Bu DOSYALARI Silmemde mahsur varmı.Rapora bir bakarmısınız..

Kodla Büyü

chertan44

Site Gezgini
Mesajlar
39
Sayın arkadaşlar;
Pc'yi RemovelT Pro v7.33 Enterprizile tarattım,aşağıdaki rapor çıktı.Bu rapora göre işaretli tehditleri silip kaldırabilirmiyim.Yardımcı olursanız sevinirim.
RemoveIT Pro v7 Enterprise (Build date: 11.11.2008) log.
Generated at: 08.11.2010 on 03:26:35
Microsoft Windows XP Home Edition Service Pack 3 (Build 2600)

03:26:35: Scanning, please wait...
03:26:51: Infected file (Win32.Unknown.Random.X) c:\program files\google\update\googleupdate.exe -> No action
taken.
03:28:18: Infected file (Sys32._iu14d2n) C:\Documents and Settings\benıbo\local settings\temp\_iu14d2n.tmp -> No
action taken.
03:29:57: Infected file (Sys32.bassmod) C:\DOCUME~1\BENBO~1\LOCALS~1\Temp\bassmod.dll -> No action
taken.
03:41:39: Infected file (Sys32.emsc) C:\WINDOWS\system32\emsc.dll -> No action taken.
03:42:42: Infected file (Sys32.igfxcoin_v4926) C:\WINDOWS\system32\igfxcoin_v4926.dll -> No action taken.
03:45:35: Infected file (Sys32.rtsustor) C:\WINDOWS\system32\rtsustor.dll -> No action taken.
03:45:36: Infected file (Sys32.rtsustoricon) C:\WINDOWS\system32\rtsustoricon.dll -> No action taken.
03:45:48: Infected file (Sys32.scrrntr) C:\WINDOWS\system32\scrrntr.dll -> No action taken.
03:46:45: Infected file (Sys32.unccplext) C:\WINDOWS\system32\unccplext.dll -> No action taken.
03:48:52: Infected file (Sys32.cadkasdeinst01e) C:\WINDOWS\cadkasdeinst01e.exe -> No action taken.
03:49:39: Infected file (Sys32.setpwr32) C:\WINDOWS\setpwr32.exe -> No action taken.
03:51:28: 11 Dangerous files has been found on your computer.
Click on "Fix" button to fix selected tasks.
Finished...
:?:
 
Bir çoğu malware gibi duruyor. silmeyi deneyin zaten sorun çıksada yeniden kurulum yapmanız gerekecek. Bu şekilde kullansanız da fayda sağlamayacaktır.
 
Teachnologist' Alıntı:
Bir çoğu malware gibi duruyor. silmeyi deneyin zaten sorun çıksada yeniden kurulum yapmanız gerekecek. Bu şekilde kullansanız da fayda sağlamayacaktır.

ESET bunlara hiçbirşey yapamıyor.Ne buluyor ne de uyarıyor.
Sileyim bari sonucu görelim.
İlgilenen arkadaşlara teşekkür ederim
 
Teachnologist' Alıntı:

ComboFix 10-11-07.09 - benıbo 08.11.2010 13:00:36.1.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1254.90.1055.18.1014.472 [GMT 2:00]
Running from: c:\documents and settings\benıbo\Belgelerim\Karşıdan Yüklenenler\ComboFix.v17.09.2010\ComboFix.v17.09.2010\ComboFix.v17.09.2010.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: ESET NOD32 Antivirus 4.0 *On-access scanning disabled* (Updated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\benıbo\Application Data\BITS
c:\documents and settings\benıbo\Application Data\BITS\BITS.ini
c:\documents and settings\benıbo\Application Data\BITS\DHTTable.dat
c:\documents and settings\benıbo\Application Data\BITS\ProxyList.ini
c:\documents and settings\benıbo\Application Data\BITS\UPnP.ini
c:\documents and settings\benıbo\Application Data\EurekaLog
c:\documents and settings\benıbo\Belgelerim\mshearts.exe
c:\windows\libem.INI
c:\windows\system32\secustat.dat

.
((((((((((((((((((((((((( Files Created from 2010-10-08 to 2010-11-08 )))))))))))))))))))))))))))))))
.

