Logfile of HiJackThis Fork by Alex Dragokas v.2.9.0.18
Platform: x64 Windows 10 (Pro), 10.0.17763.437 (ReleaseId: 1809), Service Pack: 0
Time: 18.04.2019 - 17:25 (UTC+03:00)
Language: OS: Turkish (0x41F). Display: Turkish (0x41F). Non-Unicode: Turkish (0x41F)
Elevated: Yes
Ran by: Anıl YÖNDEMLİ (group: Administrator) on DESKTOP-JIKIQKA, FirstRun: yes
Chrome: 73.0.3683.103
Edge: 11.0.17763.437
Internet Explorer: 11.0.17763.1
Default: "C:\Users\Anıl YÖNDEMLİ\AppData\Local\Programs\Opera\Launcher.exe" -noautoupdate -- "%1" (Opera Internet Browser)
Boot mode: Normal
Running processes:
Number | Path
1 C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
1 C:\Program Files (x86)\Wondershare\WAF\2.4.3.242\WsAppService.exe
1 C:\Program Files\AMD\CNext\CNext\RadeonSettings.exe
1 C:\Program Files\MobiGame\MobiGameUpdater.exe
1 C:\Program Files\MobiGame\aeg_launcher.exe
1 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
1 C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
1 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
1 C:\Program Files\WindowsApps\Microsoft.WindowsStore_11811.1001.27.0_x64__8wekyb3d8bbwe\WinStore.App.exe
1 C:\Program Files\WindowsApps\Microsoft.YourPhone_1.19031.57.0_x64__8wekyb3d8bbwe\YourPhone.exe
1 C:\Users\Anıl YÖNDEMLİ\Desktop\HiJackThis.exe
1 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
1 C:\Windows\SysWOW64\PnkBstrA.exe
1 C:\Windows\System32\ApplicationFrameHost.exe
1 C:\Windows\System32\DriverStore\FileRepository\c0339878.inf_amd64_a1916e56c42a5365\B339766\atiesrxx.exe
1 C:\Windows\System32\MusNotification.exe
5 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SearchFilterHost.exe
1 C:\Windows\System32\SearchIndexer.exe
1 C:\Windows\System32\SearchProtocolHost.exe
1 C:\Windows\System32\SettingSyncHost.exe
1 C:\Windows\System32\SgrmBroker.exe
1 C:\Windows\System32\audiodg.exe
1 C:\Windows\System32\conhost.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\igfxCUIService.exe
1 C:\Windows\System32\igfxEM.exe
1 C:\Windows\System32\igfxHK.exe
1 C:\Windows\System32\lsass.exe
1 C:\Windows\System32\schtasks.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smss.exe
67 C:\Windows\System32\svchost.exe
1 C:\Windows\System32\taskhostw.exe
1 C:\Windows\System32\wbem\WmiPrvSE.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
1 C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
1 C:\Windows\explorer.exe
1 D:\Program Files\Microvirt\MEmu\MemuService.exe
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{67C334C0-408D-4E6D-B5A7-0ADD6AFFA252}: [SuggestionsURL] = http://clients5.google.com/complete/search?q={searchTerms}&client=ie8&mw={ie:maxWidth}&sh={ie:sectionHeight}&rh={ie:rowHeight}&inputencoding={inputEncoding}&outputencoding={outputEncoding} - Google
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{67C334C0-408D-4E6D-B5A7-0ADD6AFFA252}: [URL] = http://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?} - Google
O2 - HKLM\..\BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_201\bin\jp2ssv.dll
O2 - HKLM\..\BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_201\bin\ssv.dll
O2-32 - HKLM\..\BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKCU\..\StartupApproved\Run: [Bloody2] = C:\Program Files (x86)\Bloody6\Bloody6\Bloody6.exe Minimum (2019/04/14)
O4 - HKCU\..\StartupApproved\Run: [DAEMON Tools Lite Automount] = C:\Program Files\DAEMON Tools Lite\DTAgent.exe -autorun (2019/04/14)
O4 - HKCU\..\StartupApproved\Run: [Discord] = C:\Users\Anıl YÖNDEMLİ\AppData\Local\Discord\app-0.0.305\Discord.exe (2019/03/14)
O4 - HKCU\..\StartupApproved\Run: [EpicGamesLauncher] = C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe -silent (2019/03/14)
