Şimdi Ara

SİSTEM KONTROLU ve VİRÜS TEMİZLEME (25. sayfa)

Daha Fazla
Bu Konudaki Kullanıcılar: Daha Az
3 Misafir (1 Mobil) - 2 Masaüstü1 Mobil
5 sn
901
Cevap
23
Favori
32.232
Tıklama
Daha Fazla
İstatistik
  • Konu İstatistikleri Yükleniyor
7 oy
Öne Çıkar
Sayfa: önceki 2324252627
Sayfaya Git
Git
sonraki
Giriş
Mesaj
  • Anlıyorum.Sağlık olsun diyelim.

    Ortada formatlık bir durum yoktu. En azından son Fixlist işlemini yaptıktan sonra durumu görmeliydi.

    İyi günler.
  • Malware Removal kullanıcısına yanıt
    Teşekkürler

    İyi Günler...
  • Hocam merhabalar açtığım konuda istediğiniz logları yükledim. Açtığım konu buydu:https://forum.donanimhaber.com/baslangictaki-programlar-listesindeki-virus-mu-ss-li--142705018#142705018

    Loglar:

    SİSTEM KONTROLU ve VİRÜS TEMİZLEME
    SS'de görülen "Program" yazandan şüpheleniyorum. Kaynağı belli değil ve konumuna gidemiyorum. Korsan hiçbir yazılımı bilgisayarıma hiç yüklemedim.




  • quote:

    Orijinalden alıntı: eski_nesil

    Hocam merhabalar açtığım konuda istediğiniz logları yükledim. Açtığım konu buydu:https://forum.donanimhaber.com/baslangictaki-programlar-listesindeki-virus-mu-ss-li--142705018#142705018

    Loglar:https://dosya.co/yyquiud1if8r/eski_nesil.rar.html


    SS'de görülen "Program" yazandan şüpheleniyorum. Kaynağı belli değil ve konumuna gidemiyorum. Korsan hiçbir yazılımı bilgisayarıma hiç yüklemedim.
    Arkadaşım merhaba,

    Loglarınızı inceledim.

    Sisteminizde kafaya takacak hiçbir şey yok diyebilirim.
    Ancak,Farbar yazılımı ile birkaç silme işlemi yapılsa iyi olur derim. Ne dersiniz ?

    ------------

    İnternet Explorer tarayıcınızda rama motoru olarak yandex.com bilgisini görüyorum. Bunu kaldırıp düzeltmeniz yerinde olur. Ayarlar bölümünden yapabilirsiniz.

    ------------

    Gelelim bahsettiğiniz programlar bilgisine;

    C:\Users\Default User

    Varsayılan tüm kullanıcılar için oluşturulmuş bir bilgi bu. Zararlı ile uzaktan yakından bir ilgisi kesinlikle yok. Kafanız rahat olsun.

    Sistemde ubuntu yazılımı varsa senkrenizasyon sorunu ile ilgili de olabilir. Bununla ilgili sanırım aşağıdaki hatalar raporlanmış.Sonuçta dert edecek bir durum yok.

    quote:

    System errors:
    =============
    Error: (04/02/2020 10:20:53 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-EB9HHIE)
    Description: {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} sunucusu belirtilen zaman aşımı süresi içinde DCOM'a kayıt yaptıramadı.


    İyi akşamlar.




  • quote:

    Orijinalden alıntı: Malware Removal

    Arkadaşım merhaba,

    Loglarınızı inceledim.

    Sisteminizde kafaya takacak hiçbir şey yok diyebilirim.
    Ancak,Farbar yazılımı ile birkaç silme işlemi yapılsa iyi olur derim. Ne dersiniz ?

    ------------

    İnternet Explorer tarayıcınızda rama motoru olarak yandex.com bilgisini görüyorum. Bunu kaldırıp düzeltmeniz yerinde olur. Ayarlar bölümünden yapabilirsiniz.

    ------------

    Gelelim bahsettiğiniz programlar bilgisine;

    C:\Users\Default User

    Varsayılan tüm kullanıcılar için oluşturulmuş bir bilgi bu. Zararlı ile uzaktan yakından bir ilgisi kesinlikle yok. Kafanız rahat olsun.

    Sistemde ubuntu yazılımı varsa senkrenizasyon sorunu ile ilgili de olabilir. Bununla ilgili sanırım aşağıdaki hatalar raporlanmış.Sonuçta dert edecek bir durum yok.

    quote:

    System errors:
    =============
    Error: (04/02/2020 10:20:53 PM) (Source: DCOM) (EventID: 10010) (User: DESKTOP-EB9HHIE)
    Description: {4AA0A5C4-1B9B-4F2E-99D7-99C6AEC83474} sunucusu belirtilen zaman aşımı süresi içinde DCOM'a kayıt yaptıramadı.


    İyi akşamlar.

    Alıntıları Göster
    Hocam içime su serptiniz çok sağolun. Edge kullanmadığım için Yandex duruyor öylece.




  • Rica ederim.İyi akşamlar.
  • Hocam merhaba iyi forumlar ve iyi geceler. Daha önce bana yardım etmiştiniz, dizi izlediğim sitedeki bir reklamdan virüs vb. bir şey bulaştımı bilmiyorum ve içime kurt düştü yeniden birbirimize yardımcı olabilirsek çok sevinirim.
  • quote:

    Hocam merhaba iyi forumlar ve iyi geceler. Daha önce bana yardım etmiştiniz, dizi izlediğim sitedeki bir reklamdan virüs vb. bir şey bulaştımı bilmiyorum ve içime kurt düştü yeniden birbirimize yardımcı olabilirsek çok sevinirim.


    Ne gibi bir sorun yaşıyorsunuz ?
    Bir sorun olduğunu düşünüyorsanız Farbar loglarını gönderin bakalım..



    < Bu mesaj bu kişi tarafından değiştirildi Malware Removal -- 7 Nisan 2020; 0:28:54 >
  • Malware Removal kullanıcısına yanıt
    Buyrun hocam.




    Not: Hocam müsait olursam, bu gece olmazsam sabah yazacağınız şeye cevap vereceğim.



    < Bu mesaj bu kişi tarafından değiştirildi Guest-809FC2E19 -- 7 Nisan 2020; 1:53:46 >




  • quote:

    Orijinalden alıntı: Guest-809FC2E19

    Buyrun hocam.

    https://send.firefox.com/download/aa26a1c9526a22b6/#b3A-UigWMlyC17NS5-_G7Q


    Not: Hocam müsait olursam, bu gece olmazsam sabah yazacağınız şeye cevap vereceğim.
    Merhaba

    Bilgisayarınız temiz. Zararlı ve gıvır zıvır anlamında birşey yok.

    Ancak bazı küçük sorunlar için aşağıdakileri yapmanızı öneririm;

    ------------------------
    Flash belleğiniz varsa sisteme takılı olsun.
    Masaüstünde not defterini açın ve aşağıdaki çerçeve içerisindeki bilgileri kopyalayıp yapıştırın.
    Fixlist adı ile masaüstüne kaydedin.
    Farbar yazılımı da masaüstünde olsun.
    Farbar yazılımını açın ve FİX butonuna basın.
    Yazılım işlemi bitirene kadar bir şeye dokunmayın. Sistemi yeniden başlatabilir.
    Masaüstünde Fixlog dosyası oluşturacaktır. Dosyayı gönderin.

    quote:


    Start:
    CloseProcesses:
    CreateRestorePoint:
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
    FirewallRules: [{2A46F8C1-9D0C-44AD-8D21-27C91C82D844}] => (Allow) C:\Users\Oguzhan\AppData\Roaming\uTorrent Web\utweb.exe No File
    FirewallRules: [{051D2F59-7E23-459A-8650-077F71FF0541}] => (Allow) C:\Users\Oguzhan\AppData\Roaming\uTorrent Web\utweb.exe No File
    FirewallRules: [TCP Query User{6FD4FFEB-216E-4EE2-BE1F-B4A7354BFA33}C:\users\oguzhan\appdata\local\programs\opera\65.0.3467.78\opera.exe] => (Allow) C:\users\oguzhan\appdata\local\programs\opera\65.0.3467.78\opera.exe No File
    FirewallRules: [UDP Query User{84661AA1-227E-43CF-888E-34BA1A11F6ED}C:\users\oguzhan\appdata\local\programs\opera\65.0.3467.78\opera.exe] => (Allow) C:\users\oguzhan\appdata\local\programs\opera\65.0.3467.78\opera.exe No File
    FirewallRules: [TCP Query User{F832E0A2-FA3E-415A-B711-8553B79CB71F}C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.44\opera.exe] => (Allow) C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.44\opera.exe No File
    FirewallRules: [UDP Query User{C5EE8387-AFBD-4D58-8FBB-343B30073809}C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.44\opera.exe] => (Allow) C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.44\opera.exe No File
    FirewallRules: [{B20E4C05-E5AB-468D-A9D2-F8A1B7786416}] => (Block) C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.44\opera.exe No File
    FirewallRules: [{64147D5D-5B86-4C9E-977B-313FC3A3FAC3}] => (Block) C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.44\opera.exe No File
    FirewallRules: [TCP Query User{DC47EB54-D173-4150-877D-ADC1A3044BB0}C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.115\opera.exe] => (Allow) C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.115\opera.exe No File
    FirewallRules: [UDP Query User{BD9129AC-F865-4A8B-A8AF-6F4FC89CB792}C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.115\opera.exe] => (Allow) C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.115\opera.exe No File
    HKU\S-1-5-21-3630932007-2410629183-4264424998-1001\...\MountPoints2: {ed53128f-2dc5-11e9-8301-8434976ec124} - "E:\HiSuiteDownLoader.exe"
    EmptyTemp:
    cmd: ipconfig /flushdns
    CMD: Bitsadmin /Reset /Allusers


    ---------------------------------------------

    Sistemde aşağıdaki gibi bazı sorunlar raporlanmış.
    Bunları düzeltmek isterseniz,
    1- İşletim sistemi güncellemelerinizi kontrol edin ve güncelolduğundan emin olun.
    2- Gerekirse;
    Tweaking.com - Windows Repair Free/Pro
    www.tweaking.com
    Tweaking.com - Windows Repair Free/Pro
    https://www.tweaking.com/content/page/windows_repair_all_in_one.html


    Bu yazılımı sisteme indirip repair (onarma) bölümünü uygulayabilirsiniz.


    quote:


    ==================== Faulty Device Manager Devices ============

    Name: Microsoft Basic Display Adapter
    Description: Microsoft Basic Display Adapter
    Class Guid: {4d36e968-e325-11ce-bfc1-08002be10318}
    Manufacturer: (Standard display types)
    Service: BasicDisplay
    Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
    Resolution: Update the driver

    ------------------------------------------------------------------
    Service:
    Problem: : The drivers for this device are not installed. (Code 28)
    Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

    Hizmet:
    Sorun:: Bu aygıtın sürücüleri yüklenmemiş. (Kod 28)
    Çözüm: Bu aygıtın sürücülerini yüklemek için, Donanım Güncelleme sihirbazını başlatan "Sürücüyü Güncelle" ye tıklayın.

    PCI Device
    Ralink_RT3290_Bluetooth_01



    İyi günler.



    < Bu mesaj bu kişi tarafından değiştirildi Malware Removal -- 7 Nisan 2020; 17:21:9 >




  • quote:

    Orijinalden alıntı: Malware Removal

    Merhaba

    Bilgisayarınız temiz. Zararlı ve gıvır zıvır anlamında birşey yok.

    Ancak bazı küçük sorunlar için aşağıdakileri yapmanızı öneririm;

    ------------------------
    Flash belleğiniz varsa sisteme takılı olsun.
    Masaüstünde not defterini açın ve aşağıdaki çerçeve içerisindeki bilgileri kopyalayıp yapıştırın.
    Fixlist adı ile masaüstüne kaydedin.
    Farbar yazılımı da masaüstünde olsun.
    Farbar yazılımını açın ve FİX butonuna basın.
    Yazılım işlemi bitirene kadar bir şeye dokunmayın. Sistemi yeniden başlatabilir.
    Masaüstünde Fixlog dosyası oluşturacaktır. Dosyayı gönderin.

    quote:


    Start:
    CloseProcesses:
    CreateRestorePoint:
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
    FirewallRules: [{2A46F8C1-9D0C-44AD-8D21-27C91C82D844}] => (Allow) C:\Users\Oguzhan\AppData\Roaming\uTorrent Web\utweb.exe No File
    FirewallRules: [{051D2F59-7E23-459A-8650-077F71FF0541}] => (Allow) C:\Users\Oguzhan\AppData\Roaming\uTorrent Web\utweb.exe No File
    FirewallRules: [TCP Query User{6FD4FFEB-216E-4EE2-BE1F-B4A7354BFA33}C:\users\oguzhan\appdata\local\programs\opera\65.0.3467.78\opera.exe] => (Allow) C:\users\oguzhan\appdata\local\programs\opera\65.0.3467.78\opera.exe No File
    FirewallRules: [UDP Query User{84661AA1-227E-43CF-888E-34BA1A11F6ED}C:\users\oguzhan\appdata\local\programs\opera\65.0.3467.78\opera.exe] => (Allow) C:\users\oguzhan\appdata\local\programs\opera\65.0.3467.78\opera.exe No File
    FirewallRules: [TCP Query User{F832E0A2-FA3E-415A-B711-8553B79CB71F}C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.44\opera.exe] => (Allow) C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.44\opera.exe No File
    FirewallRules: [UDP Query User{C5EE8387-AFBD-4D58-8FBB-343B30073809}C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.44\opera.exe] => (Allow) C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.44\opera.exe No File
    FirewallRules: [{B20E4C05-E5AB-468D-A9D2-F8A1B7786416}] => (Block) C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.44\opera.exe No File
    FirewallRules: [{64147D5D-5B86-4C9E-977B-313FC3A3FAC3}] => (Block) C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.44\opera.exe No File
    FirewallRules: [TCP Query User{DC47EB54-D173-4150-877D-ADC1A3044BB0}C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.115\opera.exe] => (Allow) C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.115\opera.exe No File
    FirewallRules: [UDP Query User{BD9129AC-F865-4A8B-A8AF-6F4FC89CB792}C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.115\opera.exe] => (Allow) C:\users\oguzhan\appdata\local\programs\opera\66.0.3515.115\opera.exe No File
    HKU\S-1-5-21-3630932007-2410629183-4264424998-1001\...\MountPoints2: {ed53128f-2dc5-11e9-8301-8434976ec124} - "E:\HiSuiteDownLoader.exe"
    EmptyTemp:
    cmd: ipconfig /flushdns
    CMD: Bitsadmin /Reset /Allusers


    ---------------------------------------------

    Sistemde aşağıdaki gibi bazı sorunlar raporlanmış.
    Bunları düzeltmek isterseniz,
    1- İşletim sistemi güncellemelerinizi kontrol edin ve güncelolduğundan emin olun.
    2- Gerekirse;
    Tweaking.com - Windows Repair Free/Pro
    https://www.tweaking.com/content/page/windows_repair_all_in_one.html

    Bu yazılımı sisteme indirip repair (onarma) bölümünü uygulayabilirsiniz.


    quote:


    ==================== Faulty Device Manager Devices ============

    Name: Microsoft Basic Display Adapter
    Description: Microsoft Basic Display Adapter
    Class Guid: {4d36e968-e325-11ce-bfc1-08002be10318}
    Manufacturer: (Standard display types)
    Service: BasicDisplay
    Problem: : This device is not working properly because Windows cannot load the drivers required for this device. (Code 31)
    Resolution: Update the driver

    ------------------------------------------------------------------
    Service:
    Problem: : The drivers for this device are not installed. (Code 28)
    Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.

    Hizmet:
    Sorun:: Bu aygıtın sürücüleri yüklenmemiş. (Kod 28)
    Çözüm: Bu aygıtın sürücülerini yüklemek için, Donanım Güncelleme sihirbazını başlatan "Sürücüyü Güncelle" ye tıklayın.

