Logfile of HiJackThis+ (Plus) build 2024-11-10 Alpha v.3.4.0.12
Platform: x64 Windows 10 (Home), 10.0.19045.5131 (ReleaseId: 2009, 22H2), Service Pack: 0
Time: 16.11.2024 - 19:24 (UTC+03:00)
Language: OS: Turkish (0x41F). Display: Turkish (0x41F). Non-Unicode: Turkish (0x41F)
Memory: 11332 MiB Free. Loading RAM (32 %), CPU (5 %)
Elevated: Yes
Ran by: FReeTime (group: Administrators; type: Local) on DESKTOP-0TOG362, FirstRun: yes
Chrome: 130.0.6723.117
Internet Explorer: 11.0.19041.4355
Default: "C:\Program Files\Google\Chrome\Application\chrome.exe" --single-argument %1 (Google Chrome)
Boot mode: Normal (Secure Boot: On)
Running processes:
Number | Path
1 C:\Program Files (x86)\Common Files\Aladdin Shared\HASP\hasplms.exe
1 C:\Program Files (x86)\Common Files\Aladdin Shared\HASP\hasplmv.exe
1 C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\14.4.0.11537\AdskLicensingService\AdskLicensingService.exe
1 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
1 C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
1 C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe
1 C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe
1 C:\Program Files (x86)\Internet Download Manager\IDMan.exe
6 C:\Program Files (x86)\Microsoft\EdgeWebView\Application\130.0.2849.80\msedgewebview2.exe
1 C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe
1 C:\Program Files (x86)\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe
1 C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessServiceHost.exe
1 C:\Program Files\Autodesk\AdskIdentityManager\1.11.9.11\AdskIdentityManager.exe
1 C:\Program Files\Autodesk\Autodesk AdSSO\AdSSO.exe
1 C:\Program Files\Common Files\Autodesk\AdpDesktopSDK\bin\ADPClientService.exe
1 C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe
3 C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
13 C:\Program Files\Google\Chrome\Application\chrome.exe
1 C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
1 C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
1 C:\Program Files\Microsoft Mouse and Keyboard Center\MKCHelper.exe
1 C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
2 C:\Program Files\NVIDIA Corporation\NvBroadcast.NvContainer\NvBroadcast.Container.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MsMpEng.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\NisSrv.exe
1 C:\Users\FReeTime\Desktop\HiJackThis\HiJackThis.exe
1 C:\Users\FReeTime\Downloads\Programs\ISLC v1.0.3.3\Intelligent standby list cleaner ISLC.exe
1 C:\Windows\explorer.exe
1 C:\Windows\ImmersiveControlPanel\SystemSettings.exe
1 C:\Windows\System32\ApplicationFrameHost.exe
1 C:\Windows\System32\audiodg.exe
1 C:\Windows\System32\CompPkgSrv.exe
1 C:\Windows\System32\conhost.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
1 C:\Windows\System32\dllhost.exe
2 C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_ab3196e1830c9b6c\Display.NvContainer\NVDisplay.Container.exe
2 C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_32b266092fc6592d\RtkAudUService64.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\lsass.exe
3 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SearchFilterHost.exe
1 C:\Windows\System32\SearchIndexer.exe
