Şimdi Ara

Trojen sorunu

Daha Fazla
Bu Konudaki Kullanıcılar: Daha Az
2 Misafir - 2 Masaüstü
5 sn
6
Cevap
0
Favori
1.506
Tıklama
Daha Fazla
İstatistik
  • Konu İstatistikleri Yükleniyor
0 oy
Öne Çıkar
Sayfa: 1
Giriş
Mesaj
  • pcye trojen bulaştı, notebook daki touchpad ve klavye çalışmaz hale geldi. combofix yukledım tarama tamamlandı ve sonrasında bi rapor goruntuledı ancak hala klavye falan çalışmıyor. o raporu sızınle paylaşıyorum eger yardım edebilcek biri varsa çok iyi olur.sağolun






    ComboFix 12-11-25.01 - Can 25.11.2012 17:54:54.1.2 - x86
    Microsoft Windows 7 Ultimate 6.1.7600.0.1254.90.1055.18.3069.2258 [GMT 2:00]
    Running from: c:\users\Can\Desktop\ComboFix-07.08-tamindir.exe
    AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160}
    SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD}
    SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    C:\install.exe
    c:\program files\smartdl
    c:\program files\smartdl\gunzip.exe
    c:\program files\smartdl\search.exe
    c:\program files\smartdl\status-o
    c:\program files\smartdl\status
    c:\program files\smartdl\****.exe
    c:\program files\SSearch
    c:\program files\SSearch\search.ico
    c:\program files\SSearch\sqlite3.exe
    C:\torrent.exe
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\chrome.manifest
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\funmoods.css
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\funmoods.xul
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\images\pref.jpg
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\arwDwn.gif
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ae.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\bg.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ch.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\cn.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\cz.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\de.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\eg.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\en.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\es.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\fr.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\gr.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\he.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\il.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\it.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ja.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\jp.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\nl.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\no.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\pl.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\pt.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ro.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ru.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\sa.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\se.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\sv.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\tr.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\ua.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\flgs\us.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\help_16.gif
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\home.gif
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\logo.png
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\privecy_16_hot.gif
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\imgs\tellafriend.gif
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\loader.xul
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\mtstart.js
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\preferences.xul
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\content\tmplt.js