    PCI Device
    Ralink_RT3290_Bluetooth_01



    İyi günler.

    Alıntıları Göster
    Dediğiniz işlemlerin ilk bölümünü aynen uyguladım ancak ikinci bölümdeki sorunları ben düzeltemiyorum hocam, microsoft basic display adapter denen gpu bileşeni ve laptopta tamamen kullanılmaz halde şuan, sürücüyü yüklediğim zaman bilgisayarı hiç bir şekilde kullanamıyor ve biosta tamamen bozuluyor o yüzden pek bulaşmıyorum o ekran kartı sürücüsü yükleme işine, şimdilik intel hd apusu yeterli benim için. Diğer bluetooh sürücüsüde sanırım sistemde yok çünkü daha önce sürücüsünü yüklememe rağmen kullanamamıştım.

    Fix logu vereyim en iyisi


    İyi akşamlar hocam.




  • quote:

    Orijinalden alıntı: Guest-809FC2E19

    Dediğiniz işlemlerin ilk bölümünü aynen uyguladım ancak ikinci bölümdeki sorunları ben düzeltemiyorum hocam, microsoft basic display adapter denen gpu bileşeni ve laptopta tamamen kullanılmaz halde şuan, sürücüyü yüklediğim zaman bilgisayarı hiç bir şekilde kullanamıyor ve biosta tamamen bozuluyor o yüzden pek bulaşmıyorum o ekran kartı sürücüsü yükleme işine, şimdilik intel hd apusu yeterli benim için. Diğer bluetooh sürücüsüde sanırım sistemde yok çünkü daha önce sürücüsünü yüklememe rağmen kullanamamıştım.

    Fix logu vereyim en iyisi
    https://send.firefox.com/download/9db6a08427794e64/#tkI_wTTkHGV2d-tzPwgpvw

    İyi akşamlar hocam.

    Alıntıları Göster
    Anladım.
    Fixlist işlemi başarılı olmuş. İlgili satırlar dahil 2.5 GB silme işlemi yapılmış.
    Komutlar yerine getirilmiş.

    --------

    Başka yapılabilecek bir işlem görmüyorum. Herhangi bir sorunuz var mı ?




  • quote:

    Orijinalden alıntı: Malware Removal

    Anladım.
    Fixlist işlemi başarılı olmuş. İlgili satırlar dahil 2.5 GB silme işlemi yapılmış.
    Komutlar yerine getirilmiş.

    --------

    Başka yapılabilecek bir işlem görmüyorum. Herhangi bir sorunuz var mı ?

    Alıntıları Göster
    Teşekkürler hocam. Bilgisayarda problem yoktu ama içimdeki korkuda gitti sayenizde yardım için çok teşekkür ederim.
  • Rica ederim,iyi günler.
  • Arkadaşlar Merhaba

    Garip bir virüs ile başım belada. Arama Barı olan her yere peşpeşe işaretler bırakıyo klavyeye dokunmadan durmuyo. PC yi kapatıp kitliyor bazen hiç bir işlem yaptırmıyor.
    Antivirüslerle tarama yaptığımda antivirüsleride kapatıp devre dışı bırakıyor. Konu sahibi arkadaşa ilgisinden dolayı şimdiden teşekkür ederim.

    Loglar bu şekilde.

    Addition

    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-04-2020
    Ran by Vacao (11-04-2020 17:46:38)
    Running from C:\Users\Vacao\Downloads
    Windows 7 Ultimate Service Pack 1 (X64) (2019-04-23 13:17:29)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-1050937798-2524932215-4036471439-500 - Administrator - Disabled)
    Guest (S-1-5-21-1050937798-2524932215-4036471439-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-1050937798-2524932215-4036471439-1002 - Limited - Enabled)
    Vacao (S-1-5-21-1050937798-2524932215-4036471439-1000 - Administrator - Enabled) => C:\Users\Vacao

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
    AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    µTorrent (HKU\S-1-5-21-1050937798-2524932215-4036471439-1000\...\uTorrent) (Version: 3.5.5.45608 - BitTorrent Inc.)
    3uTools (HKLM-x32\...\3uTools) (Version: 2.37.007 - ShangHai ZhangZheng Network Technology Co., Ltd.)
    Adobe Flash Player 32 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 32.0.0.344 - Adobe)
    AORUS ENGINE (HKLM-x32\...\AORUS ENGINE_is1) (Version: 1.6.0.0 - GIGABYTE Technology Co.,Inc.)
    Apple Mobile Device Support (HKLM\...\{6E93B248-22B6-48B2-A568-2E49C65B2EA4}) (Version: 13.5.0.20 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{A3985C05-7386-411F-A4BF-32A73F37EB44}) (Version: 2.6.3.1 - Apple Inc.)
    Apple Uygulama Desteği (32 Bit) (HKLM-x32\...\{6CF0CAEE-54B6-4D84-A055-3AF110F189D3}) (Version: 8.4 - Apple Inc.)
    Apple Uygulama Desteği (64 Bit) (HKLM\...\{8B127943-89E7-4691-A7A4-D05807920A84}) (Version: 8.4 - Apple Inc.)
    Bluetooth Win7 Suite (64) (HKLM\...\{230D1595-57DA-4933-8C4E-375797EBB7E1}) (Version: 7.2.0.65 - Atheros Communications)
    Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
    CCleaner (HKLM\...\CCleaner) (Version: 5.58 - Piriform)
    f.lux (HKU\S-1-5-21-1050937798-2524932215-4036471439-1000\...\Flux) (Version: - f.lux Software LLC)
    GOM Player (HKLM-x32\...\GOM Player) (Version: 2.3.43.5305 - GOM & Company)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 80.0.3987.163 - Google LLC)
    Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
    Grand Theft Auto V (HKLM-x32\...\Grand Theft Auto V_is1) (Version: 1.0.1180.1 - )
    Guek IPTV 1.0 sürümü (HKLM-x32\...\{27279B06-29DA-4268-A109-D9071177383D}_is1) (Version: 1.0 - Alptech Tecnology)
    iCloud (HKLM\...\{A3616230-EF97-44F3-83D3-1AE29DC639D3}) (Version: 7.18.0.22 - Apple Inc.)
    Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.5.0.1026 - Intel Corporation)
    iTunes (HKLM\...\{0020C944-CFA5-4B6A-948D-30C338906483}) (Version: 12.10.5.12 - Apple Inc.)
    Malwarebytes version 3.6.1.2711 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)
    Microsoft .NET Framework 4.7.2 (Türkçe) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1055) (Version: 4.7.03062 - Microsoft Corporation)
    Microsoft .NET Framework 4.8 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.8.03761 - Microsoft Corporation)
    Microsoft Office Professional 2013 - en-us (HKLM\...\ProfessionalRetail - en-us) (Version: 15.0.4420.1017 - Microsoft Corporation)
    Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
    Microsoft SkyDrive (HKU\S-1-5-21-1050937798-2524932215-4036471439-1000\...\SkyDriveSetup.exe) (Version: 16.4.6012.0828 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
    Microsoft Visual C++ 2017 Redistributable (x64) - 14.13.26020 (HKLM-x32\...\{7474cd6e-76cc-4257-837e-5b9261e526af}) (Version: 14.13.26020.0 - Microsoft Corporation)
    Microsoft Visual C++ 2017 Redistributable (x86) - 14.13.26020 (HKLM-x32\...\{5c045b7f-e561-4794-91f8-c6cda0893107}) (Version: 14.13.26020.0 - Microsoft Corporation)
    NVAPI Monitor plugin for NvContainer (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NvContainer.NvapiMonitor) (Version: 1.19 - NVIDIA Corporation) Hidden
    NVIDIA GeForce Experience 3.20.2.34 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.20.2.34 - NVIDIA Corporation)
    NVIDIA Grafik Sürücüsü 445.75 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 445.75 - NVIDIA Corporation)
    NVIDIA HD Ses Sürücüsü 1.3.38.26 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.38.26 - NVIDIA Corporation)
    NVIDIA PhysX Sistem Yazılımı 9.19.0218 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.19.0218 - NVIDIA Corporation)
    Office 15 Click-to-Run Extensibility Component (HKLM-x32\...\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
    Office 15 Click-to-Run Localization Component (HKLM-x32\...\{90150000-008C-0409-0000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
    Phoneboard 1.7.0 (HKLM\...\Phoneboard_is1) (Version: 1.7.0 - Phoneboard)
    ProtonVPN (HKLM-x32\...\{8725D84B-70EA-468D-A8F3-D175DA616B52}) (Version: 1.10.1 - ProtonVPN AG) Hidden
    ProtonVPN (HKLM-x32\...\ProtonVPN 1.10.1) (Version: 1.10.1 - ProtonVPN AG)
    ProtonVPNTap (HKLM-x32\...\{C23BCE3A-FD25-48BA-948E-2CE94576F983}) (Version: 1.0.1 - ProtonVPN AG)
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.31.1025.2010 - Realtek)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6235 - Realtek Semiconductor Corp.)
    Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
    Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
    Skype 8.49 sürümü (HKLM-x32\...\Skype_is1) (Version: 8.49 - Skype Technologies S.A.)
    Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation)
    TeamViewer (HKLM-x32\...\TeamViewer) (Version: 15.0.8397 - TeamViewer)
    TruckersMP Launcher 1.0.0.4 (HKLM\...\{A227B892-C548-4490-9C5D-DB341F8194A6}_is1) (Version: 1.0.0.4 - TruckersMP Team)
    VLC media player (HKLM\...\VLC media player) (Version: 3.0.8 - VideoLAN)
    Windscribe (HKLM-x32\...\{fa690e90-ddb0-4f0c-b3f1-136c084e5fc7}_is1) (Version: 1.83 Build 20 - Windscribe Limited)
    WinRAR 5.71 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
    World War Z (HKLM-x32\...\World War Z_is1) (Version: - )

    ==================== Custom CLSID (Whitelisted): ==============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    CustomCLSID: HKU\S-1-5-21-1050937798-2524932215-4036471439-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Vacao\AppData\Local\Microsoft\SkyDrive\16.4.6012.0828_1\amd64\SkyDriveShell64.dll (Microsoft Corporation -> Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-1050937798-2524932215-4036471439-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Vacao\AppData\Local\Microsoft\SkyDrive\16.4.6012.0828_1\amd64\SkyDriveShell64.dll (Microsoft Corporation -> Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-1050937798-2524932215-4036471439-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Vacao\AppData\Local\Microsoft\SkyDrive\16.4.6012.0828_1\amd64\SkyDriveShell64.dll (Microsoft Corporation -> Microsoft Corporation)
    CustomCLSID: HKU\S-1-5-21-1050937798-2524932215-4036471439-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Vacao\AppData\Local\Microsoft\SkyDrive\16.4.6012.0828_1\amd64\FileSyncApi64.dll (Microsoft Corporation -> Microsoft Corporation)
    ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
    ContextMenuHandlers1: [Atheros] -> {B8952421-0E55-400B-94A6-FA858FC0A39F} => C:\Program Files (x86)\Bluetooth Suite\BtvAppExt.dll [2011-03-13] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
    ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
    ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2020-03-22] (Apple Inc. -> Apple Inc.)
    ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
    ContextMenuHandlers3: [FTShellContext] -> {AFF81F7B-6942-40c4-AADA-7214EF7B6DD1} => C:\Program Files (x86)\Bluetooth Suite\ShellContextExt.dll [2011-03-13] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
    ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
    ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
    ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2020-03-18] (NVIDIA Corporation -> NVIDIA Corporation)
    ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
    ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
    ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)

    ==================== Codecs (Whitelisted) ====================

    ==================== Shortcuts & WMI ========================

    (The entries could be listed to be restored or removed.)

    WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\"::
    WMI:subscription\__EventFilter->BVTFilter::[Query => SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99]
    WMI:subscription\CommandLineEventConsumer->BVTConsumer::[CommandLineTemplate => cscript KernCap.vbs][WorkingDirectory => C:\\tools\\kernrate]

    ==================== Loaded Modules (Whitelisted) =============

    2019-04-28 16:54 - 2019-02-19 13:45 - 000025088 _____ () [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\BSL430.dll
    2019-04-28 16:54 - 2019-02-19 13:45 - 000225792 _____ () [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GvFireware.dll
    2019-04-23 16:28 - 2011-04-30 00:28 - 000059904 _____ () [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
    2019-07-02 09:41 - 2019-07-02 09:41 - 000152064 _____ () [File not signed] C:\Program Files (x86)\Proton Technologies\ProtonVPN\Resources\64-bit\SplitTunnel.dll
    2019-08-12 13:08 - 2019-08-12 13:08 - 000484352 _____ () [File not signed] C:\Program Files (x86)\Proton Technologies\ProtonVPN\x64\IPFilter.dll
    2019-05-18 01:51 - 2019-05-18 01:51 - 000172544 _____ () [File not signed] C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\b00e2b665b7f824d850fd83d6498be39\IsdiInterop.ni.dll
    2011-03-13 10:58 - 2011-03-13 10:58 - 000061088 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\AthCopyHook.dll
    2011-03-13 10:58 - 2011-03-13 10:58 - 000044704 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\BPP.DLL
    2011-03-13 10:58 - 2011-03-13 10:58 - 000043680 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\BTBIP.DLL
    2011-03-13 10:58 - 2011-03-13 10:58 - 000029856 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\BtFileStore.dll
    2011-03-13 10:58 - 2011-03-13 10:58 - 000030368 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\BtFileStoreOpp.dll
    2011-03-13 10:58 - 2011-03-13 10:58 - 000207520 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\BtObexFt.dll
    2011-03-13 10:58 - 2011-03-13 10:58 - 000208544 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\BTOBEXOP.dll
    2011-03-13 10:58 - 2011-03-13 10:58 - 000072352 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\goep.dll
    2011-03-13 10:58 - 2011-03-13 10:58 - 000078496 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\GOEP_bpp.DLL
    2011-03-13 10:58 - 2011-03-13 10:58 - 000073376 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\GOEP_SINGLE.DLL
    2011-03-13 10:58 - 2011-03-13 10:58 - 000079008 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\Handsfree.dll
    2011-03-13 10:58 - 2011-03-13 10:58 - 000119456 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\L2capLib.dll
    2011-03-13 10:59 - 2011-03-13 10:59 - 002233504 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\OutLookLib.dll
    2011-03-13 10:59 - 2011-03-13 10:59 - 000081056 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\RfcommLib.dll
    2011-03-13 10:59 - 2011-03-13 10:59 - 000066720 _____ (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\Sync.dll
    2019-04-28 16:54 - 2019-02-25 16:33 - 000154624 _____ (GIGA-BYTE TECHNOLOGY CO., LTD.) [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\yccV2.DLL
    2019-04-28 16:54 - 2019-02-19 13:45 - 000287744 _____ (GIGABYTE Technology Co.,Ltd.) [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GVBIOSLib.dll
    2019-04-28 16:54 - 2019-02-19 13:45 - 000628736 _____ (GIGABYTE Technology Co.,Ltd.) [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GvComW.dll
    2019-04-28 16:54 - 2019-02-19 13:45 - 000013312 _____ (GIGABYTE Technology Co.,Ltd.) [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GvCrypt.dll
    2019-04-28 16:54 - 2019-02-19 13:45 - 000439808 _____ (GIGABYTE Technology Co.,Ltd.) [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GVDisplay.dll
    2019-04-28 16:54 - 2019-02-19 13:45 - 000240640 _____ (GIGABYTE Technology Co.,Ltd.) [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GvIllumLib.dll
    2019-04-28 16:54 - 2019-02-19 13:45 - 000218112 _____ (GIGABYTE Technology Co.,Ltd.) [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GvOrderLib.dll
    2019-05-18 01:51 - 2019-05-18 01:51 - 000014336 _____ (Intel Corp.) [File not signed] C:\Windows\assembly\NativeImages_v2.0.50727_32\IAStorCommon\a9c87f9ce4594b26721b78181990ba11\IAStorCommon.ni.dll
    2019-04-23 16:28 - 2011-04-30 00:28 - 000062464 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgr.dll
    2019-04-23 16:28 - 2011-04-30 00:28 - 000184320 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorUIHelper.dll
    2019-04-23 16:28 - 2011-04-30 00:28 - 000140288 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorUtil.dll
    2019-04-23 16:28 - 2011-04-30 00:28 - 001318912 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IntelVisualDesign.dll
    2019-04-23 16:28 - 2011-04-30 00:19 - 000278528 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\ISDI.dll
    2019-04-23 16:28 - 2011-04-30 00:31 - 000007680 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\tr-TR\IAStorDataMgr.resources.dll
    2019-04-23 16:28 - 2011-04-30 00:31 - 000032768 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\tr-TR\IAStorIcon.resources.dll
    2019-04-23 16:28 - 2011-04-30 00:31 - 000004608 _____ (Intel Corporation) [File not signed] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\tr-TR\IntelVisualDesign.resources.dll
    2019-04-23 16:26 - 2019-04-23 16:26 - 001655296 _____ (Microsoft Corporation) [File not signed] C:\Windows\WinSxS\amd64_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_8444db7d32915e4c\MFC80U.DLL
    2019-04-23 16:26 - 2019-04-23 16:26 - 001093120 _____ (Microsoft Corporation) [File not signed] C:\Windows\WinSxS\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\MFC80U.DLL
    2020-01-11 20:31 - 2020-01-11 20:31 - 000225280 _____ (Microsoft Corporation) [File not signed] C:\Windows\WinSxS\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.6161_none_50934f2ebcb7eb57\msvcm90.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 000026112 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qico.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 000020992 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\imageformats\qsvg.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 001181184 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\platforms\qwindows.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 005010944 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Core.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 005139968 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Gui.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 002234880 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Network.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 002950144 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Qml.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 003084800 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Quick.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 000259584 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Svg.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 004571648 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5Widgets.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 000438272 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\Qt5WinExtras.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQml\Models.2\modelsplugin.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick.2\qtquick2plugin.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 000729088 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Controls\qtquickcontrolsplugin.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 000179712 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Dialogs\dialogplugin.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 000073216 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Layouts\qquicklayoutsplugin.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 000101888 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\PrivateWidgets\widgetsplugin.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 000014848 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\QtQuick\Window.2\windowplugin.dll
    2020-04-11 17:13 - 2018-12-04 15:29 - 000124928 _____ (The Qt Company Ltd.) [File not signed] C:\Program Files\Malwarebytes\Anti-Malware\styles\qwindowsvistastyle.dll
    2019-04-28 16:54 - 2018-06-14 15:14 - 002134016 _____ (TODO: <Company name>) [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GLedApi.DLL
    2019-04-28 16:54 - 2019-02-19 13:45 - 000183296 _____ (TODO: <Company name>) [File not signed] C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\GvAutoUpdate.dll