2010-11-08 02:50 . 2010-11-08 02:50 -------- d-----w- c:\documents and settings\benıbo\Application Data\Avira
2010-11-08 02:49 . 2010-03-01 08:05 124784 ----a-w- c:\windows\system32\drivers\avipbb.sys
2010-11-08 02:49 . 2010-02-16 12:24 60936 ----a-w- c:\windows\system32\drivers\avgntflt.sys
2010-11-08 02:49 . 2009-05-11 10:49 45416 ----a-w- c:\windows\system32\drivers\avgntdd.sys
2010-11-08 02:49 . 2009-05-11 10:49 22360 ----a-w- c:\windows\system32\drivers\avgntmgr.sys
2010-11-08 01:24 . 2010-11-08 01:24 -------- d-----w- c:\program files\InCode Solutions
2010-11-07 23:58 . 2010-11-07 23:58 2 --shatr- c:\windows\winstart.bat
2010-11-06 12:46 . 2010-11-06 12:46 -------- d-----w- c:\windows\system32\wbem\Repository
2010-11-06 12:46 . 2010-11-06 12:46 -------- d-----w- c:\program files\JDownloader
2010-11-06 12:46 . 2010-11-06 12:46 -------- d-----w- c:\program files\Your_Uninstaller__7.0.2010.7
2010-11-06 12:46 . 2010-11-06 12:46 -------- d-----w- c:\program files\Avira
2010-11-06 12:46 . 2010-11-06 12:46 -------- d-----w- c:\program files\USB Disk Security
2010-11-05 01:17 . 2010-11-05 01:17 -------- d-----w- c:\program files\Loaris
2010-11-03 20:48 . 2010-11-03 20:48 -------- d-----w- c:\documents and settings\benıbo\Application Data\ProgSense
2010-11-03 20:47 . 2010-11-03 20:50 -------- d-----w- c:\documents and settings\benıbo\Local Settings\Application Data\OpenCandy
2010-11-03 20:47 . 2010-11-03 20:47 -------- d-----w- c:\documents and settings\benıbo\Application Data\OpenCandy
2010-11-03 20:47 . 2010-11-03 21:22 -------- d-----w- c:\documents and settings\benıbo\Application Data\Orbit
2010-11-03 18:22 . 2010-11-03 19:38 -------- d-----w- c:\documents and settings\benıbo\Application Data\IDM
2010-11-02 17:09 . 2010-11-02 17:09 16856 ----a-w- c:\program files\Mozilla Firefox\plugin-container.exe
2010-11-02 17:09 . 2010-11-02 17:09 719832 ----a-w- c:\program files\Mozilla Firefox\mozcpp19.dll
2010-11-02 01:34 . 2010-11-02 01:34 -------- d-----w- c:\documents and settings\benıbo\Application Data\TopcKit
2010-11-02 00:31 . 2010-11-02 00:31 -------- d-----w- c:\documents and settings\benıbo\Local Settings\Application Data\DFX
2010-11-01 21:53 . 2010-11-05 01:46 -------- d-----w- C:\Downloads
2010-10-18 13:41 . 2008-02-15 15:12 206256 ----a-w- c:\windows\system32\idmmbc(2).dll
2010-10-17 19:59 . 2010-09-18 06:53 954368 -c----w- c:\windows\system32\dllcache\mfc40.dll
2010-10-17 19:59 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2010-10-17 19:59 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2010-10-17 19:52 . 2010-08-23 16:12 617472 -c----w- c:\windows\system32\dllcache\comctl32.dll
2010-10-12 23:46 . 2010-10-22 23:14 -------- d-----w- c:\windows\system32\NtmsData
2010-10-12 23:31 . 2010-10-12 23:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Avira
2010-10-11 18:29 . 2010-10-11 18:29 -------- d-----w- c:\documents and settings\benıbo\Local Settings\Application Data\Thinstall
2010-10-11 18:29 . 2010-10-11 18:29 -------- d-----w- c:\documents and settings\benıbo\Application Data\Thinstall
2010-10-11 18:29 . 2010-10-11 18:29 -------- d-----w- c:\documents and settings\All Users\Application Data\DFX
2010-10-09 23:52 . 2010-10-09 23:52 -------- d-----w- c:\program files\Pool Billiard 1