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\install.rdf
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.rsa
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\META-INF\le_c6a58f26_4d2d_4341_b387_c4f2289b6170.sf
    c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\extensions\ffxtlbr@funmoods.com\META-INF\manifest.mf
    C:\w7lxe-v10.exe
    c:\w7lxe-v10.exe\w7lxe-v10.exe
    c:\windows\$NtUninstallKB62280$
    c:\windows\Downloaded Program Files\popcaploader.dll
    c:\windows\Downloaded Program Files\popcaploader.inf
    c:\windows\PFRO.log
    c:\windows\system32\roboot.exe
    .
    ---- Previous Run -------
    .
    c:\program files\Internet Explorer\setupapi.dll
    c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}
    c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\chrome.manifest
    c:\program files\Mozilla Firefox\extensions\{9CE11043-9A15-4207-A565-0C94C42D590D}\install.rdf
    c:\program files\Mozilla Firefox\setupapi.dll
    c:\program files\Securityessentials2010
    c:\users\1120\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Security Essentials 2011.lnk
    c:\users\1120\AppData\Roaming\Security Essentials 2011
    c:\users\1120\AppData\Roaming\Security Essentials 2011\SE2010.exe
    c:\users\1120\AppData\Roaming\Security Essentials 2011\seablbuls\seoxbjrls.cfg
    c:\users\1120\AppData\Roaming\SystemProc
    c:\users\1120\AppData\Roaming\SystemProc\lsass.exe
    c:\users\1120\Desktop\Security Essentials 2011.lnk
    c:\windows\system32\933823387.dat
    c:\windows\system32\crt.dat
    c:\windows\system32\cryptnet32.dll
    c:\windows\system32\shimg.dll
    .
    .
    ((((((((((((((((((((((((( Files Created from 2012-10-25 to 2012-11-25 )))))))))))))))))))))))))))))))
    .
    .
    2012-11-25 16:05 . 2012-11-25 16:07 -------- d-----w- c:\users\Can\AppData\Local\temp
    2012-11-25 16:05 . 2012-11-25 16:05 -------- d-----w- c:\users\Default\AppData\Local\temp
    2012-11-25 15:45 . 2012-11-25 15:49 -------- d-----w- C:\ComboFix-07.08-tamindir
    2012-11-24 22:12 . 2012-11-08 18:00 6812136 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{A9C8B2AA-6779-4D5E-A39F-FC5658EBF0EB}\mpengine.dll
    2012-11-02 21:27 . 2012-11-24 22:15 -------- d-----w- c:\users\Can\AppData\Local\ElevatedDiagnostics
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2012-10-12 05:56 . 2012-04-26 19:39 6918632 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
    2012-10-07 09:47 . 2012-04-07 09:04 696240 ----a-w- c:\windows\system32\FlashPlayerApp.exe
    2012-10-07 09:47 . 2011-05-13 12:41 73136 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IDM Shell Extension]
    @="{CDC95B92-E27C-4745-A8C5-64A52A78855D}"
    [HKEY_CLASSES_ROOT\CLSID\{CDC95B92-E27C-4745-A8C5-64A52A78855D}]
    2011-05-30 16:50 21864 ----a-w- c:\program files\İnternet Download Manager\IDMShellExt.dll
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "uTorrent"="c:\program files\uTorrent\uTorrent.exe" [2011-03-31 399736]
    "DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\DTLite.exe" [2010-04-01 357696]
    "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2009-07-14 1173504]
    "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2007-03-12 153136]
    "Skype"="c:\program files\Skype\Phone\Skype.exe" [2012-07-13 17418928]
    "IDMan"="c:\program files\İnternet Download Manager\idman.exe" [2011-12-29 3462552]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]
    "DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" [2011-03-21 1230704]
    "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
    "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 937920]
    "NeroFilterCheck"="c:\program files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-09 153136]
    .
    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
