1543056134722.png


Sisteminizde yaşadığınız performans düşüşü, kilitlenme, zararlı etkisi, uygulama hatalarından kaynaklanan sorunsalları analiz etmek ve performans iyileştirmesi, zararlı etkisini inaktif etmek için bize HijackThis yazılımı ile yaptığınız tarama Logunu burada paylaşmanız gerekmektedir.



Kullanımı:

1)
Bir geliştirici tarafından yeni özellikler kazandırılan güncel sürümünü buradan indirip, arşiv dosyasından masaüstüne uygulamayı çıkartın.

Alternatif: Download HiJackThis Fork - MajorGeeks

Eski Sürüm: HiJackThis | Free software downloads at SourceForge.net

2) Bilgisayarınızı yeniden başlatın 3 dk işlem yapmadan bekleyin.

3) HijackThis yazılımına sağ tıklayıp yönetici olarak çalıştırın (XP için geçerli değil).

1543056459730.png


4) Açılan arayüzde, "Do a system scan and save a log file" butonuna tıklayın.

1543053000396.png


5) Otomatik olarak Hijackthis taraması başlayacak, taramanın tamamlanması sürece fare ve klavyeyi kullanmayın.
1543053111358.png


6) Tarama tamamlandığında HijackThis raporunu içeren bir Log dosyası karşınıza gelecektir.

1543053449185.png



*7) Log dosyasını incelememiz için buraya cevaplama bölümünden eklemeniz gerekmektedir.

1543053710016.png

Kod'a tıklayın.

1543053809056.png


Log'da yazanları mavi bölmenin içine yapıştırıp "Devam Et" butonuna basın.

Uyarı: Sitede kod eklemede sorun yaşarsanız kod paylaşımlarını altta verilen sitelerden birine yapıştırıp linki paylaşmanız gerekmektedir. Bu durumda *7. seçeneği şu anlık kullanmayın.

Paste ofCode

8) Ayrıca sisteminizde var olan sorunu detaylıca (Performans düşüşü, Malware varlığı şüphesi vb.) belirterek konuyu cevaplayın.
(Bunu yapmayana cevap verilmeyecektir)

Fixleme:

Konuda şahsım tarafından veya uzman kişilerden geri dönüş yapıldığında Hijackthis uygulama arayüzünden söylediğimiz satırların başlarına tik işareti koyun. Ardından "Fix checked" butonuna basın.
1543054420492.png
 
Son düzenleme:
Merhabalar ofiste monster laptop kullanıyorum NVME takmıştım ilk aldığımda ve RAM'i de 32'ye çıkardım 1 yıl önce.

Amacım chrome da 20-30 sekme açınca kasmayı azaltmak. Ki kısmen başardım da.

Ancak 20-25 gündür bir kasma geldi PC ye. Windows ekran görüntü alıcısını açarken birkaç saniye geçikmeli açıyor. Normalde "başlat+shift+S" ile anında gelirdi ekrana.

Acaba ne yapmalıyım.



Kod:
Logfile of HiJackThis+ (Plus) build 2024-04-18 Alpha v.3.4.0.9

Platform:  x64 Windows 11 (Pro), 10.0.22631.3737 (ReleaseId: 2009, 23H2), Service Pack: 0
Time:      08.07.2024 - 20:26 (UTC+03:00)
Language:  OS: Turkish (0x41F). Display: English (0x409). Non-Unicode: Turkish (0x41F)
Memory:    26785 MiB Free. Loading RAM (19 %), CPU (1 %)
Elevated:  Yes
Ran by:    Amazoner    (group: Administrators; type: Local) on DESKTOP-U45H6DV, FirstRun: yes

Chrome:  126.0.6478.127
Internet Explorer: 11.0.22621.3527
Default: "C:\Program Files\Google\Chrome\Application\chrome.exe" --single-argument %1 (Google Chrome)

Boot mode: Normal (Secure Boot: Off) (Code Integrity: On)

Running processes:
Number | Path
   1  C:\Program Files (x86)\Internet Download Manager\IDMan.exe
   3  C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\avp.exe
   1  C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\avpui.exe
   1  C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 24.1\kpm_service.exe
   1  C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
   1  C:\Program Files (x86)\Samsung\Samsung Magician\MigrationService\MigrationService.exe
   4  C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe
   1  C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagicianSVC.exe
   1  C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
  11  C:\Program Files\Google\Chrome\Application\chrome.exe
   1  C:\Program Files\Google\Drive File Stream\92.0.1.0\crashpad_handler.exe
   7  C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe
   1  C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
   1  C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
   1  C:\Program Files\LogiOptionsPlus\logioptionsplus_agent.exe
   1  C:\Program Files\LogiOptionsPlus\logioptionsplus_appbroker.exe
   1  C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe
   1  C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\nvrla.exe
   2  C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\PresentMon_x64.exe
   1  C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe
   3  C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
   3  C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
   1  C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
   1  C:\Program Files\NZXT CAM\resources\app.asar.unpacked\node_modules\@nzxt\cam-core\dist\target\x86_64-pc-windows-msvc\release\service.exe
   1  C:\Program Files\OEM\Monster Kontrol Merkezi\UniwillService\GCUBridge.exe
   1  C:\Program Files\OEM\Monster Kontrol Merkezi\UniwillService\MyControlCenter\GCUService.exe
   1  C:\Program Files\OEM\Monster Kontrol Merkezi\UniwillService\MyControlCenter\OSDTpDetect.exe
   1  C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2424.6.0_x64__cv1g1gvanyjgm\WhatsApp.exe
   1  C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.12.1.0_x64__8wekyb3d8bbwe\PCManager\MSPCManagerService.exe
   1  C:\Program Files\WindowsApps\Microsoft.Windows.DevHome_0.1501.533.0_x64__8wekyb3d8bbwe\DevHome.PI.exe
   1  C:\Program Files\WindowsApps\Microsoft.YourPhone_1.24061.93.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
   1  C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.13200.30.0_x64__cw5n1h2txyewy\Dashboard\Widgets.exe
   1  C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.13200.30.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
   1  C:\Users\Amazoner\Downloads\Compressed\HiJackThis.exe
   1  C:\Windows\explorer.exe
   1  C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
   1  C:\Windows\System32\AggregatorHost.exe
   1  C:\Windows\System32\ApplicationFrameHost.exe
   1  C:\Windows\System32\audiodg.exe
   2  C:\Windows\System32\backgroundTaskHost.exe
   5  C:\Windows\System32\conhost.exe
   2  C:\Windows\System32\csrss.exe
   1  C:\Windows\System32\ctfmon.exe
   1  C:\Windows\System32\dllhost.exe
   1  C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_5207db0559876a61\igfxCUIService.exe
   1  C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_5207db0559876a61\igfxEM.exe
   1  C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
   1  C:\Windows\System32\DriverStore\FileRepository\iaahcic.inf_amd64_48973fc6c96c696a\RstMwService.exe
   1  C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_401fde8782680631\OneApp.IGCC.WinService.exe
   1  C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b260c545909302e9\IntelCpHDCPSvc.exe
   1  C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b260c545909302e9\IntelCpHeciSvc.exe
   1  C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
   2  C:\Windows\System32\DriverStore\FileRepository\nvtfi.inf_amd64_4cd94d3ab4900da6\Display.NvContainer\NVDisplay.Container.exe
   1  C:\Windows\System32\dwm.exe
   2  C:\Windows\System32\fontdrvhost.exe
   1  C:\Windows\System32\LsaIso.exe
   1  C:\Windows\System32\lsass.exe
   2  C:\Windows\System32\RtkAudUService64.exe
   1  C:\Windows\System32\rundll32.exe
   6  C:\Windows\System32\RuntimeBroker.exe
   1  C:\Windows\System32\SearchIndexer.exe
   1  C:\Windows\System32\SearchProtocolHost.exe
   1  C:\Windows\System32\SecurityHealthService.exe
   1  C:\Windows\System32\SecurityHealthSystray.exe
   1  C:\Windows\System32\services.exe
   1  C:\Windows\System32\sihost.exe
   1  C:\Windows\System32\smartscreen.exe
   1  C:\Windows\System32\smss.exe
   1  C:\Windows\System32\spoolsv.exe
  88  C:\Windows\System32\svchost.exe
   2  C:\Windows\System32\taskhostw.exe
   1  C:\Windows\System32\VSHelper.exe
   1  C:\Windows\System32\VSSrv.exe
   2  C:\Windows\System32\wbem\unsecapp.exe
   2  C:\Windows\System32\wbem\WmiPrvSE.exe
   1  C:\Windows\System32\wininit.exe
   1  C:\Windows\System32\winlogon.exe
   1  C:\Windows\System32\wlanext.exe
   1  C:\Windows\System32\WUDFHost.exe
   1  C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
   1  C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
   1  C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchHost.exe
   1  C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
   1  C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe

R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8}: [SuggestionsURL_JSON] = hxxps://suggest.yandex.com.tr/suggest-ff.cgi?srv=ie11&uil=tr&part={searchTerms}&clid=2233630 - Yandex
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8}: [URL] = hxxps://yandex.com.tr/search/?text={searchTerms}&clid=2233630 - Yandex
O2 - HKLM\..\BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (sign: 'Tonec Inc.')
O2-32 - HKLM\..\BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (sign: 'Tonec Inc.')
O2-32 - HKLM\..\BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre-1.8\bin\jp2ssv.dll (sign: 'Oracle America, Inc.')
O2-32 - HKLM\..\BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre-1.8\bin\ssv.dll (sign: 'Oracle America, Inc.')
O4 - ActiveSetup: HKLM\..\{8A69D345-D564-463c-AFF1-A69D9E530F96}: [StubPath] = C:\Program Files\Google\Chrome\Application\126.0.6478.127\Installer\chrmstp.exe --configure-user-settings --verbose-logging --system-level --channel=stable (sign: 'Google LLC')
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_179A20440F73D81F360A8C91425976B5] = C:\Program Files\Google\Chrome\Application\chrome.exe --no-startup-window /prefetch:5 (sign: 'Google LLC')
O4 - HKCU\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe --startup_mode (sign: 'Google LLC')
O4 - HKCU\..\StartupApproved\Run: [Discord] = C:\Users\Amazoner\AppData\Local\Discord\Update.exe --processStart Discord.exe (2023/10/25) (sign: 'Discord Inc.')
O4 - HKCU\..\StartupApproved\Run: [EADM] = C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe -silent (2023/03/28) (sign: 'Electronic Arts, Inc.')
O4 - HKCU\..\StartupApproved\Run: [IDMan] = C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot (2022/11/22) (sign: 'Tonec Inc.')
O4 - HKCU\..\StartupApproved\Run: [kpm.exe] = C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 24.1\kpm.exe autoStart (2023/10/25) (sign: 'AO Kaspersky Lab')
O4 - HKCU\..\StartupApproved\Run: [MicrosoftEdgeAutoLaunch_4E936087059E131F21130A0886C1FCE8] = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --no-startup-window --win-session-start (2022/11/22) (sign: 'Microsoft')
O4 - HKCU\..\StartupApproved\Run: [NZXT.CAM] = C:\Program Files\NZXT CAM\NZXT CAM.exe --startup (2022/11/22) (sign: 'NZXT, Inc.')
O4 - HKCU\..\StartupApproved\Run: [OneDrive] = C:\Program Files\Microsoft OneDrive\OneDrive.exe /background (2022/11/22) (sign: 'Microsoft')
O4 - HKCU\..\StartupApproved\Run: [Opera Browser Assistant] = C:\Users\Amazoner\AppData\Local\Programs\Opera\assistant\browser_assistant.exe (sign: 'Opera Norway AS')
O4 - HKCU\..\StartupApproved\Run: [Opera Stable] = C:\Users\Amazoner\AppData\Local\Programs\Opera\opera.exe (sign: 'Opera Norway AS')
O4 - HKCU\..\StartupApproved\Run: [Steam] = C:\Program Files (x86)\Steam\steam.exe -silent (2023/03/28) (sign: 'Valve Corp.')
O4 - HKCU\..\StartupApproved\Run: [Wechat] = C:\Program Files (x86)\Tencent\WeChat\WeChat.exe -autorun (2023/03/28) (sign: 'Tencent Technology (Shenzhen) Company Limited')
O4 - HKLM\..\Run: [IAStorIcon] = C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60 (sign: 'Intel(R) Rapid Storage Technology')
O4 - HKLM\..\Run: [Logitech Download Assistant] = C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch (sign: 'Microsoft')
O4 - HKLM\..\Run: [RtkAudUService] = C:\WINDOWS\System32\RtkAudUService64.exe -background (sign: 'Realtek Semiconductor Corp.')
O4 - HKLM\..\StartupApproved\Run: [LogiOptions] = C:\Program Files\Logitech\LogiOptions\LogiOptions.exe /noui (sign: 'Logitech Inc')
O4 - HKLM\..\StartupApproved\Run32: [SunJavaUpdateSched] = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (sign: 'Oracle America, Inc.')
O4 - HKU\S-1-5-18\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe --startup_mode (User 'LocalSystem') (sign: 'Google LLC')
O4 - HKU\S-1-5-19\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe --startup_mode (User 'Local service') (sign: 'Google LLC')
O4 - HKU\S-1-5-19\..\Run: [OneDriveSetup] = C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'Local service') (sign: 'Microsoft')
O4 - HKU\S-1-5-20\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe --startup_mode (User 'Network service') (sign: 'Google LLC')
O4 - HKU\S-1-5-20\..\Run: [OneDriveSetup] = C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'Network service') (sign: 'Microsoft')
O7 - Policy: HKLM\Software\Microsoft\Windows Defender: [DisableAntiSpyware] = 1
O7 - Policy: HKLM\Software\Microsoft\Windows Defender: [DisableAntiVirus] = 1
O8 - Context menu item: HKCU\..\Internet Explorer\MenuExt\IDM ile indir: (default) = C:\Program Files (x86)\Internet Download Manager\IEExt.htm (not signed - no company - 1A49C5F7A98580F8002AC1D6115AB39CB753975B)
O8 - Context menu item: HKCU\..\Internet Explorer\MenuExt\Se&nd to OneNote: (default) = C:\Program Files (x86)\Microsoft Office\root\Office16\ONBttnIE.dll (file missing)
O17 - DHCP DNS 1: 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{409de61f-e366-424b-bfb0-a3dbed42e1f5}: [NameServer] = 198.51.100.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{409de61f-e366-424b-bfb0-a3dbed42e1f5}: [NameServer] = 198.51.100.2
O17 - HKLM\System\CCS\Services\Tcpip\..\{ce9dc194-aba9-4b70-8ace-b6e67dd685a0}: [NameServer] = 198.51.100.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{ce9dc194-aba9-4b70-8ace-b6e67dd685a0}: [NameServer] = 198.51.100.2
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (sign: 'Tonec Inc.')
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Program Files\Google\Drive File Stream\92.0.1.0\drivefsext.dll (sign: 'Google LLC')
O22 - Tasks: (disabled) \Microsoft\Windows\Clip\LicenseImdsIntegration - C:\WINDOWS\system32\fclip.exe (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\MdmDiagnosticsCleanup - C:\WINDOWS\system32\MdmDiagnosticsTool.exe /clean (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ProvRetryTask (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Shell\ThemeAssetTask_SyncFODState - {3BC5DD7D-EA3B-428C-B9B6-0723DB6A1057} - C:\Windows\System32\Windows.UI.Immersive.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\WINDOWS\system32\usoclient.exe StartMaintenanceWork (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\WINDOWS\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\WINDOWS\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareData (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\WINDOWS\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - C:\WINDOWS\system32\sc.exe start InventorySvc (sign: '')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\PcaWallpaperAppDetect - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaWallpaperAppDetect (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\SdbinstMergeDbTask - C:\WINDOWS\system32\sdbinst.exe -mm (sign: 'Microsoft')
O22 - Tasks: (telemetry) NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: (telemetry) NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: (telemetry) NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: (telemetry) NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: \GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem128.0.6537.0{2C26F013-60FA-4EFC-A89E-248BC014374F} - C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe --wake --system (sign: 'Google LLC')
O22 - Tasks: \Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - C:\WINDOWS\System32\MbaeParserTask.exe (file missing)
O22 - Tasks: \Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults - C:\WINDOWS\system32\MusNotification.exe LogonUpdateResults (file missing)
O22 - Tasks: \Microsoft\Windows\UpdateOrchestrator\Reboot_AC - C:\WINDOWS\system32\MusNotification.exe /RunOnAC ReadyToReboot (file missing)
O22 - Tasks: \Microsoft\Windows\UpdateOrchestrator\Reboot_Battery - C:\WINDOWS\system32\MusNotification.exe /RunOnBattery ReadyToReboot (file missing)
O22 - Tasks: \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker - C:\WINDOWS\system32\MusNotification.exe (file missing)
O22 - Tasks: \THX Ltd\THX Update Service\THX-Restart-v0-33-0 - C:\WINDOWS\system32\shutdown.exe /r /d p:01:01 (sign: 'Microsoft')
O22 - Tasks: \THX Ltd\THX Update Service\THX-Update-Service-v0-33-0 - C:\Program Files\THX\thx-update-svc.exe -syslog (sign: 'THX Ltd')
O22 - Tasks: \THX Ltd\THX Update Service\THX-Upgrade-Install-v0-33-0 - C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Bypass -File "C:\Program Files\thx\THX-Upgrade-Install.ps1" (sign: 'Microsoft')
O22 - Tasks: BlueStacksHelper_nxt - C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe -sr (sign: 'Now.gg, INC')
O22 - Tasks: Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} - C:\Program Files\Common Files\AV\Kaspersky\upgrade_launcher.exe /waitUpgrade (sign: 'AO Kaspersky Lab')
O22 - Tasks: NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log (sign: 'NVIDIA Corporation')
O22 - Tasks: NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe --launcher=TaskScheduler (sign: 'NVIDIA Corporation')
O22 - Tasks: NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: OneDrive Reporting Task-S-1-5-21-1523529878-4115861191-3633226384-1001 - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting (sign: 'Microsoft')
O22 - Tasks: Opera scheduled assistant Autoupdate 1686249293 - C:\Users\Amazoner\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Amazoner\AppData\Local\Programs\Opera\assistant" $(Arg0) (sign: 'Opera Norway AS')
O22 - Tasks: Opera scheduled Autoupdate 1667986183 - C:\Users\Amazoner\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe --scheduledtask --bypasslauncher $(Arg0) (sign: 'Opera Norway AS')
O22 - Tasks: PostponeDeviceSetupToast_S-1-5-21-1523529878-4115861191-3633226384-1001_4 - {5ded83ef-1e99-48cf-bf83-676d2a6db408},PostponeDeviceSetupToast - C:\Windows\System32\oobe\UserOOBE.dll (file missing)
O22 - Tasks: SamsungMagician - C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe --disable-gpu-sandbox /AUTOHIDE (sign: 'Samsung Electronics Co., Ltd.')
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Clip\LicenseImdsIntegration - C:\WINDOWS\system32\fclip.exe (sign: 'Microsoft')
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ProvRetryTask (sign: 'Microsoft')
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (sign: 'Microsoft')
O22 - Tasks_Migrated: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\WINDOWS\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc (sign: 'Microsoft')
O22 - Tasks_Migrated: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\WINDOWS\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareData (sign: 'Microsoft')
O22 - Tasks_Migrated: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\WINDOWS\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun (sign: 'Microsoft')
O22 - Tasks_Migrated: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask (sign: 'Microsoft')
O22 - Tasks_Migrated: (telemetry) NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'NVIDIA Corporation')
O22 - Tasks_Migrated: (telemetry) NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'NVIDIA Corporation')
O22 - Tasks_Migrated: (telemetry) NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'NVIDIA Corporation')
O22 - Tasks_Migrated: (telemetry) NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'NVIDIA Corporation')
O22 - Tasks_Migrated: \Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser - C:\WINDOWS\System32\MbaeParserTask.exe (file missing)
O22 - Tasks_Migrated: \Microsoft\Windows\SettingSync\BackgroundUploadTask - {59B9640B-3F70-4D1C-B159-F26EEB8A4C87} - (no file)
O22 - Tasks_Migrated: \Microsoft\Windows\SettingSync\NetworkStateChangeTask - {A4173A49-F373-4475-9A0F-2D615204DC20} - (no file)
O22 - Tasks_Migrated: \Microsoft\Windows\UpdateOrchestrator\MusUx_LogonUpdateResults - C:\WINDOWS\system32\MusNotification.exe LogonUpdateResults (file missing)
O22 - Tasks_Migrated: \THX Ltd\THX Update Service\THX-Restart-v0-33-0 - C:\WINDOWS\system32\shutdown.exe /r /d p:01:01 (sign: 'Microsoft')
O22 - Tasks_Migrated: \THX Ltd\THX Update Service\THX-Update-Service-v0-33-0 - C:\Program Files\THX\thx-update-svc.exe -syslog (sign: 'THX Ltd')
O22 - Tasks_Migrated: \THX Ltd\THX Update Service\THX-Upgrade-Install-v0-33-0 - C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Bypass -File "C:\Program Files\thx\THX-Upgrade-Install.ps1" (sign: 'Microsoft')
O22 - Tasks_Migrated: GoogleUpdateTaskMachineCore{170E9C36-C56A-4BAE-869C-8A7722B9A319} - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c (sign: 'Google LLC')
O22 - Tasks_Migrated: GoogleUpdateTaskMachineUA{42443CFA-896E-4882-8BD8-113FF6953144} - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler (sign: 'Google LLC')
O22 - Tasks_Migrated: Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} - C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe /waitUpgrade (file missing)
O22 - Tasks_Migrated: NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log (sign: 'NVIDIA Corporation')
O22 - Tasks_Migrated: NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (sign: 'NVIDIA Corporation')
O22 - Tasks_Migrated: NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe --launcher=TaskScheduler (sign: 'NVIDIA Corporation')
O22 - Tasks_Migrated: NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe (sign: 'NVIDIA Corporation')
O22 - Tasks_Migrated: NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe (sign: 'NVIDIA Corporation')
O22 - Tasks_Migrated: OneDrive Reporting Task-S-1-5-21-1523529878-4115861191-3633226384-1001 - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting (sign: 'Microsoft')
O22 - Tasks_Migrated: Opera scheduled assistant Autoupdate 1686249293 - C:\Users\Amazoner\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Amazoner\AppData\Local\Programs\Opera\assistant" $(Arg0) (sign: 'Opera Norway AS')
O22 - Tasks_Migrated: Opera scheduled Autoupdate 1667986183 - C:\Users\Amazoner\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (sign: 'Opera Norway AS')
O22 - Tasks_Migrated: SamsungMagician - C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe /AUTOHIDE (sign: 'Samsung Electronics Co., Ltd.')
O23 - Service R2: CAM Service - (CAMService) - C:\Program Files\NZXT CAM\resources\app.asar.unpacked\node_modules\@nzxt\cam-core\dist\target\x86_64-pc-windows-msvc\release\service.exe (sign: 'NZXT, Inc.')
O23 - Service R2: CMigrationService - C:\Program Files (x86)\Samsung\Samsung Magician\MigrationService\MigrationService.exe (sign: 'Samsung Electronics Co., Ltd.')
O23 - Service R2: GCUBridge - C:\Program Files\OEM\Monster Kontrol Merkezi\UniwillService\GCUBridge.exe (sign: 'Uniwill Technology Inc.')
O23 - Service R2: Intel(R) Content Protection HDCP Service - (cplspcon) - C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b260c545909302e9\IntelCpHDCPSvc.exe (sign: 'Intel Corporation')
O23 - Service R2: Intel(R) Dynamic Application Loader Host Interface Service - (jhi_service) - C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe (sign: 'Intel Corporation')
O23 - Service R2: Intel(R) Graphics Command Center Service - (igccservice) - C:\WINDOWS\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_401fde8782680631\OneApp.IGCC.WinService.exe (sign: 'Intel Corporation')
O23 - Service R2: Intel(R) HD Graphics Control Panel Service - (igfxCUIService2.0.0.0) - C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_5207db0559876a61\igfxCUIService.exe (sign: 'Intel Corporation')
O23 - Service R2: Intel(R) Management Engine WMI Provider Registration - (WMIRegistrationService) - C:\WINDOWS\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe (sign: 'Intel Corporation')
O23 - Service R2: Intel(R) Rapid Storage Technology - (IAStorDataMgrSvc) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (sign: 'Intel(R) Rapid Storage Technology')
O23 - Service R2: Intel(R) Storage Middleware Service - (RstMwService) - C:\WINDOWS\System32\DriverStore\FileRepository\iaahcic.inf_amd64_48973fc6c96c696a\RstMwService.exe (sign: 'Intel(R) Rapid Storage Technology')
O23 - Service R2: Kaspersky Password Manager 24.1 Service - (kpm_service_24.1) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Password Manager 24.1\kpm_service.exe (sign: 'AO Kaspersky Lab')
O23 - Service R2: Kaspersky Service 21.17 - (AVP21.17) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\avp.exe -r (sign: 'Kaspersky Lab JSC')
O23 - Service R2: Logi Options+ - (OptionsPlusUpdaterService) - C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe --run-as-service (sign: 'Logitech Inc')
O23 - Service R2: MSPCManager Service (Store) - (PCManager Service Store) - C:\Program Files\WindowsApps\Microsoft.MicrosoftPCManager_3.12.1.0_x64__8wekyb3d8bbwe\PCManager\MSPCManagerService.exe (sign: 'Microsoft')
O23 - Service R2: NVIDIA Display Container LS - (NVDisplay.ContainerLocalSystem) - C:\WINDOWS\System32\DriverStore\FileRepository\nvtfi.inf_amd64_4cd94d3ab4900da6\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvtfi.inf_amd64_4cd94d3ab4900da6\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem /ert (sign: 'NVIDIA Corporation')
O23 - Service R2: NVIDIA LocalSystem Container - (NvContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" -ert (sign: 'NVIDIA Corporation')
O23 - Service R2: Realtek Audio Universal Service - (RtkAudioUniversalService) - C:\WINDOWS\System32\RtkAudUService64.exe (sign: 'Realtek Semiconductor Corp.')
O23 - Service R2: SamsungMagicianSVC - C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagicianSVC.exe (sign: 'Samsung Electronics Co., Ltd.')
O23 - Service R2: VSSrv - C:\Windows\system32\VSSrv.exe (sign: 'THX Ltd')
O23 - Service R3: Intel(R) Content Protection HECI Service - (cphs) - C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b260c545909302e9\IntelCpHeciSvc.exe (sign: 'Intel Corporation')
O23 - Service R3: NVIDIA FrameView SDK service - (FvSvc) - C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe -service (sign: 'NVIDIA Corporation')
O23 - Service S2: Google Güncelleme Hizmeti (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc (sign: 'Google LLC')
O23 - Service S2: GoogleUpdater InternalService 128.0.6537.0 (GoogleUpdaterInternalService128.0.6537.0) - (GoogleUpdaterInternalService128.0.6537.0) - C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe --system --windows-service --service=update-internal (sign: 'Google LLC')
O23 - Service S2: GoogleUpdater Service 128.0.6537.0 (GoogleUpdaterService128.0.6537.0) - (GoogleUpdaterService128.0.6537.0) - C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe --system --windows-service --service=update (sign: 'Google LLC')
O23 - Service S2: Intel(R) TPM Provisioning Service - C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\TPMProvisioningService.exe (sign: 'Intel Corporation')
O23 - Service S2: Kaspersky Service 21.16 - (AVP21.16) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.16\avp.exe -r (file missing)
O23 - Service S3: EABackgroundService - C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe (sign: 'Electronic Arts, Inc.')
O23 - Service S3: FileSyncHelper - C:\Program Files\Microsoft OneDrive\24.116.0609.0005\FileSyncHelper.exe (sign: 'Microsoft')
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService) - (GoogleChromeElevationService) - C:\Program Files\Google\Chrome\Application\126.0.6478.127\elevation_service.exe (sign: 'Google LLC')
O23 - Service S3: Google Güncelleme Hizmeti (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc (sign: 'Google LLC')
O23 - Service S3: Intel(R) Capability Licensing Service TCP IP Interface - C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\SocketHeciServer.exe (sign: 'Intel Corporation')
O23 - Service S3: Kaspersky Volume Shadow Copy Service Bridge 21.16 - (klvssbridge64_21.16) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.16\x64\vssbridge64.exe (sign: 'AO Kaspersky Lab')
O23 - Service S3: Kaspersky Volume Shadow Copy Service Bridge 21.17 - (klvssbridge64_21.17) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\x64\vssbridge64.exe (sign: 'AO Kaspersky Lab')
O23 - Service S3: Kaspersky VPN Secure Connection Hizmeti 5.17 - (KSDE5.17) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.17\ksde.exe -r (sign: 'Kaspersky Lab JSC')
O23 - Service S3: OneDrive Updater Service - C:\Program Files\Microsoft OneDrive\24.116.0609.0005\OneDriveUpdaterService.exe (sign: 'Microsoft')
O23 - Service S3: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\steamservice.exe /RunAsService (sign: 'Valve Corp.')
O23 - Driver R0: AO Kaspersky Lab Cryptographic Module x64 (56 bit) - (cm_km) - C:\WINDOWS\system32\DRIVERS\cm_km.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R0: Intel(R) Chipset SATA/PCIe RST Premium Controller - (iaStorAC) - C:\WINDOWS\System32\drivers\iaStorAC.sys (sign: 'Intel(R) Rapid Storage Technology')
O23 - Driver R0: klupd_K4W-21-17_arkmon - C:\WINDOWS\System32\Drivers\klupd_K4W-21-17_arkmon.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R0: klupd_K4W-21-17_klbg - C:\WINDOWS\System32\Drivers\klupd_K4W-21-17_klbg.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: googledrivefs31357 - C:\WINDOWS\System32\DriverStore\FileRepository\googledrivefs31357.inf_amd64_a8bf31a168cf7d00\googledrivefs31357.sys (+safe mode) (sign: 'Microsoft' - Google, Inc.)
O23 - Driver R1: Kaspersky Anti-Virus NDIS 6 Filter - (klim6) - C:\WINDOWS\system32\DRIVERS\klim6.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab Driver.K4W-21-16 - (KLIF.K4W-21-16) - C:\WINDOWS\system32\DRIVERS\K4W-21-16\klif.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab Driver.K4W-21-17 - (KLIF.K4W-21-17) - C:\WINDOWS\system32\DRIVERS\K4W-21-17\klif.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab format recognizer driver.K4W-21-16 - (klpd.K4W-21-16) - C:\WINDOWS\system32\DRIVERS\K4W-21-16\klpd.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab format recognizer driver.K4W-21-17 - (klpd.K4W-21-17) - C:\WINDOWS\system32\DRIVERS\K4W-21-17\klpd.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab Kernel DLL.K4W-21-16 - (klflt.K4W-21-16) - C:\WINDOWS\system32\DRIVERS\K4W-21-16\klflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab Kernel DLL.K4W-21-17 - (KLFLT.K4W-21-17) - C:\WINDOWS\system32\DRIVERS\K4W-21-17\klflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab klbackupdisk.K4W-21-16 - (klbackupdisk.K4W-21-16) - C:\WINDOWS\system32\DRIVERS\K4W-21-16\klbackupdisk.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab klbackupdisk.K4W-21-17 - (klbackupdisk.K4W-21-17) - C:\WINDOWS\system32\DRIVERS\K4W-21-17\klbackupdisk.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab klbackupflt.K4W-21-16 - (klbackupflt.K4W-21-16) - C:\WINDOWS\system32\DRIVERS\K4W-21-16\klbackupflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab klbackupflt.K4W-21-17 - (klbackupflt.K4W-21-17) - C:\WINDOWS\system32\DRIVERS\K4W-21-17\klbackupflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab KLKBDFLT.K4W-21-16 - (klkbdflt.K4W-21-16) - C:\WINDOWS\system32\DRIVERS\K4W-21-16\klkbdflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab KLKBDFLT.K4W-21-17 - (klkbdflt.K4W-21-17) - C:\WINDOWS\system32\DRIVERS\K4W-21-17\klkbdflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab klpnpflt.K4W-21-16 - (klpnpflt.K4W-21-16) - C:\WINDOWS\system32\DRIVERS\K4W-21-16\klpnpflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab klpnpflt.K4W-21-17 - (klpnpflt.K4W-21-17) - C:\WINDOWS\system32\DRIVERS\K4W-21-17\klpnpflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab Security Extender Driver.K4W-21-17 - (klgse.K4W-21-17) - C:\WINDOWS\system32\DRIVERS\K4W-21-17\klgse.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab service driver.K4W-21-17 - (KLHK.K4W-21-17) - C:\WINDOWS\system32\DRIVERS\K4W-21-17\klhk.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: kldisk.K4W-21-16 - C:\WINDOWS\system32\DRIVERS\K4W-21-16\kldisk.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: kldisk.K4W-21-17 - C:\WINDOWS\system32\DRIVERS\K4W-21-17\kldisk.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: klwtp.K4W-21-16 - C:\WINDOWS\system32\DRIVERS\K4W-21-16\klwtp.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: klwtp.K4W-21-17 - C:\WINDOWS\system32\DRIVERS\K4W-21-17\klwtp.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: kneps.K4W-21-16 - C:\WINDOWS\system32\DRIVERS\K4W-21-16\kneps.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: kneps.K4W-21-17 - C:\WINDOWS\system32\DRIVERS\K4W-21-17\kneps.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R2: BlueStacks Hypervisor_nxt - (BlueStacksDrv_nxt) - C:\Program Files\BlueStacks_nxt\BstkDrv_nxt.sys (sign: 'Microsoft' - Bluestack System Inc.)
O23 - Driver R2: IDMWFP - C:\WINDOWS\System32\drivers\idmwfp.sys (sign: 'Microsoft' - Tonec Inc.)
O23 - Driver R2: inpoutx64 - C:\WINDOWS\System32\Drivers\inpoutx64.sys (sign: 'Red Fox UK Limited')
O23 - Driver R3: ___ Windows 10 64 Bit için Intel(R) Wireless Bağdaştırıcı Sürücüsü  - (Netwtw10) - C:\WINDOWS\System32\drivers\Netwtw10.sys (+safe mode) (sign: 'Intel Corporation')
O23 - Driver R3: HID ACPI driver - (vhidmini) - C:\WINDOWS\System32\drivers\vhidmini.sys (sign: 'Microsoft' - Windows (R) Win 7 DDK provider)
O23 - Driver R3: igfx - C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b260c545909302e9\igdkmd64.sys (sign: 'Intel Corporation')
O23 - Driver R3: Intel(R) Display Audio - (IntcDAud) - C:\WINDOWS\System32\DriverStore\FileRepository\intcdaud.inf_amd64_718877413f6508de\IntcDAud.sys (sign: 'Intel Corporation')
O23 - Driver R3: Intel(R) Management Engine Interface  - (MEIx64) - C:\WINDOWS\System32\DriverStore\FileRepository\heci.inf_amd64_6b6e8cc42a3d1f09\x64\TeeDriverW10x64.sys (sign: 'Intel Corporation')
O23 - Driver R3: Intel(R) Serial IO GPIO Driver v2 - (iaLPSS2_GPIO2) - C:\WINDOWS\System32\drivers\iaLPSS2_GPIO2.sys (sign: 'Intel(R) Embedded Subsystems and IP Blocks Group')
O23 - Driver R3: Intel(R) Serial IO UART Driver v2 - (iaLPSS2_UART2) - C:\WINDOWS\System32\drivers\iaLPSS2_UART2.sys (sign: 'Intel(R) Embedded Subsystems and IP Blocks Group')
O23 - Driver R3: Intel(R) Wireless Bluetooth(R) - (ibtusb) - C:\WINDOWS\System32\DriverStore\FileRepository\ibtusb.inf_amd64_f75065d93521b024\ibtusb.sys (+safe mode) (sign: 'Intel Corporation')
O23 - Driver R3: Kaspersky Lab KLMOUFLT.K4W-21-17 - (klmouflt.K4W-21-17) - C:\WINDOWS\system32\DRIVERS\K4W-21-17\klmouflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: Kaspersky VPN - (kltun) - C:\WINDOWS\system32\DRIVERS\kltun.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: klids.K4W-21-17 - C:\ProgramData\Kaspersky Lab\AVP21.17\Bases\klids.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: klupd_K4W-21-17_klark - C:\WINDOWS\System32\Drivers\klupd_K4W-21-17_klark.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: klupd_K4W-21-17_mark - C:\WINDOWS\System32\Drivers\klupd_K4W-21-17_mark.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: NVIDIA Virtual Audio Device (Wave Extensible) (WDM) - (nvvad_WaveExtensible) - C:\WINDOWS\system32\drivers\nvvad64v.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: nvlddmkm - C:\WINDOWS\System32\DriverStore\FileRepository\nvtfi.inf_amd64_4cd94d3ab4900da6\nvlddmkm.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: NvModuleTracker - C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: NVVHCI Enumerator Service - (nvvhci) - C:\WINDOWS\System32\drivers\nvvhci.sys (sign: 'Nvidia Corporation')
O23 - Driver R3: Realtek USB Card Reader - UER - (RTSUER) - C:\WINDOWS\system32\Drivers\RtsUer.sys (sign: 'Realtek Semiconductor Corp.')
O23 - Driver R3: Service for NVIDIA High Definition Audio Driver - (NVHDA) - C:\WINDOWS\system32\drivers\nvhda64v.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: Service for Realtek HD Audio (WDM) - (IntcAzAudAddService) - C:\WINDOWS\system32\drivers\RTKVHD64.sys (sign: 'Realtek Semiconductor Corp.')
O23 - Driver R3: SparkIO - C:\Windows\system32\SparkIO.sys (sign: 'Microsoft' - no company)
O23 - Driver R3: THX Spatial Audio - (THXVAD) - C:\WINDOWS\System32\drivers\THXVAD.sys (sign: 'THX Ltd')
O23 - Driver S1: WinSetupMon - C:\WINDOWS\system32\DRIVERS\WinSetupMon.sys (file missing)
O23 - Driver S3: Apple KMDF Filter Driver - (AppleKmdfFilter) - C:\WINDOWS\System32\drivers\AppleKmdfFilter.sys (sign: 'WDKTestCert build,132303256403278908', but untrusted root: 'WDKTestCert build,132303256403278908' with fingerprint: 8EEDA9453BAACAF984D1D35995292793B3D27A28)
O23 - Driver S3: Apple Lower Filter Driver - (AppleLowerFilter) - C:\WINDOWS\System32\drivers\AppleLowerFilter.sys (sign: 'Apple Inc.')
O23 - Driver S3: Apple Wireless Mouse - (applebmt) - C:\WINDOWS\system32\DRIVERS\applebmt.sys (not signed - Apple Inc. - 9FB593BFA11923224EDC09C8D8D9092EBC276CFA)
O23 - Driver S3: Intel(R) Serial IO GPIO Controller Driver - (iaLPSSi_GPIO) - C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys (sign: 'Intel Corporation - Client Components Group')
O23 - Driver S3: Kaspersky Lab KLMOUFLT.K4W-21-16 - (klmouflt.K4W-21-16) - C:\WINDOWS\system32\DRIVERS\K4W-21-16\klmouflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver S3: klids.K4W-21-16 - C:\ProgramData\Kaspersky Lab\AVP21.16\Bases\klids.sys (file missing)
O23 - Driver S3: Realtek USB FE/1GbE/2.5GbE/5GbE NIC Family Miniport 6.4 64-bit Driver - (rtump64x64) - C:\WINDOWS\System32\drivers\rtump64x64.sys (+safe mode) (sign: 'Realtek Semiconductor Corp.')
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service:  'klim6'
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service:  'kltun'
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service:  'klwtp.K4W-21-16'
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service:  'klwtp.K4W-21-17'
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service:  'Netwtw10'
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service:  'rtump64x64'


--
End of file - Time spent: 41.4 sec. - 86910 bytes, CRC32: FFFFFFFF. Sign: ᒯꦈ
 
Acaba ne yapmalıyım.
Bunları fixleyin ilk önce:
Kod:
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8}: [SuggestionsURL_JSON] = hxxps://suggest.yandex.com.tr/suggest-ff.cgi?srv=ie11&uil=tr&part={searchTerms}&clid=2233630 - Yandex
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8}: [URL] = hxxps://yandex.com.tr/search/?text={searchTerms}&clid=2233630 - Yandex
O4 - ActiveSetup: HKLM\..\{8A69D345-D564-463c-AFF1-A69D9E530F96}: [StubPath] = C:\Program Files\Google\Chrome\Application\126.0.6478.127\Installer\chrmstp.exe --configure-user-settings --verbose-logging --system-level --channel=stable (sign: 'Google LLC')
O4 - HKCU\..\Run: [GoogleChromeAutoLaunch_179A20440F73D81F360A8C91425976B5] = C:\Program Files\Google\Chrome\Application\chrome.exe --no-startup-window /prefetch:5 (sign: 'Google LLC')
O4 - HKCU\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe --startup_mode (sign: 'Google LLC')
O4 - HKCU\..\StartupApproved\Run: [MicrosoftEdgeAutoLaunch_4E936087059E131F21130A0886C1FCE8] = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --no-startup-window --win-session-start (2022/11/22) (sign: 'Microsoft')
O4 - HKCU\..\StartupApproved\Run: [NZXT.CAM] = C:\Program Files\NZXT CAM\NZXT CAM.exe --startup (2022/11/22) (sign: 'NZXT, Inc.')
O4 - HKCU\..\StartupApproved\Run: [OneDrive] = C:\Program Files\Microsoft OneDrive\OneDrive.exe /background (2022/11/22) (sign: 'Microsoft')
O4 - HKCU\..\StartupApproved\Run: [Opera Browser Assistant] = C:\Users\Amazoner\AppData\Local\Programs\Opera\assistant\browser_assistant.exe (sign: 'Opera Norway AS')
O4 - HKCU\..\StartupApproved\Run: [Opera Stable] = C:\Users\Amazoner\AppData\Local\Programs\Opera\opera.exe (sign: 'Opera Norway AS')
O4 - HKCU\..\StartupApproved\Run: [Wechat] = C:\Program Files (x86)\Tencent\WeChat\WeChat.exe -autorun (2023/03/28) (sign: 'Tencent Technology (Shenzhen) Company Limited')
O4 - HKLM\..\Run: [IAStorIcon] = C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60 (sign: 'Intel(R) Rapid Storage Technology')
O4 - HKLM\..\Run: [Logitech Download Assistant] = C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch (sign: 'Microsoft')

O4 - HKLM\..\StartupApproved\Run32: [SunJavaUpdateSched] = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (sign: 'Oracle America, Inc.')
O4 - HKU\S-1-5-18\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe --startup_mode (User 'LocalSystem') (sign: 'Google LLC')
O4 - HKU\S-1-5-19\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe --startup_mode (User 'Local service') (sign: 'Google LLC')
O4 - HKU\S-1-5-19\..\Run: [OneDriveSetup] = C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'Local service') (sign: 'Microsoft')
O4 - HKU\S-1-5-20\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\92.0.1.0\GoogleDriveFS.exe --startup_mode (User 'Network service') (sign: 'Google LLC')
O4 - HKU\S-1-5-20\..\Run: [OneDriveSetup] = C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'Network service') (sign: 'Microsoft')
O22 - Tasks: BlueStacksHelper_nxt - C:\Program Files\BlueStacks_nxt\BlueStacksHelper.exe -sr (sign: 'Now.gg, INC')
O22 - Tasks: OneDrive Reporting Task-S-1-5-21-1523529878-4115861191-3633226384-1001 - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting (sign: 'Microsoft')
O22 - Tasks: Opera scheduled assistant Autoupdate 1686249293 - C:\Users\Amazoner\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Amazoner\AppData\Local\Programs\Opera\assistant" $(Arg0) (sign: 'Opera Norway AS')
O22 - Tasks: Opera scheduled Autoupdate 1667986183 - C:\Users\Amazoner\AppData\Local\Programs\Opera\autoupdate\opera_autoupdate.exe --scheduledtask --bypasslauncher $(Arg0) (sign: 'Opera Norway AS')
O22 - Tasks: SamsungMagician - C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe --disable-gpu-sandbox /AUTOHIDE (sign: 'Samsung Electronics Co., Ltd.')
O22 - Tasks_Migrated: OneDrive Reporting Task-S-1-5-21-1523529878-4115861191-3633226384-1001 - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting (sign: 'Microsoft')
O22 - Tasks_Migrated: Opera scheduled assistant Autoupdate 1686249293 - C:\Users\Amazoner\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Amazoner\AppData\Local\Programs\Opera\assistant" $(Arg0) (sign: 'Opera Norway AS')
O22 - Tasks_Migrated: Opera scheduled Autoupdate 1667986183 - C:\Users\Amazoner\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (sign: 'Opera Norway AS')
O22 - Tasks_Migrated: SamsungMagician - C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe /AUTOHIDE (sign: 'Samsung Electronics Co., Ltd.')
 