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-09 23:52 . 2010-09-17 14:13 75776 ----a-w- c:\windows\cadkasdeinst01e.exe
2010-09-18 09:23 . 2008-05-07 23:45 974848 ----a-w- c:\windows\system32\mfc42u.dll
2010-09-18 06:53 . 2008-05-07 23:45 974848 ----a-w- c:\windows\system32\mfc42.dll
2010-09-18 06:53 . 2008-05-07 23:45 954368 ----a-w- c:\windows\system32\mfc40.dll
2010-09-18 06:53 . 2008-05-07 23:45 953856 ----a-w- c:\windows\system32\mfc40u.dll
2010-09-09 14:17 . 2008-05-07 23:45 666624 ----a-w- c:\windows\system32\wininet.dll
2010-09-09 14:17 . 2008-05-07 23:45 61952 ----a-w- c:\windows\system32\tdc.ocx
2010-09-09 14:17 . 2008-05-07 23:45 81920 ----a-w- c:\windows\system32\ieencode.dll
2010-09-09 14:15 . 2008-05-07 23:45 369664 ----a-w- c:\windows\system32\html.iec
2010-09-01 11:51 . 2008-05-07 23:45 285824 ----a-w- c:\windows\system32\atmfd.dll
2010-09-01 07:54 . 2008-05-07 23:45 1861888 ----a-w- c:\windows\system32\win32k.sys
2010-08-27 08:02 . 2008-05-07 23:45 119808 ----a-w- c:\windows\system32\t2embed.dll
2010-08-27 05:58 . 2008-05-07 23:45 99840 ----a-w- c:\windows\system32\srvsvc.dll
2010-08-27 01:43 . 2008-05-05 12:25 5120 ----a-w- c:\windows\system32\xpsp4res.dll
2010-08-26 13:39 . 2008-05-07 23:45 357248 ----a-w- c:\windows\system32\drivers\srv.sys
2010-08-23 16:12 . 2008-05-07 23:45 617472 ----a-w- c:\windows\system32\comctl32.dll
2010-08-17 13:17 . 2008-05-07 23:45 58880 ----a-w- c:\windows\system32\spoolsv.exe
2010-08-16 08:44 . 2008-05-07 23:45 590848 ----a-w- c:\windows\system32\rpcrt4.dll
2010-01-04 23:00 . 2010-01-04 22:59 1924200 ----a-w- c:\program files\install_flash_player.exe
2010-01-02 00:04 . 2010-01-02 00:04 5846216 ----a-w- c:\program files\Firefox Setup 2.0.0.18.exe
2010-01-01 20:09 . 2010-01-01 20:09 6147544 ----a-w- c:\program files\3414-GOMPLAYERENSETUP.EXE
2010-01-01 19:28 . 2010-01-01 19:28 1604248 ----a-w- c:\program files\wrar391tr.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Advanced SystemCare 3"="c:\program files\IObit\Advanced SystemCare 3\AWC.exe" [2010-03-29 2343120]
"RemoveIT Pro v7Ent"="c:\program files\InCode Solutions\RemoveIT Pro v7 Enterprise\removeit.exe" [2010-11-04 2198528]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2009-03-15 1434920]
"RTHDCPL"="RTHDCPL.EXE" [2009-03-15 17529856]
"Persistence"="c:\windows\system32\igfxpers.exe" [2009-02-15 137752]
"OA012Mon"="c:\windows\OA012Mon.exe" [2009-05-11 24576]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2009-01-06 2289664]
"WSED"="c:\program files\WSED\WSED.exe" [2009-03-31 251176]
"BTMeter"="c:\program files\Battery Meter\BTMeter.exe" [2008-11-05 623912]
"CapsLKNotify"="c:\program files\CapsLKNotify\CapsLKNotify.exe" [2009-02-23 320808]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
"AutorunRemover.exe"="c:\program files\AutorunRemover\AutorunRemover.exe" [2009-10-21 1360896]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"USB Antivirus"="c:\program files\USB Disk Security\USBGuard.exe" [2009-12-14 819200]
"egui"="c:\program files\ESET\ESET NOD32 Antivirus\egui.exe" [2009-09-11 2054360]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-15 15360]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=

