Şimdi Ara

HijackThis. Performans + Güvenlik! (Virüslerden kurtulun). 500.000+ (272. sayfa)

Daha Fazla
Bu Konudaki Kullanıcılar: Daha Az
3 Misafir - 3 Masaüstü
5 sn
9.878
Cevap
17
Favori
1.234.477
Tıklama
Daha Fazla
İstatistik
  • Konu İstatistikleri Yükleniyor
0 oy
Öne Çıkar
Sayfa: önceki 270271272273274
Sayfaya Git
Git
sonraki
Giriş
Mesaj
  • çok teşekkürler serji görev yöneticisinde cpu fazla kullanılıyor gösteriyor ama bilgisayar virüs girmedigi zamandaki kadar hızlı. birde mouse göstergecinde ilk virüs girdiginde her 2-3 saniyede bir kum saati beliriyor, 1 sn kdr donuyordu. söyledigin işlemlerden sonra şu an bu işlem 5 saniye kadar durunca kum saati beliriyor, sonra hemen kayboluyor. sistem yöneticisinde kullanıcı adımın karsısındaki işlemleri kapattıgımda bir daha kum saati falan çıkmıyor. acaba bu işlemlerden birindemi sorun var? neyse seni bugünlük çok yorduk inş. sınavın iyi geçer çok sagol. virüs girdikten sonra rahat 20 antivirüs vb. program denedim hiçbiri sorunu çözmedi. çok tskrler iyi geceler.
  • HBService32(System.exe)'den bir türlü kurtulamıyorum...

    Evet 1 haftadır bilgisayar kullanamama neden olan trojen,virüs,spy her ne halt ise bir türlü kurtulamadım.İki elin parmakları kadar antivirüs,antitrojen,antispyware programı yükledim fakat sorun düzelmedi.Halen Kayıt defterinde "Run"ın içinde ve msconfig de duruyor.Ne yapabiliriz ?

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\Program Files\AntiVir PersonalEdition Premium\avgnt.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\AntiVir PersonalEdition Premium\sched.exe
    C:\Program Files\AntiVir PersonalEdition Premium\avguard.exe
    C:\Program Files\AntiVir PersonalEdition Premium\avesvc.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
    C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\WINDOWS\system32\wdfmgr.exe
    C:\Program Files\AntiVir PersonalEdition Premium\avmailc.exe
    C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Spyware Doctor\TFEngine\TFService.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe




  • Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:40:32, on 18.10.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\McAfee\Common Framework\FrameworkService.exe
    C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
    C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\Program Files\McAfee\Common Framework\UdaterUI.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\hkcmd.exe
    C:\WINDOWS\system32\igfxpers.exe
    C:\Program Files\McAfee\Common Framework\McTray.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\WINDOWS\tsnpstd3.exe
    C:\WINDOWS\vsnpstd3.exe
    C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe
    C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\a.exe
    C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\f.exe
    C:\Program Files\Hewlett-Packard\Toolbox\jre\bin\javaw.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
    C:\Documents and Settings\Administrator\Desktop\HiJackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =http://www.meteor.gov.tr
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =http://www.meteor.gov.tr
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =http://www.dmi.meteor.gov.tr/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Oturum Açma Yardım Aracı - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
    O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
    O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
    O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
    O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
    O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
    O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
    O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe
    O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
    O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [StatusClient 2.6] C:\Program Files\Hewlett-Packard\Toolbox\StatusClient\StatusClient.exe /auto
    O4 - HKLM\..\Run: [TomcatStartup 2.5] C:\Program Files\Hewlett-Packard\Toolbox\hpbpsttp.exe
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
    O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [Somefox] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\a.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: Microsoft Excel'e Gö&nder - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {34635AA6-B593-4F06-9EDD-5FF60FC13310} (Speaky Chat) -http://download.speakyweb.com/speakyldr.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1178772105500
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -http://www.adobe.com/products/acrobat/nos/gp.cab
    O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) -http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
    O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
    O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
    O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

    --
    End of file - 7473 bytes


    sabah açtığımdan beri alt sağda devamlı olarak u have security problem yazısı çıkıyor. tıklayınca da antivirus reklam sayfaları açılıyor. spy sweeper kullandım ama geçmedi. ne yapabilirim?