Merhaba @Murat5038,

Bilgisayarımın performansından memnundum son zamanlarda Discord kullanırken veya klasörlerde geçiş yaparken bile "yanıt vermiyor" şeklinde donuyordu. Bir göz atabilirseniz çok sevinirim.


Kod:
Logfile of HiJackThis+ (Plus) build 2024-04-18 Alpha v.3.4.0.9

Platform:  x64 Windows 10 (Pro), 10.0.19045.4651 (ReleaseId: 2009, 22H2), Service Pack: 0
Time:      22.07.2024 - 01:53 (UTC+03:00)
Language:  OS: English (0x409). Display: English (0x409). Non-Unicode: English (0x409)
Memory:    13095 MiB Free. Loading RAM (21 %), CPU (3 %)
Elevated:  Yes
Ran by:    Cati    (group: Administrators; type: Local) on DESKTOP-HQFUCQU, FirstRun: yes

Chrome:  126.0.6478.182
Firefox: 128.0.0.2295
Internet Explorer: 11.0.19041.4355
Default: "C:\Program Files\Google\Chrome\Application\chrome.exe" --single-argument %1 (Google Chrome)

Boot mode: Normal (Secure Boot: Off)

Running processes:
Number | Path
   1  C:\Program Files (x86)\AnyDesk\AnyDesk.exe
   1  C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
   1  C:\Program Files (x86)\Skillbrains\lightshot\5.5.0.7\Lightshot.exe
   1  C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
   2  C:\Program Files\NVIDIA Corporation\NvBroadcast.NvContainer\NvBroadcast.Container.exe
   1  C:\Program Files\NVIDIA Corporation\NVIDIA Broadcast\NVIDIA Broadcast UI.exe
   1  C:\Program Files\NVIDIA Corporation\NVIDIA Broadcast\NvVirtualCamera\NVIDIA Broadcast.exe
   1  C:\Program Files\WindowsApps\Microsoft.GamingServices_22.91.10001.0_x64__8wekyb3d8bbwe\gamingservices.exe
   1  C:\Program Files\WindowsApps\Microsoft.GamingServices_22.91.10001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe
   6  C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.241.434.0_x64__zpdnekdrzrea0\Spotify.exe
   1  C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpDefenderCoreService.exe
   1  C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MsMpEng.exe
   1  C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\NisSrv.exe
   1  C:\Users\Cati\Downloads\HiJackThis\HiJackThis.exe
   1  C:\Windows\explorer.exe
   1  C:\Windows\System32\audiodg.exe
   1  C:\Windows\System32\backgroundTaskHost.exe
   2  C:\Windows\System32\csrss.exe
   2  C:\Windows\System32\dllhost.exe
   1  C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe
   2  C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_7e5fd280efaa5445\Display.NvContainer\NVDisplay.Container.exe
   1  C:\Windows\System32\dwm.exe
   2  C:\Windows\System32\fontdrvhost.exe
   1  C:\Windows\System32\lsass.exe
   1  C:\Windows\System32\MoUsoCoreWorker.exe
   1  C:\Windows\System32\MusNotification.exe
   4  C:\Windows\System32\RuntimeBroker.exe
   1  C:\Windows\System32\SearchIndexer.exe
   1  C:\Windows\System32\SecurityHealthService.exe
   1  C:\Windows\System32\SecurityHealthSystray.exe
   1  C:\Windows\System32\services.exe
   1  C:\Windows\System32\SgrmBroker.exe
   1  C:\Windows\System32\sihost.exe
   1  C:\Windows\System32\smartscreen.exe
   1  C:\Windows\System32\smss.exe
   1  C:\Windows\System32\spoolsv.exe
   1  C:\Windows\System32\SppExtComObj.Exe
   1  C:\Windows\System32\sppsvc.exe
  75  C:\Windows\System32\svchost.exe
   1  C:\Windows\System32\taskhostw.exe
   1  C:\Windows\System32\wbem\WmiPrvSE.exe
   1  C:\Windows\System32\wininit.exe
   1  C:\Windows\System32\winlogon.exe
   1  C:\Windows\System32\WUDFHost.exe
   1  C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
   1  C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
   1  C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
   1  C:\Windows\SysWOW64\dllhost.exe

O2-32 - HKLM\..\BHO: Lync Click to Call BHO - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll (file missing)
O4 - ActiveSetup: HKLM\..\{8A69D345-D564-463c-AFF1-A69D9E530F96}: [StubPath] = C:\Program Files\Google\Chrome\Application\126.0.6478.182\Installer\chrmstp.exe --configure-user-settings --verbose-logging --system-level --channel=stable (sign: 'Google LLC')
O4 - HKCU\..\StartupApproved\Run: [Battle.net] = C:\Program Files (x86)\Battle.net\Battle.net.exe --autostarted (2023/02/21) (sign: 'Blizzard Entertainment, Inc.')
O4 - HKCU\..\StartupApproved\Run: [com.blitz.app] = "C:\Users\Cati\AppData\Local\Programs\Blitz\Blitz.exe" --autostart (file missing) (2022/12/15)
O4 - HKCU\..\StartupApproved\Run: [com.squirrel.slack.slack] = C:\Users\Cati\AppData\Local\slack\slack.exe --process-start-args --startup (sign: 'Slack Technologies, LLC')
O4 - HKCU\..\StartupApproved\Run: [Discord] = C:\Users\Cati\AppData\Local\Discord\Update.exe --processStart Discord.exe (2022/02/16) (sign: 'Discord Inc.')
O4 - HKCU\..\StartupApproved\Run: [DiscordCanary] = C:\Users\Cati\AppData\Local\DiscordCanary\Update.exe --processStart DiscordCanary.exe (2022/02/16) (sign: 'Discord Inc.')
O4 - HKCU\..\StartupApproved\Run: [EpicGamesLauncher] = C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe -silent -launchcontext=boot (2022/02/16) (sign: 'Epic Games Inc.')
O4 - HKCU\..\StartupApproved\Run: [Medal] = C:\Users\Cati\AppData\Local\Medal\update.exe --processStart "Medal.exe" (2022/12/15) (sign: 'Ferox Games B.V.')
O4 - HKCU\..\StartupApproved\Run: [MicrosoftEdgeAutoLaunch_568E5DCA129F25A9393055C379DB1F74] = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --no-startup-window --win-session-start (2022/02/02) (sign: 'Microsoft')
O4 - HKCU\..\StartupApproved\Run: [NoxMultiPlayer] = "D:\Program Files\Nox\bin\MultiPlayerManager.exe" -startSource:auto_start (file missing) (2022/06/06)
O4 - HKCU\..\StartupApproved\Run: [Opera GX Browser Assistant] = C:\Users\Cati\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe (2023/02/21) (sign: 'Opera Software AS')
O4 - HKCU\..\StartupApproved\Run: [Opera GX Stable] = C:\Users\Cati\AppData\Local\Programs\Opera GX\launcher.exe (2023/02/21) (sign: 'Opera Norway AS')
O4 - HKCU\..\StartupApproved\Run: [Overwolf] = C:\Program Files (x86)\Overwolf\OverwolfLauncher.exe -overwolfsilent (2022/02/16) (sign: 'Overwolf Ltd')
O4 - HKCU\..\StartupApproved\Run: [RiotClient] = C:\Riot Games\Riot Client\RiotClientServices.exe --launch-background-mode (2023/10/09) (sign: 'Riot Games, Inc.')
O4 - HKCU\..\StartupApproved\Run: [Snap Camera] = C:\Program Files\Snap Inc\Snap Camera\Snap Camera.exe --minimized-mode (2022/02/16) (sign: 'Snap Inc.')
O4 - HKCU\..\StartupApproved\Run: [Steam] = C:\Program Files (x86)\Steam\steam.exe -silent (2023/10/09) (sign: 'Valve Corp.')
O4 - HKCU\..\StartupApproved\Run: [utweb] = "C:\Users\Cati\AppData\Roaming\uTorrent Web\utweb.exe" /MINIMIZED (file missing) (2022/12/15)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\W32X86\3\New\mxdwdrv.dll -> C:\Windows\system32\spool\DRIVERS\W32X86\3\mxdwdrv.dll (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\W32X86\3\New\PrintConfig.dll -> C:\Windows\system32\spool\DRIVERS\W32X86\3\PrintConfig.dll (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\FXSAPI.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\FXSAPI.DLL (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\FXSDRV.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\FXSDRV.DLL (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\FXSRES.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\FXSRES.DLL (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\FXSTIFF.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\FXSTIFF.DLL (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\FXSUI.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\FXSUI.DLL (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\FXSUI.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\FXSUI.DLL (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\FXSWZRD.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\FXSWZRD.DLL (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\MXDWDRV.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\MXDWDRV.DLL (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\PJLMON.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\PJLMON.DLL (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\PrintConfig.dll -> C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\PS5UI.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\PS5UI.DLL (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\PSCRIPT5.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\PSCRIPT5.DLL (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\UNIDRV.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\UNIDRV.DLL (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\UNIDRVUI.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\UNIDRVUI.DLL (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\UNIRES.DLL -> C:\Windows\system32\spool\DRIVERS\x64\3\UNIRES.DLL (file missing)
O4 - HKLM\..\StartupApproved\Run: [Riot Vanguard] = C:\Program Files\Riot Vanguard\vgtray.exe (2023/10/09) (sign: 'Riot Games, Inc.')
O4 - HKLM\..\StartupApproved\Run: [SteelSeriesGG] = C:\Program Files\SteelSeries\GG\SteelSeriesGG.exe -dataPath="C:\ProgramData\SteelSeries\GG" -dbEnv=production -auto=true (2023/08/24) (sign: 'SteelSeries ApS')
O4 - HKLM\..\StartupApproved\Run32: [Adobe CCXProcess] = C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe (2022/06/06) (sign: 'Adobe Inc.')
O4 - HKLM\..\StartupApproved\Run32: [DiscordCanary] = C:\ProgramData\SquirrelMachineInstalls\DiscordCanary.exe --checkInstall (2023/03/31) (sign: 'Discord Inc.')
O4 - HKLM\..\StartupApproved\StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DeepL auto-start.lnk    ->    C:\ProgramData\0install.net\desktop-integration\stubs\1eae01f3cdb5ff0ecf683b15a60a1489573c1188cb34abc205fcf7a924b4e54d\auto-start.exe (2024/02/19) (not signed - no company - FE3ABCDC59CD077ECF316CDDBA14D0B95C240951)
O4 - HKU\S-1-5-18\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe --startup_mode (file missing) (User 'LocalSystem')
O4 - HKU\S-1-5-18\..\Run: [Synapse3] = C:\Program Files (x86)\Razer\Synapse3\WPFUI\Framework\Razer Synapse 3 Host\Razer Synapse 3.exe /StartMinimized (file missing) (User 'LocalSystem')
O4 - HKU\S-1-5-19\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe --startup_mode (file missing) (User 'Local service')
O4 - HKU\S-1-5-20\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe --startup_mode (file missing) (User 'Network service')
O4-32 - HKLM\..\Run: [Discord] = C:\ProgramData\SquirrelMachineInstalls\Discord.exe --checkInstall (sign: 'Discord Inc.')
O4-32 - HKLM\..\Run: [Lightshot] = C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe (sign: 'Kilonova LLC')
O7 - Policy: HKCU\..\Windows\Explorer: [DisableSearchBoxSuggestions] = 1
O8 - Context menu item: HKCU\..\Internet Explorer\MenuExt\E&xport to Microsoft Excel: (default) = C:\Program Files\Microsoft Office\root\Office16\EXCEL.EXE (file missing)
O9-32 - Button: HKLM\..\{2670000A-7350-4f3c-8081-5663EE0C6C49}: Send to OneNote - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll (file missing)
O9-32 - Button: HKLM\..\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}: Lync Click to Call - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll (file missing)
O9-32 - Button: HKLM\..\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}: OneNote Lin&ked Notes - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll (file missing)
O9-32 - Tools menu item: HKLM\..\{2670000A-7350-4f3c-8081-5663EE0C6C49}: Se&nd to OneNote - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIE.dll (file missing)
O9-32 - Tools menu item: HKLM\..\{31D09BA0-12F5-4CCE-BE8A-2923E76605DA}: Lync Click to Call - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll (file missing)
O9-32 - Tools menu item: HKLM\..\{789FE86F-6FC4-46A1-9849-EDE0DB0C95CA}: OneNote Lin&ked Notes - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\ONBttnIELinkedNotes.dll (file missing)
O17 - DHCP DNS 1: 192.168.1.1
O18 - HKLM\Software\Classes\Protocols\Filter\text/xml: [CLSID] = {807583E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\MSOXMLMF.DLL
O18 - HKLM\Software\Classes\Protocols\Handler\mso-minsb.16: [CLSID] = {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL
O18 - HKLM\Software\Classes\Protocols\Handler\mso-minsb-roaming.16: [CLSID] = {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL
O18 - HKLM\Software\Classes\Protocols\Handler\osf.16: [CLSID] = {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL
O18 - HKLM\Software\Classes\Protocols\Handler\osf-roaming.16: [CLSID] = {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll (sign: 'Adobe Inc.')
O22 - BITS Job: (download) {0841AA33-3D01-49AF-A0C6-5C63E875BADD} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0/update/win64/tr/firefox-125.0.3-126.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {0F8A6A6D-ADEC-487F-848C-06F0BEDCE51F} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {1A5F8DF8-88B4-4D88-B366-D046B8FE84BA} - hxxp://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adm37caashf6gvsmqx3yidu5p6ha_20240709.652133070.14/obedbbhbpmojnkanicioggnmelmoomoc_20240709.652133070.14_all_ENUS500000_acyhiqi74u66ie3llv4kpunjpvfa.crx3 -> C:\Users\Cati\AppData\Local\Temp\chrome_BITS_20444_1405492117\obedbbhbpmojnkanicioggnmelmoomoc_20240709.652133070.14_all_ENUS500000_acyhiqi74u66ie3llv4kpunjpvfa.crx3
O22 - BITS Job: (download) {20082AEB-6F10-429F-BC83-FB9AFB6394D5} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {24105810-F6C0-4CF2-8C79-7D2BA999262A} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {28C8062A-AA4B-449C-B71F-189A0B0E920B} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.3/update/win64/tr/firefox-125.0.2-125.0.3.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {49AA37C0-28E2-483E-8F5C-99C568560C69} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {52735089-34B9-452F-BBCB-F509958F8430} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.2/update/win64/tr/firefox-127.0.1-127.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {54B1A44B-0F28-4F4C-A3DB-5CF9B29CEE12} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {5C01CA19-5B8B-4A1B-B535-7AC30F04634D} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.3/update/win64/tr/firefox-125.0.2-125.0.3.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {61DFA850-9E8B-4D5A-898A-AA0EF9B50A06} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.3/update/win64/tr/firefox-125.0.2-125.0.3.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {652C9118-A010-446E-9BB3-C813B8038F32} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {707300A3-36C9-479D-962E-49DACD616A6D} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.2/update/win64/tr/firefox-125.0.1-125.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {7B5E9960-58B8-492B-B2B1-310D3DB22D0E} - hxxps://dl.google.com/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3 -> C:\Users\Cati\AppData\Local\Temp\chrome_BITS_3332_335878003\gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3
O22 - BITS Job: (download) {7EF7CEAD-AE5B-421D-8C09-C39C31008F57} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {7F6A8E75-AB60-4C23-93C2-13ECB7851B93} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.2/update/win64/tr/firefox-127.0.1-127.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {820218AA-FFCA-4C35-9E6B-39C3C90C7567} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.2/update/win64/tr/firefox-125.0.1-125.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {834B6C42-922D-43E3-8830-F6F34FFD95EF} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {85A3F02A-1175-46DC-B3BB-BD630A01835F} - hxxp://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3 -> C:\Users\Cati\AppData\Local\Temp\chrome_BITS_7708_333219676\gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3
O22 - BITS Job: (download) {95CF8834-2B0C-42B6-ACCD-B0DA4446AE69} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.2/update/win64/tr/firefox-125.0.1-125.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {A16FDE7E-643F-4975-9CF2-C75624433E31} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {A703E28B-05B0-43AA-B421-E66F37A57890} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.2/update/win64/tr/firefox-125.0.1-125.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {AFA2B2FD-15EE-4FF0-A7E4-537A73DF5B12} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0/update/win64/tr/firefox-125.0.3-126.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {B8C5DBB4-B00A-4327-856C-28B5F4B15638} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.2/update/win64/tr/firefox-127.0.1-127.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {CBDD7177-A797-4646-A72F-502C4F4B9AFB} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {D4D538BF-4014-4C0D-9958-F14DE1A2BA99} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/128.0/update/win64/tr/firefox-127.0.2-128.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {D9607849-6DBD-4CB3-B730-E5B22104D620} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {EFD0C79F-BC69-409C-93BB-09B110EB8FAD} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.2/update/win64/tr/firefox-127.0.1-127.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {FDF81677-EE22-476D-B350-88BDEB9EDF97} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: Fix all (including legit)
O22 - Task (.job): (disabled) (Not scheduled) Intel PTT EK Recertification.job - C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe (sign: 'Intel Corporation')
O22 - Task (.job): (Not scheduled) update-S-1-5-21-2481017610-3025791784-1655446462-1001.job - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe (sign: 'OOO Lightshot')
O22 - Task (.job): (Not scheduled) update-sys.job - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe (sign: 'OOO Lightshot')
O22 - Tasks: (disabled) \Agent Activation Runtime\S-1-5-21-2481017610-3025791784-1655446462-1001 - C:\Windows\System32\AgentActivationRuntimeStarter.exe (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Clip\LicenseImdsIntegration - C:\Windows\system32\fclip.exe (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\Windows\system32\ProvTool.exe /turn 5 /source ProvRetryTask (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\Windows\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\Windows\system32\usoclient.exe StartMaintenanceWork (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareData (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\Windows\system32\rundll32.exe C:\Windows\system32\PcaSvc.dll,PcaPatchSdbTask (sign: 'Microsoft')
O22 - Tasks: \GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem128.0.6597.0{3A2AA521-EB83-42F9-BD9A-299CB0765D99} - C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exe --wake --system (sign: 'Google LLC')
O22 - Tasks: \Microsoft\Office\Office Feature Updates - C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe (file missing)
O22 - Tasks: \Microsoft\Office\Office Feature Updates Logon - C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe /onlogon (file missing)
O22 - Tasks: \Mozilla\Firefox Background Update 308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate (sign: 'Mozilla Corporation')
O22 - Tasks: \Mozilla\Firefox Background Update S-1-5-21-2481017610-3025791784-1655446462-1001 308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate (sign: 'Mozilla Corporation')
O22 - Tasks: \Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB" (sign: 'Mozilla Corporation')
O22 - Tasks: \Zero Install\Self update - C:\Program Files\Zero Install\0install-win.exe self update --batch (file missing)
O22 - Tasks: \Zero Install\Update apps - C:\Program Files\Zero Install\0install-win.exe update-all --batch --machine --clean (file missing)
O22 - Tasks: Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (sign: 'Adobe Inc.')
O22 - Tasks: BraveSoftwareUpdateTaskMachineCore{87907D3E-D7F8-41EB-84E1-62EAD6B441B9} - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /c (file missing)
O22 - Tasks: BraveSoftwareUpdateTaskMachineUA{9BB4FD41-9412-4BD2-ADE3-A065C25EBBEC} - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /ua /installsource scheduler (file missing)
O22 - Tasks: Intel PTT EK Recertification - C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\IntelPTTEKRecertification.exe (sign: 'Intel Corporation')
O22 - Tasks: kapat - C:\Windows\system32\shutdown.exe /s (sign: 'Microsoft')
O22 - Tasks: NvBroadcast_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NVIDIA Broadcast\NVIDIA Broadcast UI.exe -minimized (sign: 'NVIDIA Corporation')
O22 - Tasks: NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: Opera GX scheduled assistant Autoupdate 1676468231 - C:\Users\Cati\AppData\Local\Programs\Opera GX\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Cati\AppData\Local\Programs\Opera GX\assistant" $(Arg0) (sign: 'Opera Norway AS')
O22 - Tasks: Opera GX scheduled Autoupdate 1676036192 - C:\Users\Cati\AppData\Local\Programs\Opera GX\launcher.exe --scheduledautoupdate $(Arg0) (sign: 'Opera Norway AS')
O22 - Tasks: Overwolf Updater Task - C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe /RunningFrom Schedule (sign: 'Overwolf Ltd')
O22 - Tasks: update-S-1-5-21-2481017610-3025791784-1655446462-1001 - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate (sign: 'OOO Lightshot')
O22 - Tasks: update-sys - C:\Program Files (x86)\Skillbrains\Updater\Updater.exe -runmode=checkupdate (sign: 'OOO Lightshot')
O23 - Service R2: Adobe Acrobat Update Service - (AdobeARMservice) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (sign: 'Adobe Inc.')
O23 - Service R2: AnyDesk Service - (AnyDesk) - C:\Program Files (x86)\AnyDesk\AnyDesk.exe --service (sign: 'AnyDesk Software GmbH')
O23 - Service R2: Gaming Services - (GamingServices) - C:\Program Files\WindowsApps\Microsoft.GamingServices_22.91.10001.0_x64__8wekyb3d8bbwe\GamingServices.exe (sign: 'Microsoft')
O23 - Service R2: Gaming Services - (GamingServicesNet) - C:\Program Files\WindowsApps\Microsoft.GamingServices_22.91.10001.0_x64__8wekyb3d8bbwe\GamingServicesNet.exe (sign: 'Microsoft')
O23 - Service R2: Intel(R) Management and Security Application Local Management Service - (LMS) - C:\Windows\System32\DriverStore\FileRepository\lms.inf_amd64_fddb643595e0b8d0\LMS.exe (sign: 'Intel Corporation')
O23 - Service R2: Microsoft Defender Core Service - (MDCoreSvc) - C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpDefenderCoreService.exe (sign: 'Microsoft')
O23 - Service R2: NVIDIA Broadcast LocalSystem Container - (NvBroadcast.ContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\NvBroadcast.NvContainer\NvBroadcast.Container.exe -s NvBroadcast.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvBroadcast.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvBroadcast.NvContainer\plugins\LocalSystem" -r -p 30000  (sign: 'Nvidia Corporation')
O23 - Service R2: NVIDIA Display Container LS - (NVDisplay.ContainerLocalSystem) - C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_7e5fd280efaa5445\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_7e5fd280efaa5445\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem (sign: 'NVIDIA Corporation')
O23 - Service S2: Brave Update Service (brave) - (brave) - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /svc (file missing)
O23 - Service S2: GoogleUpdater InternalService 128.0.6597.0 (GoogleUpdaterInternalService128.0.6597.0) - (GoogleUpdaterInternalService128.0.6597.0) - C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exe --system --windows-service --service=update-internal (sign: 'Google LLC')
O23 - Service S2: GoogleUpdater Service 128.0.6597.0 (GoogleUpdaterService128.0.6597.0) - (GoogleUpdaterService128.0.6597.0) - C:\Program Files (x86)\Google\GoogleUpdater\128.0.6597.0\updater.exe --system --windows-service --service=update (sign: 'Google LLC')
O23 - Service S2: Intel(R) Dynamic Application Loader Host Interface Service - (jhi_service) - C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_b5484efd38adbe8d\jhi_service.exe (sign: 'Intel(R) Embedded Subsystems and IP Blocks Group')
O23 - Service S2: Intel(R) TPM Provisioning Service - C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\TPMProvisioningService.exe (sign: 'Intel Corporation')
O23 - Service S2: Zero Install Store Service - (0store-service) - C:\Program Files\Zero Install\0store-service.exe (file missing)
O23 - Service S3: Battle.net Update Helper Svc - (battlenet_helpersvc) - C:\ProgramData\Battle.net_components\battlenet_helpersvc\AgentHelper.exe (sign: 'Blizzard Entertainment, Inc.')
O23 - Service S3: BattlEye Service - (BEService) - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe (sign: 'BattlEye Innovations e.K.')
O23 - Service S3: Brave Update Service (bravem) - (bravem) - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /medsvc (file missing)
O23 - Service S3: Chrome Remote Desktop Service - (chromoting) - C:\Program Files (x86)\Google\Chrome Remote Desktop\125.0.6422.31\remoting_host.exe --type=daemon --host-config="C:\ProgramData\Google\Chrome Remote Desktop\host.json" (sign: 'Google LLC')
O23 - Service S3: EasyAntiCheat - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe (sign: 'EasyAntiCheat Oy')
O23 - Service S3: Epic Online Services - (EpicOnlineServices) - C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe (sign: 'Epic Games Inc.')
O23 - Service S3: Gameforge Client Service - (GameforgeClientService) - C:\Program Files (x86)\GameforgeClient\gfservice.exe (sign: 'Gameforge 4D GmbH')
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService) - (GoogleChromeElevationService) - C:\Program Files\Google\Chrome\Application\126.0.6478.182\elevation_service.exe (sign: 'Google LLC')
O23 - Service S3: Intel(R) Capability Licensing Service TCP IP Interface - C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\SocketHeciServer.exe (sign: 'Intel Corporation')
O23 - Service S3: Mozilla Maintenance Service - (MozillaMaintenance) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (sign: 'Mozilla Corporation')
O23 - Service S3: Overwolf Updater Windows SCM - (OverwolfUpdater) - C:\Program Files (x86)\Common Files\Overwolf\OverwolfUpdater.exe /RunningFrom SCM (sign: 'Overwolf Ltd')
O23 - Service S3: Rockstar Game Library Service - (Rockstar Service) - C:\Program Files\Rockstar Games\Launcher\RockstarService.exe (sign: 'Rockstar Games, Inc.')
O23 - Service S3: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\steamservice.exe /RunAsService (sign: 'Valve Corp.')
O23 - Service S3: SteelSeries Update Service - (SteelSeriesUpdateService) - C:\Program Files\SteelSeries\GG\SteelSeriesUpdateService.exe (sign: 'SteelSeries ApS')
O23 - Service S3: Uncheater for BattleGrounds_GL - (ucldr_battlegrounds_gl) - C:\Program Files\Common Files\Wellbia.com\ucldr_battlegrounds_gl.exe (file missing)
O23 - Service S3: vgc - C:\Program Files\Riot Vanguard\vgc.exe (sign: 'Riot Games, Inc.')
O23 - Service S3: XIGNCODE3 for KnightOnline NA - (xldr_KnightOnline_NA) - C:\Program Files\Common Files\Wellbia.com\xldr_KnightOnline_NA.exe (file missing)
O23 - Service S3: Zakynthos Service - (zksvc) - C:\Program Files\Common Files\PUBG\zksvc.exe (file missing)
O23 - Driver R1: googledrivefs31357 - C:\Windows\System32\DriverStore\FileRepository\googledrivefs31357.inf_amd64_a8bf31a168cf7d00\googledrivefs31357.sys (+safe mode) (sign: 'Microsoft' - Google, Inc.)
O23 - Driver R1: Nox Limited Service - (YSDrv) - C:\Program Files (x86)\Bignox\BigNoxVM\RT\YSDrv.sys (sign: 'Microsoft' - Nox Limited Corporation)
O23 - Driver R1: vgk - C:\Program Files\Riot Vanguard\vgk.sys (sign: 'Riot Games, Inc.')
O23 - Driver R3: ASMedia XHCI Service - (asmtxhci) - C:\Windows\system32\DRIVERS\asmtxhci.sys (+safe mode) (sign: 'ASMedia Technology Inc.')
O23 - Driver R3: Intel(R) Management Engine Interface  - (MEIx64) - C:\Windows\System32\DriverStore\FileRepository\heci.inf_amd64_6557ea4289534d04\x64\TeeDriverW10x64.sys (sign: 'Intel(R) Embedded Subsystems and IP Blocks Group')
O23 - Driver R3: Intel(R) PRO/1000 PCI Express Network Connection Driver D - (e1dexpress) - C:\Windows\System32\DriverStore\FileRepository\e1d68x64.inf_amd64_f6c146a8872514f7\e1d68x64.sys (+safe mode) (sign: 'Intel(R) INTELND1820')
O23 - Driver R3: NVIDIA Broadcast - (nvrtxvad_WaveExtensible) - C:\Windows\system32\drivers\nvrtxvad64v.sys (sign: 'Nvidia Corporation')
O23 - Driver R3: NVIDIA USB Type-C PPC Service - (UcmCxUcsiNvppc) - C:\Windows\System32\DriverStore\FileRepository\nvppc.inf_amd64_a0410c7d79f2444c\UcmCxUcsiNvppc.sys (sign: 'Nvidia Corporation')
O23 - Driver R3: nvlddmkm - C:\Windows\System32\DriverStore\FileRepository\nv_dispig.inf_amd64_7e5fd280efaa5445\nvlddmkm.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: Service for NVIDIA High Definition Audio Driver - (NVHDA) - C:\Windows\system32\drivers\nvhda64v.sys (sign: 'Nvidia Corporation')
O23 - Driver R3: Snap Camera - (SnapCameraVirtualDevice) - C:\Windows\System32\drivers\SnapCameraVirtualDevice.sys (sign: 'Snap Inc.')
O23 - Driver R3: SteelSeries Device Factory Service - (ssdevfactory) - C:\Windows\System32\drivers\ssdevfactory.sys (sign: 'Microsoft' - SteelSeries ApS)
O23 - Driver R3: SteelSeries HID Service - (sshid) - C:\Windows\System32\drivers\sshid.sys (sign: 'Microsoft' - SteelSeries ApS)
O23 - Driver R3: SteelSeries Sonar Driver - (SteelSeries_Sonar_VAD) - C:\Windows\System32\DriverStore\FileRepository\steelseries-sonar-vad.inf_amd64_da15ab44a6216a8e\SteelSeries-Sonar-VAD.sys (sign: 'SteelSeries ApS')
O23 - Driver S3: @oem22.inf,%RzCommon.SVCDESC%;Razer Control Service - (RzCommon) - C:\Windows\System32\drivers\RzCommon.sys (sign: 'Razer USA Ltd.')
O23 - Driver S3: @oem59.inf,%ladfGSS.SvcDesc%;Logitech USB Surround Filter Driver (LGS) - (ladfGSS) - C:\Windows\system32\drivers\ladfGSS.sys (sign: 'Logitech Inc')
O23 - Driver S3: Apple Lower Filter Driver - (AppleLowerFilter) - C:\Windows\System32\drivers\AppleLowerFilter.sys (sign: 'Microsoft' - Apple Inc.)
O23 - Driver S3: Intel(R) Serial IO GPIO Controller Driver - (iaLPSSi_GPIO) - C:\Windows\System32\drivers\iaLPSSi_GPIO.sys (sign: 'Intel Corporation - Client Components Group')
O23 - Driver S3: Logitech G HUB HID Filter Driver - (logi_joy_hid_filter) - C:\Windows\system32\drivers\logi_joy_hid_filter.sys (sign: 'Logitech Inc')
O23 - Driver S3: Logitech G HUB KMDF HID IO Filter Driver - (logi_generic_hid_filter) - C:\Windows\system32\drivers\logi_generic_hid_filter.sys (sign: 'Logitech Inc')
O23 - Driver S3: Logitech G HUB USB Filter Driver - (logi_joy_hid_lo) - C:\Windows\system32\drivers\logi_joy_hid_lo.sys (sign: 'Logitech Inc')
O23 - Driver S3: Logitech G HUB Virtual HID Device Driver - (logi_joy_vir_hid) - C:\Windows\system32\drivers\logi_joy_vir_hid.sys (sign: 'Logitech Inc')
O23 - Driver S3: SAMSUNG  Mobile USB Modem Drivers (DEVGURU Ver.) - (ssudmdm) - C:\Windows\system32\DRIVERS\ssudmdm.sys (sign: 'Samsung Electronics CO., LTD.')
O23 - Driver S3: SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.) - (dg_ssudbus) - C:\Windows\system32\DRIVERS\ssudbus2.sys (+safe mode) (sign: 'Samsung Electronics CO., LTD.')
O23 - Driver S3: VB-Audio VoiceMeeter AUX VAIO (WDM) - (VBAudioVMAUXVAIOMME) - C:\Windows\System32\drivers\vbaudio_vmauxvaio64_win10.sys (file missing)
O23 - Driver S3: VB-Audio VoiceMeeter VAIO (WDM) - (VBAudioVMVAIOMME) - C:\Windows\System32\drivers\vbaudio_vmvaio64_win10.sys (file missing)
O23 - Driver S3: xhunter1 - C:\Windows\xhunter1.sys (sign: 'Wellbia.com Co., Ltd.')