1 C:\Windows\System32\SearchProtocolHost.exe
1 C:\Windows\System32\SecurityHealthService.exe
1 C:\Windows\System32\SecurityHealthSystray.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\SgrmBroker.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smartscreen.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
63 C:\Windows\System32\svchost.exe
3 C:\Windows\System32\taskhostw.exe
2 C:\Windows\System32\wbem\WmiPrvSE.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\System32\WirelessKB850NotificationService.exe
2 C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
1 C:\Windows\SysWOW64\PnkBstrA.exe
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8}: [SuggestionsURL_JSON] = hxxps://suggest.yandex.com.tr/suggest-ff.cgi?srv=ie11&uil=tr&part={searchTerms}&clid=2233630 - Yandex
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8}: [URL] = hxxps://yandex.com.tr/search/?text={searchTerms}&clid=2233630 - Yandex
O1 - Hosts: Reset contents to default
O1 - Hosts: 0.0.0.0 license.piriform.com
O1 - Hosts: 0.0.0.0 vvv.ccleaner.com
O1 - Hosts: 0.0.0.0 analytics.ff.avast.com
O1 - Hosts: 0.0.0.0 ipm-provider.ff.avast.com
O1 - Hosts: 0.0.0.0 license-api.ccleaner.com
O1 - Hosts: 0.0.0.0 shepherd.ff.avast.concc.avast.com
O1 - Hosts: 0.0.0.0 ncc.avast.com.edgesuite.net
O1 - Hosts: 0.0.0.0 ip-info.ff.avast.com
O1 - Hosts: 127.0.0.1 vvv.oncyazilim.com
O1 - Hosts: 127.0.0.1 vvv.lideryazilim.com
O1 - Hosts: 127.0.0.1 mirillis.com
O1 - Hosts: 0.0.0.0 netcad.com
O1 - Hosts: 0.0.0.0 netcad.com.tr
O1 - Hosts: 0.0.0.0 vvv.netcad.com
O1 - Hosts: 0.0.0.0 vvv.netcad.com.tr
O1 - Hosts: 0.0.0.0 update.netcad.com
O1 - Hosts: 0.0.0.0 update.netcad.com.tr
O1 - Hosts: 0.0.0.0 lisans.netcad.com
O1 - Hosts: 0.0.0.0 lisans.netcad.com.tr
O1 - Hosts: 127.0.0.1 germi
O1 - Hosts: 127.0.0.1 netcad.com
O1 - Hosts: 127.0.0.1 netcad.com.tr
O1 - Hosts: 127.0.0.1 update.netcad.com
O1 - Hosts: 127.0.0.1 update.netcad.com.tr
O1 - Hosts: 127.0.0.1 lisans.netcad.com
O1 - Hosts: 127.0.0.1 lisans.netcad.com.tr
O1 - Hosts: 127.0.0.1 update.netcad.com.tr
O1 - Hosts: 127.0.0.1 update.netcad.com
O1 - Hosts: 127.0.0.1 lisans.netcad.com
O1 - Hosts: 127.0.0.1 lisans.netcad.com.tr
O1 - Hosts: 127.0.0.1 dataupdate.netcad.com.tr
O1 - Hosts: 127.0.0.1 netcad.com
O1 - Hosts: 127.0.0.1 netcad.com.tr
O1 - Hosts: 127.0.0.1 netcadportal.com
O1 - Hosts: 127.0.0.1 netigma.com.tr
O1 - Hosts: 127.0.0.1 netcadkampus.com
O1 - Hosts: 127.0.0.1 netcad.ru
O1 - Hosts: 127.0.0.1 netcad.az
O1 - Hosts: 127.0.0.1 vvv.netcad.com
O1 - Hosts: 127.0.0.1 vvv.netcad.com.tr
O1 - Hosts: 127.0.0.1 vvv.netcadportal.com
O1 - Hosts: 127.0.0.1 vvv.netigma.com.tr
O1 - Hosts: 127.0.0.1 vvv.netcadkampus.com
O1 - Hosts: 127.0.0.1 vvv.netcad.ru
O1 - Hosts: 127.0.0.1 vvv.netcad.az
O1 - Hosts: 127.0.0.1 update.netcad.com.tr
O2 - HKLM\..\BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (sign: 'Tonec Inc.')
O2 - HKLM\..\BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_431\bin\jp2ssv.dll (sign: 'Oracle America, Inc.')
O2 - HKLM\..\BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_431\bin\ssv.dll (sign: 'Oracle America, Inc.')
O2-32 - HKLM\..\BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (sign: 'Tonec Inc.')