  • Logfile of Trend Micro HijackThis v2.0.2 
    Scan saved at 11:58:01, on 16.10.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe
    C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
    C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe
    C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
    C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Opera\opera.exe
    C:\Documents and Settings\cilgin\Desktop\HiJackThis.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar
    O1 - Hosts: 127.1 localhost
    O1 - Hosts: 127.1 fffff8888fsgfbghj88.cn
    O1 - Hosts: 127.1 61.134.37.12
    O1 - Hosts: 127.1 ko.ssa387.cn
    O1 - Hosts: 127.1 www.ndxrr.cn
    O1 - Hosts: 127.1 12345.ssa387.cn
    O1 - Hosts: 127.1 lihai88.com
    O1 - Hosts: 127.1 wwwwhf.cn
    O1 - Hosts: 127.1 a89369093.sq.u9idc.com
    O1 - Hosts: 127.1 www.mmd178.cn
    O1 - Hosts: 127.1 www.178mmd.cn
    O1 - Hosts: 127.1 www.wenzhuoyyy.cn
    O1 - Hosts: 127.1 tw.lovechina.tw.cn
    O1 - Hosts: 127.1 222.189.238.151
    O1 - Hosts: 127.1 222.179.185.78
    O1 - Hosts: 127.1 www.wq9q.cn
    O1 - Hosts: 127.1 593ffcey.cn
    O1 - Hosts: 127.1 set.yay520.cn
    O1 - Hosts: 127.1 tenmoc999.cn
    O1 - Hosts: 127.1 lihai88.com
    O1 - Hosts: 127.1 121.kcuf-01.com
    O1 - Hosts: 127.1 www.ew1q.cn
    O1 - Hosts: 127.1 www.b3sk.cn
    O1 - Hosts: 127.1 up.bizmd.cn
    O1 - Hosts: 127.1 www.ms2a.cn
    O1 - Hosts: 127.1 www.wo9188.cn
    O1 - Hosts: 127.1 www.fgetchr.cn
    O1 - Hosts: 127.1 www.e6zx.cn
    O1 - Hosts: 127.1 hai067.com
    O1 - Hosts: 127.1 hai088.com
    O1 - Hosts: 127.1 778899.jd8j.cn
    O1 - Hosts: 127.1 sql.78-11.net
    O1 - Hosts: 127.1 www.bbbirdy.com
    O1 - Hosts: 127.1 www.s1na1.com.cn
    O1 - Hosts: 127.1 www.dianyinjzd.cn
    O1 - Hosts: 127.1 www.dj5201314dj.com
    O1 - Hosts: 127.1 max-2.cn
    O1 - Hosts: 127.1 a.asp-o.cn
    O1 - Hosts: 127.1 b.asp-o.cn
    O1 - Hosts: 127.1 c.asp-o.cn
    O1 - Hosts: 127.1 x.kprobb.cn
    O1 - Hosts: 127.1 js.php-k.cn
    O1 - Hosts: 127.1 max-1.cn
    O1 - Hosts: 127.1 max-3.cn
    O1 - Hosts: 127.1 max-4.cn
    O1 - Hosts: 127.1 max-5.cn
    O1 - Hosts: 127.1 max-6.cn
    O1 - Hosts: 127.1 max-7.cn
    O1 - Hosts: 127.1 max-8.cn
    O1 - Hosts: 127.1 max-9.cn
    O1 - Hosts: 127.1 max-10.cn
    O1 - Hosts: 127.1 max-11.cn
    O1 - Hosts: 127.1 max-12.cn
    O1 - Hosts: 127.1 twocannon250.com.cn
    O1 - Hosts: 127.1 www.133mm.cn
    O1 - Hosts: 127.1 www.51vmm.cn
    O1 - Hosts: 127.1 www.7mmoo.cn
    O1 - Hosts: 127.1 www.99mmm.org.cn
    O1 - Hosts: 127.1 www.hdec.cn
    O1 - Hosts: 127.1 www.picc18.com
    O1 - Hosts: 127.1 www.kissdh.com
    O1 - Hosts: 127.1 www.x7v.cn
    O1 - Hosts: 127.1 biqulu.cn
    O1 - Hosts: 127.1 2008.qq2006.com.cn
    O1 - Hosts: 127.1 giaitrisex.com
    O1 - Hosts: 127.1 www.giaitrisex.com
    O1 - Hosts: 127.1 www.giaitrituoitre.net
    O1 - Hosts: 127.1 mekiep.com
    O1 - Hosts: 127.1 www.1sex1day.com
    O1 - Hosts: 127.1 a.9ymm.com
    O1 - Hosts: 127.1 bobo.7wyt.com
    O1 - Hosts: 127.1 www.591caobi.cn
    O1 - Hosts: 127.1 www.hrz008.cn
    O1 - Hosts: 127.1 asp-15.cn
    O1 - Hosts: 127.1 asp-12.cn
    O1 - Hosts: 127.1 www.jb88.net
    O1 - Hosts: 127.1 6.a88a.com
    O1 - Hosts: 127.1 w.b2c3.cn
    O1 - Hosts: 127.1 m.c5x8.com
    O1 - Hosts: 127.1 www.518sfw.cn
    O1 - Hosts: 127.1 www.jjyyzmj.cn
    O1 - Hosts: 127.1 u.cnmrx.net
    O1 - Hosts: 127.1 duowan.czm.cn
    O1 - Hosts: 127.1 xccxcxcxcxcx.cn
    O1 - Hosts: 127.1 google-yahoo.org.cn
    O1 - Hosts: 127.1 tudou-net.org.cn
    O1 - Hosts: 127.1 downloads.zango.com
    O1 - Hosts: 127.1 ftp.surfnet.nl
    O1 - Hosts: 127.1 bis.180solutions.com
    O1 - Hosts: 127.1 installs.hotbar.com
    O1 - Hosts: 127.1 www.hbdownloads.com
    O1 - Hosts: 127.1 static.zangocash.com
    O1 - Hosts: 127.1 www.qq-songli.cn
    O1 - Hosts: 127.1 aa.9234.net
    O1 - Hosts: 127.1 www.97love.info
    O1 - Hosts: 127.1 97love.info
    O1 - Hosts: 127.1 www.zyzhuiku.cn
    O1 - Hosts: 127.1 zyzhuiku.cn
    O1 - Hosts: 127.1 www.lang18.com
    O1 - Hosts: 127.1 lang18.com
    O1 - Hosts: 127.1 sao6666.com
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - (no file)
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" /min
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [HBService32] System.exe
    O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - AutorunsDisabled - (no file)
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O20 - AppInit_DLLs: HBmhly.dll,HBBO.dll,HBCHIBI.dll,HBQQSG.dll,HBZHUXIAN.dll,HBFY.dll,HBZG.dll,HBQQFFO.dll,HBSO2.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O21 - SSODL: msnmsg - {DA191DE0-AA86-4ED0-4B87-293D48B2AE99} - C:\Program Files\Messenger\msgmr.dll
    O21 - SSODL: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - (no file)
    O21 - SSODL: Upnp - {DE01DA19-A6A8-EB80-4D47-248DEB2A9399} - C:\WINDOWS\system32\upnpsrv.dll (file missing)
    O23 - Service: Avira Premium Security Suite Firewall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe
    O23 - Service: Avira Premium Security Suite MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
    O23 - Service: Avira Premium Security Suite Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
    O23 - Service: Avira Premium Security Suite Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
    O23 - Service: Avira Premium Security Suite WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Avira Premium Security Suite MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe
    O23 - Service: PVBNGX - Unknown owner - C:\DOCUME~1\cilgin\LOCALS~1\Temp\PVBNGX.exe (file missing)

    --
    End of file - 7535 bytes


    ip saldırısı yapan virüslerle başım belada.