    ==================== Alternate Data Streams (Whitelisted) ========

    ==================== Safe Mode (Whitelisted) ==================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

    ==================== Association (Whitelisted) =================

    ==================== Internet Explorer trusted/restricted ==========

    ==================== Hosts content: =========================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2020-04-05 02:29 - 2020-04-05 02:29 - 000000824 _____ C:\Windows\system32\drivers\etc\hosts

    ==================== Other Areas ===========================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-1050937798-2524932215-4036471439-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Vacao\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 192.168.1.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (If an entry is included in the fixlist, it will be removed.)

    MSCONFIG\startupreg: CCleaner Smart Cleaning => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
    MSCONFIG\startupreg: DAEMON Tools Ultra Agent => "C:\Program Files\DAEMON Tools Ultra\DTAgent.exe" -autorun
    MSCONFIG\startupreg: iCloudServices => "C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe"
    MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"
    MSCONFIG\startupreg: Skype for Desktop => C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe
    MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\steam.exe" -silent
    MSCONFIG\startupreg: uTorrent => "C:\Users\Vacao\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
    MSCONFIG\startupreg: Windscribe => "C:\Program Files (x86)\Windscribe\Windscribe.exe" -os_restart

    ==================== FirewallRules (Whitelisted) ================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{0E296314-DBA9-43BD-A3EA-798F46C46F19}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
    FirewallRules: [{C74EF6EF-20DF-46C4-B048-3188BB3D3103}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
    FirewallRules: [TCP Query User{201264FF-C6BC-4BF2-B24C-2B64C4AD3827}C:\program files (x86)\windscribe\wsappcontrol.exe] => (Allow) C:\program files (x86)\windscribe\wsappcontrol.exe (Windscribe Limited -> Windscribe Limited)
    FirewallRules: [UDP Query User{66F4021C-FA12-44AF-95AA-D5D5AD1D756E}C:\program files (x86)\windscribe\wsappcontrol.exe] => (Allow) C:\program files (x86)\windscribe\wsappcontrol.exe (Windscribe Limited -> Windscribe Limited)
    FirewallRules: [{710B89A2-4276-4D58-9136-D2046F0BB4B5}] => (Allow) C:\Users\Vacao\AppData\Roaming\uTorrent\uTorrent.exe No File
    FirewallRules: [{8A974E9D-C263-4D29-9B23-9EC7BBFC6406}] => (Allow) C:\Users\Vacao\AppData\Roaming\uTorrent\uTorrent.exe No File
    FirewallRules: [TCP Query User{5FBF5ABB-55DE-48D6-9CDB-C60C98FD0D02}C:\program files (x86)\world war z\en_us\client\bin\pc\wwzretailegs.exe] => (Allow) C:\program files (x86)\world war z\en_us\client\bin\pc\wwzretailegs.exe (Saber Interactive) [File not signed]
    FirewallRules: [UDP Query User{74A1E630-4300-426F-A025-88BCC549DE36}C:\program files (x86)\world war z\en_us\client\bin\pc\wwzretailegs.exe] => (Allow) C:\program files (x86)\world war z\en_us\client\bin\pc\wwzretailegs.exe (Saber Interactive) [File not signed]
    FirewallRules: [TCP Query User{45CED103-AE5A-4063-813B-F6ADCE8454CE}C:\program files (x86)\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\grand theft auto v\gta5.exe (Rockstar Games) [File not signed]
    FirewallRules: [UDP Query User{E095DAA4-4AC6-4B7A-A582-E63BD5EA90E5}C:\program files (x86)\grand theft auto v\gta5.exe] => (Allow) C:\program files (x86)\grand theft auto v\gta5.exe (Rockstar Games) [File not signed]
    FirewallRules: [{0C7261A9-6E98-4DF3-AF32-B710FBC5B11F}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
    FirewallRules: [{81D7B8B3-186D-4439-B946-2221CBD20DED}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe (Valve -> Valve Corporation)
    FirewallRules: [{8B04E4AD-84A0-44C7-87F8-72E03A120E28}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
    FirewallRules: [{9013DA8C-1321-4432-8074-34654651B5D8}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
    FirewallRules: [{3FA0172F-C009-477E-B72F-9309039E5C06}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
    FirewallRules: [{147530AE-AA2E-41A3-B692-D83505F70670}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
    FirewallRules: [{6ABAD22E-2649-4BEF-B205-88B643BAEAB8}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
    FirewallRules: [{CAF41EC3-AC43-463B-A657-B9A42724E7C9}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe (Valve -> Valve Corporation)
    FirewallRules: [{351E6F28-ADCD-427A-B01A-8E6B5C847904}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{FEF67CC4-D32F-4043-A6A4-687F2D8F6AFC}] => (Allow) C:\Program Files (x86)\Microsoft\Skype for Desktop\Skype.exe (Skype Software Sarl -> Skype Technologies S.A.)
    FirewallRules: [{A610A44E-4BE3-488E-A805-AB1F0D5813CA}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Europa Universalis IV\eu4.exe (Paradox Interactive AB (publ) -> Paradox Interactive)
    FirewallRules: [{9CE1851C-00B4-451A-B680-00F3AD9E9FFF}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Europa Universalis IV\eu4.exe (Paradox Interactive AB (publ) -> Paradox Interactive)
    FirewallRules: [{6AF5BDFF-EB8E-4E1B-8751-D4B93903A432}] => (Allow) C:\Program Files (x86)\3uTools\libXunlei\Download\MiniThunderPlatform.exe (ShenZhen Thunder Networking Technologies Ltd. -> 深圳市迅雷网络技术有限公司)
    FirewallRules: [{D82120B2-D1F6-4D1F-8A2C-33A1639371C6}] => (Allow) C:\Program Files (x86)\3uTools\libXunlei\Download\MiniThunderPlatform.exe (ShenZhen Thunder Networking Technologies Ltd. -> 深圳市迅雷网络技术有限公司)
    FirewallRules: [{1475EAD4-C393-47BC-8950-E0039A30B4A8}] => (Allow) LPort=80
    FirewallRules: [TCP Query User{0402C77A-849F-4929-B5FE-E8E226343EBA}C:\users\vacao\downloads\ultrasurf-1902\utmp\u.exe] => (Block) C:\users\vacao\downloads\ultrasurf-1902\utmp\u.exe (Ultrareach Internet Corp. -> )
    FirewallRules: [UDP Query User{3064EFB0-2762-44FA-88C4-5B905672CCE6}C:\users\vacao\downloads\ultrasurf-1902\utmp\u.exe] => (Block) C:\users\vacao\downloads\ultrasurf-1902\utmp\u.exe (Ultrareach Internet Corp. -> )
    FirewallRules: [{6121A0C0-9EF3-4B5B-810B-46E51AC5292E}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Europa Universalis IV\dowser.exe (Paradox Interactive Ab (Publ) -> )
    FirewallRules: [{BDF10784-626F-4448-8DE1-B6B75CAD3D57}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Europa Universalis IV\dowser.exe (Paradox Interactive Ab (Publ) -> )
    FirewallRules: [TCP Query User{60AA6E9B-3141-45F8-9D29-91225DB5FB8B}C:\program files (x86)\3utools\3uairplayer.exe] => (Block) C:\program files (x86)\3utools\3uairplayer.exe (ShangHai ZhangZheng Network Technology Co., Ltd. -> ShangHai ZhangZheng Network Technology Co., Ltd.)
    FirewallRules: [UDP Query User{F369B7F4-6392-4021-9188-2FCEC224032F}C:\program files (x86)\3utools\3uairplayer.exe] => (Block) C:\program files (x86)\3utools\3uairplayer.exe (ShangHai ZhangZheng Network Technology Co., Ltd. -> ShangHai ZhangZheng Network Technology Co., Ltd.)
    FirewallRules: [TCP Query User{0466A1C7-5A1E-4328-BA00-8C25C43CCE5E}C:\program files (x86)\windscribe\wsappcontrol.exe] => (Block) C:\program files (x86)\windscribe\wsappcontrol.exe (Windscribe Limited -> Windscribe Limited)
    FirewallRules: [UDP Query User{DE98DC32-09E5-4E2F-8EBA-EF78B3B3D58A}C:\program files (x86)\windscribe\wsappcontrol.exe] => (Block) C:\program files (x86)\windscribe\wsappcontrol.exe (Windscribe Limited -> Windscribe Limited)
    FirewallRules: [{F5A1A190-CF13-4A2B-A943-3A23CAE0E5BB}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{78F57F71-CD70-4C01-982A-1E31C8A9207C}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{4F96009F-99B1-45CE-8B93-56280AB894CB}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{08AA9FFD-C627-431D-AD6D-6C1BDB6ECFCD}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{1FBA178C-EB9E-427B-9413-C3EFC57A1546}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{CEA8D2C8-7024-4C89-B01A-6059DE760C48}] => (Allow) LPort=27015
    FirewallRules: [{182AFA00-18C8-4071-88AA-10B0D2C758B6}] => (Allow) C:\Program Files\iTunes\iTunes.exe (Apple Inc. -> Apple Inc.)
    FirewallRules: [{12ACBB31-7321-4EA4-BF8A-B8F07191E02C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer Germany GmbH)
    FirewallRules: [{79C6801C-E4CC-4C01-BAD3-01806350326C}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer GmbH -> TeamViewer Germany GmbH)
    FirewallRules: [{3804E3D6-A023-4C35-9606-2076DA00D337}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer Germany GmbH)
    FirewallRules: [{F8425ADB-8D88-4394-8B0A-45C388EF8108}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer GmbH -> TeamViewer Germany GmbH)
    FirewallRules: [{EDB33023-0210-4780-B110-943B00BE08D6}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
    FirewallRules: [{35F230FF-16CC-46A2-8E33-265D2D4CB9B8}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe (NVIDIA Corporation -> NVIDIA Corporation)
    FirewallRules: [{8C86290D-BA17-40A9-BBC8-4B18FD60C50F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
    FirewallRules: [{4F3C1F87-1B23-4CF4-A595-D1391887C9DC}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe (NVIDIA Corporation -> NVIDIA Corporation)
    FirewallRules: [{3B5C40C3-D961-4A6D-B209-A3226A20313F}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
    FirewallRules: [{194064E6-19F8-4E31-96E7-08ADA4C1AA15}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x64\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
    FirewallRules: [{B60403C4-3714-438F-9823-51251ED55922}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
    FirewallRules: [{07963D09-E543-46CC-9ED9-E34A44B84B45}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\Euro Truck Simulator 2\bin\win_x86\eurotrucks2.exe (SCS Software s.r.o. -> SCS Software)
    FirewallRules: [{CDFD28DB-5329-42A4-AEFE-B9E10770D4AE}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
    FirewallRules: [{C8FEF63D-C43A-4E46-AC2E-F8ADD7730EB7}] => (Allow) C:\Users\Vacao\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe (Microsoft Corporation -> Microsoft Corporation)
    FirewallRules: [{0A9E4713-A66A-4F15-9DB4-D1FBE3A2A743}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)

    ==================== Restore Points =========================

    24-03-2020 13:52:38 Windows Update
    29-03-2020 02:05:18 Windows Update
    01-04-2020 19:22:54 Windows Update
    04-04-2020 20:33:10 Windows Update
    11-04-2020 12:40:32 Windows Update
    11-04-2020 15:15:31 Windows Update

    ==================== Faulty Device Manager Devices ============

    Name: ASUS Bluetooth
    Description: ASUS Bluetooth
    Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
    Manufacturer: Atheros Communications
    Service: BTHUSB
    Problem: : This device is disabled. (Code 22)
    Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

    Name: G19 Gaming Keyboard (Display interface)
    Description: G19 Gaming Keyboard (Display interface)
    Class Guid:
    Manufacturer:
    Service:
    Problem: : The drivers for this device are not installed. (Code 28)
    Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


