LogFile of HijackThis+ (Plus) Build 2024-04-18 Alpha v.3.4.0.9
Platform: X64 Windows 10 (Home), 10.0.19045.4842 (releaseıd: 2009, 22H2), service pack: 0
Time: 09.09.2024 - 02:19 (utc+03:00)
Language: OS: Turkish (0x41F). Display: Turkish (0x41F). Non-unicode: Turkish (0x41F)
Memory: 14908 mib Free. Loading RAM (10 %), CPU (1 %)
Elevated: Yes.
Ran by: Ted (group: Administrators; type: Local) on desktop-dpd91nr, firstrun: Yes.
Internet Explorer: 11.0.19041.4355
Default: "C:\program Files\BraveSoftware\Brave-Browser\Application\brave.exe" --Single-argument %1 (Brave)
Boot mode: Normal (Secure Boot: Off)
Running processes:
Number | path.
1 C:\program Files\AMD\CNext\CNext\cncmd.exe
1 C:\program Files\Realtek\Audio\HDA\RtkNGUI64.exe
1 C:\Users\ted\Desktop\HiJackThis.exe
1 C:\Windows\explorer.exe
1 C:\Windows\servicing\TrustedInstaller.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
1 C:\Windows\System32\DriverStore\FileRepository\u0395510.inf_amd64_266bc083bb7590df\B395348\atieclxx.exe
1 C:\Windows\System32\DriverStore\FileRepository\u0395510.inf_amd64_266bc083bb7590df\B395348\atiesrxx.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\lsass.exe
1 C:\Windows\System32\MoUsoCoreWorker.exe
1 C:\Windows\System32\rundll32.exe
1 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\SgrmBroker.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smss.exe
20 C:\Windows\System32\svchost.exe
1 C:\Windows\System32\taskhostw.exe
1 C:\Windows\System32\userinit.exe
1 C:\Windows\System32\wbem\WMIADAP.exe
1 C:\Windows\System32\wbem\WmiPrvSE.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
1 C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.4840_none_7de2e3147cada334\TiWorker.exe
O2 - HKLM\..\BHO: ıetoedge bho - {1FD49718-1D00-4B19-AF5F-070 AF6D5D54C} - C:\program files (x86)\Microsoft\Edge\Application\128.0.2739.63\BHO\ie_to_edge_bho_64.dll (file missing)
O4 - activesetup: HKLM\..\{9459C573-B17A-45AE-9F64-1857B5D58CEE}: [StubPath] = "C:\program files (x86)\Microsoft\Edge\Application\128.0.2739.63\Installer\setup.exe" --configure-user-settings --verbose-logging --System-level --msedge --channel = stable (file missing)
O4 - activesetup: HKLM\..\{AFE6A462-C574-4B8A-AF43-4CC60DF4563B}: [StubPath] = C:\program Files\BraveSoftware\Brave-Browser\Application\128.1.69.162\Installer\chrmstp.exe --configure-user-settings --verbose-logging --System-level (sign: 'Brave software, ınc.')
O4 - HKCU\..\StartupApproved\Run: [Discord] = C:\Users\ted\AppData\Local\Discord\Update.exe --processstart Discord.exe (2024/09/06) (sign: 'Discord ınc.')