--
End of file - Time spent: 26.5 sec. - 81684 bytes, CRC32: FFFFFFFF. Sign: 艠뀛
 
Bunları fixleyin:
Kod:
O4 - HKCU\..\StartupApproved\Run: [com.blitz.app] = "C:\Users\Cati\AppData\Local\Programs\Blitz\Blitz.exe" --autostart (file missing) (2022/12/15)
O4 - HKCU\..\StartupApproved\Run: [com.squirrel.slack.slack] = C:\Users\Cati\AppData\Local\slack\slack.exe --process-start-args --startup (sign: 'Slack Technologies, LLC')
O4 - HKCU\..\StartupApproved\Run: [DiscordCanary] = C:\Users\Cati\AppData\Local\DiscordCanary\Update.exe --processStart DiscordCanary.exe (2022/02/16) (sign: 'Discord Inc.')
O4 - HKCU\..\StartupApproved\Run: [EpicGamesLauncher] = C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe -silent -launchcontext=boot (2022/02/16) (sign: 'Epic Games Inc.')
O4 - HKCU\..\StartupApproved\Run: [Medal] = C:\Users\Cati\AppData\Local\Medal\update.exe --processStart "Medal.exe" (2022/12/15) (sign: 'Ferox Games B.V.')
O4 - HKCU\..\StartupApproved\Run: [MicrosoftEdgeAutoLaunch_568E5DCA129F25A9393055C379DB1F74] = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --no-startup-window --win-session-start (2022/02/02) (sign: 'Microsoft')
O4 - HKCU\..\StartupApproved\Run: [NoxMultiPlayer] = "D:\Program Files\Nox\bin\MultiPlayerManager.exe" -startSource:auto_start (file missing) (2022/06/06)
O4 - HKCU\..\StartupApproved\Run: [Opera GX Browser Assistant] = C:\Users\Cati\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe (2023/02/21) (sign: 'Opera Software AS')
O4 - HKCU\..\StartupApproved\Run: [Opera GX Stable] = C:\Users\Cati\AppData\Local\Programs\Opera GX\launcher.exe (2023/02/21) (sign: 'Opera Norway AS')
O4 - HKCU\..\StartupApproved\Run: [RiotClient] = C:\Riot Games\Riot Client\RiotClientServices.exe --launch-background-mode (2023/10/09) (sign: 'Riot Games, Inc.')
O4 - HKCU\..\StartupApproved\Run: [Snap Camera] = C:\Program Files\Snap Inc\Snap Camera\Snap Camera.exe --minimized-mode (2022/02/16) (sign: 'Snap Inc.')
O4 - HKCU\..\StartupApproved\Run: [utweb] = "C:\Users\Cati\AppData\Roaming\uTorrent Web\utweb.exe" /MINIMIZED (file missing) (2022/12/15)
O4 - HKLM\..\StartupApproved\Run32: [Adobe CCXProcess] = C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe (2022/06/06) (sign: 'Adobe Inc.')
O4 - HKLM\..\StartupApproved\Run32: [DiscordCanary] = C:\ProgramData\SquirrelMachineInstalls\DiscordCanary.exe --checkInstall (2023/03/31) (sign: 'Discord Inc.')
O4 - HKLM\..\StartupApproved\StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\DeepL auto-start.lnk    ->    C:\ProgramData\0install.net\desktop-integration\stubs\1eae01f3cdb5ff0ecf683b15a60a1489573c1188cb34abc205fcf7a924b4e54d\auto-start.exe (2024/02/19) (not signed - no company - FE3ABCDC59CD077ECF316CDDBA14D0B95C240951)
O4 - HKU\S-1-5-18\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe --startup_mode (file missing) (User 'LocalSystem')-
O4 - HKU\S-1-5-19\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe --startup_mode (file missing) (User 'Local service')
O4 - HKU\S-1-5-20\..\Run: [GoogleDriveFS] = C:\Program Files\Google\Drive File Stream\93.0.1.0\GoogleDriveFS.exe --startup_mode (file missing) (User 'Network service')
O22 - BITS Job: (download) {0841AA33-3D01-49AF-A0C6-5C63E875BADD} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0/update/win64/tr/firefox-125.0.3-126.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {0F8A6A6D-ADEC-487F-848C-06F0BEDCE51F} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {1A5F8DF8-88B4-4D88-B366-D046B8FE84BA} - hxxp://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adm37caashf6gvsmqx3yidu5p6ha_20240709.652133070.14/obedbbhbpmojnkanicioggnmelmoomoc_20240709.652133070.14_all_ENUS500000_acyhiqi74u66ie3llv4kpunjpvfa.crx3 -> C:\Users\Cati\AppData\Local\Temp\chrome_BITS_20444_1405492117\obedbbhbpmojnkanicioggnmelmoomoc_20240709.652133070.14_all_ENUS500000_acyhiqi74u66ie3llv4kpunjpvfa.crx3
O22 - BITS Job: (download) {20082AEB-6F10-429F-BC83-FB9AFB6394D5} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {24105810-F6C0-4CF2-8C79-7D2BA999262A} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {28C8062A-AA4B-449C-B71F-189A0B0E920B} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.3/update/win64/tr/firefox-125.0.2-125.0.3.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {49AA37C0-28E2-483E-8F5C-99C568560C69} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {52735089-34B9-452F-BBCB-F509958F8430} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.2/update/win64/tr/firefox-127.0.1-127.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {54B1A44B-0F28-4F4C-A3DB-5CF9B29CEE12} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {5C01CA19-5B8B-4A1B-B535-7AC30F04634D} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.3/update/win64/tr/firefox-125.0.2-125.0.3.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {61DFA850-9E8B-4D5A-898A-AA0EF9B50A06} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.3/update/win64/tr/firefox-125.0.2-125.0.3.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {652C9118-A010-446E-9BB3-C813B8038F32} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {707300A3-36C9-479D-962E-49DACD616A6D} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.2/update/win64/tr/firefox-125.0.1-125.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {7B5E9960-58B8-492B-B2B1-310D3DB22D0E} - hxxps://dl.google.com/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3 -> C:\Users\Cati\AppData\Local\Temp\chrome_BITS_3332_335878003\gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3
O22 - BITS Job: (download) {7EF7CEAD-AE5B-421D-8C09-C39C31008F57} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {7F6A8E75-AB60-4C23-93C2-13ECB7851B93} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.2/update/win64/tr/firefox-127.0.1-127.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {820218AA-FFCA-4C35-9E6B-39C3C90C7567} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.2/update/win64/tr/firefox-125.0.1-125.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {834B6C42-922D-43E3-8830-F6F34FFD95EF} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {85A3F02A-1175-46DC-B3BB-BD630A01835F} - hxxp://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3 -> C:\Users\Cati\AppData\Local\Temp\chrome_BITS_7708_333219676\gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3
O22 - BITS Job: (download) {95CF8834-2B0C-42B6-ACCD-B0DA4446AE69} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.2/update/win64/tr/firefox-125.0.1-125.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {A16FDE7E-643F-4975-9CF2-C75624433E31} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {A703E28B-05B0-43AA-B421-E66F37A57890} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/125.0.2/update/win64/tr/firefox-125.0.1-125.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {AFA2B2FD-15EE-4FF0-A7E4-537A73DF5B12} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0/update/win64/tr/firefox-125.0.3-126.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {B8C5DBB4-B00A-4327-856C-28B5F4B15638} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.2/update/win64/tr/firefox-127.0.1-127.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {CBDD7177-A797-4646-A72F-502C4F4B9AFB} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {D4D538BF-4014-4C0D-9958-F14DE1A2BA99} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/128.0/update/win64/tr/firefox-127.0.2-128.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {D9607849-6DBD-4CB3-B730-E5B22104D620} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {EFD0C79F-BC69-409C-93BB-09B110EB8FAD} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.2/update/win64/tr/firefox-127.0.1-127.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {FDF81677-EE22-476D-B350-88BDEB9EDF97} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: Fix all (including legit)
O22 - Tasks: \Zero Install\Self update - C:\Program Files\Zero Install\0install-win.exe self update --batch (file missing)
O22 - Tasks: \Zero Install\Update apps - C:\Program Files\Zero Install\0install-win.exe update-all --batch --machine --clean (file missing)
O22 - Tasks: kapat - C:\Windows\system32\shutdown.exe /s (sign: 'Microsoft')
O23 - Service S2: Zero Install Store Service - (0store-service) - C:\Program Files\Zero Install\0store-service.exe (file missing)
Sırasıyla bunları yapın;
MBAM ile sistemi taratın.
Discord ve Firefox kaldırıp yeniden yükleyin.
sfc /scannow çalıştırın.
 
