Virüs bulaştı chrome farklı siteye gidiyor

SMOKEALOT

Hectopat
Katılım
6 Eylül 2013
Mesajlar
175
Merhaba, torrentten indirme yapmak istiyordum. İndirdiğim dosyaya tıklayınca farklı programı kurdum. Silmeye çalıştım ama kendi kendine program açıyor chrome çalıştırdığımda konuslandığım sayfaya giriyor ne yapabilirim ?
 
Son düzenleyen: Moderatör:
Programların kurulduğu sayfayı açtığımda yabancı birşey görülmüyor. Açılan programı da normal yollarla kapatamıyorum ancak görev yöneticisinden kapatabiliyorum.
 
Son düzenleyen: Moderatör:
Tarama temiz çıkmıştı ama avast sürekli bana şu konuda hata veriyor ''win32:evo-gen (SUSP). ''Win32 Adware-gen '' Birde malware bulaşma hatası verdi.
 
GetSystemInfo Parser 2.96

Şöyle bir amatörlük yaptım. Sistem 2 taraması yaptığımda ilkinde 6000 küsür dosya aramıştı. Hata ile ilkinde dosyaları remove tuşuna bastım, geri alamadığım içinde biraz vakitten sonra da görev yöneticisinden kapattım. Bu paylaştığım ikinci tarama sonuçlarıdır.



Kod:
Saved date:          20.4.2015 02:05:33
Files detected:     57
Files scanned:         10.316
Processes scanned:     78
Modules scanned:     696
ASEPs scanned:         515
Downloads scanned:     0
Deep analysis:         8/0
---------------------------------------------------------------------------------

Files

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\03000200-1429479130-0500-0006-000700080009\cnsd3e5.tmp
Publisher:      
MD5:             44f603d4277db8794f48ebaf9f929863
SHA-1:             2998c9229e1a714fe89926fd6b6ba9a4af6fe247
Created:         19.4.2015 21:32:15
Detections:         7
Determination:         UndefinedMalware
            - Lavasoft Ad-Aware as Gen:Variant.Graftor.184327 (Undefined)
            - MicroWorld eScan as Gen:Variant.Graftor.184327 (Undefined)
            - Kaspersky as UDS:DangerousObject.Multi.Generic (Undefined)
            - Bitdefender as Gen:Variant.Graftor.184327 (Undefined)
            - Emsisoft Anti-Malware as Gen:Variant.Graftor.184327 (Undefined)
            - F-Secure as Gen:Variant.Graftor.184327 (Undefined)
            - G Data as Gen:Variant.Graftor.184327 (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\03000200-1429479147-0500-0006-000700080009\snsi42e0.tmp
Publisher:      
MD5:             fea74eed4883ca7a3eed74cdc73962c9
SHA-1:             62d9c9ceb8a03b041e60c761ab704a6d256236f6
Created:         19.4.2015 21:32:35
Detections:         1
Determination:         Inconclusive
            - Kaspersky as UDS:DangerousObject.Multi.Generic (Undefined)

---------------------------------------------------------------------------------

File path:         c:\program files (x86)\xtab\suptab.dll
Publisher:         Thinknice Co. Limited
Signer:         Giner Tech Inc
MD5:             fc60e0ceb67207edd48ed4acbea5de98
SHA-1:             a1aa6396b9d450c3d6b5955f714ab029f06babfe
Created:         2.4.2015 06:39:36
Detections:         14
Determination:         Adware
            - Bkav FE as W32.HfsAdware (Adware)
            - McAfee as Artemis!FC60E0CEB672 (Undefined)
            - Malwarebytes as PUP.Optional.SupTab.A (Adware)
            - K7 AntiVirus as Adware  (Adware)
            - K7 Gateway Antivirus as Adware  (Adware)
            - Trend Micro House Call as Suspicious_GEN.F47V0402 (Undefined)
            - avast! as Win32:GenMaliciousA-EHB [PUP] (Adware)
            - Clam AntiVirus as Win.Adware.SupTab (Adware)
            - VIPRE Antivirus as Adware.SearchProtect (Adware)
            - Sophos as Generic PUA KB (Undefined)
            - ESET NOD32 as Win32/Thinknice.B potentially unwanted (variant) (Adware)
            - Fortinet FortiGate as Riskware/Thinknice (Undefined)
            - Qihoo 360 Security as HEUR/QVM30.1.Malware.Gen (Undefined)
            - Reason Heuristics as PUP.BHO.Thinknice (Adware)

---------------------------------------------------------------------------------

File path:         C:\Program Files (x86)\Infonaut_1.10.0.14\Service\insvc.exe
Publisher:         Infonaut
Signer:         Infonaut
MD5:             d1afccbc2bc504f9f0c70b058ebe344b
SHA-1:             e0359b12a990bb29a0db03e0fedd5d84fb760eb3
Created:         10.4.2015 22:57:08
Detections:         4
Determination:         Adware
            - VIPRE Antivirus as InfoAtoms (Undefined)
            - Baidu Antivirus as Adware.Win32.Vitruvian (Adware)
            - ESET NOD32 as Win32/Adware.Vitruvian (variant) (Adware)
            - Qihoo 360 Security as HEUR/QVM10.1.Malware.Gen (Undefined)