O4 - ActiveSetup: HKLM\..\{8A69D345-D564-463c-AFF1-A69D9E530F96}: [StubPath] = C:\Program Files\Google\Chrome\Application\130.0.6723.117\Installer\chrmstp.exe --configure-user-settings --verbose-logging --system-level --channel=stable (sign: 'Google LLC')
O4 - ActiveSetup: HKLM\..\OpenVPN_UserSetup: [StubPath] = C:\Windows\system32\reg.exe delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v OPENVPN-GUI /f (sign: 'Microsoft') (disabled)
O4 - HKCU\..\Run: [IDMan] = C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot (not signed - Tonec Inc. - 2948C4356C6AE01720FEC22AE131747F84067911)
O4 - HKCU\..\StartupApproved\Run: [CompactGUI] = C:\Users\FReeTime\Desktop\Uygulamalar\CompactGUI.exe -tray (2024/10/11) (not signed - IridiumIO - 3A98674EFE246FB69635707079F2F4CD56B5BA3B)
O4 - HKCU\..\StartupApproved\Run: [EpicGamesLauncher] = C:\Program Files (x86)\Epic Games\Launcher\Portal\Binaries\Win64\EpicGamesLauncher.exe -silent -launchcontext=boot (2024/03/27) (sign: 'Epic Games Inc.')
O4 - HKCU\..\StartupApproved\Run: [Steam] = C:\Program Files (x86)\Steam\steam.exe -silent (2023/02/05) (sign: 'Valve Corp.')
O4 - HKLM\..\Run: [RtkAudUService] = C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_32b266092fc6592d\RtkAudUService64.exe -background (sign: 'Realtek Semiconductor Corp.')
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\W32X86\3\New\PrintConfig.dll -> C:\Windows\system32\spool\DRIVERS\W32X86\3\PrintConfig.dll (file missing)
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Windows\system32\spool\DRIVERS\x64\3\New\PrintConfig.dll -> C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll (file missing)
O4 - HKLM\..\StartupApproved\Run: [Autodesk Access] = C:\Program Files\Autodesk\AdODIS\V1\Access\AdskAccessCore.exe --minimizedUi --autoLaunch (2024/04/14) (sign: 'Autodesk, Inc.')
O4 - MountPoints2: HKCU\..\{80b35a5e-48b8-11ee-ab82-00d861d43d72}\shell\AutoRun\command: (default) = "E:\OnePlus_setup.exe" /s (file missing)
O4 - Startup: C:\Users\FReeTime\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\downloadcli_v2.lnk -> C:\Users\FReeTime\AppData\Roaming\WinXBluRay.exe (file missing)
O4-32 - HKLM\..\Run: [SunJavaUpdateSched] = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (sign: 'Oracle America, Inc.')
O5 - Applet: C:\Windows\System32\plotman.cpl (sign: 'Autodesk, Inc.')
O5 - Applet: C:\Windows\System32\styleman.cpl (sign: 'Autodesk, Inc.')
O5 - Applet: C:\Windows\SysWOW64\BDEADMIN.CPL (not signed - no company - 2F63F06840D899BDF7A7917517921EC48F922636)
O5 - Applet: C:\Windows\SysWOW64\Firebird2Control.cpl (not signed - IBPhoenix - 6243781FDF6763B2302568E99B4EF4DD3897608C)
O7 - KnownFolder: C:\Users\Public\Music (folder missing)
O7 - Policy: (UAC) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System: [ConsentPromptBehaviorAdmin] = 0
O7 - Policy: (UAC) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System: [EnableLUA] = 0
O7 - Policy: (UAC) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System: [PromptOnSecureDesktop] = 0
O7 - Policy: HKCU\..\Windows\Explorer: [DisableSearchBoxSuggestions] = 1
O7 - Policy: HKLM\..\Windows\Explorer: [DisableSearchBoxSuggestions] = 1
O7 - Policy: HKLM\Software\Microsoft\Windows Defender\Features: [TamperProtection] = 4
O8 - Context menu item: HKCU\..\Internet Explorer\MenuExt\IDM ile indir: (default) = C:\Program Files (x86)\Internet Download Manager\IEExt.htm (not signed - no company - 1A49C5F7A98580F8002AC1D6115AB39CB753975B)
O15 - Trusted Zone: hxxps://ogrgumushaneedutr-files.sharepoint.com
O15 - Trusted Zone: hxxps://ogrgumushaneedutr-myfiles.sharepoint.com
O15 - Trusted Zone: hxxps://wkuackr-files.sharepoint.com
O17 - DHCP DNS 1: 192.168.2.1
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (sign: 'Tonec Inc.')
