Bilgisayarda işlemler engelleniyor

TéQ10

Kilopat
Katılım
11 Ağustos 2017
Mesajlar
1.535
Çözümler
5
Bilgisayarımda ESET kullanıyordum, şimdi ESET'i Sosyal'dekilerin önerisiyle sileceğim. MalvareBytes'a geçeceğim. Ama ESET'i ve MalvareBytes'ın korumasını kapatsam bile bir şey uygulamaların çalışmasını engelliyor. Bu büyük ihtimalle antivirüs uygulamasıyla alakalı değil. Bu büyük ihtimalle virüs ve bunu MalvareBytes ve ESET derin tarama sonucu bulamıyorlar. Bu sorunu nasıl çözebilirim?
Not: ESET'i biraz önce sildim hala ESET çalışıyor hatası alıyorum.

Tencent Gaming Buddy, Minecraft gibi uygulamalar güncelleme yapamıyor, Windows güvenlik duvarı açılmıyor, tarayıcılar gereğinden fazla RAM kullanıyor.
Not 2: Bilgisayarımda Miner yok.
Bu arada bir rapor gerekiyor mu?
 
Çözüm
Merhaba,

Dün size cevap yazamadım forum yöneticilerinin lüzumsuz Türkçe uygulamaları nedeni ile. Bu nedenle, bu konuda işim bittikten sonra artık forumdan tamamen ayrılıyorum.

Loglarınızı inceledim. Yapılması gereken çok iş var. İzin ve erişim sorunlarınız, kaldırılması gereken yazılımlar, halen sisteminizde bulunan antivirüs kalıntıları falan. Benimle bunları çözmeye hala istekli iseniz, adım adım ilerleyebilmek için aşağıda verdiğim işlemleri yapın. Yoksa yukarıda yazdığım gibi.

Task: {81769E9B-F0AB-48D6-B832-559185A6990A} - System32\Tasks\AdwCleaner_onReboot => C:\Users\lamer\AppData\Local\Temp\scoped_dir7704_28056\AdwCleaner.exe [2018-09-16] (Malwarebytes) <==== ATTENTION
UmmyVideoDownloader (HKLM-x32\...\{E028DBDA-EEE7-48A0-ADF7-D250589A02C5}_is1) (Version: 1.8.3.3 - ) <==== ATTENTION
UmmyVideoDownloader ve Adwcleaner yazılımlarını kaldırın. UmmyVideoDownloader yazılımını RevoUninstaller Free ile kaldırmanızı öneririm.

RevoUninstaller yazılımını açmışken alttaki yazılımları da kaldırmanızı öneririm. Bu yazılımları hiç kullanmamanız en iyisidir. Bu sadece bir öneridir ve kaldırmayacaksanız yazın bileyim. Çünkü, kaldırmamız gereken birçok bilgi satırı var. Onlarla beraber bu yazılımlara ait bilgileri de eklemem gerekecek listeye.

Wise Registry Cleaner
Wise Game Booster
Wise Memory Optimizer
IObit Uninstaller 8 (IObit klasörünü tamamen)

================================================================
C:\Users\lamer\Downloads\CReaTive_HacKs.rar
C:\Users\lamer\NTUSER.rhk
C:\Users\lamer\Desktop\cpppckaiebkfps.exe

Bunlar hakkında bilginiz var mı?
-----------------------------------------------------------------------------

Windows Defender:
===================================
Date: 2018-08-21 16:12:41.625
Description:
Windows Defender Virüsten Koruma kötü amaçlı yazılım veya başka bir istenmeyebilecek yazılım algıladı.
Daha fazla bilgi için lütfen aşağıya bakın:
Trojan:Win32/Tiggre!rfn threat description - Windows Defender Security Intelligence
Ad: Trojan:Win32/Tiggre!rfn
Kimlik: 2147723625
Önem Derecesi: Ciddi
Kategori: Truva Atı
Yol: file:_C:\Users\lamer\AppData\Local\Temp\Rar$EXa0.455\Steam Code Generator 2018.exe; process:_pid:8292,ProcessStart:131793305823454899
Algılama Başlangıç Noktası: Yerel makine
Algılama Türü: Somut
Algılama Kaynağı: Sistem
Kullanıcı: NT AUTHORITY\SYSTEM
İşlem Adı: C:\Users\lamer\AppData\Local\Temp\Rar$EXa0.455\Steam Code Generator 2018.exe
İmza Sürümü: AV: 1.273.1749.0, AS: 1.273.1749.0, NIS: 1.273.1749.0
Altyapı Sürümü: AM: 1.1.15100.1, NIS: 1.1.15100.1