Merhaba,
Bilgisayarımda son bir hafta içerisinde masaüstü ve görev çubuğu ikonlarında yaklaşık olarak 10 saniyede bir göz kırpma şeklinde bir gitgel oluyor. Kaskersky ile tarama yaptım fakat bu beni tatmin etmedi.
Konu için yardım almak için sizlere danışıyorum.

Kod:
Logfile of HiJackThis+ (Plus) build 2024-04-18 Alpha v.3.4.0.9

Platform: x64 Windows 10 (Home Single Language), 10.0.19045.4651 (ReleaseId: 2009, 22H2), Service Pack: 0
Time: 30.07.2024 - 22:06 (UTC+03:00)
Language: OS: Turkish (0x41F). Display: Turkish (0x41F). Non-Unicode: Turkish (0x41F)
Memory: 27763 MiB Free. Loading RAM (17 %), CPU (48 %)
Elevated: Yes.
Ran by: Alkandras (group: Administrators; type: Local) on DESKTOP-U1AU4G2, FirstRun: yes.

Chrome: 125.0.6422.176
Firefox: 128.0.3.199
Internet Explorer: 11.0.19041.4355
Default: "C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --single-argument %1 (Brave)

Boot mode: Normal (Secure Boot: Off)

Running processes:
Number | Path.
 2 C:\AppServ\Apache24\bin\httpd.exe
 2 C:\AppServ\MySQL\bin\mysqld.exe
 1 C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe
 1 C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\11.0.0.4854\AdskLicensingService\AdskLicensingService.exe
 1 C:\Program Files (x86)\Common Files\Foxit\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe
 1 C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
 1 C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe
 4 C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\avp.exe
 1 C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\avpui.exe
 1 C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.17\ksde.exe
 1 C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.17\ksdeui.exe
 12 C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.113\msedgewebview2.exe
 1 C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
 1 C:\Program Files (x86)\RocketDock\RocketDock.exe
 1 C:\Program Files (x86)\SwifDooPDF\PDFEngine.exe
 1 C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe
 1 C:\Program Files (x86)\VMware\VMware Workstation\vmware-autostart.exe
 1 C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe
 1 C:\Program Files\CCleaner\CCleaner64.exe
 1 C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
 1 C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
 1 C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
 1 C:\Program Files\LogiOptionsPlus\logi_ai_prompt_builder\LogiAiPromptBuilder.exe
 1 C:\Program Files\LogiOptionsPlus\logioptionsplus_agent.exe
 1 C:\Program Files\LogiOptionsPlus\logioptionsplus_appbroker.exe
 1 C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe
 1 C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\nvrla.exe
 2 C:\Program Files\NVIDIA Corporation\FrameViewSDK\bin\PresentMon_x64.exe
 1 C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe
 3 C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
 3 C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
 1 C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
 1 C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
 1 C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Visualize Boost\SWVisualize.BoostService.exe
 1 C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Visualize\SWVisualize.Queue.Server.exe
 2 C:\SolidSQUAD_License_Servers\Bin\lmgrd.exe
 1 C:\SolidSQUAD_License_Servers\Bin\ugslmd.exe
 2 C:\SolidWorks_Flexnet_Server\lmgrd.exe
 1 C:\SolidWorks_Flexnet_Server\sw_d.exe
 1 C:\Users\Alkandras\AppData\Local\0install.net\implementations\sha256new_EYRJUS5B7ZXHBM3J5SUWEBGFTOF63RH2VJRKPSVL27GZPYENRXNA\DeepL.exe
 5 C:\Users\Alkandras\AppData\Local\0install.net\implementations\sha256new_URIJA5AX26HNM7QVJKAF4VRTKDDVZDUL2XD4MMI4IJ3R32IZBLRA\CefSharp.BrowserSubprocess.exe
 1 C:\Users\Alkandras\AppData\Local\Reverso\Reverso\Reverso.exe
 1 C:\Users\Alkandras\Desktop\HiJackThis\HiJackThis.exe
 1 C:\Windows\explorer.exe
 1 C:\Windows\System32\AggregatorHost.exe
 1 C:\Windows\System32\audiodg.exe
 6 C:\Windows\System32\conhost.exe
 2 C:\Windows\System32\csrss.exe
 1 C:\Windows\System32\ctfmon.exe
 2 C:\Windows\System32\dllhost.exe
 1 C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe
 1 C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
 2 C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_1196b342b24df5d1\Display.NvContainer\NVDisplay.Container.exe
 1 C:\Windows\System32\dwm.exe
 2 C:\Windows\System32\fontdrvhost.exe
 1 C:\Windows\System32\lsass.exe
 1 C:\Windows\System32\MoUsoCoreWorker.exe
 1 C:\Windows\System32\rundll32.exe
 4 C:\Windows\System32\RuntimeBroker.exe
 1 C:\Windows\System32\SearchFilterHost.exe
 1 C:\Windows\System32\SearchIndexer.exe
 1 C:\Windows\System32\SearchProtocolHost.exe
 1 C:\Windows\System32\SecurityHealthService.exe
 1 C:\Windows\System32\SecurityHealthSystray.exe
 1 C:\Windows\System32\services.exe
 1 C:\Windows\System32\SgrmBroker.exe
 1 C:\Windows\System32\sihost.exe
 1 C:\Windows\System32\smartscreen.exe
 1 C:\Windows\System32\smss.exe
 1 C:\Windows\System32\spoolsv.exe
 74 C:\Windows\System32\svchost.exe
 2 C:\Windows\System32\taskhostw.exe
 1 C:\Windows\System32\wbem\unsecapp.exe
 1 C:\Windows\System32\wbem\WMIADAP.exe
 2 C:\Windows\System32\wbem\WmiPrvSE.exe
 1 C:\Windows\System32\wininit.exe
 1 C:\Windows\System32\winlogon.exe
 1 C:\Windows\System32\WUDFHost.exe
 1 C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
 1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
 1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
 1 C:\Windows\SysWOW64\dllhost.exe
 1 C:\Windows\SysWOW64\vmnat.exe
 1 C:\Windows\SysWOW64\vmnetdhcp.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxyOverride] = *.local
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8}: [SuggestionsURL_JSON] = hxxps://suggest.yandex.com.tr/suggest-ff.cgi?srv=ie11&uil=tr&part={searchTerms}&clid=2233630 - Yandex.
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8}: [URL] = hxxps://yandex.com.tr/search/?text={searchTerms}&clid=2233630 - Yandex.
O4 - ActiveSetup: HKLM\..\{8A69D345-D564-463c-AFF1-A69D9E530F96}: [StubPath] = C:\Program Files\Google\Chrome\Application\125.0.6422.176\Installer\chrmstp.exe --configure-user-settings --verbose-logging --system-level --channel=stable (sign: 'Google LLC')
O4 - ActiveSetup: HKLM\..\{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}: [StubPath] = C:\Program Files\BraveSoftware\Brave-Browser\Application\127.1.68.131\Installer\chrmstp.exe --configure-user-settings --verbose-logging --system-level (sign: 'Brave Software, Inc.')
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] = C:\Program Files\CCleaner\CCleaner64.exe /MONITOR (sign: 'Gen Digital Inc.')
O4 - HKCU\..\Run: [Reverso] = C:\Users\Alkandras\AppData\Local\Reverso\Reverso\Reverso.exe -minimized (sign: 'REVERSO S.A.S.')
O4 - HKCU\..\Run: [RocketDock] = C:\Program Files (x86)\RocketDock\RocketDock.exe (not signed - no company - 521E9198E3DC1D41FAC02EB01FB9F47F6D2A9855)
O4 - HKCU\..\RunOnce: [Application Restart #0] = C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe --component-updater=url-source=hxxps://go-updater.brave.com/extensions --disable-domain-reliability --enable-distillability-service --enable-dom-distiller --lso-url=hxxps://no-thanks.invalid --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --sync-url=hxxps://sync-v2.brave.com/v2 --variations-insecure-server-url=hxxps://variations.brave.com/seed --variations-server-url=hxxps://variations.brave.com/seed --restore-last-session --restart (sign: 'Brave Software, Inc.')
O4 - HKCU\..\StartupApproved\Run: [Discord] = C:\Users\Alkandras\AppData\Local\Discord\Update.exe --processStart Discord.exe (2024/04/17) (sign: 'Discord Inc.')
O4 - HKCU\..\StartupApproved\Run: [EADM] = C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EALauncher.exe -silent (2023/06/05) (sign: 'Electronic Arts, Inc.')
O4 - HKCU\..\StartupApproved\Run: [Epic Privacy Browser Installer] = C:\Users\Alkandras\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe /c (sign: 'Google Inc (TEST)', but untrusted root: 'Google Inc (TEST)' with fingerprint: 471DE9EEBF4AF31E2FF65B1C3A3272DB999E9509)
O4 - HKCU\..\StartupApproved\Run: [MicrosoftEdgeAutoLaunch_5594F3D88385289021792D3510255E96] = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --no-startup-window --win-session-start (sign: 'Microsoft')
O4 - HKCU\..\StartupApproved\Run: [OneDrive] = C:\Program Files\Microsoft OneDrive\OneDrive.exe /background (sign: 'Microsoft')
O4 - HKCU\..\StartupApproved\Run: [Steam] = C:\Program Files (x86)\Steam\steam.exe -silent (sign: 'Valve Corp.')
O4 - HKLM\..\Run: [Logitech Download Assistant] = C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch (sign: 'Microsoft')
O4 - HKLM\..\Run: [RTHDVCPL] = C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s (sign: 'Realtek Semiconductor Corp.')
O4 - HKLM\..\StartupApproved\Run: [Autodesk Access] = C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessCore.exe --minimizedUi (2023/05/13) (sign: 'Autodesk, Inc.')
O4 - HKLM\..\StartupApproved\Run32: [Adobe CCXProcess] = C:\Program Files (x86)\Adobe\Adobe Creative Cloud Experience\CCXProcess.exe (2023/05/13) (sign: 'Adobe Inc.')
O4 - HKLM\..\StartupApproved\StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SOLIDWORKS 2022 Hızlı Başlangıç.lnk -> C:\Windows\Installer\{26EA0056-4BAD-4F9E-BDCE-A72E25C7D06D}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe (2023/05/13) (not signed - Flexera - B9FC8844AF011C56310B304FCBDE46FF67B90BC8)
O4 - HKLM\..\StartupApproved\StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SOLIDWORKS Arkaplan İndiricisi.lnk -> C:\Program Files (x86)\Common Files\SOLIDWORKS Kurulum Yöneticisi\BackgroundDownloading\sldBgDwld.exe /launch_from 0 (2023/05/13) (sign: 'Dassault Systemes SolidWorks Corp.')
O4 - Startup: C:\Users\Alkandras\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DeepL auto-start.lnk -> C:\Users\Alkandras\AppData\Roaming\0install.net\desktop-integration\stubs\1eae01f3cdb5ff0ecf683b15a60a1489573c1188cb34abc205fcf7a924b4e54d\auto-start.exe (not signed - no company - FE3ABCDC59CD077ECF316CDDBA14D0B95C240951)
O4-32 - HKLM\..\Run: [vmware-tray.exe] = C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (sign: 'VMware, Inc.')
O5 - Applet: C:\Windows\System32\plotman.cpl (sign: 'Autodesk, Inc.')
O5 - Applet: C:\Windows\System32\RTSnMg64.cpl (sign: 'Realtek Semiconductor Corp.')
O5 - Applet: C:\Windows\System32\styleman.cpl (sign: 'Autodesk, Inc.')
O7 - Policy: HKLM\Software\Microsoft\Windows Defender: [DisableAntiSpyware] = 1
O7 - Policy: HKLM\Software\Microsoft\Windows Defender: [DisableAntiVirus] = 1
O7 - Policy: HKLM\Software\Microsoft\Windows Defender\Features: [TamperProtection] = 4
O8 - Context menu item: HKCU\..\Internet Explorer\MenuExt\Se&nd to OneNote: (default) = C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll (file missing)
O10 - Unknown file in Winsock LSP: C:\Program Files (x86)\Bonjour\mdnsNSP.dll (sign: 'Apple Inc.')
O17 - DHCP DNS 1: 192.168.1.1
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Program Files (x86)\Common Files\Adobe\CoreSyncExtension\CoreSync_x64.dll (sign: 'Adobe Inc.')
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Windows\system32\AcSignIcon.dll (sign: 'Autodesk, Inc.')
O22 - BITS Job: (download) {01E616F7-F2F8-4447-93C4-FF371A6BF682} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/128.0/update/win64/tr/firefox-127.0.2-128.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {17D886DC-D2A7-44CD-8A73-6EE3E3C549C6} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0/update/win64/tr/firefox-125.0.3-126.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {220BF640-880A-47E7-8B6B-0B6DEE20E243} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {3EE1D5C8-83BE-4FFF-A571-54AF68E5174F} - hxxp://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3 -> C:\Users\ALKAND~1\AppData\Local\Temp\chrome_BITS_3908_394102754\gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3
O22 - BITS Job: (download) {52FDA215-D725-4276-B4A1-D888693BDF9A} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0/update/win64/tr/firefox-126.0.1-127.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {56533264-27B7-4152-B2F9-8D22F43154D6} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {5A170B56-55D2-4E08-8C09-0D57DE7663A8} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/128.0.2/update/win64/tr/firefox-128.0-128.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {88BDE918-77F9-4E95-A686-C4B85A1921BF} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0/update/win64/tr/firefox-126.0.1-127.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {BD7BBF33-0DA6-4D1A-B300-2A039F4D0A47} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {D46B717C-88B1-428D-B3FF-1ED9A9ECE215} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.2/update/win64/tr/firefox-127.0.1-127.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {DDAC7313-8555-474C-98B3-99989FA43519} - hxxp://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adrnpn4oqndirc4e4znryad25caa_2024.7.25.0/niikhdgajlphfehepabhhblakbdgeefj_2024.07.25.00_all_ac77hp7ujdfagzpwcjuouk7ix2wa.crx3 -> C:\Users\ALKAND~1\AppData\Local\Temp\chrome_BITS_16016_1063282233\niikhdgajlphfehepabhhblakbdgeefj_2024.07.25.00_all_ac77hp7ujdfagzpwcjuouk7ix2wa.crx3
O22 - BITS Job: (download) {E6C0A3B0-FE96-4A96-8FF9-AE041844951F} - hxxps://download.mozilla.org/?product=firefox-127.0.1-partial-127.0&os=win64&lang=tr -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {EFDC91A7-C9F6-49D8-82AE-7B63FC7F9B37} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0/update/win64/tr/firefox-125.0.3-126.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {FFD11E3E-74B3-46C8-AFE9-0C397C3073D1} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: Fix all (including legit)
O22 - Task (.job): (Not scheduled) CCleanerClean.job - C:\Program Files\CCleaner\CCleaner.exe (sign: 'Gen Digital Inc.')
O22 - Task (.job): (Not scheduled) CCleanerCrashReporting.job - C:\Program Files\CCleaner\CCleanerBugReport.exe (sign: 'Gen Digital Inc.')
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{493D859B-3CC9-461B-BDB0-6A3C728EE1C1} - \GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem127.0.6490.0{52F548D7-7E32-4DC0-826D-B03F068B42D9} (no xml)
O22 - Tasks: (disabled) \Agent Activation Runtime\S-1-5-21-3558330945-3730327421-88870818-1002 - C:\Windows\System32\AgentActivationRuntimeStarter.exe (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\Windows\system32\ProvTool.exe /turn 5 /source ProvRetryTask (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\Windows\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\Windows\system32\usoclient.exe StartMaintenanceWork (sign: 'Microsoft')
O22 - Tasks: (disabled) BraveSoftwareUpdateTaskMachineCore{AFB67181-242D-4F88-B410-C3F7A30B1584} - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /c (sign: 'Brave Software, Inc.')
O22 - Tasks: (disabled) BraveSoftwareUpdateTaskMachineUA{F9E69D53-E9A2-4B86-B986-6F7A8F2DE6A6} - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /ua /installsource scheduler (sign: 'Brave Software, Inc.')
O22 - Tasks: (telemetry) \Microsoft\Office\Office Performance Monitor - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareData (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\Windows\system32\rundll32.exe C:\Windows\system32\PcaSvc.dll,PcaPatchSdbTask (sign: 'Microsoft')
O22 - Tasks: (telemetry) NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: (telemetry) NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: (telemetry) NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: (telemetry) NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: \GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem128.0.6537.0{9321DCA2-3117-4512-A686-84306EAAD47E} - C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe --wake --system (sign: 'Google LLC')
O22 - Tasks: \Mozilla\Firefox Background Update 308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate (sign: 'Mozilla Corporation')
O22 - Tasks: \Mozilla\Firefox Background Update S-1-5-21-3558330945-3730327421-88870818-1002 308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate (sign: 'Mozilla Corporation')
O22 - Tasks: \Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB" (sign: 'Mozilla Corporation')
O22 - Tasks: CCleaner Update - C:\Program Files\CCleaner\CCUpdate.exe (sign: 'Gen Digital Inc.')
O22 - Tasks: CCleanerClean - C:\Program Files\CCleaner\CCleaner.exe /AUTOSC (sign: 'Gen Digital Inc.')
O22 - Tasks: CCleanerCrashReporting - C:\Program Files\CCleaner\CCleanerBugReport.exe --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --guid "078702d4-6fad-4b11-8780-bdc4684c6813" --version "6.26.11169" --silent (sign: 'Gen Digital Inc.')
O22 - Tasks: CCleanerSkipUAC - Alkandras - C:\Program Files\CCleaner\CCleaner.exe $(Arg0) (sign: 'Gen Digital Inc.')
O22 - Tasks: Intel PTT EK Recertification - C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\IntelPTTEKRecertification.exe (sign: 'Intel Corporation')
O22 - Tasks: NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log (sign: 'NVIDIA Corporation')
O22 - Tasks: NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe --launcher=TaskScheduler (sign: 'NVIDIA Corporation')
O22 - Tasks: NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe (sign: 'NVIDIA Corporation')
O22 - Tasks: OneDrive Reporting Task-S-1-5-21-3558330945-3730327421-88870818-1002 - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting (sign: 'Microsoft')
O22 - Tasks: PDFEngine - C:\Program Files (x86)\SwifDooPDF\PDFEngine.exe --from=tk (sign: 'Chengdu Aishang Office Technology Co., Ltd.')
O23 - Service R2: Apache24 - C:\AppServ\Apache24\bin\httpd.exe -k runservice (not signed - Apache Software Foundation - 297A86BDF6E2EC31A2D7563DAA824AF409BD5949)
O23 - Service R2: Autodesk Desktop Licensing Service - (AdskLicensingService) - C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingService\AdskLicensingService.exe (sign: 'Autodesk, Inc.')
O23 - Service R2: CCleaner Performance Optimizer Service - (CCleanerPerformanceOptimizerService) - C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe (sign: 'Gen Digital Inc.')
O23 - Service R2: FlexNet Licensing Service - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe (sign: 'Flexera Software LLC')
O23 - Service R2: FlexNet Licensing Service 64 - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe (sign: 'Flexera Software LLC')
O23 - Service R2: Foxit PDF Reader Update Service - (FoxitReaderUpdateService) - C:\Program Files (x86)\Common Files\Foxit\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe (sign: 'FOXIT SOFTWARE INC.')
O23 - Service R2: Intel(R) Dynamic Application Loader Host Interface Service - (jhi_service) - C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_af50fdb80983f7bc\jhi_service.exe (sign: 'Intel Corporation')
O23 - Service R2: Intel(R) Management Engine WMI Provider Registration - (WMIRegistrationService) - C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe (sign: 'Intel Corporation')
O23 - Service R2: Kaspersky Hizmeti 21.17 - (AVP21.17) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\avp.exe -r (sign: 'Kaspersky Lab JSC')
O23 - Service R2: Kaspersky VPN Secure Connection Hizmeti 5.17 - (KSDE5.17) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.17\ksde.exe -r (sign: 'Kaspersky Lab JSC')
O23 - Service R2: Logi Options+ - (OptionsPlusUpdaterService) - C:\Program Files\LogiOptionsPlus\logioptionsplus_updater.exe --run-as-service (sign: 'Logitech Inc')
O23 - Service R2: mysql8 - C:\AppServ\MySQL\bin\mysqld.exe --defaults-file=C:\AppServ\MySQL\my.ini mysql8 (sign: 'Oracle America, Inc.')
O23 - Service R2: NVIDIA Display Container LS - (NVDisplay.ContainerLocalSystem) - C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_1196b342b24df5d1\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_1196b342b24df5d1\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem /ert (sign: 'NVIDIA Corporation')
O23 - Service R2: NVIDIA LocalSystem Container - (NvContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" -ert (sign: 'NVIDIA Corporation')
O23 - Service R2: SolidWorks Flexnet Server - C:\SolidWorks_Flexnet_Server\lmgrd.exe (sign: 'Flexera Software LLC')
O23 - Service R2: SSQ FLEXLM Service - C:\SolidSQUAD_License_Servers\Bin\lmgrd.exe (sign: 'Flexera Software LLC')
O23 - Service R2: SWVisualize2022.BoostService - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Visualize Boost\SWVisualize.BoostService.exe (sign: 'Dassault Systemes SolidWorks Corp.')
O23 - Service R2: SWVisualize2022.Queue.Server - C:\Program Files\SOLIDWORKS Corp\SOLIDWORKS Visualize\SWVisualize.Queue.Server.exe (sign: 'Dassault Systemes SolidWorks Corp.')
O23 - Service R2: VMware Authorization Service - (VMAuthdService) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-authd.exe (sign: 'VMware, Inc.')
O23 - Service R2: VMware Autostart Service - (VmwareAutostartService) - C:\Program Files (x86)\VMware\VMware Workstation\vmware-autostart.exe (sign: 'VMware, Inc.')
O23 - Service R2: VMware DHCP Service - (VMnetDHCP) - C:\Windows\SysWOW64\vmnetdhcp.exe (sign: 'VMware, Inc.')
O23 - Service R2: VMware NAT Service - C:\Windows\SysWOW64\vmnat.exe (sign: 'VMware, Inc.')
O23 - Service R2: VMware USB Arbitration Service - (VMUSBArbService) - C:\Program Files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe (sign: 'VMware, Inc.')
O23 - Service R3: NVIDIA FrameView SDK service - (FvSvc) - C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe -service (sign: 'NVIDIA Corporation')
O23 - Service S2: Brave Güncelleme Hizmeti (brave) - (brave) - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /svc (sign: 'Brave Software, Inc.')
O23 - Service S2: Google Güncelleme Hizmeti (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc (sign: 'Google LLC')
O23 - Service S2: GoogleUpdater InternalService 127.0.6490.0 (GoogleUpdaterInternalService127.0.6490.0) - (GoogleUpdaterInternalService127.0.6490.0) - C:\Program Files (x86)\Google\GoogleUpdater\127.0.6490.0\updater.exe --system --windows-service --service=update-internal (file missing)
O23 - Service S2: GoogleUpdater InternalService 128.0.6537.0 (GoogleUpdaterInternalService128.0.6537.0) - (GoogleUpdaterInternalService128.0.6537.0) - C:\Program Files (x86)\Google\GoogleUpdater\128.0.6537.0\updater.exe --system --windows-service --service=update-internal (sign: 'Google LLC')
O23 - Service S2: GoogleUpdater Service 127.0.6490.0 (GoogleUpdaterService127.0.6490.0) - (GoogleUpdaterService127.0.6490.0) - C:\Program Files (x86)\Google\GoogleUpdater\127.0.6490.0\updater.exe --system --windows-service --service=update (file missing)
O23 - Service S2: Intel(R) TPM Provisioning Service - C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_fc84dfa25a6a7727\lib\TPMProvisioningService.exe (sign: 'Intel Corporation')
O23 - Service S3: Brave Elevation Service (BraveElevationService) - (BraveElevationService) - C:\Program Files\BraveSoftware\Brave-Browser\Application\127.1.68.131\elevation_service.exe (sign: 'Brave Software, Inc.')
O23 - Service S3: Brave Güncelleme Hizmeti (bravem) - (bravem) - C:\Program Files (x86)\BraveSoftware\Update\BraveUpdate.exe /medsvc (sign: 'Brave Software, Inc.')
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService) - (GoogleChromeElevationService) - C:\Program Files\Google\Chrome\Application\125.0.6422.176\elevation_service.exe (sign: 'Google LLC')
O23 - Service S3: Google Güncelleme Hizmeti (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc (sign: 'Google LLC')
O23 - Service S3: Intel(R) Capability Licensing Service TCP IP Interface - C:\Windows\System32\DriverStore\FileRepository\iclsclient.inf_amd64_76523213b78d9046\lib\SocketHeciServer.exe (sign: 'Intel Corporation')
O23 - Service S3: Kaspersky Volume Shadow Copy Service Bridge 21.17 - (klvssbridge64_21.17) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky 21.17\x64\vssbridge64.exe (sign: 'AO Kaspersky Lab')
O23 - Service S3: Mozilla Maintenance Service - (MozillaMaintenance) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (sign: 'Mozilla Corporation')
O23 - Service S3: OpcEnum - C:\Windows\SysWOW64\OpcEnum.exe (sign: 'OPC Foundation, Inc.')
O23 - Service S3: SolidWorks Licensing Service - C:\Program Files (x86)\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe (not signed - SolidWorks - A8176E9B8F210C6AEE3835804257E78727B421E0)
O23 - Service S3: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\steamservice.exe /RunAsService (sign: 'Valve Corp.')
O23 - Driver R: VMware virtual network driver (64-bit) - C:\Windows\system32\DRIVERS\VMNET.SYS (sign: 'VMware, Inc.')
O23 - Driver R0: AO Kaspersky Lab Cryptographic Module x64 (56 bit) - (cm_km) - C:\Windows\system32\DRIVERS\cm_km.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R0: klupd_K4W-21-17_arkmon - C:\Windows\System32\Drivers\klupd_K4W-21-17_arkmon.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R0: klupd_K4W-21-17_klbg - C:\Windows\System32\Drivers\klupd_K4W-21-17_klbg.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R0: VMware VMCI Bus Driver - (vmci) - C:\Windows\System32\drivers\vmci.sys (+safe mode) (sign: 'Microsoft' - VMware, Inc.)
O23 - Driver R0: vSockets Virtual Machine Communication Interface Sockets driver - (vsock) - C:\Windows\system32\DRIVERS\vsock.sys (+safe mode) (sign: 'Microsoft' - VMware, Inc.)
O23 - Driver R1: Kaspersky Anti-Virus NDIS 6 Filter - (klim6) - C:\Windows\system32\DRIVERS\klim6.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab Driver.K4W-21-17 - (KLIF.K4W-21-17) - C:\Windows\system32\DRIVERS\K4W-21-17\klif.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab format recognizer driver.K4W-21-17 - (klpd.K4W-21-17) - C:\Windows\system32\DRIVERS\K4W-21-17\klpd.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab Kernel DLL.K4W-21-17 - (KLFLT.K4W-21-17) - C:\Windows\system32\DRIVERS\K4W-21-17\klflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab klbackupdisk.K4W-21-17 - (klbackupdisk.K4W-21-17) - C:\Windows\system32\DRIVERS\K4W-21-17\klbackupdisk.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab klbackupflt.K4W-21-17 - (klbackupflt.K4W-21-17) - C:\Windows\system32\DRIVERS\K4W-21-17\klbackupflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab KLKBDFLT.K4W-21-17 - (klkbdflt.K4W-21-17) - C:\Windows\system32\DRIVERS\K4W-21-17\klkbdflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab klpnpflt.K4W-21-17 - (klpnpflt.K4W-21-17) - C:\Windows\system32\DRIVERS\K4W-21-17\klpnpflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab Security Extender Driver.K4W-21-17 - (klgse.K4W-21-17) - C:\Windows\system32\DRIVERS\K4W-21-17\klgse.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab service driver.K4W-21-17 - (KLHK.K4W-21-17) - C:\Windows\system32\DRIVERS\K4W-21-17\klhk.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: kldisk.K4W-21-17 - C:\Windows\system32\DRIVERS\K4W-21-17\kldisk.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: klwtp.K4W-21-17 - C:\Windows\system32\DRIVERS\K4W-21-17\klwtp.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: kneps.K4W-21-17 - C:\Windows\system32\DRIVERS\K4W-21-17\kneps.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: LUMDriver - C:\Windows\system32\drivers\LUMDriver.sys (sign: 'IBM Polska Sp. z o.o.')
O23 - Driver R2: Sentinel64 - C:\Windows\System32\Drivers\Sentinel64.sys (sign: 'SafeNet, Inc.')
O23 - Driver R2: VMware Bridge Protocol - (VMnetBridge) - C:\Windows\system32\DRIVERS\vmnetbridge.sys (+safe mode) (sign: 'VMware, Inc.')
O23 - Driver R2: VMware hcmon - (hcmon) - C:\Windows\system32\DRIVERS\hcmon.sys (sign: 'VMware, Inc.')
O23 - Driver R2: VMware Virtual Ethernet Userif for VMnet - (VMnetuserif) - C:\Windows\system32\DRIVERS\vmnetuserif.sys (+safe mode) (sign: 'VMware, Inc.')
O23 - Driver R2: VMware vmx86 - (vmx86) - C:\Windows\system32\DRIVERS\vmx86.sys (sign: 'Microsoft' - VMware, Inc.)
O23 - Driver R3: Intel(R) Management Engine Interface - (MEIx64) - C:\Windows\System32\DriverStore\FileRepository\heci.inf_amd64_6b6e8cc42a3d1f09\x64\TeeDriverW10x64.sys (sign: 'Intel Corporation')
O23 - Driver R3: Kaspersky Lab KLMOUFLT.K4W-21-17 - (klmouflt.K4W-21-17) - C:\Windows\system32\DRIVERS\K4W-21-17\klmouflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: Kaspersky VPN - (kltun) - C:\Windows\system32\DRIVERS\kltun.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: klids.K4W-21-17 - C:\ProgramData\Kaspersky Lab\AVP21.17\Bases\klids.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: klupd_K4W-21-17_klark - C:\Windows\System32\Drivers\klupd_K4W-21-17_klark.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: klupd_K4W-21-17_mark - C:\Windows\System32\Drivers\klupd_K4W-21-17_mark.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: NDIS Miniport Driver for Killer PCI-E Gigabit Ethernet Controller - (e2xw10x64) - C:\Windows\System32\drivers\e2xw10x64.sys (+safe mode) (sign: 'Rivet Networks LLC')
O23 - Driver R3: NVIDIA Virtual Audio Device (Wave Extensible) (WDM) - (nvvad_WaveExtensible) - C:\Windows\system32\drivers\nvvad64v.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: nvlddmkm - C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_1196b342b24df5d1\nvlddmkm.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: NvModuleTracker - C:\Windows\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_ea6cec41fc5b2a8b\NvModuleTracker.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: NVVHCI Enumerator Service - (nvvhci) - C:\Windows\System32\drivers\nvvhci.sys (sign: 'Nvidia Corporation')
O23 - Driver R3: Service for NVIDIA High Definition Audio Driver - (NVHDA) - C:\Windows\system32\drivers\nvhda64v.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: Service for Realtek HD Audio (WDM) - (IntcAzAudAddService) - C:\Windows\system32\drivers\RTKVHD64.sys (sign: 'Realtek Semiconductor Corp.')
O23 - Driver R3: VMware Virtual Ethernet Adapter Driver - (VMnetAdapter) - C:\Windows\system32\DRIVERS\vmnetadapter.sys (+safe mode) (sign: 'VMware, Inc.')
O23 - Driver S3: Intel(R) Serial IO GPIO Controller Driver - (iaLPSSi_GPIO) - C:\Windows\System32\drivers\iaLPSSi_GPIO.sys (sign: 'Intel Corporation - Client Components Group')
O23 - Driver S3: NDIS Miniport Driver for Killer PCI-E Gigabit Ethernet Controller - (KillerEth) - C:\Windows\System32\drivers\e2xw10x64.sys (+safe mode) (sign: 'Rivet Networks LLC')
O23 - Driver S3: SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.) - (ssudmdm) - C:\Windows\system32\DRIVERS\ssudmdm.sys (sign: 'Samsung Electronics CO., LTD.')
O23 - Driver S3: SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.) - (dg_ssudbus) - C:\Windows\system32\DRIVERS\ssudbus2.sys (+safe mode) (sign: 'Samsung Electronics CO., LTD.')
O23 - Driver S3: SAMSUNG Mobile USB Connectivity Device Driver V2 - (ss_conn_usb_driver2) - C:\Windows\System32\Drivers\ss_conn_usb_driver2.sys (+safe mode) (sign: 'Samsung Electronics CO., LTD.')
O23 - Driver S3: ThrottleStop - C:\Users\Alkandras\AppData\Local\Temp\ThrottleStop.sys (sign: 'TechPowerUp LLC')
O23 - Driver S3: VMware USB Client Driver - (vmusb) - C:\Windows\System32\drivers\vmusb.sys (sign: 'VMware, Inc.')
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service: 'e2xw10x64'.
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service: 'KillerEth'.
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service: 'klim6'.
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service: 'kltun'.
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service: 'klwtp.K4W-21-17'
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service: 'VMnetAdapter'.
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service: 'VMnetuserif'.