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Windows\system32\AcSignIcon.dll (sign: 'Autodesk, Inc.')
O22 - Task (.job): (disabled) (Not scheduled) CreateExplorerShellUnelevatedTask.job - C:\Windows\explorer.exe (sign: 'Microsoft')
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B06BDC0F-FC47-4B7D-9AF4-87F14EBE13CB} - (no key)
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B06BDC0F-FC47-4B7D-9AF4-87F14EBE13CB} - \AMDAutoUpdate (no xml)
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\Windows\system32\ProvTool.exe /turn 5 /source ProvRetryTask (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\Windows\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\Windows\system32\usoclient.exe StartMaintenanceWork (sign: 'Microsoft')
O22 - Tasks: (disabled) NvBroadcast_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\NVIDIA Broadcast\NVIDIA Broadcast UI.exe -minimized (sign: 'NVIDIA Corporation')
O22 - Tasks: (telemetry) \Microsoft\Office\Office Performance Monitor - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesCommonX64\Microsoft Shared\Office16\operfmon.exe (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareData (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\Windows\system32\rundll32.exe C:\Windows\system32\PcaSvc.dll,PcaPatchSdbTask (sign: 'Microsoft')
O22 - Tasks: \GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem132.0.6806.0{062391D6-E128-4FDD-B0C8-8E2FC4BE1E8B} - C:\Program Files (x86)\Google\GoogleUpdater\132.0.6806.0\updater.exe --wake --system (sign: 'Google LLC')
O22 - Tasks: \HardDiskSentinel\Hard Disk Sentinel_FReeTime - D:\test\Hard Disk Sentinel\HDSentinel.exe /AUTORUN (file missing)
O22 - Tasks: \Microsoft\Windows\AppxDeploymentClient\AppInstallerUpdater - C:\Windows\system32\rundll32.exe C:\Windows\system32\AppxDeploymentClient.dll,AppInstallerUpdateAllTask (sign: 'Microsoft')
O22 - Tasks: \Microsoft\Windows\Clip\ClipESU - C:\Windows\system32\clipesu.exe (sign: 'Microsoft')
O22 - Tasks: AMDInstallLauncher - C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe /InstallAUEP (file missing)
O22 - Tasks: AMDRyzenMasterSDKTask - C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe (sign: 'Advanced Micro Devices Inc.')
O22 - Tasks: Intelligent StandbyList Cleaner - C:\Users\FReeTime\Downloads\Programs\ISLC v1.0.3.3\Intelligent standby list cleaner ISLC.exe (sign: 'Wagnardsoft')
O22 - Tasks: Microsoft_Hardware_Launch_ipoint_exe - C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (sign: 'Microsoft')
O22 - Tasks: Microsoft_Hardware_Launch_itype_exe - C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (sign: 'Microsoft')
O22 - Tasks: Microsoft_Hardware_Launch_mousekeyboardcenter_exe - C:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe (sign: 'Microsoft')
O22 - Tasks: Microsoft_MKC_Logon_Task_ceip.exe - C:\Program Files\Microsoft Mouse and Keyboard Center\ceip.exe (sign: 'Microsoft')
O22 - Tasks: Microsoft_MKC_Logon_Task_ipoint.exe - C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe (sign: 'Microsoft')
O22 - Tasks: Microsoft_MKC_Logon_Task_itype.exe - C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (sign: 'Microsoft')
O22 - Tasks: ModifyLinkUpdate - C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe -UpdateCurrentUser (file missing)
O22 - Tasks: MSIAfterburner - C:\Program Files (x86)\MSI Afterburner\MSIAfterburner.exe /s (sign: 'MICRO-STAR INTERNATIONAL CO., LTD.')
