Bilgisayara keylogger bulaşmış olabilir mi?

Fe4rlessBurak

Hectopat
Katılım
30 Mart 2020
Mesajlar
176
Merhaba, bilgisayarıma dün sanırım keylogger bulaştı, yani Instagram ve Twitter'ım çalındı ve aynı zamanda mailime 1000 tane spam geldi fakat gözükmüyorlar, tüm hesaplarıma giriş yapılan kısımlara baktım gözükmüyor herhangi bir lokasyon (kendi bilgisayarım dışında) 5 tane virüs tarayıcı kullandım 90 tane buldular fakat hala emin olamıyorum bilgisayarda donma vesaire yok. Keylogger saptama araçları ve yöntemlerini denedim gözükmüyor o yöntemlere göre. Fakat az önce SS almaya çalıştığımda bir error ve görev yöneticisin açmaya çalıştığımda yetkiniz yok diye bir error verdi. Yeniden başlatınca sıkıntı yok ama anlayamıyorum.
 
Basbaya bulaşmış işte. Antivirüs bile bulmuş neden emin olamadınız? Keylogger zaten sistemi yavaşlatan bir virüs değildir. Malwarebytes ile tam tarama gerçekleştirin.
 
Keylogger tespit yöntemlerinin birçoğu varsayımsal yöntemlerdir, tam sonuç vermez. KVRT, Hitman.Pro, ESET Scanner ile taramalar gerçekleştirin, farklı tarama motorları ile taranması en doğrusu. Sırası ile yapmanız gerekenlerin rehberlerini bırakıyorum.






İlgili adımları sırası ile uygulayın. Son Log paylaşımı, zararlının temizlendiğinden emin olmak için gereklidir.
 
Basbaya bulaşmış işte. Antivirüs bile bulmuş neden emin olamadınız? Keylogger zaten sistemi yavaşlatan bir virüs değildir. Malwarebytes ile tam tarama gerçekleştirin.

Hocam, anti virüsün bulduklarının keylogger olduğunu düşünmemiştim, bayağıdır tarama yapmadığım için başka şeylerdir diye düşündüm. Bulsa bile hala devam ediyor sanırım.
Hocam sistem patates olmuş. Ayrıca keylogger sistemi yavaşlatan değil tersine çok hafif durup sizin ne bastığınızı kayıt altına alıp saldırgana gönderir. Tam tarama yapın malwarebytes ile.
MalwareBytes herhangi bir şey bulamadı hocam yaptım.
 
Alın bir 8GB USB indirin isonuzu yazın rufus ile atın formatınızı. Hiç kafa yormaya değmez. Ya da 32/64 GB bir usbnin içine isoyu YAZDIKTAN SONRA önemli dosyalarınızı atıp windowsu kurduktan sonra usbnin içinden formatladığınız bilgisayara geri gönderebilirsiniz.
 
Keylogger tespit yöntemlerinin birçoğu varsayımsal yöntemlerdir, tam sonuç vermez. KVRT, Hitman.Pro, ESET Scanner ile taramalar gerçekleştirin, farklı tarama motorları ile taranması en doğrusu. Sırası ile yapmanız gerekenlerin rehberlerini bırakıyorum.






İlgili adımları sırası ile uygulayın. Son Log paylaşımı, zararlının temizlendiğinden emin olmak için gereklidir.
Deniyorum hocam sağolun.
Alın bir 8 GB USB indirin isonuzu yazın Rufus ile atın formatınızı. Hiç kafa yormaya değmez. Ya da 32/64 GB bir USB'nin içine ISO'yu yazdıktan sonra önemli dosyalarınızı atıp Windows'u kurduktan sonra USB'nin içinden formatladığınız bilgisayara geri gönderebilirsiniz.

İşte USB yok yanımda sıkıntı o.
 
Son düzenleme:

Bu rehberin tamamını eksiksiz bir şekilde uygulayın.
 
