W32 Almaneha.b

Kodla Büyü
Mesajlar
2
Bilgisayara W32 Almaneha.b diye bir Worm Yerleşti tabi nasıl olduysa bende anlamadım PC Açık kalmıştı Ben Dershaneye gitmiştim döndüğümde pat C:\ Sürücüsünde Şöyle Bir Hata Çıktı :
C:\ erişilemez
Dosya Başka bir işlem tarafından kullanıldığından bu dosyaya erişilemiyor, diyor ve bugün oldu bu sorun PC C:\ Sürücüsünün Özelliklerine baktığımda Boş Alan 0 bayt Dolu Alan 0 bayt Toplam Alan 0 bayt hatası çıktı hal buki program yüklediğimde C:\ ye kolayca kuruyordu ve Avira Antivirus Premium ile tarattım tabi Chip den aldım programı orjinal 5 aylık şimdi Tarattığımda 1 Patchs çıktı ama C:\Docume and Setting\***** ********\Belgelerim' i tarattım sonra nasıl olduysa bir açık yakalayıp bütün Dosyaları Tarattım C:\Windows\system\fsproflt vb. programlar virüs kapmış C:\ Açılmıyor ve C:\ Windowsun kurulduğu. dur Tarama Raporlarını veriyorum belki işinize yarar :


Avira AntiVir Premium
Report file date: 04 Aralık 2010 Cumartesi 21:19

Scanning for 3118676 virus strains and unwanted programs.

The program is running as a fully functional evaluation version.
Online services are available:

Licensee : KAĞAN DEMİRBAŞ
Serial number : 2210590597-PEPWE-0000001
Platform : Windows XP
Windows version : (Service Pack 2) [5.1.2600]
Boot mode : Normally booted
Username : Kağan DEMİRBAŞ
Computer name : KA-BC0D6D3B4F30