R0 EMSC;COMPAL Embedded System Control;c:\windows\system32\drivers\EMSC.sys [20.09.2009 06:31 14248]
R1 ehdrv;ehdrv;c:\windows\system32\drivers\ehdrv.sys [11.09.2009 06:23 108792]
R1 epfwtdir;epfwtdir;c:\windows\system32\drivers\epfwtdir.sys [11.09.2009 06:26 96408]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [08.11.2010 04:49 135336]
R2 ekrn;ESET Service;c:\program files\ESET\ESET NOD32 Antivirus\ekrn.exe [11.09.2009 06:24 735960]
R3 CtClsFlt;Creative Camera Class Upper Filter Driver;c:\windows\system32\drivers\CtClsFlt.sys [20.09.2009 06:37 143840]
R3 OA012Afx;Provides a software interface to control audio effects of OA012 camera.;c:\windows\system32\drivers\OA012Afx.sys [20.09.2009 09:02 135168]
R3 OA012Ufd;Creative Camera OA012 Upper Filter Driver;c:\windows\system32\drivers\OA012Ufd.sys [20.09.2009 09:02 133632]
R3 OA012Vid;Creative Camera OA012 Function Driver;c:\windows\system32\drivers\OA012Vid.sys [20.09.2009 09:02 272032]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\drivers\RtsUStor.sys [20.09.2009 09:01 162816]
S2 gupdate;Google Güncelleme Hizmeti (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [08.06.2010 23:34 136176]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [20.09.2009 09:00 1684736]

--- Other Services/Drivers In Memory ---

*NewlyCreated* - SSMDRV
.
Contents of the 'Scheduled Tasks' folder

2010-11-08 c:\windows\Tasks\AWC AutoSweep.job
- c:\program files\IObit\Advanced SystemCare 3\AutoSweep.exe [2010-01-17 11:11]

2010-11-04 c:\windows\Tasks\AWC Update.job
- c:\program files\IObit\Advanced SystemCare 3\IObitUpdate.exe [2010-01-17 10:38]

2010-11-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-08 21:34]

2010-11-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-08 21:34]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://search.orbitdownloader.com
IE: Send to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send To Bluetooth - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Tüm Yüklemeler FlashGet3
IE: Yüklenen by FlashGet3
TCP: {163D3774-17BA-4A96-89FD-00DF3124019A} = 8.8.8.8
FF - ProfilePath - c:\documents and settings\benıbo\Application Data\Mozilla\Firefox\Profiles\bigz5v7y.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.tr/
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\docume~1\BENBO~1\APPLIC~1\Flatcast\NpFv522.dll
FF - plugin: c:\program files\Google\Update\1.2.183.39\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
FF - user.js: browser.cache.memory.capacity - 16000
FF - user.js: browser.chrome.favicons - false
FF - user.js: browser.display.show_image_placeholders - true
FF - user.js: browser.turbo.enabled - true
FF - user.js: browser.urlbar.autocomplete.enabled - true
FF - user.js: browser.urlbar.autofill - true
FF - user.js: content.max.tokenizing.time - 3000000
FF - user.js: content.maxtextrun - 4095
FF - user.js: content.notify.backoffcount - 5
FF - user.js: content.notify.interval - 1000000
FF - user.js: content.notify.ontimer - true
FF - user.js: content.switch.threshold - 1000000
FF - user.js: dom.disable_window_status_change - true
FF - user.js: network.http.max-connections - 48
FF - user.js: network.http.max-connections-per-server - 16
FF - user.js: network.http.max-persistent-connections-per-proxy - 16
FF - user.js: network.http.max-persistent-connections-per-server - 8
FF - user.js: network.http.pipelining - true
FF - user.js: network.http.pipelining.firstrequest - true
FF - user.js: network.http.pipelining.maxrequests - 8
FF - user.js: network.http.proxy.pipelining - true
FF - user.js: network.http.request.max-start-delay - 0
FF - user.js: nglayout.initialpaint.delay - 1000
FF - user.js: plugin.expose_full_path - true
FF - user.js: ui.submenuDelay - 0
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqz9s", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--fiqs8s", true); // Simplified
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--j6w193g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4a87g", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7c0a67fbc", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbqly7cvafr", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kpry57d", true); // Traditional
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--kprw13d", true); // Simplified
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -

SafeBoot-SolutoService



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-11-08 13:05
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(736)
c:\windows\System32\BCMLogon.dll
c:\windows\SYSTEM32\igfxdev.dll
.
Completion time: 2010-11-08 13:08:06
ComboFix-quarantined-files.txt 2010-11-08 11:08

Pre-Run: 112.678.760.448 bayt boş
Post-Run: 112.692.592.640 bayt boş

WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect

- - End Of File - - CE5116B63B8B92127D514803B96C6EFA


Combofix kurup tarattım sonuç bu not defterinde.Neler olmuş bir yorum yaparmısın hocam.
 
tavsiyem kendiniz komut satırından kontrol edin:
1)"çalıştır>cmd" komut satırı çalışacak ekranda şu şekilde devam ediyoruz:
2)"cd.."
3)"cd.. " burada C diskine düşmüş olacağız
4)"cd windows" windows klasörüne girdik
5)"cd system32" system 32 ye girdik
6)"dir/ah" gizli dosya ve klasörleri listeliyoruz. burada .exe uzantılı dosya görürseniz şüphe edebilirsiniz. kesin virüsdür demiyorum ama olma ihtimali yüksek. buna siz kara vereceksizniz. örneğin gördüğünüz dosyayı google aratıp yada http://www.budosyanedir.com dan bakabilirsiniz. eğer virüs olduğuna karar verdiyseniz
7)"attrib *.exe -s -r -h -a" burada dosya izinlerini veriyoruz.
8-"del *.exe" şimdi dosya silinecek. eğer silinmezse dosya kullanılıyordur. görev yöneteicinden durdurmayı deneyin yada güvenli modda çalıştırın. dikkat *.exe yazdığınızda tüm exe dosyalarıyla işlem yaparsınız. pek olmaz ama birden fazla exe dosyası varsa ve siz sadece bazılarının virüs olduğunu düşünüyorsanız dosyanın tam adını yazın. örn: *.exe yerine abc.exe

uyarı bilmediğiniz dosyaları silmek format gerektirebilir
 
aak' Alıntı:
tavsiyem kendiniz komut satırından kontrol edin:
1)"çalıştır>cmd" komut satırı çalışacak ekranda şu şekilde devam ediyoruz:
2)"cd.."
3)"cd.. " burada C diskine düşmüş olacağız
4)"cd windows" windows klasörüne girdik
5)"cd system32" system 32 ye girdik
6)"dir/ah" gizli dosya ve klasörleri listeliyoruz. burada .exe uzantılı dosya görürseniz şüphe edebilirsiniz. kesin virüsdür demiyorum ama olma ihtimali yüksek. buna siz kara vereceksizniz. örneğin gördüğünüz dosyayı google aratıp yada http://www.budosyanedir.com dan bakabilirsiniz. eğer virüs olduğuna karar verdiyseniz
7)"attrib *.exe -s -r -h -a" burada dosya izinlerini veriyoruz.
8-"del *.exe" şimdi dosya silinecek. eğer silinmezse dosya kullanılıyordur. görev yöneteicinden durdurmayı deneyin yada güvenli modda çalıştırın. dikkat *.exe yazdığınızda tüm exe dosyalarıyla işlem yaparsınız. pek olmaz ama birden fazla exe dosyası varsa ve siz sadece bazılarının virüs olduğunu düşünüyorsanız dosyanın tam adını yazın. örn: *.exe yerine abc.exe

uyarı bilmediğiniz dosyaları silmek format gerektirebilir

Hocam combo bunları otomatik silmiyormu ?Ya da onarma yapmıyormu?
 
yapıyor olabillir ama emin olmak için bu şeklde görüp işlem yapabilirsiniz diye söyledim. ayrıca combo sadece içinde kayıtlı olan dosyalar için işlem yapar
 
Sağol hocam Bismillah deyip başlayım bakalım.Sonunda format .görünüyor gibi.İçlerinden kesin solucan olan dosya var ,onu biliyorum.
setpwr32.exe(Trojan)---BU KESİN VİRÜS..
setver.exe(vorm)
Hiç olmazsa sistem dosyasından bunları kaldırayım bari..
Tekrar teşekkür ederim.
 
Geri
Üst