HiJack This sonuçlarım

esadomer

Hectopat
Katılım
20 Nisan 2019
Mesajlar
640
Çözümler
3
[CODE title="HiJackThis"]Logfile of HiJackThis Fork by Alex Dragokas v.2.10.0.13

Platform: x64 Windows 10 (Pro), 10.0.19043.1348 (ReleaseId: 2009, 21H1), Service Pack: 0
Time: 11.12.2021 - 22:59 (UTC+03:00)
Language: OS: Turkish (0x41F). Display: Turkish (0x41F). Non-Unicode: Turkish (0x41F)
Elevated: Yes
Ran by: user (group: Administrators) on DESKTOP-****, FirstRun: yes

Chrome: 96.0.4664.93
Internet Explorer: 11.0.19041.1202
Default: "C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --single-argument %1 (Brave)

Boot mode: Normal

Running processes:
Number | Path
1 C:\Program Files (x86)\BraveSoftware\Update\1.3.361.111\BraveCrashHandler.exe
1 C:\Program Files (x86)\BraveSoftware\Update\1.3.361.111\BraveCrashHandler64.exe
1 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
1 C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
1 C:\Program Files (x86)\GlassWire\GlassWire.exe
1 C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
1 C:\Program Files (x86)\GlassWire\GWIdlMon.exe
1 C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler.exe
1 C:\Program Files (x86)\Google\Update\1.3.36.112\GoogleCrashHandler64.exe
1 C:\Program Files (x86)\Gyazo\GyStation.exe
1 C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
1 C:\Program Files (x86)\LogMeIn Hamachi\x64\hamachi-2.exe
1 C:\Program Files (x86)\LogMeIn Hamachi\x64\LMIGuardianSvc.exe
1 C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
1 C:\Program Files (x86)\Origin\OriginWebHelperService.exe
7 C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
1 C:\Program Files (x86)\Steam\steam.exe
1 C:\Program Files (x86)\Steam\steamapps\common\wallpaper_engine\wallpaper32.exe
1 C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
1 C:\Program Files (x86)\VPN Unlimited\vpn-unlimited-daemon.exe
29 C:\Program Files\BraveSoftware\Brave-Browser\Application\brave.exe
1 C:\Program Files\Electronic Arts\EA Desktop\EA Desktop\EABackgroundService.exe
1 C:\Program Files\LGHUB\lghub_updater.exe
1 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
1 C:\Program Files\NordVPN\nordvpn-service.exe
3 C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
3 C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA Share.exe
1 C:\Program Files\NVIDIA Corporation\ShadowPlay\nvsphelper64.exe
1 C:\Program Files\Riot Vanguard\vgc.exe
1 C:\Program Files\SteelSeries\GG\moments\SteelSeriesSvcLauncher.exe
1 C:\Program Files\SteelSeries\GG\SteelSeriesEngine.exe
1 C:\Program Files\SteelSeries\GG\SteelSeriesGG.exe
1 C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2110.13603.0_x64__8wekyb3d8bbwe\Cortana.exe
1 C:\Program Files\WindowsApps\Microsoft.549981C3F5F10_3.2110.13603.0_x64__8wekyb3d8bbwe\Win32Bridge.Server.exe
1 C:\Program Files\WindowsApps\Microsoft.GamingServices_3.59.11001.0_x64__8wekyb3d8bbwe\gamingservices.exe
1 C:\Program Files\WindowsApps\Microsoft.GamingServices_3.59.11001.0_x64__8wekyb3d8bbwe\gamingservicesnet.exe
1 C:\Program Files\WindowsApps\Microsoft.YourPhone_1.21111.120.0_x64__8wekyb3d8bbwe\YourPhone.exe
6 C:\Program Files\WindowsApps\SpotifyAB.SpotifyMusic_1.173.517.0_x86__zpdnekdrzrea0\Spotify.exe
1 C:\ProgramData\Autodesk\Genuine Service\x64\GenuineService.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\MsMpEng.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2110.6-0\NisSrv.exe
6 C:\Users\user\AppData\Local\Plarium\PlariumPlay\6.8.1-0.0.1\PlariumPlay.exe
1 C:\Users\user\AppData\Local\Plarium\PlariumPlay\6.8.1-0.0.1\PlariumPlayClientService\PlariumPlayClientService.exe
1 C:\Users\user\AppData\Local\Plarium\PlariumPlay\6.8.1-0.0.1\PlariumPlayInfo.exe
1 C:\Users\user\Desktop\HiJackThis.exe
1 C:\Windows\explorer.exe
1 C:\Windows\IMF\Runtime Explorer.exe
1 C:\Windows\IMF\Secure System Shell.exe
1 C:\Windows\IMF\Windows Services.exe
1 C:\Windows\System32\audiodg.exe
2 C:\Windows\System32\backgroundTaskHost.exe
3 C:\Windows\System32\conhost.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
1 C:\Windows\System32\dasHost.exe
2 C:\Windows\System32\dllhost.exe
2 C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_642e50d7b66aa2a4\Display.NvContainer\NVDisplay.Container.exe
2 C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_01042bb7f11c17c4\RtkAudUService64.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\lsass.exe
1 C:\Windows\System32\rundll32.exe
7 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SearchFilterHost.exe
1 C:\Windows\System32\SearchIndexer.exe
1 C:\Windows\System32\SearchProtocolHost.exe
1 C:\Windows\System32\SecurityHealthService.exe
1 C:\Windows\System32\SecurityHealthSystray.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\SettingSyncHost.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smartscreen.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\SpaceAgent.exe
1 C:\Windows\System32\spaceman.exe
1 C:\Windows\System32\spoolsv.exe
1 C:\Windows\System32\sppsvc.exe
86 C:\Windows\System32\svchost.exe
1 C:\Windows\System32\taskhostw.exe
3 C:\Windows\System32\wbem\WmiPrvSE.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\System32\WpcMon.exe
1 C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\InputApp\TextInputHost.exe
1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
1 D:\Program Files\TxGameAssistant\AppMarket\AppMarket.exe
3 D:\Program Files\TxGameAssistant\AppMarket\cef_frame_render.exe
1 D:\Program Files\TxGameAssistant\AppMarket\DL\syzs_dl_svr.exe
1 D:\Program Files\TxGameAssistant\AppMarket\QMEmulatorService.exe

R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8}: [SuggestionsURL_JSON] = https://suggest.yandex.com.tr/suggest-ff.cgi?srv=ie11&uil=tr&part={searchTerms}&clid=2233630 - Yandex
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8}: = https://yandex.com.tr/search/?te... FFFFFFFF. Sign: ??[/CODE] Sonuçlarım bunlar.
 
Şunları fixleyin:

C:\Windows\IMF\Runtime Explorer.exe
C:\Windows\IMF\Secure System Shell.exe
C:\Windows\IMF\Windows Services.exe
O4 - HKCU\..\Run: [Runtime Explorer] = C:\Windows\IMF\\Windows Services.exe
O4 - Startup: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Startup.lnk -> C:\Windows\IMF\Windows Services.exe

Yönetici powershell'inde şu komutu çalıştırın:

Remove-MpPreference -ExclusionPath C:\Windows\IMF\

Şunları kurup tam tarama gerçekleştirin.

 

Geri
Yukarı