Version information:
BUILD.DAT : 10.0.0.628 35935 Bytes 16.11.2010 15:55:00
AVSCAN.EXE : 10.0.3.1 434344 Bytes 02.11.2010 16:32:53
AVSCAN.DLL : 10.0.3.0 46440 Bytes 01.04.2010 10:57:05
LUKE.DLL : 10.0.2.3 104296 Bytes 07.03.2010 16:34:00
LUKERES.DLL : 10.0.0.1 12648 Bytes 10.02.2010 21:40:54
VBASE000.VDF : 7.10.0.0 19875328 Bytes 06.11.2009 07:05:36
VBASE001.VDF : 7.10.1.0 1372672 Bytes 19.11.2009 17:27:49
VBASE002.VDF : 7.10.3.1 3143680 Bytes 20.01.2010 15:37:42
VBASE003.VDF : 7.10.3.75 996864 Bytes 26.01.2010 14:37:42
VBASE004.VDF : 7.10.4.203 1579008 Bytes 05.03.2010 09:29:03
VBASE005.VDF : 7.10.6.82 2494464 Bytes 15.04.2010 09:25:42
VBASE006.VDF : 7.10.7.218 2294784 Bytes 02.06.2010 09:26:06
VBASE007.VDF : 7.10.9.165 4840960 Bytes 23.07.2010 09:26:56
VBASE008.VDF : 7.10.11.133 3454464 Bytes 13.09.2010 09:27:34
VBASE009.VDF : 7.10.13.80 2265600 Bytes 02.11.2010 16:32:51
VBASE010.VDF : 7.10.13.81 2048 Bytes 02.11.2010 16:32:51
VBASE011.VDF : 7.10.13.82 2048 Bytes 02.11.2010 16:32:51
VBASE012.VDF : 7.10.13.83 2048 Bytes 02.11.2010 16:32:51
VBASE013.VDF : 7.10.13.116 147968 Bytes 04.11.2010 16:14:29
VBASE014.VDF : 7.10.13.147 146944 Bytes 07.11.2010 18:10:23
VBASE015.VDF : 7.10.13.180 123904 Bytes 09.11.2010 16:27:12
VBASE016.VDF : 7.10.13.211 122368 Bytes 11.11.2010 16:03:19
VBASE017.VDF : 7.10.13.243 147456 Bytes 15.11.2010 06:52:29
VBASE018.VDF : 7.10.14.15 142848 Bytes 17.11.2010 11:00:51
VBASE019.VDF : 7.10.14.41 134144 Bytes 19.11.2010 13:27:48
VBASE020.VDF : 7.10.14.63 128000 Bytes 22.11.2010 16:14:44
VBASE021.VDF : 7.10.14.87 143872 Bytes 24.11.2010 17:41:38
VBASE022.VDF : 7.10.14.116 140800 Bytes 26.11.2010 18:49:39
VBASE023.VDF : 7.10.14.147 150528 Bytes 30.11.2010 16:27:30
VBASE024.VDF : 7.10.14.175 126464 Bytes 03.12.2010 16:00:39
VBASE025.VDF : 7.10.14.176 2048 Bytes 03.12.2010 16:00:40
VBASE026.VDF : 7.10.14.177 2048 Bytes 03.12.2010 16:00:40
VBASE027.VDF : 7.10.14.178 2048 Bytes 03.12.2010 16:00:40
VBASE028.VDF : 7.10.14.179 2048 Bytes 03.12.2010 16:00:40
VBASE029.VDF : 7.10.14.180 2048 Bytes 03.12.2010 16:00:41
VBASE030.VDF : 7.10.14.181 2048 Bytes 03.12.2010 16:00:41
VBASE031.VDF : 7.10.14.189 37888 Bytes 03.12.2010 00:31:46
Engineversion : 8.2.4.120
AEVDF.DLL : 8.1.2.1 106868 Bytes 10.10.2010 09:28:33
AESCRIPT.DLL : 8.1.3.48 1286524 Bytes 03.12.2010 06:51:18
AESCN.DLL : 8.1.7.2 127349 Bytes 22.11.2010 16:15:52
AESBX.DLL : 8.1.3.2 254324 Bytes 22.11.2010 16:15:59
AERDL.DLL : 8.1.9.2 635252 Bytes 10.10.2010 09:28:27
AEPACK.DLL : 8.2.4.1 512375 Bytes 03.12.2010 06:51:13
AEOFFICE.DLL : 8.1.1.10 201084 Bytes 22.11.2010 16:15:50
AEHEUR.DLL : 8.1.2.52 3109238 Bytes 04.12.2010 00:32:01
AEHELP.DLL : 8.1.16.0 246136 Bytes 03.12.2010 06:50:53
AEGEN.DLL : 8.1.5.0 397685 Bytes 03.12.2010 06:50:51
AEEMU.DLL : 8.1.3.0 393589 Bytes 22.11.2010 16:14:49
AECORE.DLL : 8.1.19.0 196984 Bytes 03.12.2010 06:50:48
AEBB.DLL : 8.1.1.0 53618 Bytes 10.10.2010 09:28:00
AVWINLL.DLL : 10.0.0.0 19304 Bytes 14.01.2010 10:01:20
AVPREF.DLL : 10.0.0.0 44904 Bytes 14.01.2010 10:01:15
AVREP.DLL : 10.0.0.8 62209 Bytes 18.02.2010 14:47:40
AVREG.DLL : 10.0.3.2 53096 Bytes 02.11.2010 16:32:53
AVSCPLR.DLL : 10.0.3.1 83816 Bytes 02.11.2010 16:32:53
AVARKT.DLL : 10.0.0.14 227176 Bytes 01.04.2010 10:22:38
AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 26.01.2010 07:54:30
SQLITE3.DLL : 3.6.19.0 355688 Bytes 28.01.2010 11:00:45
AVSMTP.DLL : 10.0.0.17 63848 Bytes 16.03.2010 13:39:13
NETNT.DLL : 10.0.0.0 11624 Bytes 19.02.2010 12:41:56
RCIMAGE.DLL : 10.0.0.32 2631528 Bytes 01.04.2010 10:57:42
RCTEXT.DLL : 10.0.58.0 97128 Bytes 02.11.2010 16:32:50

Configuration settings for the scan:
Jobname.............................: Local Hard Disks
Configuration file..................: c:\program files\avira\antivir desktop\alldiscs.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: off
Integrity checking of system files..: off
Scan all files......................: Intelligent file selection
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: 04 Aralık 2010 Cumartesi 21:30