    "aux1"=wdmaud.drv
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
    @="Service"
    .
    R2 5925;5925;c:\windows\TEMP\5925.sys [x]
    R2 SkypeUpdate;Skype Updater;c:\program files\Skype\Updater\Updater.exe [x]
    R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\DRIVERS\MpNWMon.sys [x]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
    S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [x]
    S2 IDMWFP;IDMWFP;c:\windows\system32\DRIVERS\idmwfp.sys [x]
    S2 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
    S3 netw5v32;Windows Vista 32 Bit için Intel(R) Wireless WiFi Link 5000 Serisi Bağdaştırıcı Sürücüsü;c:\windows\system32\DRIVERS\netw5v32.sys [x]
    S3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [x]
    S3 NisSrv;Microsoft Ağ Denetlemesi;c:\program files\Microsoft Security Client\Antimalware\NisSrv.exe [x]
    S3 RTL8167;Realtek 8167 NT Sürücüsü;c:\windows\system32\DRIVERS\Rt86win7.sys [x]
    .
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2012-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-11-05 18:27]
    .
    2012-11-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files\Google\Update\GoogleUpdate.exe [2010-11-05 18:27]
    .
    .
    ------- Supplementary Scan -------
    .
    uStart Page = hxxp://www.google.com.tr/
    uDefault_Search_URL = hxxp://www.google.com/ie
    mStart Page = hxxp://www.startsearcher.com
    uSearchAssistant = hxxp://www.google.com/ie
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: Bütün linkleri IDM ile indir - c:\program files\İnternet Download Manager\IEGetAll.htm
    IE: IDM ile indir - c:\program files\İnternet Download Manager\IEExt.htm
    IE: Microsoft Excel'e Gö&nder - c:\progra~1\MIF5BA~1\Office10\EXCEL.EXE/3000
    IE: Search the Web - c:\program files\SweetIM\Toolbars\Internet Explorer\resources\menuext.html
    TCP: DhcpNameServer = 192.168.1.1
    TCP: Interfaces\{394F95D4-6045-42F4-AAE3-6D490C41ED4E}: NameServer = 8.8.8.8,208.67.222.222,208.67.220.220
    TCP: Interfaces\{394F95D4-6045-42F4-AAE3-6D490C41ED4E}\D697274646271616C6: NameServer = 8.8.8.8,208.67.222.222,208.67.220.220
    FF - ProfilePath - c:\users\Can\AppData\Roaming\Mozilla\Firefox\Profiles\7kar55x3.default\
    FF - prefs.js: browser.search.defaulturl - hxxp://www.startsearcher.com/?q=
    FF - prefs.js: browser.search.selectedEngine - Yahoo
    FF - prefs.js: browser.startup.homepage - hxxp://www.ddlstart.com/?src=startpage&provider=&provider_name=yahoo&provider_code=&partner_id=750&product_id=872&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.5.0&install_country=TR&install_date=20120811&user_guid=6BBDAD5E5CFE43EE806F5B083FE8F12C&machine_id=adc905e333d7daecb46647820e5927a8&browser=FF&os=win&os_version=6.1-x86-SP0
    FF - prefs.js: keyword.URL - hxxp://www.ddlstart.com/s/?src=addrbar&provider=&provider_name=yahoo&provider_code=&partner_id=750&product_id=872&affiliate_id=&channel=&toolbar_id=200&toolbar_version=2.5.0&install_country=TR&install_date=20120811&user_guid=6BBDAD5E5CFE43EE806F5B083FE8F12C&machine_id=adc905e333d7daecb46647820e5927a8&browser=FF&os=win&os_version=6.1-x86-SP0&q=
    FF - Ext: Skype Click to Call: {82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} - c:\program files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
    FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
    FF - Ext: Java Console: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
    FF - Ext: InternetSearch: plugin@startsearcher.com - %profile%\extensions\plugin@startsearcher.com
    FF - Ext: VideoFileDownload - Download YouTube Videos: plugin@videofiledownload.com - %profile%\extensions\plugin@videofiledownload.com
    FF - Ext: SweetIM Toolbar for Firefox: {EEE6C361-6118-11DC-9C72-001320C79847} - %profile%\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}