  • quote:

    Orjinalden alıntı: recoill
    Normale döndü sanirim Cok sagolasin

    Iste hepsi bu kadar. Sistem temiz. Kolay gelsin.


    quote:

    Orjinalden alıntı: linkin_park20

    çok teşekkürler serji görev yöneticisinde cpu fazla kullanılıyor gösteriyor ama bilgisayar virüs girmedigi zamandaki kadar hızlı. birde mouse göstergecinde ilk virüs girdiginde her 2-3 saniyede bir kum saati beliriyor, 1 sn kdr donuyordu. söyledigin işlemlerden sonra şu an bu işlem 5 saniye kadar durunca kum saati beliriyor, sonra hemen kayboluyor. sistem yöneticisinde kullanıcı adımın karsısındaki işlemleri kapattıgımda bir daha kum saati falan çıkmıyor. acaba bu işlemlerden birindemi sorun var? neyse seni bugünlük çok yorduk inş. sınavın iyi geçer çok sagol. virüs girdikten sonra rahat 20 antivirüs vb. program denedim hiçbiri sorunu çözmedi. çok tskrler iyi geceler.

    rica ederim. Sorunun cozuldugune cok sevindim. Eger islemleri sonlandirinca duzeliyorsa evet o islemlerde bir sorun vardir. Kontrol etmeni oneririm. Takildigin bir yer olursa buradayim. Kolay eglsin




  • quote:

    Orjinalden alıntı: Méchatronic

    HBService32(System.exe)'den bir türlü kurtulamıyorum...

    Evet 1 haftadır bilgisayar kullanamama neden olan trojen,virüs,spy her ne halt ise bir türlü kurtulamadım.İki elin parmakları kadar antivirüs,antitrojen,antispyware programı yükledim fakat sorun düzelmedi.Halen Kayıt defterinde "Run"ın içinde ve msconfig de duruyor.Ne yapabiliriz ?

    HJ logu'nu eksik gondermissin. Hic bir kismini kesmeden gondermen gerekiyor.


    quote:

    Orjinalden alıntı: edgar davids
    sabah açtığımdan beri alt sağda devamlı olarak u have security problem yazısı çıkıyor. tıklayınca da antivirus reklam sayfaları açılıyor. spy sweeper kullandım ama geçmedi. ne yapabilirim?

    * HijackThis adlı programı açın.
    * Do a system scan only seçeneğine tıklayın.
    * Aşağıdaki satırları işaretleyin.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar 
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Oturum Açma Yardım Aracı - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe
    O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
    O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [Somefox] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\a.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: Microsoft Excel'e Gö&nder - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    * CTRL+ALT+DEL basıp işlemler sekmesine gelin. Kullanıcı Adınızın karşısındaki HijackThis.exe ve explorer.exe hariç tüm işlemleri sonlandırın. HijackThis hariç tüm programları, pencereleri kapatın ve Fix Checked butonuna tıklayın. Ardından bilgisayarınızı hemen yeniden başlatın.

    Daha sonra bir HJ logu daha gonder.




  • quote:

    Orjinalden alıntı: serji


    quote:

    Orjinalden alıntı: verbandal
    serji ben elinterin arkadaşı, banlanmış o yüzden ben veriyorum malwarebytes log'unu. bu arada pc hala yavaşmış
    işte log:

    Bir sorun olusmus MB ile sanirim. Bir de bunlari deneyin:

    * Bilgisayarınızı taramak için Bitdefender Çevrimiçi Tarama açın.

    http://www.bitdefender.com/scan8/ie.html

    * I agree ve sonra da Scan tıklayın. (Ayarları değiştirmeyin)
    * Tarama bittikten sonra Detected Problems sekmesini tıklayın ve Click here to export the scan report.
    * Raporu HTML olarak kaydettikten sonra mesajınıza ekleyerek bize gönderin.

    SuperAntiSpyware adlı programı indirip kurun.

    http://www.superantispyware.com/downloads/SUPERAntiSpyware.exe

    * SUPERAntiSypware.exe çift tıklayın ve programı varsayılan ayarlarıyla kurun.
    * Masaüstünüzde programın ikonu oluşacaktır. Programı çalıştırmak için ikona çift tıklayın.
    * Eğer güncellemeniz için soru sorarsa Evet tıklayın. Eğer sormazsa, taratmadan önce kendiniz Check for Updates butonuna tıklayarak güncelleştirin.
    * Configuration and Preferences sekmesi altında Preferences butonuna tıklayın.
    * General and Startup sekmesine tıklayın ve Start-up Options altında Start SUPERAntiSpyware when Windows starts seçeneğinin seçili olmadığından emin olun.
    * Scanning Control sekmesine gelin ve Scanner Options altında yalnızca aşağıdakilerin işaretli olduğundan emin olun. (Diğerlerini işaretsiz bırakın.)

    # Close browsers before scanning.
    # Scan for tracking cookies.
    # Terminate memory threats before quarantining.
    * Close butonuna tıklayarak programı kapatın.
    * Henüz sisteminizi taratmayın.

