM FILES (X86)\EMSISOFT INTERNET SECURITY\a2accx64.sys -- (a2acc)
DRV - [2014.05.12 17:43:56 | 000,023,088 | ---- | M] (Emsisoft GmbH) [File_System | System | Running] -- C:\Program Files (x86)\Emsisoft Internet Security\a2util64.sys -- (a2util)
DRV - [2013.12.04 18:23:36 | 000,057,024 | ---- | M] (Emsisoft GmbH) [File_System | On_Demand | Running] -- C:\Program Files (x86)\Emsisoft Internet Security\cleanhlp64.sys -- (cleanhlp)
DRV - [2013.09.30 17:23:02 | 000,045,208 | ---- | M] (Emsisoft GmbH) [File_System | System | Running] -- C:\Program Files (x86)\Emsisoft Internet Security\a2dix64.sys -- (a2injectiondriver)
DRV - [2013.03.28 18:03:02 | 000,026,176 | ---- | M] (Emsisoft GmbH) [File_System | System | Running] -- C:\Program Files (x86)\Emsisoft Internet Security\a2ddax64.sys -- (A2DDA)
DRV - [2012.07.13 15:13:14 | 000,070,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys -- (VSPerfDrv110)
DRV - [2007.12.12 13:04:56 | 000,034,963 | ---- | M] (Compuware Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\hid7906.sys -- (hid7906)
DRV - [2007.12.03 07:46:12 | 000,037,024 | ---- | M] (Compuware Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\hid8101.sys -- (hid8101)
DRV - [2007.11.28 09:52:46 | 000,034,587 | ---- | M] (Compuware Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\hid8103.sys -- (hid8103)
 
 
[color=#E56717]========== Standard Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== Internet Explorer ==========[/color]
 
IE:[b]64bit:[/b] - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
[color=#E56717]========== FireFox ==========[/color]
 
FF - prefs.js..browser.search.isUS: false
FF - prefs.js..extensions.enabledAddons: magicplayer%40acestream.org:1.1.41
FF - prefs.js..extensions.enabledAddons: %7Be968fc70-8f95-4ab9-9e79-304de2a71ee1%7D:0.7.3
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:34.0.5
FF - user.js - File not found
 
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=11.25.2: C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=11.25.2: C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~4\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect:  File not found
FF:[b]64bit:[/b] - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/Lync,version=15.0: C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\PDF Architect 2: C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF - HKCU\Software\MozillaPlugins\@acestream.net/acestreamplugin,version=3.0.5: C:\Users\ihsan\AppData\Roaming\ACEStream\player\npace_plugin.dll (Innovative Digital Technologies)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\ihsan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\ubisoft.com/uplaypc: C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension\ [2014.10.18 22:33:12 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox [2014.12.16 21:33:40 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 34.0.5\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014.10.26 12:49:21 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Users\ihsan\AppData\Roaming\IDM\idmmzcc5 [2014.09.28 15:49:08 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\SeaMonkey\Extensions\\[email protected]: C:\Users\ihsan\AppData\Roaming\IDM\idmmzcc5 [2014.09.28 15:49:08 | 000,000,000 | ---D | M]
 
[2015.01.05 21:31:07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ihsan\AppData\Roaming\mozilla\Extensions
[2015.01.15 12:08:36 | 000,000,000 | ---D | M] (No name found) -- C:\Users\ihsan\AppData\Roaming\mozilla\Firefox\Profiles\kg35b0ue.default\extensions
[2015.01.08 20:19:04 | 000,461,623 | ---- | M] () (No name found) -- C:\Users\ihsan\AppData\Roaming\mozilla\firefox\profiles\kg35b0ue.default\extensions\[email protected]
[2015.01.15 12:08:36 | 000,042,336 | ---- | M] () (No name found) -- C:\Users\ihsan\AppData\Roaming\mozilla\firefox\profiles\kg35b0ue.default\extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi
[2015.01.05 21:30:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\mozilla firefox\browser\extensions
[2015.01.05 21:30:46 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\mozilla firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2014.05.21 12:23:56 | 000,034,072 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
 
[color=#E56717]========== Chrome  ==========[/color]
 
CHR - default_search_provider:  ()
CHR - default_search_provider: search_url = 
CHR - default_search_provider: suggest_url = 
CHR - plugin: Widevine Content Decryption Module (Enabled) = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.6.758\_platform_specific\win_x64\widevinecdmadapter.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.35\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.35\internal-nacl-plugin
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.35\pdf.dll
CHR - plugin: Internet Download Manager Plugin (Enabled) = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn\6.21.10_0\IDMGCExt64.dll
CHR - plugin: Microsoft Office 2013 (Disabled) = C:\PROGRA~1\MICROS~4\Office15\NPSPWRAP.DLL
CHR - plugin: AdobeAAMDetect (Disabled) = C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll
CHR - plugin: Java Deployment Toolkit 8.0.250.18 (Enabled) = C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll
CHR - plugin: Java(TM) Platform SE 8 U25 (Enabled) = C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\anelkojiepicmcldgnmkplocifmegpfj\0.0.0.23_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bebalkdfejapnfbngpmhchkboajaofen\1.9.0.7_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg\1.0.3.8_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod\1.0.230_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.10_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd\160_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoieeedlomnegifmaghhjnghhmcldobl\1.3_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbmppankahdodchhioklnbcmohehhjoa\1.4_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme\4.2.1_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbkeegbaiigmenfmjfclcdgdpimamgkj\100.729.741_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\geddoclleiomckbhadiaipdggiiccfje\1.3.2_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjgkjeheegjnnmheaflhdocglkiegoni\0.0.1.8_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\glcimepnljoholdmjchkloafkggfoijh\2.0.6_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik\2.2015.130.10317_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihedienojfhdahpomfldoejaimefofff\6.0.2_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbnkffmindojffecdhbbmekbmkkfpmjd\0.167_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn\6.21.10_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifpbeccnghkjeaalbbjmodiffmgedin\1.2.4_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\llldafpkkdiljghncbdnkgfinfiifnig\1.0.1_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\4.4.0_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohmmkhmmmpcnpikjeljgnaoabkaalbgc\0.1.18_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: No name found = C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnoffddplpippgcfjdhbmhkofpnaalpg\0.19.3489_0\
 
O1 HOSTS File: ([2014.12.15 00:30:32 | 000,001,132 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1                   activate.adobe.com
O1 - Hosts: 127.0.0.1                   practivate.adobe.com
O1 - Hosts: 127.0.0.1                   lmlicenses.wip4.adobe.com
O1 - Hosts: 127.0.0.1                   lm.licenses.adobe.com
O1 - Hosts: 127.0.0.1                   na1r.services.adobe.com
O1 - Hosts: 127.0.0.1                   hlrcv.stage.adobe.com
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
O2:[b]64bit:[/b] - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (PDF Architect Helper) - {691B33B0-B86E-47F3-81C7-56E4FE3B929C} - C:\Program Files (x86)\PDF Architect 2\creator-ie-helper.dll (pdfforge GmbH)
O2 - BHO: (Microsoft Web Test Recorder 10.0 Helper) - {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} - C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MIF5BA~1\Office15\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Microsoft Web Test Recorder 14.0 Helper) - {b924f0b4-0b3c-49c0-bab2-213fb9ebd1d3} - C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
O2 - BHO: (Microsoft SkyDrive Pro Browser Helper) - {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} - C:\PROGRA~2\MIF5BA~1\Office15\GROOVEEX.DLL (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (PDF Architect Toolbar) - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - C:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll (pdfforge GmbH)
O4:[b]64bit:[/b] - HKLM..\Run: [BtServer] C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe (Realtek Semiconductor Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:[b]64bit:[/b] - HKLM..\Run: [IAStorIcon] C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe (Intel Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [Logitech Download Assistant] C:\Windows\SysNative\LogiLDA.dll (Logitech, Inc.)
O4:[b]64bit:[/b] - HKLM..\Run: [MBCfg64] C:\Windows\SysNative\MBCfg64.DLL (Creative Technology Ltd.)
O4:[b]64bit:[/b] - HKLM..\Run: [NvBackend] C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe (NVIDIA Corporation)
O4:[b]64bit:[/b] - HKLM..\Run: [Radio Manager] C:\Program Files (x86)\SCM\Radio Manager.exe (MSI)
O4:[b]64bit:[/b] - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:[b]64bit:[/b] - HKLM..\Run: [SCM] C:\Program Files (x86)\SCM\SCM.exe (MSI)
O4:[b]64bit:[/b] - HKLM..\Run: [ShadowPlay] C:\Windows\SysNative\nvspcap64.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCEPServiceManager] C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [emsisoft anti-malware] c:\program files (x86)\emsisoft internet security\a2guard.exe (Emsisoft GmbH)
O4 - HKLM..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\isuspm.exe (Flexera Software LLC.)
O4 - HKLM..\Run: [jswtrayutil] C:\Program Files (x86)\Jumpstart\jswtrayutil.exe (Atheros Communications, Inc.)
O4 - HKLM..\Run: [Nuance OmniPage Ultimate-reminder] C:\Program Files (x86)\Nuance\OmniPage19\Ereg\Ereg.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [OmniPage Preload] C:\Program Files (x86)\Nuance\OmniPage19\OmniPage19.exe (Nuance Communications, Inc.)
O4 - HKLM..\Run: [QHSafeTray] C:\Program Files (x86)\360\Total Security\safemon\360Tray.exe (Qihu Software Co. Limited)
O4 - HKLM..\Run: [Sound Blaster Cinema] C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe (Creative Technology Ltd)
O4 - HKCU..\Run: [CCleaner Monitoring] C:\Program Files\CCleaner\CCleaner64.exe (Piriform Ltd)
O4 - HKCU..\Run: [IDMan] C:\Program Files (x86)\Internet Download Manager\IDMan.exe (Tonec Inc.)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\isuspm.exe (Flexera Software LLC.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 221
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O8:[b]64bit:[/b] - Extra context menu item: IDM ile indir - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8:[b]64bit:[/b] - Extra context menu item: Tüm bağlantıları IDM ile indir - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O8 - Extra context menu item: IDM ile indir - C:\Program Files (x86)\Internet Download Manager\IEExt.htm ()
O8 - Extra context menu item: Tüm bağlantıları IDM ile indir - C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm ()
O9:[b]64bit:[/b] - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O9 - Extra Button: Skype Click to Call settings - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O13[b]64bit:[/b] - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 0.0.0.0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{21323E34-A400-4C48-8BF5-9D036F343C60}: DhcpNameServer = 192.168.1.1 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{78FA00C6-2245-43D4-9A83-7FED19DE07AA}: DhcpNameServer = 192.168.1.1 0.0.0.0
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{78FA00C6-2245-43D4-9A83-7FED19DE07AA}: NameServer = 8.8.8.8,8.8.4.8
O18:[b]64bit:[/b] - Protocol\Handler\mso-offdap11 - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Handler\skypec2c {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
O20:[b]64bit:[/b] - AppInit_DLLs: (C:\Windows\system32\nvinitx.dll) - C:\Windows\SysNative\nvinitx.dll (NVIDIA Corporation)
O20 - AppInit_DLLs: (C:\Windows\SysWOW64\nvinit.dll) - C:\Windows\SysWOW64\nvinit.dll (NVIDIA Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:[b]64bit:[/b] - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:[b]64bit:[/b] - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:[b]64bit:[/b] - HKLM\..comfile [open] -- "%1" %*
O35:[b]64bit:[/b] - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...com [@ = comfile] -- "%1" %*
O37:[b]64bit:[/b] - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
 
[2015.02.01 22:55:58 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\ihsan\Desktop\OTL.exe
[2015.01.31 04:30:20 | 000,000,000 | ---D | C] -- C:\OutputFolder
[2015.01.31 04:27:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Allok Video Converter
[2015.01.31 04:27:02 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Allok Video Converter
[2015.01.31 00:48:11 | 000,000,000 | ---D | C] -- C:\Users\ihsan\Documents\Freemake
[2015.01.31 00:48:10 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
[2015.01.31 00:48:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
[2015.01.31 00:48:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Freemake
[2015.01.31 00:46:59 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Freemake
[2015.01.30 04:34:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Emsisoft
[2015.01.30 04:10:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Internet Security
[2015.01.30 04:09:47 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Emsisoft Internet Security
[2015.01.30 03:30:58 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\Wise Registry Cleaner
[2015.01.30 03:29:39 | 000,076,565 | ---- | C] (RaProducts.org) -- C:\Users\ihsan\Desktop\PureRa.exe
[2015.01.30 03:25:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2015.01.30 03:25:14 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2015.01.30 03:02:54 | 000,000,000 | ---D | C] -- C:\Users\ihsan\Desktop\hellsing altyazı
[2015.01.30 02:53:17 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Local\VSIXInstaller
[2015.01.30 02:33:13 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Local\VS Revo Group
[2015.01.30 02:32:53 | 000,000,000 | ---D | C] -- C:\ProgramData\VS Revo Group
[2015.01.30 02:32:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
[2015.01.30 02:32:52 | 000,031,800 | ---- | C] (VS Revo Group) -- C:\Windows\SysNative\drivers\revoflt.sys
[2015.01.30 02:32:51 | 000,000,000 | ---D | C] -- C:\Program Files\VS Revo Group
[2015.01.29 00:46:42 | 000,000,000 | ---D | C] -- C:\Users\ihsan\Documents\GenTool
[2015.01.28 22:53:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Command and Conquer Generals and Zero Hour
[2015.01.28 22:53:55 | 000,000,000 | ---D | C] -- C:\Users\ihsan\Documents\Command and Conquer Generals Zero Hour Data
[2015.01.28 22:53:55 | 000,000,000 | ---D | C] -- C:\Users\ihsan\Documents\Command and Conquer Generals Data
[2015.01.26 02:10:10 | 000,000,000 | ---D | C] -- C:\data_from_forms
[2015.01.26 02:09:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ETS
[2015.01.26 02:09:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ETS
[2015.01.26 02:06:09 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Local\Downloaded Installations
[2015.01.20 02:29:08 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Local\Sublight
[2015.01.20 02:29:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sublight
[2015.01.20 02:29:06 | 000,000,000 | ---D | C] -- C:\Program Files\Sublight
[2015.01.19 14:52:48 | 000,174,624 | ---- | C] (EasyAntiCheat Ltd) -- C:\Windows\SysWow64\EasyAntiCheat.exe
[2015.01.19 00:42:00 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Command and Conquer Red Alert 2
[2015.01.19 00:41:55 | 000,000,000 | -H-D | C] -- C:\Program Files (x86)\Common Files\EAInstaller
[2015.01.18 23:21:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Origin Games
[2015.01.18 23:04:40 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\Origin
[2015.01.18 23:04:38 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Local\Origin
[2015.01.18 17:36:34 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\URUSoft
[2015.01.18 17:36:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\URUSoft
[2015.01.18 17:36:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\URUSoft
[2015.01.16 00:10:49 | 000,000,000 | ---D | C] -- C:\Users\ihsan\Desktop\işletimsistemleri
[2015.01.12 21:40:00 | 000,000,000 | ---D | C] -- C:\Users\ihsan\Documents\Red Alert 3
[2015.01.12 21:34:54 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\Red Alert 3
[2015.01.12 18:08:35 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\fontconfig
[2015.01.12 18:08:06 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\Aegisub
[2015.01.12 09:33:03 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\Dev-Cpp
[2015.01.12 09:32:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bloodshed Dev-C++
[2015.01.12 09:32:26 | 000,000,000 | ---D | C] -- C:\Dev-Cpp
[2015.01.09 21:10:27 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\Bioshock2Steam
[2015.01.09 21:10:27 | 000,000,000 | ---D | C] -- C:\Users\ihsan\Documents\Bioshock2
[2015.01.09 20:38:28 | 000,000,000 | ---D | C] -- C:\Users\ihsan\Documents\Bioshock
[2015.01.09 20:38:28 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\Bioshock
[2015.01.09 20:38:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bioshock Türkçe
[2015.01.08 20:32:05 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\vlc
[2015.01.08 20:08:09 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ace Stream Media
[2015.01.07 17:12:08 | 000,129,752 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\1C5070DB.sys
[2015.01.06 02:42:55 | 000,000,000 | ---D | C] -- C:\Users\ihsan\Desktop\This War Of Mine
[2015.01.05 21:31:50 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\huawei
[2015.01.05 21:31:43 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Local\Macromedia
[2015.01.05 21:31:03 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\Mozilla
[2015.01.05 21:31:03 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Local\Mozilla
[2015.01.05 21:30:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2015.01.05 21:30:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Mozilla
[2015.01.05 21:07:52 | 000,000,000 | ---D | C] -- C:\ProgramData\TTNetIlkYardim
[2015.01.05 16:48:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Verimatrix
[2015.01.04 15:03:55 | 000,000,000 | ---D | C] -- C:\Users\ihsan\AppData\Roaming\TeamViewer
[2015.01.04 15:03:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\TeamViewer
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
 
[2015.02.01 22:55:48 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\ihsan\Desktop\OTL.exe
[2015.02.01 22:18:00 | 000,000,814 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015.02.01 20:45:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2015.01.31 11:52:34 | 002,230,282 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2015.01.31 11:52:34 | 000,896,376 | ---- | M] () -- C:\Windows\SysNative\perfh01F.dat
[2015.01.31 11:52:34 | 000,894,630 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2015.01.31 11:52:34 | 000,224,000 | ---- | M] () -- C:\Windows\SysNative\perfc01F.dat
[2015.01.31 11:52:34 | 000,206,956 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2015.01.31 04:27:16 | 000,001,085 | ---- | M] () -- C:\Users\Public\Desktop\Allok Video Converter.lnk
[2015.01.31 00:48:10 | 000,001,336 | ---- | M] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2015.01.30 14:03:48 | 027,590,656 | ---- | M] () -- C:\Windows\SysNative\vmguest.iso
[2015.01.30 13:49:55 | 268,435,456 | -HS- | M] () -- C:\swapfile.sys
[2015.01.30 13:49:51 | 2510,847,999 | -HS- | M] () -- C:\hiberfil.sys
[2015.01.30 04:36:49 | 005,184,440 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2015.01.30 04:10:06 | 000,001,138 | ---- | M] () -- C:\Users\Public\Desktop\Emsisoft Internet Security.lnk
[2015.01.30 03:25:16 | 000,000,834 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2015.01.30 03:05:44 | 000,000,196 | ---- | M] () -- C:\Users\ihsan\Desktop\ksifre.rar
[2015.01.30 02:48:57 | 000,002,295 | ---- | M] () -- C:\Users\ihsan\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2015.01.30 02:32:57 | 000,001,117 | ---- | M] () -- C:\Users\ihsan\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2015.01.29 18:03:44 | 000,007,639 | ---- | M] () -- C:\Users\ihsan\AppData\Local\Resmon.ResmonCfg
[2015.01.25 15:14:07 | 000,121,108 | ---- | M] () -- C:\Users\ihsan\Desktop\ihsan_Soydas_CV.pdf
[2015.01.21 03:09:38 | 000,000,396 | RHS- | M] () -- C:\ProgramData\ntuser.pol
[2015.01.20 02:40:00 | 000,121,105 | ---- | M] () -- C:\Users\ihsan\Desktop\pk altyazı.srt
[2015.01.19 02:17:31 | 000,174,624 | ---- | M] (EasyAntiCheat Ltd) -- C:\Windows\SysWow64\EasyAntiCheat.exe
[2015.01.18 17:36:34 | 000,002,212 | ---- | M] () -- C:\Users\ihsan\Application Data\Microsoft\Internet Explorer\Quick Launch\Subtitle Workshop.lnk
[2015.01.12 09:32:55 | 000,000,617 | ---- | M] () -- C:\Users\ihsan\Application Data\Microsoft\Internet Explorer\Quick Launch\Dev-C++.lnk
[2015.01.08 20:33:35 | 000,036,577 | ---- | M] () -- C:\Users\ihsan\Desktop\[kickass.so]cbm.hellsing.ultimate.1.10.complete.dual.audio.bdrip.720p.8bit.torrent
[2015.01.08 17:59:40 | 000,038,519 | ---- | M] () -- C:\Users\ihsan\Desktop\Hellsing Ultimate OVA 01-10.torrent
[2015.01.07 17:12:08 | 000,129,752 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\1C5070DB.sys
[1 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
[color=#E56717]========== Files Created - No Company Name ==========[/color]
 
[2015.01.31 04:27:16 | 000,001,085 | ---- | C] () -- C:\Users\Public\Desktop\Allok Video Converter.lnk
[2015.01.31 04:27:11 | 000,129,024 | ---- | C] () -- C:\Windows\SysWow64\AVERM.dll
[2015.01.31 04:27:10 | 000,028,672 | ---- | C] () -- C:\Windows\SysWow64\AVEQT.dll
[2015.01.31 00:48:10 | 000,001,336 | ---- | C] () -- C:\Users\Public\Desktop\Freemake Video Converter.lnk
[2015.01.30 04:10:06 | 000,001,138 | ---- | C] () -- C:\Users\Public\Desktop\Emsisoft Internet Security.lnk
[2015.01.30 04:09:53 | 000,491,632 | ---- | C] () -- C:\Windows\SysNative\drivers\fwndis64.sys
[2015.01.30 03:25:16 | 000,000,834 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2015.01.30 03:05:44 | 000,000,196 | ---- | C] () -- C:\Users\ihsan\Desktop\ksifre.rar
[2015.01.30 02:32:57 | 000,001,117 | ---- | C] () -- C:\Users\ihsan\Application Data\Microsoft\Internet Explorer\Quick Launch\Revo Uninstaller Pro.lnk
[2015.01.25 15:14:05 | 000,121,108 | ---- | C] () -- C:\Users\ihsan\Desktop\ihsan_Soydas_CV.pdf
[2015.01.18 17:50:24 | 000,121,105 | ---- | C] () -- C:\Users\ihsan\Desktop\pk altyazı.srt
[2015.01.18 17:36:34 | 000,002,212 | ---- | C] () -- C:\Users\ihsan\Application Data\Microsoft\Internet Explorer\Quick Launch\Subtitle Workshop.lnk
[2015.01.12 09:32:55 | 000,000,617 | ---- | C] () -- C:\Users\ihsan\Application Data\Microsoft\Internet Explorer\Quick Launch\Dev-C++.lnk
[2015.01.09 13:44:01 | 000,000,814 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2015.01.08 20:33:32 | 000,036,577 | ---- | C] () -- C:\Users\ihsan\Desktop\[kickass.so]cbm.hellsing.ultimate.1.10.complete.dual.audio.bdrip.720p.8bit.torrent
[2015.01.08 17:59:43 | 000,038,519 | ---- | C] () -- C:\Users\ihsan\Desktop\Hellsing Ultimate OVA 01-10.torrent
[2015.01.05 21:30:56 | 000,001,171 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2015.01.04 15:03:52 | 000,001,055 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk
[2015.01.01 14:43:03 | 000,000,048 | ---- | C] () -- C:\Users\ihsan\.gitconfig
[2014.12.23 17:31:21 | 000,007,639 | ---- | C] () -- C:\Users\ihsan\AppData\Local\Resmon.ResmonCfg
[2014.12.04 09:41:29 | 000,000,409 | ---- | C] () -- C:\Windows\MAXLINK.INI
[2014.11.27 18:14:40 | 000,008,570 | ---- | C] () -- C:\Windows\SysWow64\MBCfg32.ini
[2014.11.27 18:14:40 | 000,005,856 | ---- | C] () -- C:\Windows\SysWow64\MBCfgUninstall32.ini
[2014.11.27 18:14:40 | 000,002,835 | ---- | C] () -- C:\Windows\MBCfg_SP_APOIM.ini
[2014.11.27 18:14:40 | 000,002,783 | ---- | C] () -- C:\Windows\MBCfg_APOIM.ini
[2014.11.27 18:14:40 | 000,002,747 | ---- | C] () -- C:\Windows\MBCfg_HP_APOIM.ini
[2014.11.27 18:14:37 | 000,246,272 | ---- | C] () -- C:\Windows\SysWow64\APOMngr.DLL
[2014.11.27 18:14:37 | 000,074,240 | ---- | C] () -- C:\Windows\SysWow64\CmdRtr.DLL
[2014.11.24 23:55:20 | 000,000,600 | ---- | C] () -- C:\Users\ihsan\AppData\Local\PUTTY.RND
[2014.11.22 12:42:16 | 000,000,132 | ---- | C] () -- C:\Users\ihsan\AppData\Roaming\Adobe PNG Format CC Prefs
[2014.11.16 16:28:41 | 000,281,688 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2014.11.16 16:28:40 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2014.10.30 21:25:10 | 000,000,396 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2014.10.27 01:18:41 | 000,001,708 | ---- | C] () -- C:\Users\ihsan\Desktop.pem
[2014.10.09 16:29:05 | 000,216,064 | ---- | C] ( ) -- C:\Windows\SysWow64\lagarith.dll
[2014.10.09 16:29:04 | 000,650,752 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2014.10.09 16:29:04 | 000,243,200 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2014.10.09 16:29:04 | 000,218,200 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2014.10.09 16:29:02 | 000,112,640 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2014.09.30 16:18:03 | 000,002,255 | ---- | C] () -- C:\Windows\SysWow64\WimBootCompress.ini
[2014.09.28 23:08:33 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\Access.dat
[2014.09.28 18:52:31 | 000,103,936 | ---- | C] () -- C:\Windows\SysWow64\OEMLicense.dll
[2014.09.28 16:11:12 | 001,668,664 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014.09.28 16:07:33 | 000,044,104 | ---- | C] () -- C:\Windows\runSW.exe
[2014.09.28 16:07:32 | 000,451,072 | ---- | C] () -- C:\Windows\SysWow64\ISSRemoveSP.exe
[2014.09.28 15:20:54 | 000,068,608 | ---- | C] () -- C:\Windows\SysWow64\igfxexps32.dll
[2014.09.28 15:20:53 | 000,342,944 | ---- | C] () -- C:\Windows\SysWow64\igdmd32.dll
[2014.09.28 15:20:51 | 000,183,296 | ---- | C] () -- C:\Windows\SysWow64\igdde32.dll
[2014.09.28 15:20:51 | 000,142,848 | ---- | C] () -- C:\Windows\SysWow64\igdail32.dll
[2014.02.20 17:14:02 | 000,179,377 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat
[2013.09.26 12:58:58 | 000,255,392 | ---- | C] () -- C:\Windows\SysWow64\DeviceCount.exe
[2013.08.22 17:36:43 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2013.08.22 17:36:42 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2013.08.22 16:46:23 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2013.08.22 09:01:23 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2013.08.22 05:32:36 | 000,046,080 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2013.08.22 01:55:20 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2013.08.22 01:52:39 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2013.05.11 16:17:52 | 000,001,536 | ---- | C] () -- C:\Windows\SysWow64\IusEventLog.dll
 
[color=#E56717]========== ZeroAccess Check ==========[/color]
 
[2014.10.02 23:52:58 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014.08.31 02:15:33 | 021,197,152 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014.08.31 00:59:13 | 018,723,112 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2013.08.22 11:49:49 | 000,921,088 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2013.08.22 04:45:10 | 000,691,712 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2013.08.22 11:45:17 | 000,483,840 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
[color=#E56717]========== LOP Check ==========[/color]
 
[2015.01.23 13:36:02 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\.ACEStream
[2014.10.19 01:46:00 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\0ad
[2014.12.26 01:07:51 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\11bitstudios
[2014.10.18 17:18:09 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\360safe
[2015.01.08 20:09:28 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\ACEStream
[2015.01.12 18:08:06 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Aegisub
[2014.12.28 22:42:17 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Anvsoft
[2014.09.28 20:24:27 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Battle.net
[2015.01.09 21:09:49 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Bioshock
[2015.01.09 21:12:46 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Bioshock2Steam
[2014.12.16 17:05:09 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\ClumsyLeaf Software
[2014.12.17 20:42:43 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\CodeRush for VS .NET
[2015.01.30 03:29:04 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\DAEMON Tools Lite
[2015.01.12 09:39:00 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Dev-Cpp
[2014.12.17 20:44:01 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\DevExpress
[2014.10.18 21:44:00 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\DiskDefrag
[2015.01.30 17:52:15 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\DMCache
[2014.12.01 00:04:25 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Downloaded Installations
[2014.11.28 02:14:12 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\driveridentifier
[2014.12.22 17:06:02 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\e-academy Inc
[2014.12.20 22:46:53 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\ExLPT
[2015.01.30 03:29:04 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\FileZilla
[2015.01.14 21:59:52 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\fontconfig
[2014.10.30 17:54:21 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\GameRanger
[2015.01.06 05:37:10 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\GitHub
[2014.11.11 12:40:12 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\GlarySoft
[2015.01.05 21:31:50 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\huawei
[2015.01.30 17:50:43 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\IDM
[2014.10.02 20:17:58 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\JetBrains
[2014.09.29 17:52:07 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\LolClient
[2014.12.11 12:49:42 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\MPC-HC
[2014.10.30 20:07:45 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\My Battle for Middle-earth(tm) II Files
[2014.12.15 01:42:22 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Nitro
[2014.12.16 15:03:07 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Notepad++
[2014.12.04 16:35:59 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Nuance
[2014.12.02 13:04:39 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\NuGet
[2015.01.28 22:46:49 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Origin
[2014.11.10 01:53:33 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\PDAppFlex
[2014.10.18 22:34:28 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\PDF Architect 2
[2014.11.16 14:50:49 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\pdfforge_GmbH
[2014.10.19 14:52:27 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Python-Eggs
[2015.01.12 21:34:58 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Red Alert 3
[2015.01.30 02:45:59 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\RenPy
[2014.12.04 09:45:37 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\ScanSoft
[2014.09.28 22:59:42 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Steam
[2015.01.30 03:29:04 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\TeamViewer
[2015.01.31 04:35:57 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\tixati
[2014.10.30 17:55:20 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Tunngle
[2014.10.19 02:53:52 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\UDP Software
[2014.10.30 00:24:19 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Unity
[2015.01.30 03:45:23 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Wise Registry Cleaner
[2014.12.04 01:53:04 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\YCanPDF
[2014.12.04 11:08:02 | 000,000,000 | ---D | M] -- C:\Users\ihsan\AppData\Roaming\Zeon
 
[color=#E56717]========== Purity Check ==========[/color]
 
 
 
[color=#E56717]========== Alternate Data Streams ==========[/color]
 
@Alternate Data Stream - 237 bytes -> C:\Users\ihsan\SkyDrive:ms-properties
@Alternate Data Stream - 192 bytes -> C:\Windows:nlsPreferences
@Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:AEC0AC81
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:A303874F

< End of report >

OLT extras

OTL Extras logfile created on: 1.2.2015 23:08:36 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\ihsan\Desktop
64bit- Professional  (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17498)
Locale: 0000041f | Country: Türkiye | Language: TRK | Date Format: d.M.yyyy
 
7,92 Gb Total Physical Memory | 3,70 Gb Available Physical Memory | 46,76% Memory free
9,56 Gb Paging File | 3,13 Gb Available in Paging File | 32,74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 488,61 Gb Total Space | 250,90 Gb Free Space | 51,35% Space Free | Partition Type: NTFS
Drive D: | 442,38 Gb Total Space | 132,43 Gb Free Space | 29,94% Space Free | Partition Type: NTFS
 
Computer Name: IHOCAN | User Name: ihsan | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
 
[color=#E56717]========== Extra Registry (SafeList) ==========[/color]
 
 
[color=#E56717]========== File Associations ==========[/color]
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
.js[@ = WebIde80] -- C:\Program Files (x86)\JetBrains\PhpStorm 8.0.1\bin\PhpStorm.exe (JetBrains s.r.o.)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.js [@ = WebIde80] -- C:\Program Files (x86)\JetBrains\PhpStorm 8.0.1\bin\PhpStorm.exe (JetBrains s.r.o.)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = ChromeHTML] -- Reg Error: Key error. File not found
 
[color=#E56717]========== Shell Spawning ==========[/color]
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
[color=#E56717]========== Security Center Settings ==========[/color]
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = AC 1C AE C5 46 9F CE 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" =  [binary data]
 
[b]64bit:[/b] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Upgrade]
"UpgradeTime" = Reg Error: Unknown registry data type -- File not found
 
[color=#E56717]========== Firewall Settings ==========[/color]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
 
[color=#E56717]========== Authorized Applications List ==========[/color]
 
 
[color=#E56717]========== Vista Active Open Ports Exception List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{057886F9-FD50-4BA1-BC74-7848C9A9B97C}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{0A2F73A0-187D-45E1-B893-73A9EA2127BD}" = lport=445 | protocol=6 | dir=in | app=system | 
"{1D40CC2C-4A94-4D86-AE02-D912A2747778}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{2358890E-2268-4446-8F09-2C00C6EF94BF}" = lport=6918 | protocol=6 | dir=in | app=c:\program files (x86)\microsoft visual studio 14.0\common7\ide\devenv.exe | 
"{25606998-6953-4992-9B7E-45BC75727763}" = lport=6917 | protocol=6 | dir=in | app=c:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe | 
"{266EAF79-2DBD-458D-AF05-2E9D7D965715}" = lport=6919 | protocol=6 | dir=in | app=c:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe | 
"{332351D4-DD4E-45FC-A8DE-96B496C6659C}" = lport=47984 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{33654EE8-1A2E-4EB7-BEE4-15D2EBE451F5}" = lport=5353 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamsvc.exe | 
"{37B869EC-99C5-4271-A7AA-0B0A621E3A28}" = lport=3702 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe | 
"{41C2FB7B-355A-4F82-8D0D-342A90955F8D}" = lport=6920 | protocol=6 | dir=in | app=c:\program files (x86)\microsoft visual studio 14.0\common7\ide\devenv.exe | 
"{44E86E88-A7D1-4864-AB7E-C5BE8C679518}" = lport=48000 | protocol=17 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{4DF08375-F9AD-4CE3-9385-732F300694CC}" = lport=443 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | 
"{51B1A66D-97E0-4B86-9D09-DD9D9AE4B67A}" = rport=10243 | protocol=6 | dir=out | app=system | 
"{5540B78E-5F12-45C0-BAB3-7873D01B8F4B}" = lport=47991 | protocol=6 | dir=in | app=c:\program files\nvidia corporation\nvstreamsrv\nvstreamer.exe | 
"{72A5F75E-EA04-4927-BA64-B50195F399B5}" = lport=6916 | protocol=6 | dir=in | app=c:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe | 
"{7691CE27-58FD-4D51-9D47-2CC07F0C3072}" = lport=5353 | protocol=17 | dir=in | app=c:\program files (x86)\google\chrome\application\chrome.exe | 
"{79889F71-2474-4BCF-B36D-91AC6D788836}" = lport=6918 | protocol=6 | dir=in | app=c:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe | 
"{7B409DE8-30A1-4A36-BCFF-8142B386970A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 | 
"{80F40683-0993-4CFA-AAC3-0078F65708C1}" = rport=138 | protocol=17 | dir=out | app=system | 
"{936192C6-0B74-454D-AD31-39A2B10850FF}" = lport=80 | protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\netservice\nvnetworkservice.exe | 
"{9423514B-6891-4F12-BC32-59AF55A87386}" = lport=137 | protocol=17 | dir=in | app=system | 
"{98F38E91-4C91-4378-9FEA-EF0986C01E13}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{9938CA6E-AAF2-4AA9-985E-DE9FC50143FE}" = lport=10243 | protocol=6 | dir=in | app=system | 
"{9E4EEDC4-0BDD-4973-B375-DA9CBE47EC44}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{A5DEE671-70CA-4335-96F5-86753223C185}" = lport=138 | protocol=17 | dir=in | app=system | 
"{A865C585-F41D-4D67-8180-707F7717BE41}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{B1E9320F-8A1B-4FC9-9918-DF6369B182C5}" = lport=6917 | protocol=6 | dir=in | app=c:\program files (x86)\microsoft visual studio 14.0\common7\ide\devenv.exe | 
"{BD486FD2-ABC8-44E4-B9A2-2333F89FDF68}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{BDE19143-476A-421F-A64E-9E69D8EA02A5}" = rport=137 | protocol=17 | dir=out | app=system | 
"{C0B0FFB1-E250-4515-A297-BE55295D348B}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office15\outlook.exe | 
"{C5620D34-ACA6-4604-B8A9-B3E1B4EF72CA}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{C5C47625-BE30-43FA-8940-94F81B698813}" = lport=6915 | protocol=6 | dir=in | app=c:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe | 
"{C74D4C7A-0DA5-4CDA-9E60-2CFC78413D2E}" = lport=6916 | protocol=6 | dir=in | app=c:\program files (x86)\microsoft visual studio 14.0\common7\ide\devenv.exe | 
"{C909FCDF-0869-4E73-836F-D5B179725ACD}" = rport=445 | protocol=6 | dir=out | app=system | 
"{C9BA834F-7F4C-4BB4-B690-233259B0F3B0}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{CEB5808F-08DF-4B08-9FF4-D2987281778A}" = lport=6915 | protocol=6 | dir=in | app=c:\program files (x86)\microsoft visual studio 14.0\common7\ide\devenv.exe | 
"{D0CE9E65-72ED-4F36-B080-319EF9B2AAB3}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{D5B3C189-3B26-43B2-B6F0-6D7A026FC821}" = lport=6920 | protocol=6 | dir=in | app=c:\program files (x86)\microsoft visual studio 11.0\common7\ide\devenv.exe | 
"{DED83FA9-C181-418C-88FE-CC88C5D0FACE}" = lport=3702 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft visual studio 14.0\common7\ide\devenv.exe | 
"{E03C4704-BF03-4389-A8CE-31938212C5EB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe | 
"{F25ADA54-820E-4C0D-8BC6-0BD9DD50CAA6}" = rport=139 | protocol=6 | dir=out | app=system | 
"{F6C2A97E-E8B1-446E-8D27-E1F1F37E53D5}" = lport=139 | protocol=6 | dir=in | app=system | 
"{F720045E-6F16-4A4C-8A61-15916B6E88D3}" = lport=6919 | protocol=6 | dir=in | app=c:\program files (x86)\microsoft visual studio 14.0\common7\ide\devenv.exe | 
"{FE29B487-4EC8-4F50-94AA-526C8F590C96}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
 
