NotesWhat is notes.io?

Notes brand slogan

Notes - notes.io

ComboFix 16-01-24.01 - Rynduse 30.01.2016 20:32:35.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1254.90.1055.18.3327.2004 [GMT 2:00]
Running from: c:usersRynduseDownloadsComboFix.exe
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:CFLog
c:cflogEPLog.txt
c:programdatantuser.pol
.
.
((((((((((((((((((((((((( Files Created from 2015-12-28 to 2016-01-30 )))))))))))))))))))))))))))))))
.
.
2016-01-30 18:36 . 2016-01-30 18:36 -------- d-----w- c:usersPublicAppDataLocaltemp
2016-01-30 18:36 . 2016-01-30 18:36 -------- d-----w- c:usersDefaultAppDataLocaltemp
2016-01-30 11:37 . 2016-01-30 11:40 191992 ----a-w- c:windowssystem32driversEasyAntiCheat.sys
2016-01-30 11:37 . 2016-01-22 15:49 239904 ----a-w- c:windowssystem32EasyAntiCheat.exe
2016-01-30 05:20 . 2016-01-30 05:20 -------- d-----w- c:usersRynduseAppDataLocalChromium
2016-01-30 05:15 . 2016-01-30 05:15 -------- d-----w- c:usersRynduseAppDataRoamingDead Island Riptide
2016-01-29 23:24 . 2016-01-29 23:24 -------- d-----w- c:usersRynduseAppDataLocalAMD
2016-01-29 23:23 . 2016-01-29 23:23 -------- d-----w- c:usersRynduseAppDataRoamingATI
2016-01-29 23:23 . 2016-01-29 23:23 -------- d-----w- c:usersRynduseAppDataLocalATI
2016-01-29 23:23 . 2016-01-29 23:23 -------- d-----w- c:programdataATI
2016-01-29 23:01 . 2016-01-29 23:01 -------- d-----w- c:usersRynduseAppDataRoaminglibrary_dir
2016-01-29 22:58 . 2016-01-30 16:49 -------- d-----w- c:usersRynduseAppDataRoamingRaptr
2016-01-29 22:58 . 2016-01-29 23:23 -------- d-----w- c:program filesRaptr
2016-01-29 22:58 . 2016-01-29 22:58 -------- d-----w- c:program filesAMD AVT
2016-01-29 22:11 . 2016-01-29 22:11 -------- d-----w- c:program filesCommon FilesATI Technologies
2016-01-29 22:10 . 2016-01-29 23:20 -------- d-----w- c:program filesAMD
2016-01-29 22:09 . 2016-01-29 23:18 -------- d-----w- C:AMD
2016-01-24 08:22 . 2016-01-24 08:22 -------- d-----w- c:program filesflaxess
2016-01-23 20:44 . 2016-01-24 02:58 -------- d-----w- c:usersRynduseAppDataRoaming.minecraft
2016-01-22 13:49 . 2016-01-22 13:49 -------- d-----w- c:program filesCommon FilesJava
2016-01-21 17:41 . 2016-01-30 16:55 -------- d-----w- c:program filesValve
2016-01-20 07:03 . 2016-01-20 20:49 -------- d-----w- c:program filesAMX Mod X
2016-01-20 04:40 . 2016-01-20 05:19 -------- d-----w- C:HLDS
2016-01-19 19:26 . 2016-01-19 19:26 -------- d-----w- C:Games
2016-01-18 01:01 . 2016-01-18 01:01 -------- d-----w- c:program filesOyunSunucum
2016-01-17 22:55 . 2016-01-17 22:55 -------- d-----w- c:program filesMicrosoft Virtual PC
2016-01-15 19:59 . 2016-01-15 19:59 -------- d-----w- c:programdataAVS4YOU
2016-01-15 19:59 . 2016-01-15 19:59 -------- d-----w- c:usersRynduseAppDataRoamingAVS4YOU
2016-01-15 19:58 . 2016-01-15 21:39 -------- d-----w- c:program filesCommon FilesAVSMedia
2016-01-15 19:58 . 2016-01-15 21:39 -------- d-----w- c:program filesAVS4YOU
2016-01-15 19:58 . 2011-06-23 10:26 1700352 ----a-w- c:windowssystem32GdiPlus.dll
2016-01-15 19:58 . 2011-06-23 10:25 24576 ----a-w- c:windowssystem32msxml3a.dll
2016-01-15 19:28 . 2016-01-15 20:32 -------- d-----w- c:programdataFreemake
2016-01-15 19:28 . 2016-01-15 20:31 -------- d-----w- c:program filesFreemake
2016-01-12 13:39 . 2016-01-12 13:39 -------- d-----w- c:programdataMalwarebytes
2016-01-12 13:35 . 2016-01-12 13:35 -------- d-----w- c:usersRynduseAppDataRoamingeCyber
2016-01-12 13:30 . 2016-01-12 13:48 -------- d-----w- c:programdataSWdMS
2016-01-10 17:17 . 2016-01-10 17:17 -------- d-----w- c:program filesITSecTeam