    Şimdi tekrar programı çalıştırın:

    * Ana menüde Scan for Harmful Software altında Scan your computer tıklayın.
    * Sol tarafta C:\Fixed Drive işaretli olduğundan emin olun.
    * Sağ tarafta Complete Scan altında Perform Complete Scan seçin ve Next tıklayın.
    * Tarama işlemi bittikten sonra zararlı yazılımları içeren bir tarama özeti açılacak. OK tıklayın.
    * Herşeyin işaretli olduğundan emin olun ve Next tıklayın.
    * Quarantine and Removal is Complete şeklinde bir uyarı alacaksınız. OK tıklayın ve ana menüye dönmek için Finish tıklayın.
    * Eğer yeniden başlatmanız gerektiği söylenirse, Yes tıklayıp bilgisayarınızı yeniden başlatın.
    * İşlem sonuçlarını öğrenmek için:
    # Preferences tıklayın ve Statistics/Logs sekmesine gelin.
    # Scanner Logs altında SUPERAntiSpyware Scan Log çift tıklayın.
    # Eğer birden fazla log varsa, güncel olanı seçin ve View log tıklayın. Bir yazı dosyası açılacaktır.
    # Açılan dosyayı kaydedip mesajınıza ekleyerek bize gönderin.
    * Close tıklayarak programı kapatın.


    abi tamı tamına dörtbuçuk saat bitdef. taraması yaptık işte sonuçları:



    bu da antispyware:

    Application Version : 4.21.1004

    Core Rules Database Version : 3601
    Trace Rules Database Version: 1587

    Scan type : Complete Scan
    Total Scan Time : 03:45:37

    Memory items scanned : 480
    Memory threats detected : 0
    Registry items scanned : 4786
    Registry threats detected : 0
    File items scanned : 78391
    File threats detected : 11

    Adware.Tracking Cookie
    C:\Documents and Settings\EliNTeR\Cookies\EliNTeR@atdmt[2].txt
    C:\Documents and Settings\EliNTeR\Cookies\EliNTeR@ad.e-kolay[1].txt
    C:\Documents and Settings\EliNTeR\Cookies\EliNTeR@bs.serving-sys[2].txt
    C:\Documents and Settings\EliNTeR\Cookies\EliNTeR@weborama[1].txt
    C:\Documents and Settings\EliNTeR\Cookies\EliNTeR@doubleclick[1].txt
    C:\Documents and Settings\EliNTeR\Cookies\EliNTeR@serving-sys[2].txt
    C:\Documents and Settings\EliNTeR\Cookies\EliNTeR@www.googleadservices[1].txt
    C:\Documents and Settings\EliNTeR\Cookies\EliNTeR@2o7[2].txt
    C:\Documents and Settings\EliNTeR\Cookies\EliNTeR@adtech[1].txt
    C:\Documents and Settings\EliNTeR\Cookies\EliNTeR@banner.sahibinden[2].txt
    C:\Documents and Settings\EliNTeR\Cookies\EliNTeR@ad.yieldmanager[1].txt


    -------

    bunlardanda bi sonuç çıkmicak sanırım




  • quote:

    Orjinalden alıntı: WhyTheyCallMeInsane
    ip saldırısı yapan virüslerle başım belada.