[color=#E56717]========== Vista Active Application Exception List ==========[/color]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0126A443-72A2-4033-A1B9-502AB80D4E56}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\tropico 4\tropico4.exe | 
"{03D37732-15E3-4641-A655-E7AE6644EE17}" = protocol=17 | dir=in | app=d:\steam\bin\steamwebhelper.exe | 
"{05357AF9-27A4-4559-A52C-DA38075CD79D}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\farcry\bin32\farcry.exe | 
"{05C1F9F8-3328-4E83-96EB-C1F9DDE92DF5}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe | 
"{0680DC8A-397D-4D3A-BE28-F150033E6697}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.1267\agent.exe | 
"{0AB18283-87DF-4976-BA26-CF22B48C6EED}" = protocol=17 | dir=in | app=c:\program files (x86)\nuance\omnipage19\omnipage19.exe | 
"{10E76BCD-A21A-420A-82D2-03E1CFDB7F9C}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{127978C3-41D3-4A0D-B9EC-21FFD2F3345C}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\democracy 3\democracy3.exe | 
"{138780A9-0EED-4825-8768-7892EB9D732D}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{14883E3B-8074-48E0-82E2-FE52BAA85158}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{16D0B6DC-C488-4C0B-BFBA-E6285F50182D}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\rust\legacy\rust.exe | 
"{199E5793-49CD-48C0-A23A-65C5A9C2F690}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\age of empires 3\bin\age3.exe | 
"{1CF2C385-92DE-4470-A4F7-ECABF7E4F5DB}" = protocol=6 | dir=in | app=c:\program files (x86)\nuance\omnipage19\ppmv.exe | 
"{20F37969-ED30-4AE1-B779-65A6CE09DA3A}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe | 
"{23ADC30D-37EA-46FD-9B71-EF2F3F7A0065}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\age2hd\launcher.exe | 
"{2415F0F0-F2B9-4FDF-A8D0-8DFB6C3AD7E4}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{2B2331F5-0178-40B3-B1B9-47E3CA3F4954}" = protocol=58 | dir=out | [email protected],-28546 | 
"{2F1CCF50-DDF9-408D-8206-EE43A56572BC}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\naruto shippuden ultimate ninja storm 3 full burst\ns3fb_launcher.exe | 
"{30C0F663-EC6C-40DC-AAE9-F6F45F5670B5}" = dir=out | [email protected]{microsoft.binghealthandfitness_3.0.4.254_x64__8wekyb3d8bbwe?ms-resource://microsoft.binghealthandfitness/resources/apptitle} | 
"{32E99157-C95D-40C4-92A8-645E44B586B8}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\rust\rust.exe | 
"{362930BF-799E-4B77-B285-24A6EE268E1A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{36CFD216-6F58-4C84-87F0-DBE154F66545}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer_service.exe | 
"{394228DA-5007-41E2-BE8E-C35917342847}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{3A78718F-17C7-44E3-8C63-1498B1E526E3}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\rust\legacy\rust.exe | 
"{3C3853EB-97DC-4074-A42D-9E741E6CDDE1}" = dir=out | [email protected]{microsoft.bingfoodanddrink_3.0.4.253_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfoodanddrink/resources/apptitlewithbranding} | 
"{3D841C80-03CD-4E4B-8828-E4039AC38FC1}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\age2hd\launcher.exe | 
"{3F5F854B-542B-42D3-B1A2-B03049AF3B29}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{3F79536E-12F4-4F89-A858-E3829B752251}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{3FFAD54A-CCDC-4E9A-A36F-0118AB1BD055}" = dir=out | [email protected]{microsoft.bingfinance_3.0.4.253_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/brandedapptitle} | 
"{409185D6-B46D-4D54-870F-6E1183C3DE9F}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{4282FE99-8560-4BC7-9576-5F3ED84E263F}" = dir=in | name=checkpoint.vpn | 
"{4709DE60-BD13-464C-815C-9EBADAAB1560}" = protocol=17 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | 
"{4A4A3867-1C17-4884-B4CB-8B3966B92AEA}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\far cry 2\bin\farcry2.exe | 
"{4B1E28A9-0DA6-46DB-8B4A-FF965E8202CA}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{4B4CA474-9569-4FDF-9766-61B452DA4F12}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{4BE4C243-D51B-4D88-B0B2-6BF35028F21A}" = protocol=17 | dir=in | app=c:\program files (x86)\360\total security\safemon\qhsafetray.exe | 
"{4C60F7FF-9FB5-40EB-9B72-855FB47654BE}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\age of empires 3\bin\age3y.exe | 
"{4D54BCFB-47D5-4DF7-AE48-70F68EFD696E}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\far cry 2\bin\fc2serverlauncher.exe | 
"{4DD886AD-E6E0-474D-A9DC-302048A736AE}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer.exe | 
"{4F3D88D8-0700-42C9-A93E-CDF599A11E66}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\skyrim\skyrimlauncher.exe | 
"{535D8527-9C85-4407-9998-9D249EFA0563}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\far cry 2\bin\fc2editor.exe | 
"{540DDFBE-A5F3-45A7-AD11-89591963E718}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer.exe | 
"{542401E1-FEC4-4DFB-8852-6098C7D637F9}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{54606235-C8D0-4E21-854E-A3F06A732E9A}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\grand theft auto iv\gtaiv\launchgtaiv.exe | 
"{548DCF8C-BFF2-4BA4-AA88-FBAF9AC8BCC6}" = dir=in | [email protected]{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{560448D6-095C-4907-B046-AC7F710701A7}" = dir=in | name=sonicwall.mobileconnect | 
"{5634046F-75FB-40AD-8B8A-15065036D452}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\tropico 4\tropico4.exe | 
"{5698AA11-C29C-4BC8-88A3-2E64AE3574C2}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\teamviewer_service.exe | 
"{56C202E0-5CB9-416B-A456-28A9E99E0EE7}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\farcry\bin32\farcry.exe | 
"{59E6284D-6A16-4531-9EC7-E76A26BE466C}" = protocol=17 | dir=in | app=c:\program files (x86)\nuance\omnipage19\ppmv.exe | 
"{5A716DCB-3988-47FD-A648-A60A68DCD6C1}" = protocol=58 | dir=in | [email protected],-28545 | 
"{5BB0D020-751A-49CB-A255-A869E8E38370}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.3372\agent.exe | 
"{5C05DD69-18DE-4C9D-9ADB-DFCE216D3DF4}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{5D19A7D9-CBEC-4F6C-895B-F1F771887BAA}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\far cry 3\bin\farcry3.exe | 
"{5D3DDB40-E75E-42F8-B6F6-711E0B19D665}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\the battle for middle-earth (tm) ii\game.dat | 
"{5F4632C0-D5B1-40C3-B0D9-E3A759C81B9E}" = dir=out | name=sonicwall.mobileconnect | 
"{602AB22D-BF38-4C29-8DCE-4696B9B957C3}" = protocol=17 | dir=in | app=c:\program files (x86)\nuance\omnipage19\ereg\ereg.exe | 
"{6413835B-BE4F-4BB7-A4AA-A096851C92F6}" = dir=out | [email protected]{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | 
"{6A2DE2CA-CC5A-46A9-A5F4-8DD4CDBB9CC0}" = dir=out | [email protected]{microsoft.zunevideo_2.6.434.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} | 
"{6C18FA54-33A4-4C5A-AFE1-12481FF64C27}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\bioshock infinite\binaries\win32\bioshockinfinite.exe | 
"{70B9FE59-D8B2-476B-BD87-73E2F686179E}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\payday 2\payday2_win32_release.exe | 
"{70CF0C24-EB96-40BF-8893-E5F1BC15788E}" = protocol=17 | dir=in | app=c:\program files (x86)\360\total security\liveupdate360.exe | 
"{71CA6F0E-953F-4FB3-AA13-F5049557E2E5}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\far cry 2\bin\fc2benchmarktool.exe | 
"{7392889E-C8FA-4084-87C0-E9FDDA6F4E5A}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\garrysmod\hl2.exe | 
"{73EC1133-B803-40C0-BB69-35F4AC51B00D}" = protocol=6 | dir=in | app=c:\program files (x86)\360\total security\liveupdate360.exe | 
"{7473F22F-D92C-4A40-8B37-A90844EE129B}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\grand theft auto iv\gtaiv\launchgtaiv.exe | 
"{793E7749-C3CC-4B90-868D-5EA018265E4C}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe | 
"{7AB77D0C-5422-4B9C-8115-6EAE0316559D}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\rust\rust.exe | 
"{7B9BEB70-4211-4A18-B6F3-69DED542190F}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe | 
"{7C3E5909-C1B3-4EDE-AD9A-3F4377964919}" = protocol=6 | dir=in | app=c:\program files (x86)\360\total security\safemon\qhsafetray.exe | 
"{7CDBB61E-EB45-4D93-9040-3D7BA69B7FA9}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe | 
"{7DFCC02F-194C-4E88-B826-C1EB8DDA470A}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{81C7CBCD-A759-4A23-A7D7-C3614B321DEE}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{841DF171-40EA-48E0-A7F8-6765EA04FA5F}" = protocol=6 | dir=in | app=c:\program files (x86)\battle.net\battle.net.exe | 
"{8581D7A1-98F6-48A1-8347-F13F41286785}" = protocol=6 | dir=in | app=d:\steam\steam.exe | 
"{864D11B3-9CDF-4795-A8D8-D56C625035D6}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{87E0ADAF-ACFB-4E7B-ADFA-91C54A8E9716}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\age of empires 3\bin\age3x.exe | 
"{890A9C1B-8A37-40EB-9994-246D792226E9}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe | 
"{8ADA25A7-BE4B-4E19-A339-0DA40CC73229}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{8F047B31-A59B-45B9-AF1F-2D168A344DFB}" = dir=in | [email protected]{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{8FBD890B-E096-4CC0-BCF9-5ECB0BF2BE48}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\command and conquer red alert ii\ra2launcher.exe | 
"{91495ACF-1835-42FC-BF79-DE6F9DA573BF}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\far cry 2\bin\fc2benchmarktool.exe | 
"{947EE26D-40D1-4164-869C-C755AE1EC680}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\dont_starve\bin\dontstarve_steam.exe | 
"{97D930D2-6753-461B-A46C-FDE3837AE61C}" = protocol=17 | dir=in | app=d:\steam\steam.exe | 
"{9E3D57FC-7C37-4424-9352-4831E97D029D}" = dir=out | [email protected]{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} | 
"{A3DC0883-DBB3-465C-B845-688A52247411}" = dir=out | [email protected]{microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} | 
"{A5FC7F68-3956-43B1-A9A3-269016508F25}" = dir=out | name=skype | 
"{A81A616D-18B6-4B77-8D2B-E9BDFBC06C37}" = dir=out | [email protected]{microsoft.zunemusic_2.6.653.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} | 
"{A8D3CE6D-8D14-4463-8D36-443EF0D1243F}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\payday 2\payday2_win32_release.exe | 
"{A91FE23B-AD7B-4949-A835-B43EA138C943}" = protocol=6 | dir=in | app=d:\steam\bin\steamwebhelper.exe | 
"{AAB1FB15-1D98-4813-91B6-AA03ED64574A}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\far cry 2\bin\fc2editor.exe | 
"{ABBF6EF4-9241-4E93-A798-F362E9D7DEA0}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\far cry 3\bin\fc3updatersteam.exe | 
"{AD1E9EBA-C3A2-4B83-B9D4-52F11B71E2F0}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\far cry 3\bin\farcry3.exe | 
"{AE27102E-FBDD-49E3-AC1B-6084817B1DE5}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\naruto shippuden ultimate ninja storm 3 full burst\ns3fb_launcher.exe | 
"{AEAE680B-F48D-423F-BF4A-65F1DFE7106F}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\age of empires 3\bin\age3.exe | 
"{B0B2A575-FC9F-4388-9594-652855EB61B4}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\age of empires 3\bin\age3x.exe | 
"{B2E05566-A361-4ADC-8778-A9C121FB8B7A}" = protocol=6 | dir=out | app=system | 
"{B3E0D702-E390-4355-81B1-CE8E3CE47622}" = protocol=17 | dir=in | app=c:\program files (x86)\360\total security\liveupdate360.exe | 
"{B3E64D47-FACC-4911-AE7C-5F2F71712541}" = protocol=1 | dir=out | [email protected],-28544 | 
"{B70214B9-02EF-48CE-9E7C-D49972A5681F}" = protocol=6 | dir=in | app=c:\program files (x86)\360\total security\safemon\qhsafetray.exe | 
"{B743D918-A821-47B8-A117-82096DCD2753}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\the battle for middle-earth (tm) ii\game.dat | 
"{B86AE31C-183D-414F-B5C5-85F44A497D31}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.3372\agent.exe | 
"{B8E15F41-83AF-4D5B-8A1E-DFC767CBDF6A}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\left 4 dead 2\left4dead2.exe | 
"{B8FF556E-47CA-4A40-9D3E-0A23C6BBB5D5}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\far cry 3\bin\fc3updatersteam.exe | 
"{BB5588E6-B5C8-4A02-8D3D-E76CE5341512}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\insurgency2\insurgency.exe | 
"{BC283488-FE6D-4019-8685-E000B12681D6}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\skyrim\skyrimlauncher.exe | 
"{BD38B63F-1575-453A-AFBD-735DECA4F752}" = dir=out | [email protected]{microsoft.bingsports_3.0.4.244_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/brandedapptitle} | 
"{BD669162-A081-4541-9374-3531444463AE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{BD7624B1-66BD-4A71-A4B0-89FED5569752}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\command and conquer generals zero hour\generals.exe | 
"{BF4B00A8-EEAA-4761-B209-2C8152E7B79B}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\age of empires 3\bin\age3y.exe | 
"{BF6A702C-5EAF-4DF1-9041-3F7CA4FD7660}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\bioshock\builds\release\bioshock.exe | 
"{C25D12BC-3AB1-4691-801E-9A6BD99971D4}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe | 
"{C65D020B-260A-4F9F-8300-8C2ABCC455A1}" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\command and conquer generals zero hour\generals.exe | 
"{C69CFC6D-674E-4A26-8E29-B08D6CC22A10}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe | 
"{C878661E-55B4-4403-B68A-271BB15B6C5C}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{CABF5220-997D-4DF5-AEFF-E0CF717F8299}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\bioshock\builds\release\bioshock.exe | 
"{CE8BF53B-BFE1-4944-9DE4-647997442744}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | 
"{CF4D3970-0E9F-48EC-BEAE-FB25338E4967}" = dir=out | [email protected]{microsoft.bingmaps_2.1.3230.2048_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} | 
"{D158A186-AE93-4E56-B986-6930DC846012}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\farcry\bin32\farcryconfigurator.exe | 
"{D214FD1E-AB4D-42B3-95B2-7C81DAEC0C36}" = dir=out | [email protected]{microsoft.xboxlivegames_2.0.139.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} | 
"{D4A4C179-C532-4C4A-9F2B-1027B060E764}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{D6980480-941A-4DF6-AB81-3734ECD3D779}" = dir=out | name=junipernetworks.junospulsevpn | 
"{D71BD33E-761F-4C44-A6AD-794E4C5095F3}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\farcry\bin32\farcryconfigurator.exe | 
"{D77007DE-0EF5-455D-B433-4C3392CB1298}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{D7E8509F-CA71-488C-9491-A6B06428F80E}" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\command and conquer red alert ii\ra2launcher.exe | 
"{DA939CE8-B740-42B7-86E3-755895895A19}" = dir=in | [email protected]{microsoft.windowsreadinglist_6.3.9654.20540_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsreadinglist/resources/apppackagename} | 
"{DB59588E-ED90-4C47-A7B5-7929DD0C0BD2}" = dir=out | name=checkpoint.vpn | 
"{DD39E4C4-A899-4DEA-9E3C-7E80B8275410}" = protocol=6 | dir=in | app=c:\program files (x86)\360\total security\liveupdate360.exe | 
"{E27264BA-827E-4E80-B6D6-CA8B0ABECB61}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\garrysmod\hl2.exe | 
"{E2C18D5F-7B2E-49A1-8F47-285EFDD9489F}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\far cry 3 blood dragon\bin\fc3bdupdatersteam.exe | 
"{E3705053-1B1A-4550-A98F-CA9D6A54B528}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\democracy 3\democracy3.exe | 
"{E3AF0EB4-5899-455C-BB46-A0156FAF7B56}" = dir=out | [email protected]{microsoft.bingnews_3.0.4.268_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/brandedapptitle} | 
"{EBF7A667-07E4-4C2A-B8F4-756F122BB468}" = protocol=1 | dir=in | [email protected],-28543 | 
"{EC799E33-72BA-42D7-9127-DEFE68F9799D}" = dir=in | name=junipernetworks.junospulsevpn | 
"{F0028F60-E013-4903-A943-0F5348037726}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\left 4 dead 2\left4dead2.exe | 
"{F022D7C5-A69F-407D-8075-79FBFECC7DE0}" = protocol=6 | dir=in | app=c:\program files (x86)\nuance\omnipage19\ereg\ereg.exe | 
"{F028062E-5B50-4570-A284-846A212E0AFA}" = dir=out | [email protected]{microsoft.bingtravel_3.0.4.212_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/brandedapptitle} | 
"{F1123C4D-67B2-4BDF-80B3-6E63EFCEFD2E}" = protocol=6 | dir=in | app=c:\program files (x86)\nuance\omnipage19\omnipage19.exe | 
"{F1CA665F-3FB1-4021-9ABA-FD547CF695ED}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\ucmapi.exe | 
"{F2909413-7820-4C1F-8121-84674A4E4305}" = dir=in | name=skype | 
"{F319F0EA-9FB5-4286-9BD1-0350F70ECA26}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\insurgency2\insurgency.exe | 
"{F3824B7D-A0BA-4A1F-9BD6-32442916B258}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{F3DEC0BB-E009-4FBA-ACD1-435E4ED9BF1B}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\far cry 2\bin\fc2serverlauncher.exe | 
"{F42199BD-5979-480F-AECA-84D26E470D9B}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office15\lync.exe | 
"{F4A8609C-CE82-4495-919D-80677AA77F67}" = protocol=17 | dir=in | app=c:\program files (x86)\360\total security\safemon\qhsafetray.exe | 
"{F4E4667C-20BA-4988-9545-BA4E51399123}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\bioshock infinite\binaries\win32\bioshockinfinite.exe | 
"{F6309E61-9E72-4059-89DB-FF80A69AA7BA}" = dir=out | [email protected]{microsoft.bingweather_3.0.4.249_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/brandedapptitle} | 
"{F64300AD-D559-4000-BD45-0997BCC8E70A}" = dir=out | name=f5.vpn.client | 
"{F77E5446-4378-4E99-8B7A-7061AAAEA193}" = dir=in | name=f5.vpn.client | 
"{F7A15C4E-1488-42DB-9CF4-C76F6A09EC28}" = protocol=6 | dir=in | app=d:\steam\steamapps\common\far cry 3 blood dragon\bin\fc3bdupdatersteam.exe | 
"{F87AF30A-3B9D-4729-99A5-8D4FCC68B348}" = protocol=17 | dir=in | app=d:\steam\steamapps\common\far cry 2\bin\farcry2.exe | 
"{FFBF8BF5-4722-4B35-8B04-C5C38191DDA2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"TCP Query User{0052E339-0AEA-4D76-889D-66A0BC72810D}C:\users\ihsan\appdata\roaming\acestream\engine\ace_engine.exe" = protocol=6 | dir=in | app=c:\users\ihsan\appdata\roaming\acestream\engine\ace_engine.exe | 
"TCP Query User{29B55146-9213-43CE-8688-52D5DF5D6800}C:\users\ihsan\appdata\local\popcorn time\node-webkit\popcorn time.exe" = protocol=6 | dir=in | app=c:\users\ihsan\appdata\local\popcorn time\node-webkit\popcorn time.exe | 
"TCP Query User{3A6EC144-55E2-4713-A9D1-81AE77EB3EDC}C:\users\ihsan\appdata\roaming\acestream\player\ace_player.exe" = protocol=6 | dir=in | app=c:\users\ihsan\appdata\roaming\acestream\player\ace_player.exe | 
"TCP Query User{3C8F9155-5817-4FB7-B0E4-DBD69B567925}C:\program files (x86)\borderlands 2\binaries\win32\borderlands2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\borderlands 2\binaries\win32\borderlands2.exe | 
"TCP Query User{4A0ADFAA-A969-4D77-B33D-0F3C956B6371}C:\program files (x86)\origin games\command and conquer red alert ii\gamemd.exe" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\command and conquer red alert ii\gamemd.exe | 
"TCP Query User{5B02265A-ABE1-437A-BE64-AE9CA5302F79}C:\users\ihsan\appdata\roaming\acestream\engine\ace_engine.exe" = protocol=6 | dir=in | app=c:\users\ihsan\appdata\roaming\acestream\engine\ace_engine.exe | 
"TCP Query User{60120D4B-2000-4EE1-A7A7-EFE839F52689}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"TCP Query User{6803C4D8-DBA2-4E89-A1E6-7B818D672D57}C:\users\ihsan\appdata\roaming\gameranger\gameranger\gameranger.exe" = protocol=6 | dir=in | app=c:\users\ihsan\appdata\roaming\gameranger\gameranger\gameranger.exe | 
"TCP Query User{78C33420-AFDF-4148-BB48-D25C6728420A}D:\steam\steamapps\common\the witcher 2\bin\witcher2.exe" = protocol=6 | dir=in | app=d:\steam\steamapps\common\the witcher 2\bin\witcher2.exe | 
"TCP Query User{888D45E7-C44E-4DA8-9AB2-266621427F69}D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe" = protocol=6 | dir=in | app=d:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe | 
"TCP Query User{89BF1D71-8C00-49AE-932C-305678B507E4}C:\program files\tixati\tixati.exe" = protocol=6 | dir=in | app=c:\program files\tixati\tixati.exe | 
"TCP Query User{A917ABF3-396F-441C-A519-C4762B93A6EA}C:\users\ihsan\appdata\local\popcorn time\node-webkit\popcorn time.exe" = protocol=6 | dir=in | app=c:\users\ihsan\appdata\local\popcorn time\node-webkit\popcorn time.exe | 
"TCP Query User{AE2A56FD-1607-4509-8952-15E325FBD011}C:\program files (x86)\skype\phone\skype.exe" = protocol=6 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"TCP Query User{B49A5DDE-7B53-4BC4-8C9C-B26DEE10E2FB}C:\users\ihsan\desktop\oyun\command.and.conquer.red.alert.3.multi4.full-rip.skullptura\red alert 3\data\ra3_1.0.game" = protocol=6 | dir=in | app=c:\users\ihsan\desktop\oyun\command.and.conquer.red.alert.3.multi4.full-rip.skullptura\red alert 3\data\ra3_1.0.game | 
"TCP Query User{D6A9B620-37B6-44BF-94AF-F33B009223C3}C:\program files\tixati\tixati.exe" = protocol=6 | dir=in | app=c:\program files\tixati\tixati.exe | 
"TCP Query User{D96EDA44-EF4C-40F3-8DF8-13F7BC29BE3D}D:\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe" = protocol=6 | dir=in | app=d:\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe | 
"TCP Query User{D97AA405-3C78-4B4E-8EF6-1F63B6851EFC}C:\program files (x86)\origin games\command and conquer generals zero hour\command and conquer generals zero hour\generals_origin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\origin games\command and conquer generals zero hour\command and conquer generals zero hour\generals_origin.exe | 
"TCP Query User{EAD243A7-7414-41F9-9351-3D686FEC1279}D:\steam\steamapps\common\naruto shippuden ultimate ninja storm 3 full burst\ns3fb.exe" = protocol=6 | dir=in | app=d:\steam\steamapps\common\naruto shippuden ultimate ninja storm 3 full burst\ns3fb.exe | 
"TCP Query User{EF4264B5-ED7F-40C4-8F20-7C7C72262BAE}C:\program files (x86)\jetbrains\phpstorm 8.0.1\bin\phpstorm.exe" = protocol=6 | dir=in | app=c:\program files (x86)\jetbrains\phpstorm 8.0.1\bin\phpstorm.exe | 
"TCP Query User{F36E106F-044B-4F36-AD31-F276E299742B}D:\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe" = protocol=6 | dir=in | app=d:\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe | 
"TCP Query User{FF049659-2305-40B3-8D0A-77793F1D4101}C:\program files (x86)\internet download manager\idman.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet download manager\idman.exe | 
"UDP Query User{02A98FD3-A10F-49A1-AFE1-D8F82CDD6EF2}D:\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe" = protocol=17 | dir=in | app=d:\steam\steamapps\common\grand theft auto iv episodes from liberty city\eflc\eflc.exe | 
"UDP Query User{2D465E7D-113E-43D1-9C0C-BBA53E1D875F}C:\users\ihsan\appdata\roaming\acestream\player\ace_player.exe" = protocol=17 | dir=in | app=c:\users\ihsan\appdata\roaming\acestream\player\ace_player.exe | 
"UDP Query User{32BA3AE0-2E15-4A9E-A671-7879E30E464F}C:\users\ihsan\appdata\roaming\gameranger\gameranger\gameranger.exe" = protocol=17 | dir=in | app=c:\users\ihsan\appdata\roaming\gameranger\gameranger\gameranger.exe | 
"UDP Query User{38A47174-1352-4544-85AE-E773A4013F13}C:\users\ihsan\appdata\local\popcorn time\node-webkit\popcorn time.exe" = protocol=17 | dir=in | app=c:\users\ihsan\appdata\local\popcorn time\node-webkit\popcorn time.exe | 
"UDP Query User{4800CCA5-575B-4D1A-BEFF-FDC7BF88A820}D:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe" = protocol=17 | dir=in | app=d:\steam\steamapps\common\far cry 3\bin\farcry3_d3d11.exe | 
"UDP Query User{6CA6AAF0-2A2E-4565-9DD1-F9FC7E2E72FF}C:\program files\tixati\tixati.exe" = protocol=17 | dir=in | app=c:\program files\tixati\tixati.exe | 
"UDP Query User{80270314-66EA-4DBE-8BA6-FD46FDC58DD6}D:\steam\steamapps\common\the witcher 2\bin\witcher2.exe" = protocol=17 | dir=in | app=d:\steam\steamapps\common\the witcher 2\bin\witcher2.exe | 
"UDP Query User{8C1F2327-525C-449A-BE45-5A0B438FD92F}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"UDP Query User{8C53D493-2B05-422B-BA6D-136340D58F2B}C:\program files (x86)\internet download manager\idman.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet download manager\idman.exe | 
"UDP Query User{9C77623E-ACE0-4460-83B6-729EB5B40FA7}C:\users\ihsan\appdata\roaming\acestream\engine\ace_engine.exe" = protocol=17 | dir=in | app=c:\users\ihsan\appdata\roaming\acestream\engine\ace_engine.exe | 
"UDP Query User{A7479C3B-EDC0-4CCE-809F-6410E5DB2B2C}C:\program files\tixati\tixati.exe" = protocol=17 | dir=in | app=c:\program files\tixati\tixati.exe | 
"UDP Query User{B43A3BF8-6549-4F8D-B3F0-A7F6B75E3D5B}C:\users\ihsan\desktop\oyun\command.and.conquer.red.alert.3.multi4.full-rip.skullptura\red alert 3\data\ra3_1.0.game" = protocol=17 | dir=in | app=c:\users\ihsan\desktop\oyun\command.and.conquer.red.alert.3.multi4.full-rip.skullptura\red alert 3\data\ra3_1.0.game | 
"UDP Query User{B6EF662B-F6BF-4624-9525-BE0E44191A1D}D:\steam\steamapps\common\naruto shippuden ultimate ninja storm 3 full burst\ns3fb.exe" = protocol=17 | dir=in | app=d:\steam\steamapps\common\naruto shippuden ultimate ninja storm 3 full burst\ns3fb.exe | 
"UDP Query User{C1750443-BC85-4646-B9A4-B87EF1B7F4ED}C:\program files (x86)\origin games\command and conquer red alert ii\gamemd.exe" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\command and conquer red alert ii\gamemd.exe | 
"UDP Query User{C5BC2CCC-3512-4919-A48A-C5752743858E}C:\users\ihsan\appdata\roaming\acestream\engine\ace_engine.exe" = protocol=17 | dir=in | app=c:\users\ihsan\appdata\roaming\acestream\engine\ace_engine.exe | 
"UDP Query User{C9D17572-263A-4C6D-8477-15A77904B7CF}D:\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe" = protocol=17 | dir=in | app=d:\steam\steamapps\common\grand theft auto iv\gtaiv\gtaiv.exe | 
"UDP Query User{D26A667B-1EE7-477F-B9C1-09DFA72B9D87}C:\program files (x86)\skype\phone\skype.exe" = protocol=17 | dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"UDP Query User{D2C8DF79-CF13-41DD-89CA-9F9712CE1645}C:\program files (x86)\jetbrains\phpstorm 8.0.1\bin\phpstorm.exe" = protocol=17 | dir=in | app=c:\program files (x86)\jetbrains\phpstorm 8.0.1\bin\phpstorm.exe | 
"UDP Query User{D82D6BB7-DA27-42D1-984D-DC0DE36DA6A1}C:\program files (x86)\origin games\command and conquer generals zero hour\command and conquer generals zero hour\generals_origin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\origin games\command and conquer generals zero hour\command and conquer generals zero hour\generals_origin.exe | 
"UDP Query User{E32868B0-19D4-4540-9EFD-B5E1DDE93078}C:\users\ihsan\appdata\local\popcorn time\node-webkit\popcorn time.exe" = protocol=17 | dir=in | app=c:\users\ihsan\appdata\local\popcorn time\node-webkit\popcorn time.exe | 
"UDP Query User{E9C9ABA4-4170-4C63-BACD-CB32EF2D90B7}C:\program files (x86)\borderlands 2\binaries\win32\borderlands2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\borderlands 2\binaries\win32\borderlands2.exe | 
 
