az-öz

Magazine
Go Back   Bilgisayar Suyu > Bilgisayar Yazılımı > Virüs, Spyware ve Güvenlik

Register


 Default 

Kötü Amaçlı Yazılım günlüğü




Reply
 
Konu Araçları
  #1  
Old 1 Mart 2008, 05:05
Üye Grubu
 
Default Kötü Amaçlı Yazılım günlüğü

Logfile Trend Micro HijackThis v2.0.2 ve
Tarama 12:00:44 at 01/03/2008 kaydedilmiş
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot modu: Normal
Çalışan süreçleri:
C: \ WINDOWS \ System32 \ Smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ Services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ spoolsv.exe
C: \ Program Files \ McAfee \ MBK \ MBackMonitor.exe
C: \ progra ~ 1 \ intern McAfee \ MSC \ mcmscsvc.exe
C: \ Program Files \ Common Files \ McAfee \ MNA \ McNASvc.exe
c: \ progra ~ 1 \ intern COMMON ~ 1 \ McAfee \ mcproxy \ mcproxy.exe
C: \ progra ~ 1 \ intern McAfee \ VIRUSS ~ 1 \ mcshield.exe
C: \ Program Files \ McAfee \ MPF \ MPFSrv.exe
C: \ Program Files \ McAfee \ MSK \ MskSrver.exe
C: \ WINDOWS \ system32 \ HPZipm12.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ Explorer.EXE
c: \ progra ~ 1 \ intern mcafee.com \ ajan \ mcagent.exe
C: \ Program Files \ TomTom HOME 2 \ HOMERunner.exe
C: \ progra ~ 1 \ intern MYWEBS ~ 1 \ çubuğu \ 1.bin \ m3SrchMn.exe
C: \ progra ~ 1 \ intern MYWEBS ~ 1 \ çubuğu \ 1.bin \ mwsoemon.exe
C: \ Program Files \ Java \ jre1.5.0_09 \ bin \ jusched.exe
C: \ WINDOWS \ System32 \ Rundll32.exe
C: \ WINDOWS \ system32 \ ctfmon.exe
C: \ Program Files \ Cyberlink \ Power2Go \ power2goexpress.exe
C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE
C: \ Program Files \ Belkin \ F5D8053 \ Belkinwcui.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Program Files \ Internet Explorer \ iexplore.exe
C: \ progra ~ 1 \ intern McAfee \ VIRUSS ~ 1 \ mcsysmon.exe
C: \ Program Files \ Java \ jre1.5.0_09 \ bin \ jucheck.exe
C: \ WINDOWS \ system32 \ rundll32.exe
C: \ Program Files \ Internet Explorer \ iexplore.exe
C: \ Program Files \ CCleaner \ CCleaner.exe
C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://uk.yahoo.com
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://uk.yahoo.com
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://uk.yahoo.com
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ SearchURL, (Varsayılan) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Local Page =
= 127.0.0.1 ProxyOverride R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Ayarlar,
R3 - URLSearchHook: (no name) - (00A6FAF6-072E-44cf-8957-5838F569A31D) - C: \ Program Files \ MyWebSearch \ SrchAstt \ 1.bin \ MWSSRCAS.DLL
R3 - URLSearchHook: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Program Files \ Yahoo! \ Companion \ yükler \ cpn \ yt.dll
O3 - Toolbar: My Web Search - (07B18EA9-A523-4961-B6BB-170DE4475CCA) - C: \ Program Files \ MyWebSearch \ çubuğu \ 1.bin \ MWSBAR.DLL
O3 - Toolbar: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Program Files \ Yahoo! \ Companion \ yükler \ cpn \ yt.dll
O4 - HKLM \ .. \ Run: [MBkLogOnHook] C: \ Program Files \ McAfee \ MBK \ LogOnHook.exe
O4 - HKLM \ .. \ Run: [TomTomHOME.exe] "C: \ Program Files \ TomTom HOME 2 \ HOMERunner.exe"-lar
O4 - HKLM \ .. \ Run: [My Web Search Bar Search Scope Monitor] "C: \ progra ~ 1 \ intern MYWEBS ~ 1 \ çubuğu \ 1.bin \ m3SrchMn.exe" / m = 2 / w
O4 - HKLM \ .. \ Run: [MyWebSearch Email Plugin] C: \ progra ~ 1 \ intern MYWEBS ~ 1 \ çubuğu \ 1.bin \ mwsoemon.exe
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.5.0_09 \ bin \ jusched.exe"
O4 - HKLM \ .. \ Run: [mcagent_exe] C: \ Program Files \ McAfee.com \ Ajan \ mcagent.exe / runkey
O4 - HKLM \ .. \ Run: [postSetupCheck] C: \ WINDOWS \ System32 \ Rundll32.exe "C: \ Windows \ system32 \ gzmrt.dll" DllStart
O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe
O4 - HKCU \ .. \ Run: [msnmsgr] "C: \ Program Files \ MSN Messenger \ msnmsgr.exe" / arka plan
O4 - HKCU \ .. \ Run: [MyWebSearch Email Plugin] C: \ progra ~ 1 \ intern MYWEBS ~ 1 \ çubuğu \ 1.bin \ mwsoemon.exe
O4 - HKCU \ .. \ Run: [Power2GoExpress] "C: \ Program Files \ Cyberlink \ Power2Go \ power2goexpress.exe" / Başlangıç
O4 - HKUS \ S-1-5-18 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (Kullanıcı 'SİSTEM')
O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (Kullanıcı 'Varsayılan kullanıcı')
O4 - Global Startup: Adobe Reader Hızlı Launch.lnk = C: \ Program Files \ Adobe \ Acrobat 7.0 \ Reader \ reader_sl.exe
O4 - Global Startup: Belkin F5D8053 N Kablosuz USB Adaptörü Utility.lnk = C: \ Program Files \ Belkin \ F5D8053 \ Belkinwcui.exe
O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE
O8 - Extra menü öğesi: & Arama -- http://edits.mywebsearch.com/toolbar...rch.jhtml?p=ZJ
O8 - Extra menü item: E & Microsoft Excel'e xport - res: / / C: \ progra ~ 1 \ intern mikro ~ 3 \ Office10 \ EXCEL.EXE/3000
O9 - Extra düğmesi: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.5.0_09 \ bin \ ssv.dll
O9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.5.0_09 \ bin \ ssv.dll
O9 - Extra düğmesi: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra 'Tools' MENUITEM: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra düğmesi: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL = http://www.pcservicecall.co.uk
O16 - DPF: (30528230-99f7-4bb4-88d8-fa1d4f56a2ab) (YInstStarter Sınıfı) - C: \ Program Files \ Yahoo! \ Common \ yinsthelper.dll
O16 - DPF: (4C39376E-FA9D-4349-BACC-D305C1750EF3) (EPUImageControl Sınıf) -- http://sell-vehicle.ebay.co.uk/image..._v1-0-3-50.cab
O16 - DPF: (56762DEC-6B0D-4AB4-A8AD-989993B5D08B) -- http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: (A90A5822-F108-45AD-8482-9BC8B12DD539) (Crucial cpcScan) -- http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: (F04A8AE2-A59D-11D2-8792-00C04F8EF29D) (Hotmail Attachments Control) -- http://by121fd.bay121.hotmail.msn.co...x/HMAtchmt.ocx
O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ (5D3D0EC7-51D8-414D-81B8-BB319A5A73C4): NameServer = 192.168.0.1
O23 - Service: McAfee Application Installer Cleanup (0287341204362868) (0287341204362868mcinstcleanup) - McAfee, Inc - C: \ Windows \ Temp \ 028734 ~ 1.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C: \ Program Files \ Common \ Google Updater \ googleupdaterservice.exe
O23 - Service: InstallDriver Tablo Yöneticisi (IDriverT) - Macrovision Corporation - C: \ Program Files \ Common Files \ InstallShield \ Driver \ 11 \ Intel 32 \ IDriverT.exe
O23 - Service: MBackMonitor - McAfee - C: \ Program Files \ McAfee \ MBK \ MBackMonitor.exe
O23 - Service: McAfee Services () mcmscsvc - McAfee, Inc - C: \ progra ~ 1 \ intern McAfee \ MSC \ mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc - C: \ Program Files \ Common Files \ McAfee \ MNA \ McNASvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc - C: \ progra ~ 1 \ intern McAfee \ VIRUSS ~ 1 \ mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc - c: \ progra ~ 1 \ intern COMMON ~ 1 \ McAfee \ mcproxy \ mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc - C: \ progra ~ 1 \ intern McAfee \ VIRUSS ~ 1 \ mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc - C: \ progra ~ 1 \ intern McAfee \ VIRUSS ~ 1 \ mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc - C: \ Program Files \ McAfee \ MPF \ MPFSrv.exe
O23 - Service: McAfee SpamKiller Servisi (MSK80Service) - McAfee, Inc - C: \ Program Files \ McAfee \ MSK \ MskSrver.exe
O23 - Service: MSSQLServerADHelper - Bilinmeyen sahibi - C: \ Program Files \ Microsoft SQL Server \ 80 \ Tools \ Binn \ (dosya eksik) sqladhlp.exe
O23 - Service: Pml Driver HPZ12 - HP - C: \ WINDOWS \ system32 \ HPZipm12.exe
--
Dosya sonu - 7858 byte