    ==================== Event log errors: ========================

    Application errors:
    ==================
    Error: (04/11/2020 05:21:39 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: NT AUTHORITY)
    Description: Kayıt defterinde performans sayaç açıklama metni dizesinin değeri hatalı biçimlendirilmiş. Hatalı dize; ﮅ鏫쒝쯕큏蓘ጬꊹᬎ塚෥Ꞩℐﬖ쇲흂뷊坯䀢敬ﯛ딾벪础溷폀ࣷ䄩ẃࡹ撦㱗⁅紌嘥㳯쌘Ⴕ挅ᘅ礩暷⦋ﳝ桟姴쪻瀠⼆㞦��oꍄ婀됯濳毡ꝥ䍄귝�∦ᵏ毠ᵩ頿ⅺ™焬᧎䟺Ӟ⢢骯귘ᖮ偂鉴䘀ᵢ倧㛻‌ꕚ۟讓溂ﶵ咩֡ꭱ怟ꦭХ⥇꫻㯼旰卨眖읞鯻惐࿄Ѭꟲ䗠㞻윴靠턂שׂ殅赑뽚镥됵ᲂẴ讜ﶌ把⧈낮쟰餺擫♖㊙㲔䧣鋫∈衦閸ꁐ҄ꚪ螗贪⢖粓꧳揧껞婓㲒髦?᫱醡䟪耢ஃ廥뿙兪୪윹⊏쿸㩏⫟⠣䓂ܴ첚얂绝⮕፩g墘굶丌齢匰魢䎏㶵䕨엋뼾ྛ鹢뻤⿍펥睹ᒬ쎫폶쮈潡픬⭜ڣ띻龼흸ﱘ鱮끌恸饶紟㛷∏䭚旾젌㨆䆝ᅵ郞钉᪻湯癬Ҏ牴粒葺䂙ಧ鐵亶蚡镯꽾誡⟤뺺ㆺ뤔㓸쮬떲㥈�䆛텋ỳ邋章᭥�쭇⸉큗턹⢀䙵븀쪜创�鐮렮簎죥윝䵾葷픁㼣ਊ쌲ㅪ塋昜�ႏ쫸⚈폑䟼૒鐒櫍倴⏂팔妚淪䷎౮颟?ꒃ�암ळ怀꼸䂉횇盺毨樖탾泌ྥ퇔家ࡱ猿ꇥ䞝즹ᙤ孿竒㙣튁£嵝Ⱖ젢傠䒑᮲픨⭏몡岃퓕륈睶먝뾰㙀계擾␶闤粊ඍ不易粎遽ꪁ屣诲㔔듘盢ྞ聎⍥罭誎Ⲧ諟뎹⯽趣Ⴁ⺯ꥹᗟ�룉紃굃꽄謡᭡萏⥂楔䃪ၼ∢풧䭢畷襝?Ḿ켡퓫뜣䖱㛽舚೾吕?ᡩ鋁妀쾺႖䇜憧騗ᄄ뭎ڎ骬玈୐鼌␏ꙇ䤴澘⸂逗췔냄싲瀰进⽐︻齕ẑ曕㉨镳㚩Ჰ銫ꪩ縪鼽瑱ᕉ⤌⑂角锵샫짏⎣徝㋦쩎鴲꯬躚㝭㷱熢폧ඈ줇뺒ۇ휯�留嵎ㅗෂ䷶䟣着ⲓ»댁䞆뻰㎱됈訸댽䉝퀸猀㎅⪖版�㎪爤맨፹ⵜ୍ἳꀗ橥팓ჩ옙蝲﷖榮?᡽我앶䉵傪瘽⭄냝ꪝⳜ鍗ᮯਊ≅혂傑딚쏖張붺硚楟៰㾘鮾䤾ٞ펯볾ᩀ↻眳ܑ炸ë뒢᷎箉秮ꬋ丶쀍⁢츽箜෩抰ᒴ쥠ﺛ䅰䃸鬫㺦㶓論䀇ﭦⳊ埜趆옷챾㈥ᦝ圹ݑ癍ꘝ�L쁿뒿韁䅘遝�翾㓤䤉숗쫅䅢ษ覤눯䳯険区욫닓ᓼ逽볅䃑ෂ걌䅀黜깩려㘏䋮瓭ꪉꞧ�綖顁ᓌ몋䌈펚泘屹岳뎿땶윮সኞᐊ멭ᷤ࿇䀣㗨參䘇羟Ⴥ+뉓烲蒤ꮐ薿舲ိ빗师쏙앣淈ﺱ拽砛뱃좄へꪈ㕓嫱麧ⴭ㉅䂐䖇妝㮋⬇㬚뚉ꈐ뮚⨀뭎관츨䰚㿎貄䪍짞睦많㙏羧�紘癦ᾜ凲樟놨ꨣ╣鿤澋㨕��靑筘犔㈈ధ⏏띠䩉몉䡓끊聐촠�毀駯Ꮮ⃄�篡釳磳鳗콉狹趐᧮瓀蠍徫䪟閖桯╫웘㝩䅃ὧ맵切≸ꃶ躼䎁蝯ܒ찀챌廫衬�ᜉㆮ싶�厽品デ?꫶㪯㉵ﺃ炥챃ﶛᮗ睊䦅綾�㸰鏁䨆븱뙘쵪чⱷ櫹捷탠쌍﵎퐾춏㥻媞詁`䶣膇ࠇ蘀䀀㬁怃c. Veri bölümündeki ilk DWORD hatalı biçimlendirilmiş dizenin dizin değerini, veri bölümündeki ikinci ve üçüncü DWORD ise son geçerli dizin değerlerini içerir.

    Error: (04/11/2020 05:20:51 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: NT AUTHORITY)
    Description: Kayıt defterinde performans sayaç açıklama metni dizesinin değeri hatalı biçimlendirilmiş. Hatalı dize; ﮅ鏫쒝쯕큏蓘ጬꊹᬎ塚෥Ꞩℐﬖ쇲흂뷊坯䀢敬ﯛ딾벪础溷폀ࣷ䄩ẃࡹ撦㱗⁅紌嘥㳯쌘Ⴕ挅ᘅ礩暷⦋ﳝ桟姴쪻瀠⼆㞦��oꍄ婀됯濳毡ꝥ䍄귝�∦ᵏ毠ᵩ頿ⅺ™焬᧎䟺Ӟ⢢骯귘ᖮ偂鉴䘀ᵢ倧㛻‌ꕚ۟讓溂ﶵ咩֡ꭱ怟ꦭХ⥇꫻㯼旰卨眖읞鯻惐࿄Ѭꟲ䗠㞻윴靠턂שׂ殅赑뽚镥됵ᲂẴ讜ﶌ把⧈낮쟰餺擫♖㊙㲔䧣鋫∈衦閸ꁐ҄ꚪ螗贪⢖粓꧳揧껞婓㲒髦?᫱醡䟪耢ஃ廥뿙兪୪윹⊏쿸㩏⫟⠣䓂ܴ첚얂绝⮕፩g墘굶丌齢匰魢䎏㶵䕨엋뼾ྛ鹢뻤⿍펥睹ᒬ쎫폶쮈潡픬⭜ڣ띻龼흸ﱘ鱮끌恸饶紟㛷∏䭚旾젌㨆䆝ᅵ郞钉᪻湯癬Ҏ牴粒葺䂙ಧ鐵亶蚡镯꽾誡⟤뺺ㆺ뤔㓸쮬떲㥈�䆛텋ỳ邋章᭥�쭇⸉큗턹⢀䙵븀쪜创�鐮렮簎죥윝䵾葷픁㼣ਊ쌲ㅪ塋昜�ႏ쫸⚈폑䟼૒鐒櫍倴⏂팔妚淪䷎౮颟?ꒃ�암ळ怀꼸䂉횇盺毨樖탾泌ྥ퇔家ࡱ猿ꇥ䞝즹ᙤ孿竒㙣튁£嵝Ⱖ젢傠䒑᮲픨⭏몡岃퓕륈睶먝뾰㙀계擾␶闤粊ඍ不易粎遽ꪁ屣诲㔔듘盢ྞ聎⍥罭誎Ⲧ諟뎹⯽趣Ⴁ⺯ꥹᗟ�룉紃굃꽄謡᭡萏⥂楔䃪ၼ∢풧䭢畷襝?Ḿ켡퓫뜣䖱㛽舚೾吕?ᡩ鋁妀쾺႖䇜憧騗ᄄ뭎ڎ骬玈୐鼌␏ꙇ䤴澘⸂逗췔냄싲瀰进⽐︻齕ẑ曕㉨镳㚩Ჰ銫ꪩ縪鼽瑱ᕉ⤌⑂角锵샫짏⎣徝㋦쩎鴲꯬躚㝭㷱熢폧ඈ줇뺒ۇ휯�留嵎ㅗෂ䷶䟣着ⲓ»댁䞆뻰㎱됈訸댽䉝퀸猀㎅⪖版�㎪爤맨፹ⵜ୍ἳꀗ橥팓ჩ옙蝲﷖榮?᡽我앶䉵傪瘽⭄냝ꪝⳜ鍗ᮯਊ≅혂傑딚쏖張붺硚楟៰㾘鮾䤾ٞ펯볾ᩀ↻眳ܑ炸ë뒢᷎箉秮ꬋ丶쀍⁢츽箜෩抰ᒴ쥠ﺛ䅰䃸鬫㺦㶓論䀇ﭦⳊ埜趆옷챾㈥ᦝ圹ݑ癍ꘝ�L쁿뒿韁䅘遝�翾㓤䤉숗쫅䅢ษ覤눯䳯険区욫닓ᓼ逽볅䃑ෂ걌䅀黜깩려㘏䋮瓭ꪉꞧ�綖顁ᓌ몋䌈펚泘屹岳뎿땶윮সኞᐊ멭ᷤ࿇䀣㗨參䘇羟Ⴥ+뉓烲蒤ꮐ薿舲ိ빗师쏙앣淈ﺱ拽砛뱃좄へꪈ㕓嫱麧ⴭ㉅䂐䖇妝㮋⬇㬚뚉ꈐ뮚⨀뭎관츨䰚㿎貄䪍짞睦많㙏羧�紘癦ᾜ凲樟놨ꨣ╣鿤澋㨕��靑筘犔㈈ధ⏏띠䩉몉䡓끊聐촠�毀駯Ꮮ⃄�篡釳磳鳗콉狹趐᧮瓀蠍徫䪟閖桯╫웘㝩䅃ὧ맵切≸ꃶ躼䎁蝯ܒ찀챌廫衬�ᜉㆮ싶�厽品デ?꫶㪯㉵ﺃ炥챃ﶛᮗ睊䦅綾�㸰鏁䨆븱뙘쵪чⱷ櫹捷탠쌍﵎퐾춏㥻媞詁`䶣膇ࠇ蘀䀀㬁怃c. Veri bölümündeki ilk DWORD hatalı biçimlendirilmiş dizenin dizin değerini, veri bölümündeki ikinci ve üçüncü DWORD ise son geçerli dizin değerlerini içerir.

    Error: (04/11/2020 05:16:48 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: NT AUTHORITY)
    Description: Kayıt defterinde performans sayaç açıklama metni dizesinin değeri hatalı biçimlendirilmiş. Hatalı dize; ﮅ鏫쒝쯕큏蓘ጬꊹᬎ塚෥Ꞩℐﬖ쇲흂뷊坯䀢敬ﯛ딾벪础溷폀ࣷ䄩ẃࡹ撦㱗⁅紌嘥㳯쌘Ⴕ挅ᘅ礩暷⦋ﳝ桟姴쪻瀠⼆㞦��oꍄ婀됯濳毡ꝥ䍄귝�∦ᵏ毠ᵩ頿ⅺ™焬᧎䟺Ӟ⢢骯귘ᖮ偂鉴䘀ᵢ倧㛻‌ꕚ۟讓溂ﶵ咩֡ꭱ怟ꦭХ⥇꫻㯼旰卨眖읞鯻惐࿄Ѭꟲ䗠㞻윴靠턂שׂ殅赑뽚镥됵ᲂẴ讜ﶌ把⧈낮쟰餺擫♖㊙㲔䧣鋫∈衦閸ꁐ҄ꚪ螗贪⢖粓꧳揧껞婓㲒髦?᫱醡䟪耢ஃ廥뿙兪୪윹⊏쿸㩏⫟⠣䓂ܴ첚얂绝⮕፩g墘굶丌齢匰魢䎏㶵䕨엋뼾ྛ鹢뻤⿍펥睹ᒬ쎫폶쮈潡픬⭜ڣ띻龼흸ﱘ鱮끌恸饶紟㛷∏䭚旾젌㨆䆝ᅵ郞钉᪻湯癬Ҏ牴粒葺䂙ಧ鐵亶蚡镯꽾誡⟤뺺ㆺ뤔㓸쮬떲㥈�䆛텋ỳ邋章᭥�쭇⸉큗턹⢀䙵븀쪜创�鐮렮簎죥윝䵾葷픁㼣ਊ쌲ㅪ塋昜�ႏ쫸⚈폑䟼૒鐒櫍倴⏂팔妚淪䷎౮颟?ꒃ�암ळ怀꼸䂉횇盺毨樖탾泌ྥ퇔家ࡱ猿ꇥ䞝즹ᙤ孿竒㙣튁£嵝Ⱖ젢傠䒑᮲픨⭏몡岃퓕륈睶먝뾰㙀계擾␶闤粊ඍ不易粎遽ꪁ屣诲㔔듘盢ྞ聎⍥罭誎Ⲧ諟뎹⯽趣Ⴁ⺯ꥹᗟ�룉紃굃꽄謡᭡萏⥂楔䃪ၼ∢풧䭢畷襝?Ḿ켡퓫뜣䖱㛽舚೾吕?ᡩ鋁妀쾺႖䇜憧騗ᄄ뭎ڎ骬玈୐鼌␏ꙇ䤴澘⸂逗췔냄싲瀰进⽐︻齕ẑ曕㉨镳㚩Ჰ銫ꪩ縪鼽瑱ᕉ⤌⑂角锵샫짏⎣徝㋦쩎鴲꯬躚㝭㷱熢폧ඈ줇뺒ۇ휯�留嵎ㅗෂ䷶䟣着ⲓ»댁䞆뻰㎱됈訸댽䉝퀸猀㎅⪖版�㎪爤맨፹ⵜ୍ἳꀗ橥팓ჩ옙蝲﷖榮?᡽我앶䉵傪瘽⭄냝ꪝⳜ鍗ᮯਊ≅혂傑딚쏖張붺硚楟៰㾘鮾䤾ٞ펯볾ᩀ↻眳ܑ炸ë뒢᷎箉秮ꬋ丶쀍⁢츽箜෩抰ᒴ쥠ﺛ䅰䃸鬫㺦㶓論䀇ﭦⳊ埜趆옷챾㈥ᦝ圹ݑ癍ꘝ�L쁿뒿韁䅘遝�翾㓤䤉숗쫅䅢ษ覤눯䳯険区욫닓ᓼ逽볅䃑ෂ걌䅀黜깩려㘏䋮瓭ꪉꞧ�綖顁ᓌ몋䌈펚泘屹岳뎿땶윮সኞᐊ멭ᷤ࿇䀣㗨參䘇羟Ⴥ+뉓烲蒤ꮐ薿舲ိ빗师쏙앣淈ﺱ拽砛뱃좄へꪈ㕓嫱麧ⴭ㉅䂐䖇妝㮋⬇㬚뚉ꈐ뮚⨀뭎관츨䰚㿎貄䪍짞睦많㙏羧�紘癦ᾜ凲樟놨ꨣ╣鿤澋㨕��靑筘犔㈈ధ⏏띠䩉몉䡓끊聐촠�毀駯Ꮮ⃄�篡釳磳鳗콉狹趐᧮瓀蠍徫䪟閖桯╫웘㝩䅃ὧ맵切≸ꃶ躼䎁蝯ܒ찀챌廫衬�ᜉㆮ싶�厽品デ?꫶㪯㉵ﺃ炥챃ﶛᮗ睊䦅綾�㸰鏁䨆븱뙘쵪чⱷ櫹捷탠쌍﵎퐾춏㥻媞詁`䶣膇ࠇ蘀䀀㬁怃c. Veri bölümündeki ilk DWORD hatalı biçimlendirilmiş dizenin dizin değerini, veri bölümündeki ikinci ve üçüncü DWORD ise son geçerli dizin değerlerini içerir.