[color=#E56717]========== HKEY_LOCAL_MACHINE Uninstall List ==========[/color]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{018F864E-BF5D-4F2A-94F9-F495DAE3F6CD}" = Microsoft Visual Studio 2015 Preview Performance Collection Tools
"{020CDFE0-C127-4047-B571-37C82396B662}" = Microsoft SQL Server 2014 Transact-SQL ScriptDom 
"{033DFDB6-AAFA-4AF0-B5CA-93276FA910EF}" = SQL Server 2012 Distributed Replay
"{03DE1AEE-D3FA-4BF3-9150-28F54815E888}" = Build Tools - amd64
"{07F0FC77-282E-42E5-BAE6-B8C098F8453E}" = Microsoft Web Deploy 3.6 Beta3
"{0E8670B8-3965-4930-ADA6-570348B67153}" = Microsoft SQL Server 2012 Transact-SQL ScriptDom 
"{0FD96F86-3293-38B8-87F4-528F09E69F20}" = Microsoft Visual Studio Team Foundation Server 2015 Preview Office Integration Language Pack (x64) - ENU
"{13417784-A359-3CDD-8DE1-B7108707D647}" = Visual Studio 2012 Prerequisites - ENU Language Pack
"{1386CBAE-DE6B-4F16-9397-8423654C2F6E}" = Microsoft Visual Studio 2015 Preview Diagnostic Tools - amd64
"{13D558FE-A863-402C-B115-160007277033}" = Microsoft SQL Server 2012 Express LocalDB 
"{18B2A97C-92C3-4AC7-BE72-F823E0BC895B}" = SQL Server 2012 Database Engine Services
"{1ABA92B0-CD1F-478B-A351-415F79B2A9E6}" = SQL Server 2012 Data quality service
"{1D2CEC61-C3F0-C27E-7280-F9D6B10378BE}" = Windows App Certification Kit Native Components
"{1D411379-9CE0-4B13-A19B-72D3222DD620}" = SQL Server 2012 Common Files
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}" = Microsoft SQL Server 2014 Management Objects  (x64)
"{202AAF1F-69AA-442A-B59F-6B54B1AD07C6}" = SQL Server 2012 Common Files
"{22BCA430-2A68-4678-9824-184F3839948F}" = SQL Server 2012 Integration Services
"{26A24AE4-039D-4CA4-87B4-2F86418025F0}" = Java 8 Update 25 (64-bit)
"{26BFF1F1-5C03-4C55-9C7C-FD65889AFA70}" = SQL Server 2012 Management Studio
"{27EF252D-800C-ED42-9904-459FE0046225}" = Windows Software Development Kit for Windows Store Apps DirectX x64 Remote
"{28D85F24-B685-3364-BB7C-284C88C2FFE5}" = Microsoft Visual Studio Team Foundation Server 2012 Storyboarding
"{2B997E80-3BEC-3222-9114-98DBE1182B2E}" = Microsoft Visual C++ 2012 x64 Debug Runtime - 11.0.50727
"{2BE9BC58-D2D3-3376-85A4-558971523CD5}" = Microsoft Visual Studio Team Foundation Server 2015 Preview Storyboarding Language Pack (x64) - ENU
"{34A7A77A-A23D-44ED-B3B6-EC8198BE2622}" = SQL Server 2012 Full text search
"{3652FFB5-6F97-4113-9420-1A09A13FDDC8}" = SQL Server 2012 Distributed Replay
"{36BF5D42-BF68-4E0C-A165-A4C6E9841F4A}" = SQL Server 2012 Integration Services
"{36E619BC-A234-4EC3-849B-779A7C865A45}" = Microsoft SQL Server 2012 Data-Tier App Framework 
"{37B8F9C7-03FB-3253-8781-2517C99D7C00}" = Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.61030
"{38661DD1-576D-48CA-A188-F97819D5B5FB}" = SQL Server 2012 Data quality service
"{3C50A8F3-6BB8-44E8-9B8B-D3696561DF2E}" = SQL Server 2012 Data quality client
"{3E0DD83F-BE4C-4478-86A0-AD0D79D1353E}" = Microsoft VSS Writer for SQL Server 2012
"{409CB30E-E457-4008-9B1A-ED1B9EA21140}" = Intel(R) Rapid Storage Technology
"{45B4BE80-F20B-4CA9-9ED0-74B8E93DF93F}" = Workflow Manager Tools 1.0 for Visual Studio
"{4701DEDE-1888-49E0-BAE5-857875924CA2}" = Microsoft SQL Server System CLR Types (x64)
"{49D665A2-4C2A-476E-9AB8-FCC425F526FC}" = Microsoft SQL Server 2012 Native Client 
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4C59E848-6CFC-4413-8C28-D706E1108744}" = Build Tools Language Resources 14.0 (amd64)
"{4D84C195-86F0-4B34-8FDE-4A17EB41306A}" = Microsoft Web Platform Installer 5.0
"{5247E16E-BCF8-95AB-1653-B3F8FBF8B3F1}" = Windows Software Development Kit DirectX x64 Remote
"{53A46069-CFE2-3B06-8FC6-5AC08EC1D0E9}" = Microsoft Visual C++ 2015 x64 Additional Runtime - 14.0.22310
"{54FF8FAB-DE27-4187-82F1-EBAE6AEE869A}" = SQL Server 2012 Database Engine Shared
"{55EFD1A6-ED8E-3A4C-9581-5E1A1FF244CD}" = Microsoft Visual Studio Team Foundation Server 2012 Storyboarding Language Pack - ENU
"{572E796D-C52B-3797-A685-2FB6F895D4BE}" = Microsoft Visual Studio 2010 Office Developer Tools (x64)
"{57469141-5684-4671-8AB3-B531429D6AC1}" = Microsoft Visual Studio 2015 Preview Performance Collection Tools - ENU
"{5FB4C443-6BD6-1514-2717-3827D65AE6FB}" = Windows Software Development Kit DirectX x64 Remote
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{614FD4D7-78CE-43E0-88E1-F6DE78069B9A}" = SCM
"{61862D7C-CDBC-48D5-8AE1-3B8BD1E23BC5}" = Visual Studio 2012 Prerequisites
"{633AB014-DDE6-403E-A302-8920CC32C543}" = Microsoft Visual Studio 2012 Performance Collection Tools
"{656E214E-B73F-458C-AD64-ED316F008207}" = SQL Server 2012 BI Development Studio
"{6603C2CE-3C54-4F1D-92F9-8390CD4CCCA8}" = SQL Server 2012 Database Engine Shared
"{6618DB5E-8788-46E1-94F4-9F1C0FC075BD}" = Build Tools Language Resources - amd64
"{662014D2-0450-37ED-ABAE-157C88127BEB}" = Visual Studio 2010 Prerequisites - English
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 3.1.2
"{68A48EF1-DF03-394F-AF40-1E4FE42BB8DD}" = Microsoft Visual Studio Team Foundation Server 2012 Object Model Language Pack - ENU
"{6A2A6311-FBFE-3432-8E28-2F430087C957}" = Microsoft Visual Studio Team Foundation Server 2015 Preview Office Integration (x64)
"{6A69AE4F-81F8-42A5-A9E0-76B25FB61537}" = Build Tools 14.0 (amd64)
"{6AAF4427-3039-4C8A-BE53-D6F01C21AD46}" = Microsoft Visual Studio 2012 IntelliTrace Core amd64
"{6B3840D6-4B8F-4E74-9202-9CE36DA94E99}" = SQL Server 2012 Client Tools
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{6E33664E-DA1D-39EE-9130-4859FB81C79B}" = Microsoft Visual Studio Team Foundation Server 2015 Preview Storyboarding (x64)
"{6F07A6C2-9068-3673-A120-DC10012468C6}" = Microsoft Visual Studio Team Foundation Server 2012 Object Model
"{7272DF1C-2F88-43AC-A481-84DD67DF9746}" = SQL Server 2012 Documentation Components
"{72D2A508-27D7-3E17-8236-F5706F5CC62A}" = Microsoft Visual C++ 2015 x64 Minimum Runtime - 14.0.22310
"{74E7AE48-2396-4779-9642-B4B015A806EC}" = SQL Server 2012 Distributed Replay
"{7842C220-6E9A-4D5A-AE70-0E138271F883}" = SQL Server 2012 Client Tools
"{78909610-D229-459C-A936-25D92283D3FD}" = Microsoft SQL Server Compact 4.0 SP1 x64 ENU
"{7B54A700-3E8B-3FF2-A16E-81EB7101B4DA}" = Microsoft Office Developer Tools for Visual Studio 14 - VSTO Design Time (x64)
"{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}" = IIS 8.0 Express
"{80162C08-0FA6-4656-9685-AD88C6527F0B}" = SQL Server 2012 Data quality client
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8267A61A-7857-4F78-A473-5E7EE818A956}" = Microsoft Visual Studio 2015 Preview IntelliTrace (x64)
"{84FBCA4A-D650-4B0D-8094-EC0671FA9B91}" = SQL Server 2012 Database Engine Services
"{85C4F12F-4F78-3E66-92DD-D4F0891108EE}" = Microsoft Visual C++ 2015 x64 Debug Runtime - 14.0.22310
"{8892BF4B-5666-326D-917B-6969C41EA02D}" = Microsoft Visual Studio 2015 VsGraphics Helper Dependencies Preview
"{89AFB053-A343-46EF-97E4-D593AD7184E6}" = Intel® Trusted Connect Service Client
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A102C92-3290-3F85-A934-D4A62CD9BA2A}" = Visual C++ IDE x64 Package
"{8CB0713F-CFE0-445D-BCB2-538465860E1A}" = Microsoft SQL Server 2012 Setup (English)
"{8EEFD9B9-47B3-4023-9794-1B0CC7B73980}" = Visual Studio 2015 Prerequisites - ENU Language Pack
"{90150000-0015-0409-1000-0000000FF1CE}" = Microsoft Access MUI (English) 2013
"{90150000-0016-0409-1000-0000000FF1CE}" = Microsoft Excel MUI (English) 2013
"{90150000-0018-0409-1000-0000000FF1CE}" = Microsoft PowerPoint MUI (English) 2013
"{90150000-0019-0409-1000-0000000FF1CE}" = Microsoft Publisher MUI (English) 2013
"{90150000-001A-0409-1000-0000000FF1CE}" = Microsoft Outlook MUI (English) 2013
"{90150000-001B-0409-1000-0000000FF1CE}" = Microsoft Word MUI (English) 2013
"{90150000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - English
"{90150000-001F-040C-1000-0000000FF1CE}" = Outils de vérification linguistique 2013 de Microsoft Office - Français
"{90150000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proofing Tools 2013 - Español
"{90150000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2013
"{90150000-0044-0409-1000-0000000FF1CE}" = Microsoft InfoPath MUI (English) 2013
"{90150000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2013
"{90150000-0090-0409-1000-0000000FF1CE}" = Microsoft DCF MUI (English) 2013
"{90150000-00A1-0409-1000-0000000FF1CE}" = Microsoft OneNote MUI (English) 2013
"{90150000-00BA-0409-1000-0000000FF1CE}" = Microsoft Groove MUI (English) 2013
"{90150000-00C1-0000-1000-0000000FF1CE}" = Microsoft Office 32-bit Components 2013
"{90150000-00C1-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2013
"{90150000-00E1-0409-1000-0000000FF1CE}" = Microsoft Office OSM MUI (English) 2013
"{90150000-00E2-0409-1000-0000000FF1CE}" = Microsoft Office OSM UX MUI (English) 2013
"{90150000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2013
"{90150000-0117-0409-1000-0000000FF1CE}" = Microsoft Access Setup Metadata MUI (English) 2013
"{90150000-012B-0409-1000-0000000FF1CE}" = Microsoft Lync MUI (English) 2013
"{91150000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2013
"{91C4DE4A-CE48-4F8B-9D73-D2BFB619FB88}" = SQL Server 2012 RS_SharePoint_SharedService
"{929FBD26-9020-399B-9A7A-751D61F0B942}" = Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.21005
"{9495AEB4-AB97-39DE-8C42-806EEF75ECA7}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{95150003-1163-0409-1000-0000000FF1CE}" = SharePoint Client Components
"{95160002-1163-0409-1000-0000000FF1CE}" = SharePoint Client Components
"{9674CB74-4808-4B59-B79D-9AB501F23279}" = SQL Server 2012 Analysis Services
"{96F4525A-470D-F15C-796E-58D9988C3E5F}" = Windows Software Development Kit for Windows Store Apps DirectX x64 Remote
"{993F6DDC-63F8-4BCD-9B28-D941971A9CAC}" = Windows XP Targeting with C++
"{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}" = Microsoft SQL Server 2012 Command Line Utilities 
"{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb" = IIS Express Application Compatibility Database for x64
"{A0F05048-7653-4FCD-9F3A-C740E4052ACE}" = Microsoft SQL Server 2012 RsFx Driver
"{A5ABAF5F-B5B6-44B3-B69F-2E13DC60FC9F}" = Workflow Manager Client 1.0
"{A7037EB2-F953-4B12-B843-195F4D988DA1}" = SQL Server 2012 Management Studio
"{A749D8E6-B613-3BE3-8F5F-045C84EBA29B}" = Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.21005
"{A9FF9568-DFC5-3566-AE05-4F147BCE822F}" = Windows Phone Tools Finalizer
"{AB8DE9BA-19E1-446A-BCFA-6B3DA9751E21}" = Microsoft SQL Server 2014 Express LocalDB 
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Denetim Masası 344.65
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Grafik Sürücüsü 344.65
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience" = NVIDIA GeForce Experience 2.1.5
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Optimus" = NVIDIA Optimus Update 16.18.9
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX Sistem Yazılımı 9.14.0702
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Güncelleştirmeleri 16.18.9
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.LEDVisualizer" = NVIDIA LED Visualizer 1.0
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv" = SHIELD Streaming
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GfExperienceService" = NVIDIA GeForce Experience Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Network.Service" = NVIDIA Network Service
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShadowPlay" = NVIDIA ShadowPlay 16.18.9
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController" = SHIELD Wireless Controller Driver
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Update.Core" = NVIDIA Update Core
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_VirtualAudio.Driver" = NVIDIA Virtual Audio 1.2.27
"{B3192F55-2CE8-4C8E-9E40-D3B4998276B2}" = SQL Server 2012 Documentation Components
"{B40EE88B-400A-4266-A17B-E3DE64E94431}" = Microsoft SQL Server 2008 Setup Support Files 
"{B7274680-CDD7-49FA-8086-964328E195E0}" = SQL Server 2012 Master Data Services
"{BD2E0D31-EE77-4177-98EC-D7F7E7838CCA}" = Visual Studio 2015 Prerequisites
"{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}" = Microsoft SQL Server 2012 Transact-SQL Compiler Service 
"{BED1EA3D-592D-4305-9D1F-20F03726EFC1}" = Sql Server Customer Experience Improvement Program
"{C596D608-3E74-3232-8CA5-DF1DCB9F10DE}" = Microsoft Visual C++ 2013 x64 Debug Runtime - 12.0.21005
"{CC8B009A-98C9-497F-99AF-CEBE35D8C0CF}" = Microsoft SQL Server 2012 T-SQL Language Service 
"{CECA0188-BD7A-43EF-B1F7-DDF719099C46}" = SQL Server 2012 Documentation Components
"{CF2BEA3C-26EA-32F8-AA9B-331F7E34BA97}" = Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.61030
"{D05595D6-8288-4DF8-A911-FD8D76268815}" = SQL Server 2012 Distributed Replay
"{D307B5CF-D1F0-48A4-8DA3-54765F535208}" = SQL Server 2012 SQL Data Quality Common
"{D3AC9C6B-91D7-4E0B-B545-327A2BC17627}" = Intel(R) Rapid Storage Technology
"{D97D5D81-3F01-3AE9-BDA8-3DC4E8814A87}" = Windows Phone Tools Finalizer
"{D9F3D00D-E946-3B3D-A4A6-93D5020DB9F7}" = Microsoft Visual C++ 2012  x64 Designtime - 11.0.50727
"{DAF4DDA4-3B5A-407D-B4DF-07922C5A0D22}" = Microsoft System CLR Types for SQL Server 2014
"{DCCB1789-1DA0-4E3A-A52F-7815B602CC98}" = SQL Server 2012 Reporting Services
"{E5748D30-7E6D-3A8E-BFE6-C1D02C6DDABB}" = Microsoft Help Viewer 1.1
"{EAB410E5-3618-4C97-8EEA-450A75F865FD}" = Windows Phone 8.1 SDK - x64
"{EE1B54D1-BFBC-4C19-8D66-E0AF3E967896}" = SQL Server 2012 BI Development Studio
"{EF9653FD-3D63-36CD-B084-6F7DC5D1C3CA}" = Microsoft Office Developer Tools for Microsoft Visual Studio (x64) - ENU Language Pack
"{F14401A9-F0A0-33CC-8444-F60823A60DEB}" = Microsoft Visual Studio Tools for Applications x64 Runtime 3.0
"{F1949145-EB64-4DE7-9D81-E6D27937146C}" = Microsoft System CLR Types for SQL Server 2012 (x64)
"{F293537F-B4B7-4AB3-9DF2-CB1AF8F85D4D}" = Microsoft Visual Studio 2015 Preview Diagnostic Tools - amd64
"{F5A2F6B7-9065-4808-9528-0B944558604A}" = SQL Server 2012 Master Data Services
"{F99F24BF-0B90-463E-9658-3FD2EFC3C992}" = Microsoft Identity Extensions
"{FA0A244E-F3C2-4589-B42A-3D522DE79A42}" = Microsoft SQL Server 2012 Management Objects  (x64)
"{FB1349FD-D102-4722-9F0A-2543670FF7FB}" = SQL Server 2012 Analysis Services
"{FCD81E1A-6ED6-4F19-A572-82FFE102654E}" = SQL Server 2012 Reporting Services
"{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb" = IIS Express Application Compatibility Database for x86
"{FE74AC04-F248-4641-B3A9-89C6AA4339CD}" = Microsoft Visual Studio 2012 Performance Collection Tools - ENU
"5AADE1068CF70DD983F763B20CF2CAAB72883915" = KB9X Radio Switch Driver
"CCleaner" = CCleaner
"Elantech" = ETDWare PS/2-X64 11.13.4.4_WHQL
"Microsoft Help Viewer 1.1" = Microsoft Help Viewer 1.1
"Microsoft SQL Server 11" = Microsoft SQL Server 2012 (64-bit)
"Microsoft SQL Server SQLServer2012" = Microsoft SQL Server 2012 (64-bit)
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"Office15.PROPLUSR" = Microsoft Office Professional Plus 2013
"PerformanceTest 8_is1" = PerformanceTest v8.0
"Sublight_is1" = Sublight
"WinRAR archiver" = WinRAR 5.11 (64-bit)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00EC8ABC-3C5A-40F8-A8CB-E7DCD5ABFA05}" = Microsoft NuGet - Visual Studio 2012
"{012D26C3-E12A-3BDA-8ECE-DF14E721A507}" = Microsoft Visual Studio 2010 Shell (Integrated) - ENU
"{01FB691A-34C6-4F4F-8B21-20EFE145EDE7}" = Microsoft LightSwitch for Visual Studio 2015 Preview v5.0 ToolsRes - ENU
"{022C982D-CC9A-3526-9171-8D940379F4DD}" = Visual C++ MSBuild Base Resource Package
"{046806D1-0A38-3FCA-AF84-F71C50A0C363}" = Microsoft Visual Studio Premium 2012
"{0489B547-1E3D-3A25-B06F-3FDCE5D23C1D}" = Team Explorer for Microsoft Visual Studio 2015 Preview
"{0610DFB0-CCEA-6EC0-E3C3-A0160AD7FD98}" = Windows Runtime Intellisense Content - en-us
"{07242F36-E189-400D-B513-D19C200193A9}" = Microsoft Azure Mobile Services Tools for Visual Studio - v1.3
"{0BCC836F-0B28-4090-B58A-64883BAA3B2F}" = WCF Data Services 5.0 (for OData v3) Primary Components
"{0C03A66F-1FF0-45F9-8D67-0D806EBFFBA1}" = Blend for Visual Studio SDK for Silverlight 5
"{0C975EE7-526A-3BE2-A47E-AFC06E3D7D09}" = Visual C++ Library PGO X64 Package
"{0DE5A7DC-FD48-302E-BC94-AD3780750F4E}" = Visual C++ Library MFC Headers Package
"{1171AB62-5AEA-3661-BAA7-2E0EA42D8AB5}" = Visual C++ Compiler/Tools X64 ARM Cross Package
"{1172AC15-080E-30E3-85B0-FF59AD2E6315}" = Microsoft Visual Studio Ultimate 2012 - ENU
"{12190F04-C7A0-3463-8B65-41604F2C60A7}" = Visual C++ Compiler/Tools Premium X64 Base Package
"{123847DD-7B97-415A-AE3E-4452C3412263}" = Microsoft LightSwitch v5.0 SDK
"{13A4EE12-23EA-3371-91EE-EFB36DDFFF3E}" = Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.21005
"{148878BD-A2A5-4CF1-A103-2BA632F41953}" = WCF Data Services Tools for Microsoft Visual Studio 2012
"{161BA7D2-B3AE-424B-9234-3150E73CEEA8}" = Windows 8 Development Essentials
"{161E3ABF-BDBC-3BA6-A6EE-B3F296D213CE}" = Microsoft Portable Library Multi-Targeting Pack
"{1632A811-85AE-3919-833D-33AD9874DC87}" = Visual C++ IDE Base Package
"{16518758-0054-3263-A044-F7CAB9F64692}" = Visual C++ Library CRT ARM Desktop Package
"{166a69f6-6512-47ea-a342-17d954fc059a}" = Windows Phone 8.1 Emulators - ENU
"{1690CE56-2231-4E59-9006-A0876D949EA8}" =  Tools for .Net 3.5
"{17B6BB82-637A-32C5-A861-95A0CF0C0AD7}" = Microsoft Visual C++ 2012 Core Libraries For Windows Phone
"{180278FE-0750-32C0-8A46-D4FED5E245E2}" = Microsoft Office Developer Tools for Visual Studio
"{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}" = Microsoft Silverlight 4 SDK
"{18AB7C25-1FFB-438E-8A1D-81AD8DFF95D2}" = TypeScript Tools for Microsoft Visual Studio 14
"{191A6F65-6878-398D-A272-EF011B80F371}" = Microsoft Visual Studio Tools for Applications x86 Runtime 3.0
"{19A5926D-66E1-46FC-854D-163AA10A52D3}" = Microsoft .NET Framework 4.5.1 SDK
"{1B3E5A23-769F-4B14-9BD6-668D135CB006}" = Microsoft Visual Studio 2015 Preview Preparation
"{1B9BBB23-65CB-3AEE-BFC6-633E7CA299FD}" = Microsoft Visual Studio Team Foundation Server 2012 Team Explorer Language Pack - ENU
"{1C1300BE-D8A1-3D68-98A1-4F515873CBEA}" = Visual C++ IDE Windows Express Plus Package
"{1C163D33-33B3-33EB-A617-0D4D852BE8E1}" = Microsoft Visual C++ 2012 x86 Debug Runtime - 11.0.50727
"{1D932B12-A6B6-38F1-9D85-C1BC64BD52B2}" = Visual C++ Library ATL Source Package
"{1DB43E5A-2F24-4F51-92B0-A2C0EBF5C742}" = Microsoft Report Viewer Add-On for Visual Studio 2012
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F8E06E2-BA93-40DC-B183-E024CBD853A8}" = Microsoft Visual C++ 2012 Compilers
"{1FBAE18D-4DE4-47AA-83EC-D1B046F262DC}" = PDF Settings CC
"{21373064-AD95-48DB-A32E-0D9E08EF7355}" = Prerequisites for SSDT 
"{22AB4513-FA62-349E-A12F-B79C66D976F6}" = Visual C++ Library CRT X64 Desktop Package
"{23176E97-26CB-C72A-19EB-BFB21AC1D15A}" = Windows Software Development Kit DirectX x86 Remote
"{235CCCE6-3CB9-4E09-9D8E-0F212644C668}" = Build Tools - x86
"{246B0F46-F84E-4857-8C47-F2A86B598BC5}" = Microsoft Visual Studio 2012 Preparation
"{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}" = Skype™ 7.0
"{24CA683D-8174-4EBF-AD4D-3F2DD7814716}" = Microsoft Exchange Web Services Managed API 2.1
"{261C4435-2B12-35E0-BA83-C2AA24474E59}" = Microsoft Visual Studio 2015 Preview XAML Designer
"{26452889-33AC-3884-9D21-4DF6DAEEE80F}" = Visual C++ Compiler/Tools Premium X86 Base Package
"{2660DE05-DDE6-3E14-A09F-1DD0160D8D9A}" = Visual C++ Compiler/Tools X86 X64 Cross Package
"{26F71396-D769-39A3-A38F-92F9E1790733}" = Windows Phone 8.0 Emulation Host
"{27319BE6-8484-3D85-BC18-C46F4846DA85}" = Visual C++ IDE Desktop Plus Package
"{2774595F-BC2A-4B12-A25B-0C37A37049B0}" = Microsoft SQL Server 2014 Management Objects 
"{27ED99D2-058C-34CA-819A-AA2EB5D7242E}" = Visual C++ Professional Templates Resource Package
"{296112CB-4C3D-3FD2-AEF3-332EBEA775A6}" = Visual C++ Compiler/Tools X64 X86 Cross Resource Package
"{29826CB9-FC30-46AF-A118-5B76FB1C1789}" = Behaviors SDK (Windows) for Visual Studio 2013
"{29F259D7-C517-3EED-84B4-237573CFD39C}" = Microsoft Visual C++ 2012 Microsoft Foundation Class Libraries
"{2A542122-5861-3993-9A7F-11B52F746B54}" = Visual C++ Compiler/Tools X86 X64 Cross Resource Package
"{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}" = The Battle for Middle-earth (tm) II
"{2C0CC01A-DDBC-3AED-AF18-E741242FD727}" = Microsoft Visual Studio Ultimate 2012 XAML UI Designer enu Resources
"{2C4F5552-27DE-3D7E-BC20-53B676C0E83F}" = Visual C++ Compiler/Tools X86 ARM Cross Package
"{2C76E3DA-BA76-4FAD-B1B1-72B46D639028}" = PreEmptive Analytics Visual Studio Components
"{2D4C690E-110D-3C3C-9FAF-E741F9F6045E}" = Visual C++ MSBuild ARM Package
"{2e4043b7-cd84-44db-b81a-8f6e5ffb7398}" = Microsoft Visual C++ 2015 Preview Redistributable (x86) - 14.0.22310
"{2F6CE32A-018D-4656-895B-9E5E20D7740A}" = Microsoft ASP.NET MVC 3 - Visual Studio 2012 Tools Update
"{2F8DE575-AEF9-4E4F-BA30-65B2DFD7A6DA}" = Windows Phone 8.1 Tools for Visual Studio Professionald 2013 - ENU
"{30F2491C-9410-4DB1-BE66-77B360B1F484}" = Microsoft Visual C++  x64-arm Cross Compilers
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver
"{326A5052-061C-F656-31E3-3B73842ABD46}" = LocalESPCui for en-us
"{3274E031-C0F1-41E0-B731-86CFEA9B2826}" = Visual Studio Extensions for Windows Library for JavaScript
"{330E5D98-20D2-4CA4-AE51-FCB8AA80F634}" = Microsoft Visual Studio 2012 Devenv
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{3470F0F7-1622-31B3-9940-421B91F32356}" = Visual C++ for Cross Platform Mobile Development
"{3588DA11-2E49-3185-A777-C909EBACB503}" = Tools for Apache Cordova
"{361A1FD5-427C-3026-B26E-3329E24A8EA5}" = Visual C++ Compiler/Tools Premium X64 X86 Cross Resource Package
"{372D17F6-A54E-4A01-B264-1314890FFE61}" = Dotfuscator and Analytics Community Edition
"{37464E70-B0B9-9DFF-649A-CBE169BAD657}" = Windows Software Development Kit for Windows Store Apps
"{37E53780-3944-4A6A-842F-727128E8616E}" = Blend for Visual Studio SDK for .NET 4.5
"{38FC6E9A-F719-431A-A83D-4C86D5FD6555}" = Microsoft Visual Studio 2012 Shell (Minimum) Resources
"{3ABC2FE9-1056-3EFD-A8B0-E9CF4CE56047}" = Visual C++ IDE Base Resource Package
"{3B2C2CC9-9EA4-3F4D-849E-236798663604}" = Visual C++ Compiler/Tools Premium X86 ARM Cross Resource Package
"{3B361091-8D4B-3B43-856C-B484DE655CE5}" = Microsoft Visual C++ 2015 x86 Debug Runtime - 14.0.22310
"{3D0D9604-0173-488D-9694-2638C44D7579}" = PDF Architect 2 Create Module
"{3DB24308-42C0-3F72-8E65-156EB1045AA4}" = Microsoft Visual Studio Ultimate 2015 Preview
"{3EA16E23-14D2-466A-8268-D7CD40DC46B6}" = Open XML SDK 2.5 for Microsoft Office
"{3F200278-7638-3C6D-98C4-CA17EDCF6B87}" = Microsoft .NET Native SDK Developer Preview
"{4015E34F-1EB6-3F19-83DA-514B9B27DFD5}" = Visual C++ CRT Headers Package
"{403759F5-1D77-49F4-812D-AF43196E8C74}" = Blend for Visual Studio SDK for Windows Phone 8.0
"{40BE32B3-F33F-3969-B02D-AC9F4CC98102}" = Visual C++ Library CRT X86 Redist Package
"{40CDF0F8-23A2-4C64-9552-8F0033B1CB49}" = Windows Phone 8.1 SDK - Images
"{41381A7A-DC83-49BA-99D2-C7F9C34D794A}" = Microsoft Visual Studio 2015 Preview Windows Diagnostic Tools - ENU
"{417EF6AA-3961-4119-9A00-312724B35D3A}" = Node.js
"{419512F9-D5E7-4ED2-BF99-E7F2C0176B6A}" = Nuance OmniPage Ultimate
"{41D98B6E-FB3A-3C20-9E86-9317A1E5EB22}" = Visual C++ Compiler/Tools X86 Native Resource Package
"{4235D8C2-4098-3FBE-8B9E-23DCA55BB7D0}" = Visual C++ Professional Shared Templates Resource Package
"{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}" = Microsoft Games for Windows - LIVE Redistributable
"{42F61556-29ED-8122-F39E-6F04EA5FF279}" = Windows Software Development Kit for Windows Store Apps DirectX x86 Remote
"{4496889E-E5AB-3168-A18D-AFCAF62623C6}" = Windows Phone SDK 8.0 Assemblies
"{455A16B4-CD22-4529-B429-DD454573E76A}" = Microsoft SQL Server Data Tools - enu (14.0.41025.0)
"{45E8D946-CB3E-301D-9C39-9564DA73CDCA}" = Visual Studio 2012 Verification SDK
"{47D08E7A-92A1-489B-B0BF-415516497BCE}" = Microsoft SQL Server 2014 T-SQL Language Service 
"{4837E99B-BFEE-4ABE-9483-295B18034F75}" = Windows Phone 8.1 Tools for Visual Studio 2013
"{48CCDDC7-39CE-3368-932D-30BDAAC7D64B}" = Visual C++ Compiler/Tools X86 Base Package
"{491D1B4D-F605-3C92-A313-5B9A05681E23}" = Windows Phone SDK 8.0 Assemblies
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AE57014-05C4-4864-A13D-86517A7E1BA4}" = Microsoft .NET Framework 4.5 SDK
"{4B9E6EB0-0EED-4E74-9479-F982C3254F71}" = SQL Server Browser for SQL Server 2012
"{4C117734-3794-4A3C-ABC5-FC79656E0A50}" = WCF Data Services Tools for Microsoft Visual Studio 2014
"{4CB8D214-0400-45FA-B084-AAB0C74AD032}" = PDF Architect 2 Forms Module
"{4E4D4C33-7837-38E0-9A8D-2A279349300F}" = Microsoft NuGet - Visual Studio 2015
"{4E66EC8A-B60F-39F0-A178-3927994E3738}" = Visual C++ Library ATL ARM Package
"{4FF5F944-B4D5-3D0A-B65F-BAB3146EFCC0}" = Visual C++ Library PGO X86 Package
"{503C7AFE-98C1-3D02-AC67-051E38D0C80C}" = Visual C++ Compiler/Tools Premium X64 ARM Cross Resource Package
"{505012BB-B138-3B97-9961-350D654321F7}" = Visual C++ Compiler/Tools Premium ARM Base Resource Package
"{5223EFD8-B18C-3353-828C-057D651AB9B7}" = Visual C++ Compiler/Tools Premium X86 X64 Cross Package
"{532DBCC8-9468-435C-AEF6-30B7F50735A2}" = Blend for Visual Studio 2012 ENU resources
"{53434783-F9A7-4D64-B91A-05A3BF925D70}" = PDF Architect 2 Convert Module
"{54C62549-F097-397F-8FBC-418BBA06DB45}" = Visual C++ Compiler/Tools X64 X86 Cross Package
"{54FDBF01-56CC-32AF-BA44-D502AF12C365}" = Visual C++ Compiler/Tools X64 Native Resource Package
"{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1" = Emsisoft Internet Security
"{564B5942-6A12-3D02-BD0C-CB6757095E4B}" = Microsoft Visual Studio 2015 Shell (Minimum)
"{56AD3004-0B49-967F-F682-B05650B61A78}" = Windows Software Development Kit for Windows Store Apps DirectX x86 Remote
"{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}" = Microsoft .NET Framework 4.5 Multi-Targeting Pack
"{57D782D7-49FD-48DE-AB47-A690A1519A2D}" = Microsoft ASP.NET Web Pages 2 - Visual Studio 2012 Tools
"{57F20F04-014D-453F-B6A3-AE9485C4DFAB}" = Blend for Visual Studio 2012
"{5877B472-4797-3470-83B9-2F25E964BEF5}" = Visual C++ Compiler/Tools Premium X64 Native Resource Package
"{5982BB26-FF80-3939-9B64-11289CF5C3AE}" = Visual C++ for Cross Platform Mobile Development - ENU
"{59D87F40-6C4B-4F80-A42B-FAA0E6EAFAB6}" = Microsoft ASP.NET MVC 4 - Visual Studio 2012 Tools
"{5A03C202-08B4-3F1D-9A60-A4F53EF1B636}" = Microsoft Visual Studio Tools for Applications Design-Time 3.0
"{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}" = Realtek Card Reader
"{5C87A4DB-31C7-465E-9356-71B485B69EC8}" = Microsoft Advertising SDK for Windows Phone - ENU
"{5D40AFB7-6DC9-3903-A065-2C122B9483CE}" = Microsoft Visual Studio Professional 2015 Preview
"{5D8DD6A8-C4D7-4554-93F9-F1CC28C72600}" = WCF RIA Services V1.0 SP2
"{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}" = Microsoft Visual C++ 2010  x86 Runtime - 10.0.40219
"{5DFCA6D7-78E3-428E-A3FA-2745C36AF4B8}" = ErrorList
"{5FD7B6B3-08C7-4FEE-9C37-A2134C699885}}_is1" = This War of Mine
"{609F6FD5-4B22-4D7A-AD30-8C9DD480D5BE}" = Command & Conquer™: Generals and Zero Hour
"{60D5EF2A-4E0C-2C30-38F6-59C26E134F4A}" = Windows Software Development Kit
"{61779718-6166-3C14-97F2-01FEBB4977FF}" = Windows Phone Emulator 8.0 Configurator
"{619AA47A-5140-49B4-A90A-C4BB6563F7D1}" = Windows 8 Development Essentials
"{619FA785-489B-4D22-911F-82D6EDF5BDB0}" = Battery Calibration
"{62136475-A3C1-387D-9911-05837EEDD88A}" = Visual C++ Compiler/Tools Premium X64 Base Resource Package
"{6218AE1F-62A0-3875-B0A9-E2F894CA1E29}" = Visual C++ Library CRT X86 Store Package
"{62910715-63E3-0AB0-0B29-99140DE1C15E}" = LocalESPC
"{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}" = Microsoft ASP.NET Web Pages
"{633A4439-31E0-496C-B192-4F8078F3E0A0}" = PDF Architect 2 Asian Fonts Pack
"{64D82C1B-C436-3568-BB82-B5143D14223C}" = Microsoft Visual C++ 2015 x86 Minimum Runtime - 14.0.22310
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components
"{659D2DBE-CA2C-4C8F-AF2B-2C8DE262B278}" = Microsoft System CLR Types for SQL Server 2014
"{664D6EE3-9A35-4284-B9D2-80A509DF9295}" = PDF Architect 2 Review Module
"{66ED8E01-C915-41F5-B33E-C5C31F27B885}" = USB Network Driver
"{67758672-F064-3AC5-B2ED-1EE52EED5FD5}" = Visual C++ Compiler/Tools X64 Native Package
"{678800C0-D94E-4513-89CB-478F2B781A0B}" = Microsoft Visual C++ 2013 x86-x64 Compilers
"{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}" = Microsoft Games for Windows Marketplace
"{6904CA84-1BDA-4F2D-B38C-979EE4EC31A6}" = Microsoft LightSwitch for Visual Studio 2015 Preview v5.0 Tools
"{697993C4-5D93-4455-A602-ED5F59EAFB22}" = Microsoft Report Viewer Add-On for Visual Studio 2015 Preview
"{6A0C6700-EA93-372C-8871-DCCF13D160A4}" = Microsoft .NET Framework 4.5.1 Multi-Targeting Pack
"{6C06FEE9-C64E-453F-B8A5-D9E9B79ED040}" = Microsoft Visual C++ 2013 32bit Compilers - ENU Resources
"{6D1221A9-17BF-4EC0-81F2-27D30EC30701}" = Skype Click to Call
"{6D6D43E5-218C-4B05-92D3-2240810F4760}" = Microsoft SQL Server 2012 T-SQL Language Service 
"{6DA0C42B-7F51-4F1B-852D-DB4DC2FD5B54}" = Windows Phone 8.1 Tools for Visual Studio Professional 2015 Preview
"{6DAB46E3-D017-3E2B-85D8-F57A230384C0}" = Microsoft Visual Studio Team Foundation Server 2012 Team Explorer
"{6E2F22E9-80BD-3FF6-BCEB-8D80F19D9104}" = Microsoft Visual Studio 2015 Preview XAML Designer - ENU
"{6F066545-40A2-4C38-A8F7-78581CC5C442}" = Microsoft ASP.NET Web Pages - Visual Studio 2012 Tools
"{6FC3B79F-47C6-38AF-B9A9-67DE3C639598}" = Microsoft Visual Studio Premium 2012 - ENU
"{6FF89029-E442-4346-BB1E-C73AA6F6D080}" = Microsoft .NET Framework 4.5.3 Preview Multi-Targeting Pack (ENU)
"{704E2674-53C3-34CA-953F-5461AEB5FA27}" = Microsoft Visual C++ 2015 x86 Additional Runtime - 14.0.22310
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{719A1B52-7F88-3653-89BD-16F000AA2D64}" = Microsoft Visual Studio 2015 Preview Team Explorer Language Pack - ENU
"{724B9AA0-5543-39F6-915C-8F89845BD3FF}" = Microsoft Visual Studio Ultimate 2015 Preview - ENU
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{72E506F2-3865-38A4-A9B3-774452120ED9}" = Roslyn Language Services - x86
"{731C183B-86A0-3442-BE55-68A7C92581E9}" = Microsoft Visual C++ 2012 Extended Libraries
"{740424CA-94AD-3DCD-BEBD-4B7063C299C5}" = Visual C++ Library CRT Redist Resource Package
"{7437A4B9-314F-3B8F-827B-22909146E471}" = Microsoft LightSwitch for Visual Studio 2012 Core
"{7515082B-0B97-331C-9725-9D42EF0DE501}" = Windows Phone 8.0 Emulation Images
"{766255CE-D156-11E3-8DBC-A136EB52ACCF}" = Adobe Dreamweaver CC 2014
"{76A5BE6F-9C1F-3464-A91E-9E085A22026E}" = Visual C++ Library CRT X86 Desktop Package
"{772590BC-E61B-4080-B9D5-A71497612F36}" = Build Tools Language Resources - x86
"{78D99732-B9AA-3544-86D3-3E855E28B5BB}" = Visual C++ Library MFC Source Package
"{790E9425-8570-493F-9AE7-81AFC9E46930}" = Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00)
"{7AC97190-67DC-4D68-B743-43F7E1FC393A}" = Windows Phone 8.1 SDK - ARM
"{7B6EA339-A4B6-30A8-B72C-C8CCA9F7D3BD}" = Visual C++ Compiler/Tools Premium X86 X64 Cross Resource Package
"{7BB726AE-892C-366E-B77E-8E3E929B2ECC}" = Visual C++ Library CRT ARM Redist Package
"{7F053528-7C2A-3958-8B8E-C7A24E786696}" = Microsoft Office Developer Tools for Visual Studio 2015 Preview Nuget Package
"{7F111167-5B0A-4DD4-8D0F-C6DB7649B938}" = ClumsyLeaf CloudXplorer
"{7f51bdb9-ee21-49ee-94d6-90afc321780e}" = Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005
"{800F484E-9D69-492D-B656-7BAA32586142}" = Microsoft Visual Studio 2012 Shell (Minimum)
"{820C677A-41B2-48C3-8136-FEE35A052E73}" = Microsoft Visual Studio 2012 Shell (Minimum) Interop Assemblies
"{82C698E4-4085-34EB-A207-47BC19EDDD74}" = Microsoft .NET Native SDK Developer Preview
"{82F2510B-1274-4AEC-976D-B80BA1A8F99F}" = Microsoft LightSwitch for Visual Studio 2015 Preview CoreRes - ENU
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83F2B8F4-5CF3-4BE9-9772-9543EAE4AC5F}" = Microsoft SQL Server 2008 R2 Management Objects
"{84A1C5D1-B913-4A71-B3DB-B432026B7647}" = Microsoft Visual Studio 2015 Preview IntelliTrace Front End
"{84D6E968-0F85-35ED-874A-0982762E680B}" = Microsoft Visual Studio 2015 Preview Devenv Resources
"{84D88F57-4130-30FE-A0B6-1E04428FE1F6}" = Microsoft Visual C++ 2013 Core Libraries
"{861F6EBB-5856-4DB9-B812-363CFB1D2F56}" = Microsoft .NET Framework 4.5.3 Preview Multi-Targeting Pack
"{878D6271-C16F-3502-842B-250D69C55862}" = Visual C++ Library ATL X64 Package
"{8801CA65-921A-4CCC-9D63-879D1D0BAA97}" = Sound Blaster Cinema
"{88614642-AC6A-3360-B7B1-A3A03AC6B29D}" = Visual C++ IDE Debugger Resource Package
"{89B4532E-19CE-4FA9-9692-10BFD5A38532}" = Visual Studio Extensions for Windows Library for JavaScript
"{8B0A956F-9BE6-495B-AF80-7B5B42061D79}" = PDF Architect 2 Edit Module
"{8CB63A01-7F9D-3959-B10F-CE4627C368AC}" = Roslyn Language Services - x86
"{8DBBE6BB-CF74-4E24-89E1-3537C3DF9653}" = Microsoft Visual C++ 2012 Compilers For Windows Phone - ENU Resources
"{8E6FA2E1-634B-4BAB-BEA7-0604B0812A4C}" = Microsoft Visual Studio 2015 Profiling Tools
"{8F5C00E3-90B1-48A9-8E33-7B1DD60B7F9E}" = VsHub
"{8F78DBCB-9382-3BB7-BF8F-2C6BE6061211}" = Microsoft Visual Studio 2015 Shell (Minimum) Interop Assemblies
"{8FA734D1-3BCD-3DCD-97A8-7A571602C32F}" = Visual C++ Library ATL Headers Package
"{8FD30080-2C5C-4326-845D-2C89BE71CBC1}" = Microsoft Visual Studio 2015 Preview Diagnostic Tools - x86
"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components
"{9169C939-ED01-446A-BD0C-29873BAF4E48}" = Prerequisites for SSDT 
"{925A11AF-CE07-4E4D-B376-7E7EAE921531}" = Microsoft Visual Studio 2015 Preview Diagnostic Tools - x86
"{93489CA8-6656-33A0-A5AC-E0EDEDB17C3E}" = Microsoft Visual Studio Professional 2012
"{938B4C99-A359-40C5-884E-07E1DA522B0C}" = Application Insights Tools for Visual Studio 2015 Preview
"{93CA5AFE-551C-3041-AA3A-6E4BDC6F3061}" = Visual C++ Library ATL X86 Package
"{942CC691-5B98-42A3-8BC5-A246BA69D983}" = Microsoft ASP.NET MVC 4 Runtime
"{943F3FB1-3F9C-4FB7-A4E2-6D53617068C3}" = PreEmptive Analytics Visual Studio Components
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{952E5B8F-82C2-46D1-B642-37B2635CE440}" = PDF Architect 2 OCR Module
"{95716cce-fc71-413f-8ad5-56c2892d4b3a}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610
"{95744E49-71D1-453A-9466-6930819043C8}" = TOEFL Sampler
"{9600393b-6ede-469b-a522-689fce1461d1}" = Microsoft Visual Studio Ultimate 2012
"{96563105-F726-4865-8C32-416753ECA5F1}" = Microsoft Visual C++  x64-x86 Cross Compilers - ENU Resources
"{976C3D92-0DEC-37A6-A870-FF4FC18CD029}" = Microsoft .NET Framework 4.5.1 RC Multi-Targeting Pack for Windows Store Apps
"{97D5B567-5728-3DA5-9CFD-004ACF5788FD}" = Windows Phone Emulator 8.0 Configurator
"{984022F2-9BCA-A41D-6A38-1AE658F01415}" = Windows Software Development Kit
"{99E0C0D4-6746-44EE-A132-5E7E3D6FAAFB}" = PDF Architect 2 Secure Module
"{99FCCA2B-F1FD-E66E-E3B9-AA57FBBF2E66}" = Windows Software Development Kit for Windows Store Apps
"{9A0DC62D-5E9F-31C6-8A8D-834CBBB25E10}" = Microsoft Blend for Visual Studio 2015 Preview - ENU
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A514444-8605-3624-83EA-AE3848687267}" = Windows Phone SDK 8.0 Assemblies for Visual Studio 2015 Preview
"{9B3A1C97-A361-463E-8817-444F9F88CDFE}" = Microsoft Expression Blend SDK for .NET 4
"{9BB0ABF8-5B15-4AE2-B09E-347BBD65172A}" = AzureTools.Notifications
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9CCE40CE-A9E6-4916-8729-B008558EEF3F}" = Microsoft Report Viewer 2012 Runtime
"{9D3D8C60-A5EF-4123-B2B9-172095903AB}" = REALTEK Bluetooth Driver
"{9DAABC60-A5EF-41FF-B2B9-17329590CD5}" = REALTEK Wireless LAN Driver
"{A181D9FD-6832-3897-A473-EFBC654A37E6}" = Tools for Apache Cordova - ENU
"{a1909659-0a08-4554-8af1-2175904903a1}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610
"{A1CB8286-CFB3-A985-D799-721A0F2A27F3}" = Windows Software Development Kit DirectX x86 Remote
"{A223B446-EC3D-3031-828D-5188800AB782}" = Microsoft .NET Framework 4.5.1 RC Multi-Targeting Pack for Windows Store Apps (ENU)
"{A2E88D61-EB7F-3A0B-9CA3-7CAE646E124C}" = Visual C++ Library CRT X64 Store Package
"{A35D7103-E0AE-4421-98E9-3F5EEEED3B7D}" = Windows Phone 8.1 Tools for Visual Studio 2013 - ENU
"{A3A6D5EA-B6B5-3C05-BDA8-EAB99C09CDDC}" = Microsoft Visual Studio 2012 SharePoint Developer Tools
"{A405158B-E65A-4562-8991-C9C98CF1FEAD}" = Python Tools Redirection Template
"{A4366F69-CE22-4DB7-9C8C-46A5845AF997}" = Microsoft Visual C++ 2012 Compilers - ENU Resources
"{A655CED5-9171-39C3-B854-11A87FC237D0}" = Microsoft ASP.NET and Web Tools 2015 - Visual Studio 2015 Preview
"{A8BB6906-7ADC-3944-ABB9-010833EA5B2B}" = Visual C++ Compiler/Tools X86 Native Package
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A97CD0E5-ACF1-311B-8777-0C3DAC184AFC}" = Visual C++ IDE Debugger Package
"{ACA6D441-026E-4808-898E-436D91E272B1}" = Microsoft Visual Studio 2015 Preview Preparation
"{AD1AEE2A-D9C0-3FAC-8D6B-B5E07B47257B}" = Microsoft Visual C++ 2012 Core Libraries
"{AEBB5873-1DF6-4190-98D8-D9FC5144EB3B}" = Windows Phone 8.1 SDK - Desktop
"{AFC3A0DE-D69C-37C4-BD84-68A3BCE2920E}" = Microsoft Visual Studio Premium 2015 Preview
"{B03A86DF-BF14-4250-A667-99A818ECBA98}" = Windows 8 Development Essentials
"{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}" = Jumpstart Installation Program
"{B1465D1D-6427-4CA1-AE29-8B699209E663}" = Microsoft Visual Studio 2012 Devenv Resources
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B3533B84-A8DF-4A7A-8E95-B15F08B26E96}" = Microsoft Visual Studio 2012 IntelliTrace Core x86
"{B3C98C29-A2BE-455F-9285-13B745282271}" = Microsoft Visual C++  x64-arm Cross Compilers - ENU Resources
"{B455E95A-B804-439F-B533-336B1635AE97}" = NVIDIA PhysX
"{B4D3393A-68BE-4A5C-B963-93FFE1128E9E}" = Windows 8 Development Essentials
"{B57FCAEE-AC2A-4D26-81A2-63B10E08639D}" = Microsoft Visual Studio 2015 Preview IntelliTrace (x86)
"{B6CB8401-B0A8-4795-8BED-F7B49D51ABCF}" = Microsoft Visual Studio 2015 Preview Secondary Installer
"{B6CB8401-B0A8-4795-8BED-F7B49D51ABCF}_SecondaryInstaller" = Microsoft Visual Studio 2015 Preview Secondary Installer
"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974
"{B8701564-A204-3801-BA2A-043A2B1A3DFC}" = Visual C++ Library CRT ARM Store Package
"{B91D266A-2AC1-4A03-97BF-F0493749EE67}" = Microsoft Azure Mobile Services SDK V2.0
"{B96FCD4F-6EDD-4258-8A6D-0FCEA8445E3E}" = Microsoft Web Developer Tools - Visual Studio 2012
"{B9F35D86-242E-3FA4-B9F8-A982E0DF918D}" = Microsoft Visual Studio 2012 SharePoint Developer Tools ENU Language Pack
"{BB0D9EE5-F7B1-4986-AF62-DB3BED9A83BC}" = Microsoft Visual C++  x64 Native Compilers - ENU Resources
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{BE1C51BC-E894-3A17-B795-8471B7A088D4}" = Visual F# 4.0 SDK
"{BE681F96-C973-4161-90D4-FB04FF0519A7}" = Microsoft Visual Studio 2015 Preview Windows Diagnostic Tools
"{BE8FAA24-79B9-3858-82FF-29D5E31D7CD9}" = Visual C++ Compiler/Tools Premium X86 Native Resource Package
"{BF43518F-FB96-4FF4-939D-7F2D46E7833C}" = Microsoft Visual Studio Connected Services
"{C1BE4600-7D15-3D1E-8AA2-B3241DB1D063}" = Microsoft Visual Studio Ultimate 2012 XAML UI Designer Core
"{C1D0E508-ECAF-45AA-A549-1E26B9ECE0FB}" = Microsoft Visual C++  x64-x86 Cross Compilers
"{C3F6F200-6D7B-4879-B9EE-700C0CE1FCDA}" = Microsoft SQL Server System CLR Types
"{C501E0D1-C84A-3747-A6DC-D20CC41075FE}" = Visual C++ Library PGO ARM Package
"{C6DE79CB-E114-3593-A5B9-874DF0B96A12}" = Microsoft Blend for Visual Studio 2015 Preview
"{C7B84BB5-B871-4020-9C0D-CB08D9B77526}" = Windows Phone 8.1 Tools for Visual Studio Professional 2013
"{C81452EB-CBCF-B8EB-3124-48C5B3D506B0}" = Windows Runtime Intellisense Content - en-us
"{C8286D1C-10D0-33D9-B6C1-6A73EE88012C}" = Visual C++ Compiler/Tools Premium ARM Base Package
"{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}" = Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030
"{CBBB824A-B72C-338E-94AE-5226DC6D5342}" = Microsoft Office Developer Tools for Visual Studio ENU Language Pack
"{CCCC58C7-2E15-41CC-B6D5-247834BBDB4E}" = TypeScript Power Tool
"{ce085a78-074e-4823-8dc1-8a721b94b76d}" = Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005
"{CEBEF06A-D5E8-4416-8BEB-358A47E5E1DA}" = Microsoft.VisualStudio.Office365
"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack
"{CFFDC0EC-6924-3347-B047-13339EDBEC28}" = Microsoft Visual Studio Professional 2012 - ENU
"{D17027BD-E4AE-3D7B-A8B7-F58AF694190B}" = Multi-Device Hybrid Apps using C# - Templates - ENU
"{D1E4A56B-473B-396D-8C00-44CBFFDE5FA2}" = Visual C++ Compiler/Tools X86 ARM Cross Resource Package
"{D21B5F75-8042-3B39-80A1-F1D56D6DB4AB}" = Windows Phone 8.0 Managed SDK Profiler (X86)
"{D2AAF445-54B0-35AB-8E61-1B8A375CE79C}" = Visual F# 4.0 VS
"{D3517C62-68A5-37CF-92F7-93C029A89681}" = Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU)
"{D42681AA-BC16-3C84-949E-45F05D2AA997}" = Microsoft Visual C++ 2013 Core Libraries
"{D5281C92-2EBB-373A-8168-BA493AC2765B}" = Visual C++ Library CRT Appx Package
"{D63950EB-B5C8-3EF5-998D-C895370ADA55}" = Microsoft Visual Studio 2015 Devenv
"{D63C0368-235C-3A79-BBB3-3BAB7AAF18AE}" = Visual C++ IDE Professional Plus Package
"{D64B6984-242F-32BC-B008-752806E5FC44}" = Microsoft Visual Studio 2010 Shell (Isolated) - ENU
"{D691E998-CF53-4F6C-AC20-E4284660E0E7}" = PDF Architect 2 View Module
"{D6DEA3AD-637E-368A-BD00-501D443F5E86}" = Windows Phone 8.0 Managed SDK Profiler (ARM)
"{D89B0A86-1069-34B6-9737-9CA2AA70D14B}" = Microsoft Visual Studio Professional 2015 Preview - ENU
"{D94931E5-E1FD-38BB-BB14-8B5670555D7F}" = Visual C++ Library MFC X64 Package
"{D971780F-A609-4F78-92AA-B56FBC3955B9}" = Microsoft Visual Studio 2012 IntelliTrace Front End x86
"{D9D0F96E-6EE0-381C-913F-A67B651A70E2}" = Visual C++ IDE Common Package
"{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}" = Microsoft SQL Server 2012 Management Objects 
"{DAF44BE4-070C-3465-B7C7-E1077A185A63}" = Visual C++ Compiler/Tools Premium X64 Native Package
"{DAFB797A-B553-31AA-AC3C-C8FC935E8FBA}" = Visual C++ Library PGO Headers Package
"{DB5600F1-DE83-46DE-B162-5FC4400EAF5B}" = Microsoft Visual C++ 2013 Compilers
"{DB769082-2027-33CF-BF7F-2571F07EB447}" = Visual C++ Professional Shared Templates Package
"{DC487E40-046E-42A9-9C7C-5D2B1A7EB211}" = Microsoft SQL Server 2012 Policies 
"{DC6CCD06-974B-338F-B3CB-6FEB88CE3F24}" = Visual C++ MSBuild X86 Package
"{DCAFA84C-9EC6-3270-93EC-0C74A7A69865}" = Microsoft Portable Library Multi-Targeting Pack Language Pack - enu
"{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}" = Microsoft ASP.NET MVC 3
"{DD7BB68A-7D8A-4F62-806A-3424C2A170E7}" = PDF Architect 2 Insert Module
"{DE0E8FAF-9758-4BFD-A16E-009DB4B8C912}" = Microsoft Visual C++  x64 Native Compilers
"{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1" = Auslogics DiskDefrag
"{E150CEAB-8FD2-3984-9A0C-A9D4727F594E}" = Visual C++ Compiler/Tools Premium X86 Native Package
"{E196DF0C-38A4-46B6-8C8D-62F1FFF7AB33}" = Build Tools 14.0 (x86)
"{e1f58f60-306c-4f5b-9788-5b9292910779}" = Microsoft Visual Studio Ultimate 2015 Preview
"{E1FBB3D4-ADB0-4949-B101-855DA061C735}" = Microsoft Silverlight 5 SDK
"{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}" = Microsoft System CLR Types for SQL Server 2012
"{E391D05A-DBD5-3393-98AD-A822310FD293}" = Microsoft Visual Studio 2015 Preview Add-in for Windows Phone
"{E403FEBB-6B86-3C58-8075-DB35C19FDC84}" = Visual C++ Compiler/Tools X64 ARM Cross Resource Package
"{E4ADE757-7FE9-322D-9CAE-C77D77A2D2BF}" = Microsoft LightSwitch for Visual Studio 2012 CoreRes - ENU
"{E4C33F5B-1B2F-466E-957E-B274F08151A0}" = Microsoft Web Deploy dbSqlPackage Provider - enu
"{E518DB32-FB90-3CCC-BDEE-FAEE5C0FAEBE}" = Visual C++ Compiler/Tools Premium X64 ARM Cross Package
"{E58C1D9D-0F69-3D4A-940F-DFD50A54A212}" = Visual C++ MSBuild Base Package
"{E5CAE8D2-9F9F-3BEA-AA0F-B5B40611C704}" = Microsoft Visual C++ 2013 x86 Debug Runtime - 12.0.21005
"{E64BF16C-A8D9-305C-85CB-5272CDC2C968}" = Microsoft Help Viewer 2.2
"{E6B90257-0DBC-35E1-AA72-38416B107F5C}" = Visual C++ Compiler/Tools X64 Base Resource Package
"{E6F3851E-CEEB-4ECB-A6FA-337C8F662E3D}" = Microsoft Visual C++ 2013 Compilers - ENU Resources
"{E818AE7C-244B-4A50-9C86-C0E4A8B69159}" = Microsoft Visual Studio 2012 Tools for SQL Server Compact 4.0 SP1 ENU
"{E84C90F4-484F-31E9-BC0F-267B37A07A1A}" = Visual C++ Compiler/Tools Premium X64 X86 Cross Package
"{E8DF741F-81C4-4DF9-B482-FBBB71C73FBE}" = Windows Phone 8.1 Tools for Visual Studio Professional 2015 Preview - ENU
"{E966D14A-E908-30D4-ADF2-A23501591CE3}" = Visual C++ Professional Items Package
"{E9DCCCB8-9BAA-4405-A42C-FA1975660FC8}" = Build Tools Language Resources 14.0 (x86)
"{EA617DCB-9F17-37C6-B1D3-28E06B12E0B3}" = Microsoft Visual Studio 2015 Preview Add-in for Windows Phone - ENU Language Pack
"{EB095AA7-926F-311D-897E-4FC2D77358E5}" = Visual C++ Library CRT Appx Resource Package
"{eb6c06e7-8ff6-4978-ab4c-561383593306}" = Microsoft Visual C++ 2015 Preview Redistributable (x64) - 14.0.22310
"{EBC584A0-C906-3436-B825-74F30151E131}" = Windows Phone 8.0 Emulation Images
"{EC6F2E68-FA67-4529-8A95-523A8A1D42FE}" = Windows Phone 8.1 Tools for Visual Studio 2015 Preview
"{ED1FD7D4-1340-3F87-8A18-738799CBD269}" = Visual C++ Library CRT X64 Redist Package
"{ED8CD608-57B6-3554-A7DA-3691ED25B8C2}" = Visual C++ Compiler/Tools X64 Base Package
"{ED96DCED-5C9A-4D22-51EF-B6FF669E83B4}" = Microsoft ASP.NET Web Frameworks and Tools - Visual Studio 2015 Preview - ENU
"{EDB1632D-FE4B-4F5B-A234-91DA81B03C41}" = Windows Phone 8.1 SDK - x86
"{EED93ADA-2467-311E-9A48-6C2699241EAF}" = Visual C++ IDE Common Resource Package
"{EFA87714-E75A-3BFC-A698-A3AABA5A8A0C}" = Microsoft Visual Studio Ultimate 2012
"{EFC589DE-94FA-34E1-A8CB-D988BAEC887E}" = Visual C++ MSBuild X64 Package
"{EFF70763-E2A8-3DE3-9779-5F291D19201F}" = Visual C++ Library CRT Source Package
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics
"{F11F1126-7579-344B-83FF-59BA6737AB78}" = Visual C++ Professional Templates Package
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F176C5A2-EF3A-41A5-9C9B-26953F75B0B2}" = Microsoft Azure Shared Components for Visual Studio 2015 Preview - v1.3
"{F361FE04-789E-42F3-BBAB-E7B380AA5E06}" = Windows XP Targeting with C++
"{F395FD4F-40E5-7B56-2BCB-B3CF52B3B52C}" = Windows App Certification Kit x64
"{F3BBC56F-2282-4464-952F-A89772181F30}" = Microsoft SQL Server Data Tools – Database Projects – Web installer entry point
"{F5223DC8-BBC8-360B-B118-39FA4EB3D7DD}" = Visual C++ Compiler/Tools X86 Base Resource Package
"{F5275D1C-D133-486D-8F07-D6C571F0A8EC}" = Command & Conquer™ Red Alert 2 and Yuri’s Revenge
"{F65AF5A5-183B-3905-959C-04A9A0C9EEF7}" = Microsoft Visual Studio Premium 2015 Preview - ENU
"{F6991D8D-6913-3E49-8647-D4108FFF710F}" = Visual C++ Compiler/Tools Premium X86 ARM Cross Package
"{F6DFB592-F444-3C32-B38E-6ACADFFDA171}" = Visual C++ Compiler/Tools Premium X86 Base Resource Package
"{F80B10DB-1859-4E8F-93C5-325BA05E6BCF}" = Dotfuscator and Analytics Community Edition 5.16.0
"{F8C9FC10-1C58-3291-908C-A75106FDC8B6}" = Visual C++ Library MFC X86 Package
"{F8CFEB22-A2E7-3971-9EDA-4B11EDEFC185}" = Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.21005
"{F943E4FA-7172-4FF7-B0CF-D880BFB42FCF}" = Microsoft LightSwitch for Visual Studio 2015 Preview Core
"{F9843E68-4E61-41B0-946E-66989DB35902}" = WCF Data Services 5.6.2 Runtime
"{FA575F06-AD3A-3A0B-81EF-EE3E1D8F6368}" = Visual C++ IDE Desktop Plus Resource Package
"{FA804794-2CCB-4301-954F-2C2894698876}" = Microsoft SQL Server Data Tools - enu (11.1.20627.00)
"{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}" = Microsoft SQL Server 2012 Data-Tier App Framework 
"{FBBC8076-BB21-4E06-9FA0-309AEF6E35EE}" = Microsoft ASP.NET Web Pages 2 Runtime
"{FCC95978-2484-4DE0-90C1-0937E838DA70}" = Microsoft Visual C++ 2012 Compilers For Windows Phone
"{FCD3548F-183A-405B-A548-07D3A053D590}" = Behaviors SDK (Windows Phone) for Visual Studio 2013
"{FD232ED3-7C6D-361C-BE66-8DC1A0CD8E9E}" = Visual C++ IDE Professional Plus Resource Package
"{FE9EAD1D-BD23-3585-A21C-603D8921A52F}" = Microsoft Visual Studio 2015 Preview Shell (Minimum) Resources
"{FEB375AB-6EEC-3929-8FAF-188ED81DD8B5}" = Microsoft Help Viewer 2.0
"{FF8D053F-4962-30DA-95D6-83F73F28D39D}" = Visual C++ Professional Items Resource Package
"{FF9EF123-9D0B-49E6-B437-0628E149C2FE}" = Windows Phone 8.1 Tools for Visual Studio 2015 Preview - ENU
"360TotalSecurity" = 360 Total Security
"Adobe Creative Cloud" = Adobe Creative Cloud
"Adobe Flash Player NPAPI" = Adobe Flash Player 16 NPAPI
"Adobe Photoshop CC 14.2.1" = Adobe Photoshop CC 14.2.1
"Allok Video Converter_is1" = Allok Video Converter 4.6.0529
"Battle.net" = Battle.net
"Bioshock TR" = Bioshock Türkçe Yama v1.00
"DAEMON Tools Lite" = DAEMON Tools Lite
"Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2)
"DomDomSoft Manga Downloader" = DomDomSoft Manga Downloader (remove only)
"FileZilla Client" = FileZilla Client 3.9.0.6
"Freemake Video Converter_is1" = Freemake Video Converter version 4.1.5
"Git_is1" = Git version 1.9.0-preview20140217
"Google Chrome" = Google Chrome
"Internet Download Manager" = Internet Download Manager
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 10.8.0
"Microsoft Help Viewer 2.0" = Microsoft Help Viewer 2.0
"Microsoft Help Viewer 2.2" = Microsoft Help Viewer 2.2
"Mozilla Firefox 34.0.5 (x86 tr)" = Mozilla Firefox 34.0.5 (x86 tr)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"Notepad++" = Notepad++
"Origin" = Origin
"PDF Architect 2" = PDF Architect 2
"PhpStorm 8.0.1" = JetBrains PhpStorm 8.0.1
"PunkBusterSvc" = PunkBuster Services
"Steam App 105450" = Age of Empires® III: Complete Collection
"Steam App 13520" = Far Cry
"Steam App 19900" = Far Cry 2
"Steam App 218620" = PAYDAY 2
"Steam App 220240" = Far Cry® 3
"Steam App 221380" = Age of Empires II: HD Edition
"Steam App 222880" = Insurgency
"Steam App 233270" = Far Cry® 3 Blood Dragon
"Steam App 234670" = NARUTO SHIPPUDEN: Ultimate Ninja STORM 3 Full Burst
"Steam App 245470" = Democracy 3
"Steam App 252490" = Rust
"Steam App 322330" = Don't Starve Together Beta
"Steam App 4000" = Garry's Mod
"Steam App 550" = Left 4 Dead 2
"Steam App 57690" = Tropico 4
"Steam App 7670" = BioShock
"Steam App 8850" = BioShock 2
"Steam App 8870" = BioShock Infinite
"SubtitleWorkshop" = Subtitle Workshop 2.51
"TeamViewer" = TeamViewer 10
"The Elder Scrolls V Skyrim TR" = The Elder Scrolls V Skyrim Türkçe Yama Uyum Programı v1.00
"tixati" = Tixati
"Uplay" = Uplay
 
[color=#E56717]========== HKEY_CURRENT_USER Uninstall List ==========[/color]
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"5f7eb300e2ea4ebf" = GitHub
"AceStream" = Ace Stream Media 3.0.5
"GameRanger" = GameRanger
"UnityWebPlayer" = Unity Web Player
 
[color=#E56717]========== Last 20 Event Log Errors ==========[/color]
 
[ Application Events ]
Error - 29.1.2015 21:06:52 | Computer Name = ihocan | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Şifreleme Hizmetleri, Sistem Yazıcısı Nesnesi'nde OnIdentity() çağrısını
 işlerken başarısız oldu.  Details: AddLegacyDriverFiles: Unable to back up image of
 binary TAP-Win32 Adapter V9 (Tunngle).  System Error: Sistem belirtilen dosyayı bulamıyor.
.
 
Error - 29.1.2015 21:15:52 | Computer Name = ihocan | Source = SideBySide | ID = 16842785
Description = "C:\Users\ihsan\Downloads\vcredist_arm.exe" için etkinleştirme içeriği
 oluşturulamadı.  Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"
 Bağımlı Derlemesi bulunamadı.  Lütfen ayrıntılı tanılama için sxstrace.exe programını
 kullanın.
 
Error - 29.1.2015 22:38:59 | Computer Name = ihocan | Source = Report Server Windows Service (MSSQLSERVER) | ID = 107
Description = Report Server Windows Service (MSSQLSERVER) cannot connect to the 
report server database.
 
Error - 30.1.2015 00:39:11 | Computer Name = ihocan | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1
 uygulamasının etkinleştirilmesi şu hatayla başarısız oldu: -2144927142 Ek bilgi
 için Microsoft-Windows-TWinUI/Operational günlüğüne bakın.
 
Error - 30.1.2015 00:39:11 | Computer Name = ihocan | Source = Microsoft-Windows-Immersive-Shell | ID = 5973
Description = microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1
 uygulamasının etkinleştirilmesi şu hatayla başarısız oldu: -2144927142 Ek bilgi
 için Microsoft-Windows-TWinUI/Operational günlüğüne bakın.
 
Error - 30.1.2015 02:12:22 | Computer Name = ihocan | Source = Application Hang | ID = 1002
Description = LiveComm.exe programının 17.5.9600.20689 sürümü, Windows ile birlikte
 çalışmayı durdurdu ve kapatıldı. Sorun hakkında daha fazla bilgi olup olmadığını
 görmek için Eylem Merkezi denetim masasında sorunun geçmişini denetleyin.    İşlem 
Kimlik No: d0    Başlatma Saati: 01d03c52fa76c686    Sona Erdirme Saati: 4294967295    Uygulama
 Yolu: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe

Rapor
 Kimliği: ee5d360d-a846-11e4-8293-8c89a50ef469    Hatalı paket tam adı: microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe

Hatalı
 paketle ilgili uygulama kimliği: ppleae38af2e007f4358a809ac99a64a67c1  
 
Error - 30.1.2015 07:52:23 | Computer Name = ihocan | Source = Report Server Windows Service (MSSQLSERVER) | ID = 107
Description = Report Server Windows Service (MSSQLSERVER) cannot connect to the 
report server database.
 
Error - 30.1.2015 22:25:17 | Computer Name = ihocan | Source = Application Error | ID = 1000
Description = Hatalı uygulama adı: Allok Video Converter v4.6.0529 Portable.exe,
 sürüm: 1.0.2.0, zaman damgası: 0x00000031  Hatalı modül adı: unknown, sürüm: 0.0.0.0,
 zaman damgası: 0x00000000  Özel durum kodu: 0xc0000005  Hata uzaklığı 0x020895c1  Hatalı
 işlem kimliği: 0x22bc  Uygulama başlangıç zamanı: 0x01d03cfd1f82c5f5  Hatalı uygulama
 yolu: C:\Users\ihsan\Desktop\downloads\Allok Video Converter v4.6.0529 + Portable\Allok
 Video Converter v4.6.0529 Portable.exe  Hatalı modül yolu: unknown  Rapor kimliği: 
64d3d730-a8f0-11e4-8294-8c89a50ef469  Hatalı paket tam adı:   Hatalı paketle ilgili 
uygulama kimliği: 
 
Error - 30.1.2015 23:05:47 | Computer Name = ihocan | Source = SideBySide | ID = 16842830
Description = "C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\Creative 
Cloud Uninstaller.exe" için etkinleştirme içeriği oluşturulamadı. "" adlı bildirim
 veya ilke dosyasında . satırda hata var.  Uygulama için gereken bir bileşen sürümü
 halen etkin olan bir başka bileşen sürümüyle çakışıyor.  Çakışan bileşenler:  Bileşen
 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Bileşen
 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.
 
Error - 1.2.2015 14:08:20 | Computer Name = ihocan | Source = Application Hang | ID = 1002
Description = wwahost.exe programının 6.3.9600.17031 sürümü, Windows ile birlikte
 çalışmayı durdurdu ve kapatıldı. Sorun hakkında daha fazla bilgi olup olmadığını
 görmek için Eylem Merkezi denetim masasında sorunun geçmişini denetleyin.    İşlem 
Kimlik No: 2a70    Başlatma Saati: 01d03e4956c2c1a5    Sona Erdirme Saati: 4294967295    Uygulama
 Yolu: C:\Windows\syswow64\wwahost.exe    Rapor Kimliği: 4aa0e109-aa3d-11e4-8294-8c89a50ef469

Hatalı
 paket tam adı: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c    Hatalı paketle ilgili
 uygulama kimliği: App  
 
[ System Events ]
Error - 30.1.2015 07:52:23 | Computer Name = ihocan | Source = Service Control Manager | ID = 7034
Description = 360 Total Security hizmeti beklenmeyen bir şekilde sonlandırıldı. 
Bu durum 1 defa oluştu.
 
Error - 30.1.2015 09:22:59 | Computer Name = ihocan | Source = volsnap | ID = 393252
Description = Gölge kopya depolama ortamı kullanıcı tarafından tanımlanan bir sınır
 nedeniyle büyütülemediğinden C: biriminin gölge kopyaları durduruldu.
 
Error - 30.1.2015 11:06:58 | Computer Name = ihocan | Source = DCOM | ID = 10010
Description = 
 
Error - 30.1.2015 20:25:19 | Computer Name = ihocan | Source = Service Control Manager | ID = 7031
Description = TeamViewer 10 hizmeti beklenmedik şekilde sona erdi.  Bu durum 1 defa
 oluştu.  2000 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti yeniden
 başlat.
 
Error - 30.1.2015 20:25:29 | Computer Name = ihocan | Source = Service Control Manager | ID = 7031
Description = TeamViewer 10 hizmeti beklenmedik şekilde sona erdi.  Bu durum 2 defa
 oluştu.  2000 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti yeniden
 başlat.
 
Error - 31.1.2015 05:49:36 | Computer Name = ihocan | Source = Service Control Manager | ID = 7011
Description = WSearch hizmetinden işlem yanıtı beklenirken zaman aşımı (30000 milisaniye)
 oluştu.
 
Error - 1.2.2015 14:06:49 | Computer Name = ihocan | Source = Service Control Manager | ID = 7031
Description = Emsisoft Protection Service hizmeti beklenmedik şekilde sona erdi.
  Bu durum 1 defa oluştu.  0 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti
 yeniden başlat.
 
Error - 1.2.2015 14:06:57 | Computer Name = ihocan | Source = Service Control Manager | ID = 7031
Description = Emsisoft Protection Service hizmeti beklenmedik şekilde sona erdi.
  Bu durum 2 defa oluştu.  0 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti
 yeniden başlat.
 
Error - 1.2.2015 14:26:26 | Computer Name = ihocan | Source = Service Control Manager | ID = 7009
Description = Steam Client Service hizmetinin bağlanması beklenirken zaman aşımı
 (30000 milisaniye) oluştu.
 
Error - 1.2.2015 14:26:26 | Computer Name = ihocan | Source = Service Control Manager | ID = 7000
Description = Steam Client Service hizmeti şu hata nedeniyle başlatılamadı:   %%1053
 
 
< End of report >


Edited by ihocan, 01 February 2015 - 03:15 PM.

  • 0

Advertisements


#2
bloopie

bloopie

    Trusted Helper

  • Malware Removal
  • 62 posts
Please Click here!, and follow the recommendations in the guide.

Someone will be along to tell you what steps to take after you post the contents of the scan results.
  • 0

#3
ihocan

ihocan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts

thanks for comment, first time i put wrong log files (hijackthis log :D) i updated the post.


  • 0

#4
bloopie

bloopie

    Trusted Helper

  • Malware Removal
  • 62 posts

Hello ihocan, and welcome to G2G! :wave:

My name is bloopie and I'll be helping you with your problems as best I can! :thumbsup:

I noticed you made a few changes to your first logs you were posting...please don't edit your posts containing logs, as it will only confuse who is helping you.

A few things to keep in mind while we are working together:

  • If you have since resolved the original problem you were having, I would appreciate it if you let me know.
  • If you are unsure about any of the steps just post what you can and I will guide you!
  • Please tell me if you have your original Windows CD/DVD available.
  • Please copy and paste all logs here unless otherwise instructed!
  • Upon completing the steps below I will review your topic an do my best to resolve your issues.
  • Please do not run any other tools without my instruction to do so!

====================

At this time I'd like you to run FRST, and post the resultant logs in your next reply. ...Instructions on running the tool are below:

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. You will need the 64-bit version.

  • Right-click FRST then click "Run as administrator"
  • When the tool opens, click Yes to disclaimer.
  • Press the Scan button.
  • When finished, it will produce a log called FRST.txt in the same directory the tool was run from.
  • Please copy and paste the log in your next reply.