TEMİZLİK TAMAMLAMA - (3,135 saniye)
-------------------------------------------------- ----------------------------------------
5.71MB kaldırıldı.
-------------------------------------------------- ----------------------------------------
Dosya Ayrıntıları silindi
-------------------------------------------------- ----------------------------------------
IE Geçici İnternet Dosyaları (421 dosyalar) 5.70MB
C: \ Documents and Settings \ Bann \ Çerezler \ bann@int.sitestat [1]. Txt 103 byte
C: \ Documents and Settings \ Bann \ Çerezler \ mediaplex @ Bann [2]. Txt 85 bayt
C: \ Documents and Settings \ Bann \ Çerezler \ bilgisayar suyu [2 @ Bann]. Txt 808 byte
C: \ Documents and Settings \ Bann \ Çerezler \ bann@www.burstnet [2]. Txt 77 bayt
C: \ Documents and Settings \ Bann \ Çerezler \ canlı @ Bann [2]. Txt 504 byte
C: \ Documents and Settings \ Bann \ Çerezler \ bann@rad.live [2]. Txt 690 byte
C: \ Documents and Settings \ Bann \ Çerezler \ tribalfusion @ Bann [2]. Txt 330 byte
C: \ Documents and Settings \ Bann \ Çerezler \ MSN @ Bann [1]. Txt 345 byte
C: \ Documents and Settings \ Bann \ Çerezler \ adecn @ Bann [1]. Txt 214 byte
C: \ Documents and Settings \ Bann \ Çerezler \ reklam @ Bann [1]. Txt 283 byte
C: \ Documents and Settings \ Bann \ Çerezler \ bann@d3.zedo [1]. Txt 72 bayt
C: \ Documents and Settings \ Bann \ Çerezler \ bann@ads.pointroll [1]. Txt 668 byte
C: \ Documents and Settings \ Bann \ Çerezler \ Bann @ zedo [1]. Txt 408 byte
C: \ Documents and Settings \ Bann \ Çerezler \ 888 @ Bann [2]. Txt 155 byte
C: \ Documents and Settings \ Bann \ Çerezler \ bann@eas.apm.emediate [1]. Txt 289 byte
C: \ Documents and Settings \ Bann \ Çerezler \ interclick @ Bann [2]. Txt 414 byte
C: \ Documents and Settings \ Bann \ Çerezler \ bann@rotator.its.adjuggler [1]. Txt 113 byte
C: \ Documents and Settings \ Bann \ Çerezler \ bann@p.live [1]. Txt 102 byte
C: \ Documents and Settings \ Bann \ Çerezler \ Bann @ yahoo [1]. Txt 82 bayt
C: \ Documents and Settings \ Bann \ Çerezler \ çift @ Bann [1]. Txt 89 bayt
C: \ Documents and Settings \ Bann \ Çerezler \ bann@int.sitestat [2]. Txt 99 bayt
C: \ Documents and Settings \ Bann \ Çerezler \ bann@login.live [2]. Txt 180 byte
C: \ Documents and Settings \ Bann \ Çerezler \ bann@h.live [1]. Txt 68 bayt
C: \ Documents and Settings \ Bann \ Çerezler \ bann@rotator.adjuggler [2]. Txt 205 byte
C: \ Documents and Settings \ Bann \ Çerezler \ bann@www.iefjios [1]. Txt 90 bayt
C: \ Documents and Settings \ Bann \ Çerezler \ atdmt @ Bann [2]. Txt 101 byte
C: \ Documents and Settings \ Bann \ Çerezler \ bann@ad.yieldmanager [2]. Txt 1.06KB
C: \ Documents and Settings \ Bann \ Application Data \ Pazar \ Java \ Deployment \ önbellek \ javapi \ v1.0 \ kavanoz \ JVM impro.jar-51fad18-787f377f.idx 153 byte
C: \ Documents and Settings \ Bann \ Application Data \ Pazar \ Java \ Deployment \ önbellek \ javapi \ v1.0 \ kavanoz \ JVM vers.jar-4b6e6f5b-4dc46c65.idx 152 byte
C: \ Documents and Settings \ Bann \ Application Data \ Macromedia \ Flash Player \ # SharedObjects \ 99SH2MHK \ interclick.com \ ud.s Ol 139 byte
C: \ Documents and Settings \ Bann \ Application Data \ Macromedia \ Flash Player \ macromedia.com \ support \ flashplayer \ SYS \ # int erclick.com \ settings.sol 84 bayt
C: \ Documents and Settings \ Bann \ Application Data \ Macromedia \ Flash Player \ macromedia.com \ support \ flashplayer \ SYS \ Sett ings.sol 380 byte
-------------------------------------------------- ----------------------------------------
  #2  
Old 1 Mart 2008, 09:14
Üye Grubu
 