    Error: (04/11/2020 05:14:36 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3002) (User: NT AUTHORITY)
    Description: Kayıt defterinde performans sayaç açıklama metni dizesinin değeri hatalı biçimlendirilmiş. Hatalı dize; ﮅ鏫쒝쯕큏蓘ጬꊹᬎ塚෥Ꞩℐﬖ쇲흂뷊坯䀢敬ﯛ딾벪础溷폀ࣷ䄩ẃࡹ撦㱗⁅紌嘥㳯쌘Ⴕ挅ᘅ礩暷⦋ﳝ桟姴쪻瀠⼆㞦��oꍄ婀됯濳毡ꝥ䍄귝�∦ᵏ毠ᵩ頿ⅺ™焬᧎䟺Ӟ⢢骯귘ᖮ偂鉴䘀ᵢ倧㛻‌ꕚ۟讓溂ﶵ咩֡ꭱ怟ꦭХ⥇꫻㯼旰卨眖읞鯻惐࿄Ѭꟲ䗠㞻윴靠턂שׂ殅赑뽚镥됵ᲂẴ讜ﶌ把⧈낮쟰餺擫♖㊙㲔䧣鋫∈衦閸ꁐ҄ꚪ螗贪⢖粓꧳揧껞婓㲒髦?᫱醡䟪耢ஃ廥뿙兪୪윹⊏쿸㩏⫟⠣䓂ܴ첚얂绝⮕፩g墘굶丌齢匰魢䎏㶵䕨엋뼾ྛ鹢뻤⿍펥睹ᒬ쎫폶쮈潡픬⭜ڣ띻龼흸ﱘ鱮끌恸饶紟㛷∏䭚旾젌㨆䆝ᅵ郞钉᪻湯癬Ҏ牴粒葺䂙ಧ鐵亶蚡镯꽾誡⟤뺺ㆺ뤔㓸쮬떲㥈�䆛텋ỳ邋章᭥�쭇⸉큗턹⢀䙵븀쪜创�鐮렮簎죥윝䵾葷픁㼣ਊ쌲ㅪ塋昜�ႏ쫸⚈폑䟼૒鐒櫍倴⏂팔妚淪䷎౮颟?ꒃ�암ळ怀꼸䂉횇盺毨樖탾泌ྥ퇔家ࡱ猿ꇥ䞝즹ᙤ孿竒㙣튁£嵝Ⱖ젢傠䒑᮲픨⭏몡岃퓕륈睶먝뾰㙀계擾␶闤粊ඍ不易粎遽ꪁ屣诲㔔듘盢ྞ聎⍥罭誎Ⲧ諟뎹⯽趣Ⴁ⺯ꥹᗟ�룉紃굃꽄謡᭡萏⥂楔䃪ၼ∢풧䭢畷襝?Ḿ켡퓫뜣䖱㛽舚೾吕?ᡩ鋁妀쾺႖䇜憧騗ᄄ뭎ڎ骬玈୐鼌␏ꙇ䤴澘⸂逗췔냄싲瀰进⽐︻齕ẑ曕㉨镳㚩Ჰ銫ꪩ縪鼽瑱ᕉ⤌⑂角锵샫짏⎣徝㋦쩎鴲꯬躚㝭㷱熢폧ඈ줇뺒ۇ휯�留嵎ㅗෂ䷶䟣着ⲓ»댁䞆뻰㎱됈訸댽䉝퀸猀㎅⪖版�㎪爤맨፹ⵜ୍ἳꀗ橥팓ჩ옙蝲﷖榮?᡽我앶䉵傪瘽⭄냝ꪝⳜ鍗ᮯਊ≅혂傑딚쏖張붺硚楟៰㾘鮾䤾ٞ펯볾ᩀ↻眳ܑ炸ë뒢᷎箉秮ꬋ丶쀍⁢츽箜෩抰ᒴ쥠ﺛ䅰䃸鬫㺦㶓論䀇ﭦⳊ埜趆옷챾㈥ᦝ圹ݑ癍ꘝ�L쁿뒿韁䅘遝�翾㓤䤉숗쫅䅢ษ覤눯䳯険区욫닓ᓼ逽볅䃑ෂ걌䅀黜깩려㘏䋮瓭ꪉꞧ�綖顁ᓌ몋䌈펚泘屹岳뎿땶윮সኞᐊ멭ᷤ࿇䀣㗨參䘇羟Ⴥ+뉓烲蒤ꮐ薿舲ိ빗师쏙앣淈ﺱ拽砛뱃좄へꪈ㕓嫱麧ⴭ㉅䂐䖇妝㮋⬇㬚뚉ꈐ뮚⨀뭎관츨䰚㿎貄䪍짞睦많㙏羧�紘癦ᾜ凲樟놨ꨣ╣鿤澋㨕��靑筘犔㈈ధ⏏띠䩉몉䡓끊聐촠�毀駯Ꮮ⃄�篡釳磳鳗콉狹趐᧮瓀蠍徫䪟閖桯╫웘㝩䅃ὧ맵切≸ꃶ躼䎁蝯ܒ찀챌廫衬�ᜉㆮ싶�厽品デ?꫶㪯㉵ﺃ炥챃ﶛᮗ睊䦅綾�㸰鏁䨆븱뙘쵪чⱷ櫹捷탠쌍﵎퐾춏㥻媞詁`䶣膇ࠇ蘀䀀㬁怃c. Veri bölümündeki ilk DWORD hatalı biçimlendirilmiş dizenin dizin değerini, veri bölümündeki ikinci ve üçüncü DWORD ise son geçerli dizin değerlerini içerir.

    Error: (04/11/2020 05:13:35 PM) (Source: .NET Runtime Optimization Service) (EventID: 1107) (User: )
    Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_32) - Failed to execute command from the offline queue: uninstall "System.Printing, Version=3.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=x86". The error returned was Error: The specified assembly is not installed.
    .

    Error: (04/11/2020 05:13:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (04/11/2020 04:51:33 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Hatalı uygulama adı: housecall.bin, sürüm: 1.62.0.1226, zaman damgası: 0x4cc3574b
    Hatalı modül adı: housecall.bin, sürüm: 1.62.0.1226, zaman damgası: 0x4cc3574b
    Özel durum kodu: 0xc000041d
    Hata uzaklığı 0x0000000000031f9e
    Hatalı işlem kimliği: 0x3904
    Uygulama başlangıç zamanı: 0x01d60ffe2ff5d677
    Hatalı uygulama yolu: C:\Users\Vacao\AppData\Local\Temp\HouseCall\housecall.bin
    Hatalı modül yolu: C:\Users\Vacao\AppData\Local\Temp\HouseCall\housecall.bin
    Rapor kimliği: 8d6d89a2-7bfb-11ea-9ae7-bcaec5cea7e6

    Error: (04/11/2020 04:51:31 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Hatalı uygulama adı: housecall.bin, sürüm: 1.62.0.1226, zaman damgası: 0x4cc3574b
    Hatalı modül adı: housecall.bin, sürüm: 1.62.0.1226, zaman damgası: 0x4cc3574b
    Özel durum kodu: 0xc0000005
    Hata uzaklığı 0x0000000000031f9e
    Hatalı işlem kimliği: 0x3904
    Uygulama başlangıç zamanı: 0x01d60ffe2ff5d677
    Hatalı uygulama yolu: C:\Users\Vacao\AppData\Local\Temp\HouseCall\housecall.bin
    Hatalı modül yolu: C:\Users\Vacao\AppData\Local\Temp\HouseCall\housecall.bin
    Rapor kimliği: 8c3ec934-7bfb-11ea-9ae7-bcaec5cea7e6


    System errors:
    =============
    Error: (04/11/2020 05:21:42 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: WMI Performance Adapter hizmet şu hata ile sona erdi:
    Belirtilmemiş hata

    Error: (04/11/2020 05:16:51 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: WMI Performance Adapter hizmet şu hata ile sona erdi:
    Belirtilmemiş hata

    Error: (04/11/2020 05:14:39 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: WMI Performance Adapter hizmet şu hata ile sona erdi:
    Belirtilmemiş hata

    Error: (04/11/2020 05:13:24 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
    Description: Aşağıdaki önyükleme başlatma veya sistem başlatma sürücüsü (sürücüleri) yüklenemedi:
    cdrom

    Error: (04/11/2020 03:34:59 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
    Description: WMI Performance Adapter hizmet şu hata ile sona erdi:
    Belirtilmemiş hata

    Error: (04/11/2020 03:33:44 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
    Description: Hizmet Denetimi Yöneticisi, Bilgisayar Tarayıcısı hizmetinin beklenmedik şekilde sonlanmasından sonra, bir düzeltme eylemi (Hizmeti yeniden başlat) uygulamayı denedi, ancak bu eylem şu hatayla başarısız oldu:
    Bir hizmet kopyası halen çalışıyor.

    Error: (04/11/2020 03:33:44 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
    Description: Hizmet Denetimi Yöneticisi, Multimedya Sınıf Zamanlayıcısı hizmetinin beklenmedik şekilde sonlanmasından sonra, bir düzeltme eylemi (Hizmeti yeniden başlat) uygulamayı denedi, ancak bu eylem şu hatayla başarısız oldu:
    Bir hizmet kopyası halen çalışıyor.

    Error: (04/11/2020 03:33:44 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
    Description: Hizmet Denetimi Yöneticisi, Windows Yönetim Yardımcıları hizmetinin beklenmedik şekilde sonlanmasından sonra, bir düzeltme eylemi (Hizmeti yeniden başlat) uygulamayı denedi, ancak bu eylem şu hatayla başarısız oldu:
    Bir hizmet kopyası halen çalışıyor.


    ==================== Memory info ===========================

    BIOS: American Megatrends Inc. 3602 11/01/2012
    Motherboard: ASUSTeK Computer INC. P8P67
    Processor: Intel(R) Core(TM) i5-2500K CPU @ 3.30GHz
    Percentage of memory in use: 31%
    Total physical RAM: 16351.09 MB
    Available physical RAM: 11207.22 MB
    Total Virtual: 32700.33 MB
    Available Virtual: 26486.89 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:447.04 GB) (Free:130.79 GB) NTFS ==>[drive with boot components (obtained from BCD)]
    Drive d: () (Fixed) (Total:146.38 GB) (Free:103 GB) NTFS
    Drive e: (Yerel Disk) (Fixed) (Total:97.65 GB) (Free:9.64 GB) NTFS
    Drive f: () (Fixed) (Total:123.95 GB) (Free:82.97 GB) NTFS
    Drive g: () (Fixed) (Total:97.66 GB) (Free:8.49 GB) NTFS


    ==================== MBR & Partition Table ====================

    ==========================================================
    Disk: 0 (MBR Code: Windows 7/8/10) (Size: 447.1 GB) (Disk ID: 50FE866D)
    Partition 1: (Active) - (Size=447 GB) - (Type=07 NTFS)

    ==========================================================
    Disk: 1 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 370D370D)
    Partition 1: (Not Active) - (Size=146.4 GB) - (Type=07 NTFS)
    Partition 2: (Not Active) - (Size=97.7 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=221.6 GB) - (Type=0F Extended)

    ==================== End of Addition.txt =======================




  • FRST LOGLARI

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-04-2020
    Ran by Vacao (administrator) on VACAO77 (11-04-2020 17:44:10)
    Running from C:\Users\Vacao\Downloads
    Loaded Profiles: Vacao (Available Profiles: Vacao)
    Platform: Windows 7 Ultimate Service Pack 1 (X64) Language: Türkçe (Türkiye)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool:http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
    (Apple Inc. -> Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
    (Apple Inc. -> Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Apple Inc. -> Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Apple Inc. -> Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (Apple Inc. -> Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
    (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\AdminService.exe
    (Atheros Communications Inc. -> Atheros Commnucations) [File not signed] C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
    (Atheros Communications Inc. -> Atheros Communications) [File not signed] C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
    (F.lux Software LLC -> f.lux Software LLC) C:\Users\Vacao\AppData\Local\FluxSoftware\Flux\flux.exe
    (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGABYTE Technology Co.,Ltd.) C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\AORUS.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    (Intel Corporation -> Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
    (Malwarebytes Corporation -> Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
    (Microsoft Corporation -> Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
    (Microsoft Dynamic Code Publisher -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
    (Microsoft Dynamic Code Publisher -> Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe
    (Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
    (NVIDIA Corporation -> Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
    (NVIDIA Corporation -> NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
    (Piriform Software Ltd -> Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
    (ProtonVPN AG -> ) C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPNService.exe
    (Realtek Semiconductor Corp -> Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (Renesas Electronics Corporation -> Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
    (TeamViewer GmbH -> TeamViewer Germany GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
    (ToolsLib -> ) C:\Users\Vacao\Downloads\delfix_1.013.exe
    (Windscribe Limited -> Windscribe Limited) C:\Program Files (x86)\Windscribe\WindscribeService.exe

    ==================== Registry (Whitelisted) ===================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11545192 2010-11-02] (Realtek Semiconductor Corp -> Realtek Semiconductor)
    HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [617120 2011-03-13] (Atheros Communications Inc. -> Atheros Communications) [File not signed]
    HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [379552 2011-03-13] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
    HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [302904 2019-10-25] (Apple Inc. -> Apple Inc.)
    HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-04-30] (Intel Corporation -> Intel Corporation)
    HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation -> Renesas Electronics Corporation)
    HKU\S-1-5-21-1050937798-2524932215-4036471439-1000\...\Run: [f.lux] => C:\Users\Vacao\AppData\Local\FluxSoftware\Flux\flux.exe [1385480 2019-08-30] (F.lux Software LLC -> f.lux Software LLC)
    HKU\S-1-5-21-1050937798-2524932215-4036471439-1000\...\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [24552064 2019-10-15] (Piriform Software Ltd -> Piriform Ltd)
    HKU\S-1-5-21-1050937798-2524932215-4036471439-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2020-03-22] (Apple Inc. -> Apple Inc.)
    HKU\S-1-5-21-1050937798-2524932215-4036471439-1000\...\Run: [Windscribe] => C:\Program Files (x86)\Windscribe\Windscribe.exe [10106544 2019-01-19] (Windscribe Limited -> Windscribe Limited)
    HKU\S-1-5-21-1050937798-2524932215-4036471439-1000\...\MountPoints2: {a443287f-81e1-11e9-a851-bcaec5cea7e6} - I:\setup.exe
    HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.163\Installer\chrmstp.exe [2020-04-11] (Google LLC -> Google LLC)
    Startup: C:\Users\Vacao\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GIGABYTE AORUS GRAPHICS ENGINE.lnk [2019-04-28]
    ShortcutTarget: GIGABYTE AORUS GRAPHICS ENGINE.lnk -> C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\autorun.exe () [File not signed]