--
End of file - Time spent: 133,5 sec. - 78114 bytes, CRC32: FFFFFFFF. Sign: ꭅ
 
Zararlı şüphesi
Kod:
Logfile of HiJackThis+ (Plus) build 2024-04-18 Alpha v.3.4.0.9

Platform:  x64 Windows 11 (Home Single Language), 10.0.22631.3880 (ReleaseId: 2009, 23H2), Service Pack: 0
Time:      31.07.2024 - 13:17 (UTC+03:00)
Language:  OS: Turkish (0x41F). Display: Turkish (0x41F). Non-Unicode: Turkish (0x41F)
Memory:    1480 MiB Free. Loading RAM (81 %), CPU (3 %)
Elevated:  Yes
Ran by:    aresk    (group: Administrators; type: Microsoft) on ARESK, FirstRun: no

Internet Explorer: 11.0.22621.3527
Default: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument %1 (Microsoft Edge)

Boot mode: Normal (Secure Boot: On)

Running processes:
Number | Path
   1  C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
   1  C:\Program Files (x86)\Common Files\Steam\steamservice.exe
   2  C:\Program Files (x86)\Epic Games\Launcher\Engine\Binaries\Win64\EpicWebHelper.exe
   1  C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe
   1  C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\avp.exe
   1  C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\avpui.exe
   1  C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\plugins_nms.exe
   1  C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.17\ksde.exe
   1  C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.17\ksdeui.exe
   1  C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\LenovoVantage-(DeviceSettingsSystemAddin).exe
   1  C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\LenovoVantage-(GenericMessagingAddin).exe
   1  C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\LenovoVantage-(LenovoGamingSystemAddin).exe
   1  C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\LenovoVantage-(VantageCoreAddin).exe
   1  C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\LenovoVantageService.exe
  20  C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
   1  C:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe
   6  C:\Program Files (x86)\Microsoft\EdgeWebView\Application\126.0.2592.113\msedgewebview2.exe
   7  C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
   1  C:\Program Files (x86)\Steam\steam.exe
   1  C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
   1  C:\Program Files\WindowsApps\a-volute.nahimic_1.10.1.0_x64__w2gh52qy24etm\Nahimic3.exe
   1  C:\Program Files\WindowsApps\Microsoft.YourPhone_1.24062.101.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
   1  C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.16300.20.0_x64__cw5n1h2txyewy\Dashboard\Widgets.exe
   1  C:\Program Files\WindowsApps\MicrosoftWindows.Client.WebExperience_524.16300.20.0_x64__cw5n1h2txyewy\Dashboard\WidgetService.exe
   1  C:\Program Files\WinRAR\WinRAR.exe
   1  C:\ProgramData\Lenovo\Udc\Hosts\24.2.1.44\x64\AppProvisioningPlugin.exe
   1  C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpDefenderCoreService.exe
   1  C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MsMpEng.exe
   1  C:\Users\aresk\AppData\Local\Microsoft\OneDrive\24.141.0714.0002\FileCoAuth.exe
   1  C:\Users\aresk\AppData\Local\Microsoft\OneDrive\OneDrive.exe
   1  C:\Users\aresk\AppData\Local\NhNotifSys\nahimic\nahimicNotifSys.exe
   1  C:\Users\aresk\AppData\Local\Temp\Rar$EXa18184.4807.rartemp\HiJackThis.exe
   1  C:\Windows\explorer.exe
   1  C:\Windows\Lenovo\ImController\PluginHost86\Lenovo.Modern.ImController.PluginHost.Device.exe
   1  C:\Windows\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe
   1  C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
   1  C:\Windows\System32\AggregatorHost.exe
   1  C:\Windows\System32\ApplicationFrameHost.exe
   1  C:\Windows\System32\audiodg.exe
   1  C:\Windows\System32\cmd.exe
   3  C:\Windows\System32\conhost.exe
   2  C:\Windows\System32\csrss.exe
   1  C:\Windows\System32\ctfmon.exe
   2  C:\Windows\System32\dllhost.exe
   1  C:\Windows\System32\drivers\Lenovo\udc\Service\UDClientService.exe
   1  C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_6673c5322430fc8a\igfxCUIServiceN.exe
   1  C:\Windows\System32\DriverStore\FileRepository\cui_dch.inf_amd64_6673c5322430fc8a\igfxEMN.exe
   1  C:\Windows\System32\DriverStore\FileRepository\dal.inf_amd64_64d7fcfcde9b9c10\jhi_service.exe
   1  C:\Windows\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_897ea327b3fe52f7\esif_uf.exe
   1  C:\Windows\System32\DriverStore\FileRepository\iastorvd.inf_amd64_a5d1cbafba9d4a6c\RstMwService.exe
   1  C:\Windows\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_a687edda40db3316\OneApp.IGCC.WinService.exe
   1  C:\Windows\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b38f68fdfc88d52c\IntelCpHDCPSvc.exe
   1  C:\Windows\System32\DriverStore\FileRepository\intcoed.inf_amd64_6f0a892deb241071\AS\IAS\IntelAudioService.exe
   1  C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_1446a24b89ad2808\FnHotkeyCapsLKNumLK.exe
   1  C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_1446a24b89ad2808\FnHotkeyUtility.exe
   1  C:\Windows\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_1446a24b89ad2808\LenovoUtilityService.exe
   1  C:\Windows\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe
   2  C:\Windows\System32\DriverStore\FileRepository\nvlt.inf_amd64_8224697fd70278c7\Display.NvContainer\NVDisplay.Container.exe
   2  C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_4401706d277a86e0\RtkAudUService64.exe
   1  C:\Windows\System32\dwm.exe
   2  C:\Windows\System32\fontdrvhost.exe
   1  C:\Windows\System32\Locator.exe
   1  C:\Windows\System32\lsass.exe
   1  C:\Windows\System32\NahimicService.exe
   1  C:\Windows\System32\NahimicSvc64.exe
   1  C:\Windows\System32\oobe\UserOOBEBroker.exe
   6  C:\Windows\System32\RuntimeBroker.exe
   1  C:\Windows\System32\SearchIndexer.exe
   1  C:\Windows\System32\SecurityHealthService.exe
   1  C:\Windows\System32\SecurityHealthSystray.exe
   1  C:\Windows\System32\services.exe
   1  C:\Windows\System32\sihost.exe
   1  C:\Windows\System32\smartscreen.exe
   1  C:\Windows\System32\smss.exe
   1  C:\Windows\System32\spoolsv.exe
  89  C:\Windows\System32\svchost.exe
   1  C:\Windows\System32\taskhostw.exe
   3  C:\Windows\System32\wbem\unsecapp.exe
   1  C:\Windows\System32\wbem\WmiApSrv.exe
   2  C:\Windows\System32\wbem\WmiPrvSE.exe
   1  C:\Windows\System32\wininit.exe
   1  C:\Windows\System32\winlogon.exe
   1  C:\Windows\System32\wlanext.exe
   4  C:\Windows\System32\WUDFHost.exe
   1  C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
   1  C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
   1  C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\SearchHost.exe
   1  C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
   1  C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
   1  C:\Windows\SysWOW64\NahimicSvc32.exe
   1  C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
   1  C:\Windows\UUS\Packages\Preview\amd64\MoUsoCoreWorker.exe