Keylogger tespit yöntemlerinin birçoğu varsayımsal yöntemlerdir, tam sonuç vermez. KVRT, Hitman.Pro, ESET Scanner ile taramalar gerçekleştirin, farklı tarama motorları ile taranması en doğrusu. Sırası ile yapmanız gerekenlerin rehberlerini bırakıyorum.






İlgili adımları sırası ile uygulayın. Son Log paylaşımı, zararlının temizlendiğinden emin olmak için gereklidir.
@Dutchman Hocam orda olan tüm anti virüs programlarıyla temizledim fakat hiçbirinde virüs çıkmadı, sadece cookieler çıktı temizledim. Hijack logunu aşağı bırakıyorum.






Kod:
Logfile of HiJackThis Fork by Alex Dragokas v.2.10.0.17

Platform:  x64 Windows 10 (Pro), 10.0.19044.1645 (ReleaseId: 2009, 21H2), Service Pack: 0
Time:      03.05.2022 - 18:50 (UTC+03:00)
Language:  OS: Turkish (0x41F). Display: Turkish (0x41F). Non-Unicode: Turkish (0x41F)
Elevated:  Yes
Ran by:    Burak    (group: Administrators) on FE4RLESSBURAK, FirstRun: no

Chrome:  100.0.4896.127
Firefox: 99.0.1.8136
Internet Explorer: 11.0.19041.1566
Default: "C:\Users\Burak\AppData\Local\Programs\Opera GX\Launcher.exe" -noautoupdate -- "%1" (Opera GX Internet Browser)