O4 - HKCU\..\StartupApproved\Run: [GoogleChromeAutoLaunch_5226F1E3D6F341F50A31E555A6C4465D] = C:\Program Files (x86)\Google\Chrome\Application\chrome.exe --no-startup-window /prefetch:5 (2019/02/25)
O4 - HKCU\..\StartupApproved\Run: [OneDrive] = C:\Users\Anıl YÖNDEMLİ\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background (2019/02/25)
O4 - HKCU\..\StartupApproved\Run: [Steam] = C:\Program Files (x86)\Steam\steam.exe -silent (2019/03/14)
O4 - HKCU\..\StartupApproved\Run: [uTorrent] = C:\Users\Anıl YÖNDEMLİ\AppData\Roaming\uTorrent\uTorrent.exe (2019/04/14)
O4 - HKCU\..\StartupApproved\StartupFolder: C:\Users\Anıl YÖNDEMLİ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe (2019/03/14)
O4 - HKLM\..\StartupApproved\Run32: [Adobe ARM] = C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (2019/02/25)
O4 - HKLM\..\StartupApproved\Run32: [Adobe Reader Speed Launcher] = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe (2019/02/25)
O4 - HKLM\..\StartupApproved\Run32: [SunJavaUpdateSched] = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (2019/03/07)
O4 - HKLM\..\StartupApproved\Run: [Play Store] = C:\Program Files\MobiGame\player\mobiplayer.exe --light-PS "C:\Users\Anıl YÖNDEMLİ\AppData\Local\MobiGame\playstore.json" --emulatorId "464B527DCB35465F8A6B79E53AD88302" --installId "B0154BD58C2C45499245CBD4A3F0851E" (2019/04/05)
O4 - HKLM\..\StartupApproved\Run: [SecurityHealth] = C:\WINDOWS\system32\SecurityHealthSystray.exe (2019/02/25)
O17 - DHCP DNS 1: 97.64.179.251
O17 - DHCP DNS 2: 202.155.46.77
O17 - HKLM\System\CCS\Services\Tcpip\..\{2414b7c4-e1e0-462b-a332-85fc8ec0cb05}: [NameServer] = 202.155.46.77
O17 - HKLM\System\CCS\Services\Tcpip\..\{2414b7c4-e1e0-462b-a332-85fc8ec0cb05}: [NameServer] = 97.64.179.251
O17 - HKLM\System\CCS\Services\Tcpip\..\{c74fbcdd-7aaf-49cc-b616-4bbe1d20dbed}: [NameServer] = 1.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{c74fbcdd-7aaf-49cc-b616-4bbe1d20dbed}: [NameServer] = 1.1.1.1
O23 - Service R2: AMD External Events Utility - C:\WINDOWS\System32\DriverStore\FileRepository\c0339878.inf_amd64_a1916e56c42a5365\B339766\atiesrxx.exe
O23 - Service R2: AegLauncher - C:\Program Files\MobiGame\aeg_launcher.exe
O23 - Service R2: CodeMeter Runtime Server - (CodeMeter.exe) - C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe
O23 - Service R2: Intel(R) HD Graphics Control Panel Service - (igfxCUIService2.0.0.0) - C:\WINDOWS\system32\igfxCUIService.exe
O23 - Service R2: MEmuSVC - D:\Program Files\Microvirt\MEmu\MemuService.exe
O23 - Service R2: MobiGameUpdater - C:\Program Files\MobiGame\MobiGameUpdater.exe
O23 - Service R2: PnkBstrA - C:\WINDOWS\system32\PnkBstrA.exe (file missing)
O23 - Service R2: SynTPEnh Caller Service - (SynTPEnhService) - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
O23 - Service R2: Wondershare Application Framework Service - (WsAppService) - C:\Program Files (x86)\Wondershare\WAF\2.4.3.242\WsAppService.exe
O23 - Service S2: Google Güncelleme Hizmeti (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc
O23 - Service S3: Disc Soft Lite Bus Service - C:\Program Files\DAEMON Tools Lite\DiscSoftBusServiceLite.exe
O23 - Service S3: Google Chrome Elevation Service - (GoogleChromeElevationService) - C:\Program Files (x86)\Google\Chrome\Application\73.0.3683.103\elevation_service.exe
O23 - Service S3: Google Güncelleme Hizmeti (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc
O23 - Service S3: Intel(R) Content Protection HECI Service - (cphs) - C:\WINDOWS\SysWow64\IntelCpHeciSvc.exe
O23 - Service S3: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\SteamService.exe /RunAsService
--
End of file - Time spent: 41,5 sec. - 17130 bytes, CRC32: FFFFFFFF. Sign: ẜ林