2016-01-10 17:10 . 2004-03-09 10:00 124688 ----a-w- c:windowssystem32Mswinsck.ocx
2016-01-10 17:10 . 2004-03-09 10:00 1081616 ----a-w- c:windowssystem32Mscomctl.ocx
2016-01-10 17:10 . 2001-02-20 13:17 140288 ----a-w- c:windowssystem32comdlg32.ocx
2016-01-10 17:10 . 2000-12-06 09:30 209608 ----a-w- c:windowssystem32tabctl32.ocx
2016-01-10 17:10 . 1998-06-24 08:30 115016 ----a-w- c:windowssystem32MSInet.ocx
2016-01-10 17:10 . 2009-09-09 21:36 260096 ----a-w- c:windowssystem32RICHTX32.ocx
2016-01-10 10:21 . 2016-01-10 10:21 -------- d-----w- c:usersRynduseAppDataRoamingLolClient
2016-01-10 07:58 . 2016-01-10 07:58 -------- d-----w- c:program filesZ8Games
2016-01-09 22:24 . 2016-01-09 22:29 -------- d-----w- C:Perl
2016-01-09 18:23 . 2016-01-09 18:23 -------- d-----w- c:programdataRiot Games
2016-01-09 18:15 . 2008-07-12 06:18 467984 ----a-w- c:windowssystem32d3dx10_39.dll
2016-01-09 18:15 . 2008-07-12 06:18 1493528 ----a-w- c:windowssystem32D3DCompiler_39.dll
2016-01-09 18:15 . 2008-07-12 06:18 3851784 ----a-w- c:windowssystem32D3DX9_39.dll
2016-01-09 18:14 . 2016-01-23 04:24 -------- d-----w- c:usersRynduseAppDataRoamingRiot Games
2016-01-09 14:07 . 2016-01-17 13:56 -------- d-----w- c:usersRynduseAppDataRoamingHLSW
2016-01-09 14:07 . 2016-01-09 14:07 -------- d-s---w- c:program filesHLSW
2016-01-09 14:05 . 2016-01-30 16:55 16043 ----a-w- c:usersRynduseAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupreload.vbs
2016-01-08 23:57 . 2016-01-08 23:58 -------- d-----w- c:usersRynduseAppDataLocalAdobe
2016-01-08 23:57 . 2016-01-08 23:57 -------- d-----w- c:program filesCommon FilesAdobe
2016-01-08 23:57 . 2016-01-08 23:57 -------- d-----w- c:usersRynduseAppDataLocalSpoon
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2016-01-22 13:49 . 2015-12-14 22:10 95840 ----a-w- c:windowssystem32WindowsAccessBridge.dll
2016-01-20 04:22 . 2015-12-06 01:28 164880 ---ha-w- c:usersRynduseAppDataRoamingMicrosoftVirtual PCVPCKeyboard.dll
2015-12-16 23:29 . 2013-08-22 12:40 35288 ----a-w- c:windowssystem32driverstap0901.sys
2015-12-14 22:27 . 2015-12-14 22:27 796864 ----a-w- c:windowssystem32FlashPlayerApp.exe
2015-12-14 22:27 . 2015-12-14 22:27 142528 ----a-w- c:windowssystem32FlashPlayerCPLApp.cpl
2015-12-03 20:17 . 2009-07-13 23:40 409088 ----a-w- c:windowssystem32systemcpl.dll
2015-12-03 20:17 . 2009-07-13 23:36 13824 ----a-w- c:windowssystem32slwga.dll
2015-12-03 20:17 . 2009-07-13 23:24 811520 ----a-w- c:windowssystem32user32.dll
2015-12-02 05:36 . 2015-12-02 05:36 248672 ----a-w- c:windowssystem32d3dx11_43.dll
2015-12-02 05:36 . 2015-12-02 05:36 2106216 ----a-w- c:windowssystem32D3DCompiler_43.dll
2015-12-02 05:36 . 2015-12-02 05:36 182432 ----a-w- c:windowssystem32vcomp140.dll
2015-11-17 05:43 . 2015-12-03 19:01 8991856 ----a-w- c:programdataMicrosoftWindows DefenderDefinition Updates{E16BC9B7-AD65-465C-BF79-8058EB5DE5BB}mpengine.dll
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2015-12-03 . 7BD7F45FF37FA0669CD32CA0EF46E22C . 811520 . . [6.1.7600.16385] . . c:windowsSystem32user32.dll
[7] 2009-07-14 . 34B7E222E81FAFA885F0C5F2CFA56861 . 811520 . . [6.1.7600.16385] . . c:windowswinsxsx86_microsoft-windows-user32_31bf3856ad364e35_6.1.7600.16385_none_cd0ec264ceb014a3user32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRun]
"Sidebar"="c:program filesWindows Sidebarsidebar.exe" [2009-07-14 1173504]
"GoogleChromeAutoLaunch_24D20C11096602DA59EED06DB366DFB2"="c:program filesGoogleChromeApplicationchrome.exe" [2016-01-27 748872]
.
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun]
"SunJavaUpdateSched"="c:program filesCommon FilesJavaJava Updatejusched.exe" [2015-12-22 596528]