Boot mode: Normal

Running processes:
Number | Path
   1  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
   1  C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
   2  C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
   1  C:\Program Files (x86)\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe
   1  C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe
   1  C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler.exe
   1  C:\Program Files (x86)\Google\Update\1.3.36.132\GoogleCrashHandler64.exe
   1  C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 21.3\avp.exe
   1  C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 21.3\avpui.exe
   1  C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
   1  C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
   1  C:\Program Files (x86)\Origin\OriginWebHelperService.exe
   1  C:\Program Files (x86)\RivaTuner Statistics Server\EncoderServer.exe
   1  C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe
   1  C:\Program Files (x86)\RivaTuner Statistics Server\RTSSHooksLoader64.exe
   1  C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe
   1  C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\bin\wallpaperservice32_c.exe
   1  C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe
   1  C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
   1  C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
   1  C:\Program Files\Bonjour\mDNSResponder.exe
  28  C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
   1  C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
   1  C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
   1  C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe
   1  C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CorsairMsiPluginService.exe
   1  C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueLLAccessService.exe
   1  C:\Program Files\Everything\Everything.exe
   1  C:\Program Files\GamingOSD\GamingOSD.exe
   1  C:\Program Files\GamingOSD\MonitorMicroKeyDetector.exe
   1  C:\Program Files\GamingOSD\mysticlight\MysticLightController.exe
   1  C:\Program Files\GamingOSD\WeatherDetector.exe
   1  C:\Program Files\HitmanPro\HitmanPro.exe
   1  C:\Program Files\HitmanPro\hmpsched.exe
   1  C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
   1  C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
   3  C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
   3  C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
   1  C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
   1  C:\Program Files\Riot Vanguard\vgtray.exe
   1  C:\Program Files\Softdeluxe\Free Download Manager\helperservice.exe
   1  C:\Program Files\SteelSeries\GG\sonar\SteelSeriesSonar.exe
   1  C:\Program Files\SteelSeries\GG\SteelSeriesEngine.exe
   1  C:\Program Files\SteelSeries\GG\SteelSeriesGG.exe
   1  C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\ApplePhotoStreams.exe
   1  C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\APSDaemon.exe
   1  C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\iCloudDrive.exe
   1  C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\iCloudPhotos.exe
   1  C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\iCloudServices.exe
   1  C:\Program Files\WindowsApps\AppleInc.iCloud_13.0.201.0_x86__nzyj5cx40ttqa\iCloud\secd.exe
   1  C:\Program Files\WindowsApps\Microsoft.GamingApp_2204.1001.3.0_x64__8wekyb3d8bbwe\XboxAppServices.exe
   1  C:\Program Files\WindowsApps\Microsoft.GamingServices_3.63.31001.0_x64__8wekyb3d8bbwe\gamingservices.exe
   1  C:\Program Files\WindowsApps\Microsoft.GamingServices_3.63.31001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe
   1  C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.722.3302.0_x64__8wekyb3d8bbwe\GameBar.exe
   1  C:\Program Files\WindowsApps\Microsoft.XboxGamingOverlay_5.722.3302.0_x64__8wekyb3d8bbwe\GameBarFTServer.exe
   6  C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.184.716.0_x86__zpdnekdrzrea0\Spotify.exe
   6  C:\Users\Burak\AppData\Local\Discord\app-1.0.9004\Discord.exe
   1  C:\Users\Burak\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe
   1  C:\Users\Burak\Desktop\HiJackThis\HiJackThis.exe
   2  C:\Windows\explorer.exe
   1  C:\Windows\runSW.exe
   1  C:\Windows\SwUSB.exe
   1  C:\Windows\System32\ApplicationFrameHost.exe