    ==================== Scheduled Tasks (Whitelisted) ============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {073B2D03-1C45-448B-9DA8-CEAA4B98B7F5} - System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-12-06] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {0F0234E3-BA74-40F0-8501-B3668DC5CD6C} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [914456 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {2206D301-859D-4727-922F-0F4BE26F6C5D} - System32\Tasks\NvTmRep_CrashReport1_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {36619A79-C0BF-405F-8199-940B9FD39DDE} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1800832 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
    Task: {37B649A9-D927-42FD-8711-BBB073AC1AD7} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18458752 2019-10-15] (Piriform Software Ltd -> Piriform Ltd)
    Task: {4C6491E6-6AFE-4E3B-8819-CD2E396E0128} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [616832 2019-09-04] (Apple Inc. -> Apple Inc.)
    Task: {595B78A4-891A-4D93-A79C-F2E14B4255D5} - System32\Tasks\NvTmRep_CrashReport3_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {5E17E795-4A7D-414A-AFEA-1F05164079E4} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [608384 2019-10-15] (Piriform Software Ltd -> Piriform Software Ltd)
    Task: {616DF15A-FC61-4232-9A22-EF76A2CF1EB3} - System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NVIDIA GeForce Experience\NVIDIA GeForce Experience.exe [3302880 2019-12-09] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {8E9B346C-3705-4607-A13F-5F1AF51DD5E8} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_344_pepper.exe [1453624 2020-03-12] (Adobe Inc. -> Adobe)
    Task: {90E2A492-ACBE-4010-8E75-33856478D816} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-23] (Google Inc -> Google LLC)
    Task: {9171D241-F93A-4434-B62F-0BA86F2D170E} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [653848 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {9AC2795D-A1D6-4152-8307-441160160A97} - System32\Tasks\Launcher GIGABYTE AORUS GRAPHICS ENGINE => C:\Program Files (x86)\GIGABYTE\AORUS ENGINE\AORUS.exe [32555976 2019-04-08] (GIGA-BYTE TECHNOLOGY CO., LTD. -> GIGABYTE Technology Co.,Ltd.)
    Task: {A109416C-0C63-4EF5-B442-09E8BE4ED885} - System32\Tasks\NvTmRep_CrashReport4_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {D9CBEF8B-3E55-424D-BCC5-83EF96C3CABD} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [410784 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
    Task: {DDF5C6DC-ED1C-4F31-BB23-531DB92BDE26} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [914456 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {E1B278DC-C375-45D5-88CE-0CAF78695177} - System32\Tasks\NvTmRep_CrashReport2_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvBackend\NvTmRep.exe [1134104 2019-12-08] (NVIDIA Corporation -> NVIDIA Corporation)
    Task: {E619A346-59EB-4904-A9E0-9500DDB50938} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [335416 2020-03-12] (Adobe Inc. -> Adobe)
    Task: {E6DC2D35-C731-45A2-9563-8AB437CCC5C3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [156456 2019-04-23] (Google Inc -> Google LLC)
    Task: {EA91F784-0C7D-4973-A559-6ACD308602FC} - System32\Tasks\NvBatteryBoostCheckOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-12-06] (NVIDIA Corporation -> NVIDIA Corporation)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Winsock: Catalog5 08 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128 2015-08-12] (Apple Inc. -> Apple Inc.)
    Winsock: Catalog5-x64 08 C:\Program Files\Bonjour\mdnsNSP.dll [133392 2015-08-12] (Apple Inc. -> Apple Inc.)
    Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
    Tcpip\..\Interfaces\{4031E070-9A73-4DBE-8B35-84FAE1415294}: [DhcpNameServer] 192.168.1.1

    Internet Explorer:
    ==================
    HKU\S-1-5-21-1050937798-2524932215-4036471439-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/tr-tr/?ocid=iehp
    BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
    BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
    BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
    BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll [2011-03-13] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
    BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2020-03-03] (Microsoft Corporation -> Microsoft Corporation)
    Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2020-03-03] (Microsoft Corporation -> Microsoft Corporation)

    FireFox:
    ========
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2020-03-03] (Microsoft Corporation -> Microsoft Corporation)

    Chrome:
    =======
    CHR Profile: C:\Users\Vacao\AppData\Local\Google\Chrome\User Data\Default [2020-04-11]
    CHR Extension: (Windscribe - Free Proxy and Ad Blocker) - C:\Users\Vacao\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnmpcagpplmpfojmgmnngilcnanddlhb [2020-02-01]
    CHR Extension: (Chrome Web Mağazası Ödemeleri) - C:\Users\Vacao\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-10-04]
    CHR Extension: (Chrome Media Router) - C:\Users\Vacao\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-04-03]

    ==================== Services (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [96056 2020-03-12] (Apple Inc. -> Apple Inc.)
    R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [74912 2011-03-13] (Atheros Communications Inc. -> Atheros Commnucations) [File not signed]
    R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes Corporation -> Malwarebytes)
    R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
    R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation -> Microsoft Corporation)
    R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-12-06] (NVIDIA Corporation -> NVIDIA Corporation)
    S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [858480 2019-12-06] (NVIDIA Corporation -> NVIDIA Corporation)
    R2 OfficeSvc; C:\Program Files\Microsoft Office 15\ClientX64\integratedoffice.exe [1800832 2012-10-01] (Microsoft Corporation -> Microsoft Corporation)
    R2 ProtonVPN Service; C:\Program Files (x86)\Proton Technologies\ProtonVPN\ProtonVPNService.exe [97080 2019-08-12] (ProtonVPN AG -> )
    R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [12097024 2019-11-06] (TeamViewer GmbH -> TeamViewer Germany GmbH)
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2015-06-12] (Microsoft Windows -> Microsoft Corporation)
    R2 WindscribeService; C:\Program Files (x86)\Windscribe\WindscribeService.exe [493232 2019-01-19] (Windscribe Limited -> Windscribe Limited)
    R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000

    ===================== Drivers (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S3 ATHDFU; C:\Windows\System32\Drivers\AthDfu.sys [51872 2011-03-13] (Atheros Communications Inc. -> Windows (R) Win 7 DDK provider)
    S3 dtultrascsibus; C:\Windows\System32\DRIVERS\dtultrascsibus.sys [42256 2019-05-29] (AVB Disc Soft, SIA -> Disc Soft Ltd)
    S3 dtultrausbbus; C:\Windows\System32\DRIVERS\dtultrausbbus.sys [59344 2019-05-29] (AVB Disc Soft, SIA -> Disc Soft Ltd)
    R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [152688 2018-12-04] (Malwarebytes Corporation -> Malwarebytes)
    R3 gdrv2; C:\Windows\gdrv2.sys [32008 2019-04-28] (GIGA-BYTE Technology Co., Ltd. -> GIGA-BYTE TECHNOLOGY CO., LTD.)
    R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [198512 2020-04-11] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [126624 2020-04-11] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [72536 2020-04-11] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [261032 2020-04-11] (Malwarebytes Corporation -> Malwarebytes)
    R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [103760 2020-04-11] (Malwarebytes Corporation -> Malwarebytes)
    R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
    R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation -> Microsoft Corporation)
    R3 nusb3hub; C:\Windows\System32\DRIVERS\nusb3hub.sys [80384 2010-12-10] (Microsoft Windows Hardware Compatibility Publisher -> Renesas Electronics Corporation)
    R3 nusb3xhc; C:\Windows\System32\DRIVERS\nusb3xhc.sys [181248 2010-12-10] (Microsoft Windows Hardware Compatibility Publisher -> Renesas Electronics Corporation)
    S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30336 2019-12-07] (NVIDIA Corporation -> NVIDIA Corporation)
    R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [69840 2019-04-17] (NVIDIA Corporation -> NVIDIA Corporation)
    R3 nvvhci; C:\Windows\System32\DRIVERS\nvvhci.sys [75600 2019-10-17] (NVIDIA Corporation -> NVIDIA Corporation)
    S3 ProtonVPNSplitTunnelCalloutDriver; C:\Program Files (x86)\Proton Technologies\ProtonVPN\Resources\64-bit\win7\ProtonVPNSplitTunnelCalloutDriver.Sys [39352 2019-07-02] (ProtonVPN AG -> )
    R3 tapprotonvpn; C:\Windows\System32\DRIVERS\tapprotonvpn.sys [35768 2019-07-02] (ProtonVPN AG -> The OpenVPN Project)
    R3 tapwindscribe0901; C:\Windows\System32\DRIVERS\tapwindscribe0901.sys [45560 2018-07-06] (Windscribe Limited -> The OpenVPN Project)
    S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2019-04-03] (Microsoft Windows Hardware Compatibility Publisher -> Apple, Inc.)
    S3 vcd10bus; C:\Windows\System32\DRIVERS\vcd10bus.sys [40464 2008-06-17] (H und H Software GmbH -> H+H Software GmbH)
    U3 aswbdisk; no ImagePath
    S3 GPCIDrv; \??\C:\Users\Vacao\AppData\Local\Temp\7zSCE46.tmp\N2080_FW_Upgrade_Tool_V003\GPCIDrv64.sys [X] <==== ATTENTION
    S3 VGPU; System32\drivers\rdvgkmd.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== Three months (created) ===================