Default Kötü Amaçlı Yazılım günlüğü

Sen hangi adware yüklü / MyWebSearch casus yazılım var eğer eklemek çıkarın görmek / programları kaldırın. Değilse

Bir onay işareti bu tıklayın yanındaki koy "" kontrol düzeltmek

O4 - HKLM \ .. \ Run: [My Web Search Bar Search Scope Monitor] "C: \ progra ~ 1 \ intern MYWEBS ~ 1 \ çubuğu \ 1.bin \ m3SrchMn.exe" / m = 2 / w
O4 - HKLM \ .. \ Run: [MyWebSearch E-posta Plugin] C: \ progra ~ 1 \ intern MYWEBS ~ 1 \ çubuğu \ 1.bin \ mwsoemon.exe
R3 - URLSearchHook: (no name) - (00A6FAF6-072E-44cf-8957-5838F569A31D) - C: \ Program Files \ MyWebSearch \ SrchAstt \ 1.bin \ MWSSRCAS.DLL
O4 - HKLM \ .. \ Run: [postSetupCheck] C: \ WINDOWS \ System32 \ Rundll32.exe "C: \ Windows \ system32 \ gzmrt.dll" DllStart
  #3  
Old 1 Mart 2008, 11:23
Moderatör Grubu
 
Default Kötü Amaçlı Yazılım günlüğü

Sonra yeni bir Hijackthis sonrası giriş yapın.
__________________

  #4  
Old 1 Mart 2008, 14:19
Üye Grubu
 
Default Kötü Amaçlı Yazılım günlüğü

Logfile Trend Micro HijackThis v2.0.2 ve
Tarama 17:37:28 at 01/03/2008 kaydedilmiş
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot modu: Normal
Çalışan süreçleri:
C: \ WINDOWS \ System32 \ Smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ Services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ spoolsv.exe
C: \ Program Files \ McAfee \ MBK \ MBackMonitor.exe
C: \ progra ~ 1 \ intern McAfee \ MSC \ mcmscsvc.exe
C: \ Program Files \ Common Files \ McAfee \ MNA \ McNASvc.exe
c: \ progra ~ 1 \ intern COMMON ~ 1 \ McAfee \ mcproxy \ mcproxy.exe
C: \ progra ~ 1 \ intern McAfee \ VIRUSS ~ 1 \ mcshield.exe
C: \ Program Files \ McAfee \ MPF \ MPFSrv.exe
C: \ Program Files \ McAfee \ MSK \ MskSrver.exe
C: \ WINDOWS \ system32 \ HPZipm12.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ Explorer.EXE
c: \ progra ~ 1 \ intern mcafee.com \ ajan \ mcagent.exe
C: \ Program Files \ TomTom HOME 2 \ HOMERunner.exe
C: \ Program Files \ Java \ jre1.5.0_09 \ bin \ jusched.exe
C: \ progra ~ 1 \ intern MYWEBS ~ 1 \ çubuğu \ 1.bin \ m3SrchMn.exe
C: \ WINDOWS \ System32 \ Rundll32.exe
C: \ WINDOWS \ system32 \ ctfmon.exe
C: \ Program Files \ Internet Explorer \ IEXPLORE.EXE
C: \ Program Files \ Cyberlink \ Power2Go \ power2goexpress.exe
C: \ Program Files \ Belkin \ F5D8053 \ Belkinwcui.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ progra ~ 1 \ intern McAfee \ VIRUSS ~ 1 \ mcsysmon.exe
C: \ Program Files \ Internet Explorer \ iexplore.exe
C: \ Program Files \ Java \ jre1.5.0_09 \ bin \ jucheck.exe
C: \ Program Files \ Trend Micro \ HijackThis \ HijackThis.exe
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://uk.yahoo.com
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://uk.yahoo.com
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://uk.yahoo.com
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ SearchURL, (Varsayılan) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBR
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Local Page =
= 127.0.0.1 ProxyOverride R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Ayarlar,
O4 - HKLM \ .. \ Run: [MBkLogOnHook] C: \ Program Files \ McAfee \ MBK \ LogOnHook.exe
O4 - HKLM \ .. \ Run: [TomTomHOME.exe] "C: \ Program Files \ TomTom HOME 2 \ HOMERunner.exe"-lar
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.5.0_09 \ bin \ jusched.exe"
O4 - HKLM \ .. \ Run: [mcagent_exe] C: \ Program Files \ McAfee.com \ Ajan \ mcagent.exe / runkey
O4 - HKLM \ .. \ Run: [My Web Search Bar Search Scope Monitor] "C: \ progra ~ 1 \ intern MYWEBS ~ 1 \ çubuğu \ 1.bin \ m3SrchMn.exe" / m = 2 / w
O4 - HKLM \ .. \ Run: [postSetupCheck] C: \ WINDOWS \ System32 \ Rundll32.exe "C: \ Windows \ system32 \ gzmrt.dll" DllStart
O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe
O4 - HKCU \ .. \ Run: [msnmsgr] "C: \ Program Files \ MSN Messenger \ msnmsgr.exe" / arka plan
O4 - HKCU \ .. \ Run: [Power2GoExpress] "C: \ Program Files \ Cyberlink \ Power2Go \ power2goexpress.exe" / Başlangıç
O4 - HKUS \ S-1-5-18 \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (Kullanıcı 'SİSTEM')
O4 - HKUS \. DEFAULT \ .. \ Run: [Ctfmon.exe] C: \ WINDOWS \ system32 \ Ctfmon.exe (Kullanıcı 'Varsayılan kullanıcı')
O4 - Global Startup: Adobe Reader Hızlı Launch.lnk = C: \ Program Files \ Adobe \ Acrobat 7.0 \ Reader \ reader_sl.exe
O4 - Global Startup: Belkin F5D8053 N Kablosuz USB Adaptörü Utility.lnk = C: \ Program Files \ Belkin \ F5D8053 \ Belkinwcui.exe
O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE
O8 - Extra menü öğesi: & Arama -- http://edits.mywebsearch.com/toolbar...rch.jhtml?p=ZJ
O8 - Extra menü item: E & Microsoft Excel'e xport - res: / / C: \ progra ~ 1 \ intern mikro ~ 3 \ Office10 \ EXCEL.EXE/3000
O9 - Extra düğmesi: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.5.0_09 \ bin \ ssv.dll
O9 - Extra 'Tools' MENUITEM: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.5.0_09 \ bin \ ssv.dll
O9 - Extra düğmesi: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra 'Tools' MENUITEM: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe
O9 - Extra düğmesi: Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra 'Tools' MENUITEM: Windows Messenger - (FB5F1910-F110-11D2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL = http://www.pcservicecall.co.uk
O16 - DPF: (30528230-99f7-4bb4-88d8-fa1d4f56a2ab) (YInstStarter Sınıfı) - C: \ Program Files \ Yahoo! \ Common \ yinsthelper.dll
O16 - DPF: (4C39376E-FA9D-4349-BACC-D305C1750EF3) (EPUImageControl Sınıf) -- http://sell-vehicle.ebay.co.uk/image..._v1-0-3-50.cab
O16 - DPF: (56762DEC-6B0D-4AB4-A8AD-989993B5D08B) -- http://www.eset.eu/buxus/docs/OnlineScanner.cab
O16 - DPF: (A90A5822-F108-45AD-8482-9BC8B12DD539) (Crucial cpcScan) -- http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: (F04A8AE2-A59D-11D2-8792-00C04F8EF29D) (Hotmail Attachments Control) -- http://by121fd.bay121.hotmail.msn.co...x/HMAtchmt.ocx
O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ (5D3D0EC7-51D8-414D-81B8-BB319A5A73C4): NameServer = 192.168.0.1
O23 - Service: Google Updater Service (gusvc) - Google - C: \ Program Files \ Common \ Google Updater \ googleupdaterservice.exe
O23 - Service: InstallDriver Tablo Yöneticisi (IDriverT) - Macrovision Corporation - C: \ Program Files \ Common Files \ InstallShield \ Driver \ 11 \ Intel 32 \ IDriverT.exe
O23 - Service: MBackMonitor - McAfee - C: \ Program Files \ McAfee \ MBK \ MBackMonitor.exe
O23 - Service: McAfee Services () mcmscsvc - McAfee, Inc - C: \ progra ~ 1 \ intern McAfee \ MSC \ mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc - C: \ Program Files \ Common Files \ McAfee \ MNA \ McNASvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc - C: \ progra ~ 1 \ intern McAfee \ VIRUSS ~ 1 \ mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc - c: \ progra ~ 1 \ intern COMMON ~ 1 \ McAfee \ mcproxy \ mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc - C: \ progra ~ 1 \ intern McAfee \ VIRUSS ~ 1 \ mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc - C: \ progra ~ 1 \ intern McAfee \ VIRUSS ~ 1 \ mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc - C: \ Program Files \ McAfee \ MPF \ MPFSrv.exe
O23 - Service: McAfee SpamKiller Servisi (MSK80Service) - McAfee, Inc - C: \ Program Files \ McAfee \ MSK \ MskSrver.exe
O23 - Service: MSSQLServerADHelper - Bilinmeyen sahibi - C: \ Program Files \ Microsoft SQL Server \ 80 \ Tools \ Binn \ (dosya eksik) sqladhlp.exe
O23 - Service: Pml Driver HPZ12 - HP - C: \ WINDOWS \ system32 \ HPZipm12.exe
--
Dosya sonu - 6847 byte
  #5  
Old 1 Mart 2008, 14:31
Moderatör Grubu
 
Default Kötü Amaçlı Yazılım günlüğü

, Aynı günlükleri hakkında ilanıyla / bilgisayar iki ipliği misiniz?
__________________

Reply

Register

Bookmarks

Benzer Konular
Iplik Konuyu Başlatan Forum Cevaplar Son Mesaj
Malware Antivirus Yardım Pro jjohan Virüs, Spyware ve Güvenlik 2 20 Ekim 2009 07:05
Autorun Malware? sungod000 Virüs, Spyware ve Güvenlik 5 23. Haziran 2009 12:14
Konu Araçları




Arabic Bulgarian Chinese (Simplified) Chinese (Traditional) Croatian Czech Danish Dutch English Finnish French German Greek Hebrew Hungarian Italian Japanese Korean Latvian Lithuanian Norwegian Polish Portuguese Romanian Russian Serbian Slovak Spanish Swedish Thai Turkish Ukrainian

Copyright © 2006 - 2009 Bilgisayar Suyu.

By vBulletin ® Copyright © 2000 Powered - 2009 Jelsoft Enterprises Ltd SEO by vBSEO © 2009, Crawlability, Inc tarafından