Çözüldü Hijack this sonuçları

Bu konu çözüldü olarak işaretlenmiştir. Çözülmediğini düşünüyorsanız konuyu rapor edebilirsiniz.

Awdiki

Kilopat
Katılım
27 Ağustos 2018
Mesajlar
1.318
Çözümler
4
Son zamanlarda bilgisayarımda ara sıra performans düşüşleri gördüm, ardından arkadan gülme sesleri geldiğini fark ettim. Malwarebytes ve zemana ile tarattığımda ciddi bir sorun yok gibi gözüküyordu. Paylaştığım raporu değerlendirirseniz sevinirim.

Kod:
Logfile of HiJackThis Fork by Alex Dragokas v.2.9.0.26.

Platform: x64 Windows 10 (Home Single Language), 10.0.19041.546 (ReleaseId: 2004), Service Pack: 0.
Time: 12.10.2020 - 19:42 (UTC+03:00)
Language: OS: English (0x409). Display: English (0x409). Non-Unicode: English (0x409)
Elevated: Yes.
Ran by: salaw (group: Administrator) on DESKTOP-H6HPOA5, FirstRun: yes.

Chrome: 85.0.4183.121.
Edge: 11.0.19041.546.
Internet Explorer: 11.508.19041.0.
Default: "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --single-argument %1 (Microsoft Edge)

Boot mode: Normal.

Running processes:
Number | Path.
1 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe.
1 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksde.exe.
1 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksdeui.exe.
1 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.1\avp.exe.
1 C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.1\avpui.exe.
1 C:\Program Files (x86)\Origin\Origin.exe.
1 C:\Program Files (x86)\Origin\OriginWebHelperService.exe.
2 C:\Program Files (x86)\Origin\QtWebEngineProcess.exe.
1 C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe.
1 C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe.
1 C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe.
1 C:\Program Files\AMD\CNext\CNext\amdow.exe.
1 C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe.
1 C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe.
1 C:\Program Files\Riot Vanguard\vgtray.exe.
1 C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_2.2009.23741.0_x64__8wekyb3d8bbwe\Cortana.exe.
1 C:\Program Files\WindowsApps\Microsoft.WindowsStore_12009.1001.1.0_x64__8wekyb3d8bbwe\WinStore.App.exe.
5 C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.143.700.0_x86__zpdnekdrzrea0\Spotify.exe.
1 C:\Users\salaw\AppData\Local\Microsoft\OneDrive\OneDrive.exe.
8 C:\Users\salaw\AppData\Local\Programs\Blitz\Blitz.exe.
1 C:\Users\salaw\Downloads\HiJackThis.exe.
1 C:\Users\salaw\Downloads\ISLC v1.0.2.2\Intelligent standby list cleaner ISLC.exe.
1 C:\Windows\ImmersiveControlPanel\SystemSettings.exe.
1 C:\Windows\System32\ApplicationFrameHost.exe.
1 C:\Windows\System32\DriverStore\FileRepository\u0359518.inf_amd64_ddc5c961c2795261\B359297\atieclxx.exe.
1 C:\Windows\System32\DriverStore\FileRepository\u0359518.inf_amd64_ddc5c961c2795261\B359297\atiesrxx.exe.
2 C:\Windows\System32\RtkAudUService64.exe.
7 C:\Windows\System32\RuntimeBroker.exe.
1 C:\Windows\System32\SearchFilterHost.exe.
1 C:\Windows\System32\SearchIndexer.exe.
1 C:\Windows\System32\SearchProtocolHost.exe.
1 C:\Windows\System32\SecurityHealthService.exe.
1 C:\Windows\System32\SecurityHealthSystray.exe.
1 C:\Windows\System32\SettingSyncHost.exe.
1 C:\Windows\System32\SgrmBroker.exe.
1 C:\Windows\System32\Speech_OneCore\common\SpeechRuntime.exe.
1 C:\Windows\System32\WUDFHost.exe.
1 C:\Windows\System32\amdfendrsr.exe.
1 C:\Windows\System32\audiodg.exe.
2 C:\Windows\System32\csrss.exe.
1 C:\Windows\System32\ctfmon.exe.
1 C:\Windows\System32\dwm.exe.
2 C:\Windows\System32\fontdrvhost.exe.
1 C:\Windows\System32\lsass.exe.
1 C:\Windows\System32\rundll32.exe.
1 C:\Windows\System32\services.exe.
1 C:\Windows\System32\sihost.exe.
1 C:\Windows\System32\smartscreen.exe.
1 C:\Windows\System32\smss.exe.
1 C:\Windows\System32\spoolsv.exe.
76 C:\Windows\System32\svchost.exe.
1 C:\Windows\System32\taskhostw.exe.
2 C:\Windows\System32\wbem\WmiPrvSE.exe.
1 C:\Windows\System32\wininit.exe.
1 C:\Windows\System32\winlogon.exe.
1 C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe.
1 C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe.
1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe.
1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe.
1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe.
1 C:\Windows\explorer.exe.