O22 - Tasks: RTSS - C:\Program Files (x86)\RivaTuner Statistics Server\RTSS.exe /s (file missing)
O22 - Tasks: StartCN - C:\Program Files\AMD\CNext\CNext\cncmd.exe startwithdelay (file missing)
O22 - Tasks: StartCNHealth - C:\ProgramData\AMD\StartCNHealth\ATICMD.exe C:\Windows\system32\cmd.exe /c C:\ProgramData\AMD\StartCNHealth\ATICN.cmd (not signed - Advanced Micro Devices, Inc. - 3645518751ADD4625BE695BC0A20BE990F02ADDC)
O22 - Tasks: StartDVR - C:\Program Files\AMD\CNext\CNext\RSServCmd.exe (file missing)
O23 - Service R2: Autodesk Access Service Host - C:\Program Files\Autodesk\AdODIS\V1\Setup\AdskAccessServiceHost.exe (sign: 'Autodesk, Inc.')
O23 - Service R2: Autodesk Desktop Licensing Service - (AdskLicensingService) - C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingService\AdskLicensingService.exe (sign: 'Autodesk, Inc.')
O23 - Service R2: Firebird Guardian - DefaultInstance - (FirebirdGuardianDefaultInstance) - C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbguard.exe -s DefaultInstance (not signed - Firebird Project - AF6B63F0B1C564E5D2A27E9887066355870CE213)
O23 - Service R2: FlexNet Licensing Service - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe (sign: 'Flexera Software LLC')
O23 - Service R2: FlexNet Licensing Service 64 - C:\Program Files\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService64.exe (sign: 'Flexera Software LLC')
O23 - Service R2: Microsoft Defender Çekirdek Hizmeti - (MDCoreSvc) - C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24090.11-0\MpDefenderCoreService.exe (sign: 'Microsoft')
O23 - Service R2: NVIDIA Broadcast LocalSystem Container - (NvBroadcast.ContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\NvBroadcast.NvContainer\NvBroadcast.Container.exe -s NvBroadcast.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NvBroadcast.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\NvBroadcast.NvContainer\plugins\LocalSystem" -r -p 30000 (sign: 'Nvidia Corporation')
O23 - Service R2: NVIDIA Display Container LS - (NVDisplay.ContainerLocalSystem) - C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_ab3196e1830c9b6c\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log -l 3 -d C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_ab3196e1830c9b6c\Display.NvContainer\plugins\LocalSystem -r -p 30000 -cfg NVDisplay.ContainerLocalSystem\LocalSystem /ert (sign: 'NVIDIA Corporation')
O23 - Service R2: PnkBstrA - C:\Windows\system32\PnkBstrA.exe (file missing)
O23 - Service R2: Qualcomm MTU Service - (qcmtusvc) - C:\Program Files (x86)\QUALCOMM Incorporated\Qualcomm USB Drivers For Windows\DriverPackage\Qualcomm\Tools\qcmtusvc.exe (not signed - QUALCOMM, Inc. - 9725CB577B28F9A71D66AF1F5C075423C3F2C66A)
O23 - Service R2: Realtek Audio Universal Service - (RtkAudioUniversalService) - C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_32b266092fc6592d\RtkAudUService64.exe (sign: 'Realtek Semiconductor Corp.')
O23 - Service R2: Sentinel LDK License Manager - (hasplms) - C:\Program Files (x86)\Common Files\Aladdin Shared\HASP\hasplms.exe -run (sign: 'Gemalto, Inc.')
