i just saw ur response,here u are.
sorry but it's still too big to fit in. it gives an error mesaage so i just put the additon file here.
btw . hitmanpro is still finding 2 trojans and 2 riskwares and 1 suspicous registry something ( i just checked didn do any action with them.)!
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 15-03-2017
Ran by ozg (14-04-2017 02:09:50)
Running from C:\Documents and Settings\ozg\Desktop
Microsoft Windows XP Professional Service Pack 3 (X86) (2017-04-11 18:41:16)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1214440339-1343024091-1202660629-500 - Administrator - Enabled)
ASPNET (S-1-5-21-1214440339-1343024091-1202660629-1005 - Limited - Enabled)
Guest (S-1-5-21-1214440339-1343024091-1202660629-501 - Limited - Disabled)
HelpAssistant (S-1-5-21-1214440339-1343024091-1202660629-1000 - Limited - Disabled)
ozg (S-1-5-21-1214440339-1343024091-1202660629-1003 - Administrator - Enabled) => %SystemDrive%\Documents and Settings\ozg
SUPPORT_388945a0 (S-1-5-21-1214440339-1343024091-1202660629-1002 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-1214440339-1343024091-1202660629-1003\...\uTorrent) (Version: 3.5.0.43580 - BitTorrent Inc.)
1.0.0.1 (HKLM\...\YeaDesktop) (Version: 1.0.0.1 - )
7-Zip 16.04 (HKLM\...\7-Zip) (Version: 16.04 - Igor Pavlov)
Adobe Flash Player 25 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 25.0.0.148 - Adobe Systems Incorporated)
AIDA64 Engineer v4.30 (HKLM\...\AIDA64 Engineer_is1) (Version: 4.30 - FinalWire Ltd.)
Alarmlı Sayısal Saat Kaldır (HKLM\...\Alarmli Sayisal Saat 2.11) (Version: - )
ATI - Yazılım Kaldır Yardımcı Programı (HKLM\...\All ATI Software) (Version: 6.14.10.1012 - )
ATI Catalyst Control Center (HKLM\...\{C18F4235-BF97-4284-8318-7EFF20B0D07B}) (Version: 1.2.2044.226 - )
ATI Display Driver (HKLM\...\ATI Display Driver) (Version: 8.162-050803a2-025790C-NEC CI - )
Autorun Virus Remover 3.2 (HKLM\...\Autorun Virus Remover_is1) (Version: - Autorun Remover)
Barbarian Invasion (HKLM\...\{FD69C8CB-6964-432C-98AB-A5A09ED50EEA}) (Version: 1.4 - )
BrainWave Generator (HKLM\...\BrainWave Generator) (Version: - )
CCleaner (HKLM\...\CCleaner) (Version: 5.28 - Piriform)
CDBurnerXP (HKLM\...\{7E265513-8CDA-4631-B696-F40D983F3B07}_is1) (Version: 4.0.024.439 - CDBurnerXP)
ChessBase Reader (HKLM\...\{9664C520-5725-4885-B286-A4EC43A6B738}) (Version: 12.32.0.0 - ChessBase)
ConvertHelper 2.2 (HKLM\...\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF51}_is1) (Version: - DownloadHelper)
EB Documentation 1.1 (HKLM\...\EB Documentation_is1) (Version: - Europa Barbarorum)
EB Trivial Script 0.125 (HKLM\...\EB Trivial Script_is1) (Version: - EuropaBarbarorum)
Europa Barbarorum 1.1 (HKLM\...\{9BCAC864-84C0-409F-8D12-364109622D18}_is1) (Version: - Europa Barbarorum)
Europa Barbarorum 1.2 (HKLM\...\{AD3E68F5-D141-49C0-B002-28B48030B902}_is1) (Version: - Europa Barbarorum)
Foxit Cloud (HKLM\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.3.99.311 - Foxit Corporation)
Foxit Reader (HKLM\...\Foxit Reader_is1) (Version: 6.2.0.429 - Foxit Corporation)
GOM Player (HKLM\...\GOM Player) (Version: 2.2.77.5240 - Gretech Corporation)
HitmanPro 3.7 (HKLM\...\HitmanPro37) (Version: 3.7.18.284 - SurfRight B.V.)