Date: 2018-08-21 16:10:08.156
Description:
Windows Defender Virüsten Koruma kötü amaçlı yazılım veya başka bir istenmeyebilecek yazılım algıladı.
Daha fazla bilgi için lütfen aşağıya bakın:
Trojan:Win32/Tiggre!rfn threat description - Windows Defender Security Intelligence
Ad: Trojan:Win32/Tiggre!rfn
Kimlik: 2147723625
Önem Derecesi: Ciddi
Kategori: Truva Atı
Yol: file:_C:\Users\lamer\AppData\Local\Temp\Rar$EXa0.455\Steam Code Generator 2018.exe
Yukarıdaki bulgu için, Kasperky yazılımını durdurun. Defender ile tam tarama yaparak bulunanları silin.

Yukarıdaki yaptığınız işlem adımları ile ilgili beni de bilgilendirin. Sonra diğer işlemlere geçelim.
Merhaba,

Dün size cevap yazamadım forum yöneticilerinin lüzumsuz Türkçe uygulamaları nedeni ile. Bu nedenle, bu konuda işim bittikten sonra artık forumdan tamamen ayrılıyorum.

Loglarınızı inceledim. Yapılması gereken çok iş var. İzin ve erişim sorunlarınız, kaldırılması gereken yazılımlar, halen sisteminizde bulunan antivirüs kalıntıları falan. Benimle bunları çözmeye hala istekli iseniz, adım adım ilerleyebilmek için aşağıda verdiğim işlemleri yapın. Yoksa yukarıda yazdığım gibi.

Task: {81769E9B-F0AB-48D6-B832-559185A6990A} - System32\Tasks\AdwCleaner_onReboot => C:\Users\lamer\AppData\Local\Temp\scoped_dir7704_28056\AdwCleaner.exe [2018-09-16] (Malwarebytes) <==== ATTENTION
UmmyVideoDownloader (HKLM-x32\...\{E028DBDA-EEE7-48A0-ADF7-D250589A02C5}_is1) (Version: 1.8.3.3 - ) <==== ATTENTION
UmmyVideoDownloader ve Adwcleaner yazılımlarını kaldırın. UmmyVideoDownloader yazılımını RevoUninstaller Free ile kaldırmanızı öneririm.

RevoUninstaller yazılımını açmışken alttaki yazılımları da kaldırmanızı öneririm. Bu yazılımları hiç kullanmamanız en iyisidir. Bu sadece bir öneridir ve kaldırmayacaksanız yazın bileyim. Çünkü, kaldırmamız gereken birçok bilgi satırı var. Onlarla beraber bu yazılımlara ait bilgileri de eklemem gerekecek listeye.

Wise Registry Cleaner
Wise Game Booster
Wise Memory Optimizer
IObit Uninstaller 8 (IObit klasörünü tamamen)

================================================================
C:\Users\lamer\Downloads\CReaTive_HacKs.rar
C:\Users\lamer\NTUSER.rhk
C:\Users\lamer\Desktop\cpppckaiebkfps.exe

Bunlar hakkında bilginiz var mı?
-----------------------------------------------------------------------------

Windows Defender:
===================================
Date: 2018-08-21 16:12:41.625
Description:
Windows Defender Virüsten Koruma kötü amaçlı yazılım veya başka bir istenmeyebilecek yazılım algıladı.
Daha fazla bilgi için lütfen aşağıya bakın:
Trojan:Win32/Tiggre!rfn threat description - Windows Defender Security Intelligence
Ad: Trojan:Win32/Tiggre!rfn
Kimlik: 2147723625
Önem Derecesi: Ciddi
Kategori: Truva Atı
Yol: file:_C:\Users\lamer\AppData\Local\Temp\Rar$EXa0.455\Steam Code Generator 2018.exe; process:_pid:8292,ProcessStart:131793305823454899
Algılama Başlangıç Noktası: Yerel makine
Algılama Türü: Somut
Algılama Kaynağı: Sistem
Kullanıcı: NT AUTHORITY\SYSTEM
İşlem Adı: C:\Users\lamer\AppData\Local\Temp\Rar$EXa0.455\Steam Code Generator 2018.exe
İmza Sürümü: AV: 1.273.1749.0, AS: 1.273.1749.0, NIS: 1.273.1749.0
Altyapı Sürümü: AM: 1.1.15100.1, NIS: 1.1.15100.1