    * HijackThis adlı programı açın.
    * Do a system scan only seçeneğine tıklayın.
    * Aşağıdaki satırları işaretleyin.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar 
    O1 - Hosts: 127.1 localhost
    O1 - Hosts: 127.1 fffff8888fsgfbghj88.cn
    O1 - Hosts: 127.1 61.134.37.12
    O1 - Hosts: 127.1 ko.ssa387.cn
    O1 - Hosts: 127.1 www.ndxrr.cn
    O1 - Hosts: 127.1 12345.ssa387.cn
    O1 - Hosts: 127.1 lihai88.com
    O1 - Hosts: 127.1 wwwwhf.cn
    O1 - Hosts: 127.1 a89369093.sq.u9idc.com
    O1 - Hosts: 127.1 www.mmd178.cn
    O1 - Hosts: 127.1 www.178mmd.cn
    O1 - Hosts: 127.1 www.wenzhuoyyy.cn
    O1 - Hosts: 127.1 tw.lovechina.tw.cn
    O1 - Hosts: 127.1 222.189.238.151
    O1 - Hosts: 127.1 222.179.185.78
    O1 - Hosts: 127.1 www.wq9q.cn
    O1 - Hosts: 127.1 593ffcey.cn
    O1 - Hosts: 127.1 set.yay520.cn
    O1 - Hosts: 127.1 tenmoc999.cn
    O1 - Hosts: 127.1 lihai88.com
    O1 - Hosts: 127.1 121.kcuf-01.com
    O1 - Hosts: 127.1 www.ew1q.cn
    O1 - Hosts: 127.1 www.b3sk.cn
    O1 - Hosts: 127.1 up.bizmd.cn
    O1 - Hosts: 127.1 www.ms2a.cn
    O1 - Hosts: 127.1 www.wo9188.cn
    O1 - Hosts: 127.1 www.fgetchr.cn
    O1 - Hosts: 127.1 www.e6zx.cn
    O1 - Hosts: 127.1 hai067.com
    O1 - Hosts: 127.1 hai088.com
    O1 - Hosts: 127.1 778899.jd8j.cn
    O1 - Hosts: 127.1 sql.78-11.net
    O1 - Hosts: 127.1 www.bbbirdy.com
    O1 - Hosts: 127.1 www.s1na1.com.cn
    O1 - Hosts: 127.1 www.dianyinjzd.cn
    O1 - Hosts: 127.1 www.dj5201314dj.com
    O1 - Hosts: 127.1 max-2.cn
    O1 - Hosts: 127.1 a.asp-o.cn
    O1 - Hosts: 127.1 b.asp-o.cn
    O1 - Hosts: 127.1 c.asp-o.cn
    O1 - Hosts: 127.1 x.kprobb.cn
    O1 - Hosts: 127.1 js.php-k.cn
    O1 - Hosts: 127.1 max-1.cn
    O1 - Hosts: 127.1 max-3.cn
    O1 - Hosts: 127.1 max-4.cn
    O1 - Hosts: 127.1 max-5.cn
    O1 - Hosts: 127.1 max-6.cn
    O1 - Hosts: 127.1 max-7.cn
    O1 - Hosts: 127.1 max-8.cn
    O1 - Hosts: 127.1 max-9.cn
    O1 - Hosts: 127.1 max-10.cn
    O1 - Hosts: 127.1 max-11.cn
    O1 - Hosts: 127.1 max-12.cn
    O1 - Hosts: 127.1 twocannon250.com.cn
    O1 - Hosts: 127.1 www.133mm.cn
    O1 - Hosts: 127.1 www.51vmm.cn
    O1 - Hosts: 127.1 www.7mmoo.cn
    O1 - Hosts: 127.1 www.99mmm.org.cn
    O1 - Hosts: 127.1 www.hdec.cn
    O1 - Hosts: 127.1 www.picc18.com
    O1 - Hosts: 127.1 www.kissdh.com
    O1 - Hosts: 127.1 www.x7v.cn
    O1 - Hosts: 127.1 biqulu.cn
    O1 - Hosts: 127.1 2008.qq2006.com.cn
    O1 - Hosts: 127.1 giaitrisex.com
    O1 - Hosts: 127.1 www.giaitrisex.com
    O1 - Hosts: 127.1 www.giaitrituoitre.net
    O1 - Hosts: 127.1 mekiep.com
    O1 - Hosts: 127.1 www.1sex1day.com
    O1 - Hosts: 127.1 a.9ymm.com
    O1 - Hosts: 127.1 bobo.7wyt.com
    O1 - Hosts: 127.1 www.591caobi.cn
    O1 - Hosts: 127.1 www.hrz008.cn
    O1 - Hosts: 127.1 asp-15.cn
    O1 - Hosts: 127.1 asp-12.cn
    O1 - Hosts: 127.1 www.jb88.net
    O1 - Hosts: 127.1 6.a88a.com
    O1 - Hosts: 127.1 w.b2c3.cn
    O1 - Hosts: 127.1 m.c5x8.com
    O1 - Hosts: 127.1 www.518sfw.cn
    O1 - Hosts: 127.1 www.jjyyzmj.cn
    O1 - Hosts: 127.1 u.cnmrx.net
    O1 - Hosts: 127.1 duowan.czm.cn
    O1 - Hosts: 127.1 xccxcxcxcxcx.cn
    O1 - Hosts: 127.1 google-yahoo.org.cn
    O1 - Hosts: 127.1 tudou-net.org.cn
    O1 - Hosts: 127.1 downloads.zango.com
    O1 - Hosts: 127.1 ftp.surfnet.nl
    O1 - Hosts: 127.1 bis.180solutions.com
    O1 - Hosts: 127.1 installs.hotbar.com
    O1 - Hosts: 127.1 www.hbdownloads.com
    O1 - Hosts: 127.1 static.zangocash.com
    O1 - Hosts: 127.1 www.qq-songli.cn
    O1 - Hosts: 127.1 aa.9234.net
    O1 - Hosts: 127.1 www.97love.info
    O1 - Hosts: 127.1 97love.info
    O1 - Hosts: 127.1 www.zyzhuiku.cn
    O1 - Hosts: 127.1 zyzhuiku.cn
    O1 - Hosts: 127.1 www.lang18.com
    O1 - Hosts: 127.1 lang18.com
    O1 - Hosts: 127.1 sao6666.com
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - (no file)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [HBService32] System.exe
    O4 - HKCU\..\Run: [kamsoft] C:\WINDOWS\system32\ckvo.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O9 - Extra button: (no name) - AutorunsDisabled - (no file)
    O20 - AppInit_DLLs: HBmhly.dll,HBBO.dll,HBCHIBI.dll,HBQQSG.dll,HBZHUXIAN.dll,HBFY.dll,HBZG.dll,HBQQFFO.dll,HBSO2.dll
    O21 - SSODL: msnmsg - {DA191DE0-AA86-4ED0-4B87-293D48B2AE99} - C:\Program Files\Messenger\msgmr.dll
    O21 - SSODL: ThunderAdvise - {97421D0D-E07F-40DF-8F07-99597B9585AD} - (no file)
    O21 - SSODL: Upnp - {DE01DA19-A6A8-EB80-4D47-248DEB2A9399} - C:\WINDOWS\system32\upnpsrv.dll (file missing)


    * CTRL+ALT+DEL basıp işlemler sekmesine gelin. Kullanıcı Adınızın karşısındaki HijackThis.exe ve explorer.exe hariç tüm işlemleri sonlandırın. HijackThis hariç tüm programları, pencereleri kapatın ve Fix Checked butonuna tıklayın. Ardından bilgisayarınızı hemen yeniden başlatın.

    Daha sonra bir Log daha gonder.




  • Anti virüs ile taradığımda virüs bulmadığı halde sistemim çok yavaş.