Note 2: The first time the tool is run it generates another log (Addition.txt - also located in the same directory the tool was run from). Please also paste that, along with the FRST.txt into your next reply.

bloopie


  • 0

#5
ihocan

ihocan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts

i have a original Windows but i dont have dvd if it necessary i will download dreamspark
FRTS Log file

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015
Ran by ihsan (administrator) on IHOCAN on 01-02-2015 23:43:42
Running from C:\Users\ihsan\Downloads
Loaded Profiles: ihsan & MsDtsServer110 & MSSQLServerOLAPService & ReportServer & MSSQLFDLauncher & MSSQLSERVER (Available profiles: ihsan & MsDtsServer110 & MSSQLServerOLAPService & ReportServer & MSSQLFDLauncher & MSSQLSERVER)
Platform: Windows 8.1 Pro (X64) OS Language: Türkçe (Türkiye)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
(Atheros Communications, Inc.) C:\Program Files (x86)\Jumpstart\jswpbapi.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\110\DTS\Binn\MsDtsSrvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSAS11.MSSQLSERVER\OLAP\bin\msmdsrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\vmms.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\fdhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\ws.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(MSI) C:\Program Files (x86)\SCM\Radio Manager.exe
(MSI) C:\Program Files (x86)\SCM\SCM.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VsHub\1.0.0.0\VsHub.exe
() C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Internet Security\a2service.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(OldTimer Tools) C:\Users\ihsan\Desktop\OTL.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(NVIDIA Corporation) C:\Users\ihsan\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [253952 2013-05-07] (Realtek Semiconductor Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2893104 2013-08-23] (ELAN Microelectronics Corp.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [320360 2014-08-04] (Intel Corporation)
HKLM\...\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [406920 2013-09-26] (MSI)
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [408232 2013-09-26] (MSI)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor)
HKLM\...\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM-x32\...\Run: [QHSafeTray] => C:\Program Files (x86)\360\Total Security\safemon\360Tray.exe [270960 2014-12-12] (Qihu Software Co. Limited)
HKLM-x32\...\Run: [jswtrayutil] => C:\Program Files (x86)\Jumpstart\jswtrayutil.exe [528384 2008-09-26] (Atheros Communications, Inc.)
HKLM-x32\...\Run: [AdobeCEPServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CEPServiceManager4\CEPServiceManager.exe [1039248 2013-03-13] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2012-11-29] (Creative Technology Ltd)
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKLM-x32\...\Run: [OmniPage Preload] => C:\Program Files (x86)\Nuance\OmniPage19\OmniPage19.exe [2922824 2013-04-22] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [Nuance OmniPage Ultimate-reminder] => C:\Program Files (x86)\Nuance\OmniPage19\Ereg\Ereg.exe [334152 2013-01-14] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2694320 2014-10-15] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [VsHub.exe] => C:\Program Files (x86)\Common Files\Microsoft Shared\VsHub\1.0.0.0\vshub.exe [141440 2014-11-10] (Microsoft Corporation)
HKLM-x32\...\Run: [emsisoft anti-malware] => c:\program files (x86)\emsisoft internet security\a2guard.exe [4997872 2014-12-31] (Emsisoft GmbH)
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7404312 2015-01-20] (Piriform Ltd)
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3878480 2014-09-03] (Tonec Inc.)
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [174856 2014-11-04] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156840 2014-11-04] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll ()
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (Tonec Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

URLSearchHook: [S-1-5-80-1770670200-1234090253-3451813168-4041049723-2370973757] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-2885764129-887777008-271615777-1616004480-2722851051] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-1770670200-1234090253-3451813168-4041049723-2370973757 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-2885764129-887777008-271615777-1616004480-2722851051 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: PDF Architect Helper -> {691B33B0-B86E-47F3-81C7-56E4FE3B929C} -> C:\Program Files (x86)\PDF Architect 2\creator-ie-helper.dll (pdfforge GmbH)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper -> {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} -> C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft Web Test Recorder 14.0 Helper -> {b924f0b4-0b3c-49c0-bab2-213fb9ebd1d3} -> C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - C:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll (pdfforge GmbH)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0
Tcpip\..\Interfaces\{78FA00C6-2245-43D4-9A83-7FED19DE07AA}: [NameServer] 8.8.8.8,8.8.4.8

FireFox:
========
FF ProfilePath: C:\Users\ihsan\AppData\Roaming\Mozilla\Firefox\Profiles\kg35b0ue.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~4\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect_x86_64 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF Plugin HKU\S-1-5-21-3051402733-4133393625-984315149-1001: @acestream.net/acestreamplugin,version=3.0.5 -> C:\Users\ihsan\AppData\Roaming\ACEStream\player\npace_plugin.dll (Innovative Digital Technologies)
FF Plugin HKU\S-1-5-21-3051402733-4133393625-984315149-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ihsan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3051402733-4133393625-984315149-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex-tr.xml
FF Extension: AS Magic Player - C:\Users\ihsan\AppData\Roaming\Mozilla\Firefox\Profiles\kg35b0ue.default\Extensions\[email protected] [2015-01-08]
FF Extension: User Agent Switcher - C:\Users\ihsan\AppData\Roaming\Mozilla\Firefox\Profiles\kg35b0ue.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2015-01-15]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: PDF Architect 2 Creator - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-10-18]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox
FF Extension: 360网页保护 - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox [2014-09-28]
FF HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Firefox\Extensions: [[email protected]] - C:\Users\ihsan\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\ihsan\AppData\Roaming\IDM\idmmzcc5 [2014-09-28]
FF HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\ihsan\AppData\Roaming\IDM\idmmzcc5

Chrome: 
=======
CHR HomePage: Default -> hxxp://klit.startnow.com/?src=startpage&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=US&install_date=20120929&user_guid=3220074E5BF444FFABB0303EA47C4FB8&machine_id=67326ca3ae2301667ef9afd37f603db0&browser=CR&os=win&os_version=6.1-x86-SP0
CHR StartupUrls: Default -> "https://www.google.com.tr/"
CHR DefaultSearchKeyword: Default -> google.com.trhttps://www.google.com.tr/preferences?hl=tr
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (From Dust) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\anelkojiepicmcldgnmkplocifmegpfj [2014-12-28]
CHR Extension: (Google Drive) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-28]
CHR Extension: (Manga Viewer) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bebalkdfejapnfbngpmhchkboajaofen [2014-12-28]
CHR Extension: (Adguard AdBlocker) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2014-12-29]
CHR Extension: (MEGA) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2014-12-28]
CHR Extension: (Adblock Plus) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-12-28]
CHR Extension: (Pushbullet) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2015-01-10]
CHR Extension: (Google Apps Script) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoieeedlomnegifmaghhjnghhmcldobl [2014-12-28]
CHR Extension: (+ Flip It) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbmppankahdodchhioklnbcmohehhjoa [2014-12-28]
CHR Extension: (ZenMate Security & Privacy VPN) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2014-12-28]
CHR Extension: (Office Belgeleri Düzenleme) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbkeegbaiigmenfmjfclcdgdpimamgkj [2014-12-28]
CHR Extension: (Quick Javascript Switcher) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\geddoclleiomckbhadiaipdggiiccfje [2014-12-28]
CHR Extension: (Orta Dünya'da Bir Yolculuk) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjgkjeheegjnnmheaflhdocglkiegoni [2014-12-28]
CHR Extension: (360 İnternet Koruması) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\glcimepnljoholdmjchkloafkggfoijh [2014-12-28]
CHR Extension: (Bookmark Manager) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2014-12-29]
CHR Extension: (Tureng Dictionary) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihedienojfhdahpomfldoejaimefofff [2014-12-28]
CHR Extension: (Streamus™) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbnkffmindojffecdhbbmekbmkkfpmjd [2014-12-28]
CHR Extension: (IDM Integration Module) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn [2014-12-28]
CHR Extension: (Chrome extension source viewer) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifpbeccnghkjeaalbbjmodiffmgedin [2014-12-28]
CHR Extension: (Google Inbox Checker (Inbox by Gmail)) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\llldafpkkdiljghncbdnkgfinfiifnig [2014-12-28]
CHR Extension: (Google Mail Checker) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-12-28]
CHR Extension: (Google Cüzdan) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-28]
CHR Extension: (Chrome Apps & Extensions Developer Tool) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohmmkhmmmpcnpikjeljgnaoabkaalbgc [2014-12-28]
CHR Extension: (Gmail) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-28]
CHR Extension: (Chrome Dev Editor (developer preview)) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnoffddplpippgcfjdhbmhkofpnaalpg [2014-12-28]
CHR HKLM\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2014-09-12]
CHR HKLM-x32\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2014-09-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Internet Security\a2service.exe [4920104 2014-12-31] (Emsisoft GmbH)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [56832 2013-08-28] () [File not signed]
S3 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
S3 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2014-12-23] (Microsoft Corporation)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [174624 2015-01-19] (EasyAntiCheat Ltd)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [99632 2013-08-23] (ELAN Microelectronics Corp.)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2014-12-13] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-08-04] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-12] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [22744 2014-10-15] (Microsoft Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
R2 jswpbapi; C:\Program Files (x86)\Jumpstart\jswpbapi.exe [265216 2008-09-26] (Atheros Communications, Inc.) [File not signed]
S3 jswpsapi; C:\Program Files (x86)\Jumpstart\jswpsapi.exe [954368 2008-09-26] (Atheros Communications, Inc.) [File not signed]
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2013-09-26] (Micro-Star International Co., Ltd.) [File not signed]
R2 MsDtsServer110; C:\Program Files\Microsoft SQL Server\110\DTS\Binn\MsDtsSrvr.exe [218200 2012-02-11] (Microsoft Corporation)
R3 MSSQLFDLauncher; C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe [49752 2012-02-11] (Microsoft Corporation)
R2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [191064 2012-02-11] (Microsoft Corporation)
R2 MSSQLServerOLAPService; C:\Program Files\Microsoft SQL Server\MSAS11.MSSQLSERVER\OLAP\bin\msmdsrv.exe [61538904 2012-02-11] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19823248 2014-12-13] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910128 2015-01-28] (Electronic Arts)
R3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1771560 2014-10-10] (pdfforge GmbH)
S4 PDF Architect 2 Creator; C:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
S4 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-10-10] (pdfforge GmbH)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-11-16] ()
R2 QHActiveDefense; C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe [707184 2014-12-12] ()
R2 ReportServer; C:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2348632 2012-02-11] (Microsoft Corporation)
S3 SQL Server Distributed Replay Client; C:\Program Files (x86)\Microsoft SQL Server\110\Tools\DReplayClient\DReplayClient.exe [137304 2012-02-11] (Microsoft Corporation)
S3 SQL Server Distributed Replay Controller; C:\Program Files (x86)\Microsoft SQL Server\110\Tools\DReplayController\DReplayController.exe [342104 2012-02-11] (Microsoft Corporation)
S3 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [597080 2012-02-11] (Microsoft Corporation)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH)
R2 vmms; C:\Windows\system32\vmms.exe [13401600 2014-12-23] (Microsoft Corporation)
S3 VsEtwService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89240 2014-11-10] (Microsoft Corporation)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [147664 2014-11-10] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R1 360AntiHacker; C:\Windows\System32\Drivers\360AntiHacker64.sys [100424 2014-09-23] (360.cn)
R3 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [77896 2014-12-12] (360.cn)
R1 360Box64; C:\Windows\System32\DRIVERS\360Box64.sys [305736 2014-12-12] (360.cn)
S3 360Camera; C:\Windows\System32\Drivers\360Camera64.sys [40520 2014-09-23] (360.cn)
R1 360FsFlt; C:\Windows\System32\DRIVERS\360FsFlt.sys [312400 2014-09-23] (Qihu 360 Software Co., Ltd.)
R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT INTERNET SECURITY\a2accx64.sys [71472 2014-05-12] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files (x86)\Emsisoft Internet Security\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Internet Security\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files (x86)\Emsisoft Internet Security\a2util64.sys [23088 2014-05-12] (Emsisoft GmbH)
S1 BAPIDRV; C:\Windows\System32\DRIVERS\BAPIDRV64.sys [180816 2014-09-23] (Qihu 360 Software Co., Ltd.)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 cleanhlp; C:\Program Files (x86)\Emsisoft Internet Security\cleanhlp64.sys [57024 2013-12-04] (Emsisoft GmbH)
S3 DIRECTIO; C:\Program Files\PerformanceTest\DirectIo64.sys [31160 2014-04-24] ()
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-10-30] (Disc Soft Ltd)
R3 fwndis; C:\Windows\system32\DRIVERS\fwndis64.sys [491632 2015-01-01] ()
S1 fwwfp; C:\Program Files (x86)\Emsisoft Internet Security\fwwfp764.sys [414936 2015-01-01] ()
S3 hid7906; C:\Windows\SysWOW64\drivers\hid7906.sys [34963 2007-12-12] (Compuware Corporation) [File not signed]
S3 hid8101; C:\Windows\SysWOW64\drivers\hid8101.sys [37024 2007-12-03] (Compuware Corporation) [File not signed]
S3 hid8103; C:\Windows\SysWOW64\drivers\hid8103.sys [34587 2007-11-28] (Compuware Corporation) [File not signed]
R1 hvservice; C:\Windows\System32\drivers\hvservice.sys [68960 2014-12-23] (Microsoft Corporation)
S3 lunparser; C:\Windows\System32\drivers\lunparser.sys [19456 2014-12-23] (Microsoft Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-08] (Intel Corporation)
S3 NPF; C:\Windows\System32\drivers\NPF.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2014-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 passthruparser; C:\Windows\System32\drivers\passthruparser.sys [22016 2014-12-23] (Microsoft Corporation)
S3 pvhdparser; C:\Windows\System32\drivers\pvhdparser.sys [27136 2014-12-23] (Microsoft Corporation)
S4 RsFx0200; C:\Windows\System32\DRIVERS\RsFx0200.sys [334936 2012-02-11] (Microsoft Corporation)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [547032 2013-07-04] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [2944216 2013-08-21] (Realtek Semiconductor Corporation                           )
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 vhdparser; C:\Windows\System32\drivers\vhdparser.sys [18944 2014-12-23] (Microsoft Corporation)
R3 VMSMP; C:\Windows\system32\DRIVERS\vmswitch.sys [690688 2014-08-26] (Microsoft Corporation)
S3 VMSP; C:\Windows\system32\DRIVERS\vmswitch.sys [690688 2014-08-26] (Microsoft Corporation)
S3 VMSVSF; C:\Windows\system32\DRIVERS\vmswitch.sys [690688 2014-08-26] (Microsoft Corporation)
S3 VMSVSP; C:\Windows\system32\DRIVERS\vmswitch.sys [690688 2014-08-26] (Microsoft Corporation)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-13] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-01 23:43 - 2015-02-01 23:44 - 00036206 _____ () C:\Users\ihsan\Downloads\FRST.txt
2015-02-01 23:42 - 2015-02-01 23:43 - 00000000 ____D () C:\FRST
2015-02-01 23:41 - 2015-02-01 23:41 - 02131456 _____ (Farbar) C:\Users\ihsan\Downloads\FRST64.exe
2015-02-01 23:08 - 2015-02-01 23:14 - 00205616 _____ () C:\Users\ihsan\Desktop\Extras.Txt
2015-02-01 23:07 - 2015-02-01 23:13 - 00185112 _____ () C:\Users\ihsan\Desktop\OTL.Txt
2015-02-01 22:55 - 2015-02-01 22:55 - 00602112 _____ (OldTimer Tools) C:\Users\ihsan\Downloads\OTL.exe
2015-02-01 22:55 - 2015-02-01 22:55 - 00602112 _____ (OldTimer Tools) C:\Users\ihsan\Desktop\OTL.exe
2015-02-01 22:51 - 2015-02-01 22:51 - 00468480 _____ () C:\Users\ihsan\Downloads\CKScanner.exe
2015-02-01 20:43 - 2015-02-01 20:43 - 05661717 _____ () C:\Users\ihsan\Downloads\chipset_intel_9.4.0.1026_0xb351380a_818700.zip
2015-02-01 20:43 - 2015-02-01 20:43 - 05661717 _____ () C:\Users\ihsan\Downloads\chipset_intel_9.4.0.1026_0xb351380a_818700 (2).zip
2015-02-01 20:43 - 2015-02-01 20:43 - 05661717 _____ () C:\Users\ihsan\Downloads\chipset_intel_9.4.0.1026_0xb351380a_818700 (1).zip
2015-02-01 20:28 - 2015-02-01 20:36 - 00013721 _____ () C:\Users\ihsan\Downloads\hijackthis.log
2015-02-01 20:27 - 2015-02-01 20:27 - 00388608 _____ (Trend Micro Inc.) C:\Users\ihsan\Downloads\HijackThis.exe
2015-01-31 09:00 - 2015-01-31 09:00 - 00030289 _____ () C:\Users\ihsan\Downloads\(336817)Edge_of_Tomorrow_23.976fps_1CD_Turkce_SubRip_DiVXPlanet.rar
2015-01-31 08:56 - 2015-01-31 08:56 - 00031049 _____ () C:\Users\ihsan\Downloads\(336078)Edge_of_Tomorrow_23.976fps_1CD_Turkce_SubRip_DiVXPlanet.rar
2015-01-31 08:42 - 2015-01-31 08:42 - 00034598 _____ () C:\Users\ihsan\Downloads\(328659)Noah_23.976fps_1CD_Turkce_SubRip_DiVXPlanet.rar
2015-01-31 04:30 - 2015-01-31 10:38 - 00000000 ____D () C:\OutputFolder
2015-01-31 04:27 - 2015-01-31 04:29 - 00000000 ____D () C:\Program Files (x86)\Allok Video Converter
2015-01-31 04:27 - 2015-01-31 04:27 - 00001085 _____ () C:\Users\Public\Desktop\Allok Video Converter.lnk
2015-01-31 04:27 - 2015-01-31 04:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Allok Video Converter
2015-01-31 04:27 - 2007-04-12 14:19 - 00129024 _____ () C:\Windows\SysWOW64\AVERM.dll
2015-01-31 04:27 - 2006-09-26 13:57 - 00028672 _____ () C:\Windows\SysWOW64\AVEQT.dll
2015-01-31 04:20 - 2015-01-31 04:20 - 00219648 _____ () C:\Users\ihsan\Downloads\scheduling-05.ppt
2015-01-31 04:00 - 2015-01-31 04:00 - 04882432 _____ () C:\Users\ihsan\Downloads\ch7.ppt
2015-01-31 03:59 - 2015-01-31 03:59 - 03999232 _____ () C:\Users\ihsan\Downloads\ch6.ppt
2015-01-31 03:38 - 2015-01-31 03:38 - 00038632 _____ () C:\Users\ihsan\Downloads\(324302)RoboCop_23.976fps_1CD_Turkce_SubRip_DiVXPlanet.rar
2015-01-31 00:59 - 2015-01-31 01:00 - 00424448 _____ () C:\Users\ihsan\Downloads\csc4320 Chapter 5-2.ppt
2015-01-31 00:48 - 2015-01-31 03:25 - 00000000 ____D () C:\Users\ihsan\Documents\Freemake
2015-01-31 00:48 - 2015-01-31 03:25 - 00000000 ____D () C:\ProgramData\Freemake
2015-01-31 00:48 - 2015-01-31 00:48 - 00001336 _____ () C:\Users\Public\Desktop\Freemake Video Converter.lnk
2015-01-31 00:48 - 2015-01-31 00:48 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2015-01-31 00:48 - 2015-01-31 00:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
2015-01-31 00:46 - 2015-01-31 00:48 - 00000000 ____D () C:\Program Files (x86)\Freemake
2015-01-31 00:14 - 2015-01-31 00:15 - 01270544 _____ (Ellora Assets Corporation ) C:\Users\ihsan\Downloads\FreemakeVideoConverterSetup.exe
2015-01-31 00:13 - 2015-01-31 00:13 - 00008844 _____ () C:\Users\ihsan\Downloads\Edge_of_Tomorrow_2014_720p.torrent
2015-01-31 00:08 - 2015-01-31 00:08 - 00010011 _____ () C:\Users\ihsan\Downloads\Noah_2014_720p.torrent
2015-01-31 00:08 - 2015-01-31 00:08 - 00009367 _____ () C:\Users\ihsan\Downloads\RoboCop_2014_720p.torrent
2015-01-30 21:50 - 2015-01-30 21:51 - 00850432 _____ () C:\Users\ihsan\Downloads\Scheduling.ppt
2015-01-30 05:07 - 2015-01-30 05:07 - 00000000 ____D () C:\Users\ihsan\Downloads\Video
2015-01-30 04:39 - 2015-02-01 20:31 - 00184336 _____ () C:\Windows\WindowsUpdate.log
2015-01-30 04:37 - 2015-02-01 23:40 - 00002264 _____ () C:\Windows\setupact.log
2015-01-30 04:37 - 2015-01-30 04:37 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-30 04:36 - 2015-01-30 04:36 - 00002412 _____ () C:\Windows\PFRO.log
2015-01-30 04:34 - 2015-01-30 04:34 - 00000000 ____D () C:\ProgramData\Emsisoft
2015-01-30 04:10 - 2015-01-30 04:10 - 00037376 ___SH () C:\Users\ihsan\Desktop\Thumbs.db
2015-01-30 04:10 - 2015-01-30 04:10 - 00001138 _____ () C:\Users\Public\Desktop\Emsisoft Internet Security.lnk
2015-01-30 04:10 - 2015-01-30 04:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Internet Security
2015-01-30 04:09 - 2015-02-01 23:07 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Internet Security
2015-01-30 04:09 - 2015-01-01 21:36 - 00491632 _____ () C:\Windows\system32\Drivers\fwndis64.sys
2015-01-30 03:30 - 2015-01-30 03:45 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Wise Registry Cleaner
2015-01-30 03:29 - 2011-07-31 15:14 - 00076565 _____ (RaProducts.org) C:\Users\ihsan\Desktop\PureRa.exe
2015-01-30 03:25 - 2015-01-30 03:25 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-01-30 03:25 - 2015-01-30 03:25 - 00000834 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-01-30 03:25 - 2015-01-30 03:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-01-30 03:25 - 2015-01-30 03:25 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-30 03:05 - 2015-01-30 03:05 - 00000196 _____ () C:\Users\ihsan\Desktop\ksifre.rar
2015-01-30 03:02 - 2015-01-30 03:11 - 00000000 ____D () C:\Users\ihsan\Desktop\hellsing altyazı
2015-01-30 02:33 - 2015-01-30 02:33 - 00000000 ____D () C:\Users\ihsan\AppData\Local\VS Revo Group
2015-01-30 02:32 - 2015-01-30 02:32 - 00000000 ____D () C:\ProgramData\VS Revo Group
2015-01-30 02:32 - 2015-01-30 02:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2015-01-30 02:32 - 2015-01-30 02:32 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-01-30 02:32 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2015-01-29 00:46 - 2015-01-29 05:20 - 00000000 ____D () C:\Users\ihsan\Documents\GenTool
2015-01-28 22:53 - 2015-01-29 03:11 - 00000000 ____D () C:\Users\ihsan\Documents\Command and Conquer Generals Zero Hour Data
2015-01-28 22:53 - 2015-01-29 03:11 - 00000000 ____D () C:\Users\ihsan\Documents\Command and Conquer Generals Data
2015-01-28 22:53 - 2015-01-28 22:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Command and Conquer Generals and Zero Hour
2015-01-26 02:10 - 2015-01-26 02:10 - 00000000 ____D () C:\data_from_forms
2015-01-26 02:09 - 2015-01-26 02:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ETS
2015-01-26 02:09 - 2015-01-26 02:09 - 00000000 ____D () C:\Program Files (x86)\ETS
2015-01-26 02:06 - 2015-01-26 02:06 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Downloaded Installations
2015-01-20 02:29 - 2015-01-20 02:30 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Sublight
2015-01-20 02:29 - 2015-01-20 02:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sublight
2015-01-20 02:29 - 2015-01-20 02:29 - 00000000 ____D () C:\Program Files\Sublight
2015-01-19 14:52 - 2015-01-19 02:17 - 00174624 _____ (EasyAntiCheat Ltd) C:\Windows\SysWOW64\EasyAntiCheat.exe
2015-01-19 01:57 - 2014-11-22 12:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-01-19 01:57 - 2014-11-22 12:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-01-19 00:42 - 2015-01-19 00:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Command and Conquer Red Alert 2
2015-01-18 23:21 - 2015-01-28 22:51 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2015-01-18 23:04 - 2015-01-28 22:46 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Origin
2015-01-18 23:04 - 2015-01-18 23:28 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Origin
2015-01-18 17:50 - 2015-01-20 02:40 - 00121105 _____ () C:\Users\ihsan\Desktop\pk altyazı.srt
2015-01-18 17:36 - 2015-01-18 17:36 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\URUSoft
2015-01-18 17:36 - 2015-01-18 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\URUSoft
2015-01-18 17:36 - 2015-01-18 17:36 - 00000000 ____D () C:\Program Files (x86)\URUSoft
2015-01-18 14:55 - 2013-07-09 07:58 - 00263896 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtsUStor.sys
2015-01-18 14:55 - 2013-04-25 12:12 - 09889352 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtsUStoricon.dll
2015-01-16 00:10 - 2015-01-30 03:30 - 00000000 ____D () C:\Users\ihsan\Desktop\işletimsistemleri
2015-01-14 17:16 - 2014-12-19 08:26 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 17:16 - 2014-12-12 04:04 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 17:16 - 2014-12-12 02:51 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ahcache.sys
2015-01-14 17:16 - 2014-12-09 03:50 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00535640 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00531616 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00448792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00413248 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00372408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00108944 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00038264 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2015-01-14 17:16 - 2014-12-08 21:42 - 00033584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
2015-01-14 17:16 - 2014-12-06 05:17 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 17:16 - 2014-12-06 03:41 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 17:16 - 2014-12-06 03:35 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2015-01-14 17:16 - 2014-10-29 06:00 - 00465320 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2015-01-14 17:16 - 2014-10-29 06:00 - 00139984 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2015-01-14 17:16 - 2014-10-29 05:52 - 00500016 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-01-14 17:16 - 2014-10-29 05:52 - 00482872 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-01-14 17:16 - 2014-10-29 05:52 - 00394120 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-01-14 17:16 - 2014-10-29 05:52 - 00272248 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-01-14 17:16 - 2014-10-29 05:12 - 00413136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2015-01-14 17:16 - 2014-10-29 05:12 - 00136296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2015-01-14 17:16 - 2014-10-29 05:07 - 00424544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2015-01-14 17:16 - 2014-10-29 05:07 - 00370424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2015-01-14 17:16 - 2014-10-29 05:07 - 00344536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2015-01-14 17:16 - 2014-10-29 04:44 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2015-01-14 17:16 - 2014-10-29 03:59 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
2015-01-14 17:16 - 2014-10-29 03:24 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-14 17:16 - 2014-10-29 03:02 - 00911360 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-01-14 17:16 - 2014-10-29 03:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-12 21:40 - 2015-01-12 21:40 - 00000000 ____D () C:\Users\ihsan\Documents\Red Alert 3
2015-01-12 21:34 - 2015-01-12 21:34 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Red Alert 3
2015-01-12 18:08 - 2015-01-12 18:08 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Aegisub
2015-01-12 09:33 - 2015-01-12 09:39 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Dev-Cpp
2015-01-12 09:32 - 2015-01-12 09:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bloodshed Dev-C++
2015-01-12 09:32 - 2015-01-12 09:32 - 00000000 ____D () C:\Dev-Cpp
2015-01-09 21:10 - 2015-01-09 21:12 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Bioshock2Steam
2015-01-09 21:10 - 2015-01-09 21:10 - 00000000 ____D () C:\Users\ihsan\Documents\Bioshock2
2015-01-09 20:38 - 2015-01-09 21:09 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Bioshock
2015-01-09 20:38 - 2015-01-09 20:54 - 00000000 ____D () C:\Users\ihsan\Documents\Bioshock
2015-01-09 20:38 - 2015-01-09 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bioshock Türkçe
2015-01-09 13:44 - 2015-02-01 23:18 - 00000814 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-09 13:44 - 2015-01-24 22:18 - 00003702 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-08 20:33 - 2015-01-08 20:33 - 00036577 _____ () C:\Users\ihsan\Desktop\[kickass.so]cbm.hellsing.ultimate.1.10.complete.dual.audio.bdrip.720p.8bit.torrent
2015-01-08 20:32 - 2015-01-14 21:12 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\vlc
2015-01-08 20:08 - 2015-01-08 20:08 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ace Stream Media
2015-01-08 17:59 - 2015-01-08 17:59 - 00038519 _____ () C:\Users\ihsan\Desktop\Hellsing Ultimate OVA 01-10.torrent
2015-01-07 17:12 - 2015-01-07 17:12 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1C5070DB.sys
2015-01-06 02:42 - 2015-01-06 02:42 - 00000000 ____D () C:\Users\ihsan\Desktop\This War Of Mine
2015-01-05 21:31 - 2015-01-05 21:31 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Mozilla
2015-01-05 21:31 - 2015-01-05 21:31 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\huawei
2015-01-05 21:31 - 2015-01-05 21:31 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Mozilla
2015-01-05 21:31 - 2015-01-05 21:31 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Macromedia
2015-01-05 21:30 - 2015-01-05 21:30 - 00001171 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-01-05 21:30 - 2015-01-05 21:30 - 00000000 ____D () C:\ProgramData\Mozilla
2015-01-05 21:30 - 2015-01-05 21:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-05 21:07 - 2015-01-05 21:07 - 00000000 ____D () C:\ProgramData\TTNetIlkYardim
2015-01-05 16:48 - 2015-01-05 16:48 - 00000000 ____D () C:\ProgramData\Verimatrix
2015-01-04 15:03 - 2015-01-30 03:29 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\TeamViewer
2015-01-04 15:03 - 2015-01-04 15:04 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2015-01-04 15:03 - 2015-01-04 15:03 - 00001055 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-01 23:43 - 2014-09-28 12:52 - 02230282 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-01 23:43 - 2013-08-23 00:53 - 00896376 _____ () C:\Windows\system32\perfh01F.dat
2015-02-01 23:43 - 2013-08-23 00:53 - 00224000 _____ () C:\Windows\system32\perfc01F.dat
2015-02-01 23:39 - 2014-09-28 15:06 - 00038972 _____ () C:\Users\ihsan\AppData\Local\BTServer.log
2015-02-01 23:00 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2015-02-01 20:56 - 2014-09-28 12:55 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3051402733-4133393625-984315149-1001
2015-02-01 20:03 - 2014-09-28 12:52 - 00000000 __RDO () C:\Users\ihsan\SkyDrive
2015-02-01 20:02 - 2014-09-28 15:04 - 00000000 ____D () C:\ProgramData\Realtek
2015-01-31 14:59 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF
2015-01-31 11:40 - 2014-09-28 12:50 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Packages
2015-01-31 04:35 - 2014-09-28 19:59 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\tixati
2015-01-31 04:21 - 2014-09-11 15:39 - 00000000 _RSHD () C:\360SANDBOX
2015-01-30 17:52 - 2014-09-28 12:59 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\DMCache
2015-01-30 17:50 - 2014-09-28 12:59 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\IDM
2015-01-30 14:03 - 2014-12-23 16:49 - 27590656 _____ () C:\Windows\system32\vmguest.iso
2015-01-30 13:50 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-30 08:38 - 2014-10-20 22:03 - 00000000 ___RD () C:\Users\ihsan\Desktop\program
2015-01-30 08:38 - 2013-08-22 15:25 - 00524288 ___SH () C:\Windows\system32\config\BBI
2015-01-30 04:36 - 2014-11-28 23:06 - 05184440 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-30 03:40 - 2014-10-19 01:46 - 00000000 ____D () C:\Users\ihsan\AppData\Local\0ad
2015-01-30 03:35 - 2014-09-28 20:12 - 00000000 __SHD () C:\ProgramData\360Quarant
2015-01-30 03:35 - 2014-09-11 16:00 - 00000000 __SHD () C:\$360Section
2015-01-30 03:35 - 2014-09-02 12:13 - 00033432 _____ () C:\PureRa.txt
2015-01-30 03:30 - 2014-11-13 21:54 - 00000000 ____D () C:\Users\ihsan\Desktop\Ders Notları
2015-01-30 03:30 - 2014-10-02 20:15 - 00000000 ____D () C:\Users\ihsan\.WebIde80
2015-01-30 03:30 - 2014-09-28 19:39 - 00000000 ___RD () C:\Users\ihsan\Downloads\Microsoft.SkypeApp_kzf8qxf38zg5c!App
2015-01-30 03:30 - 2014-09-28 15:06 - 00000000 ____D () C:\Users\ihsan\Documents\My Bluetooth
2015-01-30 03:30 - 2014-09-28 13:00 - 00000000 ____D () C:\Users\ihsan\Downloads\Compressed
2015-01-30 03:29 - 2014-10-30 20:00 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\DAEMON Tools Lite
2015-01-30 03:29 - 2014-10-27 00:54 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\FileZilla
2015-01-30 03:01 - 2014-12-17 20:08 - 00000000 ____D () C:\Users\Public\Documents\DevExpress Demos 14.2
2015-01-30 03:01 - 2014-12-17 20:07 - 00000000 ____D () C:\Program Files (x86)\DevExpress 14.2
2015-01-30 03:00 - 2014-12-17 20:34 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DevExpress 14.2
2015-01-30 02:59 - 2014-10-20 22:03 - 00000000 ____D () C:\Users\ihsan\Desktop\yazlım p
2015-01-30 02:58 - 2014-10-20 22:03 - 00000000 ____D () C:\Users\ihsan\Desktop\Oyun
2015-01-30 02:54 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-01-30 02:45 - 2014-10-02 16:28 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\RenPy
2015-01-30 02:39 - 2014-12-04 09:39 - 00000000 ____D () C:\Program Files (x86)\Nuance
2015-01-30 02:24 - 2014-09-28 19:44 - 00000000 ____D () C:\Program Files (x86)\StarCraft II
2015-01-29 18:17 - 2014-06-26 08:24 - 00000000 ____D () C:\AdwCleaner
2015-01-29 18:03 - 2014-12-23 17:31 - 00007639 _____ () C:\Users\ihsan\AppData\Local\Resmon.ResmonCfg
2015-01-29 06:54 - 2014-11-26 12:47 - 00000000 ____D () C:\ProgramData\Origin
2015-01-28 23:28 - 2014-11-26 12:47 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-01-28 23:22 - 2014-09-28 19:36 - 00000000 ____D () C:\Windows\system32\appmgmt
2015-01-28 22:28 - 2014-10-05 20:47 - 00000000 ____D () C:\Program Files (x86)\Jumpstart
2015-01-28 02:14 - 2014-10-21 10:03 - 00000000 ____D () C:\Users\ihsan\Documents\SQL Server Management Studio
2015-01-27 21:06 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-01-26 02:10 - 2014-09-28 12:53 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Macromedia
2015-01-24 22:20 - 2013-08-22 17:38 - 00714720 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-24 22:20 - 2013-08-22 17:38 - 00106976 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-24 01:03 - 2014-12-23 16:32 - 00000000 ____D () C:\Users\ihsan\Documents\Visual Studio 2015
2015-01-24 00:13 - 2014-10-20 20:53 - 00000000 ____D () C:\Users\ihsan\Documents\Visual Studio 2012
2015-01-23 13:36 - 2014-11-22 15:22 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\.ACEStream
2015-01-23 13:29 - 2014-11-22 15:22 - 00000000 ___HD () C:\_acestream_cache_
2015-01-21 03:09 - 2014-10-30 21:25 - 00000396 __RSH () C:\ProgramData\ntuser.pol
2015-01-18 14:55 - 2014-09-28 15:20 - 00000000 ____D () C:\Windows\SysWOW64\sda
2015-01-18 14:55 - 2014-09-28 14:38 - 00000000 ____D () C:\Program Files (x86)\Realtek
2015-01-14 17:29 - 2014-09-28 19:32 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 17:21 - 2014-09-28 19:32 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-12 21:30 - 2014-09-12 17:38 - 00000000 ____D () C:\Games
2015-01-12 18:08 - 2014-10-21 07:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-01-12 18:08 - 2014-10-21 07:49 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-01-12 09:21 - 2014-09-28 12:49 - 00000000 ____D () C:\Users\ihsan
2015-01-11 16:44 - 2014-10-21 10:04 - 00000000 ____D () C:\Users\ReportServer
2015-01-11 16:44 - 2014-10-21 10:04 - 00000000 ____D () C:\Users\MSSQLServerOLAPService
2015-01-11 16:44 - 2014-10-21 10:03 - 00000000 ____D () C:\Users\MSSQLSERVER
2015-01-11 16:44 - 2014-10-21 10:03 - 00000000 ____D () C:\Users\MSSQLFDLauncher
2015-01-11 16:44 - 2014-10-21 10:03 - 00000000 ____D () C:\Users\MsDtsServer110
2015-01-09 13:56 - 2014-10-18 17:11 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Adobe
2015-01-09 13:34 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\LiveKernelReports
2015-01-08 20:09 - 2014-11-22 15:21 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\ACEStream
2015-01-08 18:20 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\addins
2015-01-08 18:06 - 2014-10-30 15:40 - 00000000 ____D () C:\Users\ihsan\Documents\Korra
2015-01-06 05:37 - 2015-01-01 14:38 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\GitHub
2015-01-06 05:37 - 2015-01-01 14:38 - 00000000 ____D () C:\Users\ihsan\AppData\Local\GitHub
2015-01-06 04:50 - 2015-01-01 14:43 - 00000000 ____D () C:\Users\ihsan\Documents\GitHub
2015-01-06 04:46 - 2014-12-28 22:53 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Deployment
2015-01-05 21:30 - 2014-10-26 12:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-02 03:19 - 2014-12-26 01:06 - 00000000 ____D () C:\Program Files (x86)\This War of Mine
2015-01-02 03:19 - 2014-09-28 21:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oyun Çeviri

==================== Files in the root of some directories =======

2014-11-22 12:42 - 2014-11-22 12:42 - 0000132 _____ () C:\Users\ihsan\AppData\Roaming\Adobe PNG Format CC Prefs
2014-09-28 15:06 - 2015-02-01 23:39 - 0038972 _____ () C:\Users\ihsan\AppData\Local\BTServer.log
2014-11-24 23:55 - 2014-11-25 16:37 - 0000600 _____ () C:\Users\ihsan\AppData\Local\PUTTY.RND
2014-12-23 17:31 - 2015-01-29 18:03 - 0007639 _____ () C:\Users\ihsan\AppData\Local\Resmon.ResmonCfg

Some content of TEMP:
====================
C:\Users\ihsan\AppData\Local\Temp\FreemakeVideoConverterFull.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-28 19:46

==================== End Of Log ============================

addition

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-02-2015
Ran by ihsan at 2015-02-01 23:44:31
Running from C:\Users\ihsan\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Emsisoft Internet Security (Disabled - Up to date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: 360 Total Security (Enabled - Up to date) {2B66EE1E-E5C8-C2F7-648F-4E55AC68D37D}
AS: 360 Total Security (Enabled - Up to date) {90070FFA-C3F2-CD79-5E3F-7527D7EF99C0}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Internet Security (Disabled - Up to date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
FW: Emsisoft Internet Security (Disabled) {BD3F5FCA-866B-1E2E-0A68-58900A751EA1}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 Tools for .Net 3.5 (x32 Version: 3.11.50727 - Microsoft Corporation) Hidden
360 Total Security (HKLM-x32\...\360TotalSecurity) (Version: 5.2.0.1080 - 360 Güvenlik Merkezi)
Ace Stream Media 3.0.5 (HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\AceStream) (Version: 3.0.5 - Ace Stream Media)
Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 2.8.1.451 - Adobe Systems Incorporated)
Adobe Dreamweaver CC 2014 (HKLM-x32\...\{766255CE-D156-11E3-8DBC-A136EB52ACCF}) (Version: 14.0.0 - Adobe Systems Incorporated)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Adobe Photoshop CC 14.2.1 (HKLM-x32\...\Adobe Photoshop CC 14.2.1) (Version:  - )
Age of Empires II: HD Edition (HKLM-x32\...\Steam App 221380) (Version:  - Hidden Path Entertainment, Ensemble Studios)
Age of Empires® III: Complete Collection (HKLM-x32\...\Steam App 105450) (Version:  - Ensemble Studios)
Allok Video Converter 4.6.0529 (HKLM-x32\...\Allok Video Converter_is1) (Version:  - Allok Soft Inc.)
Application Insights Tools for Visual Studio 2015 Preview (x32 Version: 3.0 - Microsoft Corporation) Hidden
Auslogics DiskDefrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 5.1.0.0 - Auslogics Labs Pty Ltd)
AzureTools.Notifications (x32 Version: 2.4.20714.1601 - Microsoft Corporation) Hidden
Battery Calibration (HKLM-x32\...\{619FA785-489B-4D22-911F-82D6EDF5BDB0}) (Version: 1.0.1405.0701 - Micro-Star International Co., Ltd.)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Behaviors SDK (Windows Phone) for Visual Studio 2013 (x32 Version: 12.0.50926.80 - Microsoft Corporation) Hidden
Behaviors SDK (Windows) for Visual Studio 2013 (x32 Version: 12.0.50926.80 - Microsoft Corporation) Hidden
BioShock (HKLM-x32\...\Steam App 7670) (Version:  - 2K Boston)
BioShock 2 (HKLM-x32\...\Steam App 8850) (Version:  - 2K Marin)
BioShock Infinite (HKLM-x32\...\Steam App 8870) (Version:  - Irrational Games)
Bioshock Türkçe Yama v1.00 (HKLM-x32\...\Bioshock TR) (Version: 1.00 - )
Blend for Visual Studio 2012 (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Blend for Visual Studio 2012 ENU resources (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for Silverlight 5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for Windows Phone 8.0 (x32 Version: 3.0.30924.0 - Microsoft Corporation) Hidden
Build Tools - amd64 (Version: 12.0.31010 - Microsoft Corporation) Hidden
Build Tools - x86 (x32 Version: 12.0.31010 - Microsoft Corporation) Hidden
Build Tools 14.0 (amd64) (Version: 14.0.22310 - Microsoft Corporation) Hidden
Build Tools 14.0 (x86) (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
Build Tools Language Resources - amd64 (Version: 12.0.31010 - Microsoft Corporation) Hidden
Build Tools Language Resources - x86 (x32 Version: 12.0.31010 - Microsoft Corporation) Hidden
Build Tools Language Resources 14.0 (amd64) (Version: 14.0.22310 - Microsoft Corporation) Hidden
Build Tools Language Resources 14.0 (x86) (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.02 - Piriform)
ClumsyLeaf CloudXplorer (HKLM-x32\...\{7F111167-5B0A-4DD4-8D0F-C6DB7649B938}) (Version: 3.2.0.0 - ClumsyLeaf Software)
Command & Conquer™ Red Alert 2 and Yuri’s Revenge (HKLM-x32\...\{F5275D1C-D133-486D-8F07-D6C571F0A8EC}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Command & Conquer™: Generals and Zero Hour (HKLM-x32\...\{609F6FD5-4B22-4D7A-AD30-8C9DD480D5BE}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Democracy 3 (HKLM-x32\...\Steam App 245470) (Version:  - Positech Games)
Dev-C++ 5 beta 9 release (4.9.9.2) (HKLM-x32\...\Dev-C++) (Version:  - )
DomDomSoft Manga Downloader (remove only) (HKLM-x32\...\DomDomSoft Manga Downloader) (Version:  - )
Don't Starve Together Beta (HKLM-x32\...\Steam App 322330) (Version:  - )
Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4521.29298 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition 5.16.0 (x32 Version: 5.16.0.2178 - PreEmptive Solutions) Hidden
Emsisoft Internet Security (HKLM-x32\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 9.0 - Emsisoft Ltd.)
ErrorList (x32 Version: 1.0 - Microsoft Corporation) Hidden
ETDWare PS/2-X64 11.13.4.4_WHQL (HKLM\...\Elantech) (Version: 11.13.4.4 - ELAN Microelectronic Corp.)
Far Cry (HKLM-x32\...\Steam App 13520) (Version:  - Crytek Studios)
Far Cry 2 (HKLM-x32\...\Steam App 19900) (Version:  - Ubisoft Montreal)
Far Cry® 3 (HKLM-x32\...\Steam App 220240) (Version:  - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai)
Far Cry® 3 Blood Dragon (HKLM-x32\...\Steam App 233270) (Version:  - Ubisoft Montreal)
FileZilla Client 3.9.0.6 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.6 - Tim Kosse)
Freemake Video Converter version 4.1.5 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.5 - Ellora Assets Corporation)
GameRanger (HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\GameRanger) (Version:  - GameRanger Technologies)
Garry's Mod (HKLM-x32\...\Steam App 4000) (Version:  - Facepunch Studios)
Git version 1.9.0-preview20140217 (HKLM-x32\...\Git_is1) (Version: 1.9.0-preview20140217 - The Git Development Community)
GitHub (HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\5f7eb300e2ea4ebf) (Version: 2.6.6.2 - GitHub, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 41.0.2272.35 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
IIS 8.0 Express (HKLM\...\{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}) (Version: 8.0.1557 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb) (Version:  - )
Insurgency (HKLM-x32\...\Steam App 222880) (Version:  - New World Interactive)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.20.1447 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.2.4.1000 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
Java 8 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418025F0}) (Version: 8.0.250 - Oracle Corporation)
JetBrains PhpStorm 8.0.1 (HKLM-x32\...\PhpStorm 8.0.1) (Version: 138.2001.2328 - JetBrains s.r.o.)
Jumpstart Installation Program (HKLM-x32\...\{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}) (Version:  - Atheros)
KB9X Radio Switch Driver (HKLM\...\5AADE1068CF70DD983F763B20CF2CAAB72883915) (Version: 1.1.0.0 - ENE TECHNOLOGY INC.)
K-Lite Mega Codec Pack 10.8.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.0 - )
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version:  - Valve)
LocalESPC (x32 Version: 8.59.29989 - Microsoft Corporation) Hidden
LocalESPCui for en-us (x32 Version: 8.59.29989 - Microsoft) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.3 Preview Multi-Targeting Pack (ENU) (HKLM-x32\...\{6FF89029-E442-4346-BB1E-C73AA6F6D080}) (Version: 4.5.53346 - Microsoft Corporation)
Microsoft .NET Framework 4.5.3 Preview Multi-Targeting Pack (HKLM-x32\...\{861F6EBB-5856-4DB9-B812-363CFB1D2F56}) (Version: 4.5.53346 - Microsoft Corporation)
Microsoft ASP.NET MVC 3 (HKLM-x32\...\{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}) (Version: 3.0.20105.0 - Microsoft Corporation)
Microsoft ASP.NET Web Pages (HKLM-x32\...\{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}) (Version: 1.0.20105.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation)
Microsoft Help Viewer 2.0 (HKLM-x32\...\Microsoft Help Viewer 2.0) (Version: 2.0.50727 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.22310 - Microsoft Corporation)
Microsoft Office 2003 Web Components (HKLM-x32\...\{90120000-00A4-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Report Viewer 2012 Runtime (HKLM-x32\...\{9CCE40CE-A9E6-4916-8729-B008558EEF3F}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Silverlight 4 SDK (HKLM-x32\...\{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Silverlight 5 SDK (HKLM-x32\...\{E1FBB3D4-ADB0-4949-B101-855DA061C735}) (Version: 5.0.61118.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{83F2B8F4-5CF3-4BE9-9772-9543EAE4AC5F}) (Version: 10.51.2500.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files  (HKLM\...\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server 2012 (64-bit) (HKLM\...\Microsoft SQL Server SQLServer2012) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM\...\{36E619BC-A234-4EC3-849B-779A7C865A45}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM-x32\...\{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\...\{13D558FE-A863-402C-B115-160007277033}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (HKLM-x32\...\{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (x64) (HKLM\...\{FA0A244E-F3C2-4589-B42A-3D522DE79A42}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Policies  (HKLM-x32\...\{DC487E40-046E-42A9-9C7C-5D2B1A7EB211}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Setup (English) (HKLM\...\{8CB0713F-CFE0-445D-BCB2-538465860E1A}) (Version: 11.1.3128.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL Compiler Service  (HKLM\...\{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL ScriptDom  (HKLM\...\{0E8670B8-3965-4930-ADA6-570348B67153}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 T-SQL Language Service  (HKLM\...\{CC8B009A-98C9-497F-99AF-CEBE35D8C0CF}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 T-SQL Language Service  (HKLM-x32\...\{6D6D43E5-218C-4B05-92D3-2240810F4760}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2014 Express LocalDB  (HKLM\...\{AB8DE9BA-19E1-446A-BCFA-6B3DA9751E21}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Transact-SQL ScriptDom  (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 T-SQL Language Service  (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools – Database Projects – Web installer entry point (HKLM-x32\...\{F3BBC56F-2282-4464-952F-A89772181F30}) (Version: 10.3.20116.0 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (11.1.20627.00) (HKLM-x32\...\{FA804794-2CCB-4301-954F-2C2894698876}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (14.0.41025.0) (HKLM-x32\...\{455A16B4-CD22-4529-B429-DD454573E76A}) (Version: 14.0.41025.0 - Microsoft Corporation)
Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00) (HKLM-x32\...\{790E9425-8570-493F-9AE7-81AFC9E46930}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{C3F6F200-6D7B-4879-B9EE-700C0CE1FCDA}) (Version: 10.51.2500.0 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (x64) (HKLM\...\{4701DEDE-1888-49E0-BAE5-857875924CA2}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\...\{F1949145-EB64-4DE7-9D81-E6D27937146C}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{DAF4DDA4-3B5A-407D-B4DF-07922C5A0D22}) (Version: 12.0.2360.29 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{659D2DBE-CA2C-4C8F-AF2B-2C8DE262B278}) (Version: 12.0.2360.29 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Preview Redistributable (x64) - 14.0.22310 (HKLM-x32\...\{eb6c06e7-8ff6-4978-ab4c-561383593306}) (Version: 14.0.22310.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Preview Redistributable (x86) - 14.0.22310 (HKLM-x32\...\{2e4043b7-cd84-44db-b81a-8f6e5ffb7398}) (Version: 14.0.22310.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Shell (Integrated) - ENU (HKLM-x32\...\{012D26C3-E12A-3BDA-8ECE-DF14E721A507}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Shell (Isolated) - ENU (HKLM-x32\...\{D64B6984-242F-32BC-B008-752806E5FC44}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2015 Preview Secondary Installer (HKLM-x32\...\{B6CB8401-B0A8-4795-8BED-F7B49D51ABCF}_SecondaryInstaller) (Version: 14.0.22310 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications Design-Time 3.0 (HKLM-x32\...\{5A03C202-08B4-3F1D-9A60-A4F53EF1B636}) (Version: 10.0.40220 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications x64 Runtime 3.0 (HKLM\...\{F14401A9-F0A0-33CC-8444-F60823A60DEB}) (Version: 10.0.40220 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications x86 Runtime 3.0 (HKLM-x32\...\{191A6F65-6878-398D-A272-EF011B80F371}) (Version: 10.0.40220 - Microsoft Corporation)
Microsoft Visual Studio Ultimate 2012 (HKLM-x32\...\{9600393b-6ede-469b-a522-689fce1461d1}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual Studio Ultimate 2015 Preview (HKLM-x32\...\{e1f58f60-306c-4f5b-9788-5b9292910779}) (Version: 14.0.22310.1 - Microsoft Corporation)
Microsoft VSS Writer for SQL Server 2012 (HKLM\...\{3E0DD83F-BE4C-4478-86A0-AD0D79D1353E}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Web Deploy 3.6 Beta3 (HKLM\...\{07F0FC77-282E-42E5-BAE6-B8C098F8453E}) (Version: 3.1238.1942 - Microsoft Corporation)
Microsoft Web Deploy dbSqlPackage Provider - enu (HKLM-x32\...\{E4C33F5B-1B2F-466E-957E-B274F08151A0}) (Version: 10.3.20225.0 - Microsoft Corporation)
Microsoft Web Platform Installer 5.0 (HKLM\...\{4D84C195-86F0-4B34-8FDE-4A17EB41306A}) (Version: 5.0.50430.0 - Microsoft Corporation)
Mozilla Firefox 34.0.5 (x86 tr) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 tr)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
Multi-Device Hybrid Apps using C# - Templates - ENU (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
NARUTO SHIPPUDEN: Ultimate Ninja STORM 3 Full Burst (HKLM-x32\...\Steam App 234670) (Version:  - CyberConnect 2)
Node.js (HKLM-x32\...\{417EF6AA-3961-4119-9A00-312724B35D3A}) (Version: 0.10.33 - Joyent, Inc. and other Node contributors)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.9 - Notepad++ Team)
Nuance OmniPage Ultimate (HKLM-x32\...\{419512F9-D5E7-4ED2-BF99-E7F2C0176B6A}) (Version: 19.00.0000 - Nuance Communications, Inc.)
NVIDIA GeForce Experience 2.1.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.5 - NVIDIA Corporation)
NVIDIA Grafik Sürücüsü 344.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.65 - NVIDIA Corporation)
NVIDIA PhysX Sistem Yazılımı 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
Open XML SDK 2.5 for Microsoft Office (x32 Version: 2.5.5631 - Microsoft Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: 9.5.2.2829 - Electronic Arts, Inc.)
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
PAYDAY 2 (HKLM-x32\...\Steam App 218620) (Version:  - OVERKILL - a Starbreeze Studio.)
PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.41.17507 - pdfforge GmbH)
PDF Architect 2 Asian Fonts Pack (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Convert Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Edit Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Forms Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Insert Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 OCR Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Review Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Secure Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 View Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Settings CC (x32 Version: 12.0 - Adobe Systems Incorporated) Hidden
PerformanceTest v8.0 (HKLM\...\PerformanceTest 8_is1) (Version: 8.0.1042.0 - Passmark Software)
PreEmptive Analytics Visual Studio Components (x32 Version: 1.0.2180.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.3197.1 - PreEmptive Solutions) Hidden
Prerequisites for SSDT  (HKLM-x32\...\{21373064-AD95-48DB-A32E-0D9E08EF7355}) (Version: 12.0.2000.8 - Microsoft Corporation)
Prerequisites for SSDT  (HKLM-x32\...\{9169C939-ED01-446A-BD0C-29873BAF4E48}) (Version: 11.0.2100.60 - Microsoft Corporation)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Python Tools Redirection Template (x32 Version: 1.1 - Microsoft Corporation) Hidden
Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.21 - Qualcomm Atheros Inc.)
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.754.754.082813 - REALTEK Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30164 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0224 - REALTEK Semiconductor Corp.)
Revo Uninstaller Pro 3.1.2 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.2 - VS Revo Group, Ltd.)
Roslyn Language Services - x86 (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
Rust (HKLM-x32\...\Steam App 252490) (Version:  - Facepunch Studios)
SCM (HKLM\...\{614FD4D7-78CE-43E0-88E1-F6DE78069B9A}) (Version: 13.013.09262 - Application)
SharePoint Client Components (Version: 15.0.4641.1002 - Microsoft Corporation) Hidden
SharePoint Client Components (Version: 16.0.3104.1200 - Microsoft Corporation) Hidden
SHIELD Streaming (Version: 3.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.18.9 - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Sound Blaster Cinema (HKLM-x32\...\{8801CA65-921A-4CCC-9D63-879D1D0BAA97}) (Version: 1.00.02 - Creative Technology Limited)
SQL Server 2012 Analysis Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 BI Development Studio (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Client Tools (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Common Files (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Data quality client (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Data quality service (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Shared (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Distributed Replay (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Documentation Components (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Full text search (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Integration Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Management Studio (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Master Data Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Reporting Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 RS_SharePoint_SharedService (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 SQL Data Quality Common (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server Browser for SQL Server 2012 (HKLM-x32\...\{4B9E6EB0-0EED-4E74-9479-F982C3254F71}) (Version: 11.0.2100.60 - Microsoft Corporation)
Sql Server Customer Experience Improvement Program (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
Sublight (HKLM\...\Sublight_is1) (Version: 4 - Sublight Labs)
Subtitle Workshop 2.51 (HKLM-x32\...\SubtitleWorkshop) (Version:  - )
Team Explorer for Microsoft Visual Studio 2015 Preview (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.36897 - TeamViewer)
The Battle for Middle-earth (tm) II (HKLM-x32\...\{2A9F95AB-65A3-432c-8631-B8BC5BF7477A}) (Version:  - )
The Elder Scrolls V Skyrim Türkçe Yama Uyum Programı v1.00 (HKLM-x32\...\The Elder Scrolls V Skyrim TR) (Version: 1.00 - OyunCeviri.com)
This War of Mine (HKLM-x32\...\{5FD7B6B3-08C7-4FEE-9C37-A2134C699885}}_is1) (Version: 1 - 11 bit studios)
Tixati (HKLM-x32\...\tixati) (Version:  - )
TOEFL Sampler (HKLM-x32\...\{95744E49-71D1-453A-9466-6930819043C8}) (Version: 1.00.0001 - ETS)
Tropico 4 (HKLM-x32\...\Steam App 57690) (Version:  - Haemimont Games)
TypeScript Power Tool (x32 Version: 1.3.0.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 14 (x32 Version: 1.3.0.0 - Microsoft Corporation) Hidden
Unity Web Player (HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\UnityWebPlayer) (Version: 4.5.5f1 - Unity Technologies ApS)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
USB Network Driver (HKLM-x32\...\{66ED8E01-C915-41F5-B33E-C5C31F27B885}) (Version: 2007.07.3 - )
Visual Studio 2010 Prerequisites - English (HKLM\...\{662014D2-0450-37ED-ABAE-157C88127BEB}) (Version: 10.0.40219 - Microsoft Corporation)
VsHub (x32 Version: 1.0.0.0 - Microsoft Corporation) Hidden
WCF Data Services 5.0 (for OData v3) Primary Components (x32 Version: 5.0.50628.0 - Microsoft Corporation) Hidden
WCF Data Services 5.6.2 Runtime (x32 Version: 5.6.61937.2 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2012 (x32 Version: 5.0.50710.0 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2014 (x32 Version: 5.6.61937.2 - Microsoft Corporation) Hidden
WCF RIA Services V1.0 SP2 (HKLM-x32\...\{5D8DD6A8-C4D7-4554-93F9-F1CC28C72600}) (Version: 4.1.62812.0 - Microsoft Corporation)
Windows Phone 8.1 Emulators - ENU (HKLM-x32\...\{166a69f6-6512-47ea-a342-17d954fc059a}) (Version: 12.0.31010.0 - Microsoft Corporation)
WinRAR 5.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
Workflow Manager Client 1.0 (Version: 2.0.40131.0 - Microsoft Corporation) Hidden
Workflow Manager Tools 1.0 for Visual Studio (Version: 2.0.41015.0 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-3051402733-4133393625-984315149-1001_Classes\CLSID\{0BC0D8BD-047A-4620-9070-11B2CABC838B}\InprocServer32 -> 0x0ADCCA3361B30CBC8D98C765E8A222CC324FD91738B27840 No File
CustomCLSID: HKU\S-1-5-21-3051402733-4133393625-984315149-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)