Date: 2018-08-21 16:10:08.156
Description:
Windows Defender Virüsten Koruma kötü amaçlı yazılım veya başka bir istenmeyebilecek yazılım algıladı.
Daha fazla bilgi için lütfen aşağıya bakın:
Trojan:Win32/Tiggre!rfn threat description - Windows Defender Security Intelligence
Ad: Trojan:Win32/Tiggre!rfn
Kimlik: 2147723625
Önem Derecesi: Ciddi
Kategori: Truva Atı
Yol: file:_C:\Users\lamer\AppData\Local\Temp\Rar$EXa0.455\Steam Code Generator 2018.exe
Yukarıdaki bulgu için, Kasperky yazılımını durdurun. Defender ile tam tarama yaparak bulunanları silin.

Yukarıdaki yaptığınız işlem adımları ile ilgili beni de bilgilendirin. Sonra diğer işlemlere geçelim.
 
Çözüm
@Boztepe o 2 uygulama oyun hile uygulamaları ama ntuser'i bilmiyorum. Hileleri Sadece denemiştim ve silmeyi unutmuştum :D
Tarama yapmama gerek yok çünkü zaten yakın bir zamanda temp dosyalarını silmiştim.
Bu arada bütün işlemleri yaptım.
 
Hepsini kaldırdım. Devam etmek istiyorum.
C:\Users\lamer\NTUSER.rhk ---->> Wise yazılımlarınızdan kaynaklanıyor.
-----------------------------------------------------------------------------------

Aşağıdaki işlemi yapalım;

Tüm aktif güvenlik yazılımlarınızı kapatın.
Masaüstünde bir not defteri açın. Aşağıdaki bağlantıdaki bilgileri kopyalayıp yapıştırın.
Paste ofCode
Dosya adı:Fixlist,
Dosya türü:Tüm dosyalar

olarak kaydedin. Farbar yazılımı ve Fixlist dosyası masaüstünde olmalı kısaca.
Sadece bir defa FİX butonuna basıp işlemin bitmesini bekleyin. Sistem yeniden başlatılabilir.
Masaüstünde oluşan Fixlog dosyasını paylaşın.
Bir sorun varsa yazın. İşlemlerimiz bu kadar.
 
@Boztepe
Kod:
Fix result of Farbar Recovery Scan Tool (x64) Version: 18-10-2017 01
Ran by lamer (17-09-2018 17:16:36) Run:2
Running from C:\Users\lamer\Desktop
Loaded Profiles: lamer (Available Profiles: lamer)
Boot Mode: Normal
==============================================

fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
(Malwarebytes) C:\Users\lamer\AppData\Local\Temp\scoped_dir7704_28056\AdwCleaner.exe
(WiseCleaner.com) C:\Users\lamer\Desktop\Wise Registry Cleaner\WiseRegCleaner.exe
C:\Users\lamer\Desktop\JRT.exe
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1315265887-1540288157-3388349337-1001\...\Policies\Explorer: [NoLowDiskSpaceChecks] 1
ShellExecuteHooks-x32: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll -> No File
GroupPolicy: Restriction ? <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR NewTab: Default ->  Not-active:"chrome-extension://ecfnoapfedndbghojfaillliflooafkp/newtab.html"
OPR Extension: (Avira Browser Safety) - C:\Users\lamer\AppData\Roaming\Opera Software\Opera Stable\Extensions\dalelnnofafalcmkmnhdbigbjjkloabo [2018-09-02]
S3 ESETCleanersDriver; C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys [181160 2018-08-05] (ESET)
S3 xhunter1; C:\WINDOWS\xhunter1.sys [1 2018-09-12] ()
R1 SMR521; C:\WINDOWS\System32\drivers\SMR521.SYS
C:\WINDOWS\KMSAutoS
C:\WINDOWS\system32\Drivers\SMR521.dat
C:\WINDOWS\system32\Drivers\SMR521.SYS
C:\Users\lamer\AppData\Local\NPE
C:\ProgramData\Norton
C:\Users\lamer\Desktop\NPE.exe
C:\Users\lamer\Desktop\Zemana.AntiMalware.Setup.exe
C:\ProgramData\ProductData
UmmyVideoDownloader (HKLM-x32\...\{E028DBDA-EEE7-48A0-ADF7-D250589A02C5}_is1) (Version: 1.8.3.3 - ) <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-1315265887-1540288157-3388349337-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-7B735D5D84EA}\InprocServer32 -> %%systemroot%%\system32\shell32.dll => No File
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers-x32-x32: [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll -> No File
ShellIconOverlayIdentifiers-x32-x32-x32: [Groove Explorer Icon Overlay 2 (GFS Stub)] -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll -> No File
ShellIconOverlayIdentifiers-x32-x32-x32-x32: [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll -> No File
ShellIconOverlayIdentifiers-x32-x32-x32-x32-x32: [Groove Explorer Icon Overlay 3 (GFS Folder)] -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll -> No File
ShellIconOverlayIdentifiers-x32-x32-x32-x32-x32-x32: [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll -> No File
ContextMenuHandlers2: [ESET Security Shell] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Smart Security\shellExt.dll -> No File
ContextMenuHandlers2: [LockHunterShellExt] -> [CC]{0BB27CDA-7029-4C0E-9C56-D922B229F0EB} =>  -> No File
ContextMenuHandlers3: [GB3ContextMenu] -> [CC]{3A488FE8-9916-4F36-BDFF-3DED559142E5} =>  -> No File
ContextMenuHandlers3-x32: [XXX Groove GFS Context Menu Handler XXX] -> {6C467336-8281-4E60-8204-430CED96822D} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll -> No File
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
Task: {2AD0C8C6-5115-4DB2-8A58-630A0923A090} - System32\Tasks\KMSAuto => C:\Windows\KMSAutoS\KMSAuto x64.exe [2018-01-07] ()