Java 7 Update 67 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F03217067FF}) (Version: 7.0.670 - Oracle)
KMPlayer (remove only) (HKLM\...\The KMPlayer) (Version: 4.0.5.3 - PandoraTV)
Logitech SetPoint 6.65 (HKLM\...\sp6) (Version: 6.65.62 - Logitech)
Malwarebytes Anti-Malware version 2.0.1.1004 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
Microsoft .NET Framework 1.1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 2.0 Service Pack 2 (HKLM\...\{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}) (Version: 2.2.30729 - Microsoft Corporation)
Microsoft Office Excel Viewer (HKLM\...\{95120000-003F-041F-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 52.0.2 ESR (x86 tr) (HKLM\...\Mozilla Firefox 52.0.2 ESR (x86 tr)) (Version: 52.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 52.0.2 - Mozilla)
OpenOffice 4.1.1 (HKLM\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
Opera Stable 36.0.2130.80 (HKLM\...\Opera 36.0.2130.80) (Version: 36.0.2130.80 - Opera Software)
PlayChess (HKLM\...\PlayChess) (Version: - ChessBase GmbH)
Potplayer (HKLM\...\PotPlayer) (Version: - Kakao Corp.)
PowerISO (HKLM\...\PowerISO) (Version: 6.8 - Power Software Ltd)
REALTEK Gigabit and Fast Ethernet NIC Driver (HKLM\...\{94FB906A-CF42-4128-A509-D353026A607E}) (Version: 1.70 - REALTEK Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 1.87 - Realtek Semiconductor Corp.)
Recruitment Viewer 0.9 (HKLM\...\Recruitment Viewer_is1) (Version: - EuropaBarbarorum)
Rome - Total War(TM) (HKLM\...\InstallShield_{A642BB6B-CA1D-4142-8DD4-318C3F3DC834}) (Version: 1.0 - Activision)
Rome - Total War(TM) (Version: 1.0 - Activision) Hidden
Spybot - Search & Destroy (HKLM\...\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.3.39 - Safer-Networking Ltd.)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1240 - SUPERAntiSpyware.com)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 8.0.13.0 - Synaptics)
Texas Instruments PCIxx21/x515 drivers. (HKLM\...\InstallShield_{406A5ABF-CA65-4E11-95C7-52228FE48F58}) (Version: 1.11.0000 - Texas Instruments Inc.)
TIxx21 (Version: 1.11.0000 - Texas Instruments Inc.) Hidden
Tweaking.com - Registry Backup (HKLM\...\Tweaking.com - Registry Backup) (Version: 3.5.3 - Tweaking.com)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
WebFldrs XP (Version: 9.50.7523 - Microsoft Corporation) Hidden
Winamp (HKLM\...\Winamp) (Version: 5.666 - Nullsoft, Inc)
Windows Driver Package - Intel (NETw4x32) net (09/26/2007 11.5.0.32) (HKLM\...\5D81FBED6E61194F43FF1556F43BD8309BA44634) (Version: 09/26/2007 11.5.0.32 - Intel)
Windows Driver Package - Intel (w29n51) net (07/25/2007 9.0.4.37) (HKLM\...\EFD65E7CD7A28D00217941F33C5CA55964F96136) (Version: 07/25/2007 9.0.4.37 - Intel)
Windows Driver Package - Intel net (09/26/2007 11.5.0.32) (HKLM\...\0BF49E9448DA0DFB69DB9D673379652AB9087171) (Version: 09/26/2007 11.5.0.32 - Intel)
Zemana AntiMalware (HKLM\...\{8F0CD7D1-42F3-4195-95CD-833578D45057}_is1) (Version: 2.72.0.388 - Zemana Ltd.)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Check for updates (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
Task: C:\WINDOWS\Tasks\defrag.job => C:\WINDOWS\system32\defrag.exe
Task: C:\WINDOWS\Tasks\Opera scheduled Autoupdate 1491967284.job => C:\Program Files\Opera\launcher.exe
Task: C:\WINDOWS\Tasks\Refresh immunization (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDImmunize.exe
Task: C:\WINDOWS\Tasks\Scan the system (Spybot - Search & Destroy).job => C:\Program Files\Spybot - Search & Destroy 2\SDScan.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Europa Barbarorum\Validate Install.lnk -> D:\Program Files\Activision\Rome - Total War\validateInstall.bat ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\Europa Barbarorum\Validate Installation.lnk -> D:\Program Files\Activision\Rome - Total War\validateInstall.bat ()
Shortcut: C:\Documents and Settings\All Users\Start Menu\Programs\AutorunRemover\AutorunRemover on the Web.lnk -> hxxp://www.autorunremover.com
==================== Loaded Modules (Whitelisted) ==============
2017-04-12 00:48 - 2014-04-25 14:11 - 00109400 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2017-04-12 00:48 - 2014-04-25 14:11 - 00416600 _____ () C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
2017-04-13 23:46 - 2017-04-13 23:46 - 00130928 _____ () C:\Program Files\Zemana AntiMalware\ZAMShellExt32.dll
2017-04-12 00:38 - 2013-03-28 17:27 - 01929216 _____ () C:\Program Files\AutorunRemover\AutorunRemover.exe
2017-04-12 06:48 - 2008-03-09 11:20 - 00071096 _____ () C:\Program Files\CDBurnerXP\NMSAccessU.exe