O4 - HKCU\..\StartupApproved\Run: [Snap Camera] = C:\program Files\Snap Inc\Snap Camera\Snap Camera.exe --minimized-mode (2024/09/07) (invalid sign: Trust_e_bad_dıgest - snap ınc - A7109E2Ab38BD69299E3F7e8C049C8085CD45618)
O4 - HKLM\..\Run: [RTHDVCPL] = C:\program Files\Realtek\Audio\HDA\RtkNGUI64.exe -s (sign: 'Realtek semiconductor corp')
O5 - applet: C:\Windows\System32\RTSnMg64.cpl (sign: 'Realtek semiconductor corp')
O7 - policy: (UAC) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System: [ConsentPromptBehaviorAdmin] = 0
O7 - policy: (UAC) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System: [PromptOnSecureDesktop] = 0
O7 - policy: HKCU\..\Windows\Explorer: [DisableSearchBoxSuggestions] = 1
O7 - policy: HKLM\..\Windows\Explorer: [DisableSearchBoxSuggestions] = 1
O7 - policy: HKLM\Software\Microsoft\Windows Defender\Features: [TamperProtection] = 4
O7 - policy: HKLM\Software\Microsoft\Windows Defender\Real-Time protection: [DisableRealtimeMonitoring] = 1
O7 - policy: HKLM\Software\Policies\Microsoft\Windows Defender: [DisableAntiSpyware] = 1
O7 - policy: HKLM\Software\Policies\Microsoft\Windows Defender: [DisableAntiVirus] = 1
O17 - DHCP DNS 1: 8.8.8.8 (well-known DNS: Google)
O17 - DHCP DNS 2: 8.8.4.4 (well-known DNS: Google)
O17 - HKLM\System\CCS\Services\Tcpip\..\{b9c34cce-626b-4d0e-ac7d-5a6b16f70f71}: [NameServer] = 8.8.4.4 (well-known DNS: Google)
O17 - HKLM\System\CCS\Services\Tcpip\..\{b9c34cce-626b-4d0e-ac7d-5a6b16f70f71}: [NameServer] = 8.8.8.8 (well-known DNS: Google)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive1: (no name) - {bbacc218-34EA-4666-9D7A-C78F2274A524} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive2: (no name) - {5AB7172C-9C11-405C-8DD5-AF20F3606282} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive3: (no name) - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive4: (no name) - {F241C880-6982-4CE5-8CF7-7085BA96da5a} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive5: (no name) - {A0396A93-DC06-4AEF-BEE9-95ffccaef20e} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive6: (no name) - {9AA2F32D-362a-42D9-9328-24A483E2CCC3} - (no file)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive7: (no name) - {C5FF006E-2AE9-408C-B85b-2dfDD5449D9C} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive1: (no name) - {bbacc218-34EA-4666-9D7A-C78F2274A524} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive2: (no name) - {5AB7172C-9C11-405C-8DD5-AF20F3606282} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive3: (no name) - {A78ED123-AB77-406B-9962-2A5D9D2F7F30} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive4: (no name) - {F241C880-6982-4CE5-8CF7-7085BA96da5a} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive5: (no name) - {A0396A93-DC06-4AEF-BEE9-95ffccaef20e} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive6: (no name) - {9AA2F32D-362a-42D9-9328-24A483E2CCC3} - (no file)
O21-32 - HKLM\..\ShellIconOverlayIdentifiers\ OneDrive7: (no name) - {C5FF006E-2AE9-408C-B85b-2dfDD5449D9C} - (no file)
O22 - task (.job): (not scheduled) Yandex browser güncellemesi. Job - C:\Users\ted\AppData\Local\Yandex\YandexBrowser\Application\browser.exe (file missing)
O22 - task (.job): (not scheduled) Yandex browser sistem güncellemesi. Job - C:\program files (x86)\Yandex\YandexBrowser\24.7.2.1100\service_update.exe (sign: 'Yandex llc')
O22 - task (.job): (not scheduled) Yandex browser güncelleme servisinin geri yüklenmesi. Job - C:\program files (x86)\Yandex\YandexBrowser\24.7.2.1100\service_update.exe (sign: 'Yandex llc')
O22 - tasks: (disabled) (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\Windows\system32\rundll32.exe C:\Windows\system32\PcaSvc.dll,PcaPatchSdbTask (sign: 'Microsoft')
O22 - tasks: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62b2DD2C-F129-42EE-BF59-55D3FD21C215},detecthardwarechange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - tasks: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62b2DD2C-F129-42EE-BF59-55D3FD21C215},remediatehardwarechange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - tasks: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\Windows\system32\ProvTool.exe /turn 5 /source provretrytask (sign: 'Microsoft')
O22 - tasks: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\Windows\system32\ProvTool.exe /turn 5 /source continuesessiontask (sign: 'Microsoft')
O22 - tasks: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule maintenance work - C:\Windows\system32\usoclient.exe startmaintenancework (sign: 'Microsoft')
O22 - tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:aeinv.dll -F: Updatesoftwareınventoryw invsvc (sign: 'Microsoft')
O22 - tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:aemarebackup.dll -F: Backupmaredata (sign: 'Microsoft')
O22 - tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:appraiser.dll -F: Doscheduledtelemetryrun (sign: 'Microsoft')
O22 - tasks: \Microsoft\Windows\SMB\UninstallSMB1ClientTask - C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -executionpolicy unrestricted -nonınteractive -noprofile -windowstyle hidden "& C:\Windows\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -scenario Client" (sign: ")
O22 - tasks: \Microsoft\Windows\SMB\UninstallSMB1ServerTask - C:\Windows\system32\WindowsPowerShell\v1.0\powershell.exe -executionpolicy unrestricted -nonınteractive -noprofile -windowstyle hidden "& C:\Windows\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -scenario server" (sign: ")
O22 - tasks: Amdınstalllauncher - C:\program Files\AMD\CIM\Bin64\InstallManagerApp.exe /ınstallauep (sign: 'Advanced Micro devices ınc.')