==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2014-12-15 00:30 - 00001132 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1                   activate.adobe.com
127.0.0.1                   practivate.adobe.com
127.0.0.1                   lmlicenses.wip4.adobe.com
127.0.0.1                   lm.licenses.adobe.com
127.0.0.1                   na1r.services.adobe.com
127.0.0.1                   hlrcv.stage.adobe.com


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {074EDE9A-F3E7-44D3-B7D9-6D0342C8CF4D} - System32\Tasks\[email protected] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2014-10-14] (Adobe Systems Incorporated)
Task: {23081457-A505-40A0-A99D-A2C00BA91AB4} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-24] (Adobe Systems Incorporated)
Task: {2D215246-5F93-4498-818D-6D8E08550B24} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {35A7EB11-BBFF-4755-A60F-4C6954D6702D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-28] (Google Inc.)
Task: {4F41FB20-FF5A-4670-9CDF-10C4FE25619B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-01-20] (Piriform Ltd)
Task: {596C62E0-D813-434E-B840-C3A43565DACD} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-3051402733-4133393625-984315149-1001
Task: {62AD2687-6051-44F7-A86F-8B6B910F9ADA} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {7CFBB224-A68D-4A61-A116-38F219528831} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-28] (Google Inc.)
Task: {EE8F767C-9BE7-4074-8832-56834A6CE58D} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-10-06] ()
Task: {F203A82A-F19C-4D53-82AA-EC974E4F4EF0} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2014-09-28 15:14 - 2013-08-28 11:35 - 00056832 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
2014-11-16 16:28 - 2014-11-16 16:28 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-09-28 20:05 - 2014-12-12 11:10 - 00707184 _____ () C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
2014-09-28 15:37 - 2014-11-04 02:04 - 00013120 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2014-09-28 15:38 - 2014-11-04 00:02 - 00116880 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-09-26 14:41 - 2014-09-26 14:41 - 01021088 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll
2012-10-01 19:36 - 2012-10-01 19:36 - 06522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-09-28 20:05 - 2014-12-12 11:10 - 00259152 _____ () C:\Program Files (x86)\360\Total Security\MenuEx64.dll
2014-05-12 11:49 - 2014-05-12 11:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2014-11-27 18:14 - 2012-11-01 11:21 - 00325120 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL
2014-09-28 20:05 - 2014-12-12 11:10 - 01818736 _____ () C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe
2015-01-30 02:48 - 2015-01-28 06:49 - 01529672 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.35\libglesv2.dll
2015-01-30 02:48 - 2015-01-28 06:49 - 00091976 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.35\libegl.dll
2015-01-30 02:48 - 2015-01-28 06:49 - 11286344 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.35\pdf.dll
2015-01-30 02:48 - 2015-01-28 06:49 - 26725704 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.35\PepperFlash\pepflashplayer.dll
2014-09-28 16:20 - 2013-08-08 12:25 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-09-28 15:37 - 2014-11-04 02:04 - 00010952 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\ProgramData\TEMP:A303874F
AlternateDataStreams: C:\ProgramData\TEMP:AEC0AC81
AlternateDataStreams: C:\Users\ihsan\SkyDrive:ms-properties

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: GladFileMonSvc => 2
MSCONFIG\Services: jswpbapi => 2
MSCONFIG\Services: jswpsapi => 3
MSCONFIG\Services: NitroDriverReadSpool9 => 2
MSCONFIG\Services: NitroUpdateService => 2
MSCONFIG\Services: PDF Architect 2 Creator => 2
MSCONFIG\Services: pdfforge CrashHandler => 3
MSCONFIG\Services: PDFProFiltSrv => 2
HKLM\...\StartupApproved\StartupFolder: => "Nuance Cloud Connector.lnk"
HKLM\...\StartupApproved\Run: => "Nvtmru"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "jswtrayutil"
HKLM\...\StartupApproved\Run32: => "USB Gamepad"
HKLM\...\StartupApproved\Run32: => "AdobeCEPServiceManager"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "ISUSPM"
HKLM\...\StartupApproved\Run32: => "Nuance OmniPage Ultimate-reminder"
HKLM\...\StartupApproved\Run32: => "OmniPage Preload"
HKLM\...\StartupApproved\Run32: => "PDFProHook"
HKLM\...\StartupApproved\Run32: => "PDF8 Registry Controller"
HKLM\...\StartupApproved\Run32: => "Babylon Client"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "IDMan"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "GUDelayStartup"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "AceStream"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "ISUSPM"

========================= Accounts: ==========================

Administrator (S-1-5-21-3051402733-4133393625-984315149-500 - Administrator - Disabled)
Guest (S-1-5-21-3051402733-4133393625-984315149-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3051402733-4133393625-984315149-1003 - Limited - Enabled)
ihsan (S-1-5-21-3051402733-4133393625-984315149-1001 - Administrator - Enabled) => C:\Users\ihsan

==================== Faulty Device Manager Devices =============

Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/01/2015 08:08:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe programının 6.3.9600.17031 sürümü, Windows ile birlikte çalışmayı durdurdu ve kapatıldı. Sorun hakkında daha fazla bilgi olup olmadığını görmek için Eylem Merkezi denetim masasında sorunun geçmişini denetleyin.

İşlem Kimlik No: 2a70

Başlatma Saati: 01d03e4956c2c1a5

Sona Erdirme Saati: 4294967295

Uygulama Yolu: C:\Windows\syswow64\wwahost.exe

Rapor Kimliği: 4aa0e109-aa3d-11e4-8294-8c89a50ef469

Hatalı paket tam adı: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c

Hatalı paketle ilgili uygulama kimliği: App

Error: (01/31/2015 05:05:47 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest1" için etkinleştirme içeriği oluşturulamadı. "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest2" adlı bildirim veya ilke dosyasında C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest3. satırda hata var.
Uygulama için gereken bir bileşen sürümü halen etkin olan bir başka bileşen sürümüyle çakışıyor.
Çakışan bileşenler:
Bileşen 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Bileşen 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.

Error: (01/31/2015 04:25:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Hatalı uygulama adı: Allok Video Converter v4.6.0529 Portable.exe, sürüm: 1.0.2.0, zaman damgası: 0x00000031
Hatalı modül adı: unknown, sürüm: 0.0.0.0, zaman damgası: 0x00000000
Özel durum kodu: 0xc0000005
Hata uzaklığı 0x020895c1
Hatalı işlem kimliği: 0x22bc
Uygulama başlangıç zamanı: 0xAllok Video Converter v4.6.0529 Portable.exe0
Hatalı uygulama yolu: Allok Video Converter v4.6.0529 Portable.exe1
Hatalı modül yolu: Allok Video Converter v4.6.0529 Portable.exe2
Rapor kimliği: Allok Video Converter v4.6.0529 Portable.exe3
Hatalı paket tam adı: Allok Video Converter v4.6.0529 Portable.exe4
Hatalı paketle ilgili uygulama kimliği: Allok Video Converter v4.6.0529 Portable.exe5

Error: (01/30/2015 01:52:23 PM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER) cannot connect to the report server database.

Error: (01/30/2015 08:12:22 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LiveComm.exe programının 17.5.9600.20689 sürümü, Windows ile birlikte çalışmayı durdurdu ve kapatıldı. Sorun hakkında daha fazla bilgi olup olmadığını görmek için Eylem Merkezi denetim masasında sorunun geçmişini denetleyin.

İşlem Kimlik No: d0

Başlatma Saati: 01d03c52fa76c686

Sona Erdirme Saati: 4294967295

Uygulama Yolu: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe

Rapor Kimliği: ee5d360d-a846-11e4-8293-8c89a50ef469

Hatalı paket tam adı: microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe

Hatalı paketle ilgili uygulama kimliği: ppleae38af2e007f4358a809ac99a64a67c1

Error: (01/30/2015 06:39:11 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: IHOCAN)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 uygulamasının etkinleştirilmesi şu hatayla başarısız oldu: -2144927142 Ek bilgi için Microsoft-Windows-TWinUI/Operational günlüğüne bakın.

Error: (01/30/2015 06:39:11 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: IHOCAN)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 uygulamasının etkinleştirilmesi şu hatayla başarısız oldu: -2144927142 Ek bilgi için Microsoft-Windows-TWinUI/Operational günlüğüne bakın.

Error: (01/30/2015 04:38:59 AM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER) cannot connect to the report server database.

Error: (01/30/2015 03:15:52 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: "Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"1" için etkinleştirme içeriği oluşturulamadı.
Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" Bağımlı Derlemesi bulunamadı.
Lütfen ayrıntılı tanılama için sxstrace.exe programını kullanın.

Error: (01/30/2015 03:06:52 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Şifreleme Hizmetleri, Sistem Yazıcısı Nesnesi'nde OnIdentity() çağrısını işlerken başarısız oldu.


Details:
AddLegacyDriverFiles: Unable to back up image of binary TAP-Win32 Adapter V9 (Tunngle).

System Error:
Sistem belirtilen dosyayı bulamıyor.
.


System errors:
=============
Error: (02/01/2015 08:26:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Steam Client Service hizmeti şu hata nedeniyle başlatılamadı: 
%%1053

Error: (02/01/2015 08:26:26 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Steam Client Service hizmetinin bağlanması beklenirken zaman aşımı (30000 milisaniye) oluştu.

Error: (02/01/2015 08:06:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Emsisoft Protection Service hizmeti beklenmedik şekilde sona erdi.  Bu durum 2 defa oluştu.  0 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti yeniden başlat.

Error: (02/01/2015 08:06:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Emsisoft Protection Service hizmeti beklenmedik şekilde sona erdi.  Bu durum 1 defa oluştu.  0 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti yeniden başlat.

Error: (01/31/2015 11:49:36 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: WSearch hizmetinden işlem yanıtı beklenirken zaman aşımı (30000 milisaniye) oluştu.

Error: (01/31/2015 02:25:29 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: TeamViewer 10 hizmeti beklenmedik şekilde sona erdi.  Bu durum 2 defa oluştu.  2000 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti yeniden başlat.

Error: (01/31/2015 02:25:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: TeamViewer 10 hizmeti beklenmedik şekilde sona erdi.  Bu durum 1 defa oluştu.  2000 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti yeniden başlat.

Error: (01/30/2015 05:06:58 PM) (Source: DCOM) (EventID: 10010) (User: IHOCAN)
Description: {AC746233-E9D3-49CD-862F-068F7B7CCCA4}

Error: (01/30/2015 03:22:59 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Gölge kopya depolama ortamı kullanıcı tarafından tanımlanan bir sınır nedeniyle büyütülemediğinden C: biriminin gölge kopyaları durduruldu.

Error: (01/30/2015 01:52:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: 360 Total Security hizmeti beklenmeyen bir şekilde sonlandırıldı. Bu durum 1 defa oluştu.


Microsoft Office Sessions:
=========================
Error: (02/01/2015 08:08:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.3.9600.170312a7001d03e4956c2c1a54294967295C:\Windows\syswow64\wwahost.exe4aa0e109-aa3d-11e4-8294-8c89a50ef469Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5cApp

Error: (01/31/2015 05:05:47 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\Creative Cloud Uninstaller.exe

Error: (01/31/2015 04:25:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Allok Video Converter v4.6.0529 Portable.exe1.0.2.000000031unknown0.0.0.000000000c0000005020895c122bc01d03cfd1f82c5f5C:\Users\ihsan\Desktop\downloads\Allok Video Converter v4.6.0529 + Portable\Allok Video Converter v4.6.0529 Portable.exeunknown64d3d730-a8f0-11e4-8294-8c89a50ef469

Error: (01/30/2015 01:52:23 PM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER)

Error: (01/30/2015 08:12:22 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LiveComm.exe17.5.9600.20689d001d03c52fa76c6864294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exeee5d360d-a846-11e4-8293-8c89a50ef469microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

Error: (01/30/2015 06:39:11 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: IHOCAN)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927142

Error: (01/30/2015 06:39:11 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: IHOCAN)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927142

Error: (01/30/2015 04:38:59 AM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER)

Error: (01/30/2015 03:15:52 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Microsoft.Windows.Common-Controls,language="&#x2a;",processorArchitecture="arm",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0"C:\Users\ihsan\Downloads\vcredist_arm.exe

Error: (01/30/2015 03:06:52 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: 
Details:
AddLegacyDriverFiles: Unable to back up image of binary TAP-Win32 Adapter V9 (Tunngle).

System Error:
Sistem belirtilen dosyayı bulamıyor.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i7-4702MQ CPU @ 2.20GHz
Percentage of memory in use: 53%
Total physical RAM: 8113.17 MB
Available physical RAM: 3737.04 MB
Total Pagefile: 9792.29 MB
Available Pagefile: 3051.05 MB
Total Virtual: 131072 MB
Available Virtual: 131071.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:488.61 GB) (Free:250.65 GB) NTFS
Drive d: () (Fixed) (Total:442.38 GB) (Free:132.43 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 70873948)

Partition: GPT Partition Type.

==================== End Of Log ============================

  • 0

#6
bloopie

bloopie

    Trusted Helper

  • Malware Removal
  • 62 posts

Hello again, and thank you for the logs! :)

 

 

...But I must insist...there is evidence of pirated software on your computer. ...Before we can continue on, I must ask you to remove it. Please let me know if you are willing to do so.

 

==========

Failure to remove the illegal software will only result in a greater difficulty of successfully removing any malware that resides on your system.

 

And aside from it being overall against the law, many times, the failure of malware removal on a system such as yours, is 100%...and therefore, renders any fixes we will imply...useless.

 

I do not wish to waste my time here, so please get yourself a legitimate copy of Adobe software to run on your machine. Once this is done, I will be happy to clean your machine back into a well working state! :)

 

bloopie


  • 1

#7
ihocan

ihocan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts

ok i will remove adobe software :D i downloaded them for school project.
after remove i must to  sent the log again? and which one ?


  • 0

#8
ihocan

ihocan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts

Hello again bloopie i removed illegal software (adobe software and battle of middle earth 2 game)

and i use frst again 
 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-02-2015
Ran by ihsan (administrator) on IHOCAN on 02-02-2015 01:10:13
Running from C:\Users\ihsan\Downloads
Loaded Profiles: ihsan & MsDtsServer110 & MSSQLServerOLAPService & ReportServer & MSSQLFDLauncher & MSSQLSERVER (Available profiles: ihsan & MsDtsServer110 & MSSQLServerOLAPService & ReportServer & MSSQLFDLauncher & MSSQLSERVER)
Platform: Windows 8.1 Pro (X64) OS Language: Türkçe (Türkiye)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
(Atheros Communications, Inc.) C:\Program Files (x86)\Jumpstart\jswpbapi.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\110\DTS\Binn\MsDtsSrvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSAS11.MSSQLSERVER\OLAP\bin\msmdsrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\vmms.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\fdhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
() C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(pdfforge GmbH) C:\Program Files (x86)\PDF Architect 2\ws.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(MSI) C:\Program Files (x86)\SCM\Radio Manager.exe
(MSI) C:\Program Files (x86)\SCM\SCM.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VsHub\1.0.0.0\VsHub.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Internet Security\a2service.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\SysWOW64\WWAHost.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IDMan.exe
(Tonec Inc.) C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(diakov.net) C:\Users\ihsan\AppData\Local\Temp\~nsu.tmp\Au_.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [253952 2013-05-07] (Realtek Semiconductor Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2893104 2013-08-23] (ELAN Microelectronics Corp.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [320360 2014-08-04] (Intel Corporation)
HKLM\...\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [406920 2013-09-26] (MSI)
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [408232 2013-09-26] (MSI)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor)
HKLM\...\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM-x32\...\Run: [QHSafeTray] => C:\Program Files (x86)\360\Total Security\safemon\360Tray.exe [270960 2014-12-12] (Qihu Software Co. Limited)
HKLM-x32\...\Run: [jswtrayutil] => C:\Program Files (x86)\Jumpstart\jswtrayutil.exe [528384 2008-09-26] (Atheros Communications, Inc.)
HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2012-11-29] (Creative Technology Ltd)
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKLM-x32\...\Run: [OmniPage Preload] => C:\Program Files (x86)\Nuance\OmniPage19\OmniPage19.exe [2922824 2013-04-22] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [Nuance OmniPage Ultimate-reminder] => C:\Program Files (x86)\Nuance\OmniPage19\Ereg\Ereg.exe [334152 2013-01-14] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [VsHub.exe] => C:\Program Files (x86)\Common Files\Microsoft Shared\VsHub\1.0.0.0\vshub.exe [141440 2014-11-10] (Microsoft Corporation)
HKLM-x32\...\Run: [emsisoft anti-malware] => c:\program files (x86)\emsisoft internet security\a2guard.exe [4997872 2014-12-31] (Emsisoft GmbH)
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7404312 2015-01-20] (Piriform Ltd)
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3878480 2014-09-03] (Tonec Inc.)
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [174856 2014-11-04] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156840 2014-11-04] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (Tonec Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

URLSearchHook: [S-1-5-80-1770670200-1234090253-3451813168-4041049723-2370973757] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-2885764129-887777008-271615777-1616004480-2722851051] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-1770670200-1234090253-3451813168-4041049723-2370973757 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-2885764129-887777008-271615777-1616004480-2722851051 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: PDF Architect Helper -> {691B33B0-B86E-47F3-81C7-56E4FE3B929C} -> C:\Program Files (x86)\PDF Architect 2\creator-ie-helper.dll (pdfforge GmbH)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper -> {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} -> C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft Web Test Recorder 14.0 Helper -> {b924f0b4-0b3c-49c0-bab2-213fb9ebd1d3} -> C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - C:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll (pdfforge GmbH)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0
Tcpip\..\Interfaces\{78FA00C6-2245-43D4-9A83-7FED19DE07AA}: [NameServer] 8.8.8.8,8.8.4.8

FireFox:
========
FF ProfilePath: C:\Users\ihsan\AppData\Roaming\Mozilla\Firefox\Profiles\kg35b0ue.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_296.dll ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~4\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_296.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF Plugin HKU\S-1-5-21-3051402733-4133393625-984315149-1001: @acestream.net/acestreamplugin,version=3.0.5 -> C:\Users\ihsan\AppData\Roaming\ACEStream\player\npace_plugin.dll (Innovative Digital Technologies)
FF Plugin HKU\S-1-5-21-3051402733-4133393625-984315149-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ihsan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3051402733-4133393625-984315149-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex-tr.xml
FF Extension: AS Magic Player - C:\Users\ihsan\AppData\Roaming\Mozilla\Firefox\Profiles\kg35b0ue.default\Extensions\[email protected] [2015-01-08]
FF Extension: User Agent Switcher - C:\Users\ihsan\AppData\Roaming\Mozilla\Firefox\Profiles\kg35b0ue.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2015-01-15]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: PDF Architect 2 Creator - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-10-18]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox
FF Extension: 360网页保护 - C:\Program Files (x86)\360\Total Security\safemon\webprotection_firefox [2014-09-28]
FF HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Firefox\Extensions: [[email protected]] - C:\Users\ihsan\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\ihsan\AppData\Roaming\IDM\idmmzcc5 [2014-09-28]
FF HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\ihsan\AppData\Roaming\IDM\idmmzcc5

Chrome: 
=======
CHR HomePage: Default -> hxxp://klit.startnow.com/?src=startpage&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=US&install_date=20120929&user_guid=3220074E5BF444FFABB0303EA47C4FB8&machine_id=67326ca3ae2301667ef9afd37f603db0&browser=CR&os=win&os_version=6.1-x86-SP0
CHR StartupUrls: Default -> "https://www.google.com.tr/"
CHR DefaultSearchKeyword: Default -> google.com.trhttps://www.google.com.tr/preferences?hl=tr
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (From Dust) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\anelkojiepicmcldgnmkplocifmegpfj [2014-12-28]
CHR Extension: (Google Drive) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-28]
CHR Extension: (Manga Viewer) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bebalkdfejapnfbngpmhchkboajaofen [2014-12-28]
CHR Extension: (Adguard AdBlocker) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2014-12-29]
CHR Extension: (MEGA) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2014-12-28]
CHR Extension: (Adblock Plus) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-12-28]
CHR Extension: (Pushbullet) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2015-01-10]
CHR Extension: (Google Apps Script) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoieeedlomnegifmaghhjnghhmcldobl [2014-12-28]
CHR Extension: (+ Flip It) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbmppankahdodchhioklnbcmohehhjoa [2014-12-28]
CHR Extension: (ZenMate Security & Privacy VPN) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2014-12-28]
CHR Extension: (Office Belgeleri Düzenleme) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbkeegbaiigmenfmjfclcdgdpimamgkj [2014-12-28]
CHR Extension: (Quick Javascript Switcher) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\geddoclleiomckbhadiaipdggiiccfje [2014-12-28]
CHR Extension: (Orta Dünya'da Bir Yolculuk) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjgkjeheegjnnmheaflhdocglkiegoni [2014-12-28]
CHR Extension: (360 İnternet Koruması) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\glcimepnljoholdmjchkloafkggfoijh [2014-12-28]
CHR Extension: (Bookmark Manager) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2014-12-29]
CHR Extension: (Tureng Dictionary) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihedienojfhdahpomfldoejaimefofff [2014-12-28]
CHR Extension: (Streamus™) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbnkffmindojffecdhbbmekbmkkfpmjd [2014-12-28]
CHR Extension: (IDM Integration Module) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn [2014-12-28]
CHR Extension: (Chrome extension source viewer) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifpbeccnghkjeaalbbjmodiffmgedin [2014-12-28]
CHR Extension: (Google Inbox Checker (Inbox by Gmail)) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\llldafpkkdiljghncbdnkgfinfiifnig [2014-12-28]
CHR Extension: (Google Mail Checker) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-12-28]
CHR Extension: (Google Cüzdan) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-28]
CHR Extension: (Chrome Apps & Extensions Developer Tool) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohmmkhmmmpcnpikjeljgnaoabkaalbgc [2014-12-28]
CHR Extension: (Gmail) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-28]
CHR Extension: (Chrome Dev Editor (developer preview)) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnoffddplpippgcfjdhbmhkofpnaalpg [2014-12-28]
CHR HKLM\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2014-09-12]
CHR HKLM-x32\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2014-09-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Internet Security\a2service.exe [4920104 2014-12-31] (Emsisoft GmbH)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [56832 2013-08-28] () [File not signed]
S3 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
S3 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2014-12-23] (Microsoft Corporation)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [174624 2015-01-19] (EasyAntiCheat Ltd)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [99632 2013-08-23] (ELAN Microelectronics Corp.)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2014-12-13] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-08-04] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-12] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [22744 2014-10-15] (Microsoft Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
R2 jswpbapi; C:\Program Files (x86)\Jumpstart\jswpbapi.exe [265216 2008-09-26] (Atheros Communications, Inc.) [File not signed]
S3 jswpsapi; C:\Program Files (x86)\Jumpstart\jswpsapi.exe [954368 2008-09-26] (Atheros Communications, Inc.) [File not signed]
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2013-09-26] (Micro-Star International Co., Ltd.) [File not signed]
R2 MsDtsServer110; C:\Program Files\Microsoft SQL Server\110\DTS\Binn\MsDtsSrvr.exe [218200 2012-02-11] (Microsoft Corporation)
R3 MSSQLFDLauncher; C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe [49752 2012-02-11] (Microsoft Corporation)
R2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [191064 2012-02-11] (Microsoft Corporation)
R2 MSSQLServerOLAPService; C:\Program Files\Microsoft SQL Server\MSAS11.MSSQLSERVER\OLAP\bin\msmdsrv.exe [61538904 2012-02-11] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19823248 2014-12-13] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910128 2015-01-28] (Electronic Arts)
R3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1771560 2014-10-10] (pdfforge GmbH)
S4 PDF Architect 2 Creator; C:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
S4 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-10-10] (pdfforge GmbH)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-11-16] ()
R2 QHActiveDefense; C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe [707184 2014-12-12] ()
R2 ReportServer; C:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2348632 2012-02-11] (Microsoft Corporation)
S3 SQL Server Distributed Replay Client; C:\Program Files (x86)\Microsoft SQL Server\110\Tools\DReplayClient\DReplayClient.exe [137304 2012-02-11] (Microsoft Corporation)
S3 SQL Server Distributed Replay Controller; C:\Program Files (x86)\Microsoft SQL Server\110\Tools\DReplayController\DReplayController.exe [342104 2012-02-11] (Microsoft Corporation)
S3 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [597080 2012-02-11] (Microsoft Corporation)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH)
R2 vmms; C:\Windows\system32\vmms.exe [13401600 2014-12-23] (Microsoft Corporation)
S3 VsEtwService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89240 2014-11-10] (Microsoft Corporation)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [147664 2014-11-10] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 360AntiHacker; C:\Windows\System32\Drivers\360AntiHacker64.sys [100424 2014-09-23] (360.cn)
R3 360AvFlt; C:\Windows\System32\DRIVERS\360AvFlt.sys [77896 2014-12-12] (360.cn)
R1 360Box64; C:\Windows\System32\DRIVERS\360Box64.sys [305736 2014-12-12] (360.cn)
S3 360Camera; C:\Windows\System32\Drivers\360Camera64.sys [40520 2014-09-23] (360.cn)
R1 360FsFlt; C:\Windows\System32\DRIVERS\360FsFlt.sys [312400 2014-09-23] (Qihu 360 Software Co., Ltd.)
R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT INTERNET SECURITY\a2accx64.sys [71472 2014-05-12] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files (x86)\Emsisoft Internet Security\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Internet Security\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files (x86)\Emsisoft Internet Security\a2util64.sys [23088 2014-05-12] (Emsisoft GmbH)
S1 BAPIDRV; C:\Windows\System32\DRIVERS\BAPIDRV64.sys [180816 2014-09-23] (Qihu 360 Software Co., Ltd.)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 cleanhlp; C:\Program Files (x86)\Emsisoft Internet Security\cleanhlp64.sys [57024 2013-12-04] (Emsisoft GmbH)
S3 DIRECTIO; C:\Program Files\PerformanceTest\DirectIo64.sys [31160 2014-04-24] ()
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-10-30] (Disc Soft Ltd)
R3 fwndis; C:\Windows\system32\DRIVERS\fwndis64.sys [491632 2015-01-01] ()
S1 fwwfp; C:\Program Files (x86)\Emsisoft Internet Security\fwwfp764.sys [414936 2015-01-01] ()
S3 hid7906; C:\Windows\SysWOW64\drivers\hid7906.sys [34963 2007-12-12] (Compuware Corporation) [File not signed]
S3 hid8101; C:\Windows\SysWOW64\drivers\hid8101.sys [37024 2007-12-03] (Compuware Corporation) [File not signed]
S3 hid8103; C:\Windows\SysWOW64\drivers\hid8103.sys [34587 2007-11-28] (Compuware Corporation) [File not signed]
R1 hvservice; C:\Windows\System32\drivers\hvservice.sys [68960 2014-12-23] (Microsoft Corporation)
S3 lunparser; C:\Windows\System32\drivers\lunparser.sys [19456 2014-12-23] (Microsoft Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-08] (Intel Corporation)
S3 NPF; C:\Windows\System32\drivers\NPF.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2014-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 passthruparser; C:\Windows\System32\drivers\passthruparser.sys [22016 2014-12-23] (Microsoft Corporation)
S3 pvhdparser; C:\Windows\System32\drivers\pvhdparser.sys [27136 2014-12-23] (Microsoft Corporation)
S4 RsFx0200; C:\Windows\System32\DRIVERS\RsFx0200.sys [334936 2012-02-11] (Microsoft Corporation)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [547032 2013-07-04] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [2944216 2013-08-21] (Realtek Semiconductor Corporation                           )
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 vhdparser; C:\Windows\System32\drivers\vhdparser.sys [18944 2014-12-23] (Microsoft Corporation)
R3 VMSMP; C:\Windows\system32\DRIVERS\vmswitch.sys [690688 2014-08-26] (Microsoft Corporation)
S3 VMSP; C:\Windows\system32\DRIVERS\vmswitch.sys [690688 2014-08-26] (Microsoft Corporation)
S3 VMSVSF; C:\Windows\system32\DRIVERS\vmswitch.sys [690688 2014-08-26] (Microsoft Corporation)
S3 VMSVSP; C:\Windows\system32\DRIVERS\vmswitch.sys [690688 2014-08-26] (Microsoft Corporation)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-13] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-01 23:43 - 2015-02-02 01:10 - 00034168 _____ () C:\Users\ihsan\Downloads\FRST.txt
2015-02-01 23:42 - 2015-02-02 01:10 - 00000000 ____D () C:\FRST
2015-02-01 23:41 - 2015-02-01 23:41 - 02131456 _____ (Farbar) C:\Users\ihsan\Downloads\FRST64.exe
2015-02-01 23:08 - 2015-02-01 23:14 - 00205616 _____ () C:\Users\ihsan\Desktop\Extras.Txt
2015-02-01 23:07 - 2015-02-01 23:13 - 00185112 _____ () C:\Users\ihsan\Desktop\OTL.Txt
2015-02-01 22:55 - 2015-02-01 22:55 - 00602112 _____ (OldTimer Tools) C:\Users\ihsan\Downloads\OTL.exe
2015-02-01 22:55 - 2015-02-01 22:55 - 00602112 _____ (OldTimer Tools) C:\Users\ihsan\Desktop\OTL.exe
2015-02-01 22:51 - 2015-02-01 22:51 - 00468480 _____ () C:\Users\ihsan\Downloads\CKScanner.exe
2015-02-01 20:43 - 2015-02-01 20:43 - 05661717 _____ () C:\Users\ihsan\Downloads\chipset_intel_9.4.0.1026_0xb351380a_818700.zip
2015-02-01 20:43 - 2015-02-01 20:43 - 05661717 _____ () C:\Users\ihsan\Downloads\chipset_intel_9.4.0.1026_0xb351380a_818700 (2).zip
2015-02-01 20:43 - 2015-02-01 20:43 - 05661717 _____ () C:\Users\ihsan\Downloads\chipset_intel_9.4.0.1026_0xb351380a_818700 (1).zip
2015-02-01 20:28 - 2015-02-01 20:36 - 00013721 _____ () C:\Users\ihsan\Downloads\hijackthis.log
2015-02-01 20:27 - 2015-02-01 20:27 - 00388608 _____ (Trend Micro Inc.) C:\Users\ihsan\Downloads\HijackThis.exe
2015-01-31 09:00 - 2015-01-31 09:00 - 00030289 _____ () C:\Users\ihsan\Downloads\(336817)Edge_of_Tomorrow_23.976fps_1CD_Turkce_SubRip_DiVXPlanet.rar
2015-01-31 08:56 - 2015-01-31 08:56 - 00031049 _____ () C:\Users\ihsan\Downloads\(336078)Edge_of_Tomorrow_23.976fps_1CD_Turkce_SubRip_DiVXPlanet.rar
2015-01-31 08:42 - 2015-01-31 08:42 - 00034598 _____ () C:\Users\ihsan\Downloads\(328659)Noah_23.976fps_1CD_Turkce_SubRip_DiVXPlanet.rar
2015-01-31 04:30 - 2015-01-31 10:38 - 00000000 ____D () C:\OutputFolder
2015-01-31 04:27 - 2015-01-31 04:29 - 00000000 ____D () C:\Program Files (x86)\Allok Video Converter
2015-01-31 04:27 - 2015-01-31 04:27 - 00001085 _____ () C:\Users\Public\Desktop\Allok Video Converter.lnk
2015-01-31 04:27 - 2015-01-31 04:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Allok Video Converter
2015-01-31 04:27 - 2007-04-12 14:19 - 00129024 _____ () C:\Windows\SysWOW64\AVERM.dll
2015-01-31 04:27 - 2006-09-26 13:57 - 00028672 _____ () C:\Windows\SysWOW64\AVEQT.dll
2015-01-31 04:20 - 2015-01-31 04:20 - 00219648 _____ () C:\Users\ihsan\Downloads\scheduling-05.ppt
2015-01-31 04:00 - 2015-01-31 04:00 - 04882432 _____ () C:\Users\ihsan\Downloads\ch7.ppt
2015-01-31 03:59 - 2015-01-31 03:59 - 03999232 _____ () C:\Users\ihsan\Downloads\ch6.ppt
2015-01-31 03:38 - 2015-01-31 03:38 - 00038632 _____ () C:\Users\ihsan\Downloads\(324302)RoboCop_23.976fps_1CD_Turkce_SubRip_DiVXPlanet.rar
2015-01-31 00:59 - 2015-01-31 01:00 - 00424448 _____ () C:\Users\ihsan\Downloads\csc4320 Chapter 5-2.ppt
2015-01-31 00:48 - 2015-01-31 03:25 - 00000000 ____D () C:\Users\ihsan\Documents\Freemake
2015-01-31 00:48 - 2015-01-31 03:25 - 00000000 ____D () C:\ProgramData\Freemake
2015-01-31 00:48 - 2015-01-31 00:48 - 00001336 _____ () C:\Users\Public\Desktop\Freemake Video Converter.lnk
2015-01-31 00:48 - 2015-01-31 00:48 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2015-01-31 00:48 - 2015-01-31 00:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
2015-01-31 00:46 - 2015-01-31 00:48 - 00000000 ____D () C:\Program Files (x86)\Freemake
2015-01-31 00:14 - 2015-01-31 00:15 - 01270544 _____ (Ellora Assets Corporation ) C:\Users\ihsan\Downloads\FreemakeVideoConverterSetup.exe
2015-01-31 00:13 - 2015-01-31 00:13 - 00008844 _____ () C:\Users\ihsan\Downloads\Edge_of_Tomorrow_2014_720p.torrent
2015-01-31 00:08 - 2015-01-31 00:08 - 00010011 _____ () C:\Users\ihsan\Downloads\Noah_2014_720p.torrent
2015-01-31 00:08 - 2015-01-31 00:08 - 00009367 _____ () C:\Users\ihsan\Downloads\RoboCop_2014_720p.torrent
2015-01-30 21:50 - 2015-01-30 21:51 - 00850432 _____ () C:\Users\ihsan\Downloads\Scheduling.ppt
2015-01-30 05:07 - 2015-01-30 05:07 - 00000000 ____D () C:\Users\ihsan\Downloads\Video
2015-01-30 04:39 - 2015-02-01 20:31 - 00184336 _____ () C:\Windows\WindowsUpdate.log
2015-01-30 04:37 - 2015-02-01 23:40 - 00002264 _____ () C:\Windows\setupact.log
2015-01-30 04:37 - 2015-01-30 04:37 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-30 04:36 - 2015-01-30 04:36 - 00002412 _____ () C:\Windows\PFRO.log
2015-01-30 04:34 - 2015-01-30 04:34 - 00000000 ____D () C:\ProgramData\Emsisoft
2015-01-30 04:10 - 2015-01-30 04:10 - 00037376 ___SH () C:\Users\ihsan\Desktop\Thumbs.db
2015-01-30 04:10 - 2015-01-30 04:10 - 00001138 _____ () C:\Users\Public\Desktop\Emsisoft Internet Security.lnk
2015-01-30 04:10 - 2015-01-30 04:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Internet Security
2015-01-30 04:09 - 2015-02-02 01:00 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Internet Security
2015-01-30 04:09 - 2015-01-01 21:36 - 00491632 _____ () C:\Windows\system32\Drivers\fwndis64.sys
2015-01-30 03:30 - 2015-01-30 03:45 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Wise Registry Cleaner
2015-01-30 03:29 - 2011-07-31 15:14 - 00076565 _____ (RaProducts.org) C:\Users\ihsan\Desktop\PureRa.exe
2015-01-30 03:25 - 2015-01-30 03:25 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-01-30 03:25 - 2015-01-30 03:25 - 00000834 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-01-30 03:25 - 2015-01-30 03:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-01-30 03:25 - 2015-01-30 03:25 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-30 03:05 - 2015-01-30 03:05 - 00000196 _____ () C:\Users\ihsan\Desktop\ksifre.rar
2015-01-30 03:02 - 2015-01-30 03:11 - 00000000 ____D () C:\Users\ihsan\Desktop\hellsing altyazı
2015-01-30 02:33 - 2015-01-30 02:33 - 00000000 ____D () C:\Users\ihsan\AppData\Local\VS Revo Group
2015-01-30 02:32 - 2015-01-30 02:32 - 00000000 ____D () C:\ProgramData\VS Revo Group
2015-01-30 02:32 - 2015-01-30 02:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2015-01-30 02:32 - 2015-01-30 02:32 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-01-30 02:32 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2015-01-29 00:46 - 2015-01-29 05:20 - 00000000 ____D () C:\Users\ihsan\Documents\GenTool
2015-01-28 22:53 - 2015-01-29 03:11 - 00000000 ____D () C:\Users\ihsan\Documents\Command and Conquer Generals Zero Hour Data
2015-01-28 22:53 - 2015-01-29 03:11 - 00000000 ____D () C:\Users\ihsan\Documents\Command and Conquer Generals Data
2015-01-28 22:53 - 2015-01-28 22:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Command and Conquer Generals and Zero Hour
2015-01-26 02:10 - 2015-01-26 02:10 - 00000000 ____D () C:\data_from_forms
2015-01-26 02:09 - 2015-01-26 02:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ETS
2015-01-26 02:09 - 2015-01-26 02:09 - 00000000 ____D () C:\Program Files (x86)\ETS
2015-01-26 02:06 - 2015-01-26 02:06 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Downloaded Installations
2015-01-20 02:29 - 2015-01-20 02:30 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Sublight
2015-01-20 02:29 - 2015-01-20 02:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sublight
2015-01-20 02:29 - 2015-01-20 02:29 - 00000000 ____D () C:\Program Files\Sublight
2015-01-19 14:52 - 2015-01-19 02:17 - 00174624 _____ (EasyAntiCheat Ltd) C:\Windows\SysWOW64\EasyAntiCheat.exe
2015-01-19 01:57 - 2014-11-22 12:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-01-19 01:57 - 2014-11-22 12:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-01-19 00:42 - 2015-01-19 00:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Command and Conquer Red Alert 2
2015-01-18 23:21 - 2015-01-28 22:51 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2015-01-18 23:04 - 2015-01-28 22:46 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Origin
2015-01-18 23:04 - 2015-01-18 23:28 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Origin
2015-01-18 17:50 - 2015-01-20 02:40 - 00121105 _____ () C:\Users\ihsan\Desktop\pk altyazı.srt
2015-01-18 17:36 - 2015-01-18 17:36 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\URUSoft
2015-01-18 17:36 - 2015-01-18 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\URUSoft
2015-01-18 17:36 - 2015-01-18 17:36 - 00000000 ____D () C:\Program Files (x86)\URUSoft
2015-01-18 14:55 - 2013-07-09 07:58 - 00263896 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtsUStor.sys
2015-01-18 14:55 - 2013-04-25 12:12 - 09889352 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtsUStoricon.dll
2015-01-16 00:10 - 2015-01-30 03:30 - 00000000 ____D () C:\Users\ihsan\Desktop\işletimsistemleri
2015-01-14 17:16 - 2014-12-19 08:26 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 17:16 - 2014-12-12 04:04 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 17:16 - 2014-12-12 02:51 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ahcache.sys
2015-01-14 17:16 - 2014-12-09 03:50 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00535640 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00531616 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00448792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00413248 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00372408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00108944 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00038264 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2015-01-14 17:16 - 2014-12-08 21:42 - 00033584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
2015-01-14 17:16 - 2014-12-06 05:17 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 17:16 - 2014-12-06 03:41 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 17:16 - 2014-12-06 03:35 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2015-01-14 17:16 - 2014-10-29 06:00 - 00465320 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2015-01-14 17:16 - 2014-10-29 06:00 - 00139984 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2015-01-14 17:16 - 2014-10-29 05:52 - 00500016 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-01-14 17:16 - 2014-10-29 05:52 - 00482872 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-01-14 17:16 - 2014-10-29 05:52 - 00394120 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-01-14 17:16 - 2014-10-29 05:52 - 00272248 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-01-14 17:16 - 2014-10-29 05:12 - 00413136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2015-01-14 17:16 - 2014-10-29 05:12 - 00136296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2015-01-14 17:16 - 2014-10-29 05:07 - 00424544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2015-01-14 17:16 - 2014-10-29 05:07 - 00370424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2015-01-14 17:16 - 2014-10-29 05:07 - 00344536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2015-01-14 17:16 - 2014-10-29 04:44 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2015-01-14 17:16 - 2014-10-29 03:59 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
2015-01-14 17:16 - 2014-10-29 03:24 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-14 17:16 - 2014-10-29 03:02 - 00911360 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-01-14 17:16 - 2014-10-29 03:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-12 21:40 - 2015-01-12 21:40 - 00000000 ____D () C:\Users\ihsan\Documents\Red Alert 3
2015-01-12 21:34 - 2015-01-12 21:34 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Red Alert 3
2015-01-12 18:08 - 2015-01-12 18:08 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Aegisub
2015-01-12 09:33 - 2015-01-12 09:39 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Dev-Cpp
2015-01-12 09:32 - 2015-01-12 09:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bloodshed Dev-C++
2015-01-12 09:32 - 2015-01-12 09:32 - 00000000 ____D () C:\Dev-Cpp
2015-01-09 21:10 - 2015-01-09 21:12 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Bioshock2Steam
2015-01-09 21:10 - 2015-01-09 21:10 - 00000000 ____D () C:\Users\ihsan\Documents\Bioshock2
2015-01-09 20:38 - 2015-01-09 21:09 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Bioshock
2015-01-09 20:38 - 2015-01-09 20:54 - 00000000 ____D () C:\Users\ihsan\Documents\Bioshock
2015-01-09 20:38 - 2015-01-09 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bioshock Türkçe
2015-01-09 13:44 - 2015-02-02 00:18 - 00000814 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-09 13:44 - 2015-01-24 22:18 - 00003702 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-08 20:33 - 2015-01-08 20:33 - 00036577 _____ () C:\Users\ihsan\Desktop\[kickass.so]cbm.hellsing.ultimate.1.10.complete.dual.audio.bdrip.720p.8bit.torrent
2015-01-08 20:32 - 2015-01-14 21:12 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\vlc
2015-01-08 20:08 - 2015-01-08 20:08 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ace Stream Media
2015-01-08 17:59 - 2015-01-08 17:59 - 00038519 _____ () C:\Users\ihsan\Desktop\Hellsing Ultimate OVA 01-10.torrent
2015-01-07 17:12 - 2015-01-07 17:12 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1C5070DB.sys
2015-01-06 02:42 - 2015-01-06 02:42 - 00000000 ____D () C:\Users\ihsan\Desktop\This War Of Mine
2015-01-05 21:31 - 2015-01-05 21:31 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Mozilla
2015-01-05 21:31 - 2015-01-05 21:31 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\huawei
2015-01-05 21:31 - 2015-01-05 21:31 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Mozilla
2015-01-05 21:31 - 2015-01-05 21:31 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Macromedia
2015-01-05 21:30 - 2015-01-05 21:30 - 00001171 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2015-01-05 21:30 - 2015-01-05 21:30 - 00000000 ____D () C:\ProgramData\Mozilla
2015-01-05 21:30 - 2015-01-05 21:30 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-05 21:07 - 2015-01-05 21:07 - 00000000 ____D () C:\ProgramData\TTNetIlkYardim
2015-01-05 16:48 - 2015-01-05 16:48 - 00000000 ____D () C:\ProgramData\Verimatrix
2015-01-04 15:03 - 2015-01-30 03:29 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\TeamViewer
2015-01-04 15:03 - 2015-01-04 15:04 - 00000000 ____D () C:\Program Files (x86)\TeamViewer
2015-01-04 15:03 - 2015-01-04 15:03 - 00001055 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-02 01:05 - 2014-09-28 12:55 - 00003596 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3051402733-4133393625-984315149-1001
2015-02-02 01:02 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2015-02-02 00:56 - 2014-10-21 12:09 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-02-02 00:56 - 2014-10-21 12:07 - 00000000 ____D () C:\ProgramData\Adobe
2015-02-02 00:56 - 2014-10-21 12:04 - 00000000 ____D () C:\Program Files\Adobe
2015-02-02 00:56 - 2014-09-28 12:50 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Adobe
2015-02-02 00:50 - 2014-10-21 12:13 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-02-01 23:43 - 2014-09-28 12:52 - 02230282 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-01 23:43 - 2013-08-23 00:53 - 00896376 _____ () C:\Windows\system32\perfh01F.dat
2015-02-01 23:43 - 2013-08-23 00:53 - 00224000 _____ () C:\Windows\system32\perfc01F.dat
2015-02-01 23:39 - 2014-09-28 15:06 - 00038972 _____ () C:\Users\ihsan\AppData\Local\BTServer.log
2015-02-01 20:03 - 2014-09-28 12:52 - 00000000 __RDO () C:\Users\ihsan\SkyDrive
2015-02-01 20:02 - 2014-09-28 15:04 - 00000000 ____D () C:\ProgramData\Realtek
2015-01-31 14:59 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF
2015-01-31 11:40 - 2014-09-28 12:50 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Packages
2015-01-31 04:35 - 2014-09-28 19:59 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\tixati
2015-01-31 04:21 - 2014-09-11 15:39 - 00000000 _RSHD () C:\360SANDBOX
2015-01-30 17:52 - 2014-09-28 12:59 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\DMCache
2015-01-30 17:50 - 2014-09-28 12:59 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\IDM
2015-01-30 14:03 - 2014-12-23 16:49 - 27590656 _____ () C:\Windows\system32\vmguest.iso
2015-01-30 13:50 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-01-30 08:38 - 2014-10-20 22:03 - 00000000 ___RD () C:\Users\ihsan\Desktop\program
2015-01-30 08:38 - 2013-08-22 15:25 - 00524288 ___SH () C:\Windows\system32\config\BBI
2015-01-30 04:36 - 2014-11-28 23:06 - 05184440 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-30 03:40 - 2014-10-19 01:46 - 00000000 ____D () C:\Users\ihsan\AppData\Local\0ad
2015-01-30 03:35 - 2014-09-28 20:12 - 00000000 __SHD () C:\ProgramData\360Quarant
2015-01-30 03:35 - 2014-09-11 16:00 - 00000000 __SHD () C:\$360Section
2015-01-30 03:35 - 2014-09-02 12:13 - 00033432 _____ () C:\PureRa.txt
2015-01-30 03:30 - 2014-11-13 21:54 - 00000000 ____D () C:\Users\ihsan\Desktop\Ders Notları
2015-01-30 03:30 - 2014-10-02 20:15 - 00000000 ____D () C:\Users\ihsan\.WebIde80
2015-01-30 03:30 - 2014-09-28 19:39 - 00000000 ___RD () C:\Users\ihsan\Downloads\Microsoft.SkypeApp_kzf8qxf38zg5c!App
2015-01-30 03:30 - 2014-09-28 15:06 - 00000000 ____D () C:\Users\ihsan\Documents\My Bluetooth
2015-01-30 03:30 - 2014-09-28 13:00 - 00000000 ____D () C:\Users\ihsan\Downloads\Compressed
2015-01-30 03:29 - 2014-10-30 20:00 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\DAEMON Tools Lite
2015-01-30 03:29 - 2014-10-27 00:54 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\FileZilla
2015-01-30 03:01 - 2014-12-17 20:08 - 00000000 ____D () C:\Users\Public\Documents\DevExpress Demos 14.2
2015-01-30 03:01 - 2014-12-17 20:07 - 00000000 ____D () C:\Program Files (x86)\DevExpress 14.2
2015-01-30 03:00 - 2014-12-17 20:34 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DevExpress 14.2
2015-01-30 02:59 - 2014-10-20 22:03 - 00000000 ____D () C:\Users\ihsan\Desktop\yazlım p
2015-01-30 02:58 - 2014-10-20 22:03 - 00000000 ____D () C:\Users\ihsan\Desktop\Oyun
2015-01-30 02:54 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-01-30 02:45 - 2014-10-02 16:28 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\RenPy
2015-01-30 02:39 - 2014-12-04 09:39 - 00000000 ____D () C:\Program Files (x86)\Nuance
2015-01-30 02:24 - 2014-09-28 19:44 - 00000000 ____D () C:\Program Files (x86)\StarCraft II
2015-01-29 18:17 - 2014-06-26 08:24 - 00000000 ____D () C:\AdwCleaner
2015-01-29 18:03 - 2014-12-23 17:31 - 00007639 _____ () C:\Users\ihsan\AppData\Local\Resmon.ResmonCfg
2015-01-29 06:54 - 2014-11-26 12:47 - 00000000 ____D () C:\ProgramData\Origin
2015-01-28 23:28 - 2014-11-26 12:47 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-01-28 23:22 - 2014-09-28 19:36 - 00000000 ____D () C:\Windows\system32\appmgmt
2015-01-28 22:28 - 2014-10-05 20:47 - 00000000 ____D () C:\Program Files (x86)\Jumpstart
2015-01-28 02:14 - 2014-10-21 10:03 - 00000000 ____D () C:\Users\ihsan\Documents\SQL Server Management Studio
2015-01-27 21:06 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-01-26 02:10 - 2014-09-28 12:53 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Macromedia
2015-01-24 22:20 - 2013-08-22 17:38 - 00714720 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-24 22:20 - 2013-08-22 17:38 - 00106976 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-24 01:03 - 2014-12-23 16:32 - 00000000 ____D () C:\Users\ihsan\Documents\Visual Studio 2015
2015-01-24 00:13 - 2014-10-20 20:53 - 00000000 ____D () C:\Users\ihsan\Documents\Visual Studio 2012
2015-01-23 13:36 - 2014-11-22 15:22 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\.ACEStream
2015-01-23 13:29 - 2014-11-22 15:22 - 00000000 ___HD () C:\_acestream_cache_
2015-01-21 03:09 - 2014-10-30 21:25 - 00000396 __RSH () C:\ProgramData\ntuser.pol
2015-01-18 14:55 - 2014-09-28 15:20 - 00000000 ____D () C:\Windows\SysWOW64\sda
2015-01-18 14:55 - 2014-09-28 14:38 - 00000000 ____D () C:\Program Files (x86)\Realtek
2015-01-14 17:29 - 2014-09-28 19:32 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 17:21 - 2014-09-28 19:32 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-12 21:30 - 2014-09-12 17:38 - 00000000 ____D () C:\Games
2015-01-12 18:08 - 2014-10-21 07:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-01-12 18:08 - 2014-10-21 07:49 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-01-12 09:21 - 2014-09-28 12:49 - 00000000 ____D () C:\Users\ihsan
2015-01-11 16:44 - 2014-10-21 10:04 - 00000000 ____D () C:\Users\ReportServer
2015-01-11 16:44 - 2014-10-21 10:04 - 00000000 ____D () C:\Users\MSSQLServerOLAPService
2015-01-11 16:44 - 2014-10-21 10:03 - 00000000 ____D () C:\Users\MSSQLSERVER
2015-01-11 16:44 - 2014-10-21 10:03 - 00000000 ____D () C:\Users\MSSQLFDLauncher
2015-01-11 16:44 - 2014-10-21 10:03 - 00000000 ____D () C:\Users\MsDtsServer110
2015-01-09 13:56 - 2014-10-18 17:11 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Adobe
2015-01-09 13:34 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\LiveKernelReports
2015-01-08 20:09 - 2014-11-22 15:21 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\ACEStream
2015-01-08 18:20 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\addins
2015-01-08 18:06 - 2014-10-30 15:40 - 00000000 ____D () C:\Users\ihsan\Documents\Korra
2015-01-06 05:37 - 2015-01-01 14:38 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\GitHub
2015-01-06 05:37 - 2015-01-01 14:38 - 00000000 ____D () C:\Users\ihsan\AppData\Local\GitHub
2015-01-06 04:50 - 2015-01-01 14:43 - 00000000 ____D () C:\Users\ihsan\Documents\GitHub
2015-01-06 04:46 - 2014-12-28 22:53 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Deployment
2015-01-05 21:30 - 2014-10-26 12:49 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox

==================== Files in the root of some directories =======

2014-11-22 12:42 - 2014-11-22 12:42 - 0000132 _____ () C:\Users\ihsan\AppData\Roaming\Adobe PNG Format CC Prefs
2014-09-28 15:06 - 2015-02-01 23:39 - 0038972 _____ () C:\Users\ihsan\AppData\Local\BTServer.log
2014-11-24 23:55 - 2014-11-25 16:37 - 0000600 _____ () C:\Users\ihsan\AppData\Local\PUTTY.RND
2014-12-23 17:31 - 2015-01-29 18:03 - 0007639 _____ () C:\Users\ihsan\AppData\Local\Resmon.ResmonCfg

Some content of TEMP:
====================
C:\Users\ihsan\AppData\Local\Temp\eauninstall.exe
C:\Users\ihsan\AppData\Local\Temp\extra_uninst.exe
C:\Users\ihsan\AppData\Local\Temp\FreemakeVideoConverterFull.exe
C:\Users\ihsan\AppData\Local\Temp\The Battle for Middle-earth II_uninst.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-28 19:46

==================== End Of Log ============================

addition
 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-02-2015
Ran by ihsan at 2015-02-02 01:10:38
Running from C:\Users\ihsan\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Emsisoft Internet Security (Disabled - Up to date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: 360 Total Security (Disabled - Up to date) {2B66EE1E-E5C8-C2F7-648F-4E55AC68D37D}
AS: 360 Total Security (Disabled - Up to date) {90070FFA-C3F2-CD79-5E3F-7527D7EF99C0}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Internet Security (Disabled - Up to date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
FW: Emsisoft Internet Security (Disabled) {BD3F5FCA-866B-1E2E-0A68-58900A751EA1}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 Tools for .Net 3.5 (x32 Version: 3.11.50727 - Microsoft Corporation) Hidden
360 Total Security (HKLM-x32\...\360TotalSecurity) (Version: 5.2.0.1080 - 360 Güvenlik Merkezi)
Ace Stream Media 3.0.5 (HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\AceStream) (Version: 3.0.5 - Ace Stream Media)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated)
Age of Empires II: HD Edition (HKLM-x32\...\Steam App 221380) (Version:  - Hidden Path Entertainment, Ensemble Studios)
Age of Empires® III: Complete Collection (HKLM-x32\...\Steam App 105450) (Version:  - Ensemble Studios)
Allok Video Converter 4.6.0529 (HKLM-x32\...\Allok Video Converter_is1) (Version:  - Allok Soft Inc.)
Application Insights Tools for Visual Studio 2015 Preview (x32 Version: 3.0 - Microsoft Corporation) Hidden
Auslogics DiskDefrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 5.1.0.0 - Auslogics Labs Pty Ltd)
AzureTools.Notifications (x32 Version: 2.4.20714.1601 - Microsoft Corporation) Hidden
Battery Calibration (HKLM-x32\...\{619FA785-489B-4D22-911F-82D6EDF5BDB0}) (Version: 1.0.1405.0701 - Micro-Star International Co., Ltd.)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Behaviors SDK (Windows Phone) for Visual Studio 2013 (x32 Version: 12.0.50926.80 - Microsoft Corporation) Hidden
Behaviors SDK (Windows) for Visual Studio 2013 (x32 Version: 12.0.50926.80 - Microsoft Corporation) Hidden
BioShock (HKLM-x32\...\Steam App 7670) (Version:  - 2K Boston)
BioShock 2 (HKLM-x32\...\Steam App 8850) (Version:  - 2K Marin)
BioShock Infinite (HKLM-x32\...\Steam App 8870) (Version:  - Irrational Games)
Bioshock Türkçe Yama v1.00 (HKLM-x32\...\Bioshock TR) (Version: 1.00 - )
Blend for Visual Studio 2012 (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Blend for Visual Studio 2012 ENU resources (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for Silverlight 5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for Windows Phone 8.0 (x32 Version: 3.0.30924.0 - Microsoft Corporation) Hidden
Build Tools - amd64 (Version: 12.0.31010 - Microsoft Corporation) Hidden
Build Tools - x86 (x32 Version: 12.0.31010 - Microsoft Corporation) Hidden
Build Tools 14.0 (amd64) (Version: 14.0.22310 - Microsoft Corporation) Hidden
Build Tools 14.0 (x86) (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
Build Tools Language Resources - amd64 (Version: 12.0.31010 - Microsoft Corporation) Hidden
Build Tools Language Resources - x86 (x32 Version: 12.0.31010 - Microsoft Corporation) Hidden
Build Tools Language Resources 14.0 (amd64) (Version: 14.0.22310 - Microsoft Corporation) Hidden
Build Tools Language Resources 14.0 (x86) (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.02 - Piriform)
ClumsyLeaf CloudXplorer (HKLM-x32\...\{7F111167-5B0A-4DD4-8D0F-C6DB7649B938}) (Version: 3.2.0.0 - ClumsyLeaf Software)
Command & Conquer™ Red Alert 2 and Yuri’s Revenge (HKLM-x32\...\{F5275D1C-D133-486D-8F07-D6C571F0A8EC}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Command & Conquer™: Generals and Zero Hour (HKLM-x32\...\{609F6FD5-4B22-4D7A-AD30-8C9DD480D5BE}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Democracy 3 (HKLM-x32\...\Steam App 245470) (Version:  - Positech Games)
Dev-C++ 5 beta 9 release (4.9.9.2) (HKLM-x32\...\Dev-C++) (Version:  - )
DomDomSoft Manga Downloader (remove only) (HKLM-x32\...\DomDomSoft Manga Downloader) (Version:  - )
Don't Starve Together Beta (HKLM-x32\...\Steam App 322330) (Version:  - )
Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4521.29298 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition 5.16.0 (x32 Version: 5.16.0.2178 - PreEmptive Solutions) Hidden
Emsisoft Internet Security (HKLM-x32\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 9.0 - Emsisoft Ltd.)
ErrorList (x32 Version: 1.0 - Microsoft Corporation) Hidden
ETDWare PS/2-X64 11.13.4.4_WHQL (HKLM\...\Elantech) (Version: 11.13.4.4 - ELAN Microelectronic Corp.)
Far Cry (HKLM-x32\...\Steam App 13520) (Version:  - Crytek Studios)
Far Cry 2 (HKLM-x32\...\Steam App 19900) (Version:  - Ubisoft Montreal)
Far Cry® 3 (HKLM-x32\...\Steam App 220240) (Version:  - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai)
Far Cry® 3 Blood Dragon (HKLM-x32\...\Steam App 233270) (Version:  - Ubisoft Montreal)
FileZilla Client 3.9.0.6 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.6 - Tim Kosse)
Freemake Video Converter version 4.1.5 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.5 - Ellora Assets Corporation)
GameRanger (HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\GameRanger) (Version:  - GameRanger Technologies)
Garry's Mod (HKLM-x32\...\Steam App 4000) (Version:  - Facepunch Studios)
Git version 1.9.0-preview20140217 (HKLM-x32\...\Git_is1) (Version: 1.9.0-preview20140217 - The Git Development Community)
GitHub (HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\5f7eb300e2ea4ebf) (Version: 2.6.6.2 - GitHub, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 41.0.2272.35 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
IIS 8.0 Express (HKLM\...\{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}) (Version: 8.0.1557 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb) (Version:  - )
Insurgency (HKLM-x32\...\Steam App 222880) (Version:  - New World Interactive)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.20.1447 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.2.4.1000 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
Java 8 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418025F0}) (Version: 8.0.250 - Oracle Corporation)
JetBrains PhpStorm 8.0.1 (HKLM-x32\...\PhpStorm 8.0.1) (Version: 138.2001.2328 - JetBrains s.r.o.)
Jumpstart Installation Program (HKLM-x32\...\{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}) (Version:  - Atheros)
KB9X Radio Switch Driver (HKLM\...\5AADE1068CF70DD983F763B20CF2CAAB72883915) (Version: 1.1.0.0 - ENE TECHNOLOGY INC.)
K-Lite Mega Codec Pack 10.8.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.0 - )
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version:  - Valve)
LocalESPC (x32 Version: 8.59.29989 - Microsoft Corporation) Hidden
LocalESPCui for en-us (x32 Version: 8.59.29989 - Microsoft) Hidden
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.3 Preview Multi-Targeting Pack (ENU) (HKLM-x32\...\{6FF89029-E442-4346-BB1E-C73AA6F6D080}) (Version: 4.5.53346 - Microsoft Corporation)
Microsoft .NET Framework 4.5.3 Preview Multi-Targeting Pack (HKLM-x32\...\{861F6EBB-5856-4DB9-B812-363CFB1D2F56}) (Version: 4.5.53346 - Microsoft Corporation)
Microsoft ASP.NET MVC 3 (HKLM-x32\...\{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}) (Version: 3.0.20105.0 - Microsoft Corporation)
Microsoft ASP.NET Web Pages (HKLM-x32\...\{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}) (Version: 1.0.20105.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation)
Microsoft Help Viewer 2.0 (HKLM-x32\...\Microsoft Help Viewer 2.0) (Version: 2.0.50727 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.22310 - Microsoft Corporation)
Microsoft Office 2003 Web Components (HKLM-x32\...\{90120000-00A4-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Report Viewer 2012 Runtime (HKLM-x32\...\{9CCE40CE-A9E6-4916-8729-B008558EEF3F}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Silverlight 4 SDK (HKLM-x32\...\{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Silverlight 5 SDK (HKLM-x32\...\{E1FBB3D4-ADB0-4949-B101-855DA061C735}) (Version: 5.0.61118.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{83F2B8F4-5CF3-4BE9-9772-9543EAE4AC5F}) (Version: 10.51.2500.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files  (HKLM\...\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server 2012 (64-bit) (HKLM\...\Microsoft SQL Server SQLServer2012) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM\...\{36E619BC-A234-4EC3-849B-779A7C865A45}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM-x32\...\{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\...\{13D558FE-A863-402C-B115-160007277033}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (HKLM-x32\...\{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (x64) (HKLM\...\{FA0A244E-F3C2-4589-B42A-3D522DE79A42}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Policies  (HKLM-x32\...\{DC487E40-046E-42A9-9C7C-5D2B1A7EB211}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Setup (English) (HKLM\...\{8CB0713F-CFE0-445D-BCB2-538465860E1A}) (Version: 11.1.3128.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL Compiler Service  (HKLM\...\{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL ScriptDom  (HKLM\...\{0E8670B8-3965-4930-ADA6-570348B67153}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 T-SQL Language Service  (HKLM\...\{CC8B009A-98C9-497F-99AF-CEBE35D8C0CF}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 T-SQL Language Service  (HKLM-x32\...\{6D6D43E5-218C-4B05-92D3-2240810F4760}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2014 Express LocalDB  (HKLM\...\{AB8DE9BA-19E1-446A-BCFA-6B3DA9751E21}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Transact-SQL ScriptDom  (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 T-SQL Language Service  (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools – Database Projects – Web installer entry point (HKLM-x32\...\{F3BBC56F-2282-4464-952F-A89772181F30}) (Version: 10.3.20116.0 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (11.1.20627.00) (HKLM-x32\...\{FA804794-2CCB-4301-954F-2C2894698876}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (14.0.41025.0) (HKLM-x32\...\{455A16B4-CD22-4529-B429-DD454573E76A}) (Version: 14.0.41025.0 - Microsoft Corporation)
Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00) (HKLM-x32\...\{790E9425-8570-493F-9AE7-81AFC9E46930}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{C3F6F200-6D7B-4879-B9EE-700C0CE1FCDA}) (Version: 10.51.2500.0 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (x64) (HKLM\...\{4701DEDE-1888-49E0-BAE5-857875924CA2}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\...\{F1949145-EB64-4DE7-9D81-E6D27937146C}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{DAF4DDA4-3B5A-407D-B4DF-07922C5A0D22}) (Version: 12.0.2360.29 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{659D2DBE-CA2C-4C8F-AF2B-2C8DE262B278}) (Version: 12.0.2360.29 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Preview Redistributable (x64) - 14.0.22310 (HKLM-x32\...\{eb6c06e7-8ff6-4978-ab4c-561383593306}) (Version: 14.0.22310.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Preview Redistributable (x86) - 14.0.22310 (HKLM-x32\...\{2e4043b7-cd84-44db-b81a-8f6e5ffb7398}) (Version: 14.0.22310.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Shell (Integrated) - ENU (HKLM-x32\...\{012D26C3-E12A-3BDA-8ECE-DF14E721A507}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Shell (Isolated) - ENU (HKLM-x32\...\{D64B6984-242F-32BC-B008-752806E5FC44}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2015 Preview Secondary Installer (HKLM-x32\...\{B6CB8401-B0A8-4795-8BED-F7B49D51ABCF}_SecondaryInstaller) (Version: 14.0.22310 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications Design-Time 3.0 (HKLM-x32\...\{5A03C202-08B4-3F1D-9A60-A4F53EF1B636}) (Version: 10.0.40220 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications x64 Runtime 3.0 (HKLM\...\{F14401A9-F0A0-33CC-8444-F60823A60DEB}) (Version: 10.0.40220 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications x86 Runtime 3.0 (HKLM-x32\...\{191A6F65-6878-398D-A272-EF011B80F371}) (Version: 10.0.40220 - Microsoft Corporation)
Microsoft Visual Studio Ultimate 2012 (HKLM-x32\...\{9600393b-6ede-469b-a522-689fce1461d1}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual Studio Ultimate 2015 Preview (HKLM-x32\...\{e1f58f60-306c-4f5b-9788-5b9292910779}) (Version: 14.0.22310.1 - Microsoft Corporation)
Microsoft VSS Writer for SQL Server 2012 (HKLM\...\{3E0DD83F-BE4C-4478-86A0-AD0D79D1353E}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Web Deploy 3.6 Beta3 (HKLM\...\{07F0FC77-282E-42E5-BAE6-B8C098F8453E}) (Version: 3.1238.1942 - Microsoft Corporation)
Microsoft Web Deploy dbSqlPackage Provider - enu (HKLM-x32\...\{E4C33F5B-1B2F-466E-957E-B274F08151A0}) (Version: 10.3.20225.0 - Microsoft Corporation)
Microsoft Web Platform Installer 5.0 (HKLM\...\{4D84C195-86F0-4B34-8FDE-4A17EB41306A}) (Version: 5.0.50430.0 - Microsoft Corporation)
Mozilla Firefox 34.0.5 (x86 tr) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 tr)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
Multi-Device Hybrid Apps using C# - Templates - ENU (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
NARUTO SHIPPUDEN: Ultimate Ninja STORM 3 Full Burst (HKLM-x32\...\Steam App 234670) (Version:  - CyberConnect 2)
Node.js (HKLM-x32\...\{417EF6AA-3961-4119-9A00-312724B35D3A}) (Version: 0.10.33 - Joyent, Inc. and other Node contributors)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.9 - Notepad++ Team)
Nuance OmniPage Ultimate (HKLM-x32\...\{419512F9-D5E7-4ED2-BF99-E7F2C0176B6A}) (Version: 19.00.0000 - Nuance Communications, Inc.)
NVIDIA GeForce Experience 2.1.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.5 - NVIDIA Corporation)
NVIDIA Grafik Sürücüsü 344.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.65 - NVIDIA Corporation)
NVIDIA PhysX Sistem Yazılımı 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
Open XML SDK 2.5 for Microsoft Office (x32 Version: 2.5.5631 - Microsoft Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: 9.5.2.2829 - Electronic Arts, Inc.)
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
PAYDAY 2 (HKLM-x32\...\Steam App 218620) (Version:  - OVERKILL - a Starbreeze Studio.)
PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.41.17507 - pdfforge GmbH)
PDF Architect 2 Asian Fonts Pack (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Convert Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Edit Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Forms Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Insert Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 OCR Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Review Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Secure Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 View Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PerformanceTest v8.0 (HKLM\...\PerformanceTest 8_is1) (Version: 8.0.1042.0 - Passmark Software)
PreEmptive Analytics Visual Studio Components (x32 Version: 1.0.2180.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.3197.1 - PreEmptive Solutions) Hidden
Prerequisites for SSDT  (HKLM-x32\...\{21373064-AD95-48DB-A32E-0D9E08EF7355}) (Version: 12.0.2000.8 - Microsoft Corporation)
Prerequisites for SSDT  (HKLM-x32\...\{9169C939-ED01-446A-BD0C-29873BAF4E48}) (Version: 11.0.2100.60 - Microsoft Corporation)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Python Tools Redirection Template (x32 Version: 1.1 - Microsoft Corporation) Hidden
Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.21 - Qualcomm Atheros Inc.)
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.754.754.082813 - REALTEK Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30164 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0224 - REALTEK Semiconductor Corp.)
Revo Uninstaller Pro 3.1.2 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.2 - VS Revo Group, Ltd.)
Roslyn Language Services - x86 (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
Rust (HKLM-x32\...\Steam App 252490) (Version:  - Facepunch Studios)
SCM (HKLM\...\{614FD4D7-78CE-43E0-88E1-F6DE78069B9A}) (Version: 13.013.09262 - Application)
SharePoint Client Components (Version: 15.0.4641.1002 - Microsoft Corporation) Hidden
SharePoint Client Components (Version: 16.0.3104.1200 - Microsoft Corporation) Hidden
SHIELD Streaming (Version: 3.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.18.9 - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Sound Blaster Cinema (HKLM-x32\...\{8801CA65-921A-4CCC-9D63-879D1D0BAA97}) (Version: 1.00.02 - Creative Technology Limited)
SQL Server 2012 Analysis Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 BI Development Studio (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Client Tools (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Common Files (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Data quality client (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Data quality service (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Shared (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Distributed Replay (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Documentation Components (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Full text search (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Integration Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Management Studio (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Master Data Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Reporting Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 RS_SharePoint_SharedService (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 SQL Data Quality Common (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server Browser for SQL Server 2012 (HKLM-x32\...\{4B9E6EB0-0EED-4E74-9479-F982C3254F71}) (Version: 11.0.2100.60 - Microsoft Corporation)
Sql Server Customer Experience Improvement Program (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
Sublight (HKLM\...\Sublight_is1) (Version: 4 - Sublight Labs)
Subtitle Workshop 2.51 (HKLM-x32\...\SubtitleWorkshop) (Version:  - )
Team Explorer for Microsoft Visual Studio 2015 Preview (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.36897 - TeamViewer)
The Elder Scrolls V Skyrim Türkçe Yama Uyum Programı v1.00 (HKLM-x32\...\The Elder Scrolls V Skyrim TR) (Version: 1.00 - OyunCeviri.com)
This War of Mine (HKLM-x32\...\{5FD7B6B3-08C7-4FEE-9C37-A2134C699885}}_is1) (Version: 1 - 11 bit studios)
Tixati (HKLM-x32\...\tixati) (Version:  - )
TOEFL Sampler (HKLM-x32\...\{95744E49-71D1-453A-9466-6930819043C8}) (Version: 1.00.0001 - ETS)
Tropico 4 (HKLM-x32\...\Steam App 57690) (Version:  - Haemimont Games)
TypeScript Power Tool (x32 Version: 1.3.0.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 14 (x32 Version: 1.3.0.0 - Microsoft Corporation) Hidden
Unity Web Player (HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\UnityWebPlayer) (Version: 4.5.5f1 - Unity Technologies ApS)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
USB Network Driver (HKLM-x32\...\{66ED8E01-C915-41F5-B33E-C5C31F27B885}) (Version: 2007.07.3 - )
Visual Studio 2010 Prerequisites - English (HKLM\...\{662014D2-0450-37ED-ABAE-157C88127BEB}) (Version: 10.0.40219 - Microsoft Corporation)
VsHub (x32 Version: 1.0.0.0 - Microsoft Corporation) Hidden
WCF Data Services 5.0 (for OData v3) Primary Components (x32 Version: 5.0.50628.0 - Microsoft Corporation) Hidden
WCF Data Services 5.6.2 Runtime (x32 Version: 5.6.61937.2 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2012 (x32 Version: 5.0.50710.0 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2014 (x32 Version: 5.6.61937.2 - Microsoft Corporation) Hidden
WCF RIA Services V1.0 SP2 (HKLM-x32\...\{5D8DD6A8-C4D7-4554-93F9-F1CC28C72600}) (Version: 4.1.62812.0 - Microsoft Corporation)
Windows Phone 8.1 Emulators - ENU (HKLM-x32\...\{166a69f6-6512-47ea-a342-17d954fc059a}) (Version: 12.0.31010.0 - Microsoft Corporation)
WinRAR 5.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
Workflow Manager Client 1.0 (Version: 2.0.40131.0 - Microsoft Corporation) Hidden
Workflow Manager Tools 1.0 for Visual Studio (Version: 2.0.41015.0 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-3051402733-4133393625-984315149-1001_Classes\CLSID\{0BC0D8BD-047A-4620-9070-11B2CABC838B}\InprocServer32 -> 0x0ADCCA3361B30CBC8D98C765E8A222CC324FD91738B27840 No File
CustomCLSID: HKU\S-1-5-21-3051402733-4133393625-984315149-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)

==================== Restore Points  =========================


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 15:25 - 2014-12-15 00:30 - 00001132 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1                   activate.adobe.com
127.0.0.1                   practivate.adobe.com
127.0.0.1                   lmlicenses.wip4.adobe.com
127.0.0.1                   lm.licenses.adobe.com
127.0.0.1                   na1r.services.adobe.com
127.0.0.1                   hlrcv.stage.adobe.com


==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {23081457-A505-40A0-A99D-A2C00BA91AB4} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-24] (Adobe Systems Incorporated)
Task: {2D215246-5F93-4498-818D-6D8E08550B24} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {35A7EB11-BBFF-4755-A60F-4C6954D6702D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-28] (Google Inc.)
Task: {4F41FB20-FF5A-4670-9CDF-10C4FE25619B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-01-20] (Piriform Ltd)
Task: {596C62E0-D813-434E-B840-C3A43565DACD} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-3051402733-4133393625-984315149-1001
Task: {62AD2687-6051-44F7-A86F-8B6B910F9ADA} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {7CFBB224-A68D-4A61-A116-38F219528831} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-28] (Google Inc.)
Task: {EE8F767C-9BE7-4074-8832-56834A6CE58D} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-10-06] ()
Task: {F203A82A-F19C-4D53-82AA-EC974E4F4EF0} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2014-09-28 15:14 - 2013-08-28 11:35 - 00056832 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
2014-11-16 16:28 - 2014-11-16 16:28 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2014-09-28 20:05 - 2014-12-12 11:10 - 00707184 _____ () C:\Program Files (x86)\360\Total Security\safemon\QHActiveDefense.exe
2014-09-28 15:37 - 2014-11-04 02:04 - 00013120 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2014-09-28 15:38 - 2014-11-04 00:02 - 00116880 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2012-10-01 19:36 - 2012-10-01 19:36 - 06522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-09-28 20:05 - 2014-12-12 11:10 - 00259152 _____ () C:\Program Files (x86)\360\Total Security\MenuEx64.dll
2014-05-12 11:49 - 2014-05-12 11:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2014-11-27 18:14 - 2012-11-01 11:21 - 00325120 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL
2015-01-30 02:48 - 2015-01-28 06:49 - 01529672 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.35\libglesv2.dll
2015-01-30 02:48 - 2015-01-28 06:49 - 00091976 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.35\libegl.dll
2015-01-30 02:48 - 2015-01-28 06:49 - 11286344 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.35\pdf.dll
2015-01-30 02:48 - 2015-01-28 06:49 - 26725704 _____ () C:\Program Files (x86)\Google\Chrome\Application\41.0.2272.35\PepperFlash\pepflashplayer.dll
2015-01-21 04:06 - 2015-01-21 04:06 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1055.dll
2014-09-28 16:20 - 2013-08-08 12:25 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-09-28 15:37 - 2014-11-04 02:04 - 00010952 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
2015-02-02 00:54 - 2015-02-02 00:54 - 00011264 _____ () C:\Users\ihsan\AppData\Local\Temp\nsp5619.tmp\System.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\ProgramData\TEMP:A303874F
AlternateDataStreams: C:\ProgramData\TEMP:AEC0AC81
AlternateDataStreams: C:\Users\ihsan\SkyDrive:ms-properties

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: GladFileMonSvc => 2
MSCONFIG\Services: jswpbapi => 2
MSCONFIG\Services: jswpsapi => 3
MSCONFIG\Services: NitroDriverReadSpool9 => 2
MSCONFIG\Services: NitroUpdateService => 2
MSCONFIG\Services: PDF Architect 2 Creator => 2
MSCONFIG\Services: pdfforge CrashHandler => 3
MSCONFIG\Services: PDFProFiltSrv => 2
HKLM\...\StartupApproved\StartupFolder: => "Nuance Cloud Connector.lnk"
HKLM\...\StartupApproved\Run: => "Nvtmru"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "jswtrayutil"
HKLM\...\StartupApproved\Run32: => "USB Gamepad"
HKLM\...\StartupApproved\Run32: => "AdobeCEPServiceManager"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "ISUSPM"
HKLM\...\StartupApproved\Run32: => "Nuance OmniPage Ultimate-reminder"
HKLM\...\StartupApproved\Run32: => "OmniPage Preload"
HKLM\...\StartupApproved\Run32: => "PDFProHook"
HKLM\...\StartupApproved\Run32: => "PDF8 Registry Controller"
HKLM\...\StartupApproved\Run32: => "Babylon Client"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "IDMan"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "GUDelayStartup"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "AceStream"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "ISUSPM"

========================= Accounts: ==========================

Administrator (S-1-5-21-3051402733-4133393625-984315149-500 - Administrator - Disabled)
Guest (S-1-5-21-3051402733-4133393625-984315149-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3051402733-4133393625-984315149-1003 - Limited - Enabled)
ihsan (S-1-5-21-3051402733-4133393625-984315149-1001 - Administrator - Enabled) => C:\Users\ihsan

==================== Faulty Device Manager Devices =============

Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/02/2015 01:00:44 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Hatalı uygulama adı: explorer.exe, sürüm: 6.3.9600.17284, zaman damgası: 0x53f8130d
Hatalı modül adı: unknown, sürüm: 0.0.0.0, zaman damgası: 0x00000000
Özel durum kodu: 0xc0000005
Hata uzaklığı 0x6f83993d
Hatalı işlem kimliği: 0x2384
Uygulama başlangıç zamanı: 0xexplorer.exe0
Hatalı uygulama yolu: explorer.exe1
Hatalı modül yolu: explorer.exe2
Rapor kimliği: explorer.exe3
Hatalı paket tam adı: explorer.exe4
Hatalı paketle ilgili uygulama kimliği: explorer.exe5

Error: (02/02/2015 00:49:27 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest1" için etkinleştirme içeriği oluşturulamadı. "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest2" adlı bildirim veya ilke dosyasında C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest3. satırda hata var.
Uygulama için gereken bir bileşen sürümü halen etkin olan bir başka bileşen sürümüyle çakışıyor.
Çakışan bileşenler:
Bileşen 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Bileşen 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.

Error: (02/01/2015 08:08:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe programının 6.3.9600.17031 sürümü, Windows ile birlikte çalışmayı durdurdu ve kapatıldı. Sorun hakkında daha fazla bilgi olup olmadığını görmek için Eylem Merkezi denetim masasında sorunun geçmişini denetleyin.

İşlem Kimlik No: 2a70

Başlatma Saati: 01d03e4956c2c1a5

Sona Erdirme Saati: 4294967295

Uygulama Yolu: C:\Windows\syswow64\wwahost.exe

Rapor Kimliği: 4aa0e109-aa3d-11e4-8294-8c89a50ef469

Hatalı paket tam adı: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c

Hatalı paketle ilgili uygulama kimliği: App

Error: (01/31/2015 05:05:47 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest1" için etkinleştirme içeriği oluşturulamadı. "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest2" adlı bildirim veya ilke dosyasında C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest3. satırda hata var.
Uygulama için gereken bir bileşen sürümü halen etkin olan bir başka bileşen sürümüyle çakışıyor.
Çakışan bileşenler:
Bileşen 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifest.
Bileşen 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifest.

Error: (01/31/2015 04:25:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Hatalı uygulama adı: Allok Video Converter v4.6.0529 Portable.exe, sürüm: 1.0.2.0, zaman damgası: 0x00000031
Hatalı modül adı: unknown, sürüm: 0.0.0.0, zaman damgası: 0x00000000
Özel durum kodu: 0xc0000005
Hata uzaklığı 0x020895c1
Hatalı işlem kimliği: 0x22bc
Uygulama başlangıç zamanı: 0xAllok Video Converter v4.6.0529 Portable.exe0
Hatalı uygulama yolu: Allok Video Converter v4.6.0529 Portable.exe1
Hatalı modül yolu: Allok Video Converter v4.6.0529 Portable.exe2
Rapor kimliği: Allok Video Converter v4.6.0529 Portable.exe3
Hatalı paket tam adı: Allok Video Converter v4.6.0529 Portable.exe4
Hatalı paketle ilgili uygulama kimliği: Allok Video Converter v4.6.0529 Portable.exe5

Error: (01/30/2015 01:52:23 PM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER) cannot connect to the report server database.

Error: (01/30/2015 08:12:22 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LiveComm.exe programının 17.5.9600.20689 sürümü, Windows ile birlikte çalışmayı durdurdu ve kapatıldı. Sorun hakkında daha fazla bilgi olup olmadığını görmek için Eylem Merkezi denetim masasında sorunun geçmişini denetleyin.

İşlem Kimlik No: d0

Başlatma Saati: 01d03c52fa76c686

Sona Erdirme Saati: 4294967295

Uygulama Yolu: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exe

Rapor Kimliği: ee5d360d-a846-11e4-8293-8c89a50ef469

Hatalı paket tam adı: microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe

Hatalı paketle ilgili uygulama kimliği: ppleae38af2e007f4358a809ac99a64a67c1

Error: (01/30/2015 06:39:11 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: IHOCAN)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 uygulamasının etkinleştirilmesi şu hatayla başarısız oldu: -2144927142 Ek bilgi için Microsoft-Windows-TWinUI/Operational günlüğüne bakın.

Error: (01/30/2015 06:39:11 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: IHOCAN)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1 uygulamasının etkinleştirilmesi şu hatayla başarısız oldu: -2144927142 Ek bilgi için Microsoft-Windows-TWinUI/Operational günlüğüne bakın.

Error: (01/30/2015 04:38:59 AM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER) cannot connect to the report server database.


System errors:
=============
Error: (02/01/2015 08:26:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Steam Client Service hizmeti şu hata nedeniyle başlatılamadı: 
%%1053

Error: (02/01/2015 08:26:26 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Steam Client Service hizmetinin bağlanması beklenirken zaman aşımı (30000 milisaniye) oluştu.

Error: (02/01/2015 08:06:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Emsisoft Protection Service hizmeti beklenmedik şekilde sona erdi.  Bu durum 2 defa oluştu.  0 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti yeniden başlat.

Error: (02/01/2015 08:06:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Emsisoft Protection Service hizmeti beklenmedik şekilde sona erdi.  Bu durum 1 defa oluştu.  0 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti yeniden başlat.

Error: (01/31/2015 11:49:36 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: WSearch hizmetinden işlem yanıtı beklenirken zaman aşımı (30000 milisaniye) oluştu.

Error: (01/31/2015 02:25:29 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: TeamViewer 10 hizmeti beklenmedik şekilde sona erdi.  Bu durum 2 defa oluştu.  2000 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti yeniden başlat.

Error: (01/31/2015 02:25:19 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: TeamViewer 10 hizmeti beklenmedik şekilde sona erdi.  Bu durum 1 defa oluştu.  2000 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti yeniden başlat.

Error: (01/30/2015 05:06:58 PM) (Source: DCOM) (EventID: 10010) (User: IHOCAN)
Description: {AC746233-E9D3-49CD-862F-068F7B7CCCA4}

Error: (01/30/2015 03:22:59 PM) (Source: volsnap) (EventID: 36) (User: )
Description: Gölge kopya depolama ortamı kullanıcı tarafından tanımlanan bir sınır nedeniyle büyütülemediğinden C: biriminin gölge kopyaları durduruldu.

Error: (01/30/2015 01:52:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: 360 Total Security hizmeti beklenmeyen bir şekilde sonlandırıldı. Bu durum 1 defa oluştu.


Microsoft Office Sessions:
=========================
Error: (02/02/2015 01:00:44 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: explorer.exe6.3.9600.1728453f8130dunknown0.0.0.000000000c00000056f83993d238401d03e72e8b4d5acC:\Windows\SysWOW64\explorer.exeunknown2696fbe3-aa66-11e4-8294-8c89a50ef469

Error: (02/02/2015 00:49:27 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Users\ihsan\AppData\Local\Temp\Creative Cloud Uninstaller.exe

Error: (02/01/2015 08:08:20 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.3.9600.170312a7001d03e4956c2c1a54294967295C:\Windows\syswow64\wwahost.exe4aa0e109-aa3d-11e4-8294-8c89a50ef469Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5cApp

Error: (01/31/2015 05:05:47 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_a9efdb8b01377ea7.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9600.17031_none_6242a4b3ecbb55a1.manifestC:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\Creative Cloud Uninstaller.exe

Error: (01/31/2015 04:25:17 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Allok Video Converter v4.6.0529 Portable.exe1.0.2.000000031unknown0.0.0.000000000c0000005020895c122bc01d03cfd1f82c5f5C:\Users\ihsan\Desktop\downloads\Allok Video Converter v4.6.0529 + Portable\Allok Video Converter v4.6.0529 Portable.exeunknown64d3d730-a8f0-11e4-8294-8c89a50ef469

Error: (01/30/2015 01:52:23 PM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER)

Error: (01/30/2015 08:12:22 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: LiveComm.exe17.5.9600.20689d001d03c52fa76c6864294967295C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\LiveComm.exeee5d360d-a846-11e4-8293-8c89a50ef469microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbweppleae38af2e007f4358a809ac99a64a67c1

Error: (01/30/2015 06:39:11 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: IHOCAN)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927142

Error: (01/30/2015 06:39:11 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: IHOCAN)
Description: microsoft.windowscommunicationsapps_8wekyb3d8bbwe!ppleae38af2e007f4358a809ac99a64a67c1-2144927142

Error: (01/30/2015 04:38:59 AM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER)


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i7-4702MQ CPU @ 2.20GHz
Percentage of memory in use: 49%
Total physical RAM: 8113.17 MB
Available physical RAM: 4088.04 MB
Total Pagefile: 9792.29 MB
Available Pagefile: 3601.09 MB
Total Virtual: 131072 MB
Available Virtual: 131071.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:488.61 GB) (Free:258.37 GB) NTFS
Drive d: () (Fixed) (Total:442.38 GB) (Free:132.43 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 70873948)

Partition: GPT Partition Type.

==================== End Of Log ============================

  • 0

#9
bloopie

bloopie

    Trusted Helper

  • Malware Removal
  • 62 posts
Good work, and thanks for the logs!

Please allow me some time to analyze them and I will be back to you tomorrow with the next steps. :thumbup2:

Thanks for your patience and cooperation! It is much appreciated! :)

bloopie
  • 0

#10
bloopie

bloopie

    Trusted Helper

  • Malware Removal
  • 62 posts

Hello again,

Please do these steps next:

Step 1

Using more than one anti-virus program is not advisable. Why? The primary concern with doing so is due to Windows resource management and significant conflicts that can arise especially when they are running in real-time protection mode simultaneously. Even if one of them is disabled for use as a stand-alone on demand scanner, it can affect the other and cause conflicts. Anti-virus software components insert themselves deep into the operating systems core where they install kernel mode drivers that load at boot-up regardless of whether real-time protection is enabled or not. Thus, using multiple anti-virus solutions can result in kernel mode conflicts causing system instability, catastrophic crashes, slow performance and waste vital system resources. When actively running in the background while connected to the Internet, each anti-virus may try to update their definition databases at the same time. As the programs compete for resources required to download the necessary files this often can result in sluggish system performance or unresponsive behavior.

When scanning engines are initiated, each anti-virus may interpret the activity of the other as suspicious behavior and there is a greater chance of them alerting you to a "false positive". If one finds a virus or a suspicious file and then the other also finds the same, both programs will be competing over exclusive rights on dealing with that threat. Each anti-virus may attempt to remove the offending file and quarantine it at the same time resulting in a resource management issue as to which program gets permission to act first. If one anit-virus finds and quarantines the file before the other one does, then you may encounter the problem of both wanting to scan each other's zipped or archived files and each reporting the other's quarantined contents. This can lead to a repetitive cycle of endless alerts that continually warn you that a threat has been found after it has already been neutralized.

Anti-virus scanners use virus definitions to check for malware and these can include a fragment of the virus code which may be recognized by other anti-virus programs as the virus itself. Because of this, many anti-virus vendors encrypt their definitions so that they do not trigger a false alarm when scanned by other security programs. Other vendors do not encrypt their definitions and they can trigger false alarms when detected by the resident anti-virus. Further, dual installation is not always possible because most of the newer anti-virus programs will detect the presence of another and may insist that it be removed prior to installation. If the installation does complete with another anti-virus already installed, you may encounter issues like system freezing, unresponsiveness or similar symptoms as described above while trying to use it. In some cases, one of the anti-virus programs may even get disabled by the other.

To avoid these problems, use only one anti-virus solution. So please uninstall either Emsisoft Internet Security, or 360 Total Security.

==========

Step 2

 

Please download Malwarebytes Anti-Malware photo.jpg?sz=48 and save it to your desktop.

  • Double-click on the setup file (mbam-setup.exe), then click on Run to install.
  • Malwarebytes will automatically open to it's Dashboard. If you have never run this version, you should see a red note at the top indicating "A scan has never been run on your system"
     
    malwarebytes-anti-malware-fix-now.jpg
    .
  • Click on Update Now to download the current database definitions, then click the Scan Now >> button.
    .
  • If you have run this version before, you should see a green note at the top indicating "Your system is fully protected".
  • You will be prompted to update Malwarebytes...click on the Update Now button.
     
    malwarebytes-anti-malware-2-0-update-now
    .
  • The THREAT SCAN will automatically begin.
     
    malwarebytes-anti-malware-scan.jpg
    .
  • When the scan has completed, the results will be displayed. Click on Quarantine All, then click on Apply Actions.
     
    malwarebytes-anti-malware-potential-thre
    .
  • To complete any actions taken you will be prompted to restart your computer...click on Yes. Failure to reboot normally will prevent Malwarebytes from removing all the malware.
     
    mbam4_zps490948cc.png
    .
  • After rebooting the computer, copy and paste the mbam.log in your next reply.

.
To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 1)

  • Open Malwarebytes Anti-Malware.
  • Click the History Tab at the top and select Application Logs.
  • Select (check) the box next to Scan Log. Choose the most current scan.
  • Click the View button.
  • Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
  • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
  • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.

To retrieve the Malwarebytes Anti-Malware 2.0 scan log information (Method 2)

  • Open Malwarebytes Anti-Malware.
  • Click the Scan Tab at the top.
  • Click the View detailed log link on the right.
  • Click Copy to Clipboard at the bottom...come back to this thread, click Add Reply, then right-click and choose Paste.
  • Alternatively, you can click Export and save the log as a .txt file on your Desktop or another location.
  • Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.