Task: {81769E9B-F0AB-48D6-B832-559185A6990A} - System32\Tasks\AdwCleaner_onReboot => C:\Users\lamer\AppData\Local\Temp\scoped_dir7704_28056\AdwCleaner.exe [2018-09-16] (Malwarebytes) <==== ATTENTION
AlternateDataStreams: C:\ProgramData\Application Data:NT [40]
AlternateDataStreams: C:\ProgramData\Application Data:NT2 [660]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT [40]
AlternateDataStreams: C:\ProgramData\MTA San Andreas All:NT2 [660]
AlternateDataStreams: C:\Users\lamer\Application Data:NT [40]
AlternateDataStreams: C:\Users\lamer\Application Data:NT2 [660]
AlternateDataStreams: C:\Users\lamer\AppData\Roaming:NT [40]
AlternateDataStreams: C:\Users\lamer\AppData\Roaming:NT2 [660]
AlternateDataStreams: C:\Users\Public\AppData:CSM [476]
AlternateDataStreams: C:\Users\Public\Shared Files:VersionCache [482]
MSCONFIG\Services: McAfee SiteAdvisor Service => 3
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\McAfee SiteAdvisor Service" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services" /F
HKLM\...\StartupApproved\Run: => "AvastUI.exe"
C:\Users\lamer\Desktop\Wise Registry Cleaner
C:\Users\lamer\AppData\Roaming\Wise Euask
C:\Users\lamer\Downloads\WRCFree.zip
C:\WINDOWS\System32\Tasks\AdwCleaner_onReboot
C:\Users\lamer\Desktop\CReaTive_HacKs
C:\Users\lamer\Downloads\CReaTive_HacKs.rar
C:\Users\lamer\Desktop\CReaTive_HacKs.rar
HKU\S-1-5-21-1315265887-1540288157-3388349337-1001\...\StartupApproved\Run: => "CCleaner Monitoring"
Task: {661D8F68-4906-4B14-8A00-354B7838AE81} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe [2018-06-03] ()
Task: {3F76F4E6-4022-4A0E-9760-19643D8BDC60} - System32\Tasks\Uninstaller_SkipUac_lamer => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2018-08-08] (IObit)
ContextMenuHandlers6: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2018-07-21] (IObit)
ContextMenuHandlers4: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2018-07-21] (IObit)
ContextMenuHandlers1: [IObitUnstaler] -> {836AB26C-2DE4-41D3-AC24-4C6C2699B960} => C:\Program Files (x86)\IObit\IObit Uninstaller\IUMenuRight.dll [2018-07-21] (IObit)
SearchScopes: HKU\S-1-5-21-1315265887-1540288157-3388349337-1001 -> DefaultScope {8C3078A0-9AAB-4371-85D1-656CA8E46EE8} URL = hxxps://yandex.com.tr/search/?text={searchTerms}&clid=2233630
SearchScopes: HKU\S-1-5-21-1315265887-1540288157-3388349337-1001 -> {8C3078A0-9AAB-4371-85D1-656CA8E46EE8} URL = hxxps://yandex.com.tr/search/?text={searchTerms}&clid=2233630
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2018-07-19] (IObit)
S2 IObitUnSvr; C:\Program Files (x86)\IObit\IObit Uninstaller\IUService.exe [149776 2018-06-28] (IObit)
R3 IUProcessFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IUProcessFilter.sys [37184 2018-05-12] (IObit)
R3 IURegistryFilter; C:\Program Files (x86)\IObit\IObit Uninstaller\drivers\win10_amd64\IURegistryFilter.sys [43392 2018-05-15] (IObit)
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset C:\resettcpip.txt
CMD: Bitsadmin /Reset /Allusers
Hosts:
EMPTYTEMP:
Reboot:
End::