O22 - tasks: Amdlinkupdate - C:\program Files\AMD\CIM\Bin64\InstallManagerApp.exe -amdlinkupdate (sign: 'Advanced Micro devices ınc.')
O22 - tasks: Amdryzenmastersdktask - C:\program Files\AMD\CNext\CNext\cpumetricsserver.exe (sign: 'Advanced Micro devices ınc.')
O22 - tasks: Bravesoftwareupdatetaskmachinecore{AA5AA6C3-B055-4ECB-A3D4-ffadEE2705AC} - C:\program files (x86)\BraveSoftware\Update\BraveUpdate.exe /c (sign: 'Brave software, ınc.')
O22 - tasks: Bravesoftwareupdatetaskmachineua{a2CB8EE1-99C7-4F05-A4C2-51236A50eed5} - C:\program files (x86)\BraveSoftware\Update\BraveUpdate.exe /ua /installsource scheduler (sign: 'Brave software, ınc.')
O22 - tasks: Eosv3 scheduler onlogon - C:\Users\ted\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe logon (sign: 'ESET, spol. S r. O.')
O22 - tasks: Eosv3 scheduler ONT'ime - C:\Users\ted\AppData\Local\ESET\ESETOnlineScanner\ESETOnlineScanner.exe sched (sign: 'ESET, spol. S r. O.')
O22 - tasks: Microsoftedgeupdatetaskmachinecore - C:\program files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /c (file missing)
O22 - tasks: Microsoftedgeupdatetaskmachineua - C:\program files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /ua /installsource scheduler (file missing)
O22 - tasks: Modifylinkupdate - C:\program Files\AMD\CIM\Bin64\InstallManagerApp.exe -updatecurrentuser (sign: 'Advanced Micro devices ınc.')
O22 - tasks: Startcn - C:\program Files\AMD\CNext\CNext\cncmd.exe startwithdelay (sign: 'Advanced Micro devices ınc.')
O22 - tasks: Startdvr - C:\program Files\AMD\CNext\CNext\RSServCmd.exe (sign: 'Advanced Micro devices ınc.')
O22 - tasks: Yandex browser güncellemesi - C:\Users\ted\AppData\Local\Yandex\YandexBrowser\Application\browser.exe --background-Update --noerrdialogs (file missing)
O22 - tasks: Yandex browser sistem güncellemesi - C:\program files (x86)\Yandex\YandexBrowser\24.7.2.1100\service_update.exe --run-as-Launcher (sign: 'Yandex llc')
O22 - tasks: Yandex browser güncelleme servisinin geri yüklenmesi - C:\program files (x86)\Yandex\YandexBrowser\24.7.2.1100\service_update.exe --repair (sign: 'Yandex llc')
O23 - service r2: AMD external events Utility - C:\Windows\System32\DriverStore\FileRepository\u0395510.inf_amd64_266bc083bb7590df\B395348\atiesrxx.exe (sign: 'Advanced Micro devices ınc.')
O23 - service S2: Asusupdatecheck - C:\Windows\System32\AsusUpdateCheck.exe (sign: 'ASUSTeK Computer ınc.')
O23 - service S2: Microsoft Edge Update service (edgeupdate) - (edgeupdate) - C:\program files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /svc (file missing)
O23 - service S3: Microsoft Defender çekirdek hizmeti - (mdcoresvc) - C:\ProgramData\Microsoft\Windows Defender\platform\4.18.24070.5-0\MpDefenderCoreService.exe (sign: 'Microsoft')
O23 - service S3: Microsoft Edge elevation service (microsoftedgeelevationservice) - (microsoftedgeelevationservice) - C:\program files (x86)\Microsoft\Edge\Application\128.0.2739.63\elevation_service.exe (file missing)
O23 - service S3: Microsoft Edge Update service (edgeupdatem) - (edgeupdatem) - C:\program files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /medsvc (file missing)
O23 - service S3: Steam Client service - C:\program files (X86)\common Files\Steam\steamservice.exe /runasservice (sign: 'Valve Corp.')