The scan of running processes will be started
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\rundll32.exe>
[WARNING] The file could not be opened!
Scan process 'rundll32.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\rundll32.exe>
[WARNING] The file could not be opened!
Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\ctfmon.exe>
[WARNING] The file could not be opened!
Scan process 'plugin-container.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\Mozilla Firefox\plugin-container.exe>
[WARNING] The file could not be opened!
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Module is OK -> <c:\Avira\AntiVir Desktop\avscan.exe>
[WARNING] The file could not be opened!
Scan process 'firefox.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\Mozilla Firefox\firefox.exe>
[WARNING] The file could not be opened!
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Module is OK -> <c:\Avira\AntiVir Desktop\avcenter.exe>
[WARNING] The file could not be opened!
Scan process 'alg.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\alg.exe>
[WARNING] The file could not be opened!
Scan process 'AVWEBGRD.EXE' - '1' Module(s) have been scanned
Module is OK -> <C:\Avira\AntiVir Desktop\avwebgrd.exe>
[WARNING] The file could not be opened!
Scan process 'avmailc.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\Avira\AntiVir Desktop\avmailc.exe>
[WARNING] The file could not be opened!
Scan process 'cchservice.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\cchservice.exe>
[WARNING] The file could not be opened!
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\svchost.exe>
[WARNING] The file could not be opened!
Scan process 'pdisrvc.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\Common Files\Portrait Displays\Drivers\pdisrvc.exe>
[WARNING] The file could not be opened!
Scan process 'mdm.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe>
[WARNING] The file could not be opened!
Scan process 'hamachi-2.exe' - '1' Module(s) have been scanned
Scan process 'GoogleUpdate.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\Google\Update\GoogleUpdate.exe>
[WARNING] The file could not be opened!
Scan process 'avshadow.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\Avira\AntiVir Desktop\avshadow.exe>
[WARNING] The file could not be opened!
Scan process 'fsproflt.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\fsproflt.exe>
[WARNING] The file could not be opened!
Scan process 'btdna.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\Kağan DEMİRBAŞ\Program Files\DNA\btdna.exe>
[WARNING] The file could not be opened!
Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\MSN Messenger\msnmsgr.exe>
[WARNING] The file could not be opened!
Scan process 'avguard.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\Avira\AntiVir Desktop\avguard.exe>
[WARNING] The file could not be opened!
Scan process 'avgnt.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\Avira\AntiVir Desktop\avgnt.exe>
[WARNING] The file could not be opened!
Scan process 'Explorer.EXE' - '1' Module(s) have been scanned
Module is OK -> <C:\explorer.exe>
[WARNING] The file could not be opened!
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\svchost.exe>
[WARNING] The file could not be opened!
Scan process 'sched.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\Avira\AntiVir Desktop\sched.exe>
[WARNING] The file could not be opened!
Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\ati2evxx.exe>
[WARNING] The file could not be opened!
Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\spoolsv.exe>
[WARNING] The file could not be opened!
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\svchost.exe>
[WARNING] The file could not be opened!
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\svchost.exe>
[WARNING] The file could not be opened!
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\svchost.exe>
[WARNING] The file could not be opened!
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\svchost.exe>
[WARNING] The file could not be opened!
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\svchost.exe>
[WARNING] The file could not be opened!
Scan process 'Ati2evxx.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\ati2evxx.exe>
[WARNING] The file could not be opened!
Scan process 'DF5Serv.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\Faronics\Deep Freeze\Install C-0\DF5Serv.exe>
[WARNING] The file could not be opened!
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\lsass.exe>
[WARNING] The file could not be opened!
Scan process 'services.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\services.exe>
[WARNING] The file could not be opened!
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\winlogon.exe>
[WARNING] The file could not be opened!
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\csrss.exe>
[WARNING] The file could not be opened!
Scan process 'smss.exe' - '1' Module(s) have been scanned
Module is OK -> <C:\system32\smss.exe>
[WARNING] The file could not be opened!

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!
Master boot sector HD1
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '147' files ).


Starting the file scan:

Begin scan in 'C:\'
Begin scan in 'D:\' <BAHRİ NADİR>
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(17).rar
[0] Archive type: RAR
[DETECTION] Is the TR/Agent.210944.B Trojan
--> Babylon.v6.0.3.4.Pro\babylon.v6.0.3.4.pro-patch.exe
[DETECTION] Is the TR/Agent.210944.B Trojan
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(19).rar
[0] Archive type: RAR
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
--> Def_ENG.sfx
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(21).rar
[0] Archive type: RAR
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
--> Def_ENG.sfx
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(26).rar
[0] Archive type: RAR
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
--> Def_ENG.sfx
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(28).rar
[0] Archive type: RAR
[DETECTION] Contains recognition pattern of the DR/Turky dropper
--> Orjinal XP Yapma.exe
[DETECTION] Contains recognition pattern of the DR/Turky dropper
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(32).rar
[0] Archive type: RAR
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
--> Def_ENG.sfx
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(36).rar
[0] Archive type: RAR
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
--> Def_ENG.sfx
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(46).rar
[0] Archive type: RAR
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
--> Def_ENG.sfx
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(58).rar
[0] Archive type: RAR
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
--> Def_ENG.sfx
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(59).rar
[0] Archive type: RAR
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
--> Def_ENG.sfx
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(62).rar
[0] Archive type: RAR
[DETECTION] Is the TR/Agent.210944.B Trojan
--> Babylon.v6.0.3.4.Pro\babylon.v6.0.3.4.pro-patch.exe
[DETECTION] Is the TR/Agent.210944.B Trojan
D:\PROGRAMLAR\CHİLD CONTROL\Keygenchicho.exe
[DETECTION] Is the TR/Horse.FZV Trojan
D:\PROGRAMLAR\CHİLD CONTROL\Salfeld.Child.Control.2008.v9.996.0.0.WinALL.Incl.Keygen-BRD.rar
[0] Archive type: RAR
[DETECTION] Is the TR/Horse.FZV Trojan
--> Keygen\Keygen.exe
[DETECTION] Is the TR/Horse.FZV Trojan
D:\PROGRAMLAR\CHİLD CONTROL\Salfeld.Child.Control.2008.v9.996.0.0.WinALL.Incl.Keygen-BRD\Keygen\Keygen.exe
[DETECTION] Is the TR/Horse.FZV Trojan
D:\PROGRAMLAR\Flash.Slideshow.Maker.Pro.v4.40.RGL\Flash.Slideshow.Maker.Pro.v4.40.RGL\Flash.Slideshow.Maker.Pro.v4.40.Keygen\eclfsm44.exe
[DETECTION] Is the TR/Horse.SAL Trojan
D:\PROGRAMLAR\video\BS.Pl.Pro.v2.15.943.Multilingual.rar
[0] Archive type: RAR
[DETECTION] Is the TR/Agent.116736.V Trojan
--> BS.Pl.Pro.v2.15.943.Multilingual\KeyGen\keygen.exe
[DETECTION] Is the TR/Agent.116736.V Trojan
D:\PROGRAMLAR\video\BS.Pl.Pro.v2.15.943.Multilingual\BS.Pl.Pro.v2.15.943.Multilingual\KeyGen\keygen.exe
[DETECTION] Is the TR/Agent.116736.V Trojan
D:\RECYCLER\S-1-5-21-1390067357-926492609-1606980848-1005\Dd5.exe
[DETECTION] Contains code of the W32/Almanahe.B Windows virus
D:\RECYCLER\S-1-5-21-1390067357-926492609-1606980848-1005\Dd7.exe
[DETECTION] Contains code of the W32/Almanahe.B Windows virus