*****************

Restore point was successfully created.
Processes closed successfully.
C:\Users\lamer\AppData\Local\Temp\scoped_dir7704_28056\AdwCleaner.exe => No running process found
C:\Users\lamer\Desktop\Wise Registry Cleaner\WiseRegCleaner.exe => No running process found
"C:\Users\lamer\Desktop\JRT.exe" => not found.
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender => key removed successfully
HKU\S-1-5-21-1315265887-1540288157-3388349337-1001\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoLowDiskSpaceChecks => value removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\explorer\ShellExecuteHooks\\{B5A7F190-DDA6-4420-B3BA-52453494E6CD} => value removed successfully
HKLM\SOFTWARE\WOW6432Node\Classes\CLSID\{B5A7F190-DDA6-4420-B3BA-52453494E6CD} => key removed successfully
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Policies\Google => key removed successfully
Chrome NewTab => removed successfully
C:\Users\lamer\AppData\Roaming\Opera Software\Opera Stable\Extensions\dalelnnofafalcmkmnhdbigbjjkloabo => moved successfully
HKLM\System\CurrentControlSet\Services\ESETCleanersDriver => key removed successfully
ESETCleanersDriver => service removed successfully
HKLM\System\CurrentControlSet\Services\xhunter1 => key removed successfully
xhunter1 => service removed successfully
SMR521 => service not found.
C:\WINDOWS\KMSAutoS => moved successfully
"C:\WINDOWS\system32\Drivers\SMR521.dat" => not found.
"C:\WINDOWS\system32\Drivers\SMR521.SYS" => not found.
C:\Users\lamer\AppData\Local\NPE => moved successfully
C:\ProgramData\Norton => moved successfully
"C:\Users\lamer\Desktop\NPE.exe" => not found.
"C:\Users\lamer\Desktop\Zemana.AntiMalware.Setup.exe" => not found.
C:\ProgramData\ProductData => moved successfully
UmmyVideoDownloader (HKLM-x32\...\{E028DBDA-EEE7-48A0-ADF7-D250589A02C5}_is1) (Version: 1.8.3.3 - ) <==== ATTENTION => Error: No automatic fix found for this entry.
HKU\S-1-5-21-1315265887-1540288157-3388349337-1001_Classes\CLSID\{0E270DAA-1BE6-48F2-AC49-7B735D5D84EA} => key removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\00asw => key removed successfully
HKLM\Software\Classes\CLSID\{472083B0-C522-11CF-8763-00608CC02F24} => key not found.
ShellIconOverlayIdentifiers-x32-x32: [Groove Explorer Icon Overlay 1 (GFS Unread Stub)] -> {99FD978C-D287-4F50-827F-B2C658EDA8E7} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll -> No File => Error: No automatic fix found for this entry.
ShellIconOverlayIdentifiers-x32-x32-x32: [Groove Explorer Icon Overlay 2 (GFS Stub)] -> {AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll -> No File => Error: No automatic fix found for this entry.
ShellIconOverlayIdentifiers-x32-x32-x32-x32: [Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)] -> {920E6DB1-9907-4370-B3A0-BAFC03D81399} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll -> No File => Error: No automatic fix found for this entry.
ShellIconOverlayIdentifiers-x32-x32-x32-x32-x32: [Groove Explorer Icon Overlay 3 (GFS Folder)] -> {16F3DD56-1AF5-4347-846D-7C10C4192619} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll -> No File => Error: No automatic fix found for this entry.
ShellIconOverlayIdentifiers-x32-x32-x32-x32-x32-x32: [Groove Explorer Icon Overlay 4 (GFS Unread Mark)] -> {2916C86E-86A6-43FE-8112-43ABE6BF8DCC} => C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll -> No File => Error: No automatic fix found for this entry.
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\ESET Security Shell => key removed successfully
HKLM\Software\Classes\CLSID\{B089FE88-FB52-11D3-BDF1-0050DA34150D} => key removed successfully
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\LockHunterShellExt => key removed successfully
HKLM\Software\Classes\CLSID\[CC]{0BB27CDA-7029-4C0E-9C56-D922B229F0EB} => key not found.
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\GB3ContextMenu => key removed successfully
HKLM\Software\Classes\CLSID\[CC]{3A488FE8-9916-4F36-BDFF-3DED559142E5} => key not found.
HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers\XXX Groove GFS Context Menu Handler XXX => key removed successfully
HKLM\Software\Wow6432Node\Classes\CLSID\{6C467336-8281-4E60-8204-430CED96822D} => key removed successfully
HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers\igfxcui => key removed successfully
HKLM\Software\Classes\CLSID\{3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => key not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{2AD0C8C6-5115-4DB2-8A58-630A0923A090} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2AD0C8C6-5115-4DB2-8A58-630A0923A090} => key removed successfully
C:\WINDOWS\System32\Tasks\KMSAuto => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\KMSAuto => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{81769E9B-F0AB-48D6-B832-559185A6990A} => key not found.
C:\WINDOWS\System32\Tasks\AdwCleaner_onReboot => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\AdwCleaner_onReboot => key not found.
C:\ProgramData\Application Data => ":NT" ADS removed successfully.
C:\ProgramData\Application Data => ":NT2" ADS removed successfully.
C:\ProgramData\MTA San Andreas All => ":NT" ADS removed successfully.
C:\ProgramData\MTA San Andreas All => ":NT2" ADS removed successfully.
C:\Users\lamer\Application Data => ":NT" ADS removed successfully.
C:\Users\lamer\Application Data => ":NT2" ADS removed successfully.
"C:\Users\lamer\AppData\Roaming" => ":NT" ADS not found.
"C:\Users\lamer\AppData\Roaming" => ":NT2" ADS not found.
C:\Users\Public\AppData => ":CSM" ADS removed successfully.
C:\Users\Public\Shared Files => ":VersionCache" ADS removed successfully.
HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\Services\McAfee SiteAdvisor Service => key removed successfully
HKLM\System\CurrentControlSet\Services\McAfee SiteAdvisor Service => key not found.

========= Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services\McAfee SiteAdvisor Service" /F =========

ERROR: The system was unable to find the specified registry key or value.


========= End of Reg: =========


========= Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\services" /F =========

˜Ÿlem baŸaryla tamamland.