   1  C:\Windows\System32\audiodg.exe
   3  C:\Windows\System32\conhost.exe
   1  C:\Windows\System32\CorsairGamingAudioCfgService64.exe
   2  C:\Windows\System32\csrss.exe
   1  C:\Windows\System32\ctfmon.exe
   2  C:\Windows\System32\dasHost.exe
   1  C:\Windows\System32\DbxSvc.exe
   1  C:\Windows\System32\dllhost.exe
   2  C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4d7400884d0d52e3\Display.NvContainer\NVDisplay.Container.exe
   1  C:\Windows\System32\dwm.exe
   2  C:\Windows\System32\fontdrvhost.exe
   1  C:\Windows\System32\lsass.exe
   1  C:\Windows\System32\NahimicService.exe
   2  C:\Windows\System32\rundll32.exe
   7  C:\Windows\System32\RuntimeBroker.exe
   1  C:\Windows\System32\SearchFilterHost.exe
   1  C:\Windows\System32\SearchIndexer.exe
   2  C:\Windows\System32\SearchProtocolHost.exe
   1  C:\Windows\System32\SecurityHealthService.exe
   1  C:\Windows\System32\SecurityHealthSystray.exe
   1  C:\Windows\System32\services.exe
   1  C:\Windows\System32\SettingSyncHost.exe
   1  C:\Windows\System32\SgrmBroker.exe
   1  C:\Windows\System32\sihost.exe
   1  C:\Windows\System32\smartscreen.exe
   1  C:\Windows\System32\smss.exe
   1  C:\Windows\System32\spoolsv.exe
  84  C:\Windows\System32\svchost.exe
   2  C:\Windows\System32\taskhostw.exe
   2  C:\Windows\System32\wbem\WmiPrvSE.exe
   1  C:\Windows\System32\wininit.exe
   1  C:\Windows\System32\winlogon.exe
   1  C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
   1  C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
   1  C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
   1  C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
   1  C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
   1  C:\Windows\SysWOW64\dllhost.exe
   2  C:\Windows\SysWOW64\muachost.exe
   1  C:\Windows\SysWOW64\PnkBstrA.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main: [Start Page] = https://www.yandex.com.tr/?win=432&clid=2256396
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxyOverride] = *.local
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\1dfe8446-7a99-11ea-a0d7-00d861a15516: [SuggestionsURL_JSON] = https://suggest.yandex.com.tr/suggest-ff.cgi?uil=ru&part={searchTerms} - Yandex
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\1dfe8446-7a99-11ea-a0d7-00d861a15516: [URL] = https://yandex.com.tr/search/?win=432&clid=2256397&text={searchTerms} - Yandex
O2 - HKLM\..\BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll (file missing)
O2 - HKLM\..\BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_321\bin\jp2ssv.dll
O2 - HKLM\..\BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_321\bin\ssv.dll
O4 - HKCU\..\Run: [AntiMalwareServiceExecutable] = C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2111.5-0\MsMpEng.exe (file missing)
O4 - HKCU\..\Run: [Discord] = C:\Users\Burak\AppData\Local\Discord\Update.exe --processStart Discord.exe
O4 - HKCU\..\Run: [WindowsDefender] = C:\Program Files\Windows Defender\MpCmdRun.exe
O4 - HKCU\..\Run: [WmiPrvSE] = C:\Windows\System32\wbem\WmiPrvSE.exe
O4 - HKCU\..\StartupApproved\Run: [Cortana] = C:\Program Files\WindowsApps\Microsoft.x64__8wekyb3gfdfdgd8bbwe\Cortana.exe (file missing) (2022/05/03)
O4 - HKCU\..\StartupApproved\Run: [EpicGamesLauncher] = C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe -silent (2020/04/09)
O4 - HKCU\..\StartupApproved\Run: [MicrosoftEdgeUpd] = C:\Program Files\WindowsApps\Microsoft.x64__8wekyb3gfdfdgd8bbwe/file.exe (file missing) (2022/05/03)
O4 - HKCU\..\StartupApproved\Run: [NvStray] = C:\Program Files\WindowsApps\Microsoft.x64__8wekyb3gfdfdgd8bbwe/file.exe (file missing) (2022/05/03)
O4 - HKCU\..\StartupApproved\Run: [OneDriveService] = C:\Program Files\WindowsApps\Microsoft.x64__8wekyb3gfdfdgd8bbwe/file.exe (file missing) (2022/05/03)
O4 - HKCU\..\StartupApproved\Run: [Voicemod] = C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe (2020/07/22)
O4 - HKCU\..\StartupApproved\StartupFolder: C:\Users\Burak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AIDA64 Extreme.lnk    ->    C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe (2020/06/23)
O4 - HKCU\..\StartupApproved\StartupFolder: C:\Users\Burak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MSI Afterburner.lnk    ->    C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe (2020/06/23)
