Regedit dosyasında virüs olabilir mi?

UgurUyar

Kilopat
Katılım
7 Haziran 2018
Mesajlar
1.651
Çözümler
10
Arkadaşlar bir uygulama için zaman sıfırlayıcı bir regedit dosyası arıyordum. Kodun içinde bunlar var ne anlama geliyor güvenemedim pek.

[-HKEY_CURRENT_USER\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
[-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]
[-HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{7B8E9164-324D-4A2E-A46D-0165FB2000EC}]

[-HKEY_CURRENT_USER\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}]
[-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}]
[-HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{6DDF00DB-1234-46EC-8356-27E7B2051192}]

[-HKEY_CURRENT_USER\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}]
[-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}]
[-HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{D5B91409-A8CA-4973-9A0B-59F713D25671}]

[-HKEY_CURRENT_USER\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
[-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
[-HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]

[-HKEY_CURRENT_USER\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}]
[-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}]
[-HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{07999AC3-058B-40BF-984F-69EB1E554CA7}]

[-HKEY_CURRENT_USER\Software\Classes\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}]
[-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}]
[-HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{5312C54E-A385-46B7-B200-ABAF81B03935}]

[-HKEY_CURRENT_USER\Software\Classes\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}]
[-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}]
[-HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{436D67E1-2FB3-4A6C-B3CD-FF8A41B0664D}]





[-HKEY_CURRENT_USER\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}]
[-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}]
[-HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{9C9D53D4-A978-43FC-93E2-1C21B529E6D7}]

[-HKEY_CURRENT_USER\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}]
[-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}]
[-HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E8CF4E59-B7A3-41F2-86C7-82B03334F22A}]

[-HKEY_CURRENT_USER\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}]
[-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}]
[-HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{E6871B76-C3C8-44DD-B947-ABFFE144860D}]

[-HKEY_CURRENT_USER\Software\Classes\CLSID\{84797876-C678-1780-A556-0CD06786780F}]
[-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{84797876-C678-1780-A556-0CD06786780F}]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{84797876-C678-1780-A556-0CD06786780F}]
[-HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{84797876-C678-1780-A556-0CD06786780F}]

[-HKEY_CURRENT_USER\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}]
[-HKEY_CURRENT_USER\Software\Classes\Wow6432Node\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}]
[-HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}]
[-HKEY_LOCAL_MACHINE\Software\Classes\Wow6432Node\CLSID\{79873CC5-3951-43ED-BDF9-D8759474B6FD}]
 
Son düzenleyen: Moderatör:
Regedit ile virüs bulaşmaz. Reg dosyası görünümlü bir programdan bulaşabilir ancak kayıt defterine ekleme - çıkarma yaparak virüs bulaşamaz. Ki içeriğine bakmışsınız, reg dosyası görünümlü başka bir program da değil yani.
 
Yanlış hatırlamıyorsam daha önce buna benzer bi olay başıma geldi. Autohotkey ile hem de. Onda da virüs yoktu fakat zannettiğim kadarıyla arkaplanda kendini yükleyecek schedule oluşturuyordu o yüzden sordum.
 

Geri
Yukarı