    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 14:47:52, on 18.10.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\AppServ\Apache2\bin\Apache.exe
    C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
    C:\AppServ\Apache2\bin\Apache.exe
    C:\AppServ\MySQL\bin\mysqld-nt.exe
    C:\Program Files\CDBurnerXP\NMSAccessU.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\PnkBstrA.exe
    C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
    c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    C:\WINDOWS\system32\ntvdm.exe
    d:\Documents and Settings\Ali\Belgelerim\foptimizerrri\Firefox Ultimate Optimizer.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar
    R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
    O2 - BHO: IeCatch5 Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\PROGRA~1\FlashGet\jccatch.dll
    O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb127\Dealio.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {A3FBAED0-F0FA-43E7-906C-84A22E27751C} - (no file)
    O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
    O2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\PROGRA~1\FlashGet\getflash.dll
    O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
    O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\Msdxm6.ocx
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
    O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [FirefoxUltimateOptimizer] "d:\Documents and Settings\Ali\Belgelerim\foptimizerrri\Firefox Ultimate Optimizer.exe"
    O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
    O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\Ali\Application Data\Dealio\kb127\res\DealioSearch.html
    O8 - Extra context menu item: FlashGet'i kullanarak indir - C:\Program Files\FlashGet\jc_link.htm
    O8 - Extra context menu item: Tümünü FlashGet'i kullanarak indir - C:\Program Files\FlashGet\jc_all.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
    O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
    O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
    O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Apache2 - Apache Software Foundation - C:\AppServ\Apache2\bin\Apache.exe
    O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe
    O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
    O23 - Service: mysql - Unknown owner - C:\AppServ\MySQL\bin\mysqld-nt.exe
    O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
    O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
    O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

    --
    End of file - 6606 bytes




  • quote:

    Orjinalden alıntı: xxXtheXxx

    Anti virüs ile taradığımda virüs bulmadığı halde sistemim çok yavaş.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar 
    R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
    O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb127\Dealio.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: (no name) - {A3FBAED0-F0FA-43E7-906C-84A22E27751C} - (no file)
    O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll
    O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\Msdxm6.ocx
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
    O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\Ali\Application Data\Dealio\kb127\res\DealioSearch.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
    O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    Fixleyip yeniden baslat ve daha sonra bir lOg daha gonder.




  • Logfile of Trend Micro HijackThis v2.0.2 
    Scan saved at 15:55:52, on 16.10.2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
    C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
    C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe
    C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
    C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\WINDOWS\vsnp2std.exe
    C:\WINDOWS\FixCamera.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\MSN Messenger\usnsvc.exe
    C:\Documents and Settings\cilgin\Desktop\HiJackThis.exe

    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" /min
    O4 - HKLM\..\Run: [HBService32] System.exe
    O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe
    O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe
    O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O23 - Service: Avira Premium Security Suite Firewall (AntiVirFirewallService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe
    O23 - Service: Avira Premium Security Suite MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe
    O23 - Service: Avira Premium Security Suite Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
    O23 - Service: Avira Premium Security Suite Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
    O23 - Service: Avira Premium Security Suite WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: Avira Premium Security Suite MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe

    --
    End of file - 2749 bytes


    en son hali bu system.exe yi regeditten bulup system1.exe olarak değiştirdim ama bi faydası olmadı gene.




  • quote:

    Orjinalden alıntı: WhyTheyCallMeInsane
    en son hali bu system.exe yi regeditten bulup system1.exe olarak değiştirdim ama bi faydası olmadı gene.

    Herhangi bir seyi degistirmene gerek yok. Sirasiyla gidecegiz.

    Combofix adli programi indirin.

    http://www.guvenlikuzmanim.com/dosyalar/ComboFix.exe

    1. Tüm açık pencerelerinizi ve programlarınızı kapatın.
    2. Antivirüs ve Antispyware programlarınızı geçici olarak kapatın veya devre dışı bırakın.
    3. ComboFix.exe üzerine çift tıklayın ve programı açın. Programı açtıktan sonra kesinlikle hiç bir işlem yapmayın. 1-2 dakikalık bir mola verin.
    4. ComboFix çalışmaya başladıktan sonra sizden 1 ya da 2 tuşuna basmanız istenecektir. Devam etmek için 1 tuşuna basın.
    5. ComboFix olası bir aksilik durumunda sistemizi geri yükleyebilmek amacıyla Kayıt Defterinizin bir yedeğini alacak ve bir sistem geri yükleme noktası oluşturacaktır.
    6. Bu işlemler sırasında internet bağlantınız kesilecektir. Bu normaldir. Ayrıca sistem saatiniz de değişecektir. Fakat tüm bunlar geçicidir. İşlemler bittikten sonra hepsi orjinal haline geri döndürülecektir.
    7. Biraz sabırlı olmanız gerekebilir çünkü tam 41 aşama söz konusudur.
    8. Son olarak ComboFix işlemlerin sonucunu içeren bir rapor hazırlayacaktır. Bu sırada masaüstünüz kaybolabilir. Fakat kısa sürede geri yüklenecektir. İşlemler bittikten sonra ComboFix kapanacak ve size bir rapor açılacaktır. Bu raporu C:\ComboFix.txt bulabilirsiniz.
    9. C:\ComboFix.txt dosyasını mesajınıza ekleyerek bize gönderin.




  • link çalışmıyo anlık bi sorun var heralde çalışmaya başlayınca indirir buraya eklerim.

    görüşmek üzre.
  • quote:

    Orjinalden alıntı: WhyTheyCallMeInsane

    link çalışmıyo anlık bi sorun var heralde çalışmaya başlayınca indirir buraya eklerim.

    görüşmek üzre.