Logs are named by the date of scan in the following format: mbam-log-yyyy-mm-dd and automatically saved to the following locations:
-- XP: C:\Documents and Settings\<Username>\Application Data\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd
-- Vista, Windows 7/8: C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\Logs\mbam-log-yyyy-mm-dd

 

 

==========

 

Please post the MBAM log in your next reply, and let me know how the machine is running now!

 

bloopie


  • 0

Advertisements


#11
ihocan

ihocan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts

Here is The Log, my computer is speed good on starting but my internet problems are same, and i discovered another issuse my computer alway open "automatic maintenance"
and i  want to request :)   would you recommend  which antivrus ?

 

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 2.2.2015
Scan Time: 22:01:11
Logfile: log.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.02.02.05
Rootkit Database: v2015.01.14.01
License: Trial
Malware Protection: Enabled
Malicious Website Protection: Enabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: ihsan

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 656913
Time Elapsed: 30 min, 44 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 1
PUP.Optional.OpenCandy, C:\Users\ihsan\AppData\Local\Temp\is-TTLST.tmp\OCSetupHlp.dll, Quarantined, [199459c07812191d06419e38689de11f], 

Physical Sectors: 0
(No malicious items detected)


(end)

  • 0

#12
bloopie

bloopie

    Trusted Helper

  • Malware Removal
  • 62 posts

Hello again,
 

would you recommend  which antivrus ?

I would most certainly recommend Emsisoft in your case. :happy:
 
Okay, now I'd like you to run this for me next:
 
Step 1

Please download AdwCleaner by Xplode and save to your Desktop.

  • Double click on AdwCleaner.exe to run the tool.
    Vista/Windows 7/8 users right-click and select Run As Administrator
  • The tool will start to update the database, please wait a bit.
  • Click on I agree button.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

==========

Please post the resultant log in your next reply, and let me know if anything in that list is something you'll need to keep! :)

bloopie


  • 0

#13
ihocan

ihocan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts

hello again , i already scanned my computer with this 4-5 days ago, and this time it dont find anything :)
here is my last scan log it scan time is 29.01.2015

# AdwCleaner v3.308 - Rapor olusturuldu 02/09/2014 tarihinde 13:21:47
# Guncellendi 20/08/2014 tarafindan Xplode
# Isletim sistemi : Windows 8.1 Pro  (64 bits)
# Kullanici adi : ihsan - IHOCAN
# Adwcleaner konumu : C:\Users\ihsan\Downloads\Programs\AdwCleaner.exe
# Tarama turu : Temizle

***** [ Servisler ] *****


***** [ Dosyalar / Klasorler ] *****

Klasor Silindi : C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\obciceimmggglbmelaidpjlmodcebijb
Dosya Silindi : C:\Users\ihsan\AppData\Roaming\Mozilla\Firefox\Profiles\kckxxqfq.default\user.js

***** [ Görevler ] *****


***** [ Kisayollar ] *****


***** [ Registry ] *****

Registry Key Silindi : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extension Compatibility\{74F475FA-6C75-43BD-AAB9-ECDA6184F600}

***** [ Tarayicilar ] *****

-\\ Internet Explorer v11.0.9600.17239


-\\ Mozilla Firefox v31.0 (x86 tr)

[ Dosya : C:\Users\ihsan\AppData\Roaming\Mozilla\Firefox\Profiles\kckxxqfq.default\prefs.js ]


-\\ Google Chrome v36.0.1985.143

[ Dosya : C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Silindi [Homepage] : hxxp://klit.startnow.com/?src=startpage&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=US&install_date=20120929&user_guid=3220074E5BF444FFABB0303EA47C4FB8&machine_id=67326ca3ae2301667ef9afd37f603db0&browser=CR&os=win&os_version=6.1-x86-SP0
Silindi [Extension] : obciceimmggglbmelaidpjlmodcebijb

*************************

AdwCleaner[R0].txt - [5567 octets] - [26/06/2014 09:24:45]
AdwCleaner[R1].txt - [1857 octets] - [02/09/2014 13:21:11]
AdwCleaner[S0].txt - [4233 octets] - [26/06/2014 09:26:14]
AdwCleaner[S1].txt - [1780 octets] - [02/09/2014 13:21:47]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [1840 octets] ##########
# AdwCleaner v3.309 - Rapor olusturuldu 03/09/2014 tarihinde 02:38:56
# Guncellendi 02/09/2014 tarafindan Xplode
# Isletim sistemi : Windows 8.1 Pro  (64 bits)
# Kullanici adi : ihsan - IHOCAN
# Adwcleaner konumu : C:\Users\ihsan\Downloads\Programs\AdwCleaner.exe
# Tarama turu : Temizle

***** [ Servisler ] *****


***** [ Dosyalar / Klasorler ] *****

Klasor Silindi : C:\ProgramData\~0
Klasor Silindi : C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\obciceimmggglbmelaidpjlmodcebijb
Dosya Silindi : C:\Users\ihsan\AppData\Roaming\Mozilla\Firefox\Profiles\kckxxqfq.default\user.js

***** [ Görevler ] *****


***** [ Kisayollar ] *****


***** [ Registry ] *****


***** [ Tarayicilar ] *****

-\\ Internet Explorer v11.0.9600.17239


-\\ Mozilla Firefox v31.0 (x86 tr)

[ Dosya : C:\Users\ihsan\AppData\Roaming\Mozilla\Firefox\Profiles\kckxxqfq.default\prefs.js ]


-\\ Google Chrome v36.0.1985.143

[ Dosya : C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\preferences ]

Silindi [Homepage] : hxxp://klit.startnow.com/?src=startpage&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=US&install_date=20120929&user_guid=3220074E5BF444FFABB0303EA47C4FB8&machine_id=67326ca3ae2301667ef9afd37f603db0&browser=CR&os=win&os_version=6.1-x86-SP0
Silindi [Extension] : obciceimmggglbmelaidpjlmodcebijb

*************************

AdwCleaner[R0].txt - [5567 octets] - [26/06/2014 09:24:45]
AdwCleaner[R1].txt - [3681 octets] - [03/09/2014 02:22:46]
AdwCleaner[S0].txt - [4233 octets] - [26/06/2014 09:26:14]
AdwCleaner[S1].txt - [3607 octets] - [02/09/2014 13:22:15]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [3667 octets] ##########
# AdwCleaner v4.109 - Rapor olusturuldu 29/01/2015 tarihinde 18:16:55
# Guncellendi 24/01/2015 tarafindan Xplode
# Database : 2015-01-26.1 [Live]
# Isletim sistemi : Windows 8.1 Pro  (64 bits)
# Kullanici adi : ihsan - IHOCAN
# Adwcleaner konumu : C:\Users\ihsan\Downloads\Programs\AdwCleaner.exe
# Tarama turu : Temizle

***** [ Servisler ] *****


***** [ Dosyalar / Klasorler ] *****

Klasor Silindi : C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpckgflgdapkpabemgkielbefdildaio
Dosya Silindi : C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\hxxps_static.olark.com_0.localstorage-journal

***** [ Görevler ] *****


***** [ Kisayollar ] *****


***** [ Registry ] *****

Deger Silindi : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [[email protected]]
Registry Key Silindi : HKLM\SOFTWARE\Classes\AppID\IEPlugin.DLL

***** [ Tarayicilar ] *****

-\\ Internet Explorer v11.0.9600.17416


-\\ Mozilla Firefox v34.0.5 (x86 tr)


-\\ Google Chrome v40.0.2214.45

[C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Silindi [Search Provider] : hxxp://search.qvo6.com/web/?utm_source=b&utm_medium=newgdp&from=newgdp&uid=MAXTORXSTM3250310AS_6RYEYT0HXXXX6RYEYT0H&ts=4325441
[C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Silindi [Search Provider] : hxxp://www.awesomehp.com/web/?type=ds&ts=1392667369&from=tugs&uid=WDCXWD10JPVX-22JC3T0_WD-WXD1E63VNEH7VNEH7&q={searchTerms}
[C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Silindi [Search Provider] : hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^HJ^xdm169^YY^tr&si=pconverter&ptb=9B80911B-F2CD-4F19-A7A2-F25F95E77842&ind=2012123014&n=77ee8f86&psa=&st=sb&searchfor={searchTerms}
[C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Silindi [Search Provider] : hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?p2=^HJ^xdm169^YY^tr&si=pconverter&ptb=9B80911B-F2CD-4F19-A7A2-F25F95E77842&ind=2012123014&n=77ee8f86&psa=&st=sb&searchfor={searchTerms}
[C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Silindi [Search Provider] : hxxp://websearch.ask.com/custom/java/redirect?client=ie&tb=ORJ&o=100000026&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000
[C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Silindi [Search Provider] : hxxp://websearch.ask.com/custom/java/redirect?client=ie&tb=ORJ&o=100000026&src=kw&q={searchTerms}&locale=&apn_ptnrs=U3&apn_dtid=OSJ000
[C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Silindi [Search Provider] : hxxp://en.softonic.com/s/{searchTerms}
[C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Web Data] - Silindi [Search Provider] : hxxp://vps:8090/dosearchsite.action?queryString={searchTerms}

*************************

AdwCleaner[R0].txt - [14418 octets] - [26/06/2014 08:24:45]
AdwCleaner[R1].txt - [6908 octets] - [03/09/2014 01:22:46]
AdwCleaner[S0].txt - [12880 octets] - [26/06/2014 08:26:14]
AdwCleaner[S1].txt - [6837 octets] - [03/09/2014 01:40:46]

########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [6897 octets] ##########


  • 0

#14
bloopie

bloopie

    Trusted Helper

  • Malware Removal
  • 62 posts

Hello again,
 
There's not too much in your logs that requires attention, but let's run this next fix with FRST and let me know how things are after:

We need to run a fix with FRST:

  • Please download the attached fixlist.txt file and save it to the same location as FRST
    Note: It's important that both files, FRST.exe/FRST64.exe and fixlist.txt are in the same location or the fix will not work
    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
    Attached File  fixlist.txt   2.22KB   99 downloads
  • Run FRST.exe/FRST64.exe and press the Fix button just once and wait
  • If for some reason the tool needs a restart, please make sure you let the system restart normally, then let the tool complete its run
  • When finished, FRST will generate a log (Fixlog.txt) in the same location the tool was run, please post it to your reply

==========

Please post the resultant log and let me know how things are running after! In addition to this, please post a fresh FRST.txt for my review (please do not use any codeboxes or quotes, just simply copy and paste all logs into the post).

Note: this fix will induce a system reboot

 

Thanks,

bloopie


  • 0

#15
ihocan

ihocan

    Member

  • Topic Starter
  • Member
  • PipPip
  • 17 posts

hello 
fixlog
 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 04-02-2015 01
Ran by ihsan at 2015-02-05 11:30:40 Run:1
Running from C:\Users\ihsan\Desktop
Loaded Profiles: ihsan & MsDtsServer110 & MSSQLServerOLAPService & ReportServer & MSSQLFDLauncher (Available profiles: ihsan & MsDtsServer110 & MSSQLServerOLAPService & ReportServer & MSSQLFDLauncher & MSSQLSERVER)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
URLSearchHook: [S-1-5-80-1770670200-1234090253-3451813168-4041049723-2370973757] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-2885764129-887777008-271615777-1616004480-2722851051] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-1770670200-1234090253-3451813168-4041049723-2370973757 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-2885764129-887777008-271615777-1616004480-2722851051 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0
Tcpip\..\Interfaces\{78FA00C6-2245-43D4-9A83-7FED19DE07AA}: [NameServer] 8.8.8.8,8.8.4.8
CHR HomePage: Default -> hxxp://klit.startnow.com/?src=startpage&provider=&provider_name=yahoo&provider_code=&partner_id=693&product_id=741&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.4.0&install_country=US&install_date=20120929&user_guid=3220074E5BF444FFABB0303EA47C4FB8&machine_id=67326ca3ae2301667ef9afd37f603db0&browser=CR&os=win&os_version=6.1-x86-SP0
AlternateDataStreams: C:\ProgramData\TEMP:A303874F
AlternateDataStreams: C:\ProgramData\TEMP:AEC0AC81
Hosts:
EmptyTemp:
*****************

Error setting Default URLSearchHook.
Error setting Default URLSearchHook.
Error setting Default URLSearchHook.
Error setting Default URLSearchHook.
Error setting Default URLSearchHook.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-80-1770670200-1234090253-3451813168-4041049723-2370973757\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-80-2885764129-887777008-271615777-1616004480-2722851051\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value not found.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\\DhcpNameServer => value deleted successfully.
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{78FA00C6-2245-43D4-9A83-7FED19DE07AA}\\NameServer => value deleted successfully.
Chrome HomePage deleted successfully.
C:\ProgramData\TEMP => ":A303874F" ADS removed successfully.
C:\ProgramData\TEMP => ":AEC0AC81" ADS removed successfully.
C:\Windows\System32\Drivers\etc\hosts => Moved successfully.
Hosts was reset successfully.
EmptyTemp: => Removed 895 MB temporary data.


The system needed a reboot. 

==== End of Fixlog 11:31:18 ====

FRST log

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-02-2015 01
Ran by ihsan (administrator) on IHOCAN on 05-02-2015 11:35:21
Running from C:\Users\ihsan\Desktop
Loaded Profiles: ihsan & MsDtsServer110 & MSSQLServerOLAPService & ReportServer & MSSQLFDLauncher & MSSQLSERVER (Available profiles: ihsan & MsDtsServer110 & MSSQLServerOLAPService & ReportServer & MSSQLFDLauncher & MSSQLSERVER)
Platform: Windows 8.1 Pro (X64) OS Language: Türkçe (Türkiye)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Internet Security\a2service.exe
() C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTDevMgr.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Atheros Communications, Inc.) C:\Program Files (x86)\Jumpstart\jswpbapi.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\110\DTS\Binn\MsDtsSrvr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSAS11.MSSQLSERVER\OLAP\bin\msmdsrv.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\vmms.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\fdhost.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_6.3.9600.17477_none_fa2b7d3b9b36c7b4\TiWorker.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Realtek Semiconductor Corporation) C:\Program Files (x86)\Realtek\Realtek Bluetooth\BTServer.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Users\ihsan\AppData\Local\NVIDIA\NvBackend\ApplicationOntology\NvOAWrapperCache.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe
(MSI) C:\Program Files (x86)\SCM\Radio Manager.exe
(MSI) C:\Program Files (x86)\SCM\SCM.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\VsHub\1.0.0.0\VsHub.exe
(Emsisoft GmbH) C:\Program Files (x86)\Emsisoft Internet Security\a2guard.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [BtServer] => C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTServer.exe [253952 2013-05-07] (Realtek Semiconductor Corporation)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2893104 2013-08-23] (ELAN Microelectronics Corp.)
HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [320360 2014-08-04] (Intel Corporation)
HKLM\...\Run: [Radio Manager] => C:\Program Files (x86)\SCM\Radio Manager.exe [406920 2013-09-26] (MSI)
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [408232 2013-09-26] (MSI)
HKLM\...\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2531472 2014-12-13] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13636824 2013-07-26] (Realtek Semiconductor)
HKLM\...\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM-x32\...\Run: [jswtrayutil] => C:\Program Files (x86)\Jumpstart\jswtrayutil.exe [528384 2008-09-26] (Atheros Communications, Inc.)
HKLM-x32\...\Run: [Sound Blaster Cinema] => C:\Program Files (x86)\Creative\Sound Blaster Cinema\Sound Blaster Cinema\SBCinema.exe [711680 2012-11-29] (Creative Technology Ltd)
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKLM-x32\...\Run: [OmniPage Preload] => C:\Program Files (x86)\Nuance\OmniPage19\OmniPage19.exe [2922824 2013-04-22] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [Nuance OmniPage Ultimate-reminder] => C:\Program Files (x86)\Nuance\OmniPage19\Ereg\Ereg.exe [334152 2013-01-14] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [VsHub.exe] => C:\Program Files (x86)\Common Files\Microsoft Shared\VsHub\1.0.0.0\vshub.exe [141440 2014-11-10] (Microsoft Corporation)
HKLM-x32\...\Run: [emsisoft anti-malware] => c:\program files (x86)\emsisoft internet security\a2guard.exe [4997872 2014-12-31] (Emsisoft GmbH)
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7404312 2015-01-20] (Piriform Ltd)
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Run: [IDMan] => C:\Program Files (x86)\Internet Download Manager\IDMan.exe [3878480 2014-09-03] (Tonec Inc.)
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [174856 2014-11-04] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156840 2014-11-04] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [IDM Shell Extension] -> {CDC95B92-E27C-4745-A8C5-64A52A78855D} => C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (Tonec Inc.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

URLSearchHook: [S-1-5-80-1770670200-1234090253-3451813168-4041049723-2370973757] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-2872255330-672591203-888807865-2791174282-1554802921] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-2885764129-887777008-271615777-1616004480-2722851051] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-3263513310-3392720605-1798839546-683002060-3227631582] ATTENTION ==> Default URLSearchHook is missing.
URLSearchHook: [S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003] ATTENTION ==> Default URLSearchHook is missing.
SearchScopes: HKU\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_25\bin\ssv.dll (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_25\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll (Microsoft Corporation)
BHO-x32: PDF Architect Helper -> {691B33B0-B86E-47F3-81C7-56E4FE3B929C} -> C:\Program Files (x86)\PDF Architect 2\creator-ie-helper.dll (pdfforge GmbH)
BHO-x32: Microsoft Web Test Recorder 10.0 Helper -> {876d9f09-c6d6-4324-a2cc-04dd9a4de12f} -> C:\Program Files (x86)\Microsoft Visual Studio 11.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Microsoft Web Test Recorder 14.0 Helper -> {b924f0b4-0b3c-49c0-bab2-213fb9ebd1d3} -> C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\PrivateAssemblies\Microsoft.VisualStudio.QualityTools.RecorderBarBHO100.dll (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL (Microsoft Corporation)
Toolbar: HKLM-x32 - PDF Architect Toolbar - {DEEB13D7-CEA9-45FB-B77C-E039BEC85221} - C:\Program Files (x86)\PDF Architect 2\creator-ie-plugin.dll (pdfforge GmbH)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 0.0.0.0

FireFox:
========
FF ProfilePath: C:\Users\ihsan\AppData\Roaming\Mozilla\Firefox\Profiles\kg35b0ue.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll ()
FF Plugin: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files\Java\jre1.8.0_25\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~4\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll ()
FF Plugin-x32: @huawei.com/npHWPlugin -> C:\Program Files (x86)\Web_TV\WebTVPlugin\npHWPlugin.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MIF5BA~1\Office15\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: PDF Architect 2 -> C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH)
FF Plugin HKU\S-1-5-21-3051402733-4133393625-984315149-1001: @acestream.net/acestreamplugin,version=3.0.5 -> C:\Users\ihsan\AppData\Roaming\ACEStream\player\npace_plugin.dll (Innovative Digital Technologies)
FF Plugin HKU\S-1-5-21-3051402733-4133393625-984315149-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\ihsan\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-3051402733-4133393625-984315149-1001: ubisoft.com/uplaypc -> C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll (Microsoft Corporation)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yandex-tr.xml
FF Extension: AS Magic Player - C:\Users\ihsan\AppData\Roaming\Mozilla\Firefox\Profiles\kg35b0ue.default\Extensions\[email protected] [2015-01-08]
FF Extension: User Agent Switcher - C:\Users\ihsan\AppData\Roaming\Mozilla\Firefox\Profiles\kg35b0ue.default\Extensions\{e968fc70-8f95-4ab9-9e79-304de2a71ee1}.xpi [2015-01-15]
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension
FF Extension: PDF Architect 2 Creator - C:\Program Files (x86)\PDF Architect 2\resources\pdfarchitect2firefoxextension [2014-10-18]
FF HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\Firefox\Extensions: [[email protected]] - C:\Users\ihsan\AppData\Roaming\IDM\idmmzcc5
FF Extension: IDM CC - C:\Users\ihsan\AppData\Roaming\IDM\idmmzcc5 [2014-09-28]
FF HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\SeaMonkey\Extensions: [[email protected]] - C:\Users\ihsan\AppData\Roaming\IDM\idmmzcc5

Chrome: 
=======
CHR StartupUrls: Default -> "https://www.google.com.tr/"
CHR DefaultSearchKeyword: Default -> google.com.trhttps://www.google.com.tr/preferences?hl=tr
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Profile: C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (From Dust) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\anelkojiepicmcldgnmkplocifmegpfj [2014-12-28]
CHR Extension: (Google Drive) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-12-28]
CHR Extension: (Manga Viewer) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bebalkdfejapnfbngpmhchkboajaofen [2014-12-28]
CHR Extension: (Adguard AdBlocker) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgnkhhnnamicmpeenaelnjfhikgbkllg [2014-12-29]
CHR Extension: (MEGA) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bigefpfhnfcobdlfbedofhhaibnlghod [2014-12-28]
CHR Extension: (Adblock Plus) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-12-28]
CHR Extension: (Pushbullet) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\chlffgpmiacpedhhbkiomidkjlcfhogd [2015-01-10]
CHR Extension: (Google Apps Script) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoieeedlomnegifmaghhjnghhmcldobl [2014-12-28]
CHR Extension: (+ Flip It) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbmppankahdodchhioklnbcmohehhjoa [2014-12-28]
CHR Extension: (ZenMate Security & Privacy VPN) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdcgdnkidjaadafnichfpabhfomcebme [2014-12-28]
CHR Extension: (Office Belgeleri Düzenleme) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbkeegbaiigmenfmjfclcdgdpimamgkj [2014-12-28]
CHR Extension: (Quick Javascript Switcher) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\geddoclleiomckbhadiaipdggiiccfje [2014-12-28]
CHR Extension: (Orta Dünya'da Bir Yolculuk) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjgkjeheegjnnmheaflhdocglkiegoni [2014-12-28]
CHR Extension: (360 İnternet Koruması) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\glcimepnljoholdmjchkloafkggfoijh [2014-12-28]
CHR Extension: (Bookmark Manager) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2014-12-29]
CHR Extension: (Tureng Dictionary) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihedienojfhdahpomfldoejaimefofff [2014-12-28]
CHR Extension: (Streamus™) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jbnkffmindojffecdhbbmekbmkkfpmjd [2014-12-28]
CHR Extension: (IDM Integration Module) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jeaohhlajejodfjadcponpnjgkiikocn [2014-12-28]
CHR Extension: (Chrome extension source viewer) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\jifpbeccnghkjeaalbbjmodiffmgedin [2014-12-28]
CHR Extension: (Google Inbox Checker (Inbox by Gmail)) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\llldafpkkdiljghncbdnkgfinfiifnig [2014-12-28]
CHR Extension: (Google Mail Checker) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff [2014-12-28]
CHR Extension: (Google Cüzdan) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-28]
CHR Extension: (Chrome Apps & Extensions Developer Tool) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohmmkhmmmpcnpikjeljgnaoabkaalbgc [2014-12-28]
CHR Extension: (Gmail) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-12-28]
CHR Extension: (Chrome Dev Editor (developer preview)) - C:\Users\ihsan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnoffddplpippgcfjdhbmhkofpnaalpg [2014-12-28]
CHR HKLM\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2014-09-12]
CHR HKLM-x32\...\Chrome\Extension: [jeaohhlajejodfjadcponpnjgkiikocn] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx [2014-09-12]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 a2AntiMalware; C:\Program Files (x86)\Emsisoft Internet Security\a2service.exe [4920104 2014-12-31] (Emsisoft GmbH)
R2 BTDevManager; C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe [56832 2013-08-28] () [File not signed]
S3 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
S3 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [5632 2014-12-23] (Microsoft Corporation)
S3 EasyAntiCheat; C:\Windows\SysWOW64\EasyAntiCheat.exe [174624 2015-01-19] (EasyAntiCheat Ltd)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [99632 2013-08-23] (ELAN Microelectronics Corp.)
S3 fussvc; C:\Program Files (x86)\Windows Kits\8.1\App Certification Kit\fussvc.exe [142336 2014-02-20] (Microsoft Corporation) [File not signed]
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2014-12-13] (NVIDIA Corporation)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [16232 2014-08-04] (Intel Corporation)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [282096 2014-03-12] (Intel Corporation)
R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [733696 2013-05-11] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [822232 2013-05-11] (Intel(R) Corporation)
R2 IpOverUsbSvc; C:\Program Files (x86)\Common Files\Microsoft Shared\Phone Tools\CoreCon\11.0\bin\IpOverUsbSvc.exe [22744 2014-10-15] (Microsoft Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-08-08] (Intel Corporation)
R2 jswpbapi; C:\Program Files (x86)\Jumpstart\jswpbapi.exe [265216 2008-09-26] (Atheros Communications, Inc.) [File not signed]
S3 jswpsapi; C:\Program Files (x86)\Jumpstart\jswpsapi.exe [954368 2008-09-26] (Atheros Communications, Inc.) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation)
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2013-09-26] (Micro-Star International Co., Ltd.) [File not signed]
R2 MsDtsServer110; C:\Program Files\Microsoft SQL Server\110\DTS\Binn\MsDtsSrvr.exe [218200 2012-02-11] (Microsoft Corporation)
R3 MSSQLFDLauncher; C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe [49752 2012-02-11] (Microsoft Corporation)
R2 MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [191064 2012-02-11] (Microsoft Corporation)
R2 MSSQLServerOLAPService; C:\Program Files\Microsoft SQL Server\MSAS11.MSSQLSERVER\OLAP\bin\msmdsrv.exe [61538904 2012-02-11] (Microsoft Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1701520 2014-12-13] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19823248 2014-12-13] (NVIDIA Corporation)
S3 Origin Client Service; C:\Program Files (x86)\Origin\OriginClientService.exe [1910128 2015-01-28] (Electronic Arts)
S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1771560 2014-10-10] (pdfforge GmbH)
S4 PDF Architect 2 Creator; C:\Program Files (x86)\PDF Architect 2\creator-ws.exe [738856 2014-10-10] (pdfforge GmbH)
S4 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-10-10] (pdfforge GmbH)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-11-16] ()
R2 ReportServer; C:\Program Files\Microsoft SQL Server\MSRS11.MSSQLSERVER\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2348632 2012-02-11] (Microsoft Corporation)
S3 SQL Server Distributed Replay Client; C:\Program Files (x86)\Microsoft SQL Server\110\Tools\DReplayClient\DReplayClient.exe [137304 2012-02-11] (Microsoft Corporation)
S3 SQL Server Distributed Replay Controller; C:\Program Files (x86)\Microsoft SQL Server\110\Tools\DReplayController\DReplayController.exe [342104 2012-02-11] (Microsoft Corporation)
S3 SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL11.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [597080 2012-02-11] (Microsoft Corporation)
S3 Te.Service; C:\Program Files (x86)\Windows Kits\8.1\Testing\Runtimes\TAEF\Wex.Services.exe [119808 2013-08-22] (Microsoft Corporation) [File not signed]
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5426448 2014-12-15] (TeamViewer GmbH)
R2 vmms; C:\Windows\system32\vmms.exe [13401600 2014-12-23] (Microsoft Corporation)
S3 VsEtwService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\Packages\Debugger\Services\VsEtwService.exe [89240 2014-11-10] (Microsoft Corporation)
S3 VSStandardCollectorService140; C:\Program Files (x86)\Microsoft Visual Studio 14.0\Team Tools\DiagnosticsHub\Collector\StandardCollector.Service.exe [147664 2014-11-10] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R3 a2acc; C:\PROGRAM FILES (X86)\EMSISOFT INTERNET SECURITY\a2accx64.sys [71472 2014-05-12] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files (x86)\Emsisoft Internet Security\a2ddax64.sys [26176 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files (x86)\Emsisoft Internet Security\a2dix64.sys [45208 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files (x86)\Emsisoft Internet Security\a2util64.sys [23088 2014-05-12] (Emsisoft GmbH)
S3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation)
R3 cleanhlp; C:\Program Files (x86)\Emsisoft Internet Security\cleanhlp64.sys [57024 2013-12-04] (Emsisoft GmbH)
S3 DIRECTIO; C:\Program Files\PerformanceTest\DirectIo64.sys [31160 2014-04-24] ()
R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [283064 2014-10-30] (Disc Soft Ltd)
R3 fwndis; C:\Windows\system32\DRIVERS\fwndis64.sys [491632 2015-01-01] ()
R1 fwwfp; C:\Program Files (x86)\Emsisoft Internet Security\fwwfp764.sys [414936 2015-01-01] ()
S3 hid7906; C:\Windows\SysWOW64\drivers\hid7906.sys [34963 2007-12-12] (Compuware Corporation) [File not signed]
S3 hid8101; C:\Windows\SysWOW64\drivers\hid8101.sys [37024 2007-12-03] (Compuware Corporation) [File not signed]
S3 hid8103; C:\Windows\SysWOW64\drivers\hid8103.sys [34587 2007-11-28] (Compuware Corporation) [File not signed]
R1 hvservice; C:\Windows\System32\drivers\hvservice.sys [68960 2014-12-23] (Microsoft Corporation)
S3 lunparser; C:\Windows\System32\drivers\lunparser.sys [19456 2014-12-23] (Microsoft Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-11-21] (Malwarebytes Corporation)
R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [129752 2015-02-05] (Malwarebytes Corporation)
R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [64216 2014-11-21] (Malwarebytes Corporation)
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [99288 2013-08-08] (Intel Corporation)
S3 NPF; C:\Windows\System32\drivers\NPF.sys [36600 2013-03-01] (Riverbed Technology, Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2014-12-13] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 passthruparser; C:\Windows\System32\drivers\passthruparser.sys [22016 2014-12-23] (Microsoft Corporation)
S3 pvhdparser; C:\Windows\System32\drivers\pvhdparser.sys [27136 2014-12-23] (Microsoft Corporation)
S4 RsFx0200; C:\Windows\System32\DRIVERS\RsFx0200.sys [334936 2012-02-11] (Microsoft Corporation)
R3 RtkBtFilter; C:\Windows\system32\DRIVERS\RtkBtfilter.sys [547032 2013-07-04] (Realtek Semiconductor Corporation)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [2944216 2013-08-21] (Realtek Semiconductor Corporation                           )
R3 SensorsSimulatorDriver; C:\Windows\system32\DRIVERS\WUDFRd.sys [227840 2014-05-31] (Microsoft Corporation)
S3 vhdparser; C:\Windows\System32\drivers\vhdparser.sys [18944 2014-12-23] (Microsoft Corporation)
R3 VMSMP; C:\Windows\system32\DRIVERS\vmswitch.sys [690688 2014-08-26] (Microsoft Corporation)
S3 VMSP; C:\Windows\system32\DRIVERS\vmswitch.sys [690688 2014-08-26] (Microsoft Corporation)
S3 VMSVSF; C:\Windows\system32\DRIVERS\vmswitch.sys [690688 2014-08-26] (Microsoft Corporation)
S3 VMSVSP; C:\Windows\system32\DRIVERS\vmswitch.sys [690688 2014-08-26] (Microsoft Corporation)
S3 VSPerfDrv110; C:\Program Files (x86)\Microsoft Visual Studio 11.0\Team Tools\Performance Tools\x64\VSPerfDrv110.sys [70264 2012-07-13] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation)
S1 BAPIDRV; system32\DRIVERS\BAPIDRV64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-05 11:35 - 2015-02-05 11:35 - 00031553 _____ () C:\Users\ihsan\Desktop\FRST.txt
2015-02-05 11:27 - 2015-02-05 11:27 - 00002273 _____ () C:\Users\ihsan\Downloads\fixlist.txt
2015-02-05 11:26 - 2015-02-05 11:26 - 02131968 _____ (Farbar) C:\Users\ihsan\Desktop\FRST64.exe
2015-02-05 11:26 - 2015-02-05 11:26 - 00000000 ____D () C:\Users\ihsan\Desktop\FRST-OlderVersion
2015-02-04 13:05 - 2015-02-04 13:05 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\3909
2015-02-04 13:04 - 2015-02-04 13:04 - 00564886 _____ () C:\Users\ihsan\Downloads\tr.zip
2015-02-04 13:03 - 2015-02-04 13:03 - 00001970 _____ () C:\Users\ihsan\Desktop\Papers Please.lnk
2015-02-04 13:03 - 2015-02-04 13:03 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Papers Please
2015-02-04 13:03 - 2015-02-04 13:03 - 00000000 ____D () C:\Program Files (x86)\Papers Please
2015-02-04 12:07 - 2015-02-04 12:07 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Verimatrix
2015-02-04 12:07 - 2015-02-04 12:07 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\HWPlugin
2015-02-04 12:07 - 2015-02-04 12:07 - 00000000 ____D () C:\Program Files (x86)\Web_TV
2015-02-04 00:50 - 2015-02-04 00:50 - 10598910 _____ () C:\Users\ihsan\Downloads\TYTWOMTYV100.rar
2015-02-04 00:43 - 2015-02-04 00:43 - 00001296 _____ () C:\Users\ihsan\Desktop\This War of Mine.lnk
2015-02-04 00:43 - 2015-02-04 00:43 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\This War of Mine
2015-02-04 00:43 - 2015-02-04 00:43 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\R.G. Mechanics
2015-02-04 00:42 - 2015-02-04 00:42 - 00000000 ____D () C:\Program Files (x86)\R.G. Mechanics
2015-02-04 00:41 - 2014-12-12 11:10 - 00023752 _____ (360安全中心) C:\Windows\SysWOW64\Drivers\efimon.sys
2015-02-04 00:28 - 2015-02-04 00:28 - 02194432 _____ () C:\Users\ihsan\Downloads\adwcleaner_4.109.exe
2015-02-02 22:00 - 2015-02-05 11:34 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2015-02-02 21:59 - 2015-02-02 21:59 - 00001114 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-02-02 21:59 - 2015-02-02 21:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
2015-02-02 21:59 - 2015-02-02 21:59 - 00000000 ____D () C:\ProgramData\Malwarebytes
2015-02-02 21:59 - 2015-02-02 21:59 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2015-02-02 21:59 - 2014-11-21 06:23 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2015-02-02 21:59 - 2014-11-21 06:23 - 00064216 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2015-02-02 21:59 - 2014-11-21 06:23 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2015-02-02 15:00 - 2015-02-02 15:00 - 27111830 _____ (Insecure.org) C:\Users\ihsan\Downloads\nmap-6.47-setup.exe
2015-02-02 01:10 - 2015-02-02 01:10 - 00052048 _____ () C:\Users\ihsan\Downloads\Addition.txt
2015-02-01 23:43 - 2015-02-02 01:11 - 00059697 _____ () C:\Users\ihsan\Downloads\FRST.txt
2015-02-01 23:42 - 2015-02-05 11:35 - 00000000 ____D () C:\FRST
2015-02-01 23:41 - 2015-02-01 23:41 - 02131456 _____ (Farbar) C:\Users\ihsan\Downloads\FRST64.exe
2015-02-01 23:08 - 2015-02-01 23:14 - 00205616 _____ () C:\Users\ihsan\Desktop\Extras.Txt
2015-02-01 23:07 - 2015-02-01 23:13 - 00185112 _____ () C:\Users\ihsan\Desktop\OTL.Txt
2015-02-01 22:55 - 2015-02-01 22:55 - 00602112 _____ (OldTimer Tools) C:\Users\ihsan\Downloads\OTL.exe
2015-02-01 22:55 - 2015-02-01 22:55 - 00602112 _____ (OldTimer Tools) C:\Users\ihsan\Desktop\OTL.exe
2015-02-01 22:51 - 2015-02-01 22:51 - 00468480 _____ () C:\Users\ihsan\Downloads\CKScanner.exe
2015-02-01 20:43 - 2015-02-01 20:43 - 05661717 _____ () C:\Users\ihsan\Downloads\chipset_intel_9.4.0.1026_0xb351380a_818700.zip
2015-02-01 20:43 - 2015-02-01 20:43 - 05661717 _____ () C:\Users\ihsan\Downloads\chipset_intel_9.4.0.1026_0xb351380a_818700 (2).zip
2015-02-01 20:43 - 2015-02-01 20:43 - 05661717 _____ () C:\Users\ihsan\Downloads\chipset_intel_9.4.0.1026_0xb351380a_818700 (1).zip
2015-02-01 20:28 - 2015-02-01 20:36 - 00013721 _____ () C:\Users\ihsan\Downloads\hijackthis.log
2015-02-01 20:27 - 2015-02-01 20:27 - 00388608 _____ (Trend Micro Inc.) C:\Users\ihsan\Downloads\HijackThis.exe
2015-01-31 09:00 - 2015-01-31 09:00 - 00030289 _____ () C:\Users\ihsan\Downloads\(336817)Edge_of_Tomorrow_23.976fps_1CD_Turkce_SubRip_DiVXPlanet.rar
2015-01-31 08:56 - 2015-01-31 08:56 - 00031049 _____ () C:\Users\ihsan\Downloads\(336078)Edge_of_Tomorrow_23.976fps_1CD_Turkce_SubRip_DiVXPlanet.rar
2015-01-31 08:42 - 2015-01-31 08:42 - 00034598 _____ () C:\Users\ihsan\Downloads\(328659)Noah_23.976fps_1CD_Turkce_SubRip_DiVXPlanet.rar
2015-01-31 04:30 - 2015-01-31 10:38 - 00000000 ____D () C:\OutputFolder
2015-01-31 04:27 - 2015-01-31 04:29 - 00000000 ____D () C:\Program Files (x86)\Allok Video Converter
2015-01-31 04:27 - 2015-01-31 04:27 - 00001085 _____ () C:\Users\Public\Desktop\Allok Video Converter.lnk
2015-01-31 04:27 - 2015-01-31 04:27 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Allok Video Converter
2015-01-31 04:27 - 2007-04-12 14:19 - 00129024 _____ () C:\Windows\SysWOW64\AVERM.dll
2015-01-31 04:27 - 2006-09-26 13:57 - 00028672 _____ () C:\Windows\SysWOW64\AVEQT.dll
2015-01-31 04:20 - 2015-01-31 04:20 - 00219648 _____ () C:\Users\ihsan\Downloads\scheduling-05.ppt
2015-01-31 04:00 - 2015-01-31 04:00 - 04882432 _____ () C:\Users\ihsan\Downloads\ch7.ppt
2015-01-31 03:59 - 2015-01-31 03:59 - 03999232 _____ () C:\Users\ihsan\Downloads\ch6.ppt
2015-01-31 03:38 - 2015-01-31 03:38 - 00038632 _____ () C:\Users\ihsan\Downloads\(324302)RoboCop_23.976fps_1CD_Turkce_SubRip_DiVXPlanet.rar
2015-01-31 00:59 - 2015-01-31 01:00 - 00424448 _____ () C:\Users\ihsan\Downloads\csc4320 Chapter 5-2.ppt
2015-01-31 00:48 - 2015-01-31 03:25 - 00000000 ____D () C:\Users\ihsan\Documents\Freemake
2015-01-31 00:48 - 2015-01-31 03:25 - 00000000 ____D () C:\ProgramData\Freemake
2015-01-31 00:48 - 2015-01-31 00:48 - 00001336 _____ () C:\Users\Public\Desktop\Freemake Video Converter.lnk
2015-01-31 00:48 - 2015-01-31 00:48 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Freemake
2015-01-31 00:48 - 2015-01-31 00:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freemake
2015-01-31 00:46 - 2015-01-31 00:48 - 00000000 ____D () C:\Program Files (x86)\Freemake
2015-01-31 00:14 - 2015-01-31 00:15 - 01270544 _____ (Ellora Assets Corporation ) C:\Users\ihsan\Downloads\FreemakeVideoConverterSetup.exe
2015-01-31 00:13 - 2015-01-31 00:13 - 00008844 _____ () C:\Users\ihsan\Downloads\Edge_of_Tomorrow_2014_720p.torrent
2015-01-31 00:08 - 2015-01-31 00:08 - 00010011 _____ () C:\Users\ihsan\Downloads\Noah_2014_720p.torrent
2015-01-31 00:08 - 2015-01-31 00:08 - 00009367 _____ () C:\Users\ihsan\Downloads\RoboCop_2014_720p.torrent
2015-01-30 21:50 - 2015-01-30 21:51 - 00850432 _____ () C:\Users\ihsan\Downloads\Scheduling.ppt
2015-01-30 05:07 - 2015-01-30 05:07 - 00000000 ____D () C:\Users\ihsan\Downloads\Video
2015-01-30 04:39 - 2015-02-05 11:35 - 00458010 _____ () C:\Windows\WindowsUpdate.log
2015-01-30 04:37 - 2015-02-05 11:32 - 00002960 _____ () C:\Windows\setupact.log
2015-01-30 04:37 - 2015-01-30 04:37 - 00000000 _____ () C:\Windows\setuperr.log
2015-01-30 04:36 - 2015-02-05 11:32 - 00004854 _____ () C:\Windows\PFRO.log
2015-01-30 04:34 - 2015-01-30 04:34 - 00000000 ____D () C:\ProgramData\Emsisoft
2015-01-30 04:10 - 2015-02-05 11:34 - 00044544 ___SH () C:\Users\ihsan\Desktop\Thumbs.db
2015-01-30 04:10 - 2015-01-30 04:10 - 00001138 _____ () C:\Users\Public\Desktop\Emsisoft Internet Security.lnk
2015-01-30 04:10 - 2015-01-30 04:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Internet Security
2015-01-30 04:09 - 2015-02-05 11:34 - 00000000 ____D () C:\Program Files (x86)\Emsisoft Internet Security
2015-01-30 04:09 - 2015-01-01 21:36 - 00491632 _____ () C:\Windows\system32\Drivers\fwndis64.sys
2015-01-30 03:30 - 2015-01-30 03:45 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Wise Registry Cleaner
2015-01-30 03:29 - 2011-07-31 15:14 - 00076565 _____ (RaProducts.org) C:\Users\ihsan\Desktop\PureRa.exe
2015-01-30 03:25 - 2015-01-30 03:25 - 00002772 _____ () C:\Windows\System32\Tasks\CCleanerSkipUAC
2015-01-30 03:25 - 2015-01-30 03:25 - 00000834 _____ () C:\Users\Public\Desktop\CCleaner.lnk
2015-01-30 03:25 - 2015-01-30 03:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
2015-01-30 03:25 - 2015-01-30 03:25 - 00000000 ____D () C:\Program Files\CCleaner
2015-01-30 03:05 - 2015-01-30 03:05 - 00000196 _____ () C:\Users\ihsan\Desktop\ksifre.rar
2015-01-30 03:02 - 2015-01-30 03:11 - 00000000 ____D () C:\Users\ihsan\Desktop\hellsing altyazı
2015-01-30 02:33 - 2015-01-30 02:33 - 00000000 ____D () C:\Users\ihsan\AppData\Local\VS Revo Group
2015-01-30 02:32 - 2015-01-30 02:32 - 00000000 ____D () C:\ProgramData\VS Revo Group
2015-01-30 02:32 - 2015-01-30 02:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2015-01-30 02:32 - 2015-01-30 02:32 - 00000000 ____D () C:\Program Files\VS Revo Group
2015-01-30 02:32 - 2009-12-30 10:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2015-01-29 00:46 - 2015-01-29 05:20 - 00000000 ____D () C:\Users\ihsan\Documents\GenTool
2015-01-28 22:53 - 2015-01-29 03:11 - 00000000 ____D () C:\Users\ihsan\Documents\Command and Conquer Generals Zero Hour Data
2015-01-28 22:53 - 2015-01-29 03:11 - 00000000 ____D () C:\Users\ihsan\Documents\Command and Conquer Generals Data
2015-01-28 22:53 - 2015-01-28 22:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Command and Conquer Generals and Zero Hour
2015-01-26 02:10 - 2015-01-26 02:10 - 00000000 ____D () C:\data_from_forms
2015-01-26 02:09 - 2015-01-26 02:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ETS
2015-01-26 02:09 - 2015-01-26 02:09 - 00000000 ____D () C:\Program Files (x86)\ETS
2015-01-26 02:06 - 2015-01-26 02:06 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Downloaded Installations
2015-01-20 02:29 - 2015-01-20 02:30 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Sublight
2015-01-20 02:29 - 2015-01-20 02:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sublight
2015-01-20 02:29 - 2015-01-20 02:29 - 00000000 ____D () C:\Program Files\Sublight
2015-01-19 14:52 - 2015-01-19 02:17 - 00174624 _____ (EasyAntiCheat Ltd) C:\Windows\SysWOW64\EasyAntiCheat.exe
2015-01-19 01:57 - 2014-11-22 12:46 - 00038032 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2015-01-19 01:57 - 2014-11-22 12:46 - 00032400 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2015-01-19 00:42 - 2015-01-19 00:42 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Command and Conquer Red Alert 2
2015-01-18 23:21 - 2015-01-28 22:51 - 00000000 ____D () C:\Program Files (x86)\Origin Games
2015-01-18 23:04 - 2015-01-28 22:46 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Origin
2015-01-18 23:04 - 2015-01-18 23:28 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Origin
2015-01-18 17:50 - 2015-01-20 02:40 - 00121105 _____ () C:\Users\ihsan\Desktop\pk altyazı.srt
2015-01-18 17:36 - 2015-01-18 17:36 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\URUSoft
2015-01-18 17:36 - 2015-01-18 17:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\URUSoft
2015-01-18 17:36 - 2015-01-18 17:36 - 00000000 ____D () C:\Program Files (x86)\URUSoft
2015-01-18 14:55 - 2013-07-09 07:58 - 00263896 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RtsUStor.sys
2015-01-18 14:55 - 2013-04-25 12:12 - 09889352 _____ (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtsUStoricon.dll
2015-01-16 00:10 - 2015-01-30 03:30 - 00000000 ____D () C:\Users\ihsan\Desktop\işletimsistemleri
2015-01-14 17:16 - 2014-12-19 08:26 - 00140800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys
2015-01-14 17:16 - 2014-12-12 04:04 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe
2015-01-14 17:16 - 2014-12-12 02:51 - 00075776 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ahcache.sys
2015-01-14 17:16 - 2014-12-09 03:50 - 00225280 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00535640 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00531616 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00448792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00413248 _____ (Microsoft Corporation) C:\Windows\system32\Faultrep.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00372408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Faultrep.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00108944 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2015-01-14 17:16 - 2014-12-08 21:42 - 00038264 _____ (Microsoft Corporation) C:\Windows\system32\WerFaultSecure.exe
2015-01-14 17:16 - 2014-12-08 21:42 - 00033584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFaultSecure.exe
2015-01-14 17:16 - 2014-12-06 05:17 - 00360448 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll
2015-01-14 17:16 - 2014-12-06 03:41 - 00391680 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll
2015-01-14 17:16 - 2014-12-06 03:35 - 00229888 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll
2015-01-14 17:16 - 2014-10-29 06:00 - 00465320 _____ (Microsoft Corporation) C:\Windows\system32\WerFault.exe
2015-01-14 17:16 - 2014-10-29 06:00 - 00139984 _____ (Microsoft Corporation) C:\Windows\system32\wermgr.exe
2015-01-14 17:16 - 2014-10-29 05:52 - 00500016 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2015-01-14 17:16 - 2014-10-29 05:52 - 00482872 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2015-01-14 17:16 - 2014-10-29 05:52 - 00394120 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2015-01-14 17:16 - 2014-10-29 05:52 - 00272248 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2015-01-14 17:16 - 2014-10-29 05:12 - 00413136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WerFault.exe
2015-01-14 17:16 - 2014-10-29 05:12 - 00136296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wermgr.exe
2015-01-14 17:16 - 2014-10-29 05:07 - 00424544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2015-01-14 17:16 - 2014-10-29 05:07 - 00370424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2015-01-14 17:16 - 2014-10-29 05:07 - 00344536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2015-01-14 17:16 - 2014-10-29 04:44 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\werdiagcontroller.dll
2015-01-14 17:16 - 2014-10-29 03:59 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\werdiagcontroller.dll
2015-01-14 17:16 - 2014-10-29 03:24 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll
2015-01-14 17:16 - 2014-10-29 03:02 - 00911360 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2015-01-14 17:16 - 2014-10-29 03:01 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nlaapi.dll
2015-01-12 21:40 - 2015-01-12 21:40 - 00000000 ____D () C:\Users\ihsan\Documents\Red Alert 3
2015-01-12 21:34 - 2015-01-12 21:34 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Red Alert 3
2015-01-12 18:08 - 2015-01-12 18:08 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Aegisub
2015-01-12 09:33 - 2015-01-12 09:39 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Dev-Cpp
2015-01-12 09:32 - 2015-01-12 09:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bloodshed Dev-C++
2015-01-12 09:32 - 2015-01-12 09:32 - 00000000 ____D () C:\Dev-Cpp
2015-01-09 21:10 - 2015-01-09 21:12 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Bioshock2Steam
2015-01-09 21:10 - 2015-01-09 21:10 - 00000000 ____D () C:\Users\ihsan\Documents\Bioshock2
2015-01-09 20:38 - 2015-01-09 21:09 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Bioshock
2015-01-09 20:38 - 2015-01-09 20:54 - 00000000 ____D () C:\Users\ihsan\Documents\Bioshock
2015-01-09 20:38 - 2015-01-09 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bioshock Türkçe
2015-01-09 13:44 - 2015-02-05 11:18 - 00000814 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-01-09 13:44 - 2015-02-04 21:19 - 00003702 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2015-01-08 20:33 - 2015-01-08 20:33 - 00036577 _____ () C:\Users\ihsan\Desktop\[kickass.so]cbm.hellsing.ultimate.1.10.complete.dual.audio.bdrip.720p.8bit.torrent
2015-01-08 20:32 - 2015-01-14 21:12 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\vlc
2015-01-08 20:08 - 2015-01-08 20:08 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ace Stream Media
2015-01-08 17:59 - 2015-01-08 17:59 - 00038519 _____ () C:\Users\ihsan\Desktop\Hellsing Ultimate OVA 01-10.torrent
2015-01-07 17:12 - 2015-01-07 17:12 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\1C5070DB.sys
2015-01-06 02:42 - 2015-01-06 02:42 - 00000000 ____D () C:\Users\ihsan\Desktop\This War Of Mine