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2020-04-11 17:44 - 2020-04-11 17:44 - 000023887 _____ C:\Users\Vacao\Downloads\FRST.txt
    2020-04-11 17:42 - 2020-04-11 17:44 - 000000000 ____D C:\FRST
    2020-04-11 17:42 - 2020-04-11 17:42 - 000797760 _____ C:\Users\Vacao\Downloads\delfix_1.013.exe
    2020-04-11 17:40 - 2020-04-11 17:40 - 002281472 _____ (Farbar) C:\Users\Vacao\Downloads\FRST64.exe
    2020-04-11 17:13 - 2020-04-11 17:14 - 000103760 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
    2020-04-11 17:13 - 2020-04-11 17:13 - 000261032 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
    2020-04-11 17:13 - 2020-04-11 17:13 - 000198512 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
    2020-04-11 17:13 - 2020-04-11 17:13 - 000126624 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
    2020-04-11 17:13 - 2020-04-11 17:13 - 000072536 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
    2020-04-11 17:13 - 2020-04-11 17:13 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
    2020-04-11 17:13 - 2020-04-11 17:13 - 000001867 _____ C:\ProgramData\Desktop\Malwarebytes.lnk
    2020-04-11 17:13 - 2020-04-11 17:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
    2020-04-11 17:13 - 2020-04-11 17:13 - 000000000 ____D C:\Program Files\Malwarebytes
    2020-04-11 17:13 - 2018-12-04 08:09 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
    2020-04-11 17:12 - 2020-04-11 17:12 - 000000000 ____D C:\ProgramData\MB2Migration
    2020-04-11 17:09 - 2020-04-11 17:13 - 000000000 ____D C:\ProgramData\Malwarebytes
    2020-04-11 17:07 - 2020-04-11 17:07 - 006705178 _____ C:\Users\Vacao\Downloads\mbam-chameleon-3.1.33.0.zip
    2020-04-11 17:07 - 2020-04-11 17:07 - 000000000 ____D C:\Users\Vacao\Downloads\mbam-chameleon-3.1.33.0
    2020-04-11 16:56 - 2020-04-11 16:56 - 000000000 ____D C:\Users\Vacao\AppData\Local\mbam
    2020-04-11 16:56 - 2020-04-11 16:56 - 000000000 ____D C:\Users\Vacao\AppData\Local\cache
    2020-04-11 16:55 - 2020-04-11 16:55 - 000000000 ____D C:\Users\Vacao\AppData\Local\mbamtray
    2020-04-11 16:53 - 2020-04-11 16:53 - 001965536 _____ (Malwarebytes) C:\Users\Vacao\Downloads\MBSetup.exe
    2020-04-11 15:55 - 2020-04-11 15:55 - 000000000 ____D C:\Windows\Trend Micro
    2020-04-11 15:55 - 2020-04-11 15:55 - 000000000 ____D C:\ProgramData\Trend Micro
    2020-04-11 15:47 - 2020-04-11 15:47 - 000750186 _____ C:\Users\Vacao\AppData\Local\census.cache
    2020-04-11 15:47 - 2020-04-11 15:47 - 000363354 _____ C:\Users\Vacao\AppData\Local\ars.cache
    2020-04-11 15:38 - 2020-04-11 15:38 - 002660528 _____ (Trend Micro Inc.) C:\Users\Vacao\Downloads\HousecallLauncher64.exe
    2020-04-11 15:38 - 2020-04-11 15:38 - 000000036 _____ C:\Users\Vacao\AppData\Local\housecall.guid.cache
    2020-04-11 15:10 - 2019-08-29 05:56 - 003966904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
    2020-04-11 15:10 - 2019-08-29 05:55 - 004061112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
    2020-04-11 15:10 - 2019-08-29 05:55 - 000627424 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
    2020-04-11 15:10 - 2019-08-29 05:54 - 001319496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
    2020-04-11 15:10 - 2019-08-29 05:53 - 005553104 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
    2020-04-11 15:10 - 2019-08-29 05:53 - 000709856 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
    2020-04-11 15:10 - 2019-08-29 05:53 - 000264120 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
    2020-04-11 15:10 - 2019-08-29 05:53 - 000155360 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
    2020-04-11 15:10 - 2019-08-29 05:53 - 000096992 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
    2020-04-11 15:10 - 2019-08-29 05:52 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000836608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000555520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000275968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000261632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:52 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:51 - 001670784 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 001472512 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 001211392 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 001162752 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 001078784 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000733184 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000408576 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000236032 _____ (Microsoft Corporation) C:\Windows\system32\srvsvc.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\sscore.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:50 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:27 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
    2020-04-11 15:10 - 2019-08-29 05:27 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sscore.dll
    2020-04-11 15:10 - 2019-08-29 05:22 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
    2020-04-11 15:10 - 2019-08-29 05:22 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
    2020-04-11 15:10 - 2019-08-29 05:22 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
    2020-04-11 15:10 - 2019-08-29 05:22 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
    2020-04-11 15:10 - 2019-08-29 05:22 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
    2020-04-11 15:10 - 2019-08-29 05:22 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
    2020-04-11 15:10 - 2019-08-29 05:22 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
    2020-04-11 15:10 - 2019-08-29 05:22 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
    2020-04-11 15:10 - 2019-08-29 05:21 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
    2020-04-11 15:10 - 2019-08-29 05:21 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:21 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:21 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:21 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
    2020-04-11 15:10 - 2019-08-29 05:19 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
    2020-04-11 15:10 - 2019-08-29 05:19 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
    2020-04-11 15:10 - 2019-08-29 05:18 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
    2020-04-11 15:10 - 2019-08-29 05:15 - 000464384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv.sys
    2020-04-11 15:10 - 2019-08-29 05:15 - 000406016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srv2.sys
    2020-04-11 15:10 - 2019-08-29 05:15 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
    2020-04-11 15:10 - 2019-08-29 05:15 - 000169984 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\srvnet.sys
    2020-04-11 15:10 - 2019-08-29 05:15 - 000161280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
    2020-04-11 15:10 - 2019-08-29 05:15 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
    2020-04-11 15:10 - 2019-08-29 05:14 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
    2020-04-11 15:10 - 2019-08-29 05:14 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys
    2020-04-11 15:10 - 2019-08-29 05:14 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys
    2020-04-11 15:10 - 2019-08-29 05:14 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys
    2020-04-11 15:10 - 2019-08-29 05:14 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys
    2020-04-11 15:10 - 2019-08-29 05:14 - 000044544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\npfs.sys
    2020-04-11 15:10 - 2019-08-29 05:14 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
    2020-04-11 15:10 - 2019-08-27 23:50 - 000390536 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
    2020-04-11 15:10 - 2019-08-27 22:59 - 000341896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
    2020-04-11 15:10 - 2019-08-27 08:07 - 025752064 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
    2020-04-11 15:10 - 2019-08-27 06:41 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
    2020-04-11 15:10 - 2019-08-27 06:41 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
    2020-04-11 15:10 - 2019-08-27 06:29 - 002909184 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
    2020-04-11 15:10 - 2019-08-27 06:27 - 000579072 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
    2020-04-11 15:10 - 2019-08-27 06:27 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
    2020-04-11 15:10 - 2019-08-27 06:27 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
    2020-04-11 15:10 - 2019-08-27 06:27 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
    2020-04-11 15:10 - 2019-08-27 06:26 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
    2020-04-11 15:10 - 2019-08-27 06:21 - 020290560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
    2020-04-11 15:10 - 2019-08-27 06:20 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
    2020-04-11 15:10 - 2019-08-27 06:19 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
    2020-04-11 15:10 - 2019-08-27 06:17 - 005500928 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
    2020-04-11 15:10 - 2019-08-27 06:17 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
    2020-04-11 15:10 - 2019-08-27 06:16 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
    2020-04-11 15:10 - 2019-08-27 06:16 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
    2020-04-11 15:10 - 2019-08-27 06:15 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
    2020-04-11 15:10 - 2019-08-27 06:15 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
    2020-04-11 15:10 - 2019-08-27 06:15 - 000790528 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
    2020-04-11 15:10 - 2019-08-27 06:08 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
    2020-04-11 15:10 - 2019-08-27 06:05 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
    2020-04-11 15:10 - 2019-08-27 06:03 - 000496128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
    2020-04-11 15:10 - 2019-08-27 06:03 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
    2020-04-11 15:10 - 2019-08-27 06:02 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
    2020-04-11 15:10 - 2019-08-27 06:02 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
    2020-04-11 15:10 - 2019-08-27 06:01 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
    2020-04-11 15:10 - 2019-08-27 05:59 - 002301952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
    2020-04-11 15:10 - 2019-08-27 05:59 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
    2020-04-11 15:10 - 2019-08-27 05:58 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
    2020-04-11 15:10 - 2019-08-27 05:58 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
    2020-04-11 15:10 - 2019-08-27 05:56 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
    2020-04-11 15:10 - 2019-08-27 05:56 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
    2020-04-11 15:10 - 2019-08-27 05:55 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
    2020-04-11 15:10 - 2019-08-27 05:54 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
    2020-04-11 15:10 - 2019-08-27 05:54 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
    2020-04-11 15:10 - 2019-08-27 05:53 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
    2020-04-11 15:10 - 2019-08-27 05:53 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
    2020-04-11 15:10 - 2019-08-27 05:53 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
    2020-04-11 15:10 - 2019-08-27 05:52 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
    2020-04-11 15:10 - 2019-08-27 05:50 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
    2020-04-11 15:10 - 2019-08-27 05:45 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
    2020-04-11 15:10 - 2019-08-27 05:42 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
    2020-04-11 15:10 - 2019-08-27 05:40 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
    2020-04-11 15:10 - 2019-08-27 05:40 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
    2020-04-11 15:10 - 2019-08-27 05:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
    2020-04-11 15:10 - 2019-08-27 05:39 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
    2020-04-11 15:10 - 2019-08-27 05:39 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
    2020-04-11 15:10 - 2019-08-27 05:37 - 002132480 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
    2020-04-11 15:10 - 2019-08-27 05:37 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
    2020-04-11 15:10 - 2019-08-27 05:37 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
    2020-04-11 15:10 - 2019-08-27 05:36 - 015389184 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
    2020-04-11 15:10 - 2019-08-27 05:36 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
    2020-04-11 15:10 - 2019-08-27 05:35 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
    2020-04-11 15:10 - 2019-08-27 05:34 - 000350208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\HdAudio.sys
    2020-04-11 15:10 - 2019-08-27 05:34 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
    2020-04-11 15:10 - 2019-08-27 05:30 - 004112384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
    2020-04-11 15:10 - 2019-08-27 05:28 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
    2020-04-11 15:10 - 2019-08-27 05:27 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
    2020-04-11 15:10 - 2019-08-27 05:27 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
    2020-04-11 15:10 - 2019-08-27 05:26 - 004859392 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
    2020-04-11 15:10 - 2019-08-27 05:26 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
    2020-04-11 15:10 - 2019-08-27 05:23 - 013791744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
    2020-04-11 15:10 - 2019-08-27 05:15 - 001568256 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
    2020-04-11 15:10 - 2019-08-27 05:09 - 004387840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
    2020-04-11 15:10 - 2019-08-27 05:06 - 001331712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
    2020-04-11 15:10 - 2019-08-27 05:04 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
    2020-04-11 15:10 - 2019-08-27 05:04 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
    2020-04-11 15:10 - 2019-08-23 01:07 - 000628480 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
    2020-04-11 15:10 - 2019-08-21 04:59 - 000311008 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
    2020-04-11 15:10 - 2019-08-21 04:56 - 000071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
    2020-04-11 15:10 - 2019-08-21 04:56 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
    2020-04-11 15:10 - 2019-08-21 04:56 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
    2020-04-11 15:10 - 2019-08-21 02:19 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
    2020-04-11 15:10 - 2019-08-20 07:24 - 000385248 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
    2020-04-11 15:10 - 2019-08-20 07:21 - 000101376 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
    2020-04-11 15:10 - 2019-08-20 07:21 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
    2020-04-11 15:10 - 2019-08-20 07:21 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
    2020-04-11 15:10 - 2019-08-20 07:21 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
    2020-04-11 15:10 - 2019-08-20 06:59 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ws2ifsl.sys
    2020-04-11 15:10 - 2019-08-20 06:51 - 003232256 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
    2020-04-11 15:10 - 2019-08-20 05:47 - 001251840 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
    2020-04-11 15:10 - 2019-08-15 10:59 - 000878080 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
    2020-04-11 15:10 - 2019-08-15 10:59 - 000583680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
    2020-04-11 15:10 - 2019-08-14 20:54 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsmf.dll
    2020-04-11 15:10 - 2019-08-14 20:53 - 000253440 _____ (Microsoft) C:\Windows\SysWOW64\DShowRdpFilter.dll
    2020-04-11 15:10 - 2019-08-14 08:22 - 000374496 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
    2020-04-11 15:10 - 2019-08-14 08:20 - 000300032 _____ (Microsoft Corporation) C:\Windows\system32\tsmf.dll
    2020-04-11 15:10 - 2019-08-14 08:20 - 000282112 _____ (Microsoft) C:\Windows\system32\DShowRdpFilter.dll
    2020-04-11 15:10 - 2019-08-14 08:20 - 000133120 _____ (Microsoft Corporation) C:\Windows\system32\tssrvlic.dll
    2020-04-11 15:10 - 2019-08-14 07:59 - 000053760 _____ (Microsoft Corporation) C:\Windows\system32\LSCSHostPolicy.dll
    2020-04-11 15:10 - 2019-08-14 07:52 - 000455680 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
    2020-04-11 15:10 - 2019-08-14 01:20 - 000162016 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
    2020-04-11 15:10 - 2019-08-14 01:19 - 000988384 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
    2020-04-11 15:10 - 2019-08-14 01:19 - 000267488 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
    2020-04-11 15:10 - 2019-08-14 01:16 - 001009664 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll
    2020-04-11 15:10 - 2019-08-14 01:16 - 000484864 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
    2020-04-11 15:10 - 2019-08-14 01:15 - 000732160 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
    2020-04-11 15:10 - 2019-08-14 01:15 - 000405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
    2020-04-11 15:10 - 2019-08-14 01:15 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
    2020-04-11 15:10 - 2019-08-14 01:13 - 000833536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user32.dll
    2020-04-11 15:10 - 2019-08-14 01:13 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
    2020-04-11 15:10 - 2019-08-14 01:13 - 000313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
    2020-04-11 15:10 - 2019-08-13 05:58 - 001312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msjet40.dll
    2020-04-11 15:10 - 2019-08-13 05:58 - 000475648 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxbde40.dll
    2020-04-11 15:10 - 2019-08-13 05:58 - 000353280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
    2020-04-11 15:10 - 2019-08-13 05:58 - 000313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd2x40.dll
    2020-04-11 15:10 - 2019-08-13 05:50 - 006135808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
    2020-04-11 15:10 - 2019-08-13 03:56 - 007082496 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
    2020-04-11 15:10 - 2019-08-13 03:56 - 002863104 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
    2020-04-11 15:10 - 2019-08-13 03:56 - 001712640 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
    2020-04-11 15:10 - 2019-08-13 03:56 - 001650176 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
    2020-04-11 15:10 - 2019-08-13 03:56 - 000802304 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
    2020-04-11 15:10 - 2019-08-13 03:56 - 000634368 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
    2020-04-11 15:10 - 2019-08-13 03:56 - 000501760 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
    2020-04-11 15:10 - 2019-08-13 03:56 - 000456192 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
    2020-04-11 15:10 - 2019-08-13 03:56 - 000315904 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
    2020-04-11 15:10 - 2019-08-13 03:56 - 000257024 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
    2020-04-11 15:10 - 2019-07-13 11:14 - 000334848 _____ (Microsoft Corporation) C:\Windows\system32\sipnotify.exe
    2020-04-11 15:07 - 2020-04-11 15:27 - 000007605 _____ C:\Users\Vacao\AppData\Local\Resmon.ResmonCfg
    2020-04-11 13:42 - 2020-04-11 13:43 - 000000000 ____D C:\KVRT_Data
    2020-04-11 13:40 - 2020-04-11 13:42 - 175712184 _____ (AO Kaspersky Lab) C:\Users\Vacao\Downloads\KVRT.exe
    2020-04-11 13:07 - 2020-04-11 13:52 - 000000769 _____ C:\Users\Vacao\Desktop\ESET Online Scanner.lnk
    2020-04-11 13:07 - 2020-04-11 13:07 - 014566496 _____ (ESET spol. s r.o.) C:\Users\Vacao\Downloads\esetonlinescanner.exe
    2020-04-11 13:07 - 2020-04-11 13:07 - 000000000 ____D C:\Users\Vacao\AppData\Local\ESET
    2020-04-11 12:55 - 2020-04-11 12:55 - 000000000 ____D C:\Users\Vacao\ansel
    2020-04-04 20:38 - 2020-04-04 20:38 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
    2020-04-04 20:37 - 2020-04-04 20:37 - 000000000 ____D C:\Program Files\iPod
    2020-03-30 00:31 - 2020-03-30 00:31 - 000001337 _____ C:\Users\Vacao\Desktop\Unethical RO Patcher - Kısayol.lnk
    2020-03-29 20:12 - 2020-03-29 20:12 - 000001045 _____ C:\Users\Public\Desktop\Unethical RO Patcher.lnk
    2020-03-29 20:12 - 2020-03-29 20:12 - 000001045 _____ C:\ProgramData\Desktop\Unethical RO Patcher.lnk
    2020-03-29 20:12 - 2020-03-29 20:12 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unethical RO
    2020-03-29 20:02 - 2020-03-29 20:10 - 491562418 _____ (Unethical RO ) C:\Users\Vacao\Downloads\Unethical RO Lite Installer_20200311.exe
    2020-03-24 13:55 - 2020-03-19 08:08 - 030666848 _____ (NVIDIA Corporation) C:\Windows\system32\nvrtum64.dll
    2020-03-24 13:55 - 2020-03-19 08:08 - 011945072 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
    2020-03-24 13:55 - 2020-03-19 08:08 - 010285680 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
    2020-03-24 13:55 - 2020-03-19 08:08 - 001729448 _____ C:\Windows\system32\vulkaninfo-1-999-0-0-0.exe
    2020-03-24 13:55 - 2020-03-19 08:08 - 001729448 _____ C:\Windows\system32\vulkaninfo.exe
    2020-03-24 13:55 - 2020-03-19 08:08 - 001329568 _____ C:\Windows\SysWOW64\vulkaninfo-1-999-0-0-0.exe
    2020-03-24 13:55 - 2020-03-19 08:08 - 001329568 _____ C:\Windows\SysWOW64\vulkaninfo.exe
    2020-03-24 13:55 - 2020-03-19 08:08 - 001079208 _____ C:\Windows\system32\vulkan-1-999-0-0-0.dll
    2020-03-24 13:55 - 2020-03-19 08:08 - 001079208 _____ C:\Windows\system32\vulkan-1.dll
    2020-03-24 13:55 - 2020-03-19 08:08 - 000937896 _____ C:\Windows\SysWOW64\vulkan-1-999-0-0-0.dll
    2020-03-24 13:55 - 2020-03-19 08:08 - 000937896 _____ C:\Windows\SysWOW64\vulkan-1.dll
    2020-03-24 13:55 - 2020-03-19 08:08 - 000445552 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
    2020-03-24 13:55 - 2020-03-19 08:08 - 000419256 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
    2020-03-24 13:55 - 2020-03-19 08:08 - 000344160 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 132261608 _____ (NVIDIA Corp.) C:\Windows\system32\nvoptix.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 040448232 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 029994728 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl64.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 029697632 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 025314720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl32.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 023040112 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
    2020-03-24 13:55 - 2020-03-19 08:07 - 002071992 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 001723488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6444575.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 001565280 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 001483376 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6444575.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 001481328 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 001351776 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 001141688 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 001049696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 000626784 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 000544368 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 000517232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 000472672 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 000428640 _____ C:\Windows\system32\nvofapi64.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 000377968 _____ C:\Windows\SysWOW64\nvofapi.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 000182392 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 000165472 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 000158304 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
    2020-03-24 13:55 - 2020-03-19 08:07 - 000143472 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
    2020-03-24 13:55 - 2020-03-19 08:06 - 040557456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler64.dll
    2020-03-24 13:55 - 2020-03-19 08:06 - 035419024 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler32.dll
    2020-03-24 13:55 - 2020-03-19 08:06 - 017600416 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
    2020-03-24 13:55 - 2020-03-19 08:06 - 015159016 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
    2020-03-24 13:55 - 2020-03-19 08:06 - 005449616 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
    2020-03-24 13:55 - 2020-03-19 08:06 - 004862696 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
    2020-03-24 13:55 - 2020-03-19 08:06 - 000632760 _____ (NVIDIA Corporation) C:\Windows\system32\nvcbl64.dll
    2020-03-24 13:55 - 2020-03-19 05:05 - 035456728 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
    2020-03-24 13:55 - 2020-03-19 05:05 - 022225376 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
    2020-03-24 13:55 - 2020-03-19 05:05 - 018526272 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
    2020-03-24 13:55 - 2020-03-18 10:29 - 000223120 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys
    2020-03-24 13:55 - 2020-03-18 10:29 - 000039824 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll
    2020-03-24 13:55 - 2020-03-18 10:29 - 000000671 _____ C:\Windows\SysWOW64\nv-vk32.json
    2020-03-24 13:55 - 2020-03-18 10:29 - 000000671 _____ C:\Windows\system32\nv-vk64.json
    2020-03-21 13:48 - 2020-04-11 16:51 - 000000000 ____D C:\Users\Vacao\AppData\Local\CrashDumps
    2020-03-21 13:31 - 2020-03-21 13:31 - 000000000 ____D C:\Users\Vacao\Downloads\Streetz RO Latest
    2020-03-21 13:01 - 2020-03-21 13:30 - 2823233495 _____ C:\Users\Vacao\Downloads\Streetz RO Latest.7z
    2020-03-21 12:59 - 2020-03-21 12:59 - 000122859 _____ C:\Users\Vacao\Downloads\binkw32.dll.zip
    2020-03-21 12:59 - 2020-03-21 12:59 - 000000000 ____D C:\Users\Vacao\Downloads\binkw32.dll
    2020-03-21 12:52 - 2020-03-21 12:52 - 000000000 ____D C:\Users\Vacao\Downloads\StreetzRO Lite Client 19-02-2020
    2020-03-21 12:11 - 2020-03-21 12:22 - 432155220 _____ C:\Users\Vacao\Downloads\StreetzRO Lite Client 19-02-2020.7z
    2020-03-15 16:20 - 2020-03-15 16:20 - 000942885 _____ C:\Users\Vacao\Desktop\tv_channels_gr36d23ke (3).m3u
    2020-03-12 18:42 - 2020-04-11 12:55 - 000000000 ____D C:\Users\Vacao\AppData\LocalLow\uTorrent
    2020-03-12 18:22 - 2020-03-12 18:23 - 036421256 _____ (Logitech, Inc.) C:\Users\Vacao\Downloads\lghub_installer.exe
    2020-03-09 17:24 - 2020-03-09 17:24 - 000000000 ____D C:\Users\Vacao\Documents\Sports Interactive
    2020-03-09 17:24 - 2020-03-09 17:24 - 000000000 ____D C:\Users\Vacao\AppData\Roaming\Sports Interactive
    2020-03-09 17:24 - 2020-03-09 17:24 - 000000000 ____D C:\Users\Public\Documents\Sports Interactive
    2020-03-09 17:24 - 2020-03-09 17:24 - 000000000 ____D C:\ProgramData\Documents\Sports Interactive
    2020-03-08 01:02 - 2020-03-21 16:48 - 000000000 ____D C:\Users\Vacao\Desktop\damla2
    2020-03-03 12:20 - 2020-03-03 12:26 - 000002133 _____ C:\Users\Vacao\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
    2020-03-03 12:20 - 2020-03-03 12:26 - 000000000 ___RD C:\Users\Vacao\SkyDrive
    2020-03-03 12:20 - 2020-03-03 12:20 - 000002078 _____ C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
    2020-03-03 12:20 - 2020-03-03 12:20 - 000002078 _____ C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft SkyDrive.lnk
    2020-03-03 12:20 - 2020-03-03 12:20 - 000000000 ____D C:\ProgramData\Microsoft SkyDrive
    2020-03-03 12:20 - 2020-03-03 12:20 - 000000000 ____D C:\Program Files (x86)\Microsoft SkyDrive
    2020-03-03 12:19 - 2020-03-03 12:19 - 000000000 ____D C:\Windows\system32\Tasks\OfficeSoftwareProtectionPlatform
    2020-03-03 12:19 - 2020-03-03 12:19 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
    2020-03-03 12:19 - 2020-03-03 12:19 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
    2020-03-03 12:18 - 2020-03-03 12:26 - 000000000 ____D C:\Program Files\Microsoft Office 15
    2020-03-03 12:18 - 2020-03-03 12:19 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
    2020-03-03 12:17 - 2020-03-03 12:17 - 000000000 ____D C:\Users\Vacao\Downloads\Microsoft Office 365 Pro Plus
    2020-03-03 11:35 - 2020-03-03 11:45 - 989717006 _____ C:\Users\Vacao\Downloads\Microsoft Office 365 Pro Plus.rar
    2020-03-03 11:30 - 2020-03-03 11:30 - 000000000 ____D C:\Users\Vacao\Desktop\Pinterest
    2020-03-03 11:29 - 2020-03-08 16:56 - 000000506 _____ C:\Users\Vacao\Desktop\Yeni Metin Belgesi (6).txt
    2020-02-29 13:20 - 2020-02-29 14:11 - 000000171 _____ C:\Users\Vacao\Desktop\Yeni Metin Belgesi (5).txt
    2020-02-28 11:47 - 2020-03-10 22:18 - 000000000 ____D C:\ProgramData\boost_interprocess
    2020-02-22 19:48 - 2020-02-22 20:00 - 000000000 ____D C:\Users\Vacao\Desktop\DAMLAMM
    2020-02-22 19:47 - 2020-02-22 19:47 - 000000000 ____D C:\Users\Vacao\Desktop\SONAY
    2020-01-31 18:42 - 2019-12-28 06:50 - 040510200 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
    2020-01-31 18:42 - 2019-12-28 06:50 - 035380240 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
    2020-01-31 18:42 - 2019-12-28 06:50 - 001727320 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6444187.dll
    2020-01-31 18:42 - 2019-12-28 06:50 - 001492480 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6444187.dll
    2020-01-27 22:19 - 2020-01-27 22:19 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
    2020-01-12 19:05 - 2020-01-12 19:05 - 012824215 _____ C:\Users\Vacao\Desktop\Mb140 kurtarma Titanium.zip
    2020-01-12 19:05 - 2020-01-12 19:05 - 000000000 ____D C:\Users\Vacao\Desktop\Mb140 kurtarma Titanium
    2020-01-12 19:04 - 2020-01-12 19:05 - 012824215 _____ C:\Users\Vacao\Downloads\Mb140 kurtarma Titanium.zip