O23 - driver r0: AMD PCI root bus lower filter - (amdkmpfd) - C:\Windows\System32\drivers\amdkmpfd.sys (+safe mode) (sign: 'Advanced Micro devices ınc.')
O23 - driver r0: AMD PSP service - (amdpsp) - C:\Windows\System32\drivers\amdpsp.sys (sign: 'Advanced Micro devices, ınc.')
O23 - driver r1: Memuhyperv service - (memudrv) - C:\Windows\system32\DRIVERS\MEmuDrv.sys (sign: 'shanghai microvirt software Technology co. LTD.')
O23 - driver r2: Amdryzenmasterdriverv20 - C:\Windows\system32\AMDRyzenMasterDriver.sys (sign: 'Advanced Micro devices ınc.')
O23 - driver R3: AMD crash Defender driver - (amdfendr) - C:\Windows\System32\drivers\amdfendr.sys (sign: 'Microsoft' - Advanced Micro devices, ınc.)
O23 - driver R3: AMD crash Defender Manager driver - (amdfendrmgr) - C:\Windows\System32\drivers\amdfendrmgr.sys (sign: 'Microsoft' - Advanced Micro devices, ınc.)
O23 - driver R3: AMD function driver for HD Audio service - (atihdaudioservice) - C:\Windows\system32\drivers\AtihdWT6.sys (sign: 'Microsoft' - Advanced Micro devices)
O23 - driver R3: AMD gpıo Client driver - (amdgpio2) - C:\Windows\System32\drivers\amdgpio2.sys (sign: 'Advanced Micro devices ınc.')
O23 - driver R3: AMD gpıo Client driver - (amdgpio3) - C:\Windows\System32\drivers\amdgpio3.sys (invalid sign: Cert_e_chaınıng - Advanced Micro devices, ınc - 6C33D9E8ed5C745C079CC9cCE37EF9449E428A91)
O23 - driver R3: AMD Link Controller emulation - (amdxe) - C:\Windows\System32\drivers\amdxe.sys (sign: 'Advanced Micro devices ınc.')
O23 - driver R3: AMD PCI - (amdpcıdev) - C:\Windows\System32\drivers\AMDPCIDev.sys (sign: 'Advanced Micro devices ınc.')
O23 - driver R3: Amdsafd - C:\Windows\System32\DriverStore\FileRepository\amdsafd.inf_amd64_54807f69fe156f14\amdsafd.sys (sign: 'Advanced Micro devices ınc.')
O23 - driver R3: Amdwddmg - C:\Windows\System32\DriverStore\FileRepository\u0395510.inf_amd64_266bc083bb7590df\B395348\amdkmdag.sys (sign: 'Advanced Micro devices ınc.')
O23 - driver R3: Realtek RT640 NT driver - (RT640x64) - C:\Windows\System32\drivers\rt640x64.sys (+safe mode) (sign: 'Realtek semiconductor Corp.')
O23 - driver R3: Service for Realtek HD Audio (wdm) - (ıntcazaudaddservice) - C:\Windows\system32\drivers\RTKVHD64.sys (sign: 'Realtek semiconductor corp')
O23 - driver R3: Snap camera - (snapcameravirtualdevice) - C:\Windows\System32\drivers\SnapCameraVirtualDevice.sys (sign: 'snap ınc.')
O23 - driver S3: Intel(R) Serial IO gpıo Controller driver - (ialpssi_gpıo) - C:\Windows\System32\drivers\iaLPSSi_GPIO.sys (sign: 'Intel corporation - Client components group')
O23 - driver S3: Revoflt - C:\Windows\system32\DRIVERS\revoflt.sys (sign: 'Microsoft' - vs Revo group)
O23 - dependency: Microsoft service group 'NDIS' contains unknown service: 'RT640x64'.
O26 - debugger: HKLM\..\CompatTelRunner.exe: [Debugger] = C:\Windows\System32\taskkill.exe (sign: 'Microsoft')
O26 - debugger: HKLM\..\DeviceCensus.exe: [Debugger] = C:\Windows\System32\taskkill.exe (sign: 'Microsoft')
--
End of file - time spent: 11 sec. - 31276 bytes, CRC32: Ffffffff. Sign: 쁱ꓟ.