    FF - Ext: BS Player Community Toolbar: {fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5} - %profile%\extensions\{fed66dc5-1b74-4a04-8f5c-15c5ace2b9a5}
    FF - Ext: VideoFileDownload - Download YouTube Videos: {EB132DB0-A4CA-11DF-9732-0E29E0D72085} - c:\program files\OApps\firefoxaddon
    FF - Ext: VideoFileDownload - Download YouTube Videos: {EB132DB0-A4CA-11DF-9732-0E29E0D72085} - c:\program files\OApps\firefoxaddon
    FF - Ext: IDM CC: mozilla_cc@internetdownloadmanager.com - c:\users\Can\AppData\Roaming\IDM\idmmzcc5
    FF - user.js: extensions.autoDisableScopes - 14
    FF - user.js: security.csp.enable - false
    FF - user.js: extensions.funmoods.hmpg - true
    FF - user.js: extensions.funmoods.hmpgUrl - hxxp://start.funmoods.com/?f=1&a=iron2&chnl=iron2&cd=2XzutAtN2Y1L1QzutDtDtByEyB0EyD0A0DzyyBtCyByCyEyDtN0D0TzutBtDtCtBtDyBtBtD&cr=1549109549
    FF - user.js: extensions.funmoods.dfltSrch - true
    FF - user.js: extensions.funmoods.srchPrvdr - Search
    FF - user.js: extensions.funmoods.dnsErr - true
    FF - user.js: extensions.funmoods_i.newTab - true
    FF - user.js: extensions.funmoods.newTabUrl - hxxp://start.funmoods.com/?f=2&a=iron2&chnl=iron2&cd=2XzutAtN2Y1L1QzutDtDtByEyB0EyD0A0DzyyBtCyByCyEyDtN0D0TzutBtDtCtBtDyBtBtD&cr=1549109549
    FF - user.js: extensions.funmoods.tlbrSrchUrl -
    FF - user.js: extensions.funmoods.id - 0997764500000000000000247e5ad971
    FF - user.js: extensions.funmoods.instlDay - 15541
    FF - user.js: extensions.funmoods.vrsn - 1.5.23.22
    FF - user.js: extensions.funmoods.vrsni - 1.5.23.22
    FF - user.js: extensions.funmoods_i.vrsnTs - 1.5.23.225:8:50
    FF - user.js: extensions.funmoods.prtnrId - funmoods
    FF - user.js: extensions.funmoods.prdct - funmoods
    FF - user.js: extensions.funmoods.aflt - iron2
    FF - user.js: extensions.funmoods_i.smplGrp - none
    FF - user.js: extensions.funmoods.tlbrId - base
    FF - user.js: extensions.funmoods.instlRef - iron2
    FF - user.js: extensions.funmoods.dfltLng -
    FF - user.js: extensions.funmoods.excTlbr - false
    FF - user.js: extensions.funmoods.autoRvrt - false
    FF - user.js: extensions.funmoods.envrmnt - production
    FF - user.js: extensions.funmoods.isdcmntcmplt - true
    FF - user.js: extensions.funmoods.mntrvrsn - 1.3.0
    user_pref('extensions.dealply.partner', 'iron');
    user_pref('extensions.dealply.channel', 'iron3');
    user_pref('extensions.dealply.installId', 'v23900255745800546418752012072005095939');
    user_pref('extensions.dealply.installIdSource', 'inst');
    user_pref('extensions.dealply.sampleGroup', '9');
    user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);user_pref('extensions.autoDisableScopes', 0);user_pref('security.csp.enable', false);user_pref('security.OCSP.enabled', 0);
    .
    - - - - ORPHANS REMOVED - - - -
    .
    BHO-{74322BF9-DF26-493f-B0DA-6D2FC5E6429E} - c:\progra~1\BEARSH~1\MediaBar\Datamngr\IEBHO.dll
    Toolbar-10 - (no file)
    WebBrowser-{BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - (no file)
    WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
    WebBrowser-{5E7F9DB2-3507-467D-AA2F-DCCB5971B5AF} - (no file)
    WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
    WebBrowser-{EEE6C35B-6118-11DC-9C72-001320C79847} - (no file)
    WebBrowser-{FED66DC5-1B74-4A04-8F5C-15C5ACE2B9A5} - (no file)
    HKCU-Run-ares - c:\program files\Ares\Ares.exe
    HKLM-Run-DATAMNGR - c:\progra~1\BEARSH~1\MediaBar\Datamngr\DATAMN~1.EXE
    HKLM-Run-WinampAgent - c:\program files\Winamp\winampa.exe
    .
    .
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_USERS\S-1-5-21-1273242043-3175682604-682865593-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.Email.1"
    .
    [HKEY_USERS\S-1-5-21-1273242043-3175682604-682865593-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