O2 - HKLM\..\BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\86.0.622.38\BHO\ie_to_edge_bho_64.dll.
O2-32 - HKLM\..\BHO: IEToEdge BHO - {1FD49718-1D00-4B19-AF5F-070AF6D5D54C} - C:\Program Files (x86)\Microsoft\Edge\Application\86.0.622.38\BHO\ie_to_edge_bho.dll.
O4 - HKCU\..\Run: [EADM] = C:\Program Files (x86)\Origin\Origin.exe -AutoStart.
O4 - HKCU\..\Run: [OneDrive] = C:\Users\salaw\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background (Microsoft)
O4 - HKCU\..\Run: [Opera Browser Assistant] = C:\Users\salaw\AppData\Local\Programs\Opera\assistant\browser_assistant.exe.
O4 - HKCU\..\Run: [com.blitz.app] = C:\Users\salaw\AppData\Local\Programs\Blitz\Blitz.exe --autostart.
O4 - HKCU\..\StartupApproved\Run: [Discord] = C:\Users\salaw\AppData\Local\Discord\app-0.0.308\Discord.exe (2020/09/24)
O4 - HKCU\..\StartupApproved\Run: [EpicGamesLauncher] = C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe -silent (2020/10/10)
O4 - HKLM\..\Run: [Riot Vanguard] = C:\Program Files\Riot Vanguard\vgtray.exe.
O4 - HKLM\..\Run: [RtkAudUService] = C:\Windows\System32\RtkAudUService64.exe -background.
O17 - DHCP DNS 1: 8.8.8.8 (Well-known DNS: Google)
O17 - DHCP DNS 2: 8.8.4.4 (Well-known DNS: Google)
O17 - HKLM\System\CCS\Services\Tcpip\..\{c21cbaf8-09c3-42ca-9980-962cc67fa994}: [NameServer] = 8.8.4.4 (Well-known DNS: Google)
O17 - HKLM\System\CCS\Services\Tcpip\..\{c21cbaf8-09c3-42ca-9980-962cc67fa994}: [NameServer] = 8.8.8.8 (Well-known DNS: Google)
O22 - Task (.job): (disabled) (Not scheduled) CreateExplorerShellUnelevatedTask.job - C:\Windows\explorer.exe /NOUACCHECK.
O22 - Task: (disabled) (update) \Microsoft\Windows\UpdateOrchestrator\Reboot_AC - C:\Windows\system32\MusNotification.exe /RunOnAC RebootDialog (Microsoft)
O22 - Task: (disabled) (update) \Microsoft\Windows\UpdateOrchestrator\Reboot_Battery - C:\Windows\system32\MusNotification.exe /RunOnBattery RebootDialog (Microsoft)
O22 - Task: (disabled) \Agent Activation Runtime\S-1-5-21-27572408-228825954-269492004-1001 - C:\Windows\System32\AgentActivationRuntimeStarter.exe.
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\Windows\system32\ProvTool.exe /turn 5 /source ProvRetryTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\Windows\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\Windows\system32\usoclient.exe StartMaintenanceWork (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work - C:\Windows\system32\usoclient.exe StartWork (Microsoft)
O22 - Task: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\Windows\system32\rundll32.exe C:\Windows\system32\PcaSvc.dll,PcaPatchSdbTask (Microsoft)
O22 - Task: (update) \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker - C:\Windows\system32\MusNotification.exe (Microsoft)
O22 - Task: AMDInstallLauncher - C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe /InstallAUEP.
O22 - Task: AMDLinkUpdate - C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe -AMDLinkUpdate.
O22 - Task: AMHelper - C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe /UPDATE.
O22 - Task: AMSkipUAC - C:\Program Files (x86)\Zemana\AntiMalware\AntiMalware.exe /SKIPUAC.
O22 - Task: Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe.
O22 - Task: GoogleUpdateTaskMachineCore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c.
O22 - Task: GoogleUpdateTaskMachineUA - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler.
O22 - Task: Intelligent StandbyList Cleaner - C:\Users\salaw\Downloads\ISLC v1.0.2.2\Intelligent standby list cleaner ISLC.exe.
O22 - Task: Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} - C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe /waitUpgrade.
O22 - Task: MSIAfterburner - C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe /s (file missing)
O22 - Task: ModifyLinkUpdate - C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe -UpdateCurrentUser.
O22 - Task: Opera scheduled Autoupdate 1600690727 - C:\Users\salaw\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0)
O22 - Task: Opera scheduled assistant Autoupdate 1600690729 - C:\Users\salaw\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\salaw\AppData\Local\Programs\Opera\assistant" $(Arg0)
O22 - Task: StartCN - C:\Program Files\AMD\CNext\CNext\cncmd.exe startwithdelay.
O22 - Task: StartDVR - C:\Program Files\AMD\CNext\CNext\RSServCmd.exe.
O22 - Task: \Microsoft\Windows\SMB\UninstallSMB1ClientTask - C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\Windows\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client"
O22 - Task: \Microsoft\Windows\SMB\UninstallSMB1ServerTask - C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\Windows\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server"
O22 - Task: \WiseCleaner\WRCSkipUAC - C:\Program Files (x86)\Wise\Wise Registry Cleaner\WiseRegCleaner.exe $UAC.
O23 - Service R2: AMD Crash Defender Service - C:\Windows\system32\amdfendrsr.exe.
O23 - Service R2: AMD External Events Utility - C:\Windows\System32\DriverStore\FileRepository\u0359518.inf_amd64_ddc5c961c2795261\B359297\atiesrxx.exe.
O23 - Service R2: Adobe Acrobat Update Service - (AdobeARMservice) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe.
O23 - Service R2: Kaspersky Anti-Virus Hizmeti 21.1 - (AVP21.1) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.1\avp.exe -r.
O23 - Service R2: Kaspersky Secure Connection Hizmeti 5.1 - (KSDE5.1) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 5.1\ksde.exe -r.
O23 - Service R2: Malwarebytes Service - (MBAMService) - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe.
O23 - Service R2: Origin Web Helper Service - C:\Program Files (x86)\Origin\OriginWebHelperService.exe.
O23 - Service R2: Realtek Audio Universal Service - (RtkAudioUniversalService) - C:\Windows\System32\RtkAudUService64.exe.
O23 - Service S2: Google Update Service (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc.
O23 - Service S3: EasyAntiCheat - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe.
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService) - (GoogleChromeElevationService) - C:\Program Files\Google\Chrome\Application\85.0.4183.121\elevation_service.exe.
O23 - Service S3: Google Update Service (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc.
O23 - Service S3: Kaspersky Volume Shadow Copy Service Bridge 21.1 - (klvssbridge64_21.1) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Cloud 21.1\x64\vssbridge64.exe.
O23 - Service S3: Origin Client Service - C:\Program Files (x86)\Origin\OriginClientService.exe.
O23 - Service S3: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\SteamService.exe /RunAsService.
O23 - Service S3: vgc - C:\Program Files\Riot Vanguard\vgc.exe.

