Sağolasın hocam da denedim olmadı acaba herhangi bir driverdan kaynaklanıyormu diye bi kaç tanesini yeniden yükledim. (ekran kartı-ethernet) birde biosu güncelledim. aşağıda da combofix in log dosyası var. bahsettiğim plfovq.sys ile ilgili birşeyler diyor ama anlamadım. taramadan sonra yerine baktığımda duruyordu ve hala aynı şekilde. tek sevindiğim nokta da hackhell e girdiğimde mavi ekran vermemiş olması
ComboFix 11-04-20.04 - s1 21.04.2011 18:30:07.2.2 - x86
Microsoft Windows 7 Ultimate 6.1.7600.0.1254.90.1055.18.2013.680 [GMT 3:00]
Running from: c:\users\s1\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Outdated* {090F9C29-64CE-6C6F-379C-5901B49A85B7}
SP: AntiVir Desktop *Enabled/Outdated* {B26E7DCD-42F4-63E1-0D2C-6273CF1DCF0A}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\program files\Error Repair Professional
c:\program files\Error Repair Professional\Backups\Backup_19-32-48_15-4-2011.reg
c:\program files\Error Repair Professional\Backups\file_id.diz
c:\program files\Error Repair Professional\file_id.diz
c:\program files\Error Repair Professional\startbug\file_id.diz
c:\users\s1\AppData\Roaming\install
.
.
((((((((((((((((((((((((( Files Created from 2011-03-21 to 2011-04-21 )))))))))))))))))))))))))))))))
.
.
2011-04-21 15:34 . 2011-04-21 15:34 -------- d-----w- c:\users\s1\AppData\Local\temp
2011-04-21 15:34 . 2011-04-21 15:34 -------- d-----w- c:\users\Public\AppData\Local\temp
2011-04-21 15:34 . 2011-04-21 15:34 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-04-19 09:55 . 2011-04-19 09:55 -------- d-----w- c:\users\s1\AppData\Local\Microsoft Corporation
2011-04-19 09:54 . 2011-04-19 09:54 -------- d-----w- c:\program files\Microsoft Windows 7 Upgrade Advisor
2011-04-06 16:35 . 2011-04-06 16:39 -------- d-----w- c:\program files\Hewlett-Packard
2011-04-06 16:35 . 2011-04-06 16:38 -------- d-----w- c:\users\s1\AppData\Roaming\hpqLog
2011-04-06 16:35 . 2011-04-06 16:35 -------- d-----w- c:\programdata\{23D58E70-3B83-4B83-A227-68770F84F5EC}
2011-04-06 16:34 . 2011-04-06 16:34 -------- d-----w- C:\system.sav
2011-04-06 16:34 . 2011-04-06 16:34 -------- d-----w- c:\users\s1\AppData\Roaming\WinBatch
2011-04-06 16:34 . 2011-04-06 16:34 -------- d-----w- c:\program files\Common Files\Intel
2011-04-06 16:34 . 2011-04-06 16:34 -------- d-----w- c:\program files\Intel
2011-04-06 16:33 . 2011-04-06 16:33 -------- d-----w- C:\Intel
2011-04-06 16:32 . 2011-04-06 16:33 -------- d-----w- C:\swsetup
2011-04-06 05:26 . 2011-04-06 05:26 801792 ----a-w- c:\windows\system32\FntCache.dll
2011-04-06 05:26 . 2011-04-06 05:26 739840 ----a-w- c:\windows\system32\d2d1.dll
2011-04-06 05:26 . 2011-04-06 05:26 728448 ----a-w- c:\windows\system32\drivers\dxgkrnl.sys
2011-04-06 05:26 . 2011-04-06 05:26 283648 ----a-w- c:\windows\system32\XpsGdiConverter.dll
2011-04-06 05:26 . 2011-04-06 05:26 219008 ----a-w- c:\windows\system32\drivers\dxgmms1.sys
2011-04-06 05:26 . 2011-04-06 05:26 218624 ----a-w- c:\windows\system32\d3d10_1core.dll
2011-04-06 05:26 . 2011-04-06 05:26 161792 ----a-w- c:\windows\system32\d3d10_1.dll
2011-04-06 05:26 . 2011-04-06 05:26 1495040 ----a-w- c:\windows\system32\ExplorerFrame.dll
2011-04-06 05:26 . 2011-04-06 05:26 135168 ----a-w- c:\windows\system32\XpsRasterService.dll
2011-04-06 05:26 . 2011-04-06 05:26 1170944 ----a-w- c:\windows\system32\d3d10warp.dll
2011-04-06 05:26 . 2011-04-06 05:26 107520 ----a-w- c:\windows\system32\cdd.dll
2011-04-06 05:26 . 2011-04-06 05:26 1074176 ----a-w- c:\windows\system32\DWrite.dll
2011-04-06 05:26 . 2011-04-06 05:26 442880 ----a-w- c:\windows\system32\XpsPrint.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-03-31 13:33 . 2010-10-18 13:51 137656 ----a-w- c:\windows\system32\drivers\avipbb.sys
2011-03-09 06:20 . 2010-06-24 09:33 18328 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2011-02-12 13:13 . 2011-02-12 13:13 392 --sha-r- c:\windows\system32\8AD1.CMD
2011-01-29 13:15 . 2011-01-29 13:15 394 --sha-r- c:\windows\system32\E550.CMD
2011-03-18 18:07 . 2011-04-06 14:46 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2010-09-22 4240760]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-11-11 39408]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2011-01-26 15026056]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"NeroCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-01-31 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-26 31016]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-04-21 136216]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-04-21 171032]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-04-21 169496]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-11-04 281768]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-23 270336]
imagePROGRAF Status Monitor.lnk - c:\program files\Canon\imagePROGRAFStatusMonitor\cnwism.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"="0"
"FirewallOverride"="0"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
"AntiVirusDisableNotify"=dword:00000001
"FirewallDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"UacDisableNotify"=dword:00000001
.