Beginning disinfection:
D:\RECYCLER\S-1-5-21-1390067357-926492609-1606980848-1005\Dd7.exe
[DETECTION] Contains code of the W32/Almanahe.B Windows virus
[NOTE] The file was moved to the quarantine directory under the name '4e283a38.qua'.
D:\RECYCLER\S-1-5-21-1390067357-926492609-1606980848-1005\Dd5.exe
[DETECTION] Contains code of the W32/Almanahe.B Windows virus
[NOTE] The file was moved to the quarantine directory under the name '56a1159f.qua'.
D:\PROGRAMLAR\video\BS.Pl.Pro.v2.15.943.Multilingual\BS.Pl.Pro.v2.15.943.Multilingual\KeyGen\keygen.exe
[DETECTION] Is the TR/Agent.116736.V Trojan
[NOTE] The file was moved to the quarantine directory under the name '04a24f69.qua'.
D:\PROGRAMLAR\video\BS.Pl.Pro.v2.15.943.Multilingual.rar
[DETECTION] Is the TR/Agent.116736.V Trojan
[NOTE] The file was moved to the quarantine directory under the name '62ce0085.qua'.
D:\PROGRAMLAR\Flash.Slideshow.Maker.Pro.v4.40.RGL\Flash.Slideshow.Maker.Pro.v4.40.RGL\Flash.Slideshow.Maker.Pro.v4.40.Keygen\eclfsm44.exe
[DETECTION] Is the TR/Horse.SAL Trojan
[NOTE] The file was moved to the quarantine directory under the name '27042d8b.qua'.
D:\PROGRAMLAR\CHİLD CONTROL\Salfeld.Child.Control.2008.v9.996.0.0.WinALL.Incl.Keygen-BRD\Keygen\Keygen.exe
[DETECTION] Is the TR/Horse.FZV Trojan
[NOTE] The file was moved to the quarantine directory under the name '580a1ff4.qua'.
D:\PROGRAMLAR\CHİLD CONTROL\Salfeld.Child.Control.2008.v9.996.0.0.WinALL.Incl.Keygen-BRD.rar
[DETECTION] Is the TR/Horse.FZV Trojan
[NOTE] The file was moved to the quarantine directory under the name '14a733a2.qua'.
D:\PROGRAMLAR\CHİLD CONTROL\Keygenchicho.exe
[DETECTION] Is the TR/Horse.FZV Trojan
[NOTE] The file was moved to the quarantine directory under the name '68aa73ee.qua'.
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(62).rar
[DETECTION] Is the TR/Agent.210944.B Trojan
[NOTE] The file was moved to the quarantine directory under the name '45de5ca3.qua'.
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(59).rar
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '5cb6673a.qua'.
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(58).rar
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '30ea4b78.qua'.
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(46).rar
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '4f494998.qua'.
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(36).rar
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '0a603b4b.qua'.
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(32).rar
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '036b3fee.qua'.
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(28).rar
[DETECTION] Contains recognition pattern of the DR/Turky dropper
[NOTE] The file was moved to the quarantine directory under the name '5b2a269d.qua'.
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(26).rar
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '77de5f51.qua'.
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(21).rar
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '49203e70.qua'.
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(19).rar
[DETECTION] Is the TR/Crypt.XPACK.Gen Trojan
[NOTE] The file was moved to the quarantine directory under the name '2a2e1519.qua'.
D:\KURTARILANLAR\kurtarılandosya\WinRAR File(65)\Recoverd_rar_file(17).rar
[DETECTION] Is the TR/Agent.210944.B Trojan
[NOTE] The file was moved to the quarantine directory under the name '0ce6553d.qua'.


End of the scan: 04 Aralık 2010 Cumartesi 22:04
Used time: 30:32 Minute(s)

The scan has been done completely.

1288 Scanned directories
182445 Files were scanned
19 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
19 Files were moved to quarantine
0 Files were renamed
38 Files cannot be scanned
182388 Files not concerned
630 Archives were scanned
38 Warnings
18 Notes

Aynen Böyle Birçok Dosya karantina altındayken hemen işimi yapim diyorumda birde şu var PC Restlendiğinde veya Kapatılıp Açıldığında Virüsler Kendilerini Önceki Programlarına Atıyor ve Yardım Ederseniz çok sevinirim bu PC 2006 Yılından beri var 6 yaşında aldılar bana ve şu koskaca 4 yılda böyle zorlukla karşılaşmadım siz daha üstün bilgilere sahip olduğunuz için sizden Yardım İstiyorum Şimdiden Teşekkürler :twisted:
 
Bir İpucu Buldum

Ve Bir Daha Bilgisayarımı Resetledim Dracula ile Disklerin hepsini tarattım Level DVD Diskim vardı Auturon una bir virüs vardı ve Dershaneye giderken Level Dvd Takılıydı şimdi D sürücüsüne bakyım ve Adı RECYCLER kLasör icindeki dosyalar Geri Dönüşüm kutusu hepsini sildim 1 tanesi silinmiyor o dönüşüm kutusunun adını verim S-1-5-21-776561741-17677 adlı bir geri dönüşüm kutusu ve bir tane boot adında not defteri buldum
boot :
[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect

aynen böyle yazıyor.
Veri Taban Dosyaları ve BIN Dosyaları (ama ilk defa D' de gördüm) :
bootfont 5kb BIN Dosyası
CONFIG 0kb Sistem Dosyası
IO 0kb Sistem Dosyası
MSDOS 0kb Sistem Dosyası
ntldr 245kb Sistem Dosyası
pagefile 2.095.104kb Sistem dosyası
Thumbs 10kb Veri Taban Dosyası
MS-DOS ilk defa gördüklerim yine :
AUTOEXECT 0kb MS-DOS Toplu iş dosyası
NTDETECT 47kb MS-DOS Uygulaması
Virüssüz OLan veya Tehdit içermeyen Dosyaları Yorum Yazıp yanına Temiz veya Zarar gelmez yazsanız ve LEVEL Dergisi Almayın nedeni CD içinde Auturon da virüs olabiliyor
 
Geri
Üst