O4 - HKCU\..\StartupApproved\StartupFolder: C:\Users\Burak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OBS Studio.lnk    ->    C:\Program Files\obs-studio\bin\64bit\obs64.exe (2020/06/11)
O4 - HKCU\..\StartupApproved\StartupFolder: C:\Users\Burak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ShareX.lnk    ->    C:\Program Files\ShareX\ShareX.exe -silent (2021/06/03)
O4 - HKCU\..\StartupApproved\StartupFolder: C:\Users\Burak\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Voicemod.lnk    ->    C:\Program Files\Voicemod Desktop\VoicemodDesktop.exe (2020/09/07)
O4 - HKLM\..\Run: [Riot Vanguard] = C:\Program Files\Riot Vanguard\vgtray.exe
O4 - HKLM\..\Run: [SteelSeriesGG] = C:\Program Files\SteelSeries\GG\SteelSeriesGG.exe -dataPath="C:\ProgramData\SteelSeries\GG" -dbEnv=production -auto=true
O4 - HKLM\..\StartupApproved\Run: [CL-25-0D3A48B2-4678-4CAE-BD49-1AF5AC37EE1F] = C:\Program Files\Common Files\Bitdefender\SetupInformation\CL-25-0D3A48B2-4678-4CAE-BD49-1AF5AC37EE1F\setuplauncher.exe /run:Installer.exe /args:"/setup-folder:"CL-25-0D3A48B2-4678-4CAE-BD49-1AF5AC37EE1F"" (file missing) (2021/06/03)
O4 - HKLM\..\StartupApproved\Run: [CORSAIR iCUE 4 Software] = C:\Program Files\Corsair\CORSAIR iCUE 4 Software\iCUE Launcher.exe --autorun (2021/06/04)
O4 - HKLM\..\StartupApproved\Run: [iTunesHelper] = C:\Program Files\iTunes\iTunesHelper.exe (2021/06/04)
O4 - HKLM\..\StartupApproved\Run: [RTHDVCPL] = C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s (2020/06/11)
O4 - HKLM\..\StartupApproved\Run: [SecurityHealth] = C:\WINDOWS\system32\SecurityHealthSystray.exe (2021/06/04)
O4 - HKLM\..\StartupApproved\Run32: [Dropbox] = C:\Program Files (x86)\Dropbox\Client\Dropbox.exe /systemstartup (2020/04/22)
O4 - HKLM\..\StartupApproved\Run32: [EpicPen] = C:\Program Files (x86)\Epic Pen\EpicPen.exe -startup (2021/06/04)
O4 - HKLM\..\StartupApproved\Run32: [MSI_Diagnostic_Tool] = C:\Users\Burak\Desktop\DiagnosticTool.exe (file missing) (2022/05/03)
O4 - HKLM\..\StartupApproved\Run32: [StartCCC] = C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe MSRun (2020/04/28)
O4 - HKLM\..\StartupApproved\Run32: [Wraith Prism] = C:\Program Files (x86)\AMD Wraith\Wraith Prism\Wraith Prism HID.exe (2020/04/10)
O4 - HKU\S-1-5-19\..\RunOnce: [WAB Migrate] = C:\Program Files\Windows Mail\wab.exe /Upgrade (User 'Local service')
O4 - HKU\S-1-5-20\..\RunOnce: [WAB Migrate] = C:\Program Files\Windows Mail\wab.exe /Upgrade (User 'Network service')
O4-32 - HKLM\..\Run: [amd_dc_opt] = C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4-32 - HKLM\..\Run: [Lightshot] = C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe
O4-32 - HKLM\..\Run: [SunJavaUpdateSched] = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
O7 - TroubleShooting: (EV) %PATH% has missing system folder: C:\WINDOWS\System32\Wbem
O7 - TroubleShooting: (EV) %PATH% has missing system folder: C:\WINDOWS\System32\WindowsPowerShell\v1.0
O10 - Unknown file in Winsock LSP: C:\Program Files (x86)\Bonjour\mdnsNSP.dll
O17 - DHCP DNS 1: 8.8.8.8 (Well-known DNS: Google)
O17 - DHCP DNS 2: 8.8.8.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{4c144a88-4986-4210-ba43-2cc4e3ec70f1}: [NameServer] = 8.8.8.4
O17 - HKLM\System\CCS\Services\Tcpip\..\{4c144a88-4986-4210-ba43-2cc4e3ec70f1}: [NameServer] = 8.8.8.8 (Well-known DNS: Google)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Program Files (x86)\Dropbox\Client\DropboxExt64.52.0.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Users\Burak\AppData\Roaming\Yandex\YandexDisk2\3.2.6.4175\YandexDisk3ShellExt-1511.dll
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Program Files (x86)\Dropbox\Client\DropboxExt.52.0.dll
O22 - BITS Job: (download) {9A494E84-835D-4E8F-80CE-A6795EB2F647} - http://redirector.gvt1.com/edgedl/release2/chrome_component/adw4q3flvomh2bedc6ado3md3gmq_103.0.5037.0/jamhcnnkihinmdlkakkaopbjbbcngflc_103.0.5037.0_all_ach4a6ntv7jjaakbnv5dvifj6uma.crx3 -> C:\Users\Burak\AppData\Local\Temp\chrome_BITS_2116_627888554\jamhcnnkihinmdlkakkaopbjbbcngflc_103.0.5037.0_all_ach4a6ntv7jjaakbnv5dvifj6uma.crx3
O22 - BITS Job: Fix all (including legit)
O22 - Task (.job): (disabled) (Not scheduled) CreateExplorerShellUnelevatedTask.job - C:\WINDOWS\explorer.exe