    Linki guncelledim.
  • ComboFix 08-10-17.01 - cilgin 2008-10-18 16:31:06.1 - NTFSx86 
    Microsoft Windows XP Professional 5.1.2600.2.1254.1.1055.18.52 [GMT 3:00]
    Running from: C:\Documents and Settings\cilgin\Desktop\ComboFix.exe
    * Created a new restore point

    [COLOR=RED][B]WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !![/B][/COLOR]
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\Program Files\Messenger\msgmr.dll
    C:\WINDOWS\AppPatch\AcSpecf.sdb
    C:\WINDOWS\AppPatch\AcXtrnel.sdb
    C:\WINDOWS\Fonts\Framdee.ttf
    C:\WINDOWS\system32\[u]0[/u]8223B03.cfg
    C:\WINDOWS\system32\122B901E.cfg
    C:\WINDOWS\system32\43ACDCC5.cfg
    C:\WINDOWS\system32\495271CA.cfg
    C:\WINDOWS\system32\4BF9CBA3.cfg
    C:\WINDOWS\system32\58FF3024.cfg
    C:\WINDOWS\system32\7ADC2AB1.cfg
    C:\WINDOWS\system32\82710040.cfg
    C:\WINDOWS\system32\9CA963CA.cfg
    C:\WINDOWS\system32\C250CF20.cfg
    C:\WINDOWS\system32\C56BCC10.cfg
    C:\WINDOWS\system32\D91BC61E.cfg
    C:\WINDOWS\system32\DA63E650.cfg
    C:\WINDOWS\system32\DE02F764.cfg
    C:\WINDOWS\system32\drivers\HBKernel32.sys
    C:\WINDOWS\system32\E4814792.cfg

    .
    ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    -------\Legacy_HBKERNEL32
    -------\Service_HBKernel32


    ((((((((((((((((((((((((( Files Created from 2008-09-18 to 2008-10-18 )))))))))))))))))))))))))))))))
    .

    2008-10-16 15:45 . 2004-08-04 00:45 16,384 --a------ C:\WINDOWS\system32\ipsink.ax
    2008-10-16 15:45 . 2004-08-04 00:45 16,384 --a--c--- C:\WINDOWS\system32\dllcache\ipsink.ax
    2008-10-16 15:45 . 2004-08-03 23:10 15,360 --a------ C:\WINDOWS\system32\drivers\StreamIP.sys
    2008-10-16 15:45 . 2004-08-03 23:10 15,360 --a--c--- C:\WINDOWS\system32\dllcache\streamip.sys
    2008-10-16 15:45 . 2004-08-03 23:10 11,136 --a------ C:\WINDOWS\system32\drivers\SLIP.sys
    2008-10-16 15:45 . 2004-08-03 23:10 11,136 --a--c--- C:\WINDOWS\system32\dllcache\slip.sys
    2008-10-16 15:45 . 2004-08-03 23:10 10,880 --a------ C:\WINDOWS\system32\drivers\NdisIP.sys
    2008-10-16 15:45 . 2004-08-03 23:10 10,880 --a--c--- C:\WINDOWS\system32\dllcache\ndisip.sys
    2008-10-16 15:45 . 2004-08-03 22:58 5,504 --a------ C:\WINDOWS\system32\drivers\MSTEE.sys
    2008-10-16 15:45 . 2004-08-03 22:58 5,504 --a--c--- C:\WINDOWS\system32\dllcache\mstee.sys
    2008-10-16 15:44 . 2004-08-03 23:10 85,376 --a------ C:\WINDOWS\system32\drivers\NABTSFEC.sys
    2008-10-16 15:44 . 2004-08-03 23:10 85,376 --a--c--- C:\WINDOWS\system32\dllcache\nabtsfec.sys
    2008-10-16 15:44 . 2004-08-03 23:10 19,328 --a------ C:\WINDOWS\system32\drivers\WSTCODEC.SYS
    2008-10-16 15:44 . 2004-08-03 23:10 19,328 --a--c--- C:\WINDOWS\system32\dllcache\wstcodec.sys
    2008-10-16 15:44 . 2004-08-03 23:10 17,024 --a------ C:\WINDOWS\system32\drivers\CCDECODE.sys
    2008-10-16 15:44 . 2004-08-03 23:10 17,024 --a--c--- C:\WINDOWS\system32\dllcache\ccdecode.sys
    2008-10-16 15:43 . 2008-10-16 15:43 <DIR> d-------- C:\Program Files\Common Files\snp2std
    2008-10-16 15:43 . 2008-10-16 15:43 <DIR> d-------- C:\Documents and Settings\cilgin\Application Data\InstallShield
    2008-10-16 11:08 . 2008-10-16 11:08 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Avira
    2008-10-16 01:39 . 2008-10-16 01:39 53,248 --a------ C:\WINDOWS\linkinfo.VIR
    2008-10-16 01:24 . 2008-10-16 01:24 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
    2008-10-16 01:24 . 2008-10-16 01:24 <DIR> d-------- C:\Documents and Settings\cilgin\Application Data\SUPERAntiSpyware.com
    2008-10-16 01:24 . 2008-10-16 01:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
    2008-10-16 01:23 . 2008-10-16 01:23 <DIR> d-------- C:\Program Files\Common Files\Wise Installation Wizard
    2008-10-16 01:22 . 2008-10-16 01:22 <DIR> d-------- C:\Program Files\CCleaner
    2008-10-15 20:23 . 2008-10-15 20:23 <DIR> d---s---- C:\Documents and Settings\cilgin\UserData
    2008-10-15 20:21 . 2008-10-15 20:21 <DIR> d-------- C:\Program Files\Avira
    2008-10-15 20:21 . 2008-10-15 20:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Avira
    2008-10-15 20:21 . 2008-05-07 14:20 71,592 --a------ C:\WINDOWS\system32\drivers\avfwot.sys
    2008-10-15 20:21 . 2008-05-07 10:51 71,464 --a------ C:\WINDOWS\system32\drivers\avfwim.sys

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-10-16 12:43 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-10-15 22:23 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2008-09-03 1576176]
    "msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "avgnt"="C:\Program Files\Avira\Avira Premium Security Suite\avgnt.exe" [2008-06-12 266497]
    "FixCamera"="C:\WINDOWS\FixCamera.exe" [2007-02-12 20480]
    "tsnp2std"="C:\WINDOWS\tsnp2std.exe" [2007-05-12 270336]
    "snp2std"="C:\WINDOWS\vsnp2std.exe" [2007-05-10 344064]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "C:\Program Files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
    Authentication Packages REG_MULTI_SZ msv1_0 nwprovau