O23 - Service R2: Wireless Keyboard 850 Notification Service - (WirelessKB850NotificationService) - C:\Windows\system32\WirelessKB850NotificationService.exe (sign: 'Microsoft')
O23 - Service R3: Firebird Server - DefaultInstance - (FirebirdServerDefaultInstance) - C:\Program Files (x86)\Firebird\Firebird_2_5\bin\fbserver.exe -s DefaultInstance (not signed - Firebird Project - 7990F2B77D2389C97591BEE13EED7CC4D785E24B)
O23 - Service S2: Google Güncelleme Hizmeti (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc (sign: 'Google LLC')
O23 - Service S2: Google Güncelleyici Dahili Hizmeti (GoogleUpdaterInternalService132.0.6806.0) - (GoogleUpdaterInternalService132.0.6806.0) - C:\Program Files (x86)\Google\GoogleUpdater\132.0.6806.0\updater.exe --system --windows-service --service=update-internal (sign: 'Google LLC')
O23 - Service S2: Google Güncelleyici Hizmeti (GoogleUpdaterService132.0.6806.0) - (GoogleUpdaterService132.0.6806.0) - C:\Program Files (x86)\Google\GoogleUpdater\132.0.6806.0\updater.exe --system --windows-service --service=update (sign: 'Google LLC')
O23 - Service S3: Bentley Dgn Index Service - (DgnIndexingService) - C:\Program Files (x86)\Common Files\Bentley Shared\Dgn Index Service\DgnIndexServer.exe (not signed - Bentley Systems Inc. - 08B0299B7447DF2AA7CA0D1918B24061E59263E3)
O23 - Service S3: Epic Online Services - (EpicOnlineServices) - C:\Program Files (x86)\Epic Games\Epic Online Services\service\EpicOnlineServicesHost.exe (sign: 'Epic Games Inc.')
O23 - Service S3: FACEITService - C:\Program Files\FACEIT AC\faceitservice.exe (sign: 'ESL Gaming GmbH')
O23 - Service S3: FileSyncHelper - C:\Program Files\Microsoft OneDrive\24.025.0204.0003\FileSyncHelper.exe (sign: 'Microsoft')
O23 - Service S3: Futuremark SystemInfo Service - C:\Program Files (x86)\Futuremark\SystemInfo\FMSISvc.exe (sign: 'Underwriters Laboratories Inc.')
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService) - (GoogleChromeElevationService) - C:\Program Files\Google\Chrome\Application\130.0.6723.117\elevation_service.exe (sign: 'Google LLC')
O23 - Service S3: Google Güncelleme Hizmeti (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc (sign: 'Google LLC')
O23 - Service S3: Intel(R) Integrated Clock Controller Service - Intel(R) ICCS - (ICCS) - C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (sign: 'Intel Corporation - Intel® Management Engine Firmware')
O23 - Service S3: OneDrive Updater Service - C:\Program Files\Microsoft OneDrive\24.025.0204.0003\OneDriveUpdaterService.exe (sign: 'Microsoft')
O23 - Service S3: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\steamservice.exe /RunAsService (sign: 'Valve Corp.')
O23 - Service S3: TeamViewer - C:\Program Files\TeamViewer\TeamViewer_Service.exe (sign: 'TeamViewer Germany GmbH')
O23 - Driver R0: AMD PSP Service - (amdpsp) - C:\Windows\System32\drivers\amdpsp.sys (sign: 'Advanced Micro Devices')
O23 - Driver R1: FACEIT - C:\Program Files\FACEIT AC\FACEIT_AC.sys (sign: 'Microsoft' - no company)
O23 - Driver R1: MSIO - C:\Windows\system32\drivers\MsIo64.sys (sign: 'Microsoft' - MICSYS Technology Co., LTd)
O23 - Driver R2: aksdf - C:\Windows\system32\drivers\aksdf.sys (sign: 'Gemalto, Inc.')