2017-04-12 00:48 - 2014-04-25 14:11 - 00167768 _____ () C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2017-04-12 00:48 - 2012-08-23 10:38 - 00574840 _____ () C:\Program Files\Spybot - Search & Destroy 2\sqlite3.dll
2017-04-12 00:48 - 2012-04-03 17:06 - 00565640 _____ () C:\Program Files\Spybot - Search & Destroy 2\av\BDSmartDB.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2017-04-11 21:07 - 2017-04-13 21:40 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1214440339-1343024091-1202660629-1003\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Bliss.bmp
DNS Servers: 192.168.2.1
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupfolder: C:^Documents and Settings^All Users^Start Menu^Programs^Startup^ATI CATALYST System Tray.lnk => C:\WINDOWS\pss\ATI CATALYST System Tray.lnkCommon Startup
MSCONFIG\startupreg: Alcmtr => ALCMTR.EXE
MSCONFIG\startupreg: ATICCC => "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: CTFMON.EXE => C:\WINDOWS\system32\ctfmon.exe
MSCONFIG\startupreg: PWRISOVM.EXE => C:\Program Files\PowerISO\PWRISOVM.EXE -startup
MSCONFIG\startupreg: RTHDCPL => RTHDCPL.EXE
MSCONFIG\startupreg: SDTray => "C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe"
MSCONFIG\startupreg: SpybotPostWindows10UpgradeReInstall => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
MSCONFIG\startupreg: ZAM => "C:\Program Files\Zemana AntiMalware\ZAM.exe" /minimized
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
DomainProfile\AuthorizedApplications: [C:\Program Files\Winamp\winamp.exe] => Enabled:Winamp
StandardProfile\AuthorizedApplications: [C:\Program Files\Winamp\winamp.exe] => Enabled:Winamp
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D 2 Background update service
StandardProfile\AuthorizedApplications: [C:\Program Files\Mozilla Firefox\firefox.exe] => Enabled:Firefox (C:\Program Files\Mozilla Firefox)
StandardProfile\AuthorizedApplications: [C:\Documents and Settings\ozg\Application Data\uTorrent\uTorrent.exe] => Enabled:μTorrent
==================== Restore Points =========================
11-04-2017 21:45:11 System Checkpoint
11-04-2017 22:52:35 REALTEK Gigabit and Fast Ethernet NIC Driver
11-04-2017 22:53:39 Installed ATI Catalyst Control Center
11-04-2017 23:01:17 Installed Realtek High Definition Audio Driver
11-04-2017 23:03:45 Installed TIxx21
11-04-2017 23:06:59 REALTEK Gigabit and Fast Ethernet NIC Driver
12-04-2017 00:10:16 Installed Windows XP Wdf01009.
12-04-2017 00:14:40 Installed DirectX
12-04-2017 00:15:31 Microsoft Office Excel Viewer Yüklendi
12-04-2017 00:20:08 Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
12-04-2017 00:21:20 Installed OpenOffice 4.1.1
12-04-2017 00:22:57 Installed Windows Media Player 9 Series
12-04-2017 00:47:19 Printer Driver Foxit Reader PDF Printer Driver Installed
12-04-2017 01:14:50 Installed Java 7 Update 67
12-04-2017 01:25:59 Removed Java 8 Update 25
12-04-2017 04:58:46 Installed ChessBase Reader
12-04-2017 06:49:59 Installed Rome - Total War(TM)
12-04-2017 08:11:56 Installed Barbarian Invasion
12-04-2017 08:15:27 Installed Rome - Total War - Barbarian Invasion - patch 1.6
12-04-2017 19:43:15 HitmanPro Kontrol Noktası
12-04-2017 19:43:38 HitmanPro Kontrol Noktası
12-04-2017 20:02:22 HitmanPro Kontrol Noktası
13-04-2017 03:00:19 Software Distribution Service 3.0
13-04-2017 21:40:30 Restore Point Created by FRST
==================== Faulty Device Manager Devices =============
Name: Modem Device on High Definition Audio Bus
Description: Modem Device on High Definition Audio Bus
Class Guid: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (04/12/2017 08:35:19 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application kube.exe, version 1.0.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (04/12/2017 08:35:13 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application Bestziper.tmp, version 51.52.0.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (04/12/2017 08:33:52 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application codecfixdivx.exe, version 0.0.0.0, faulting module shell32.dll, version 6.0.2900.6242, fault address 0x0002ecae.
Processing media-specific event for [codecfixdivx.exe!ws!]
Error: (04/12/2017 06:26:53 PM) (Source: Application Hang) (EventID: 1001) (User: )
Description: Fault bucket 219665503.
Error: (04/12/2017 06:26:39 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Hanging application SDUpdate.exe, version 2.3.39.94, hang module hungapp, version 0.0.0.0, hang address 0x00000000.