O22 - Task (.job): (Not scheduled) DropboxUpdateTaskMachineCore.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O22 - Task (.job): (Not scheduled) DropboxUpdateTaskMachineUA.job - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
O22 - Task (.job): (Not scheduled) update-S-1-5-21-2964470086-3692298345-2330079707-1001.job - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
O22 - Task (.job): (Not scheduled) update-sys.job - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AntiMalwareSericeExecutable (empty)
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\NCH Software (empty)
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SettingSysHost (empty)
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WindowsDefenderServices (empty)
O22 - Task: (disabled) \Agent Activation Runtime\S-1-5-21-2964470086-3692298345-2330079707-1001 - C:\WINDOWS\System32\AgentActivationRuntimeStarter.exe
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ProvRetryTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\WINDOWS\system32\usoclient.exe StartMaintenanceWork (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work - C:\WINDOWS\system32\usoclient.exe StartWork (Microsoft)
O22 - Task: (disabled) \S-1-5-21-2964470086-3692298345-2330079707-1001\DataSenseLiveTileTask - C:\WINDOWS\System32\DataUsageLiveTileTask.exe
O22 - Task: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask (Microsoft)
O22 - Task: (telemetry) NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
O22 - Task: (telemetry) NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
O22 - Task: (telemetry) NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
O22 - Task: (telemetry) NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe
O22 - Task: \Apple\AppleSoftwareUpdate - C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe -task
O22 - Task: \Microsoft\Office\Office Performance Monitor - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe (Microsoft)
O22 - Task: \Mozilla\Firefox Background Update 308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
O22 - Task: \Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
O22 - Task: Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
O22 - Task: AIDA64 AutoStart - C:\Program Files (x86)\FinalWire\AIDA64 Extreme\aida64.exe
O22 - Task: AMDAutoUpdate - C:\Program Files\AMD\AutoUpdate\AMDAutoUpdate.exe
O22 - Task: BlueStacksHelper_nxt - C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe -sr
O22 - Task: BraveSoftwareUpdateTaskMachineCore - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /c
O22 - Task: BraveSoftwareUpdateTaskMachineUA - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /ua /installsource scheduler
O22 - Task: DropboxUpdateTaskMachineCore - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /c
O22 - Task: DropboxUpdateTaskMachineUA - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /ua /installsource scheduler
O22 - Task: EOSv3 Scheduler onLogOn - C:\Users\Burak\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe LOGON
O22 - Task: EOSv3 Scheduler onTime - C:\Users\Burak\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe SCHED
O22 - Task: ExclusiveTool - C:\Program Files (x86)\DSDCS\InputMapper\ExclusiveModeTool.exe /a
O22 - Task: FreeDownloadManagerHelperService - C:\Program Files\Softdeluxe\Free Download Manager\helperservice.exe
O22 - Task: GamingOSDAutoStartUp - C:\Program Files\GamingOSD\GamingOSD.exe -autostart
O22 - Task: Ghostpress_SkipUAC_518F51083CDB4AC1449BFC2EBA4F4543 - C:\Users\Burak\Desktop\Yeni klasör (2)\Ghostpress.exe (file missing)
O22 - Task: GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Task: GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Task: GoogleUpdateTaskUserS-1-5-21-2964470086-3692298345-2330079707-1001Core - C:\Users\Burak\AppData\Local\Google\Update\GoogleUpdate.exe /c (file missing)
O22 - Task: GoogleUpdateTaskUserS-1-5-21-2964470086-3692298345-2330079707-1001UA - C:\Users\Burak\AppData\Local\Google\Update\GoogleUpdate.exe /ua /installsource scheduler (file missing)
O22 - Task: Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} - C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe /waitUpgrade
O22 - Task: MonitorMicroKey - C:\Program Files\GamingOSD\MonitorMicroKeyDetector.exe
O22 - Task: MonitorMysticLight - C:\Program Files\GamingOSD\MysticLight\MysticLightController.exe