O2 - HKLM\..\BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_421\bin\jp2ssv.dll (sign: 'Oracle America, Inc.')
O2 - HKLM\..\BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_421\bin\ssv.dll (sign: 'Oracle America, Inc.')
O4 - HKCU\..\Run: [EpicGamesLauncher] = C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe -silent -launchcontext=boot (sign: 'Epic Games Inc.')
O4 - HKCU\..\Run: [MicrosoftEdgeAutoLaunch_20EC8B42C686303ACE16EA75728CC730] = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --no-startup-window --win-session-start (sign: 'Microsoft')
O4 - HKCU\..\Run: [OneDrive] = C:\Users\aresk\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background (sign: 'Microsoft')
O4 - HKCU\..\Run: [Opera GX Stable] = C:\Users\aresk\AppData\Local\Programs\Opera GX\opera.exe (sign: 'Opera Norway AS')
O4 - HKCU\..\Run: [Steam] = C:\Program Files (x86)\Steam\steam.exe -silent (sign: 'Valve Corp.')
O4 - HKLM\..\Run: [RtkAudUService] = C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_4401706d277a86e0\RtkAudUService64.exe -background (sign: 'Realtek Semiconductor Corp.')
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\Program Files (x86)\Lenovo\VantageService\
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\USERS\ARESK\APPDATA\LOCAL\MALWAREBYTES
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\USERS\ARESK\APPDATA\LOCAL\MALWAREBYTES\Logs
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\USERS\ARESK\APPDATA\LOCAL\MALWAREBYTES\Logs\MBAMSI.alt2.lock
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\USERS\ARESK\APPDATA\LOCAL\MALWAREBYTES\Logs\MBAMSI.alt2.log
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\USERS\ARESK\APPDATA\LOCAL\MALWAREBYTES\Logs\MBAMSI.lock
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\USERS\ARESK\APPDATA\LOCAL\MALWAREBYTES\Logs\MBAMSI.log
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\WINDOWS\TEMP\e950e1024f2411efb73f088fc3cb536d.tmp
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\WINDOWS\TEMP\e95191064f2411efb2c0088fc3cb536d.tmp
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\WINDOWS\TEMP\e96453224f2411ef9ecc088fc3cb536d.tmp
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\WINDOWS\TEMP\e96558d04f2411ef9846088fc3cb536d.tmp
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\WINDOWS\TEMP\e9b5231a4f2411ef8f19088fc3cb536d.tmp
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\WINDOWS\TEMP\e9b5e6d84f2411efa05b088fc3cb536d.tmp
O4 - HKU\S-1-5-19\..\Run: [OneDriveSetup] = C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'Local service') (sign: 'Microsoft')
O4 - HKU\S-1-5-20\..\Run: [OneDriveSetup] = C:\Windows\System32\OneDriveSetup.exe /thfirstsetup (User 'Network service') (sign: 'Microsoft')
O4-32 - HKLM\..\Run: [SunJavaUpdateSched] = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (sign: 'Oracle America, Inc.')
O8 - Context menu item: HKCU\..\Internet Explorer\MenuExt\Se&nd to OneNote: (default) = C:\Program Files\Microsoft Office\root\Office16\ONBttnIE.dll (file missing)
O17 - DHCP DNS 1: 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{409ead23-55bd-4d4b-bcd7-68ba055fde77}: [NameServer] = 198.51.100.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{409ead23-55bd-4d4b-bcd7-68ba055fde77}: [NameServer] = 198.51.100.2
O18 - HKLM\Software\Classes\Protocols\Filter\application/octet-stream: [CLSID] = {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (sign: 'Lenovo')
O18 - HKLM\Software\Classes\Protocols\Filter\application/x-complus: [CLSID] = {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (sign: 'Lenovo')
O18 - HKLM\Software\Classes\Protocols\Filter\application/x-msdownload: [CLSID] = {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - C:\Windows\System32\mscoree.dll (sign: 'Lenovo')
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Intel (empty)
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Lenovo\BatteryGauge (empty)
O22 - Tasks: (disabled) \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical - {613FBA38-A3DF-4AB8-9674-5604984A299A},/RuntimeWide - C:\Windows\System32\mscoree.dll (sign: 'Lenovo')
O22 - Tasks: (disabled) \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical - {DE434264-8FE9-4C0B-A83B-89EBEEBFF78E},/RuntimeWide - C:\Windows\System32\mscoree.dll (sign: 'Lenovo')
O22 - Tasks: (disabled) \Microsoft\Windows\Flighting\FeatureConfig\BootstrapUsageDataReporting - {D759C938-B375-41CB-A2A2-E6D866A767F4} - C:\WINDOWS\System32\fcon.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\MdmDiagnosticsCleanup - C:\WINDOWS\system32\MdmDiagnosticsTool.exe /clean (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ProvRetryTask (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Shell\ThemeAssetTask_SyncFODState - {3BC5DD7D-EA3B-428C-B9B6-0723DB6A1057} - C:\Windows\System32\Windows.UI.Immersive.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\WINDOWS\system32\usoclient.exe StartMaintenanceWork (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Lenovo\Vantage\Schedule\DailyTelemetryTransmission - C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\ScheduleEventAction.exe DailyTelemetryTransmission (sign: 'Lenovo')
O22 - Tasks: (telemetry) \Microsoft\Office\Office Performance Monitor - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\WINDOWS\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\WINDOWS\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareData (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\WINDOWS\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\Microsoft Compatibility Appraiser - C:\WINDOWS\system32\sc.exe start InventorySvc (sign: '')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\PcaWallpaperAppDetect - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaWallpaperAppDetect (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\SdbinstMergeDbTask - C:\WINDOWS\system32\sdbinst.exe -mm (sign: 'Microsoft')
O22 - Tasks: (telemetry) NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'Nvidia Corporation')
O22 - Tasks: (telemetry) NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'Nvidia Corporation')
O22 - Tasks: (telemetry) NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'Nvidia Corporation')
O22 - Tasks: (telemetry) NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'Nvidia Corporation')
O22 - Tasks: \Lenovo\ImController\Lenovo iM Controller Monitor - C:\WINDOWS\system32\ImController.InfInstaller.exe -checkremoval (sign: 'Lenovo')
O22 - Tasks: \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance - C:\WINDOWS\system32\sc.exe START ImControllerService (sign: 'Microsoft')
O22 - Tasks: \Lenovo\ImController\Plugins\LenovoSystemUpdatePlugin_WeeklyTask - C:\WINDOWS\System32\reg.exe add hklm\SOFTWARE\Lenovo\SystemUpdatePlugin\scheduler  /v start /t reg_dword /d 1 /f /reg:32 (sign: 'Microsoft')
O22 - Tasks: \Lenovo\ImController\TimeBasedEvents\3161bf55-6e32-4807-b6a8-ae296cfbb1fd - C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe /timebasedeventtrigger 3161bf55-6e32-4807-b6a8-ae296cfbb1fd (sign: 'Lenovo')
O22 - Tasks: \Lenovo\ImController\TimeBasedEvents\41dc781c-b426-424e-b374-99a14cabc3f8 - C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe /timebasedeventtrigger 41dc781c-b426-424e-b374-99a14cabc3f8 (sign: 'Lenovo')
O22 - Tasks: \Lenovo\ImController\TimeBasedEvents\4700e001-cc8b-4a94-ace2-9ead7add2ee3 - C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe /timebasedeventtrigger 4700e001-cc8b-4a94-ace2-9ead7add2ee3 (sign: 'Lenovo')
O22 - Tasks: \Lenovo\ImController\TimeBasedEvents\67fb9851-48ff-49e8-8fd7-1023a83459b5 - C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe /timebasedeventtrigger 67fb9851-48ff-49e8-8fd7-1023a83459b5 (sign: 'Lenovo')
O22 - Tasks: \Lenovo\ImController\TimeBasedEvents\999fb9fc-6bfa-46d2-9bea-39d814a97bdc - C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe /timebasedeventtrigger 999fb9fc-6bfa-46d2-9bea-39d814a97bdc (sign: 'Lenovo')
O22 - Tasks: \Lenovo\LenovoWelcomeLauncher - C:\ProgramData\Lenovo\ImController\Plugins\LenovoFirstRunExperiencePackage\x86\LenovoWelcome.exe /task (sign: 'Lenovo')
O22 - Tasks: \Lenovo\LenovoWelcomeTask - C:\ProgramData\Lenovo\ImController\Plugins\LenovoFirstRunExperiencePackage\x86\LenovoWelcomeTask.exe $(EventData) (sign: 'Lenovo')
O22 - Tasks: \Lenovo\UDC\Lenovo UDC Idle Monitor - C:\windows\system32\drivers\Lenovo\udc\Service\UDCUserAgent.exe /onidle (sign: 'Lenovo')
O22 - Tasks: \Lenovo\UDC\Lenovo UDC Monitor - C:\WINDOWS\system32\drivers\lenovo\udc\data\InfBackup\UdcInfInstaller.exe -checkremoval (sign: 'Lenovo')
O22 - Tasks: \Lenovo\Vantage\Lenovo.Vantage.ServiceMaintainance - C:\WINDOWS\system32\sc.exe start LenovoVantageService (sign: 'Microsoft')
O22 - Tasks: \Lenovo\Vantage\Schedule\BatteryGaugeAddinDailyScheduleTask - C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\ScheduleEventAction.exe BatteryGaugeAddinDailyScheduleTask (sign: 'Lenovo')
O22 - Tasks: \Lenovo\Vantage\Schedule\GenericMessagingAddin - C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\ScheduleEventAction.exe GenericMessagingAddin (sign: 'Lenovo')
O22 - Tasks: \Lenovo\Vantage\Schedule\HeartbeatAddinDailyScheduleTask - C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\ScheduleEventAction.exe HeartbeatAddinDailyScheduleTask (sign: 'Lenovo')
O22 - Tasks: \Lenovo\Vantage\Schedule\IdeaNotebookAddinDailyEvent - C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\ScheduleEventAction.exe IdeaNotebookAddinDailyEvent (sign: 'Lenovo')
O22 - Tasks: \Lenovo\Vantage\Schedule\Lenovo.Vantage.SmartPerformance.MonthlyReport - C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\ScheduleEventAction.exe Lenovo.Vantage.SmartPerformance.MonthlyReport (sign: 'Lenovo')
O22 - Tasks: \Lenovo\Vantage\Schedule\LenovoCompanionAppAddinDailyScheduleTask - C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\ScheduleEventAction.exe LenovoCompanionAppAddinDailyScheduleTask (sign: 'Lenovo')
O22 - Tasks: \Lenovo\Vantage\Schedule\LenovoSystemUpdateAddin_WeeklyTask - C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\ScheduleEventAction.exe LenovoSystemUpdateAddin_WeeklyTask (sign: 'Lenovo')
O22 - Tasks: \Lenovo\Vantage\Schedule\SettingsWidgetAddinDailyScheduleTask - C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\ScheduleEventAction.exe SettingsWidgetAddinDailyScheduleTask (sign: 'Lenovo')
O22 - Tasks: \Lenovo\Vantage\Schedule\SmartPerformance.ExpireReminder - C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\ScheduleEventAction.exe SmartPerformance.ExpireReminder (sign: 'Lenovo')
O22 - Tasks: \Lenovo\Vantage\Schedule\VantageCoreAddinWeekScheduleTask - C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\ScheduleEventAction.exe VantageCoreAddinWeekScheduleTask (sign: 'Lenovo')
O22 - Tasks: \Lenovo\Vantage\StartupFixPlan - C:\Program Files (x86)\Lenovo\VantageService\4.1.22.0\uninstall.exe /repair (sign: 'Lenovo')
O22 - Tasks: \McAfeeTsk\OOBEUpgrader - C:\Program Files\McAfee\MSC\OOBE_Upgrader.exe /Run (file missing)
O22 - Tasks: \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 - {84F0FAE1-C27B-4F6F-807B-28CF6F96287D},/RuntimeWide - C:\Windows\System32\mscoree.dll (sign: 'Lenovo')
O22 - Tasks: \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 - {429BC048-379E-45E0-80E4-EB1977941B5C},/RuntimeWide - C:\Windows\System32\mscoree.dll (sign: 'Lenovo')
O22 - Tasks: \Microsoft\Windows\Setup\EM - C:\WINDOWS\system32\EM.exe (file missing)
O22 - Tasks: \Microsoft\Windows\SMB\UninstallSMB1ClientTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client" (sign: '')
O22 - Tasks: \Microsoft\Windows\SMB\UninstallSMB1ServerTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server" (sign: '')
O22 - Tasks: \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker - C:\WINDOWS\system32\MusNotification.exe (file missing)
O22 - Tasks: Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} - C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe /waitUpgrade (sign: 'Kaspersky Lab JSC')
O22 - Tasks: NahimicTask32 - C:\WINDOWS\system32\..\SysWOW64\NahimicSvc32.exe $(Arg0) $(Arg1) $(Arg2) $(Arg3) $(Arg4) $(Arg5) $(Arg6) $(Arg7) (sign: 'A-Volute SAS')
O22 - Tasks: NahimicTask64 - C:\WINDOWS\system32\.\NahimicSvc64.exe $(Arg0) $(Arg1) $(Arg2) $(Arg3) $(Arg4) $(Arg5) $(Arg6) $(Arg7) (sign: 'A-Volute SAS')
O22 - Tasks: NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log (sign: 'Nvidia Corporation')
O22 - Tasks: NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (sign: 'Nvidia Corporation')
O22 - Tasks: NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe --launcher=TaskScheduler (sign: 'Nvidia Corporation')
O22 - Tasks: OneDrive Reporting Task-S-1-5-21-4278694630-3052081342-3401210144-1001 - C:\Users\aresk\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe /reporting (sign: 'Microsoft')
O22 - Tasks: Opera GX scheduled Autoupdate 1722338197 - C:\Users\aresk\AppData\Local\Programs\Opera GX\autoupdate\opera_autoupdate.exe --scheduledtask --bypasslauncher $(Arg0) (sign: 'Opera Norway AS')
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ProvRetryTask (sign: 'Microsoft')
O22 - Tasks_Migrated: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\WINDOWS\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (sign: 'Microsoft')
O22 - Tasks_Migrated: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTask (sign: 'Microsoft')
O22 - Tasks_Migrated: (telemetry) NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'Nvidia Corporation')
O22 - Tasks_Migrated: (telemetry) NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'Nvidia Corporation')
O22 - Tasks_Migrated: (telemetry) NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'Nvidia Corporation')
O22 - Tasks_Migrated: (telemetry) NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe (sign: 'Nvidia Corporation')
O22 - Tasks_Migrated: \Lenovo\BatteryGauge\BatteryGaugeMaintenance - C:\ProgramData\Lenovo\ImController\Plugins\LenovoBatteryGaugePackage\x64\BGHelper.exe (file missing)
O22 - Tasks_Migrated: \Lenovo\ImController\Lenovo iM Controller Monitor - C:\WINDOWS\system32\ImController.InfInstaller.exe -checkremoval (sign: 'Lenovo')
O22 - Tasks_Migrated: \Lenovo\ImController\Lenovo iM Controller Scheduled Maintenance - C:\WINDOWS\system32\sc.exe START ImControllerService (sign: 'Microsoft')
O22 - Tasks_Migrated: \Lenovo\LenovoWelcomeLauncher - C:\ProgramData\Lenovo\ImController\Plugins\LenovoFirstRunExperiencePackage\x86\LenovoWelcome.exe /task (sign: 'Lenovo')
O22 - Tasks_Migrated: \Lenovo\LenovoWelcomeTask - C:\ProgramData\Lenovo\ImController\Plugins\LenovoFirstRunExperiencePackage\x86\LenovoWelcomeTask.exe $(EventData) (sign: 'Lenovo')
O22 - Tasks_Migrated: \Lenovo\UDC\Lenovo UDC Idle Monitor - C:\windows\system32\drivers\Lenovo\udc\Service\UDCUserAgent.exe /onidle (sign: 'Lenovo')
O22 - Tasks_Migrated: \Lenovo\UDC\Lenovo UDC Monitor - C:\WINDOWS\system32\drivers\lenovo\udc\data\InfBackup\UdcInfInstaller.exe -checkremoval (sign: 'Lenovo')
O22 - Tasks_Migrated: \Lenovo\Vantage\Lenovo.Vantage.ServiceMaintainance - C:\WINDOWS\system32\sc.exe start LenovoVantageService (sign: 'Microsoft')
O22 - Tasks_Migrated: \McAfee\DAD.Execute.Updates - C:\Program Files\Common Files\McAfee\DynamicAppDownloader\DADUpdater.exe (file missing)
O22 - Tasks_Migrated: \McAfee\McAfee Auto Maintenance Task Agent - {ABCECA3B-EA5A-496B-A021-5C6BAB365E5C} - (no file)
O22 - Tasks_Migrated: \McAfee\McAfee Idle Detection Task - {ABCDCA3B-DE6B-5A7C-B132-6D7CBA63E5C5} - (no file)
O22 - Tasks_Migrated: \McAfee\StartOOBEFix - C:\Program Files\Common Files\McAfee\OOBE\McOOBEFix.exe (file missing)
O22 - Tasks_Migrated: \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 - {84F0FAE1-C27B-4F6F-807B-28CF6F96287D},/RuntimeWide - C:\Windows\System32\mscoree.dll (sign: 'Lenovo')
O22 - Tasks_Migrated: \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 - {429BC048-379E-45E0-80E4-EB1977941B5C},/RuntimeWide - C:\Windows\System32\mscoree.dll (sign: 'Lenovo')
O22 - Tasks_Migrated: \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical - {613FBA38-A3DF-4AB8-9674-5604984A299A},/RuntimeWide - C:\Windows\System32\mscoree.dll (sign: 'Lenovo')
O22 - Tasks_Migrated: \Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical - {DE434264-8FE9-4C0B-A83B-89EBEEBFF78E},/RuntimeWide - C:\Windows\System32\mscoree.dll (sign: 'Lenovo')
O22 - Tasks_Migrated: \Microsoft\Windows\Management\Provisioning\MdmDiagnosticsCleanup - C:\WINDOWS\system32\MdmDiagnosticsTool.exe /clean (sign: 'Microsoft')
O22 - Tasks_Migrated: \Microsoft\Windows\Management\Provisioning\PostResetBoot - C:\WINDOWS\system32\ProvTool.exe /turn 3 /source ProvResetBoot (sign: 'Microsoft')
O22 - Tasks_Migrated: \Microsoft\Windows\Setup\EM - C:\WINDOWS\system32\EM.exe (file missing)
O22 - Tasks_Migrated: \Microsoft\Windows\SMB\UninstallSMB1ClientTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client" (sign: '')
O22 - Tasks_Migrated: \Microsoft\Windows\SMB\UninstallSMB1ServerTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server" (sign: '')
O22 - Tasks_Migrated: McAfee Remediation (Prepare) - C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe /prepare (file missing)
O22 - Tasks_Migrated: McAfeeLogon - C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe /platui /runkey (file missing)
O22 - Tasks_Migrated: NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -d "C:\Program Files\NVIDIA Corporation\NvDriverUpdateCheck" -l 3 -f C:\ProgramData\NVIDIA\NvContainerDriverUpdateCheck.log (sign: 'Nvidia Corporation')
O22 - Tasks_Migrated: NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe (sign: 'Nvidia Corporation')
O22 - Tasks_Migrated: NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe --launcher=TaskScheduler (sign: 'Nvidia Corporation')
O23 - Service R2: Intel(R) Audio Service - (IntelAudioService) - C:\WINDOWS\System32\DriverStore\FileRepository\intcoed.inf_amd64_6f0a892deb241071\\AS\\IAS\\IntelAudioService.exe (sign: 'Intel Corporation')
O23 - Service R2: Intel(R) Content Protection HDCP Service - (cplspcon) - C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b38f68fdfc88d52c\IntelCpHDCPSvc.exe (sign: 'Intel Corporation')
O23 - Service R2: Intel(R) Dynamic Application Loader Host Interface Service - (jhi_service) - C:\WINDOWS\System32\DriverStore\FileRepository\dal.inf_amd64_64d7fcfcde9b9c10\jhi_service.exe (sign: 'Intel Corporation')
O23 - Service R2: Intel(R) Dynamic Tuning service - (esifsvc) - C:\WINDOWS\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_897ea327b3fe52f7\esif_uf.exe (sign: 'Intel Corporation')
O23 - Service R2: Intel(R) Graphics Command Center Service - (igccservice) - C:\WINDOWS\System32\DriverStore\FileRepository\igcc_dch.inf_amd64_a687edda40db3316\OneApp.IGCC.WinService.exe (sign: 'Intel Corporation')
O23 - Service R2: Intel(R) HD Graphics Control Panel Service - (igfxCUIService2.0.0.0) - C:\WINDOWS\System32\DriverStore\FileRepository\cui_dch.inf_amd64_6673c5322430fc8a\igfxCUIServiceN.exe (sign: 'Intel Corporation')
O23 - Service R2: Intel(R) Management Engine WMI Provider Registration - (WMIRegistrationService) - C:\WINDOWS\System32\DriverStore\FileRepository\mewmiprov.inf_amd64_d51901c26227fb29\WMIRegistrationService.exe (sign: 'Intel Corporation')
O23 - Service R2: Intel(R) Storage Middleware Service - (RstMwService) - C:\WINDOWS\System32\DriverStore\FileRepository\iastorvd.inf_amd64_a5d1cbafba9d4a6c\RstMwService.exe (sign: 'Intel Corporation')
O23 - Service R2: Kaspersky Anti-Virus Hizmeti 21.3 - (AVP21.3) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\avp.exe -r (sign: 'Kaspersky Lab JSC')
O23 - Service R2: Kaspersky VPN Secure Connection Hizmeti 5.17 - (KSDE5.17) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky VPN 5.17\ksde.exe -r (sign: 'Kaspersky Lab JSC')
O23 - Service R2: Lenovo Fn and function keys service - (LenovoFnAndFunctionKeys) - C:\WINDOWS\System32\DriverStore\FileRepository\lenovofnandfunctionkeys.inf_amd64_1446a24b89ad2808\LenovoUtilityService.exe (sign: 'Lenovo')
O23 - Service R2: LenovoVantageService - C:\Program Files (x86)\Lenovo\VantageService\\4.1.22.0\LenovoVantageService.exe (sign: 'Lenovo')
O23 - Service R2: Microsoft Defender Çekirdek Hizmeti - (MDCoreSvc) - C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24060.7-0\MpDefenderCoreService.exe (sign: 'Microsoft')
O23 - Service R2: Nahimic service - (NahimicService) - C:\WINDOWS\system32\NahimicService.exe (sign: 'A-Volute SAS')
O23 - Service R2: NVIDIA Display Container LS - (NVDisplay.ContainerLocalSystem) - C:\WINDOWS\System32\DriverStore\FileRepository\nvlt.inf_amd64_8224697fd70278c7\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\WINDOWS\System32\DriverStore\FileRepository\nvlt.inf_amd64_8224697fd70278c7\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem (sign: 'NVIDIA Corporation')
O23 - Service R2: Realtek Audio Universal Service - (RtkAudioUniversalService) - C:\WINDOWS\System32\DriverStore\FileRepository\realtekservice.inf_amd64_4401706d277a86e0\RtkAudUService64.exe (sign: 'Realtek Semiconductor Corp.')
O23 - Service R2: System Interface Foundation Service - (ImControllerService) - C:\WINDOWS\Lenovo\ImController\Service\Lenovo.Modern.ImController.exe (sign: 'Lenovo')
O23 - Service R2: Universal Device Client Service - (UDCService) - C:\WINDOWS\System32\drivers\Lenovo\udc\Service\UDClientService.exe (sign: 'Lenovo')
O23 - Service R3: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\steamservice.exe /RunAsService (sign: 'Valve Corp.')
O23 - Service S2: Intel(R) TPM Provisioning Service - C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_367008a610747d24\lib\TPMProvisioningService.exe (sign: 'Intel Corporation')
O23 - Service S2: spacedeskService - C:\WINDOWS\System32\spacedeskService.exe (file missing)
O23 - Service S3: Epic Online Services - (EpicOnlineServices) - C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe (sign: 'Epic Games Inc.')
O23 - Service S3: Intel(R) Capability Licensing Service TCP IP Interface - C:\WINDOWS\System32\DriverStore\FileRepository\iclsclient.inf_amd64_367008a610747d24\lib\SocketHeciServer.exe (sign: 'Intel Corporation')
O23 - Service S3: Intel(R) Optane(TM) Memory Service - (iaStorAfsService) - C:\WINDOWS\System32\iaStorAfsService.exe (sign: 'Intel Corporation')
O23 - Service S3: Kaspersky Volume Shadow Copy Service Bridge 21.3 - (klvssbridge64_21.3) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 21.3\x64\vssbridge64.exe (sign: 'Kaspersky Lab JSC')
O23 - Service S3: NVIDIA FrameView SDK service - (FvSvc) - C:\Program Files\NVIDIA Corporation\FrameViewSDK\nvfvsdksvc_x64.exe -service (sign: 'Nvidia Corporation')
O23 - Service S3: NVIDIA LocalSystem Container - (NvContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe -s NvContainerLocalSystem -a -f "C:\ProgramData\NVIDIA\NvContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvContainer\plugins\LocalSystem" -r -p 30000 -st "C:\Program Files\NVIDIA Corporation\NvContainer\NvContainerTelemetryApi.dll" (sign: 'Nvidia Corporation')
O23 - Driver R0: AO Kaspersky Lab Cryptographic Module x64 (56 bit) - (cm_km) - C:\WINDOWS\system32\DRIVERS\cm_km.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R0: Intel(R) Chipset VMD RST Controller service - (iaStorVD) - C:\WINDOWS\System32\drivers\iaStorVD.sys (sign: 'Intel Corporation')
O23 - Driver R0: klupd_klif_arkmon - C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R0: klupd_klif_klbg - C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Anti-Virus NDIS 6 Filter - (klim6) - C:\WINDOWS\system32\DRIVERS\klim6.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab Driver - (KLIF) - C:\WINDOWS\system32\DRIVERS\klif.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab format recognizer driver - (klpd) - C:\WINDOWS\system32\DRIVERS\klpd.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab Kernel DLL - (klflt) - C:\WINDOWS\system32\DRIVERS\klflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab klbackupdisk - (klbackupdisk) - C:\WINDOWS\system32\DRIVERS\klbackupdisk.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab klbackupflt - (klbackupflt) - C:\WINDOWS\system32\DRIVERS\klbackupflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab klpnpflt - (klpnpflt) - C:\WINDOWS\system32\DRIVERS\klpnpflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab Security Extender Driver - (klgse) - C:\WINDOWS\system32\DRIVERS\klgse.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: Kaspersky Lab service driver - (klhk) - C:\WINDOWS\system32\DRIVERS\klhk.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: kldisk - C:\WINDOWS\system32\DRIVERS\kldisk.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: klwfp - C:\WINDOWS\system32\DRIVERS\klwfp.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: KLwtp - WFP callout traffic inspector - (klwtp) - C:\WINDOWS\system32\DRIVERS\klwtp.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R1: kneps - C:\WINDOWS\system32\DRIVERS\kneps.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: ___ Windows 10 64 Bit için Intel(R) Wireless Bağdaştırıcı Sürücüsü  - (Netwtw10) - C:\WINDOWS\System32\drivers\Netwtw10.sys (+safe mode) (sign: 'Intel Corporation')
O23 - Driver R3: dptf_acpi - C:\WINDOWS\System32\DriverStore\FileRepository\dptf_acpi.inf_amd64_ec9dc29e11676412\dptf_acpi.sys (+safe mode) (sign: 'Intel Corporation')
O23 - Driver R3: dptf_cpu - C:\WINDOWS\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_897ea327b3fe52f7\dptf_cpu.sys (+safe mode) (sign: 'Intel Corporation')
O23 - Driver R3: esif_lf - C:\WINDOWS\System32\DriverStore\FileRepository\dptf_cpu.inf_amd64_897ea327b3fe52f7\esif_lf.sys (+safe mode) (sign: 'Intel Corporation')
O23 - Driver R3: igfxn - C:\WINDOWS\System32\DriverStore\FileRepository\iigd_dch.inf_amd64_b38f68fdfc88d52c\igdkmdn64.sys (sign: 'Intel Corporation')
O23 - Driver R3: Intel(R) GNA Scoring Accelerator service - (IntelGNA) - C:\WINDOWS\System32\DriverStore\FileRepository\gna.inf_amd64_04d4eecc5838a558\gna.sys (sign: 'Intel Corporation')
O23 - Driver R3: Intel(R) HID Event Filter - (HidEventFilter) - C:\WINDOWS\System32\DriverStore\FileRepository\hideventfilter.inf_amd64_550b85a074d33f99\HidEventFilter.sys (+safe mode) (sign: 'Intel Corporation')
O23 - Driver R3: Intel(R) Management Engine Interface  - (MEIx64) - C:\WINDOWS\System32\DriverStore\FileRepository\heci.inf_amd64_a55eae4b02a2a587\x64\TeeDriverW10x64.sys (sign: 'Intel Corporation')
O23 - Driver R3: Intel(R) Serial IO GPIO Driver v2 - (iaLPSS2_GPIO2_TGL) - C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_gpio2_tgl.inf_amd64_2546dafe2183e972\iaLPSS2_GPIO2_TGL.sys (sign: 'Intel Corporation')
O23 - Driver R3: Intel(R) Serial IO I2C Driver v2 - (iaLPSS2_I2C_TGL) - C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_i2c_tgl.inf_amd64_1308f85f1b0adf27\iaLPSS2_I2C_TGL.sys (+safe mode) (sign: 'Intel Corporation')
O23 - Driver R3: Intel(R) Wireless Bluetooth(R) - (ibtusb) - C:\WINDOWS\System32\DriverStore\FileRepository\ibtusb.inf_amd64_b9ef536b42a53211\ibtusb.sys (+safe mode) (sign: 'Intel Corporation')
O23 - Driver R3: Intel® Smart Sound Technology BUS - (IntcAudioBus) - C:\WINDOWS\System32\DriverStore\FileRepository\intcaudiobus.inf_amd64_799c962c58e6bfeb\IntcAudioBus.sys (sign: 'Intel Corporation')
O23 - Driver R3: Intel® Smart Sound Technology for Digital Microphones - (IntcDMic) - C:\WINDOWS\System32\DriverStore\FileRepository\intcdmic.inf_amd64_acd402699ea3db34\IntcDMic.sys (sign: 'Intel Corporation')
O23 - Driver R3: Intel® Smart Sound Technology OED - (IntcOED) - C:\WINDOWS\System32\DriverStore\FileRepository\intcoed.inf_amd64_6f0a892deb241071\IntcOED.sys (sign: 'Intel Corporation')
O23 - Driver R3: Kaspersky Lab KLKBDFLT - (klkbdflt) - C:\WINDOWS\system32\DRIVERS\klkbdflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: Kaspersky Lab KLMOUFLT - (klmouflt) - C:\WINDOWS\system32\DRIVERS\klmouflt.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: Kaspersky VPN - (kltun) - C:\WINDOWS\system32\DRIVERS\kltun.sys (+safe mode) (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: klids - C:\ProgramData\Kaspersky Lab\AVP21.3\Bases\klids.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: klupd_klif_klark - C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: klupd_klif_mark - C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys (sign: 'Microsoft' - AO Kaspersky Lab)
O23 - Driver R3: Lenovo Virtual Power Controller Driver - (ACPIVPC) - C:\WINDOWS\System32\drivers\AcpiVpc.sys (sign: 'Lenovo')
O23 - Driver R3: Nahimic Easy Surround device - Driver - (NahimicBTLink) - C:\WINDOWS\System32\drivers\NahimicBTLink.sys (sign: 'A-Volute SAS')
O23 - Driver R3: Nahimic mirroring device - Driver - (Nahimic_Mirroring) - C:\WINDOWS\System32\drivers\Nahimic_Mirroring.sys (sign: 'A-Volute SAS')
O23 - Driver R3: NVIDIA Virtual Audio Device (Wave Extensible) (WDM) - (nvvad_WaveExtensible) - C:\WINDOWS\system32\drivers\nvvad64v.sys (sign: 'Nvidia Corporation')
O23 - Driver R3: nvlddmkm - C:\WINDOWS\System32\DriverStore\FileRepository\nvlt.inf_amd64_8224697fd70278c7\nvlddmkm.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: NvModuleTracker - C:\WINDOWS\System32\DriverStore\FileRepository\nvmoduletracker.inf_amd64_0c1cc60a4b422185\NvModuleTracker.sys (sign: 'Nvidia Corporation')
O23 - Driver R3: NVPCF Service - (nvpcf) - C:\WINDOWS\System32\drivers\nvpcf.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: NVVHCI Enumerator Service - (nvvhci) - C:\WINDOWS\System32\drivers\nvvhci.sys (sign: 'Nvidia Corporation')
O23 - Driver R3: Realtek NetAdapter Driver - (rt68cx21) - C:\WINDOWS\System32\DriverStore\FileRepository\rt68cx21x64.inf_amd64_3037ec512dc36c3a\rt68cx21x64.sys (sign: 'Realtek Semiconductor Corp.')
O23 - Driver R3: Service for Realtek HD Audio (WDM) - (IntcAzAudAddService) - C:\WINDOWS\system32\drivers\RTKVHD64.sys (sign: 'Realtek Semiconductor Corp.')
O23 - Driver S3: FBNetFilter - C:\WINDOWS\System32\drivers\FBNetFlt.sys (sign: 'Lenovo')
O23 - Driver S3: iaStorAfs - C:\WINDOWS\System32\drivers\iaStorAfs.sys (sign: 'Intel Corporation')
O23 - Driver S3: Intel(R) Serial IO GPIO Controller Driver - (iaLPSSi_GPIO) - C:\WINDOWS\System32\drivers\iaLPSSi_GPIO.sys (sign: 'Intel Corporation - Client Components Group')
O23 - Driver S3: Intel(R) Serial IO SPI Driver v2 - (iaLPSS2_SPI_TGL) - C:\WINDOWS\System32\DriverStore\FileRepository\ialpss2_spi_tgl.inf_amd64_fc1ed3a5a1d514f2\iaLPSS2_SPI_TGL.sys (+safe mode) (sign: 'Intel Corporation')
O23 - Driver S3: Intel® Smart Sound Technology MIPI SoundWire® Controller - (IntcSdwBus) - C:\WINDOWS\System32\DriverStore\FileRepository\intcsdwbus.inf_amd64_f52c196d9030ea0e\IntcSdwBus.sys (sign: 'Intel Corporation')
O23 - Driver S3: MpKsle2c11adf - C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{85D34209-5089-443F-9B6C-875ABCCD94C9}\MpKslDrv.sys (file missing)
O23 - Driver S3: NVIDIA SHIELD Wireless Controller Trackpad Service - (NVSWCFilter) - C:\WINDOWS\System32\drivers\nvswcfilter.sys (sign: 'Nvidia Corporation')
O23 - Driver S3: NVIDIA USB Type-C PPC Service - (UcmCxUcsiNvppc) - C:\WINDOWS\System32\DriverStore\FileRepository\nvppc.inf_amd64_304d5a34dac4fe27\UcmCxUcsiNvppc.sys (sign: 'Nvidia Corporation')
O23 - Driver S3: Scp Virtual Bus Driver - (ScpVBus) - C:\WINDOWS\System32\drivers\ScpVBus.sys (sign: 'Open Source Developer, Benjamin Höglinger-Stelzer')
O23 - Driver S3: spacedesk Android Control Service - (spacedeskDriverAndroidControl) - C:\WINDOWS\System32\drivers\spacedeskDriverAndroidControl.sys (sign: 'Datronicsoft Inc.')
O23 - Driver S3: spacedesk Android USB Device Service - (spacedeskAndroidUsb) - C:\WINDOWS\System32\drivers\spacedeskDriverAndroidUsb.sys (sign: 'Datronicsoft Inc.')
O23 - Driver S3: spacedesk virtual Bus - (spacedeskDriverBus) - C:\WINDOWS\System32\drivers\spacedeskDriverBus.sys (sign: 'Datronicsoft Inc.')
O23 - Driver S3: spacedeskKtmInputMouse Service - (spacedeskKtmInputMouse) - C:\WINDOWS\System32\drivers\spacedeskKtmInputMouse.sys (sign: 'Datronicsoft Inc.')
O23 - Driver S3: Virtual Gamepad Emulation Service - (ViGEmBus) - C:\WINDOWS\System32\drivers\ViGEmBus.sys (sign: 'Microsoft' - Benjamin Höglinger-Stelzer)
O23 - Driver S3: VirtualBox USB - (VBoxUSB) - C:\WINDOWS\System32\Drivers\VBoxUSB.sys (+safe mode) (sign: 'Oracle Corporation')
O23 - Driver S3: vJoy Device - (vjoy) - C:\WINDOWS\System32\drivers\vjoy.sys (sign: 'On-site Dental Systems (Justin Shafer)')
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service:  'klim6'
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service:  'kltun'
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service:  'klwtp'
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service:  'Netwtw10'