--
End of file - Time spent: 7.4 sec. - 23796 bytes, CRC32: FFFFFFFF. Sign: 
 
Çözüm
Pyton olmasının nedeni Anaconda yazılımını kullanmanız. Bir sürü bana göre gereksiz yazılım vardı o bilgisayar sorun olması yüksek zaten.
Zararlı kaynaklı değil gördüğüm kadarıyla açık olan yazılımlardan birinden olabilir. Çok fazla güvenlik yazılımı var sadece Kaspersky ve MBAM kalacak şekilde kaldır.
Programlama yazılımlarından kullanmadıklarını kaldır.

Bu klasör içinde girip saçma klasörler var bunları sil:
C:\Users\salaw\

Gizli klasör ve korunan dosyaları açmayı unutma.

Bu klasör içini de temizle:
C:\Users\salaw\AppData\Local\Temp
 
Zararlı kaynaklı değil gördüğüm kadarıyla açık olan yazılımlardan birinden olabilir. Çok fazla güvenlik yazılımı var sadece Kaspersky ve MBAM kalacak şekilde kaldır.
Programlama yazılımlarından kullanmadıklarını kaldır.

Bu klasör içinde girip saçma klasörler var bunları sil:
C:\Users\salaw\

Gizli klasör ve korunan dosyaları açmayı unutma.

Bu klasör içini de temizle:
C:\Users\salaw\appdata\local\temp.

Öncellikle yanıtınız için teşekkür ederim. Sizlere raporları göndermeden önce MBAM ile taratığımda 2 tane trojan.Script Python bulmuştu, sanırım bundan kaynaklıydı. Benim anlamadığım arkada KIS aktif olarak çalışıyordu ve hiçbir sorun göstermedi, ayrıca yeni fark ettim ki Chrome'a girdiğimde kişiler kısmındaki isimim böyleydi.
 

Dosya Ekleri

  • Untitled.png
    Untitled.png
    8,1 KB · Görüntüleme: 86

Yeni konular

Geri
Yukarı