O22 - Task: MonitorWeatherDetector - C:\Program Files\GamingOSD\WeatherDetector.exe
O22 - Task: MSI Task Host - Detect_Monitor - C:\Program Files (x86)\MSI\One Dragon Center\MSI.NotifyServer.exe Detect_Monitor (file missing)
O22 - Task: MSI Task Host - DisplayID - C:\Program Files (x86)\MSI\One Dragon Center\MSI.NotifyServer.exe Detect_DisplayID (file missing)
O22 - Task: MSI Task Host - MSI.True Color - C:\Program Files (x86)\MSI\One Dragon Center\True Color\MSI.True Color.exe (file missing)
O22 - Task: MSIAfterburner - C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe /s
O22 - Task: MSISW_Host - C:\Windows\SysWOW64\muachost.exe
O22 - Task: NahimicSvc32Run - C:\Windows\SysWOW64\NahimicSvc32.exe $(Arg0) $(Arg1) $(Arg2) $(Arg3) $(Arg4) $(Arg5) $(Arg6) $(Arg7)
O22 - Task: NahimicSvc64Run - C:\Windows\system32\NahimicSvc64.exe $(Arg0) $(Arg1) $(Arg2) $(Arg3) $(Arg4) $(Arg5) $(Arg6) $(Arg7)
O22 - Task: NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log
O22 - Task: NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe
O22 - Task: NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe --launcher=TaskScheduler
O22 - Task: NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
O22 - Task: NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe
O22 - Task: Opera GX scheduled assistant Autoupdate 1615540798 - C:\Users\Burak\AppData\Local\Programs\Opera GX\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Burak\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
O22 - Task: Opera GX scheduled Autoupdate 1586450799 - C:\Users\Burak\AppData\Local\Programs\Opera GX\launcher.exe --scheduledautoupdate $(Arg0)
O22 - Task: Opera scheduled assistant Autoupdate 1586450404 - C:\Users\Burak\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Burak\AppData\Local\Programs\Opera\assistant" $(Arg0)
O22 - Task: Opera scheduled Autoupdate 1586450400 - C:\Users\Burak\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0)
O22 - Task: Overwolf Updater Task - C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe /RunningFrom Schedule
O22 - Task: RTSS - C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe /s
O22 - Task: Shutdown - C:\Windows\System32\shutdown.exe -s
O22 - Task: update-S-1-5-21-2964470086-3692298345-2330079707-1001 - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate
O22 - Task: update-sys - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate
O22 - Task: VivaldiUpdateCheck-df2aa5aa359171a0 - C:\Users\Burak\AppData\Local\Vivaldi\Application\update_notifier.exe --from-scheduler
O23 - Service R2: Adobe Acrobat Update Service - (AdobeARMservice) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service R2: AMD FUEL Service - C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe /launchService
O23 - Service R2: Apple Mobile Device Service - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service R2: Bonjour Service - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service R2: Corsair Gaming Audio Configuration Service - (CorsairGamingAudioConfig) - C:\Windows\System32\CorsairGamingAudioCfgService64.exe
O23 - Service R2: Corsair LLA Service - (CorsairLLAService) - C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CueLLAccessService.exe
O23 - Service R2: Corsair MSI Plugin Service - (CorsairMsiPluginService) - C:\Program Files\Corsair\CORSAIR iCUE 4 Software\CorsairMsiPluginService.exe
O23 - Service R2: Corsair Service - (CorsairService) - C:\Program Files\Corsair\CORSAIR iCUE 4 Software\Corsair.Service.exe
O23 - Service R2: DbxSvc - C:\WINDOWS\system32\DbxSvc.exe
O23 - Service R2: EABackgroundService - C:\Program Files (x86)\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe -start
O23 - Service R2: Everything - C:\Program Files\Everything\Everything.exe -svc
O23 - Service R2: Gaming Services - (GamingServices) - C:\Program Files\WindowsApps\Microsoft.GamingServices_3.63.31001.0_x64__8wekyb3d8bbwe\GamingServices.exe
O23 - Service R2: Gaming Services - (GamingServicesNet) - C:\Program Files\WindowsApps\Microsoft.GamingServices_3.63.31001.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe
O23 - Service R2: HitmanPro Scheduler - (HitmanProScheduler) - C:\Program Files\HitmanPro\hmpsched.exe
O23 - Service R2: Kaspersky Anti-Virus Service 21.3 - (AVP21.3) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 21.3\avp.exe -r