Error: (04/12/2017 06:20:52 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application icedragonsetup.exe, version 50.0.0.2, faulting module icedragonplugin.dll, version 0.0.0.0, fault address 0x00019ffc.
Processing media-specific event for [icedragonsetup.exe!ws!]
Error: (04/12/2017 12:31:46 AM) (Source: PerfNet) (EventID: 2004) (User: )
Description: Unable to open the Server service. Server performance data
will not be returned. Error code returned is in data DWORD 0.
Error: (04/12/2017 12:31:45 AM) (Source: PerfNet) (EventID: 2004) (User: )
Description: Unable to open the Server service. Server performance data
will not be returned. Error code returned is in data DWORD 0.
Error: (04/12/2017 12:16:37 AM) (Source: MsiInstaller) (EventID: 1023) (User: PC)
Description: Product: Microsoft Office Excel Viewer - Update '{5E5BD655-7AA9-47F9-BB6D-A1D8CE29AC86}' could not be installed. Error code 1642. Additional information is available in the log file C:\DOCUME~1\ozg\LOCALS~1\Temp\Microsoft Office Excel Viewer (0).log.
Error: (04/12/2017 12:16:37 AM) (Source: MsiInstaller) (EventID: 1023) (User: PC)
Description: Product: Microsoft Office Excel Viewer - Update '{47637B5E-81E0-4ECA-82F9-13FE9B204BE3}' could not be installed. Error code 1642. Additional information is available in the log file C:\DOCUME~1\ozg\LOCALS~1\Temp\Microsoft Office Excel Viewer (0).log.
System errors:
=============
Error: (04/14/2017 01:10:43 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:
Spybot-S&D 2 Security Center Service is not a valid Win32 application.
Error: (04/14/2017 12:00:05 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service.
Error: (04/13/2017 10:44:14 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:
Spybot-S&D 2 Security Center Service is not a valid Win32 application.
Error: (04/13/2017 10:37:10 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:
Spybot-S&D 2 Security Center Service is not a valid Win32 application.
Error: (04/13/2017 10:28:03 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:
Spybot-S&D 2 Security Center Service is not a valid Win32 application.
Error: (04/13/2017 10:13:53 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D 2 Security Center Service service failed to start due to the following error:
Spybot-S&D 2 Security Center Service is not a valid Win32 application.
Error: (04/13/2017 10:11:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Application Layer Gateway Service service terminated unexpectedly. It has done this 1 time(s).
Error: (04/13/2017 10:11:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The NMSAccessU service terminated unexpectedly. It has done this 1 time(s).
Error: (04/13/2017 10:11:18 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Foxit Cloud Safe Update Service service terminated unexpectedly. It has done this 1 time(s).
Error: (04/13/2017 10:11:18 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The SAS Core Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 1000 milliseconds: Restart the service.
==================== Memory info ===========================
Processor: Intel(R) Pentium(R) M processor 1.86GHz
Percentage of memory in use: 22%
Total physical RAM: 2046.05 MB
Available physical RAM: 1582.15 MB
Total Virtual: 3938.73 MB
Available Virtual: 3612.38 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:29.29 GB) (Free:17.32 GB) NTFS ==>[drive with boot components (Windows XP)]
Drive d: () (Fixed) (Total:45.23 GB) (Free:39.54 GB) NTFS
Drive f: (Salih_500) (Fixed) (Total:465.11 GB) (Free:9.58 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 74.5 GB) (Disk ID: 501C7C50)
Partition 1: (Active) - (Size=29.3 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=45.2 GB) - (Type=OF Extended)
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 465.1 GB) (Disk ID: 2FF82EFB)
Partition 1: (Active) - (Size=465.1 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
more info about past and my current situation
first i wanna share something i write yesterday and forget to tell u ( it was wirren before we were doing malwerbyte or one of the other fixes )
" on one of the restarts,(in order to fasten the situation) as my cpu usage became %100
i closed one of the svchost.exe from task manager- killed it -
and my cpu usage is stuck still on %100 !!
and i also suspect there is something missing up with my wireless lan!. cuz sometime it dissapears ,freezes or act weird when i try to solve any issue about it
for ex: 3 days ago before the format it suddenly dissapered and i couldnt use any wireless network connection , so i couldnt use internet for a brief time.. "
-------------------
Let's talk abot the sitation now !
my computer still lags and acts weird:, i got some spikes! not %100 but high enough to lag the computer considerably !
hitmanpro still finding stuff !
for ex: c:\Program Files\YeaDesktop
1 malicous version of hitmanpro at my external hard drive :F
2 trojans at system volume information
2 suspicous files : A0003752.exe at system volume inforation,
and FRST.exe at desktop ...
what do u suggest .?