    @Denied: (2) (LocalSystem)
    "Progid"="WindowsLiveMail.VCard.1"
    .
    [HKEY_USERS\S-1-5-21-1273242043-3175682604-682865593-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "scansk"=hex(0):f0,cc,1a,ca,b4,7e,8a,f2,9e,29,03,8f,6a,dc,fe,d5,69,51,da,a8,ce,
    f4,28,24,06,01,e3,f6,3e,65,6a,9c,61,7c,a8,ce,c0,eb,99,0b,00,00,00,00,00,00,\
    .
    [HKEY_USERS\S-1-5-21-1273242043-3175682604-682865593-1000_Classes\CLSID\{76201bef-ef44-4214-b72c-c6cf69e3eea5}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "Model"=dword:00000098
    "Therad"=dword:0000001e
    "MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
    38,95,44,24,2f,9b,db,fc,ac,0c,e4,0a,f8,19,08,a5,01,fa,e8,91,bf,75,10,b9,30,\
    .
    [HKEY_USERS\S-1-5-21-1273242043-3175682604-682865593-1000_Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
    @Denied: (Full) (Everyone)
    "scansk"=hex(0):99,15,f9,b1,84,55,2a,fe,e1,27,f3,75,9e,0c,c0,da,2f,5d,f5,b2,ee,
    a0,64,c8,2a,f4,f0,cd,c3,56,94,42,07,ca,35,59,02,48,b3,d8,00,00,00,00,00,00,\
    .
    [HKEY_USERS\S-1-5-21-1273242043-3175682604-682865593-1000_Classes\CLSID\{ff0667e9-d3e1-4f14-88b5-a3d9fdf22764}]
    @Denied: (Full) (Everyone)
    @Allowed: (Read) (RestrictedCode)
    "Model"=dword:000000f4
    "Therad"=dword:00000017
    "MData"=hex(0):73,d5,cf,b8,a4,07,89,80,31,e4,35,6b,2a,ca,fe,43,b6,1f,81,1f,5a,
    1b,4d,36,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,ee,21,46,8f,3c,f2,5c,68,\
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
    @Denied: (A) (Users)
    @Denied: (A) (Everyone)
    @Allowed: (B 1 2 3 4 5) (S-1-5-20)
    "BlindDial"=dword:00000000
    .
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    ------------------------ Other Running Processes ------------------------
    .
    c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
    c:\windows\system32\taskhost.exe
    c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
    c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    c:\windows\system32\conhost.exe
    c:\windows\System32\rundll32.exe
    c:\program files\c:\program files\Common Files\Ahead\Lib\NMIndexingService.exe
    c:\program files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    c:\program files\Windows Media Player\wmpnetwk.exe
    c:\windows\system32\DllHost.exe
    c:\windows\system32\sppsvc.exe
    c:\\?\c:\windows\system32\wbem\WMIADAP.EXE
    .
    **************************************************************************
    .
    Completion time: 2012-11-25 18:11:41 - machine was rebooted
    ComboFix-quarantined-files.txt 2012-11-25 16:11
    .
    Pre-Run: 96.100.491.264 bayt boş
    Post-Run: 104.665.001.984 bayt boş
    .
    - - End Of File - - 4A6B005F6C96D5F5456E2E224DA7B6BC
    < Bu mesaj bir yönetici tarafından değiştirilmiştir >







  • Hocam kaspersky kullanmayı dene olmadı temiz bir format at
  • hızlı format en iyisi saol
  • quote:

    Orijinalden alıntı: simiramis47

    hızlı format en iyisi saol

    Bazı virüsler formatla gitmez hocam bence virüsü tam olarak tanımadan format atmayın
  • quote:

    Orijinalden alıntı: Obsessive*

    quote:

    Orijinalden alıntı: simiramis47

    hızlı format en iyisi saol

    Bazı virüsler formatla gitmez hocam bence virüsü tam olarak tanımadan format atmayın

    Bencede tam olarak virüs tipini öğrendikten sonra format atın hem bilgileriniz yanmaz formatla gitmiyceklerdense
  • Formatla gitmeyen virüsler olabilir ancak , formattan sonra klavye mouse eski haline döner ve anti-virüs programıyla işlemi gerçekleştirirsiniz.
  • Yapay Zeka’dan İlgili Konular
    Hamachi Sorunu
    9 yıl önce açıldı
    Windows Sorun Giderici Sorunu
    2 ay önce açıldı
    Daha Fazla Göster
    
Sayfa: 1
- x
Bildirim
mesajınız kopyalandı (ctrl+v) yapıştırmak istediğiniz yere yapıştırabilirsiniz.