O23 - Service R2: Malwarebytes Service - (MBAMService) - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
O23 - Service R2: Nahimic service - (NahimicService) - C:\WINDOWS\system32\NahimicService.exe
O23 - Service R2: NVIDIA Display Container LS - (NVDisplay.ContainerLocalSystem) - C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4d7400884d0d52e3\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_4d7400884d0d52e3\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem
O23 - Service R2: NVIDIA LocalSystem Container - (NvContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -s NvContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll"
O23 - Service R2: Origin Web Helper Service - C:\Program Files (x86)\Origin\OriginWebHelperService.exe
O23 - Service R2: PnkBstrA - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service R2: RunSwUSB - C:\Windows\runSW.exe
O23 - Service R2: TeamViewer - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
O23 - Service R2: Wallpaper Engine Service - C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\bin\wallpaperservice32_c.exe
O23 - Service S2: Brave Update Service (brave) - (brave) - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /svc
O23 - Service S2: Dropbox Update Service (dbupdate) - (dbupdate) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /svc
O23 - Service S2: Google Güncelleme Hizmeti (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc
O23 - Service S2: MSI Central Service - (MSI_Central_Service) - C:\Program Files (x86)\MSI\One Dragon Center\MSI_Central_Service.exe (file missing)
O23 - Service S3: BattlEye Service - (BEService) - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service S3: Brave Update Service (bravem) - (bravem) - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /medsvc
O23 - Service S3: Dropbox Update Service (dbupdatem) - (dbupdatem) - C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe /medsvc
O23 - Service S3: Easy Anti-Cheat (Epic Online Services) - (EasyAntiCheat_EOS) - C:\Program Files (x86)\EasyAntiCheat_EOS\EasyAntiCheat_EOS.exe
O23 - Service S3: EasyAntiCheat - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service S3: Epic Online Services - (EpicOnlineServices) - C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe
O23 - Service S3: EQU8_36 - C:\ProgramData\EQU8\Splitgate\bin\anticheat.x64.equ8.exe
O23 - Service S3: GalaxyClientService - C:\Program Files (x86)\GOG Galaxy\GalaxyClientService.exe
O23 - Service S3: GalaxyCommunication - C:\ProgramData\GOG.com\Galaxy\redists\GalaxyCommunication.exe
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService) - (GoogleChromeElevationService) - C:\Program Files (x86)\Google\Chrome\Application\100.0.4896.127\elevation_service.exe
O23 - Service S3: Google Güncelleme Hizmeti (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc
O23 - Service S3: Kaspersky Volume Shadow Copy Service Bridge 21.3 - (klvssbridge64_21.3) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 21.3\x64\vssbridge64.exe
O23 - Service S3: Mozilla Maintenance Service - (MozillaMaintenance) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service S3: NVIDIA FrameView SDK service - (FvSvc) - C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe -service
O23 - Service S3: Origin Client Service - C:\Program Files (x86)\Origin\OriginClientService.exe
O23 - Service S3: Overwolf Updater Windows SCM - (OverwolfUpdater) - C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe /RunningFrom SCM
O23 - Service S3: Rockstar Game Library Service - (Rockstar Service) - C:\Program Files\Rockstar Games\Launcher\RockstarService.exe
O23 - Service S3: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\SteamService.exe /RunAsService
O23 - Service S3: SteelSeries Update Service - (SteelSeriesUpdateService) - C:\Program Files\SteelSeries\GG\SteelSeriesUpdateService.exe
O23 - Service S3: touchvpnsvc - C:\Program Files (x86)\TouchVPN\Hydra.Sdk.Windows.Service.exe
O23 - Service S3: Twitch Service - (TwitchService) - C:\Program Files\Common Files\Twitch\TwitchService.exe
O23 - Service S3: vgc - C:\Program Files\Riot Vanguard\vgc.exe


--
End of file - Time spent: 8 sec. - 60900 bytes, CRC32: FFFFFFFF. Sign: 頓ẛ
 

Bu rehberin tamamını eksiksiz bir şekilde uygulayın.
Uygulayın..
 

Technopat Haberler

Geri
Yukarı