R2 gupdate;Google Güncelleme Hizmeti (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-09-07 136176]
R3 WPRO_40_1340;WinPcap Packet Driver (WPRO_40_1340);c:\windows\system32\drivers\WPRO_40_1340.sys [x]
R3 WSDPrintDevice;UMB Üzerinden WSD Yazdırma Desteği;c:\windows\system32\DRIVERS\WSDPrint.sys [2009-07-14 17920]
S0 tdrpman251;Acronis Try&Decide and Restore Points filter (build 251);c:\windows\system32\DRIVERS\tdrpm251.sys [2010-07-08 902432]
S2 afcdpsrv;Acronis Nonstop Backup service;c:\program files\Common Files\Acronis\CDP\afcdpsrv.exe [2010-07-08 2326920]
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2010-11-04 135336]
S2 Canon imagePROGRAF Status Monitor;Canon imagePROGRAF Status Monitor;c:\program files\Canon\imagePROGRAFStatusMonitor\cnwisam.exe [2009-10-09 688912]
S2 HP LaserJet Service;HP LaserJet Service;c:\program files\HP\HPLaserJetService\HPLaserJetService.exe [2010-03-03 136192]
S2 HPDrvMntSvc.exe;HP Quick Synchronization Service;c:\program files\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2010-10-14 92216]
S2 iPFDeviceAgentService;iPF Device Agent Service;c:\windows\system32\Cnwiolss.exe [2008-12-08 161280]
S3 afcdp;afcdp;c:\windows\system32\DRIVERS\afcdp.sys [2010-07-08 159168]
S3 RTL8167;Realtek 8167 NT Sürücüsü;c:\windows\system32\DRIVERS\Rt86win7.sys [2009-07-13 139776]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - plfovq
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-07 06:15]
.
2011-02-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-09-07 06:15]
.
2011-02-24 c:\windows\Tasks\User_Feed_Synchronization-{D74E1F17-B3B3-4C67-9DED-43413E69D309}.job
- c:\windows\system32\msfeedssync.exe [2011-04-06 05:28]
.
2011-02-25 c:\windows\Tasks\{FF1EA5D6-7529-4513-AB7F-F18872D83EDA}.job
- c:\program files\Skype\Phone\Skype.exe [2011-01-26 15:05]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com.tr/
IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_D183CA64F05FDD98.dll/cmsidewiki.html
IE: Microsoft Excel'e &Ver - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044} - hxxp://213.248.136.171:8081/activex/AMC.cab
FF - ProfilePath - c:\users\s1\AppData\Roaming\Mozilla\Firefox\Profiles\fpzlmn0j.default\
.
.
------- File Associations -------
.
.scr=AutoCADScriptFile
.
- - - - ORPHANS REMOVED - - - -
.
URLSearchHooks-{ba14329e-9550-4989-b3f2-9732e92d17cc} - (no file)
WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
AddRemove-{08DB3902-2CE0-474D-BCE3-0177766CE9F1} - c:\program files\InstallShield Installation Information\{08DB3902-2CE0-474D-BCE3-0177766CE9F1}\setup.exe
AddRemove-{5FA67C2B-DAAB-4F7B-AE09-CA97FE73EA59} - c:\program files\HP\Digital Imaging\{5FA67C2B-DAAB-4F7B-AE09-CA97FE73EA59}\setup\hpzscr01.exe
AddRemove-{C8A37F1F-E13B-48ae-93F8-4669264969F9} - c:\program files\HP\Digital Imaging\{C8A37F1F-E13B-48ae-93F8-4669264969F9}\setup\hpzscr01.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\plfovq]
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2011-04-21 18:36:11
ComboFix-quarantined-files.txt 2011-04-21 15:36
ComboFix2.txt 2010-10-18 14:13
.
Pre-Run: 21.285.961.728 bayt boş
Post-Run: 21.155.524.608 bayt boş
.
- - End Of File - - EC7110E5ED135310F7BE76CB8EED0C3D