arkadaşım gerçekten yardımına ihtiyacım var benim bilgisayarda projec1 adlı illet bir virüs çıktı anladığım kadarıyla ve senin anlattığın kadarı ile kendim halletmeye çalıştım fakat senden hijackthis raporumu incelemeni ve şu resime bakmanı rica edecektim
Resimdeki eyt.exe kötü yazılım olan project
hijackthis Raporum Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:23:42, on 31.08.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal
kardeşim şuan için bir sorun görünmüyor bahsettigin dosyayı ise başlat çalıştır regedit HKCU_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run orada eyt.exe degeri varise sil . istersen msconfig de kullanılmayan çalıştırma satırlarını temizleyebilirsin aşagıdaki dosyayı indir çalıştır adımları uygula tamam.
çok teşekkür ederim kardeşim gerçekten çok sağol ilgin bile yeter de artar bile
quote:
Orjinalden alıntı: eray_0083
çok teşekkür ederim kardeşim gerçekten çok sağol ilgin bile yeter de artar bile
ben teşekkür ederim
burdan SEVENTYSEVEN ve SERJİ' ye seslenmek istiyorum...sizin şahsınızda burdan tüm donanımhaber ekibinin ve tüm donanım habercileri gönülden kutluyorum...hepiniz saolun varolun...yaklaşık olarak 25 dakika önce hıjackthıs le STARTDRV:EXE yi fiksledim ve şu ana kadar sürekli olarak internetteyken avast tarafından yakaladığım Win32:smal-EPJ virüsünü sildim sanıırm...teşekkürler ama koacamn teşekkürler...serji-seventyseven saolun varolun.!!!!!!!!!!!!
üstad sevetyseven!!!!bende de Win32:small-EPJ(trj) virüsü vardı dün aksam hıjack this ile resmde anlattığın gibi fix yaptım (startdrv isminde bişeydi çarpı işareti vardı)...benim sormak istediğim jack programını her türlü kötü yazılım silmek isterken kullanabilirmiyiz ve de jack programı sorunu kökünden hallediyor mu??? teşekkürler üstad!!!
şunu bir inceler misiniz üstad!!!
Logfile of Trend Micro HijackThis v2.0.2 This should be the newest version. Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) This should be the newest version. Boot mode: Normal Very safe This entry was classified from our visitors as good. C:\WINDOWS\System32\smss.exe Very safe This entry was classified from our visitors as good. C:\WINDOWS\system32\winlogon.exe Very safe This entry was classified from our visitors as good. C:\WINDOWS\system32\services.exe Safe This entry was classified from our visitors as good. C:\WINDOWS\system32\lsass.exe Very safe This entry was classified from our visitors as good. C:\WINDOWS\system32\Ati2evxx.exe Very safe This entry was classified from our visitors as good. C:\WINDOWS\system32\svchost.exe Safe This entry was classified from our visitors as good. C:\WINDOWS\System32\svchost.exe Very safe This entry was classified from our visitors as good. C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe Very safe This entry was classified from our visitors as good. C:\Program Files\Alwil Software\Avast4\ashServ.exe Very safe This entry was classified from our visitors as good. C:\WINDOWS\system32\Ati2evxx.exe Very safe This entry was classified from our visitors as good. C:\WINDOWS\Explorer.EXE Very safe This entry was classified from our visitors as good. C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe Very safe This entry was classified from our visitors as good. C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe Safe NetworkAccessManager C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe Safe Java Runtime C:\WINDOWS\FixCamera.exe Safe This is a unknown process. This entry was classified from our visitors as good. C:\WINDOWS\tsnp2std.exe Very safe This is a unknown process. This entry was classified from our visitors as good. C:\WINDOWS\vsnp2std.exe Very safe This is a unknown process. This entry was classified from our visitors as good. C:\Program Files\MSN Messenger\msnmsgr.exe Very safe This entry was classified from our visitors as good. C:\WINDOWS\system32\spoolsv.exe Safe This entry was classified from our visitors as good. C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Very safe This entry was classified from our visitors as good. C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe Safe Apache webserver C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE Safe Machine Debug Manager. Used by developers. C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe Safe Possibly nasty! According to our database this process runs normally in c:\programme\nvidia~1\bin\! Check if you know this process and arrange a viruscheck where required. This entry was classified from our visitors as good. C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe Neutral Possibly nasty! According to our database this process runs normally in c:\programme\nvidia~1\bin\! Check if you know this process and arrange a viruscheck where required. ForceWare user log service C:\WINDOWS\system32\svchost.exe Safe This entry was classified from our visitors as good. C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe Safe Possibly nasty! According to our database this process runs normally in c:\programme\nvidia~1\bin\! Check if you know this process and arrange a viruscheck where required. ForceWare Intelligent Application Manager C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe Safe Apache webserver C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe Very safe This entry was classified from our visitors as good. C:\Program Files\Alwil Software\Avast4\ashWebSv.exe Very safe This entry was classified from our visitors as good. C:\WINDOWS\System32\svchost.exe Very safe This entry was classified from our visitors as good. C:\Program Files\Internet Explorer\IEXPLORE.EXE Very safe This entry was classified from our visitors as good. C:\Program Files\Trend Micro\HijackThis\HijackThis.exe Very safe Remember that Hijackthis must be run in an own folder. Only if Hijackthis run in an own folder it will create backups! Tool, mit dem sie dieses Logfile erzeugt haben. Das Programm sollte so angelegt sein ! C:\Programme\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Bağlantılar Very safe This page has been identified as safe. O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll Very safe This entry was classified from our visitors as good. O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll Very safe SUN Java O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe Very safe This entry was classified from our visitors as good. O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe Safe NVIDIA Corporation NetworkAccessManager O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" Safe Java von Sun O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe Safe Unknown application. This entry was classified from our visitors as good. O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe Safe This entry was classified from our visitors as good. O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe Safe This entry was classified from our visitors as good. O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background Very safe This entry was classified from our visitors as good. O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Very safe This entry was classified from our visitors as good. O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') Office related O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') Office related O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') Very safe Office related O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') Very safe Office related O8 - Extra context menu item: Microsoft Excel'e Gö&nder - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 The entry Microsoft Excel'e Gö&nder has been identified as safe. O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll Very safe The entry has been identified as safe. O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll Safe The entry Sun Java Console has been identified as safe. O9 - Extra button: Araştır - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL The entry Araştır has been identified as safe. O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe Very safe The entry Messenger has been identified as safe. O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe Neutral The entry Windows Messenger has been identified as safe. O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -http://www.kaspersky.com/kos/eng/partner/default/kavwebscan_unicode.cab Very safe This entry has been identified as safe. O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL Very safe This entry was classified from our visitors as good. O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe Very safe This service (aswUpdSv.exe) was identified as a good one. O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe Safe This service (Ati2evxx.exe) was identified as a good one. This entry was classified from our visitors as good. O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe Very safe This service (ati2sgag.exe) was identified as a good one. This entry was classified from our visitors as good. O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe Very safe This service (ashServ.exe) was identified as a good one. O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe Very safe This service (ashMaiSv.exe) was identified as a good one. O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe Safe This service (ashWebSv.exe) was identified as a good one. O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe Neutral This service (nSvcAppFlt.exe) was identified as a good one. O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe This service (apache.exe) was identified as a good one. O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe This service (nSvcIp.exe) was identified as a good one. O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe Safe This service (nSvcLog.exe) was identified as a good one.
ingeniatorem bunu siteden kopyalamışsın bana bilgisayarında çıkan listeyi kopyalarsan daha saglıklı olur
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:04:10, on 05.09.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal
benım pc de bir kaç gündür şunları yaşadım: -avast pc her açılışta Ip6Fw.sys gibi birçok virüs yakalıyodu -bir ara internete her girdiğimde sürekli şüpheli mesaj uyarısı yaptı -dün startdrv.exe gibi birşey yakaladı ve ben dün startdrv yi fiksledim bir sorun yok gibiydi
bugün internetten mi geldi yoksa bir cd vardı onu takınca mı oldu tam olarka bilemiyorum...avast bir sürü virüs yakaladı ben de avastın özelliği olan acılışta tarama özelliğini programladım ve pc acılışta dos ortamında avast tarafından tarandı ve :startdrv.exe-win.dll-Ip6Fw.sys-buttonz.ocx-RUNTIME2.sys ve A0002481.ocx ve gene A000ile başlayan .acx -.exe 20 tane virsyakaladı...ben bunları hepsini karantinaya aldım....yukarıda gönderdiğim jack raporu da pc min en son hali...yaklaşık 5 saatir pc nin başındayım henüz hiçbişey olmadı.herhangi bir sorun cıkmadı...DURUM BUNDAN İBARET...TEŞEKKÜRLER
YUKARIDAKİLERİ FİKSLEMEMİ SOLEMİŞSİN ÜSTAD AMA ONLARIN KARŞISINDA HERHANGİ Bİ UYARI İŞARETİ YOK JACK PROGRAMINDA????
gezindigin sitelere dikkat et cd den bulaşma ihtimalide var tabi karantinaya aldı isen bir sorun yok cd yi birsüre kullanma bakalım yine o hataları verecekmi o zaman anlarsın geregini yaparsın, yukardakiler gereksiz çalışanlar bunlar zararsızdır ama fixlediginde bir sorun olmaz aksine explorer biraz daha rahatlar
ya zaten önceki virüslerin nası geldiğini anlamadım bile...tatil dönüşü bilgisayarı bi actım internete gireyim dedim bi baktım avast sürekli olarak ikaz veriyor şüpheli mesaj diye!!!o mesajlar nasıl ve nerden geldi anlamadım bile...akşama eve gidince solediğin yukardaki şeyleri de fiksleyeceğim...çok teşekkürler üstad Allah yolunu her daim acık etsın saolasın!!!!
sen sağolasın
Akadaşım buna bi bakarmısın
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:11:52, on 07.09.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16512) Boot mode: Normal