Logfile of HiJackThis+ (Plus) build 2024-04-18 Alpha v.3.4.0.9
Platform: x64 Windows 10 (Pro), 10.0.19045.4780 (ReleaseId: 2009, 22H2), Service Pack: 0
Time: 29.08.2024 - 01:03 (UTC+03:00)
Language: OS: Turkish (0x41F). Display: English (0x409). Non-Unicode: Turkish (0x41F)
Memory: 9295 MiB Free. Loading RAM (44 %), CPU (26 %)
Elevated: Yes
Ran by: Alper (group: Administrators; type: Local) on DESK-ALP, FirstRun: no
Chrome: 128.0.6613.85
Firefox: 129.0.1.559
Internet Explorer: 11.0.19041.4355
Default: "C:\Program Files\Google\Chrome\Application\chrome.exe" --single-argument %1 (Google Chrome)
Boot mode: Normal (Secure Boot: Off)
Running processes:
Number | Path
1 C:\Program Files (x86)\AIMP\AIMP.exe
1 C:\Program Files (x86)\Clipdiary\Clipdiary.exe
1 C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe
1 C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\9.0.3.46\AdskLicensingService\AdskLicensingService.exe
1 C:\Program Files (x86)\Common Files\Foxit\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe
1 C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe
1 C:\Program Files (x86)\DFX\dfx.exe
1 C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp32.exe
1 C:\Program Files (x86)\DFX\Universal\Apps\DfxSharedApp64.exe
1 C:\Program Files (x86)\Foxit Software\Foxit PDF Reader\FoxitPDFReader.exe
1 C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe
1 C:\Program Files (x86)\Internet Download Manager\IDMan.exe
1 C:\Program Files (x86)\Internet Download Manager\IEMonitor.exe
1 C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
1 C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe
1 C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe
1 C:\Program Files (x86)\Stardock\Groupy\GroupyCtrl.exe
1 C:\Program Files (x86)\Stardock\Groupy\GroupyHelp32.exe
1 C:\Program Files (x86)\Stardock\Groupy\GroupyHelp64.exe
1 C:\Program Files (x86)\Stardock\Groupy\GroupySrv.exe
1 C:\Program Files (x86)\USB Disk Security\USBGuard.exe
1 C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe
2 C:\Program Files\Everything\Everything.exe
25 C:\Program Files\Google\Chrome\Application\chrome.exe
1 C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
1 C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
1 C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
1 C:\Program Files\OO Software\Defrag\oodag.exe
1 C:\Program Files\TeraCopy\TeraCopyService.exe
1 C:\Program Files\WindowsApps\40459File-New-Project.EarTrumpet_2.3.0.0_x86__1sdd7yawvg6ne\EarTrumpet\EarTrumpet.exe
1 C:\Program Files\WindowsApps\5319275A.WhatsAppDesktop_2.2433.3.0_x64__cv1g1gvanyjgm\WhatsApp.exe
1 C:\Program Files\WindowsApps\Microsoft.YourPhone_1.24081.89.0_x64__8wekyb3d8bbwe\PhoneExperienceHost.exe
1 C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCoLtd.SamsungQuickShare_1.7.55.0_x64__wyx1vj98g3asy\QuickShareService\QuickShareService.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MsMpEng.exe
1 C:\Users\Alper\AppData\Roaming\DesktopOK\DesktopOK_x64.exe
1 C:\Windows\explorer.exe
1 C:\Windows\ImmersiveControlPanel\SystemSettings.exe
1 C:\Windows\System32\ApplicationFrameHost.exe
1 C:\Windows\System32\audiodg.exe
2 C:\Windows\System32\backgroundTaskHost.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
1 C:\Windows\System32\dasHost.exe
3 C:\Windows\System32\dllhost.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\lsass.exe
2 C:\Windows\System32\nvvsvc.exe
1 C:\Windows\System32\oobe\UserOOBEBroker.exe
1 C:\Windows\System32\prevhost.exe
2 C:\Windows\System32\rundll32.exe
8 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SearchIndexer.exe
1 C:\Windows\System32\SecurityHealthService.exe
1 C:\Windows\System32\SecurityHealthSystray.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\SgrmBroker.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smartscreen.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
75 C:\Windows\System32\svchost.exe
1 C:\Windows\System32\SystemSettingsBroker.exe
2 C:\Windows\System32\taskhostw.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\System32\WUDFHost.exe
1 C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe
1 C:\Windows\SysWOW64\vmnat.exe
1 C:\Windows\SysWOW64\vmnetdhcp.exe
1 Z:\E\indirilenlerim\Compressed\HiJackThis\HiJackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: [ProxyOverride] = *.local
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8}: [SuggestionsURL_JSON] = hxxps://suggest.yandex.com.tr/suggest-ff.cgi?srv=ie11&uil=tr&part={searchTerms}&clid=2233630 - Yandex
R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{8C3078A0-9AAB-4371-85D1-656CA8E46EE8}: [URL] = hxxps://yandex.com.tr/search/?text={searchTerms}&clid=2233630 - Yandex
O1 - Hosts: Reset contents to default
O1 - Hosts: 127.0.0.1 activation.acronis.com web-api-tih.acronis.com
O1 - Hosts: 127.0.0.1 activation.acronis.com web-api-tih.acronis.com
O1 - Hosts: 127.0.0.1 liveupdate.acronis.com
O1 - Hosts: 127.0.0.1 download.acronis.com
O1 - Hosts: 127.0.0.1 orders.acronis.com
O1 - Hosts: 127.0.0.1 ns1.acronis.com
O1 - Hosts: 127.0.0.1 ns2.acronis.com
O1 - Hosts: 127.0.0.1 ns3.acronis.com
O1 - Hosts: 127.0.0.1 account.acronis.com
O1 - Hosts: 127.0.0.1 gateway.acronis.com
O1 - Hosts: 127.0.0.1 192.150.14.69
O1 - Hosts: 127.0.0.1 192.150.18.101
O1 - Hosts: 127.0.0.1 192.150.18.108
O1 - Hosts: 127.0.0.1 192.150.22.40
O1 - Hosts: 127.0.0.1 192.150.8.100
O1 - Hosts: 127.0.0.1 192.150.8.118
O1 - Hosts: 127.0.0.1 209-34-83-73.ood.opsource.net
O1 - Hosts: 127.0.0.1 3dns-1.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 3dns-2.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-3.adobe.com
O1 - Hosts: 127.0.0.1 3dns-4.adobe.com
O1 - Hosts: 127.0.0.1 3dns.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 activate-sea.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 activate-sjc0.adobe.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 activate.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip1.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip2.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip3.adobe.com
O1 - Hosts: 127.0.0.1 activate.wip4.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-1.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-4.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns.adobe.com
O1 - Hosts: 127.0.0.1 adobe.activate.com
O1 - Hosts: 127.0.0.1 adobeereg.com
O1 - Hosts: 127.0.0.1 crl.verisign.net
O1 - Hosts: 127.0.0.1 CRL.VERISIGN.NET.*
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 ereg.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip1.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip2.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip3.adobe.com
O1 - Hosts: 127.0.0.1 ereg.wip4.adobe.com
O1 - Hosts: 127.0.0.1 hl2rcv.adobe.com
O1 - Hosts: 127.0.0.1 ood.opsource.net
O1 - Hosts: 127.0.0.1 practivate.adobe
O1 - Hosts: 127.0.0.1 practivate.adobe.*
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.com
O1 - Hosts: 127.0.0.1 practivate.adobe.ipp
O1 - Hosts: 127.0.0.1 practivate.adobe.newoa
O1 - Hosts: 127.0.0.1 practivate.adobe.ntp
O1 - Hosts: 127.0.0.1 tss-geotrust-crl.thawte.com
O1 - Hosts: 127.0.0.1 wip.adobe.com
O1 - Hosts: 127.0.0.1 wip1.adobe.com
O1 - Hosts: 127.0.0.1 wip2.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip3.adobe.com
O1 - Hosts: 127.0.0.1 wip4.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 wwis-dubc1-vip60.adobe.com
O1 - Hosts: 127.0.0.1 license.piriform.com
O1 - Hosts: 127.0.0.1 vvv.license.piriform.com
O1 - Hosts: 127.0.0.1 speccy.piriform.com
O1 - Hosts: 127.0.0.1 vvv.speccy.piriform.com
O1 - Hosts: 127.0.0.1 recuva.piriform.com
O1 - Hosts: 127.0.0.1 vvv.recuva.piriform.com
O1 - Hosts: 127.0.0.1 defraggler.piriform.com
O1 - Hosts: 127.0.0.1 vvv.defraggler.piriform.com
O1 - Hosts: 127.0.0.1 ccleaner.piriform.com
O1 - Hosts: 127.0.0.1 vvv.ccleaner.piriform.com
O1 - Hosts: 127.0.0.1 license-api.ccleaner.com
O2 - HKLM\..\BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC64.dll (sign: 'Tonec Inc.')
O2-32 - HKLM\..\BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files (x86)\Internet Download Manager\IDMIECC.dll (sign: 'Tonec Inc.')
O4 - ActiveSetup: HKLM\..\{8A69D345-D564-463c-AFF1-A69D9E530F96}: [StubPath] = C:\Program Files\Google\Chrome\Application\128.0.6613.85\Installer\chrmstp.exe --configure-user-settings --verbose-logging --system-level --channel=stable (sign: 'Google LLC')
O4 - HKCU\..\Run: [Clipdiary] = C:\Program Files (x86)\Clipdiary\clipdiary.exe (not signed - no company - 1D91A74383FDA79FFAB4CE66088CAC8505987F41)
O4 - HKCU\..\Run: [DesktopOK] = C:\Users\Alper\AppData\Roaming\DesktopOK\DesktopOK_x64.exe -bg -startup (sign: 'Nenad Hrg')
O4 - HKCU\..\StartupApproved\Run: [BingSvc] = C:\Users\Alper\AppData\Local\Microsoft\BingSvc\BingSvc.exe (2023/08/11) (sign: 'Microsoft')
O4 - HKCU\..\StartupApproved\Run: [Discord] = C:\Users\Alper\AppData\Local\Discord\Update.exe --processStart Discord.exe (2022/03/25) (sign: 'Discord Inc.')
O4 - HKCU\..\StartupApproved\Run: [f.lux] = C:\Users\Alper\AppData\Local\FluxSoftware\Flux\flux.exe /noshow (2023/06/21) (sign: 'F.lux Software LLC')
O4 - HKCU\..\StartupApproved\Run: [IDMan] = C:\Program Files (x86)\Internet Download Manager\IDMan.exe /onboot (2023/02/27) (not signed - Tonec Inc. - 2948C4356C6AE01720FEC22AE131747F84067911)
O4 - HKCU\..\StartupApproved\Run: [Microsoft Edge Update] = C:\Users\Alper\AppData\Local\Microsoft\EdgeUpdate\1.3.195.15\MicrosoftEdgeUpdateCore.exe (2022/03/25) (sign: 'Microsoft')
O4 - HKCU\..\StartupApproved\Run: [MicrosoftEdgeAutoLaunch_C2A78EA9E078EE19A41E2485CE0B013E] = C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe --win-session-start (2023/11/10) (sign: 'Microsoft')
O4 - HKCU\..\StartupApproved\Run: [Opera Browser Assistant] = C:\Users\Alper\AppData\Local\Programs\Opera\assistant\browser_assistant.exe (2021/05/18) (sign: 'Opera Software AS')
O4 - HKCU\..\StartupApproved\Run: [SmartSwitchPDLR.exe] = C:\Program Files (x86)\Samsung\Smart Switch PC\SmartSwitchPDLR.exe Run Kies4 (2023/11/10) (sign: 'Samsung Electronics Co., Ltd.')
O4 - HKCU\..\StartupApproved\StartupFolder: C:\Users\Alper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DeskPins.lnk -> C:\Program Files (x86)\DeskPins\deskpins.exe (2023/01/27) (not signed - Elias Fotinis - 344E1BC44210594F4AB4AC9BE349E4F906E5D354)
O4 - HKCU\..\StartupApproved\StartupFolder: C:\Users\Alper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote'a Gönder.lnk -> C:\Program Files (x86)\Microsoft Office\root\Office16\ONENOTEM.EXE /tsr (2023/08/11) (sign: 'Microsoft')
O4 - HKCU\..\StartupApproved\StartupFolder: C:\Users\Alper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Rainmeter.lnk -> C:\Program Files\Rainmeter\Rainmeter.exe (2023/09/14) (invalid sign: CERT_E_CHAINING - Rainmeter - 9C8F89FE3362B1DDB4140B4AD942C0D8A293F9A1)
O4 - HKCU\..\StartupApproved\StartupFolder: C:\Users\Alper\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Telegram.lnk -> C:\Users\Alper\AppData\Roaming\Telegram Desktop\Telegram.exe -autostart (2023/02/06) (not signed - Telegram FZ-LLC - 875C6E432182411C008BA9478D3E2B234444BBDF)
O4 - HKLM\..\Run: [Everything] = C:\Program Files\Everything\Everything.exe -startup (sign: 'voidtools')
O4 - HKLM\..\Session Manager: [PendingFileRenameOperations] = C:\Program Files\Google\Chrome\Temp -> DELETE (file missing)
O4 - HKLM\..\StartupApproved\Run: [Acronis Scheduler2 Service] = C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (2023/02/12) (sign: 'Acronis International GmbH')
O4 - HKLM\..\StartupApproved\Run: [AdobeAAMUpdater-1.0] = C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (2023/02/27) (sign: 'Adobe Systems Incorporated')
O4 - HKLM\..\StartupApproved\Run: [Cobian Reflector] = C:\Program Files\Cobian Reflector\Cobian.Reflector.Application.exe (2023/02/23) (sign: 'Luis Cobian Dorta')
O4 - HKLM\..\StartupApproved\Run: [HotKeysCmds] = C:\Windows\system32\hkcmd.exe (2021/05/17) (sign: 'Intel(R) pGFX')
O4 - HKLM\..\StartupApproved\Run: [IgfxTray] = C:\Windows\system32\igfxtray.exe (2021/05/17) (sign: 'Intel(R) pGFX')
O4 - HKLM\..\StartupApproved\Run: [Persistence] = C:\Windows\system32\igfxpers.exe (2021/05/17) (sign: 'Intel(R) pGFX')
O4 - HKLM\..\StartupApproved\Run: [Reflect UI] = C:\Program Files\Macrium\Common\ReflectUI.exe (2023/02/06) (invalid sign: TRUST_E_BAD_DIGEST - Paramount Software UK Ltd - 3CB8C7991D57971CB4D49C9F89DFA7BD1EC813E6)
O4 - HKLM\..\StartupApproved\Run: [WindowsMasterUI] = C:\Program Files\Microsoft PC Manager\MSPCManager.exe --Source=Auto --Activate=False (2024/02/12) (sign: 'Microsoft')
O4 - HKLM\..\StartupApproved\Run32: [AcronisTibMounterMonitor] = C:\Program Files (x86)\Common Files\Acronis\TibMounter\tib_mounter_monitor.exe (2023/07/03) (sign: 'Acronis International GmbH')
O4 - HKLM\..\StartupApproved\Run32: [AdobeCS6ServiceManager] = C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe -launchedbylogin (2023/02/27) (sign: 'Adobe Systems Incorporated')
O4 - HKLM\..\StartupApproved\Run32: [PWRISOVM.EXE] = C:\Program Files\PowerISO\PWRISOVM.EXE -startup (2021/05/30) (sign: 'Power Software Limited')
O4 - HKLM\..\StartupApproved\Run32: [SwitchBoard] = C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (2023/02/27) (invalid sign: CERT_E_CHAINING - Adobe Systems Incorporated - 679F13F7B14613F3AD93E7CBC04D1B5241741723)
O4 - HKLM\..\StartupApproved\Run32: [TrueImageMonitor.exe] = C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (2021/05/17) (sign: 'Acronis International GmbH')
O4 - HKLM\..\StartupApproved\Run32: [vmware-tray.exe] = C:\Program Files (x86)\VMware\VMware Workstation\vmware-tray.exe (2021/05/18) (sign: 'VMware, Inc.')
O4 - HKU\S-1-5-19\..\StartupApproved\Run: [OneDriveSetup] = C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (2023/05/24) (sign: 'Microsoft')
O4 - HKU\S-1-5-20\..\StartupApproved\Run: [OneDriveSetup] = C:\Windows\SysWOW64\OneDriveSetup.exe /thfirstsetup (2023/05/24) (sign: 'Microsoft')
O4 - MountPoints2: HKCU\..\F\shell\AutoRun\command: (default) = F:\setup.exe (file missing)
O4-32 - HKLM\..\Run: [FxSound] = C:\Program Files (x86)\DFX\dfx.exe -startup (invalid sign: TRUST_E_BAD_DIGEST - no company - C955C7C09E673F01451BD3C69493A9A9FE871BF2)
O4-32 - HKLM\..\Run: [USB Security] = C:\Program Files (x86)\USB Disk Security\USBGuard.exe (sign: 'Lanzhou Itanium Software Technology Co., Ltd.')
O4-32 - HKLM\..\RunOnce: [ccleaner_update_helper] = C:\Program Files\CCleaner\ccleaner_update_helper.exe (sign: 'PIRIFORM SOFTWARE LIMITED')
O5 - Applet: C:\Windows\System32\plotman.cpl (sign: 'Autodesk, Inc.')
O5 - Applet: C:\Windows\System32\RTSnMg64.cpl (sign: 'Realtek Semiconductor Corp')
O5 - Applet: C:\Windows\System32\styleman.cpl (sign: 'Autodesk, Inc.')
O7 - KnownFolder: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders, {374DE290-123F-4565-9164-39C4925E467B} = Z:\E\indirilenlerim
O7 - KnownFolder: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, {374DE290-123F-4565-9164-39C4925E467B} = Z:\E\indirilenlerim
O7 - KnownFolder: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, Desktop = C:\Users\Alper\Desktop
O7 - KnownFolder: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, My Pictures = C:\Users\Alper\Pictures
O7 - KnownFolder: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders, Personal = C:\Users\Alper\Documents
O7 - Policy: (UAC) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System: [PromptOnSecureDesktop] = 0
O8 - Context menu item: HKCU\..\Internet Explorer\MenuExt\IDM ile indir: (default) = C:\Program Files (x86)\Internet Download Manager\IEExt.htm (not signed - no company - 1A49C5F7A98580F8002AC1D6115AB39CB753975B)
O8 - Context menu item: HKCU\..\Internet Explorer\MenuExt\Se&nd to OneNote: (default) = C:\Program Files (x86)\Microsoft Office\Root\Office16\ONBttnIE.dll (file missing)
O8 - Context menu item: HKCU\..\Internet Explorer\MenuExt\Tüm bağlantıları IDM ile indir: (default) = C:\Program Files (x86)\Internet Download Manager\IEGetAll.htm (not signed - no company - 6FF2653314DDAD254AD252B1867D0925B30BB196)
O10 - Unknown file in Winsock LSP: C:\Program Files (x86)\Bonjour\mdnsNSP.dll (sign: 'Apple Inc.')
O17 - DHCP DNS 1: 8.8.8.8 (Well-known DNS: Google)
O17 - DHCP DNS 2: 8.8.4.4 (Well-known DNS: Google)
O17 - HKLM\System\CCS\Services\Tcpip\..\{0006f2d4-b50f-4d7a-b865-9581653269a8}: [NameServer] = 8.8.4.4 (Well-known DNS: Google)
O17 - HKLM\System\CCS\Services\Tcpip\..\{0006f2d4-b50f-4d7a-b865-9581653269a8}: [NameServer] = 8.8.8.8 (Well-known DNS: Google)
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Program Files (x86)\Acronis\TrueImageHome\tishell64_25_10_39287.dll (sign: 'Acronis International GmbH')
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Program Files (x86)\Internet Download Manager\IDMShellExt64.dll (sign: 'Tonec Inc.')
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Users\Alper\AppData\Local\MEGAsync\ShellExtX64.dll (sign: 'Mega Limited')
O21 - HKLM\..\ShellIconOverlayIdentifiers\ - C:\Windows\system32\AcSignIcon.dll (sign: 'Autodesk, Inc.')
O22 - Task (.job): CCleanerCrashReporting.job - C:\Program Files\CCleaner\CCleanerBugReport.exe (sign: 'PIRIFORM SOFTWARE LIMITED')
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Google (empty)
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\HP (empty)
O22 - Tasks: (disabled) (update) \Microsoft\Windows\UpdateOrchestrator\Reboot_AC - C:\Windows\system32\MusNotification.exe /RunOnAC Reboot (sign: 'Microsoft')
O22 - Tasks: (disabled) (update) \Microsoft\Windows\UpdateOrchestrator\Reboot_Battery - C:\Windows\system32\MusNotification.exe /RunOnBattery Reboot (sign: 'Microsoft')
O22 - Tasks: (disabled) \Agent Activation Runtime\S-1-5-21-2353887585-3353250695-3115532236-1001 - C:\Windows\System32\AgentActivationRuntimeStarter.exe (sign: 'Microsoft')
O22 - Tasks: (disabled) \MEGA\MEGAsync Update Task S-1-5-21-2353887585-3353250695-3115532236-1001 - C:\Users\Alper\AppData\Local\MEGAsync\MEGAupdater.exe (sign: 'Mega Limited')
O22 - Tasks: (disabled) \Microsoft\Windows\Clip\LicenseImdsIntegration - C:\Windows\system32\fclip.exe (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\DetectHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},DetectHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Autopilot\RemediateHardwareChange - {62B2DD2C-F129-42EE-BF59-55D3FD21C215},RemediateHardwareChange - C:\Windows\System32\Autopilot.dll (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\Windows\system32\ProvTool.exe /turn 5 /source ProvRetryTask (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\Windows\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (sign: 'Microsoft')
O22 - Tasks: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\Windows\system32\usoclient.exe StartMaintenanceWork (sign: 'Microsoft')
O22 - Tasks: (disabled) CCleanerCrashReporting - C:\Program Files\CCleaner\CCleanerBugReport.exe --product 90 --send dumps|report --path "C:\Program Files\CCleaner\LOG" --programpath "C:\Program Files\CCleaner" --configpath "C:\Program Files\CCleaner\Setup" --guid "45617df3-f429-42df-809d-085bc182ec24" --version "6.14.10584" --silent (sign: 'PIRIFORM SOFTWARE LIMITED')
O22 - Tasks: (disabled) OneDrive Standalone Update Task-S-1-5-21-2353887585-3353250695-3115532236-500 - C:\Users\Alper\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (file missing)
O22 - Tasks: (disabled) SamsungMagician - C:\Program Files (x86)\Samsung\Samsung Magician\SamsungMagician.exe /AUTOHIDE (sign: 'Samsung Electronics Co., Ltd.')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:aeinv.dll -f:UpdateSoftwareInventoryW invsvc (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:aemarebackup.dll -f:BackupMareData (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\MareBackup - C:\Windows\system32\compattelrunner.exe -m:appraiser.dll -f:DoScheduledTelemetryRun (sign: 'Microsoft')
O22 - Tasks: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\Windows\system32\rundll32.exe C:\Windows\system32\PcaSvc.dll,PcaPatchSdbTask (sign: 'Microsoft')
O22 - Tasks: \GoogleSystem\GoogleUpdater\GoogleUpdaterTaskSystem129.0.6651.2{4EAD3ECD-1618-499C-B7D7-61C73A5A4094} - C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.2\updater.exe --wake --system (sign: 'Google LLC')
O22 - Tasks: \Mozilla\Firefox Default Browser Agent E7CF176E110C211B - C:\Program Files (x86)\Mozilla Firefox\default-browser-agent.exe do-task "E7CF176E110C211B" (sign: 'Mozilla Corporation')
O22 - Tasks: CCleaner Update - C:\Program Files\CCleaner\CCUpdate.exe (sign: 'PIRIFORM SOFTWARE LIMITED')
O22 - Tasks: CCleanerSkipUAC - Alper - C:\Program Files\CCleaner\CCleaner.exe $(Arg0) (sign: 'PIRIFORM SOFTWARE LIMITED')
O22 - Tasks: klcp_update - C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe /verysilent /update /freq=30 (not signed - no company - 745559FF74A560957B438DBD3287D1054A76B68B)
O22 - Tasks: MicrosoftEdgeUpdateTaskUserS-1-5-21-2353887585-3353250695-3115532236-1001Core - C:\Users\Alper\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /c (sign: 'Microsoft')
O22 - Tasks: MicrosoftEdgeUpdateTaskUserS-1-5-21-2353887585-3353250695-3115532236-1001UA - C:\Users\Alper\AppData\Local\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exe /ua /installsource scheduler (sign: 'Microsoft')
O22 - Tasks: OneDrive Standalone Update Task-S-1-5-21-1058129444-4087973727-844704433-500 - C:\Users\Alper\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (file missing)
O22 - Tasks: Opera scheduled assistant Autoupdate 1621283805 - C:\Users\Alper\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\Alper\AppData\Local\Programs\Opera\assistant" $(Arg0) (sign: 'Opera Software AS')
O22 - Tasks: Opera scheduled Autoupdate 1621283799 - C:\Users\Alper\AppData\Local\Programs\Opera\launcher.exe --scheduledautoupdate $(Arg0) (sign: 'Opera Software AS')
O23 - Service R2: Acronis Nonstop Backup Service - (afcdpsrv) - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (sign: 'Acronis International GmbH')
O23 - Service R2: Autodesk Desktop Licensing Service - (AdskLicensingService) - C:\Program Files (x86)\Common Files\Autodesk Shared\AdskLicensing\Current\AdskLicensingService\AdskLicensingService.exe (sign: 'Autodesk, Inc.')
O23 - Service R2: CCleaner Performance Optimizer Service - (CCleanerPerformanceOptimizerService) - C:\Program Files\CCleaner\CCleanerPerformanceOptimizerService.exe (sign: 'PIRIFORM SOFTWARE LIMITED')
O23 - Service R2: Everything - C:\Program Files\Everything\Everything.exe -svc (sign: 'voidtools')
O23 - Service R2: FlexNet Licensing Service - C:\Program Files (x86)\Common Files\Macrovision Shared\FlexNet Publisher\FNPLicensingService.exe (sign: 'Flexera Software LLC')
O23 - Service R2: Foxit PDF Reader Update Service - (FoxitReaderUpdateService) - C:\Program Files (x86)\Common Files\Foxit\Foxit PDF Reader\FoxitPDFReaderUpdateService.exe (sign: 'FOXIT SOFTWARE INC.')
O23 - Service R2: Microsoft Defender Core Service - (MDCoreSvc) - C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.24070.5-0\MpDefenderCoreService.exe (sign: 'Microsoft')
O23 - Service R2: NVIDIA Display Driver Service - (nvsvc) - C:\Windows\system32\nvvsvc.exe (sign: 'NVIDIA Corporation')
O23 - Service R2: NVIDIA Stereoscopic 3D Driver Service - (Stereo Service) - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (sign: 'NVIDIA Corporation')
O23 - Service R2: O&O Defrag - (OODefragAgent) - C:\Program Files\OO Software\Defrag\oodag.exe (sign: 'O&O Software GmbH')
O23 - Service R2: Quick Share - (Quick Share Service) - C:\Program Files\WindowsApps\SAMSUNGELECTRONICSCoLtd.SamsungQuickShare_1.7.55.0_x64__wyx1vj98g3asy\QuickShareService\QuickShareService.exe (not signed - no company - 8C391B31E8257D23A4D67E9D56CAF57FC8D17FC0)
O23 - Service R2: SAMSUNG Mobile Connectivity Service - (ss_conn_service) - C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe (sign: 'Samsung Electronics CO., LTD.')
O23 - Service R2: SAMSUNG Mobile Connectivity Service V2 - (ss_conn_service2) - C:\Program Files (x86)\Samsung\USB Drivers\28_ssconn2\conn\ss_conn_service2.exe (sign: 'Samsung Electronics Co., Ltd.')
O23 - Service R2: Stardock Groupy - (Groupy) - C:\Program Files (x86)\Stardock\Groupy\GroupySrv.exe (sign: 'STARDOCK SYSTEMS, INC.')
O23 - Service R2: TeraCopy Service - (TeraCopyService.exe) - C:\Program Files\TeraCopy\TeraCopyService.exe (sign: 'Code Sector')
O23 - Service R2: VMware DHCP Service - (VMnetDHCP) - C:\Windows\SysWOW64\vmnetdhcp.exe (sign: 'VMware, Inc.')
O23 - Service R2: VMware NAT Service - C:\Windows\SysWOW64\vmnat.exe (sign: 'VMware, Inc.')
O23 - Service R3: Intel(R) Security Assist - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe (not signed - Intel Corporation - 2CB81A3DD394504C855056DF869CC00470753AF3)
O23 - Service R3: Malwarebytes Service - (MBAMService) - C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (sign: 'Malwarebytes Inc.') (+safe mode)
O23 - Service S2: Google Güncelleme Hizmeti (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc (sign: 'Google LLC')
O23 - Service S2: GoogleUpdater InternalService 129.0.6651.2 (GoogleUpdaterInternalService129.0.6651.2) - (GoogleUpdaterInternalService129.0.6651.2) - C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.2\updater.exe --system --windows-service --service=update-internal (sign: 'Google LLC')
O23 - Service S2: GoogleUpdater Service 129.0.6651.2 (GoogleUpdaterService129.0.6651.2) - (GoogleUpdaterService129.0.6651.2) - C:\Program Files (x86)\Google\GoogleUpdater\129.0.6651.2\updater.exe --system --windows-service --service=update (sign: 'Google LLC')
O23 - Service S2: Intel(R) Security Assist Helper - (isaHelperSvc) - C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe (not signed - no company - E2CAAD27F718CB9FEF12AC616CBA3F3917FCF922)
O23 - Service S2: x827206 - C:\Windows\System32\svchost.exe -k DcomLaunch; "ServiceDll" = C:\Windows\System32\x827206.dat (file missing)
O23 - Service S3: Adobe SwitchBoard - (SwitchBoard) - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (invalid sign: CERT_E_CHAINING - Adobe Systems Incorporated - 679F13F7B14613F3AD93E7CBC04D1B5241741723)
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService) - (GoogleChromeElevationService) - C:\Program Files\Google\Chrome\Application\128.0.6613.85\elevation_service.exe (sign: 'Google LLC')
O23 - Service S3: Google Güncelleme Hizmeti (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc (sign: 'Google LLC')
O23 - Service S3: Intel(R) Capability Licensing Service TCP IP Interface - C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe (sign: 'Intel® Trusted Connect Service')
O23 - Service S3: Intel(R) Content Protection HECI Service - (cphs) - C:\Windows\SysWow64\IntelCpHeciSvc.exe (sign: 'Intel(R) pGFX')
O23 - Service S3: Mozilla Maintenance Service - (MozillaMaintenance) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (sign: 'Mozilla Corporation')
O23 - Service S3: wampapache - J:\wamp\bin\apache\apache2.2.22\bin\httpd.exe -k runservice (not signed - Apache Software Foundation - 01F83EE6059BE738299C38B68909A35767A24897)
O23 - Service S3: wampmysqld - J:\wamp\bin\mysql\mysql5.5.24\bin\mysqld.exe wampmysqld (not signed - no company - 8F342B0C613B67BBC4F717F1E5AD17CCD6BB4EBF)
O23 - Driver R: PowerISO Virtual Drive - C:\Windows\System32\Drivers\SCDEmu.SYS (sign: 'Power Software Limited')
O23 - Driver R: VMware virtual network driver (64-bit) - C:\Windows\system32\DRIVERS\VMNET.SYS (sign: 'Microsoft' - VMware, Inc.)
O23 - Driver R0: Acronis File Tracker Driver - (file_tracker) - C:\Windows\system32\DRIVERS\file_tracker.sys (sign: 'Acronis International GmbH')
O23 - Driver R0: Acronis Snapshots Manager - (snapman) - C:\Windows\system32\DRIVERS\snapman.sys (sign: 'Acronis International GmbH')
O23 - Driver R0: Acronis Storage Filter Management - (fltsrv) - C:\Windows\system32\DRIVERS\fltsrv.sys (+safe mode) (sign: 'Acronis International GmbH')
O23 - Driver R0: Acronis Volume Tracker - (volume_tracker) - C:\Windows\system32\DRIVERS\volume_tracker.sys (+safe mode) (sign: 'Acronis International GmbH')
O23 - Driver R0: Macrium Change Block Tracker - (mrcbt) - C:\Windows\system32\drivers\mrcbt.sys (sign: 'Microsoft' - Windows (R) Win 7 DDK provider)
O23 - Driver R0: mrigflt - C:\Windows\system32\drivers\mrigflt.sys (sign: 'Microsoft' - Windows (R) Win 7 DDK provider)
O23 - Driver R0: PxHlpa64 - C:\Windows\System32\Drivers\PxHlpa64.sys (+safe mode) (sign: 'Sonic Solutions')
O23 - Driver R0: VMware VMCI Bus Driver - (vmci) - C:\Windows\System32\drivers\vmci.sys (+safe mode) (sign: 'Microsoft' - VMware, Inc.)
O23 - Driver R0: vSockets Virtual Machine Communication Interface Sockets driver - (vsock) - C:\Windows\system32\DRIVERS\vsock.sys (+safe mode) (sign: 'Microsoft' - VMware, Inc.)
O23 - Driver R1: ngscan - C:\Windows\system32\DRIVERS\ngscan.sys (sign: 'Acronis International GmbH')
O23 - Driver R1: VMware Input Filter and Injection Driver (vmkbd) - (vmkbd3) - C:\Windows\system32\DRIVERS\vmkbd.sys (sign: 'VMware, Inc.')
O23 - Driver R2: Acronis File Protector Driver - (file_protector) - C:\Windows\system32\DRIVERS\file_protector.sys (sign: 'Acronis International GmbH')
O23 - Driver R2: Acronis TIB Mounter - (tib_mounter) - C:\Windows\system32\DRIVERS\tib_mounter.sys (sign: 'Acronis International GmbH')
O23 - Driver R2: Acronis Virtual File Driver - (virtual_file) - C:\Windows\system32\DRIVERS\virtual_file.sys (+safe mode) (sign: 'Acronis International GmbH')
O23 - Driver R2: BdDci Service - (BdDci) - C:\Windows\system32\DRIVERS\bddci.sys (sign: 'Bitdefender SRL')
O23 - Driver R2: IDMWFP - C:\Windows\system32\DRIVERS\idmwfp.sys (sign: 'Microsoft' - Tonec Inc.)
O23 - Driver R2: MBAMChameleon - (mbamchameleon) - C:\Windows\System32\Drivers\MbamChameleon.sys (sign: 'Microsoft' - Malwarebytes)
O23 - Driver R2: Mrvdp - C:\Windows\system32\drivers\mrvdp.sys (sign: 'Paramount Software UK Ltd')
O23 - Driver R2: Mrvmdk - C:\Windows\system32\drivers\mrvmdk.sys (sign: 'Microsoft' - Windows (R) Win 7 DDK provider)
O23 - Driver R2: VMware Bridge Protocol - (VMnetBridge) - C:\Windows\system32\DRIVERS\vmnetbridge.sys (+safe mode) (sign: 'Microsoft' - VMware, Inc.)
O23 - Driver R2: VMware hcmon - (hcmon) - C:\Windows\system32\DRIVERS\hcmon.sys (sign: 'VMware, Inc.')
O23 - Driver R2: VMware Virtual Ethernet Userif for VMnet - (VMnetuserif) - C:\Windows\system32\DRIVERS\vmnetuserif.sys (+safe mode) (sign: 'Microsoft' - VMware, Inc.)
O23 - Driver R2: VMware vmx86 - (vmx86) - C:\Windows\system32\DRIVERS\vmx86.sys (sign: 'Microsoft' - VMware, Inc.)
O23 - Driver R2: WiseFs - C:\Windows\WiseFs64.sys (sign: 'Microsoft' - no company)
O23 - Driver R3: DFX Audio Enhancer - (DFX12) - C:\Windows\system32\drivers\dfx12x64.sys (sign: 'Power Technology')
O23 - Driver R3: igfx - C:\Windows\system32\DRIVERS\igdkmd64.sys (sign: 'Microsoft' - Intel Corporation)
O23 - Driver R3: Intel(R) Management Engine Interface - (MEIx64) - C:\Windows\System32\drivers\TeeDriverW8x64.sys (sign: 'Intel Corporation - Embedded Subsystems and IP Blocks Group')
O23 - Driver R3: MBAMSwissArmy - C:\Windows\System32\Drivers\mbamswissarmy.sys (sign: 'Microsoft' - Malwarebytes)
O23 - Driver R3: nvlddmkm - C:\Windows\system32\DRIVERS\nvlddmkm.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: Service for NVIDIA High Definition Audio Driver - (NVHDA) - C:\Windows\system32\drivers\nvhda64v.sys (sign: 'NVIDIA Corporation')
O23 - Driver R3: Service for Realtek HD Audio (WDM) - (IntcAzAudAddService) - C:\Windows\system32\drivers\RTKVHD64.sys (sign: 'Realtek Semiconductor Corp')
O23 - Driver R3: VMware Virtual Ethernet Adapter Driver - (VMnetAdapter) - C:\Windows\system32\DRIVERS\vmnetadapter.sys (+safe mode) (sign: 'Microsoft' - VMware, Inc.)
O23 - Driver S3: @oem16.inf,%VBoxNetAdp6Service_Desc%;VirtualBox NDIS 6.0 Miniport Service - (VBoxNetAdp) - C:\Windows\system32\DRIVERS\VBoxNetAdp6.sys (+safe mode) (sign: 'Oracle Corporation')
O23 - Driver S3: @oem22.inf,%nvvad_WaveExtensible.SvcDesc%;NVIDIA Virtual Audio Device (Wave Extensible) (WDM) - (nvvad_WaveExtensible) - C:\Windows\system32\drivers\nvvad64v.sys (sign: 'NVIDIA Corporation')
O23 - Driver S3: Acronis TIB Manager - (tib) - C:\Windows\system32\DRIVERS\tib.sys (+safe mode) (sign: 'Acronis International GmbH')
O23 - Driver S3: Acronis Try&Decide filter - (tnd) - C:\Windows\system32\DRIVERS\tnd.sys (+safe mode) (sign: 'Acronis International GmbH')
O23 - Driver S3: AsrDrv101 - C:\Windows\SysWOW64\Drivers\AsrDrv101.sys (sign: 'ASROCK Incorporation')
O23 - Driver S3: DFX Audio Enhancer 11.1 - (DFX11_1) - C:\Windows\system32\drivers\dfx11_1x64.sys (sign: 'Power Technology')
O23 - Driver S3: Intel(R) Serial IO GPIO Controller Driver - (iaLPSSi_GPIO) - C:\Windows\System32\drivers\iaLPSSi_GPIO.sys (sign: 'Intel Corporation - Client Components Group')
O23 - Driver S3: Mrvhdx - C:\Windows\system32\drivers\mrvhdx.sys (sign: 'Microsoft' - Windows (R) Win 7 DDK provider)
O23 - Driver S3: SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.) - (ssudmdm) - C:\Windows\system32\DRIVERS\ssudmdm.sys (sign: 'Samsung Electronics CO., LTD.')
O23 - Driver S3: SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.) - (dg_ssudbus) - C:\Windows\system32\DRIVERS\ssudbus2.sys (+safe mode) (sign: 'Samsung Electronics CO., LTD.')
O23 - Driver S3: SliceDisk5 - C:\Program Files\A-FF Find and Mount\slicedisk-x64.sys (sign: 'OOO Sfera-Tehno')
O23 - Driver S3: VMware USB Client Driver - (vmusb) - C:\Windows\System32\drivers\vmusb.sys (sign: 'VMware, Inc.')
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service: 'VBoxNetAdp'
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service: 'VMnetAdapter'
O23 - Dependency: Microsoft Service Group 'NDIS' contains unknown service: 'VMnetuserif'
O26 - Debugger: HKLM\..\notepad.exe: [Debugger] = C:\Program Files\Notepad2\Notepad2.exe /z (not signed - no company - F8F9C191D37B643A20870AB8D0AF39780C4677FF)
O26 - Tools: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MyComputer\DefragPath (default) = C:\Program Files\OO Software\Defrag\oodcnt.exe
O27 - Account: (Bad profile) Folder is not referenced by any of user SIDs: C:\Users\Administrator
O27 - Account: (Bad profile) Folder is not referenced by any of user SIDs: C:\Users\Guest
O27 - Account: (Bad profile) Folder is not referenced by any of user SIDs: C:\Users\VarsayılanHesap
O27 - Account: (Bad profile) Folder is not referenced by any of user SIDs: C:\Users\WDAGUtilityAccount
--
End of file - Time spent: 43 sec. - 75038 bytes, CRC32: FFFFFFFF. Sign: ም鲐