O23 - Driver R2: aksfridge - C:\Windows\system32\drivers\aksfridge.sys (sign: 'Gemalto, Inc.')
O23 - Driver R2: AMDRyzenMasterDriverV20 - C:\Windows\system32\AMDRyzenMasterDriver.sys (sign: 'Advanced Micro Devices Inc.')
O23 - Driver R2: Driver - C:\Program Files (x86)\EVGA\Kernel\driver-x64.sys (sign: 'EVGA Corp.')
O23 - Driver R2: hardlock - C:\Windows\system32\drivers\hardlock.sys (sign: 'Gemalto, Inc.')
O23 - Driver R2: IDMWFP - C:\Windows\System32\drivers\idmwfp.sys (sign: 'Microsoft' - Tonec Inc.)
O23 - Driver R3: AMD GPIO Client Driver - (amdgpio2) - C:\Windows\System32\drivers\amdgpio2.sys (sign: 'Advanced Micro Devices')
O23 - Driver R3: AMD GPIO Client Driver - (amdgpio3) - C:\Windows\System32\drivers\amdgpio3.sys (sign: 'ASMedia Technology Inc.')
O23 - Driver R3: AMD PCI - (AMDPCIDev) - C:\Windows\System32\drivers\AMDPCIDev.sys (sign: 'Advanced Micro Devices Inc.')
O23 - Driver R3: AMD Special Tools Driver - (AmdTools64) - C:\Windows\System32\drivers\AmdTools64.sys (sign: 'Advanced Micro Devices Inc.')
O23 - Driver R3: Microsoft Mouse and Keyboard Center Filter Driver - (Point64) - C:\Windows\System32\drivers\point64.sys (sign: 'Microsoft' - Microsoft Corporation)
O23 - Driver R3: MS Hardware Device Detection Driver (USB) - (dc3d) - C:\Windows\System32\drivers\dc3d.sys (sign: 'Microsoft' - Microsoft Corporation)
O23 - Driver R3: NVIDIA Broadcast - (nvrtxvad_WaveExtensible) - C:\Windows\system32\drivers\nvrtxvad64v.sys (sign: 'Nvidia Corporation')
O23 - Driver R3: nvlddmkm - C:\Windows\System32\DriverStore\FileRepository\nv_dispi.inf_amd64_ab3196e1830c9b6c\nvlddmkm.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: Realtek RT640 NT Driver - (rt640x64) - C:\Windows\System32\drivers\rt640x64.sys (+safe mode) (sign: 'Realtek Semiconductor Corp.')
O23 - Driver R3: RTCore64 - C:\Program Files (x86)\MSI Afterburner\RTCore64.sys (sign: 'MICRO-STAR INTERNATIONAL CO., LTD.')
O23 - Driver R3: Service for NVIDIA High Definition Audio Driver - (NVHDA) - C:\Windows\system32\drivers\nvhda64v.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: Service for Realtek HD Audio (WDM) - (IntcAzAudAddService) - C:\Windows\system32\drivers\RTKVHD64.sys (sign: 'Realtek Semiconductor Corp.')
O23 - Driver S2: inpoutx64 - C:\Windows\System32\Drivers\inpoutx64.sys (sign: 'Red Fox UK Limited')
O23 - Driver S2: Thaiphoon Burner hardware access driver - (SSGDIO) - C:\Windows\SysWOW64\DRIVERS\ssgdio64.sys (sign: 'ATI Technologies, Inc')
O23 - Driver S2: Virtual USB MultiKey - (multikey) - C:\Windows\System32\drivers\multikey.sys (file missing)
O23 - Driver S3: AMD HD Audio Bus Service - (AMDHDAudBusService) - C:\Windows\System32\drivers\amdhdaudbus.sys (sign: 'Microsoft' - Advanced Micro Devices)
O23 - Driver S3: AmdGpuTweak - C:\Windows\system32\drivers\AmdGpuTweak.sys (sign: 'WDKTestCert vega,132037776677716667', but untrusted root: 'WDKTestCert vega,132037776677716667' with fingerprint: 8F95257A0346EFE051BF3C3DADBC151E82C83637)
O23 - Driver S3: AsrDrv101 - C:\Windows\SysWOW64\Drivers\AsrDrv101.sys (sign: 'ASROCK Incorporation')
O23 - Driver S3: atillk64 - C:\Users\FReeTime\Desktop\XFX.RX-57XT83LD8.TRIPLE.CUSTOM-BUILT\XFX.RX-57XT83LD8.TRIPLE.CUSTOM-BUILT\atillk64.sys (file missing)
O23 - Driver S3: HWiNFO Kernel Driver (v174) - (HWiNFO_174) - C:\Users\FReeTime\AppData\Local\Temp\HWiNFO64A_174.SYS (file missing)
O23 - Driver S3: HWiNFO Kernel Driver (v190) - (HWiNFO_190) - C:\Users\FReeTime\AppData\Local\Temp\HWiNFO64A_190.SYS (file missing)
O23 - Driver S3: HWiNFO Kernel Driver (v191) - (HWiNFO_191) - C:\Users\FReeTime\AppData\Local\Temp\HWiNFO64A_191.SYS (file missing)
O23 - Driver S3: Intel(R) Serial IO GPIO Controller Driver - (iaLPSSi_GPIO) - C:\Windows\System32\drivers\iaLPSSi_GPIO.sys (sign: 'Intel Corporation - Client Components Group')
O23 - Driver S3: NTIOLib_CC_Clock - C:\Program Files (x86)\MSI\One Dragon Center\Lib\NTIOLib_X64.sys (file missing)
O23 - Driver S3: PDFWKRNL - C:\Users\FReeTime\AppData\Local\Temp\USBCPDFW\pdfwkrnl.sys (file missing)
O23 - Driver S3: Qualcomm USB Device for Legacy Serial Communication - (qcusbser) - C:\Windows\system32\DRIVERS\qcusbser.sys (not signed - QUALCOMM Incorporated - 47974D8E6512497C9AD6A79919E1CD58366D5E97)
O23 - Driver S3: Revoflt - C:\Windows\system32\DRIVERS\revoflt.sys (sign: 'Microsoft' - VS Revo Group)
O23 - Driver S3: rspLLL - C:\Windows\system32\DRIVERS\rspLLL64.sys (sign: 'Daniel Terhell')
O23 - Driver S3: Sentinel HASP Key - (akshasp) - C:\Windows\system32\DRIVERS\akshasp.sys (sign: 'Gemalto, Inc.')
O23 - Driver S3: Sentinel USB Key - (aksusb) - C:\Windows\system32\DRIVERS\aksusb.sys (+safe mode) (sign: 'Gemalto, Inc.')
O23 - Driver S3: SIV Kernel Driver - (SIVDriver) - C:\Windows\system32\Drivers\SIVX64.sys (sign: 'Microsoft' - Ray Hinchliffe)
O23 - Driver S3: TAP-Windows Adapter V9 - (tap0901) - C:\Windows\System32\drivers\tap0901.sys (+safe mode) (sign: 'Microsoft' - The OpenVPN Project)
O23 - Driver S3: USB Mouse Rate Adjuster Lower Filter by SweetLow - (hidusbf) - C:\Windows\system32\DRIVERS\hidusbf.sys (sign: 'Jeshua Starr Scully')
O23 - Driver S3: WinRing0_1_2_2 - C:\Windows\system32\drivers\WinRing0_1_2_2.sys (sign: 'PAIPTAC Driver')
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service: 'rt640x64'
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service: 'tap0901'
O27 - Account: (Bad profile) Folder is not referenced by any of user SIDs: C:\Users\webzo
--
End of file - Time spent: 24.4 sec. - 57830 bytes, CRC32: FFFFFFFF. Sign: 埒