========= End of Reg: =========

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\AvastUI.exe => value removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\AvastUI.exe => value not found.
C:\Users\lamer\Desktop\Wise Registry Cleaner => moved successfully
C:\Users\lamer\AppData\Roaming\Wise Euask => moved successfully
C:\Users\lamer\Downloads\WRCFree.zip => moved successfully
"C:\WINDOWS\System32\Tasks\AdwCleaner_onReboot" => not found.
C:\Users\lamer\Desktop\CReaTive_HacKs => moved successfully
"C:\Users\lamer\Downloads\CReaTive_HacKs.rar" => not found.
C:\Users\lamer\Desktop\CReaTive_HacKs.rar => moved successfully
HKU\S-1-5-21-1315265887-1540288157-3388349337-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\CCleaner Monitoring => value removed successfully
HKU\S-1-5-21-1315265887-1540288157-3388349337-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\CCleaner Monitoring => value not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{661D8F68-4906-4B14-8A00-354B7838AE81} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{661D8F68-4906-4B14-8A00-354B7838AE81} => key removed successfully
C:\WINDOWS\System32\Tasks\Game_Booster_AutoUpdate => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Game_Booster_AutoUpdate => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3F76F4E6-4022-4A0E-9760-19643D8BDC60} => key not found.
C:\WINDOWS\System32\Tasks\Uninstaller_SkipUac_lamer => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_lamer => key not found.
HKLM\Software\Classes\Folder\ShellEx\ContextMenuHandlers\IObitUnstaler => key removed successfully
HKLM\Software\Classes\CLSID\{836AB26C-2DE4-41D3-AC24-4C6C2699B960} => key removed successfully
HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers\IObitUnstaler => key removed successfully
HKLM\Software\Classes\CLSID\{836AB26C-2DE4-41D3-AC24-4C6C2699B960} => key not found.
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\IObitUnstaler => key removed successfully
HKLM\Software\Classes\CLSID\{836AB26C-2DE4-41D3-AC24-4C6C2699B960} => key not found.
HKU\S-1-5-21-1315265887-1540288157-3388349337-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-21-1315265887-1540288157-3388349337-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8} => key removed successfully
HKLM\Software\Classes\CLSID\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8} => key not found.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814} => key removed successfully
HKLM\Software\Classes\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814} => key removed successfully
IObitUnSvr => service not found.
IUProcessFilter => service not found.
IURegistryFilter => service not found.
"C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Uninstaller.lnk" => not found.

========= netsh advfirewall reset =========

Ok.


========= End of CMD: =========


========= netsh advfirewall set allprofiles state ON =========

Ok.


========= End of CMD: =========


========= ipconfig /flushdns =========


Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========


========= netsh winsock reset catalog =========


Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.


========= End of CMD: =========


========= netsh int ip reset C:\resettcpip.txt =========

Resetting Compartment Forwarding, OK!
Resetting Compartment, OK!
Resetting Control Protocol, OK!
Resetting Echo Sequence Request, OK!
Resetting Global, OK!
Resetting Interface, OK!
Resetting Anycast Address, OK!
Resetting Multicast Address, OK!
Resetting Unicast Address, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting Potential, OK!
Resetting Prefix Policy, OK!
Resetting Proxy Neighbor, OK!
Resetting Route, OK!
Resetting Site Prefix, OK!
Resetting Subinterface, OK!
Resetting Wakeup Pattern, OK!
Resetting Resolve Neighbor, OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , failed.
EriŸim engellendi.

Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Resetting , OK!
Restart the computer to complete this action.


========= End of CMD: =========


========= Bitsadmin /Reset /Allusers =========


BITSADMIN version 3.0
BITS administration utility.
(C) Copyright Microsoft Corp.

0 out of 0 jobs canceled.

========= End of CMD: =========

C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
End:: => Error: No automatic fix found for this entry.

=========== EmptyTemp: ==========

BITS transfer queue => 10248192 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 40972649 B
Java, Flash, Steam htmlcache => 14088474 B
Windows/system/drivers => 10321668 B
Edge => 11065941 B
Chrome => 328063883 B
Firefox => 0 B
Opera => 72622889 B

Temp, IE cache, history, cookies, recent:
Default => 6656 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 51052 B
LocalService => 0 B
NetworkService => 6656 B
NetworkService => 0 B
lamer => 169811661 B

RecycleBin => 98547910 B
EmptyTemp: => 720.8 MB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 17:19:10 ====
 
Uyarı! Bu konu 6 yıl önce açıldı.
Muhtemelen daha fazla tartışma gerekli değildir ki bu durumda yeni bir konu başlatmayı öneririz. Eğer yine de cevabınızın gerekli olduğunu düşünüyorsanız buna rağmen cevap verebilirsiniz.

Yeni konular

Geri
Yukarı