    ==================== Three months (modified) ==================

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2020-04-11 17:21 - 2009-07-14 07:45 - 000026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2020-04-11 17:21 - 2009-07-14 07:45 - 000026576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2020-04-11 17:15 - 2019-04-23 17:45 - 000000000 ____D C:\ProgramData\NVIDIA
    2020-04-11 17:13 - 2019-12-09 00:12 - 000000000 ____D C:\Program Files (x86)\TeamViewer
    2020-04-11 17:13 - 2009-07-14 08:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
    2020-04-11 17:13 - 2009-07-14 07:45 - 000438960 _____ C:\Windows\system32\FNTCACHE.DAT
    2020-04-11 17:12 - 2015-06-12 04:02 - 000000000 ___SD C:\Windows\system32\CompatTel
    2020-04-11 17:12 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\inf
    2020-04-11 16:43 - 2019-04-23 16:17 - 000000000 ____D C:\Users\Vacao\AppData\Local\VirtualStore
    2020-04-11 15:55 - 2019-05-30 09:03 - 000000000 ____D C:\Program Files (x86)\Grand Theft Auto V
    2020-04-11 15:28 - 2009-07-14 08:08 - 000032584 _____ C:\Windows\Tasks\SCHEDLGU.TXT
    2020-04-11 15:23 - 2019-04-23 20:43 - 000000000 ____D C:\Windows\system32\MRT
    2020-04-11 15:21 - 2015-06-13 01:57 - 121542864 ____C (Microsoft Corporation) C:\Windows\system32\mrt.exe
    2020-04-11 13:31 - 2019-09-25 20:29 - 000000000 ____D C:\Users\Vacao\Downloads\ultrasurf-1902
    2020-04-11 13:28 - 2019-05-22 21:17 - 000000000 ____D C:\Users\Vacao\AppData\Roaming\uTorrent
    2020-04-11 12:55 - 2019-05-22 21:21 - 000000000 ____D C:\Users\Vacao\AppData\Local\BitTorrentHelper
    2020-04-11 12:55 - 2019-04-23 16:17 - 000000000 ____D C:\Users\Vacao
    2020-04-11 12:41 - 2019-04-23 17:44 - 000002220 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2020-04-11 12:41 - 2019-04-23 17:44 - 000002179 _____ C:\Users\Public\Desktop\Google Chrome.lnk
    2020-04-11 12:41 - 2019-04-23 17:44 - 000002179 _____ C:\ProgramData\Desktop\Google Chrome.lnk
    2020-04-04 20:37 - 2019-11-03 18:43 - 000000000 ____D C:\Program Files\iTunes
    2020-04-02 02:49 - 2010-11-21 06:27 - 000744808 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
    2020-03-24 13:56 - 2009-07-14 06:20 - 000000000 ____D C:\Windows\Help
    2020-03-21 11:58 - 2019-04-23 17:43 - 000003456 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineUA
    2020-03-21 11:58 - 2019-04-23 17:43 - 000003328 _____ C:\Windows\system32\Tasks\GoogleUpdateTaskMachineCore
    2020-03-19 08:08 - 2019-10-25 20:21 - 000502880 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
    2020-03-19 05:05 - 2019-10-25 20:21 - 041102688 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
    2020-03-19 05:05 - 2019-10-25 20:21 - 004769576 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
    2020-03-19 05:05 - 2019-10-25 20:21 - 004215928 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
    2020-03-18 10:29 - 2019-10-25 20:21 - 001682368 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdagenco6420103.dll
    2020-03-18 10:29 - 2019-10-25 20:21 - 000053698 _____ C:\Windows\system32\nvinfo.pb
    2020-03-18 07:00 - 2019-10-25 20:22 - 005581800 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
    2020-03-18 07:00 - 2019-10-25 20:22 - 002632680 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
    2020-03-18 07:00 - 2019-10-25 20:22 - 001759216 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
    2020-03-18 07:00 - 2019-10-25 20:22 - 001172464 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
    2020-03-18 07:00 - 2019-10-25 20:22 - 000446264 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
    2020-03-18 07:00 - 2019-10-25 20:22 - 000121144 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
    2020-03-18 07:00 - 2019-10-25 20:22 - 000074736 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
    2020-03-16 09:39 - 2019-10-25 20:22 - 008997147 _____ C:\Windows\system32\nvcoproc.bin
    2020-03-15 19:10 - 2019-11-07 22:24 - 000000000 ____D C:\Users\Vacao\AppData\Roaming\vlc
    2020-03-12 18:19 - 2019-04-23 19:45 - 000842296 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerApp.exe
    2020-03-12 18:19 - 2019-04-23 19:45 - 000175160 _____ (Adobe) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
    2020-03-12 18:19 - 2019-04-23 19:45 - 000004414 _____ C:\Windows\system32\Tasks\Adobe Flash Player PPAPI Notifier
    2020-03-12 18:19 - 2019-04-23 19:45 - 000004266 _____ C:\Windows\system32\Tasks\Adobe Flash Player Updater
    2020-03-12 18:19 - 2019-04-23 19:45 - 000000000 ____D C:\Windows\SysWOW64\Macromed
    2020-03-12 18:19 - 2019-04-23 19:45 - 000000000 ____D C:\Windows\system32\Macromed

    ==================== Files in the root of some directories ========

    2020-04-11 15:47 - 2020-04-11 15:47 - 000363354 _____ () C:\Users\Vacao\AppData\Local\ars.cache
    2020-04-11 15:47 - 2020-04-11 15:47 - 000750186 _____ () C:\Users\Vacao\AppData\Local\census.cache
    2020-04-11 15:38 - 2020-04-11 15:38 - 000000036 _____ () C:\Users\Vacao\AppData\Local\housecall.guid.cache
    2020-04-11 15:07 - 2020-04-11 15:27 - 000007605 _____ () C:\Users\Vacao\AppData\Local\Resmon.ResmonCfg

    ==================== SigCheckExt =========================

    2019-04-23 16:20 - 2019-04-23 16:20 - 000016896 _____ (ASUS) C:\Windows\AsTaskSched.dll
    2019-04-23 16:21 - 2011-12-06 10:55 - 000053248 ____R (Windows XP Bundled build C-Centric Single User) C:\Windows\SysWOW64\CSVer.dll
    2019-09-07 23:03 - 2019-09-07 23:15 - 1087696507 _____ C:\Users\Vacao\Downloads\DreamerRO_Lite.exe
    2020-04-11 17:40 - 2020-04-11 17:40 - 002281472 _____ (Farbar) C:\Users\Vacao\Downloads\FRST64.exe
    2019-11-29 23:00 - 2019-11-29 23:01 - 026771772 _____ (Phoneboard ) C:\Users\Vacao\Downloads\phoneboard-v1.7.0.exe
    2019-08-02 12:14 - 2019-08-02 13:19 - 1791475325 _____ C:\Users\Vacao\Downloads\Ragnaforce Full.exe
    2019-08-10 13:48 - 2019-08-10 13:50 - 136075797 _____ C:\Users\Vacao\Downloads\Ragnaforce Lite.exe
    2020-03-29 20:02 - 2020-03-29 20:10 - 491562418 _____ (Unethical RO ) C:\Users\Vacao\Downloads\Unethical RO Lite Installer_20200311.exe

    ==================== SigCheck ============================

    (There is no automatic fix for files that do not pass verification.)


    ==================== BCD ================================

    Windows �ny�kleme Y�neticisi
    --------------------
    tan�mlay�c�: {bootmgr}
    device partition=C:
    description Windows Boot Manager
    locale tr-TR
    inherit {globalsettings}
    default {current}
    resumeobject {6972ed7a-65d1-11e9-a900-bcaec5cea7e6}
    displayorder {current}
    toolsdisplayorder {memdiag}
    timeout 30

    Windows �ny�kleme Y�kleyicisi
    -------------------
    tan�mlay�c�: {current}
    device partition=C:
    path \Windows\system32\winload.exe
    description Windows 7
    locale tr-TR
    inherit {bootloadersettings}
    recoverysequence {6972ed7c-65d1-11e9-a900-bcaec5cea7e6}
    recoveryenabled Yes
    osdevice partition=C:
    systemroot \Windows
    resumeobject {6972ed7a-65d1-11e9-a900-bcaec5cea7e6}
    nx OptIn

    Windows �ny�kleme Y�kleyicisi
    -------------------
    tan�mlay�c�: {6972ed7c-65d1-11e9-a900-bcaec5cea7e6}
    device ramdisk=[C:]\Recovery\6972ed7c-65d1-11e9-a900-bcaec5cea7e6\Winre.wim,{6972ed7d-65d1-11e9-a900-bcaec5cea7e6}
    path \windows\system32\winload.exe
    description Windows Recovery Environment
    inherit {bootloadersettings}
    osdevice ramdisk=[C:]\Recovery\6972ed7c-65d1-11e9-a900-bcaec5cea7e6\Winre.wim,{6972ed7d-65d1-11e9-a900-bcaec5cea7e6}
    systemroot \windows
    nx OptIn
    winpe Yes

    Haz�rda Bekleme Modundan Devam Et
    ---------------------
    tan�mlay�c�: {6972ed7a-65d1-11e9-a900-bcaec5cea7e6}
    device partition=C:
    path \Windows\system32\winresume.exe
    description Windows Resume Application
    locale tr-TR
    inherit {resumeloadersettings}
    filedevice partition=C:
    filepath \hiberfil.sys
    debugoptionenabled No

    Windows Bellek S�nama Arac�
    ---------------------
    tan�mlay�c�: {memdiag}
    device partition=C:
    path \boot\memtest.exe
    description Windows Bellek Tan�lama
    locale tr-TR
    inherit {globalsettings}
    badmemoryaccess Yes

    EMS Ayarlar�
    ------------
    tan�mlay�c�: {emssettings}
    bootems Yes

    Hata Ay�klay�c� Ayarlar�
    -----------------
    tan�mlay�c�: {dbgsettings}
    debugtype Serial
    debugport 1
    baudrate 115200

    RAM Ar�zalar�
    -----------
    tan�mlay�c�: {badmemory}

    Genel Ayarlar
    ---------------
    tan�mlay�c�: {globalsettings}
    inherit {dbgsettings}
    {emssettings}
    {badmemory}

    �ny�kleme Y�kleyicisi Ayarlar�
    --------------------
    tan�mlay�c�: {bootloadersettings}
    inherit {globalsettings}
    {hypervisorsettings}

    Hiper Y�netici Ayarlar�
    -------------------
    tan�mlay�c�: {hypervisorsettings}
    hypervisordebugtype Serial
    hypervisordebugport 1
    hypervisorbaudrate 115200

    Y�kleyici Ayarlar�na Devam Et
    ----------------------
    tan�mlay�c�: {resumeloadersettings}
    inherit {globalsettings}

    Ayg�t se�enekleri
    --------------
    tan�mlay�c�: {6972ed7d-65d1-11e9-a900-bcaec5cea7e6}
    description Ramdisk Options
    ramdisksdidevice partition=C:
    ramdisksdipath \Recovery\6972ed7c-65d1-11e9-a900-bcaec5cea7e6\boot.sdi


    LastRegBack: 2020-03-29 17:43
    ==================== End of FRST.txt ========================




  • Logları inceledikten sonra tekrar yazacağım.
  • quote:

    Orijinalden alıntı: Malware Removal

    Logları inceledikten sonra tekrar yazacağım.
    Loglar incelenip konu sahibine cevap yazılmasına rağmen cevap alınamaması nedeni ile önerilerim tekrar düzenlenerek silinmiştir.

    NOT: Konusunu 2 gün cevapsız bırakanlara cevap vermiyor ve konuyu sonlandırıyorum. Bir daha raporlarına bakmıyorum.



    < Bu mesaj bu kişi tarafından değiştirildi Malware Removal -- 14 Nisan 2020; 14:42:47 >
  • Evet hocam bu forumdan geliyorum.
    https://forum.donanimhaber.com/yavaslama-isinma-virus-etkileri--142893911#142904286

    Şimdi istediğiniz programı indirdim tarattım ve loglarını size atıyorum.
    upload.express
    upload.express - Free file sharing
    https://upload.express/download/5e9760fd0b1d6d00016c9f2c




  • quote:

    Orijinalden alıntı: CanCLc

    Evet hocam bu forumdan geliyorum.
    https://forum.donanimhaber.com/yavaslama-isinma-virus-etkileri--142893911#142904286

    Şimdi istediğiniz programı indirdim tarattım ve loglarını size atıyorum.
    https://upload.express/download/5e9760fd0b1d6d00016c9f2c
    Loglarınızı inceliyorum.
    İnceleme epey bir zaman alır. Bittiğinde yazacağım buraya.




  • 
Sayfa: önceki 2324252627
Sayfaya Git
Git
sonraki
- x
Bildirim
mesajınız kopyalandı (ctrl+v) yapıştırmak istediğiniz yere yapıştırabilirsiniz.