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2015-02-05 11:34 - 2014-09-28 15:06 - 00041772 _____ () C:\Users\ihsan\AppData\Local\BTServer.log
2015-02-05 11:34 - 2014-09-28 12:52 - 00000000 __RDO () C:\Users\ihsan\SkyDrive
2015-02-05 11:32 - 2014-12-23 16:49 - 27590656 _____ () C:\Windows\system32\vmguest.iso
2015-02-05 11:32 - 2013-08-22 16:45 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-05 11:31 - 2013-08-22 15:25 - 00524288 ___SH () C:\Windows\system32\config\BBI
2015-02-05 11:12 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\sru
2015-02-05 02:23 - 2014-09-28 19:59 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\tixati
2015-02-05 02:09 - 2015-01-04 15:03 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\TeamViewer
2015-02-04 14:46 - 2014-09-28 12:55 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3051402733-4133393625-984315149-1001
2015-02-04 13:03 - 2014-09-28 16:36 - 00000000 ___HD () C:\Windows\msdownld.tmp
2015-02-04 13:03 - 2014-09-28 16:35 - 00000000 ____D () C:\Windows\SysWOW64\directx
2015-02-04 00:52 - 2014-09-28 21:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Oyun Çeviri
2015-02-04 00:34 - 2014-06-26 08:24 - 00000000 ____D () C:\AdwCleaner
2015-02-03 18:51 - 2014-11-16 23:41 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2015-02-03 18:51 - 2014-11-16 16:28 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2015-02-02 23:49 - 2014-09-28 15:04 - 00000000 ____D () C:\ProgramData\Realtek
2015-02-02 22:46 - 2014-09-28 12:59 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\DMCache
2015-02-02 16:23 - 2014-11-16 16:28 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.ex0
2015-02-02 15:13 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\system32\NDF
2015-02-02 15:07 - 2014-12-23 16:32 - 00000000 ____D () C:\Users\ihsan\Documents\Visual Studio 2015
2015-02-02 15:03 - 2014-11-26 12:47 - 00000000 ____D () C:\ProgramData\Origin
2015-02-02 15:02 - 2014-11-26 12:47 - 00000000 ____D () C:\Program Files (x86)\Origin
2015-02-02 15:02 - 2014-10-20 22:03 - 00000000 ____D () C:\Users\ihsan\Desktop\Oyun
2015-02-02 00:56 - 2014-10-21 12:09 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2015-02-02 00:56 - 2014-10-21 12:07 - 00000000 ____D () C:\ProgramData\Adobe
2015-02-02 00:56 - 2014-10-21 12:04 - 00000000 ____D () C:\Program Files\Adobe
2015-02-02 00:56 - 2014-09-28 12:50 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Adobe
2015-02-02 00:50 - 2014-10-21 12:13 - 00000000 ____D () C:\ProgramData\regid.1986-12.com.adobe
2015-02-01 23:43 - 2014-09-28 12:52 - 02230282 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-01 23:43 - 2013-08-23 00:53 - 00896376 _____ () C:\Windows\system32\perfh01F.dat
2015-02-01 23:43 - 2013-08-23 00:53 - 00224000 _____ () C:\Windows\system32\perfc01F.dat
2015-01-31 11:40 - 2014-09-28 12:50 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Packages
2015-01-30 17:50 - 2014-09-28 12:59 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\IDM
2015-01-30 08:38 - 2014-10-20 22:03 - 00000000 ___RD () C:\Users\ihsan\Desktop\program
2015-01-30 04:36 - 2014-11-28 23:06 - 05184440 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-01-30 03:40 - 2014-10-19 01:46 - 00000000 ____D () C:\Users\ihsan\AppData\Local\0ad
2015-01-30 03:35 - 2014-09-28 20:12 - 00000000 __SHD () C:\ProgramData\360Quarant
2015-01-30 03:35 - 2014-09-11 16:00 - 00000000 __SHD () C:\$360Section
2015-01-30 03:35 - 2014-09-02 12:13 - 00033432 _____ () C:\PureRa.txt
2015-01-30 03:30 - 2014-11-13 21:54 - 00000000 ____D () C:\Users\ihsan\Desktop\Ders Notları
2015-01-30 03:30 - 2014-10-02 20:15 - 00000000 ____D () C:\Users\ihsan\.WebIde80
2015-01-30 03:30 - 2014-09-28 19:39 - 00000000 ___RD () C:\Users\ihsan\Downloads\Microsoft.SkypeApp_kzf8qxf38zg5c!App
2015-01-30 03:30 - 2014-09-28 15:06 - 00000000 ____D () C:\Users\ihsan\Documents\My Bluetooth
2015-01-30 03:30 - 2014-09-28 13:00 - 00000000 ____D () C:\Users\ihsan\Downloads\Compressed
2015-01-30 03:29 - 2014-10-30 20:00 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\DAEMON Tools Lite
2015-01-30 03:29 - 2014-10-27 00:54 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\FileZilla
2015-01-30 03:01 - 2014-12-17 20:08 - 00000000 ____D () C:\Users\Public\Documents\DevExpress Demos 14.2
2015-01-30 03:01 - 2014-12-17 20:07 - 00000000 ____D () C:\Program Files (x86)\DevExpress 14.2
2015-01-30 03:00 - 2014-12-17 20:34 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DevExpress 14.2
2015-01-30 02:59 - 2014-10-20 22:03 - 00000000 ____D () C:\Users\ihsan\Desktop\yazlım p
2015-01-30 02:54 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\AppReadiness
2015-01-30 02:45 - 2014-10-02 16:28 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\RenPy
2015-01-30 02:39 - 2014-12-04 09:39 - 00000000 ____D () C:\Program Files (x86)\Nuance
2015-01-30 02:24 - 2014-09-28 19:44 - 00000000 ____D () C:\Program Files (x86)\StarCraft II
2015-01-29 18:03 - 2014-12-23 17:31 - 00007639 _____ () C:\Users\ihsan\AppData\Local\Resmon.ResmonCfg
2015-01-28 23:22 - 2014-09-28 19:36 - 00000000 ____D () C:\Windows\system32\appmgmt
2015-01-28 22:28 - 2014-10-05 20:47 - 00000000 ____D () C:\Program Files (x86)\Jumpstart
2015-01-28 02:14 - 2014-10-21 10:03 - 00000000 ____D () C:\Users\ihsan\Documents\SQL Server Management Studio
2015-01-27 21:06 - 2013-08-22 17:20 - 00000000 ____D () C:\Windows\CbsTemp
2015-01-26 02:10 - 2014-09-28 12:53 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\Macromedia
2015-01-24 22:20 - 2013-08-22 17:38 - 00714720 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-01-24 22:20 - 2013-08-22 17:38 - 00106976 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-01-24 00:13 - 2014-10-20 20:53 - 00000000 ____D () C:\Users\ihsan\Documents\Visual Studio 2012
2015-01-23 13:36 - 2014-11-22 15:22 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\.ACEStream
2015-01-23 13:29 - 2014-11-22 15:22 - 00000000 ___HD () C:\_acestream_cache_
2015-01-21 03:09 - 2014-10-30 21:25 - 00000396 __RSH () C:\ProgramData\ntuser.pol
2015-01-18 14:55 - 2014-09-28 15:20 - 00000000 ____D () C:\Windows\SysWOW64\sda
2015-01-18 14:55 - 2014-09-28 14:38 - 00000000 ____D () C:\Program Files (x86)\Realtek
2015-01-14 17:29 - 2014-09-28 19:32 - 00000000 ____D () C:\Windows\system32\MRT
2015-01-14 17:21 - 2014-09-28 19:32 - 113365784 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2015-01-12 21:30 - 2014-09-12 17:38 - 00000000 ____D () C:\Games
2015-01-12 18:08 - 2014-10-21 07:53 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-01-12 18:08 - 2014-10-21 07:49 - 00000000 ____D () C:\ProgramData\Microsoft Help
2015-01-12 09:21 - 2014-09-28 12:49 - 00000000 ____D () C:\Users\ihsan
2015-01-11 16:44 - 2014-10-21 10:04 - 00000000 ____D () C:\Users\ReportServer
2015-01-11 16:44 - 2014-10-21 10:04 - 00000000 ____D () C:\Users\MSSQLServerOLAPService
2015-01-11 16:44 - 2014-10-21 10:03 - 00000000 ____D () C:\Users\MSSQLSERVER
2015-01-11 16:44 - 2014-10-21 10:03 - 00000000 ____D () C:\Users\MSSQLFDLauncher
2015-01-11 16:44 - 2014-10-21 10:03 - 00000000 ____D () C:\Users\MsDtsServer110
2015-01-09 13:56 - 2014-10-18 17:11 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Adobe
2015-01-09 13:34 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\LiveKernelReports
2015-01-08 20:09 - 2014-11-22 15:21 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\ACEStream
2015-01-08 18:20 - 2013-08-22 17:36 - 00000000 ____D () C:\Windows\addins
2015-01-08 18:06 - 2014-10-30 15:40 - 00000000 ____D () C:\Users\ihsan\Documents\Korra
2015-01-06 05:37 - 2015-01-01 14:38 - 00000000 ____D () C:\Users\ihsan\AppData\Roaming\GitHub
2015-01-06 05:37 - 2015-01-01 14:38 - 00000000 ____D () C:\Users\ihsan\AppData\Local\GitHub
2015-01-06 04:50 - 2015-01-01 14:43 - 00000000 ____D () C:\Users\ihsan\Documents\GitHub
2015-01-06 04:46 - 2014-12-28 22:53 - 00000000 ____D () C:\Users\ihsan\AppData\Local\Deployment

==================== Files in the root of some directories =======

2014-11-22 12:42 - 2014-11-22 12:42 - 0000132 _____ () C:\Users\ihsan\AppData\Roaming\Adobe PNG Format CC Prefs
2014-09-28 15:06 - 2015-02-05 11:34 - 0041772 _____ () C:\Users\ihsan\AppData\Local\BTServer.log
2014-11-24 23:55 - 2014-11-25 16:37 - 0000600 _____ () C:\Users\ihsan\AppData\Local\PUTTY.RND
2014-12-23 17:31 - 2015-01-29 18:03 - 0007639 _____ () C:\Users\ihsan\AppData\Local\Resmon.ResmonCfg

==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-01-28 19:46

==================== End Of Log ============================

addition

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-02-2015 01
Ran by ihsan at 2015-02-05 11:37:10
Running from C:\Users\ihsan\Desktop
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Emsisoft Internet Security (Enabled - Up to date) {8504DEEF-CC04-1F76-2137-F1A5F4A659DA}
AV: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Emsisoft Internet Security (Enabled - Up to date) {3E653F0B-EA3E-10F8-1B87-CAD78F211367}
FW: Emsisoft Internet Security (Enabled) {BD3F5FCA-866B-1E2E-0A68-58900A751EA1}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 Tools for .Net 3.5 (x32 Version: 3.11.50727 - Microsoft Corporation) Hidden
Ace Stream Media 3.0.5 (HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\AceStream) (Version: 3.0.5 - Ace Stream Media)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated)
Age of Empires II: HD Edition (HKLM-x32\...\Steam App 221380) (Version:  - Hidden Path Entertainment, Ensemble Studios)
Age of Empires® III: Complete Collection (HKLM-x32\...\Steam App 105450) (Version:  - Ensemble Studios)
Allok Video Converter 4.6.0529 (HKLM-x32\...\Allok Video Converter_is1) (Version:  - Allok Soft Inc.)
Application Insights Tools for Visual Studio 2015 Preview (x32 Version: 3.0 - Microsoft Corporation) Hidden
Auslogics DiskDefrag (HKLM-x32\...\{DF6A13C0-77DF-41FE-BD05-6D5201EB0CE7}_is1) (Version: 5.1.0.0 - Auslogics Labs Pty Ltd)
AzureTools.Notifications (x32 Version: 2.4.20714.1601 - Microsoft Corporation) Hidden
Battery Calibration (HKLM-x32\...\{619FA785-489B-4D22-911F-82D6EDF5BDB0}) (Version: 1.0.1405.0701 - Micro-Star International Co., Ltd.)
Battle.net (HKLM-x32\...\Battle.net) (Version:  - Blizzard Entertainment)
Behaviors SDK (Windows Phone) for Visual Studio 2013 (x32 Version: 12.0.50926.80 - Microsoft Corporation) Hidden
Behaviors SDK (Windows) for Visual Studio 2013 (x32 Version: 12.0.50926.80 - Microsoft Corporation) Hidden
BioShock (HKLM-x32\...\Steam App 7670) (Version:  - 2K Boston)
BioShock 2 (HKLM-x32\...\Steam App 8850) (Version:  - 2K Marin)
BioShock Infinite (HKLM-x32\...\Steam App 8870) (Version:  - Irrational Games)
Bioshock Türkçe Yama v1.00 (HKLM-x32\...\Bioshock TR) (Version: 1.00 - )
Blend for Visual Studio 2012 (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Blend for Visual Studio 2012 ENU resources (x32 Version: 5.0.30709.0 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for .NET 4.5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for Silverlight 5 (x32 Version: 3.0.40218.0 - Microsoft Corporation) Hidden
Blend for Visual Studio SDK for Windows Phone 8.0 (x32 Version: 3.0.30924.0 - Microsoft Corporation) Hidden
Build Tools - amd64 (Version: 12.0.31010 - Microsoft Corporation) Hidden
Build Tools - x86 (x32 Version: 12.0.31010 - Microsoft Corporation) Hidden
Build Tools 14.0 (amd64) (Version: 14.0.22310 - Microsoft Corporation) Hidden
Build Tools 14.0 (x86) (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
Build Tools Language Resources - amd64 (Version: 12.0.31010 - Microsoft Corporation) Hidden
Build Tools Language Resources - x86 (x32 Version: 12.0.31010 - Microsoft Corporation) Hidden
Build Tools Language Resources 14.0 (amd64) (Version: 14.0.22310 - Microsoft Corporation) Hidden
Build Tools Language Resources 14.0 (x86) (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 5.02 - Piriform)
ClumsyLeaf CloudXplorer (HKLM-x32\...\{7F111167-5B0A-4DD4-8D0F-C6DB7649B938}) (Version: 3.2.0.0 - ClumsyLeaf Software)
Command & Conquer™ Red Alert 2 and Yuri’s Revenge (HKLM-x32\...\{F5275D1C-D133-486D-8F07-D6C571F0A8EC}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
Command & Conquer™: Generals and Zero Hour (HKLM-x32\...\{609F6FD5-4B22-4D7A-AD30-8C9DD480D5BE}) (Version: 1.0.0.0 - Electronic Arts, Inc.)
DAEMON Tools Lite (HKLM-x32\...\DAEMON Tools Lite) (Version: 4.49.1.0356 - Disc Soft Ltd)
Democracy 3 (HKLM-x32\...\Steam App 245470) (Version:  - Positech Games)
Dev-C++ 5 beta 9 release (4.9.9.2) (HKLM-x32\...\Dev-C++) (Version:  - )
DomDomSoft Manga Downloader (remove only) (HKLM-x32\...\DomDomSoft Manga Downloader) (Version:  - )
Don't Starve Together Beta (HKLM-x32\...\Steam App 322330) (Version:  - )
Dotfuscator and Analytics Community Edition (x32 Version: 5.5.4521.29298 - PreEmptive Solutions) Hidden
Dotfuscator and Analytics Community Edition 5.16.0 (x32 Version: 5.16.0.2178 - PreEmptive Solutions) Hidden
Emsisoft Internet Security (HKLM-x32\...\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 9.0 - Emsisoft Ltd.)
ErrorList (x32 Version: 1.0 - Microsoft Corporation) Hidden
ETDWare PS/2-X64 11.13.4.4_WHQL (HKLM\...\Elantech) (Version: 11.13.4.4 - ELAN Microelectronic Corp.)
Far Cry (HKLM-x32\...\Steam App 13520) (Version:  - Crytek Studios)
Far Cry 2 (HKLM-x32\...\Steam App 19900) (Version:  - Ubisoft Montreal)
Far Cry® 3 (HKLM-x32\...\Steam App 220240) (Version:  - Ubisoft Montreal, Massive Entertainment, and Ubisoft Shanghai)
Far Cry® 3 Blood Dragon (HKLM-x32\...\Steam App 233270) (Version:  - Ubisoft Montreal)
FileZilla Client 3.9.0.6 (HKLM-x32\...\FileZilla Client) (Version: 3.9.0.6 - Tim Kosse)
Freemake Video Converter version 4.1.5 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 4.1.5 - Ellora Assets Corporation)
GameRanger (HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\GameRanger) (Version:  - GameRanger Technologies)
Garry's Mod (HKLM-x32\...\Steam App 4000) (Version:  - Facepunch Studios)
Git version 1.9.0-preview20140217 (HKLM-x32\...\Git_is1) (Version: 1.9.0-preview20140217 - The Git Development Community)
GitHub (HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\5f7eb300e2ea4ebf) (Version: 2.6.6.2 - GitHub, Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 41.0.2272.35 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
IIS 8.0 Express (HKLM\...\{7BF61FA9-BDFB-4563-98AD-FCB0DA28CCC7}) (Version: 8.0.1557 - Microsoft Corporation)
IIS Express Application Compatibility Database for x64 (HKLM\...\{9f4f4a9b-eec5-4906-92fe-d1f43ccf5c8d}.sdb) (Version:  - )
IIS Express Application Compatibility Database for x86 (HKLM\...\{fdfba1f3-74ae-4255-9c10-a0f552b4610f}.sdb) (Version:  - )
Insurgency (HKLM-x32\...\Steam App 222880) (Version:  - New World Interactive)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.20.1447 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3496 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 13.2.4.1000 - Intel Corporation)
Internet Download Manager (HKLM-x32\...\Internet Download Manager) (Version:  - Tonec Inc.)
Java 8 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418025F0}) (Version: 8.0.250 - Oracle Corporation)
JetBrains PhpStorm 8.0.1 (HKLM-x32\...\PhpStorm 8.0.1) (Version: 138.2001.2328 - JetBrains s.r.o.)
Jumpstart Installation Program (HKLM-x32\...\{B0BCDCBD-863D-4CAB-BF68-8D1F6B1BDC13}) (Version:  - Atheros)
KB9X Radio Switch Driver (HKLM\...\5AADE1068CF70DD983F763B20CF2CAAB72883915) (Version: 1.1.0.0 - ENE TECHNOLOGY INC.)
K-Lite Mega Codec Pack 10.8.0 (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.8.0 - )
Left 4 Dead 2 (HKLM-x32\...\Steam App 550) (Version:  - Valve)
LocalESPC (x32 Version: 8.59.29989 - Microsoft Corporation) Hidden
LocalESPCui for en-us (x32 Version: 8.59.29989 - Microsoft) Hidden
Malwarebytes Anti-Malware 2.0.4.1028 sürümü (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation)
Microsoft .NET Framework 4.5 Multi-Targeting Pack (HKLM-x32\...\{56E962F0-4FB0-3C67-88DB-9EAA6EEFC493}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5 SDK (HKLM-x32\...\{4AE57014-05C4-4864-A13D-86517A7E1BA4}) (Version: 4.5.50710 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (ENU) (HKLM-x32\...\{D3517C62-68A5-37CF-92F7-93C029A89681}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 SDK (HKLM-x32\...\{19A5926D-66E1-46FC-854D-163AA10A52D3}) (Version: 4.5.51641 - Microsoft Corporation)
Microsoft .NET Framework 4.5.3 Preview Multi-Targeting Pack (ENU) (HKLM-x32\...\{6FF89029-E442-4346-BB1E-C73AA6F6D080}) (Version: 4.5.53346 - Microsoft Corporation)
Microsoft .NET Framework 4.5.3 Preview Multi-Targeting Pack (HKLM-x32\...\{861F6EBB-5856-4DB9-B812-363CFB1D2F56}) (Version: 4.5.53346 - Microsoft Corporation)
Microsoft ASP.NET MVC 3 (HKLM-x32\...\{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}) (Version: 3.0.20105.0 - Microsoft Corporation)
Microsoft ASP.NET Web Pages (HKLM-x32\...\{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}) (Version: 1.0.20105.0 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\...\{42AA4CA8-DCD8-4308-BCAB-0B6D75856A9D}) (Version: 3.5.95.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\...\{67F42018-F647-4D3C-BE62-F8CB4FE2FCD5}) (Version: 3.5.67.0 - Microsoft Corporation)
Microsoft Help Viewer 1.1 (HKLM\...\Microsoft Help Viewer 1.1) (Version: 1.1.40219 - Microsoft Corporation)
Microsoft Help Viewer 2.0 (HKLM-x32\...\Microsoft Help Viewer 2.0) (Version: 2.0.50727 - Microsoft Corporation)
Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.22310 - Microsoft Corporation)
Microsoft Office 2003 Web Components (HKLM-x32\...\{90120000-00A4-0409-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUSR) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Report Viewer 2012 Runtime (HKLM-x32\...\{9CCE40CE-A9E6-4916-8729-B008558EEF3F}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft Silverlight 4 SDK (HKLM-x32\...\{189AEA94-DAFB-487A-8CEE-F9D3DDE0A748}) (Version: 4.0.60310.0 - Microsoft Corporation)
Microsoft Silverlight 5 SDK (HKLM-x32\...\{E1FBB3D4-ADB0-4949-B101-855DA061C735}) (Version: 5.0.61118.0 - Microsoft Corporation)
Microsoft SQL Server 2008 R2 Management Objects (HKLM-x32\...\{83F2B8F4-5CF3-4BE9-9772-9543EAE4AC5F}) (Version: 10.51.2500.0 - Microsoft Corporation)
Microsoft SQL Server 2008 Setup Support Files  (HKLM\...\{B40EE88B-400A-4266-A17B-E3DE64E94431}) (Version: 10.1.2731.0 - Microsoft Corporation)
Microsoft SQL Server 2012 (64-bit) (HKLM\...\Microsoft SQL Server SQLServer2012) (Version:  - Microsoft Corporation)
Microsoft SQL Server 2012 Command Line Utilities  (HKLM\...\{9D573E71-1077-4C7E-B4DB-4E22A5D2B48B}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM\...\{36E619BC-A234-4EC3-849B-779A7C865A45}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Data-Tier App Framework  (HKLM-x32\...\{FBA6F90E-36EC-4FC9-9B25-3834E3BD46A8}) (Version: 11.0.2316.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\...\{13D558FE-A863-402C-B115-160007277033}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (HKLM-x32\...\{DA1C1761-5F4F-4332-AB9D-29EDF3F8EA0A}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (x64) (HKLM\...\{FA0A244E-F3C2-4589-B42A-3D522DE79A42}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Native Client  (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Policies  (HKLM-x32\...\{DC487E40-046E-42A9-9C7C-5D2B1A7EB211}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Setup (English) (HKLM\...\{8CB0713F-CFE0-445D-BCB2-538465860E1A}) (Version: 11.1.3128.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL Compiler Service  (HKLM\...\{BEB0F91E-F2EA-48A1-B938-7857ABF2A93D}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 Transact-SQL ScriptDom  (HKLM\...\{0E8670B8-3965-4930-ADA6-570348B67153}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 T-SQL Language Service  (HKLM\...\{CC8B009A-98C9-497F-99AF-CEBE35D8C0CF}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2012 T-SQL Language Service  (HKLM-x32\...\{6D6D43E5-218C-4B05-92D3-2240810F4760}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft SQL Server 2014 Express LocalDB  (HKLM\...\{AB8DE9BA-19E1-446A-BCFA-6B3DA9751E21}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Management Objects  (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 Transact-SQL ScriptDom  (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server 2014 T-SQL Language Service  (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation)
Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation)
Microsoft SQL Server Data Tools – Database Projects – Web installer entry point (HKLM-x32\...\{F3BBC56F-2282-4464-952F-A89772181F30}) (Version: 10.3.20116.0 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (11.1.20627.00) (HKLM-x32\...\{FA804794-2CCB-4301-954F-2C2894698876}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server Data Tools - enu (14.0.41025.0) (HKLM-x32\...\{455A16B4-CD22-4529-B429-DD454573E76A}) (Version: 14.0.41025.0 - Microsoft Corporation)
Microsoft SQL Server Data Tools Build Utilities - enu (11.1.20627.00) (HKLM-x32\...\{790E9425-8570-493F-9AE7-81AFC9E46930}) (Version: 11.1.20627.00 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (HKLM-x32\...\{C3F6F200-6D7B-4879-B9EE-700C0CE1FCDA}) (Version: 10.51.2500.0 - Microsoft Corporation)
Microsoft SQL Server System CLR Types (x64) (HKLM\...\{4701DEDE-1888-49E0-BAE5-857875924CA2}) (Version: 10.50.1600.1 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (HKLM-x32\...\{E2082604-4BA5-44BB-BBFB-AF0F3CB8C6AB}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\...\{F1949145-EB64-4DE7-9D81-E6D27937146C}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{DAF4DDA4-3B5A-407D-B4DF-07922C5A0D22}) (Version: 12.0.2360.29 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{659D2DBE-CA2C-4C8F-AF2B-2C8DE262B278}) (Version: 12.0.2360.29 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974 (HKLM-x32\...\{B7E38540-E355-3503-AFD7-635B2F2F76E1}) (Version: 9.0.30729.4974 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Runtime - 10.0.40219 (HKLM-x32\...\{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.60610 (HKLM-x32\...\{a1909659-0a08-4554-8af1-2175904903a1}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60610 (HKLM-x32\...\{95716cce-fc71-413f-8ad5-56c2892d4b3a}) (Version: 11.0.60610.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\...\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Preview Redistributable (x64) - 14.0.22310 (HKLM-x32\...\{eb6c06e7-8ff6-4978-ab4c-561383593306}) (Version: 14.0.22310.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Preview Redistributable (x86) - 14.0.22310 (HKLM-x32\...\{2e4043b7-cd84-44db-b81a-8f6e5ffb7398}) (Version: 14.0.22310.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Shell (Integrated) - ENU (HKLM-x32\...\{012D26C3-E12A-3BDA-8ECE-DF14E721A507}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Shell (Isolated) - ENU (HKLM-x32\...\{D64B6984-242F-32BC-B008-752806E5FC44}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2015 Preview Secondary Installer (HKLM-x32\...\{B6CB8401-B0A8-4795-8BED-F7B49D51ABCF}_SecondaryInstaller) (Version: 14.0.22310 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications Design-Time 3.0 (HKLM-x32\...\{5A03C202-08B4-3F1D-9A60-A4F53EF1B636}) (Version: 10.0.40220 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications x64 Runtime 3.0 (HKLM\...\{F14401A9-F0A0-33CC-8444-F60823A60DEB}) (Version: 10.0.40220 - Microsoft Corporation)
Microsoft Visual Studio Tools for Applications x86 Runtime 3.0 (HKLM-x32\...\{191A6F65-6878-398D-A272-EF011B80F371}) (Version: 10.0.40220 - Microsoft Corporation)
Microsoft Visual Studio Ultimate 2012 (HKLM-x32\...\{9600393b-6ede-469b-a522-689fce1461d1}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual Studio Ultimate 2015 Preview (HKLM-x32\...\{e1f58f60-306c-4f5b-9788-5b9292910779}) (Version: 14.0.22310.1 - Microsoft Corporation)
Microsoft VSS Writer for SQL Server 2012 (HKLM\...\{3E0DD83F-BE4C-4478-86A0-AD0D79D1353E}) (Version: 11.0.2100.60 - Microsoft Corporation)
Microsoft Web Deploy 3.6 Beta3 (HKLM\...\{07F0FC77-282E-42E5-BAE6-B8C098F8453E}) (Version: 3.1238.1942 - Microsoft Corporation)
Microsoft Web Deploy dbSqlPackage Provider - enu (HKLM-x32\...\{E4C33F5B-1B2F-466E-957E-B274F08151A0}) (Version: 10.3.20225.0 - Microsoft Corporation)
Microsoft Web Platform Installer 5.0 (HKLM\...\{4D84C195-86F0-4B34-8FDE-4A17EB41306A}) (Version: 5.0.50430.0 - Microsoft Corporation)
Mozilla Firefox 34.0.5 (x86 tr) (HKLM-x32\...\Mozilla Firefox 34.0.5 (x86 tr)) (Version: 34.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 34.0.5 - Mozilla)
Multi-Device Hybrid Apps using C# - Templates - ENU (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
NARUTO SHIPPUDEN: Ultimate Ninja STORM 3 Full Burst (HKLM-x32\...\Steam App 234670) (Version:  - CyberConnect 2)
Node.js (HKLM-x32\...\{417EF6AA-3961-4119-9A00-312724B35D3A}) (Version: 0.10.33 - Joyent, Inc. and other Node contributors)
Notepad++ (HKLM-x32\...\Notepad++) (Version: 6.6.9 - Notepad++ Team)
Nuance OmniPage Ultimate (HKLM-x32\...\{419512F9-D5E7-4ED2-BF99-E7F2C0176B6A}) (Version: 19.00.0000 - Nuance Communications, Inc.)
NVIDIA GeForce Experience 2.1.5 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.5 - NVIDIA Corporation)
NVIDIA Grafik Sürücüsü 344.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.65 - NVIDIA Corporation)
NVIDIA PhysX Sistem Yazılımı 9.14.0702 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
Open XML SDK 2.5 for Microsoft Office (x32 Version: 2.5.5631 - Microsoft Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: 9.5.2.2829 - Electronic Arts, Inc.)
Outils de vérification linguistique 2013 de Microsoft Office - Français (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Papers Please version 1.1.60-S (HKLM-x32\...\Papers Please_is1) (Version: 1.1.60-S - )
PAYDAY 2 (HKLM-x32\...\Steam App 218620) (Version:  - OVERKILL - a Starbreeze Studio.)
PDF Architect 2 (HKLM-x32\...\PDF Architect 2) (Version: 2.0.41.17507 - pdfforge GmbH)
PDF Architect 2 Asian Fonts Pack (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Convert Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Create Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Edit Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Forms Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Insert Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 OCR Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Review Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 Secure Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PDF Architect 2 View Module (x32 Version: 2.1.6.19758 - pdfforge GmbH) Hidden
PerformanceTest v8.0 (HKLM\...\PerformanceTest 8_is1) (Version: 8.0.1042.0 - Passmark Software)
PreEmptive Analytics Visual Studio Components (x32 Version: 1.0.2180.1 - PreEmptive Solutions) Hidden
PreEmptive Analytics Visual Studio Components (x32 Version: 1.2.3197.1 - PreEmptive Solutions) Hidden
Prerequisites for SSDT  (HKLM-x32\...\{21373064-AD95-48DB-A32E-0D9E08EF7355}) (Version: 12.0.2000.8 - Microsoft Corporation)
Prerequisites for SSDT  (HKLM-x32\...\{9169C939-ED01-446A-BD0C-29873BAF4E48}) (Version: 11.0.2100.60 - Microsoft Corporation)
PunkBuster Services (HKLM-x32\...\PunkBusterSvc) (Version: 0.993 - Even Balance, Inc.)
Python Tools Redirection Template (x32 Version: 1.1 - Microsoft Corporation) Hidden
Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.21 - Qualcomm Atheros Inc.)
REALTEK Bluetooth Driver (HKLM-x32\...\{9D3D8C60-A5EF-4123-B2B9-172095903AB}) (Version: 3.754.754.082813 - REALTEK Semiconductor Corp.)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.30164 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\...\{9DAABC60-A5EF-41FF-B2B9-17329590CD5}) (Version: 1.00.0224 - REALTEK Semiconductor Corp.)
Revo Uninstaller Pro 3.1.2 (HKLM\...\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.2 - VS Revo Group, Ltd.)
Roslyn Language Services - x86 (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
Rust (HKLM-x32\...\Steam App 252490) (Version:  - Facepunch Studios)
SCM (HKLM\...\{614FD4D7-78CE-43E0-88E1-F6DE78069B9A}) (Version: 13.013.09262 - Application)
SharePoint Client Components (Version: 15.0.4641.1002 - Microsoft Corporation) Hidden
SharePoint Client Components (Version: 16.0.3104.1200 - Microsoft Corporation) Hidden
SHIELD Streaming (Version: 3.1.3000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.18.9 - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Sound Blaster Cinema (HKLM-x32\...\{8801CA65-921A-4CCC-9D63-879D1D0BAA97}) (Version: 1.00.02 - Creative Technology Limited)
SQL Server 2012 Analysis Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 BI Development Studio (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Client Tools (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Common Files (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Data quality client (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Data quality service (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Database Engine Shared (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Distributed Replay (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Documentation Components (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Full text search (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Integration Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Management Studio (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Master Data Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 Reporting Services (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 RS_SharePoint_SharedService (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server 2012 SQL Data Quality Common (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
SQL Server Browser for SQL Server 2012 (HKLM-x32\...\{4B9E6EB0-0EED-4E74-9479-F982C3254F71}) (Version: 11.0.2100.60 - Microsoft Corporation)
Sql Server Customer Experience Improvement Program (Version: 11.0.2100.60 - Microsoft Corporation) Hidden
Sublight (HKLM\...\Sublight_is1) (Version: 4 - Sublight Labs)
Subtitle Workshop 2.51 (HKLM-x32\...\SubtitleWorkshop) (Version:  - )
Team Explorer for Microsoft Visual Studio 2015 Preview (x32 Version: 14.0.22310 - Microsoft Corporation) Hidden
TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.36897 - TeamViewer)
The Elder Scrolls V Skyrim Türkçe Yama Uyum Programı v1.00 (HKLM-x32\...\The Elder Scrolls V Skyrim TR) (Version: 1.00 - OyunCeviri.com)
This War of Mine (HKLM-x32\...\{5FD7B6B3-08C7-4FEE-9C37-A2134C699885}}_is1) (Version: 1 - 11 bit studios)
This War of Mine (HKLM-x32\...\This War of Mine_R.G. Mechanics_is1) (Version:  - R.G. Mechanics, spider91)
This War of Mine Türkçe Yama v1.00 (HKLM-x32\...\This War of Mine TR) (Version: 1.00 - OyunCeviri.com)
Tixati (HKLM-x32\...\tixati) (Version:  - )
TOEFL Sampler (HKLM-x32\...\{95744E49-71D1-453A-9466-6930819043C8}) (Version: 1.00.0001 - ETS)
Tropico 4 (HKLM-x32\...\Steam App 57690) (Version:  - Haemimont Games)
TypeScript Power Tool (x32 Version: 1.3.0.0 - Microsoft Corporation) Hidden
TypeScript Tools for Microsoft Visual Studio 14 (x32 Version: 1.3.0.0 - Microsoft Corporation) Hidden
Unity Web Player (HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\UnityWebPlayer) (Version: 4.5.5f1 - Unity Technologies ApS)
Update for  (KB2504637) (HKLM-x32\...\{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}.KB2504637) (Version: 1 - Microsoft Corporation)
Uplay (HKLM-x32\...\Uplay) (Version: 2.0 - Ubisoft)
USB Network Driver (HKLM-x32\...\{66ED8E01-C915-41F5-B33E-C5C31F27B885}) (Version: 2007.07.3 - )
Visual Studio 2010 Prerequisites - English (HKLM\...\{662014D2-0450-37ED-ABAE-157C88127BEB}) (Version: 10.0.40219 - Microsoft Corporation)
VsHub (x32 Version: 1.0.0.0 - Microsoft Corporation) Hidden
WCF Data Services 5.0 (for OData v3) Primary Components (x32 Version: 5.0.50628.0 - Microsoft Corporation) Hidden
WCF Data Services 5.6.2 Runtime (x32 Version: 5.6.61937.2 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2012 (x32 Version: 5.0.50710.0 - Microsoft Corporation) Hidden
WCF Data Services Tools for Microsoft Visual Studio 2014 (x32 Version: 5.6.61937.2 - Microsoft Corporation) Hidden
WCF RIA Services V1.0 SP2 (HKLM-x32\...\{5D8DD6A8-C4D7-4554-93F9-F1CC28C72600}) (Version: 4.1.62812.0 - Microsoft Corporation)
WebTV Plugin (HKLM-x32\...\{EFC3D6C3-C96D-47F2-BC49-99BC10AB6377}) (Version: 3.2.5.0 - WebTV Plugin)
Windows Phone 8.1 Emulators - ENU (HKLM-x32\...\{166a69f6-6512-47ea-a342-17d954fc059a}) (Version: 12.0.31010.0 - Microsoft Corporation)
WinRAR 5.11 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
Workflow Manager Client 1.0 (Version: 2.0.40131.0 - Microsoft Corporation) Hidden
Workflow Manager Tools 1.0 for Visual Studio (Version: 2.0.41015.0 - Microsoft Corporation) Hidden

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)

CustomCLSID: HKU\S-1-5-21-3051402733-4133393625-984315149-1001_Classes\CLSID\{0BC0D8BD-047A-4620-9070-11B2CABC838B}\InprocServer32 -> 0x0ADCCA3361B30CBC8D98C765E8A222CC324FD91738B27840 No File
CustomCLSID: HKU\S-1-5-21-3051402733-4133393625-984315149-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)

==================== Restore Points  =========================

02-02-2015 22:58:55 Zamanlanmış Denetim Noktası
04-02-2015 12:06:47 Installed WebTV Plugin

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2015-02-02 15:13 - 2015-02-05 11:30 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {23081457-A505-40A0-A99D-A2C00BA91AB4} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04] (Adobe Systems Incorporated)
Task: {2D215246-5F93-4498-818D-6D8E08550B24} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {35A7EB11-BBFF-4755-A60F-4C6954D6702D} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-28] (Google Inc.)
Task: {4F41FB20-FF5A-4670-9CDF-10C4FE25619B} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-01-20] (Piriform Ltd)
Task: {596C62E0-D813-434E-B840-C3A43565DACD} - System32\Tasks\GenericSettingsHandler\Windows-Credentials\RetrySyncTask_for_S-1-5-21-3051402733-4133393625-984315149-1001
Task: {62AD2687-6051-44F7-A86F-8B6B910F9ADA} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {7CFBB224-A68D-4A61-A116-38F219528831} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2014-12-28] (Google Inc.)
Task: {EE8F767C-9BE7-4074-8832-56834A6CE58D} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-10-06] ()
Task: {F203A82A-F19C-4D53-82AA-EC974E4F4EF0} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) ==============

2014-09-28 15:37 - 2014-11-04 02:04 - 00013120 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2014-09-28 15:38 - 2014-11-04 00:02 - 00116880 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-09-28 15:14 - 2013-08-28 11:35 - 00056832 _____ () C:\Program Files (x86)\REALTEK\Realtek Bluetooth\BTDevMgr.exe
2014-11-16 16:28 - 2014-11-16 16:28 - 00076888 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2012-10-01 19:36 - 2012-10-01 19:36 - 06522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-05-12 11:49 - 2014-05-12 11:49 - 00222720 _____ () C:\Program Files (x86)\Notepad++\NppShell_06.dll
2014-11-27 18:14 - 2012-11-01 11:21 - 00325120 _____ () C:\Windows\SYSTEM32\APOMgr64.DLL
2015-01-21 04:06 - 2015-01-21 04:06 - 00053248 _____ () C:\Program Files\CCleaner\lang\lang-1055.dll
2012-10-01 19:37 - 2012-10-01 19:37 - 06522480 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2014-09-28 15:37 - 2014-11-04 02:04 - 00010952 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
2014-09-28 16:20 - 2013-08-08 12:25 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\Windows:nlsPreferences
AlternateDataStreams: C:\Users\ihsan\SkyDrive:ms-properties

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver"

==================== EXE Association (whitelisted) ===============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== Other Registry Areas =====================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3051402733-4133393625-984315149-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\ihsan\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
ATTENTION: Missing Desktop Wallpaper Registry entry.
ATTENTION: Missing Desktop Wallpaper Registry entry.
ATTENTION: Missing Desktop Wallpaper Registry entry.
ATTENTION: Missing Desktop Wallpaper Registry entry.
ATTENTION: Missing Desktop Wallpaper Registry entry.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\Services: GladFileMonSvc => 2
MSCONFIG\Services: jswpbapi => 2
MSCONFIG\Services: jswpsapi => 3
MSCONFIG\Services: NitroDriverReadSpool9 => 2
MSCONFIG\Services: NitroUpdateService => 2
MSCONFIG\Services: PDF Architect 2 Creator => 2
MSCONFIG\Services: pdfforge CrashHandler => 3
MSCONFIG\Services: PDFProFiltSrv => 2
HKLM\...\StartupApproved\StartupFolder: => "Nuance Cloud Connector.lnk"
HKLM\...\StartupApproved\Run: => "Nvtmru"
HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\...\StartupApproved\Run32: => "jswtrayutil"
HKLM\...\StartupApproved\Run32: => "USB Gamepad"
HKLM\...\StartupApproved\Run32: => "AdobeCEPServiceManager"
HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\...\StartupApproved\Run32: => "ISUSPM"
HKLM\...\StartupApproved\Run32: => "Nuance OmniPage Ultimate-reminder"
HKLM\...\StartupApproved\Run32: => "OmniPage Preload"
HKLM\...\StartupApproved\Run32: => "PDFProHook"
HKLM\...\StartupApproved\Run32: => "PDF8 Registry Controller"
HKLM\...\StartupApproved\Run32: => "Babylon Client"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "IDMan"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "GUDelayStartup"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "DAEMON Tools Lite"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "AceStream"
HKU\S-1-5-21-3051402733-4133393625-984315149-1001\...\StartupApproved\Run: => "ISUSPM"

==================== Accounts: =============================

Administrator (S-1-5-21-3051402733-4133393625-984315149-500 - Administrator - Disabled)
Guest (S-1-5-21-3051402733-4133393625-984315149-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3051402733-4133393625-984315149-1003 - Limited - Enabled)
ihsan (S-1-5-21-3051402733-4133393625-984315149-1001 - Administrator - Enabled) => C:\Users\ihsan

==================== Faulty Device Manager Devices =============

Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (02/05/2015 11:33:08 AM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER) cannot connect to the report server database.

Error: (02/04/2015 11:36:35 PM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER) cannot connect to the report server database.

Error: (02/04/2015 05:23:54 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: IHOCAN)
Description: Microsoft.SkypeApp_kzf8qxf38zg5c!App uygulamasının etkinleştirilmesi şu hatayla başarısız oldu: -2144927142 Ek bilgi için Microsoft-Windows-TWinUI/Operational günlüğüne bakın.

Error: (02/04/2015 05:23:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe programının 6.3.9600.17031 sürümü, Windows ile birlikte çalışmayı durdurdu ve kapatıldı. Sorun hakkında daha fazla bilgi olup olmadığını görmek için Eylem Merkezi denetim masasında sorunun geçmişini denetleyin.

İşlem Kimlik No: 1d3c

Başlatma Saati: 01d0408e845310d7

Sona Erdirme Saati: 4294967295

Uygulama Yolu: C:\Windows\syswow64\wwahost.exe

Rapor Kimliği: cf83fa21-ac81-11e4-8295-8c89a50ef469

Hatalı paket tam adı: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c

Hatalı paketle ilgili uygulama kimliği: App

Error: (02/04/2015 05:23:45 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: IHOCAN)
Description: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c+App uygulaması kendisine ayrılan sürede başlatılmadı.

Error: (02/04/2015 05:23:13 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: IHOCAN)
Description: Askıya alınması çok uzun sürdüğünden Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c+App paketi sonlandırıldı.

Error: (02/04/2015 00:07:03 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Şifreleme Hizmetleri, Sistem Yazıcısı Nesnesi'nde OnIdentity() çağrısını işlerken başarısız oldu.


Details:
AddLegacyDriverFiles: Unable to back up image of binary 360FsFlt mini-filter driver.

System Error:
Sistem belirtilen dosyayı bulamıyor.
.

Error: (02/04/2015 00:07:03 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Şifreleme Hizmetleri, Sistem Yazıcısı Nesnesi'nde OnIdentity() çağrısını işlerken başarısız oldu.


Details:
AddLegacyDriverFiles: Unable to back up image of binary 360Safe Anti Hacker Service.

System Error:
Sistem belirtilen dosyayı bulamıyor.
.

Error: (02/04/2015 11:36:02 AM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER) cannot connect to the report server database.

Error: (02/03/2015 08:29:18 PM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER) cannot connect to the report server database.


System errors:
=============
Error: (02/05/2015 11:30:47 AM) (Source: Microsoft-Windows-DNS-Client) (EventID: 1012) (User: NT AUTHORITY)
Description: Yerel ana bilgisayarlar dosyası okunmaya çalışılırken hata oldu.

Error: (02/03/2015 08:27:22 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: SQL Server Reporting Services (MSSQLSERVER) hizmeti beklenmedik şekilde sona erdi.  Bu durum 1 defa oluştu.  60000 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti yeniden başlat.

Error: (02/03/2015 08:27:10 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: SQL Server (MSSQLSERVER) hizmeti beklenmeyen bir şekilde sonlandırıldı. Bu durum 1 defa oluştu.

Error: (02/03/2015 08:25:44 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: MBAMService hizmeti beklenmeyen bir şekilde sonlandırıldı. Bu durum 1 defa oluştu.

Error: (02/02/2015 10:46:17 PM) (Source: DCOM) (EventID: 10010) (User: IHOCAN)
Description: {9BA05972-F6A8-11CF-A442-00A0C90A8F39}

Error: (02/01/2015 08:26:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Steam Client Service hizmeti şu hata nedeniyle başlatılamadı: 
%%1053

Error: (02/01/2015 08:26:26 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: Steam Client Service hizmetinin bağlanması beklenirken zaman aşımı (30000 milisaniye) oluştu.

Error: (02/01/2015 08:06:57 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Emsisoft Protection Service hizmeti beklenmedik şekilde sona erdi.  Bu durum 2 defa oluştu.  0 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti yeniden başlat.

Error: (02/01/2015 08:06:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: Emsisoft Protection Service hizmeti beklenmedik şekilde sona erdi.  Bu durum 1 defa oluştu.  0 milisaniye içinde şu düzeltme eylemi uygulanacak: Hizmeti yeniden başlat.

Error: (01/31/2015 11:49:36 AM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: WSearch hizmetinden işlem yanıtı beklenirken zaman aşımı (30000 milisaniye) oluştu.


Microsoft Office Sessions:
=========================
Error: (02/05/2015 11:33:08 AM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER)

Error: (02/04/2015 11:36:35 PM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER)

Error: (02/04/2015 05:23:54 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: IHOCAN)
Description: Microsoft.SkypeApp_kzf8qxf38zg5c!App-2144927142

Error: (02/04/2015 05:23:54 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: wwahost.exe6.3.9600.170311d3c01d0408e845310d74294967295C:\Windows\syswow64\wwahost.execf83fa21-ac81-11e4-8295-8c89a50ef469Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5cApp

Error: (02/04/2015 05:23:45 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2486) (User: IHOCAN)
Description: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c+App

Error: (02/04/2015 05:23:13 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: IHOCAN)
Description: Microsoft.SkypeApp_3.1.0.1007_x86__kzf8qxf38zg5c+App

Error: (02/04/2015 00:07:03 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: 
Details:
AddLegacyDriverFiles: Unable to back up image of binary 360FsFlt mini-filter driver.

System Error:
Sistem belirtilen dosyayı bulamıyor.

Error: (02/04/2015 00:07:03 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: 
Details:
AddLegacyDriverFiles: Unable to back up image of binary 360Safe Anti Hacker Service.

System Error:
Sistem belirtilen dosyayı bulamıyor.

Error: (02/04/2015 11:36:02 AM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER)

Error: (02/03/2015 08:29:18 PM) (Source: Report Server Windows Service (MSSQLSERVER)) (EventID: 107) (User: )
Description: Report Server Windows Service (MSSQLSERVER)


==================== Memory info =========================== 

Processor: Intel(R) Core(TM) i7-4702MQ CPU @ 2.20GHz
Percentage of memory in use: 37%
Total physical RAM: 8113.17 MB
Available physical RAM: 5056.48 MB
Total Pagefile: 9393.17 MB
Available Pagefile: 5052.25 MB
Total Virtual: 131072 MB
Available Virtual: 131071.84 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:488.61 GB) (Free:257.55 GB) NTFS
Drive d: () (Fixed) (Total:442.38 GB) (Free:132.71 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 70873948)

Partition: GPT Partition Type.

==================== End Of Log ============================

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP