O1 - Hosts: Reset contents to default
O1 - Hosts: 127.0.0.1 dns40.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns39.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns38.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns37.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns36.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns35.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns34.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns33.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns32.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns31.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns30.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns29.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns28.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns27.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns26.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns25.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns24.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns23.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns22.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns21.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns20.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns19.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns18.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns17.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns16.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns15.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns14.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns13.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns12.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns11.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns10.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns9.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns8.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns7.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns6.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns5.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns4.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns3.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns2.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns1.turktelekom.com.tr
O1 - Hosts: 127.0.0.1 dns0.turktelekom.com.tr
O1 - Hosts: 0.0.0.0 redshell.io www.redshell.io
O1 - Hosts: 0.0.0.0 api.redshell.io
O1 - Hosts: 0.0.0.0 treasuredata.com www.treasuredata.com
O1 - Hosts: 0.0.0.0 in.treasuredata.com
O1 - Hosts: 0.0.0.0 files.facepunch.com
O1 - Hosts: 0.0.0.0 gameanalytics.com
O1 - Hosts: 0.0.0.0 api.gameanalytics.com
O1 - Hosts: 0.0.0.0 rubick.gameanalytics.com
O4 - HKCU\..\StartupApproved\Run: [SandboxiePlus_AutoRun] = C:\Program Files\Sandboxie-Plus\SandMan.exe -autorun (2020/12/23)
O10 - Unknown file in Winsock LSP: C:\Windows\System32\winrnr.dll
O10 - Unknown file in Winsock LSP: C:\Windows\system32\NLAapi.dll
O10 - Unknown file in Winsock LSP: C:\Windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: C:\Windows\system32\pnrpnsp.dll
O10 - Unknown file in Winsock LSP: C:\Windows\system32\wshbth.dll
O18 - HKLM\Software\Classes\Protocols\Handler\about: [CLSID] = {3050F406-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll
O18 - HKLM\Software\Classes\Protocols\Handler\cdl: [CLSID] = {3DD53D40-7B8B-11D0-B013-00AA0059CE02} - C:\Windows\System32\urlmon.dll
O18 - HKLM\Software\Classes\Protocols\Handler\dvd: [CLSID] = {12D51199-0DB5-46FE-A120-47A3D7D937CC} - C:\Windows\System32\msvidctl.dll
O18 - HKLM\Software\Classes\Protocols\Handler\file: [CLSID] = {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\Windows\System32\urlmon.dll
O18 - HKLM\Software\Classes\Protocols\Handler\ftp: [CLSID] = {79EAC9E3-BAF9-11CE-8C82-00AA004BA90B} - C:\Windows\System32\urlmon.dll
O18 - HKLM\Software\Classes\Protocols\Handler\http: [CLSID] = {79EAC9E2-BAF9-11CE-8C82-00AA004BA90B} - C:\Windows\System32\urlmon.dll
O18 - HKLM\Software\Classes\Protocols\Handler\https: [CLSID] = {79EAC9E5-BAF9-11CE-8C82-00AA004BA90B} - C:\Windows\System32\urlmon.dll
O18 - HKLM\Software\Classes\Protocols\Handler\its: [CLSID] = {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll
O18 - HKLM\Software\Classes\Protocols\Handler\javascript: [CLSID] = {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll
O18 - HKLM\Software\Classes\Protocols\Handler\local: [CLSID] = {79EAC9E7-BAF9-11CE-8C82-00AA004BA90B} - C:\Windows\System32\urlmon.dll
O18 - HKLM\Software\Classes\Protocols\Handler\mailto: [CLSID] = {3050F3DA-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll
O18 - HKLM\Software\Classes\Protocols\Handler\mhtml: [CLSID] = {05300401-BCBC-11D0-85E3-00C04FD85AB4} - C:\Windows\System32\inetcomm.dll
O18 - HKLM\Software\Classes\Protocols\Handler\mk: [CLSID] = {79EAC9E6-BAF9-11CE-8C82-00AA004BA90B} - C:\Windows\System32\urlmon.dll
O18 - HKLM\Software\Classes\Protocols\Handler\ms-its: [CLSID] = {9D148291-B9C8-11D0-A4CC-0000F80149F6} - C:\Windows\System32\itss.dll
O18 - HKLM\Software\Classes\Protocols\Handler\res: [CLSID] = {3050F3BC-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll
O18 - HKLM\Software\Classes\Protocols\Handler\tbauth: [CLSID] = {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll
O18 - HKLM\Software\Classes\Protocols\Handler\tv: [CLSID] = {CBD30858-AF45-11D2-B6D6-00C04FBBDE6E} - C:\Windows\System32\msvidctl.dll
O18 - HKLM\Software\Classes\Protocols\Handler\vbscript: [CLSID] = {3050F3B2-98B5-11CF-BB82-00AA00BDCE0B} - C:\Windows\System32\mshtml.dll
O18 - HKLM\Software\Classes\Protocols\Handler\windows.tbauth: [CLSID] = {14654CA6-5711-491D-B89A-58E571679951} - C:\Windows\System32\tbauth.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\EnhancedStorageShell: Enhanced Storage Icon Overlay Handler Class - {D9144DCD-E998-4ECA-AB6A-DCD83CCBA16D} - C:\Windows\System32\EhStorShell.dll
O21 - HKLM\..\ShellIconOverlayIdentifiers\Offline Files: (no name) - {4E77131D-3629-431c-9818-C5679DC83E81} - C:\Windows\System32\cscui.dll
O22 - Task: (disabled) \Agent Activation Runtime\S-1-5-21-3356541362-1770980186-2827386571-1001 - C:\Windows\System32\AgentActivationRuntimeStarter.exe
O22 - Task: (disabled) \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Automated) - {CF2CF428-325B-48D3-8CA8-7633E36E5A32} - C:\Windows\system32\msdrm.dll
O22 - Task: (disabled) \Microsoft\Windows\AppID\PolicyConverter - C:\Windows\system32\appidpolicyconverter.exe
O22 - Task: (disabled) \Microsoft\Windows\AppID\VerifiedPublisherCertStoreCheck - C:\Windows\system32\appidcertstorecheck.exe
O22 - Task: (disabled) \Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup - C:\Windows\system32\rundll32.exe C:\Windows\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
O22 - Task: (disabled) \Microsoft\Windows\DeviceDirectoryClient\IntegrityCheck - {AE31B729-D5FD-401E-AF42-784074835AFE},-IntegrityCheck - C:\Windows\system32\DeviceDirectoryClient.dll
O22 - Task: (disabled) \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticResolver - C:\Windows\system32\DFDWiz.exe
O22 - Task: (disabled) \Microsoft\Windows\File Classification Infrastructure\Property Definition Sync - {2AE64751-B728-4D6B-97A0-B2DA2E7D2A3B} - C:\Windows\System32\srmclient.dll
O22 - Task: (disabled) \Microsoft\Windows\InstallService\WakeUpAndContinueUpdates - {0DC331EE-8438-49D5-A721-E10B937CE459} - C:\Windows\System32\InstallServiceTasks.dll
O22 - Task: (disabled) \Microsoft\Windows\InstallService\WakeUpAndScanForUpdates - {D5A04D91-6FE6-4FE4-A98A-FEB4500C5AF7} - C:\Windows\System32\InstallServiceTasks.dll
O22 - Task: (disabled) \Microsoft\Windows\LanguageComponentsInstaller\Uninstallation - {6F58F65F-EC0E-4ACA-99FE-FC5A1A25E4BE},Uninstall - C:\Windows\System32\LanguageComponentsInstaller.dll
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\Windows\system32\ProvTool.exe /turn 5 /source ProvRetryTask
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\Windows\system32\ProvTool.exe /turn 5 /source ContinueSessionTask
O22 - Task: (disabled) \Microsoft\Windows\Offline Files\Background Synchronization - {FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8} - C:\Windows\System32\cscui.dll
O22 - Task: (disabled) \Microsoft\Windows\Offline Files\Logon Synchronization - {FA3F3DD9-4C1A-456B-A8FA-C76EF3ED83B8},Logon - C:\Windows\System32\cscui.dll
O22 - Task: (disabled) \Microsoft\Windows\PushToInstall\LoginCheck - C:\Windows\system32\sc.exe start pushtoinstall login
O22 - Task: (disabled) \Microsoft\Windows\RecoveryEnvironment\VerifyWinRE - {89D1D0C2-A3CF-490C-ABE3-B86CDE34B047},VerifyWinRE - C:\Windows\System32\ReAgentTask.dll
O22 - Task: (disabled) \Microsoft\Windows\SharedPC\Account Cleanup - C:\Windows\System32\rundll32.exe C:\Windows\System32\Windows.SharedPC.AccountManager.dll,StartMaintenance
O22 - Task: (disabled) \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon - {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC},logon - C:\Windows\System32\sppcext.dll
O22 - Task: (disabled) \Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork - {B1AEBB5D-EAD9-4476-B375-9C3ED9F32AFC},network - C:\Windows\System32\sppcext.dll
O22 - Task: (disabled) \Microsoft\Windows\Storage Tiers Management\Storage Tiers Optimization - C:\Windows\system32\defrag.exe -c -h -g -# -m 8 -i 13500
O22 - Task: (disabled) \Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate - {17C82257-654E-4C47-8E23-DCA24EAA76A0} - C:\Windows\system32\sysmain.dll
O22 - Task: (disabled) \Microsoft\Windows\Sysmain\HybridDriveCacheRebalance - {D44377B8-1F2F-4FAA-9C8E-6C4AD2928E47} - C:\Windows\system32\sysmain.dll
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Reboot_AC - C:\Windows\system32\MusNotification.exe /RunOnAC RebootDialog
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Reboot_Battery - C:\Windows\system32\MusNotification.exe /RunOnBattery RebootDialog
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\Windows\system32\usoclient.exe StartMaintenanceWork
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work - C:\Windows\system32\usoclient.exe StartWork
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Work - C:\Windows\system32\usoclient.exe StartWork
O22 - Task: (disabled) \Microsoft\Windows\User Profile Service\HiveUploadTask - {BA677074-762C-444B-94C8-8C83F93F6605} - C:\Windows\system32\profsvc.dll
O22 - Task: (disabled) \Microsoft\Windows\Workplace Join\Automatic-Device-Join - C:\Windows\System32\dsregcmd.exe $(Arg0) $(Arg1) $(Arg2)
O22 - Task: (disabled) \Microsoft\Windows\Workplace Join\Device-Sync - {C662D912-E4D6-44A3-89A0-20550514951D},DeviceUpdate - C:\Windows\System32\dsregtask.dll
O22 - Task: (disabled) \Microsoft\Windows\Workplace Join\Recovery-Check - C:\Windows\System32\dsregcmd.exe /checkrecovery
O22 - Task: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\Windows\system32\rundll32.exe C:\Windows\system32\PcaSvc.dll,PcaPatchSdbTask
O22 - Task: (telemetry) \Microsoft\Windows\Application Experience\StartupAppTask - C:\Windows\system32\rundll32.exe Startupscan.dll,SusRunTask
O22 - Task: (telemetry) \Microsoft\Windows\Customer Experience Improvement Program\Consolidator - C:\Windows\System32\wsqmcons.exe
O22 - Task: (telemetry) \Microsoft\Windows\Customer Experience Improvement Program\UsbCeip - {C27F6B1D-FE0B-45E4-9257-38799FA69BC8},SYSTEM - C:\Windows\System32\usbceip.dll
O22 - Task: OneDrive Standalone Update Task-S-1-5-21-3356541362-1770980186-2827386571-500 - C:\Users\kingd\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (file missing)
O22 - Task: OneDrive Standalone Update Task-S-1-5-21-3559598970-2979608507-1717242270-500 - C:\Users\kingd\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (file missing)
O22 - Task: \Microsoft\Windows\Active Directory Rights Management Services Client\AD RMS Rights Policy Template Management (Manual) - {BF5CB148-7C77-4D8A-A53E-D81C70CF743C} - C:\Windows\system32\msdrm.dll
O22 - Task: \Microsoft\Windows\AppID\EDP Policy Manager - {DECA92E0-AF85-439E-9204-86679978DA08},EdpPolicyManager - C:\Windows\System32\AppLockerCsp.dll
O22 - Task: \Microsoft\Windows\Autochk\Proxy - C:\Windows\system32\rundll32.exe /d acproxy.dll,PerformAutochkOperations
O22 - Task: \Microsoft\Windows\Chkdsk\SyspartRepair - C:\Windows\system32\bcdboot.exe C:\Windows /sysrepair
O22 - Task: \Microsoft\Windows\DUSM\dusmtask - C:\Windows\System32\dusmtask.exe
O22 - Task: \Microsoft\Windows\Data Integrity Scan\Data Integrity Check And Scan - {DCFD3EA8-D960-4719-8206-490AE315F94F} - C:\Windows\System32\discan.dll
O22 - Task: \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan - {DCFD3EA8-D960-4719-8206-490AE315F94F},-Manual - C:\Windows\System32\discan.dll
O22 - Task: \Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery - {DCFD3EA8-D960-4719-8206-490AE315F94F},-CrashRecovery - C:\Windows\System32\discan.dll
O22 - Task: \Microsoft\Windows\Defrag\ScheduledDefrag - C:\Windows\system32\defrag.exe -c -h -o -$
O22 - Task: \Microsoft\Windows\Device Setup\Metadata Refresh - {23C1F3CF-C110-4512-ACA9-7B6174ECE888} - C:\Windows\System32\DeviceSetupManagerAPI.dll
O22 - Task: \Microsoft\Windows\Diagnosis\RecommendedTroubleshootingScanner - {AD08DCC2-4E35-4486-9D49-547CBD30942D} - C:\Windows\System32\MitigationClient.dll
O22 - Task: \Microsoft\Windows\Diagnosis\Scheduled - {C1F85EF8-BCC2-4606-BB39-70C523715EB3} - C:\Windows\System32\sdiagschd.dll
O22 - Task: \Microsoft\Windows\DirectX\DXGIAdapterCache - C:\Windows\system32\dxgiadaptercache.exe
O22 - Task: \Microsoft\Windows\DirectX\DirectXDatabaseUpdater - C:\Windows\system32\directxdatabaseupdater.exe
O22 - Task: \Microsoft\Windows\DiskCleanup\SilentCleanup - C:\Windows\system32\cleanmgr.exe /autoclean /d C:
O22 - Task: \Microsoft\Windows\DiskDiagnostic\Microsoft-Windows-DiskDiagnosticDataCollector - C:\Windows\system32\rundll32.exe dfdts.dll,DfdGetDefaultPolicyAndSMART
O22 - Task: \Microsoft\Windows\DiskFootprint\Diagnostics - C:\Windows\system32\disksnapshot.exe -z
O22 - Task: \Microsoft\Windows\DiskFootprint\StorageSense - {AB2A519B-03B0-43CE-940A-A73DF850B49A} - C:\Windows\system32\StorageUsage.dll
O22 - Task: \Microsoft\Windows\EDP\EDP App Launch Task - {61BCD1B9-340C-40EC-9D41-D7F1C0632F05},AppLaunch - C:\Windows\System32\edptask.dll
O22 - Task: \Microsoft\Windows\EDP\EDP Auth Task - {61BCD1B9-340C-40EC-9D41-D7F1C0632F05},ReAuth - C:\Windows\System32\edptask.dll
O22 - Task: \Microsoft\Windows\EDP\EDP Inaccessible Credentials Task - {61BCD1B9-340C-40EC-9D41-D7F1C0632F05},MissingCredentials - C:\Windows\System32\edptask.dll
O22 - Task: \Microsoft\Windows\EDP\StorageCardEncryption Task - {61BCD1B9-340C-40EC-9D41-D7F1C0632F05},SDCardEncryptionPolicy - C:\Windows\System32\edptask.dll
O22 - Task: \Microsoft\Windows\Feedback\Siuf\DmClient - C:\Windows\system32\dmclient.exe
O22 - Task: \Microsoft\Windows\Feedback\Siuf\DmClientOnScenarioDownload - C:\Windows\system32\dmclient.exe utcwnf
O22 - Task: \Microsoft\Windows\FileHistory\File History (maintenance mode) - {89917B7C-A1A6-11DF-8BF6-18A90531A85A} - C:\Windows\System32\fhtask.dll
O22 - Task: \Microsoft\Windows\Flighting\FeatureConfig\ReconcileFeatures - {59EECBFE-C2F5-4419-9B99-13FE05FF2675} - C:\Windows\System32\fcon.dll
O22 - Task: \Microsoft\Windows\Flighting\FeatureConfig\UsageDataFlushing - {99EFDAD1-0F11-4A6B-A702-4E1C37D1A3EF} - C:\Windows\System32\fcon.dll
O22 - Task: \Microsoft\Windows\Flighting\FeatureConfig\UsageDataReporting - {BBFCD054-8AAC-45DE-A1EB-7B246C9028AF} - C:\Windows\System32\fcon.dll
O22 - Task: \Microsoft\Windows\Flighting\OneSettings\RefreshCache - {E07647F7-AED2-48D9-9720-939BC24A8A3C} - C:\Windows\System32\wosc.dll
O22 - Task: \Microsoft\Windows\HelloFace\FODCleanupTask - C:\Windows\System32\WinBioPlugIns\FaceFodUninstaller.exe
O22 - Task: \Microsoft\Windows\USB\Usb-Notifications - {E05BE1C8-92A8-4757-B575-ACAECB4E6A40} - C:\Windows\System32\UsbTask.dll
O22 - Task: \Microsoft\Windows\UpdateOrchestrator\Report policies - C:\Windows\system32\usoclient.exe ReportPolicies
O22 - Task: \Microsoft\Windows\UpdateOrchestrator\Schedule Scan - C:\Windows\system32\usoclient.exe StartScan
O22 - Task: \Microsoft\Windows\UpdateOrchestrator\Schedule Scan Static Task - C:\Windows\system32\usoclient.exe StartScan
O22 - Task: \Microsoft\Windows\UpdateOrchestrator\USO_UxBroker - C:\Windows\system32\MusNotification.exe
O22 - Task: \Microsoft\Windows\UpdateOrchestrator\UpdateModelTask - C:\Windows\system32\usoclient.exe StartModelUpdates