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusDisableNotify"=dword:00000001
    "UpdatesDisableNotify"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "C:\\Program Files\\MSN Messenger\\livecall.exe"=

    R1 avfwot;avfwot;C:\WINDOWS\system32\DRIVERS\avfwot.sys [2008-05-07 71592]
    R2 AntiVirFirewallService;Avira Premium Security Suite Firewall;C:\Program Files\Avira\Avira Premium Security Suite\avfwsvc.exe [2008-05-16 344321]
    R2 AntiVirMailService;Avira Premium Security Suite MailGuard;C:\Program Files\Avira\Avira Premium Security Suite\avmailc.exe [2008-07-11 164097]
    R2 antivirwebservice;Avira Premium Security Suite WebGuard;C:\Program Files\Avira\Avira Premium Security Suite\AVWEBGRD.EXE [2008-06-12 258305]
    R2 AVEService;Avira Premium Security Suite MailGuard helper service;C:\Program Files\Avira\Avira Premium Security Suite\avesvc.exe [2008-05-09 41217]
    R2 NwSapAgent;SAP Aracısı;C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
    R3 avfwim;AvFw Packet Filter Miniport;C:\WINDOWS\system32\DRIVERS\avfwim.sys [2008-05-07 71464]
    R3 SNP2STD;USB2.0 PC Camera (SNP2STD);C:\WINDOWS\system32\DRIVERS\snp2sxp.sys [2007-05-10 12179584]
    S2 cdralw;NVIDIA Compatible Windows Miniport Driver;C:\WINDOWS\system32\DRIVERS\nvmini.sys [ ]
    S4 PVBNGX;PVBNGX;C:\DOCUME~1\cilgin\LOCALS~1\Temp\PVBNGX.exe [ ]
    .
    - - - - ORPHANS REMOVED - - - -

    ShellExecuteHooks-{4D023DE9-F4B5-4BE0-99C6-7C7AD0CF5426} - 4D023DE9.dll
    ShellExecuteHooks-{4F34C688-FD49-42FC-97F7-87D2F5791612} - 4F34C688.dll
    ShellExecuteHooks-{C56BCC10-503E-43AB-B208-3CD37FCFCE40} - C56BCC10.dll
    MSConfigStartUp-HBService32 - System.exe


    .
    ------- Supplementary Scan -------
    .
    R0 -: HKCU-Main,Start Page = hxxp://www.google.com/
    .

    **************************************************************************

    catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,http://www.gmer.net
    Rootkit scan 2008-10-18 16:34:06
    Windows 5.1.2600 Service Pack 2 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    ------------------------ Other Running Processes ------------------------
    .
    C:\WINDOWS\system32\ati2evxx.exe
    C:\Program Files\Avira\Avira Premium Security Suite\sched.exe
    C:\WINDOWS\system32\ati2evxx.exe
    C:\Program Files\Avira\Avira Premium Security Suite\avguard.exe
    .
    **************************************************************************
    .
    Completion time: 2008-10-18 16:40:05 - machine was rebooted
    ComboFix-quarantined-files.txt 2008-10-18 13:39:58

    Pre-Run: 7.837.380.608 bayt boş
    Post-Run: 7,843,409,920 bayt boş

    142



    hepsi bu




  • Virüs kalmadı gibi Serji yardımların için tşk.
  • quote:

    Orjinalden alıntı: WhyTheyCallMeInsane
    hepsi bu

    Bir HJ logu daha alalim emin olmak icin. Sistem temiz gozukuyor su anda.


    quote:

    Orjinalden alıntı: Golday

    Virüs kalmadı gibi Serji yardımların için tşk.

    Rica ederim Golday. Kolay eglsin.
  • * HijackThis adlı programı açın.
    * Do a system scan only seçeneğine tıklayın.
    * Aşağıdaki satırları işaretleyin.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Windows Live Oturum Açma Yardım Aracı - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [CameraFixer] C:\WINDOWS\CameraFixer.exe
    O4 - HKLM\..\Run: [tsnpstd3] C:\WINDOWS\tsnpstd3.exe
    O4 - HKLM\..\Run: [snpstd3] C:\WINDOWS\vsnpstd3.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [Somefox] C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\a.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: Microsoft Excel'e Gö&nder - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


    * CTRL+ALT+DEL basıp işlemler sekmesine gelin. Kullanıcı Adınızın karşısındaki HijackThis.exe ve explorer.exe hariç tüm işlemleri sonlandırın. HijackThis hariç tüm programları, pencereleri kapatın ve Fix Checked butonuna tıklayın. Ardından bilgisayarınızı hemen yeniden başlatın.

    Daha sonra bir HJ logu daha gonder.



    ctrl+alt+del den işlemleri mi yoksa uygulamaları mı sonlandıracagız? çünkü işlemleri sonlandırmak istediğimde uyarı veriyor




  • quote:

    Orjinalden alıntı: edgar davids
    ctrl+alt+del den işlemleri mi yoksa uygulamaları mı sonlandıracagız? çünkü işlemleri sonlandırmak istediğimde uyarı veriyor

    islemleri sonlandiracaksin. Fakat system olanlar vs degil. Yalnizca kullanici adinin karsisindakiler.
  • yani administrator olanlarımı sadece
    daha başka local service network service ve system var

    kusura bakmayınız pek anlamam bu işlerden
  • 
Sayfa: önceki 270271272273274
Sayfaya Git
Git
sonraki
- x
Bildirim
mesajınız kopyalandı (ctrl+v) yapıştırmak istediğiniz yere yapıştırabilirsiniz.