"StartCCC"="c:program filesAMDATI.ACECore-Staticx86CLIStart.exe" [2014-11-20 748232]
"Raptr"="c:progra~1Raptrraptrstub.exe" [2015-12-11 56080]
.
c:usersRynduseAppDataRoamingMicrosoftWindowsStart MenuProgramsStartup
reload.vbs [2016-1-30 16043]
.
[HKEY_LOCAL_MACHINEsoftwaremicrosoftwindowscurrentversionpoliciessystem]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKLM~startupfolderC:^Users^Rynduse^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Cs Serverları.lnk]
path=c:usersRynduseAppDataRoamingMicrosoftWindowsStart MenuProgramsStartupCs Serverları.lnk
backup=c:windowspssCs Serverları.lnk.Startup
backupExtension=.Startup
.
[HKEY_LOCAL_MACHINEsoftwaremicrosoftshared toolsmsconfigstartupregGoogleChromeAutoLaunch_24D20C11096602DA59EED06DB366DFB2]
2016-01-27 17:39 748872 ----a-w- c:program filesGoogleChromeApplicationchrome.exe
.
R3 EasyAntiCheat;EasyAntiCheat;c:windowssystem32EasyAntiCheat.exe [2016-01-22 239904]
R3 EasyAntiCheatSys;EasyAntiCheatSys;c:windowssystem32driversEasyAntiCheat.sys [2016-01-30 191992]
R3 glynnxxGE;glynnxxGE;c:usersRynduseDesktopIntelligent Aimbot Gold Edition Crackedglynnharr.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:windowssystem32driversMBAMSwissArmy.sys [x]
R3 vmci;VMware VMCI Bus Driver;c:windowssystem32DRIVERSvmci.sys [x]
R3 WatAdminSvc;Windows Etkinleştirme Teknolojileri Hizmeti;c:windowssystem32WatWatAdminSvc.exe [2015-12-03 1343400]
R3 XDva534;XDva534;c:windowssystem32XDva534.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:windowssystem32atiesrxx.exe [2014-11-21 212992]
S2 AMD FUEL Service;AMD FUEL Service;c:program filesATI TechnologiesATI.ACEFuelFuel.Service.exe [2014-08-19 276992]
S2 AODDriver4.3;AODDriver4.3;c:program filesATI TechnologiesATI.ACEFueli386AODDriver2.sys [2014-02-11 50400]
S3 AtcL001;Atheros L1 Gigabit Ethernet Denetleyicisi için NDIS Miniport Sürücüsü;c:windowssystem32DRIVERSl160x86.sys [2009-07-13 47104]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:windowssystem32driversAtihdW73.sys [2015-09-18 78848]
S3 netr28u;RT2870 USB Extensible Wireless LAN Card Driver;c:windowssystem32DRIVERSnetr28u.sys [2011-09-09 1265216]
S3 usbfilter;AMD USB Filter Driver;c:windowssystem32DRIVERSusbfilter.sys [2000-01-01 48352]
.
.
[HKEY_LOCAL_MACHINEsoftwaremicrosoftactive setupinstalled components{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2016-01-29 22:13 1090376 ----a-w- c:program filesGoogleChromeApplication48.0.2564.97Installerchrmstp.exe
.
Contents of the 'Scheduled Tasks' folder
.
2016-01-30 c:windowsTasksGoogleUpdateTaskMachineCore.job
- c:program filesGoogleUpdateGoogleUpdate.exe [2015-12-03 19:01]
.
2016-01-30 c:windowsTasksGoogleUpdateTaskMachineUA.job
- c:program filesGoogleUpdateGoogleUpdate.exe [2015-12-03 19:01]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.oyunsunucum.com
mStart Page = www.google.com
uInternet Settings,ProxyServer = 213.136.79.122:80
uInternet Settings,ProxyOverride = local
TCP: Interfaces{20347811-ACBB-49F1-8BFF-62A3DA5C3326}: NameServer = 8.8.8.8,8.8.4.4
.
- - - - ORPHANS REMOVED - - - -
.
AddRemove-Counter-Strike Global Offensive_is1 - d:program filesCounter-Strike Global Offensiveunins000.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINESYSTEMControlSet001ControlPCWSecurity]
@Denied: (Full) (Everyone)
.
Completion time: 2016-01-30 20:37:47
ComboFix-quarantined-files.txt 2016-01-30 18:37
ComboFix2.txt 2015-12-17 22:01
.
Pre-Run: 90.208.751.616 bayt boş
Post-Run: 90.434.813.952 bayt boş
.
- - End Of File - - 76118886D743087840E173FA65E7A715
EA923EB0EC0060F1451E9AD7B5762CFE
     