--
End of file - Time spent: 7,3 sec. - 91010 bytes, CRC32: FFFFFFFF. Sign: 넛랔
 
Konu için yardım almak için sizlere danışıyorum.
RocketDock çok gerekli değilse kaldıırn bu, bu tür sorunlara neden olabilir. Güncel sürüm varsa gerekliyse onu yükleyip deneyin.

Bunları fixleyin:
Kod:
O4 - HKCU\..\Run: [CCleaner Smart Cleaning] = C:\Program Files\CCleaner\CCleaner64.exe /MONITOR (sign: 'Gen Digital Inc.')
O4 - HKCU\..\Run: [RocketDock] = C:\Program Files (x86)\RocketDock\RocketDock.exe (not signed - no company - 521E9198E3DC1D41FAC02EB01FB9F47F6D2A9855)
O4 - HKCU\..\RunOnce: [Application Restart #0] = C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe --component-updater=url-source=hxxps://go-updater.brave.com/extensions --disable-domain-reliability --enable-distillability-service --enable-dom-distiller --lso-url=hxxps://no-thanks.invalid --origin-trial-public-key=bYUKPJoPnCxeNvu72j4EmPuK7tr1PAC7SHh8ld9Mw3E=,fMS4mpO6buLQ/QMd+zJmxzty/VQ6B1EUZqoCU04zoRU= --sync-url=hxxps://sync-v2.brave.com/v2 --variations-insecure-server-url=hxxps://variations.brave.com/seed --variations-server-url=hxxps://variations.brave.com/seed --restore-last-session --restart (sign: 'Brave Software, Inc.')
O4 - HKCU\..\StartupApproved\Run: [Epic Privacy Browser Installer] = C:\Users\Alkandras\AppData\Local\Epic Privacy Browser\Installer\EpicUpdate.exe /c (sign: 'Google Inc (TEST)', but untrusted root: 'Google Inc (TEST)' with fingerprint: 471DE9EEBF4AF31E2FF65B1C3A3272DB999E9509)
O4 - HKCU\..\StartupApproved\Run: [MicrosoftEdgeAutoLaunch_5594F3D88385289021792D3510255E96] = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --no-startup-window --win-session-start (sign: 'Microsoft')
O4 - HKCU\..\StartupApproved\Run: [OneDrive] = C:\Program Files\Microsoft OneDrive\OneDrive.exe /background (sign: 'Microsoft')
O4 - HKLM\..\StartupApproved\StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\SOLIDWORKS 2022 Hızlı Başlangıç.lnk -> C:\Windows\Installer\{26EA0056-4BAD-4F9E-BDCE-A72E25C7D06D}\NewShortcut2_87EDF6C81D0A4B7B84F42FE0C6A9D608.exe (2023/05/13) (not signed - Flexera - B9FC8844AF011C56310B304FCBDE46FF67B90BC8)
O4 - Startup: C:\Users\Alkandras\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DeepL auto-start.lnk -> C:\Users\Alkandras\AppData\Roaming\0install.net\desktop-integration\stubs\1eae01f3cdb5ff0ecf683b15a60a1489573c1188cb34abc205fcf7a924b4e54d\auto-start.exe (not signed - no company - FE3ABCDC59CD077ECF316CDDBA14D0B95C240951)
O22 - BITS Job: (download) {01E616F7-F2F8-4447-93C4-FF371A6BF682} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/128.0/update/win64/tr/firefox-127.0.2-128.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {17D886DC-D2A7-44CD-8A73-6EE3E3C549C6} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0/update/win64/tr/firefox-125.0.3-126.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {220BF640-880A-47E7-8B6B-0B6DEE20E243} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.1/update/win64/tr/firefox-127.0-127.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {3EE1D5C8-83BE-4FFF-A571-54AF68E5174F} - hxxp://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ad3rm3ciqs3fjr4bc4x5vwuildeq_9.49.1/gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3 -> C:\Users\ALKAND~1\AppData\Local\Temp\chrome_BITS_3908_394102754\gcmjkmgdlgnkkcocmoeiminaijmmjnii_9.49.1_all_ixzyrcu7pvmgu5pjv6enfqq6wa.crx3
O22 - BITS Job: (download) {52FDA215-D725-4276-B4A1-D888693BDF9A} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0/update/win64/tr/firefox-126.0.1-127.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {56533264-27B7-4152-B2F9-8D22F43154D6} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {5A170B56-55D2-4E08-8C09-0D57DE7663A8} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/128.0.2/update/win64/tr/firefox-128.0-128.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {88BDE918-77F9-4E95-A686-C4B85A1921BF} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0/update/win64/tr/firefox-126.0.1-127.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {BD7BBF33-0DA6-4D1A-B300-2A039F4D0A47} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {D46B717C-88B1-428D-B3FF-1ED9A9ECE215} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/127.0.2/update/win64/tr/firefox-127.0.1-127.0.2.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {DDAC7313-8555-474C-98B3-99989FA43519} - hxxp://edgedl.me.gvt1.com/edgedl/release2/chrome_component/adrnpn4oqndirc4e4znryad25caa_2024.7.25.0/niikhdgajlphfehepabhhblakbdgeefj_2024.07.25.00_all_ac77hp7ujdfagzpwcjuouk7ix2wa.crx3 -> C:\Users\ALKAND~1\AppData\Local\Temp\chrome_BITS_16016_1063282233\niikhdgajlphfehepabhhblakbdgeefj_2024.07.25.00_all_ac77hp7ujdfagzpwcjuouk7ix2wa.crx3
O22 - BITS Job: (download) {E6C0A3B0-FE96-4A96-8FF9-AE041844951F} - hxxps://download.mozilla.org/?product=firefox-127.0.1-partial-127.0&os=win64&lang=tr -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {EFDC91A7-C9F6-49D8-82AE-7B63FC7F9B37} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0/update/win64/tr/firefox-125.0.3-126.0.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
O22 - BITS Job: (download) {FFD11E3E-74B3-46C8-AFE9-0C397C3073D1} - hxxps://download-installer.cdn.mozilla.net/pub/firefox/releases/126.0.1/update/win64/tr/firefox-126.0-126.0.1.partial.mar -> C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\updates\downloading\update.mar
Ekran kartı sürücülerinizi de kontrol edin güncelleyin.

Zararlı şüphesi
Bunları fixleyin:
Kod:
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\Program Files (x86)\Lenovo\VantageService\
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\USERS\ARESK\APPDATA\LOCAL\MALWAREBYTES
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\USERS\ARESK\APPDATA\LOCAL\MALWAREBYTES\Logs
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\USERS\ARESK\APPDATA\LOCAL\MALWAREBYTES\Logs\MBAMSI.alt2.lock
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\USERS\ARESK\APPDATA\LOCAL\MALWAREBYTES\Logs\MBAMSI.alt2.log
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\USERS\ARESK\APPDATA\LOCAL\MALWAREBYTES\Logs\MBAMSI.lock
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\USERS\ARESK\APPDATA\LOCAL\MALWAREBYTES\Logs\MBAMSI.log
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\WINDOWS\TEMP\e950e1024f2411efb73f088fc3cb536d.tmp
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\WINDOWS\TEMP\e95191064f2411efb2c0088fc3cb536d.tmp
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\WINDOWS\TEMP\e96453224f2411ef9ecc088fc3cb536d.tmp
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\WINDOWS\TEMP\e96558d04f2411ef9846088fc3cb536d.tmp
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\WINDOWS\TEMP\e9b5231a4f2411ef8f19088fc3cb536d.tmp
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = (no file) -> C:\WINDOWS\TEMP\e9b5e6d84f2411efa05b088fc3cb536d.tmp
Sistemde zararlı görünmüyor.
C:\WINDOWS\System32\drivers\vjoy.sys
VT upload edip kontrol edin zararsız ise kalabilir.

Mcafee tam kaldırılmamış kaldırma aracıyla kaldırın.
 
Son düzenleme:
@Murat5038

Yeniden Hijackthis taraması yapınca O22 BITSJOB ile başlayan sorunlar çıkmadığı için bunlar hariç diğerlerini fixledim. Fixlediğim kodlarda zararlı bir durum var mıydı ?

RocketDock çok elzem değil fakat bu programı uzun süredir kullanıyorum. Sorunum yeni başladı. Hijackthis fixlemelerini yaparken programı revo uninstaller ile sildiğimde de problemim devam edince tekrar yükledim.

Sorunun cevabını beklerden sürücü driverını önce yeniden yükledim sonra bir önceki sürümü yükledim değişen bir şey olmayınca güncel sürümü tekrar yükledim.

Bu arada Malwarebytes ile tam taramada yaptım. Zararlı bulmadı.

Sorunum devam ediyor. Deneyebileceğim başka bir şey var mı acaba ?
 

Technopat Haberler

Yeni konular

Geri
Yukarı