 
what is notes.io
 

Notes.io is a web-based application for taking notes. You can take your notes and share with others people. If you like taking long notes, notes.io is designed for you. To date, over 8,000,000,000 notes created and continuing...

With notes.io;

  • * You can take a note from anywhere and any device with internet connection.
  • * You can share the notes in social platforms (YouTube, Facebook, Twitter, instagram etc.).
  • * You can quickly share your contents without website, blog and e-mail.
  • * You don't need to create any Account to share a note. As you wish you can use quick, easy and best shortened notes with sms, websites, e-mail, or messaging services (WhatsApp, iMessage, Telegram, Signal).
  • * Notes.io has fabulous infrastructure design for a short link and allows you to share the note as an easy and understandable link.

Fast: Notes.io is built for speed and performance. You can take a notes quickly and browse your archive.

Easy: Notes.io doesn’t require installation. Just write and share note!

Short: Notes.io’s url just 8 character. You’ll get shorten link of your note when you want to share. (Ex: notes.io/q )

Free: Notes.io works for 12 years and has been free since the day it was started.


You immediately create your first note and start sharing with the ones you wish. If you want to contact us, you can use the following communication channels;


Email: [email protected]

Twitter: http://twitter.com/notesio

Instagram: http://instagram.com/notes.io

Facebook: http://facebook.com/notesio



Regards;
Notes.io Team

     
 
Shortened Note Link
 
 
Looding Image
 
     
 
Long File
 
 

For written notes was greater than 18KB Unable to shorten.

To be smaller than 18KB, please organize your notes, or sign in.