---------------------------------------------------------------------------------

File path:         c:\program files (x86)\xtab\protectservice.exe
Publisher:         XTab system
Signer:         Giner Tech Inc
MD5:             e98c5cfa4051bfa3e2cb0afb10ff4cab
SHA-1:             a511d45ef634098c7366fd403a87fa3a20ab536a
Created:         2.4.2015 06:39:38
Detections:         20
Determination:         Adware
            - Bkav FE as W32.HfsAdware (Adware)
            - MicroWorld eScan as Adware.SearchProtect.W (Adware)
            - nProtect as Adware.SearchProtect.W (Adware)
            - McAfee as Artemis!E98C5CFA4051 (Undefined)
            - Zillya! Antivirus as Adware.SearchProtect.Win32.20 (Adware)
            - K7 AntiVirus as Trojan  (Undefined)
            - Trend Micro House Call as Suspicious_GEN.F47V0402 (Undefined)
            - NANO AntiVirus as Riskware.Win32.SearchProtect.dpvtwk (Adware)
            - Lavasoft Ad-Aware as Adware.SearchProtect.W (Adware)
            - Sophos as Generic PUA KF (Undefined)
            - F-Secure as Adware.SearchProtect.W (Adware)
            - VIPRE Antivirus as Trojan.Win32.Generic (Undefined)
            - F-Prot as W32/SearchProtect.C.gen (Undefined)
            - Jiangmin as AdWare/SearchProtect.g (Adware)
            - Avira AntiVirus as PUA/SearchProtect.Gen (Undefined)
            - G Data as Adware.SearchProtect (Adware)
            - Vba32 AntiVirus as AdWare.SearchProtect (Adware)
            - ESET NOD32 as Win32/ELEX.BM potentially unwanted (Adware)
            - Fortinet FortiGate as Riskware/Elex (Undefined)
            - Reason Heuristics as PUP.Service.Thinknice (Adware)

---------------------------------------------------------------------------------

File path:         c:\program files (x86)\xtab\hpnotify.exe
Publisher:         XTab system
Signer:         Giner Tech Inc
MD5:             8c15f35314eadbe08375dd47ad62439a
SHA-1:             f63121cdd14d9bcfa93bb10af315fb5fc0823c03
Created:         2.4.2015 06:39:38
Detections:         11
Determination:         Adware
            - Bkav FE as W32.HfsAdware (Adware)
            - Malwarebytes as PUP.Optional.ELEX (Adware)
            - Agnitum Outpost as Riskware.Agent (Adware)
            - Dr.Web as Adware.Mutabaha.121 (Adware)
            - VIPRE Antivirus as Trojan.Win32.Generic (Undefined)
            - F-Prot as W32/SearchProtect.B.gen (Undefined)
            - Jiangmin as AdWare/SearchProtect.i (Adware)
            - G Data as Win32.Application.SearchProtect.AA@gen (Undefined)
            - Baidu Antivirus as Adware.Win32.ELEX (Adware)
            - ESET NOD32 as Win32/ELEX.BM potentially unwanted (Adware)
            - Reason Heuristics as Threat.Thinknice.GinerTech (Undefined)

---------------------------------------------------------------------------------

File path:         c:\program files (x86)\xtab\browseraction.dll
Publisher:         Skytech Co., Ltd.
MD5:             5785680870eff9ba7b4f58c726552013
SHA-1:             5d628376391a827a818b0a079b64ee457ae9b82a
Created:         15.1.2015 04:27:08
Detections:         1
Determination:         Adware
            - Reason Heuristics as PUP.SkytechCo.N (Adware)

---------------------------------------------------------------------------------

File path:         C:\Program Files (x86)\XTab\IeWatchDog.dll
Publisher:         Search Protecter
Signer:         Giner Tech Inc
MD5:             e6aac50b9fc19546c5e524c47be5d66d
SHA-1:             15d0246dbdbc07ecfb0a33970bc2571ef50e40d0
Created:         2.4.2015 06:39:36
Detections:         16
Determination:         Adware
            - Bkav FE as W32.HfsAdware (Adware)
            - Quick Heal as PUA.SearchProtect.OD3 (Adware)
            - Malwarebytes as PUP.Optional.SearchProtect (Adware)
            - Zillya! Antivirus as Adware.SearchProtect.Win32.25 (Adware)
            - K7 Gateway Antivirus as Trojan  (Undefined)
            - K7 AntiVirus as Trojan  (Undefined)
            - F-Prot as W32/SearchProtect.B (Undefined)
            - Agnitum Outpost as Riskware.Agent (Adware)
            - Dr.Web as Adware.Mutabaha.120 (Adware)
            - VIPRE Antivirus as Trojan.Win32.Generic (Undefined)
            - Jiangmin as AdWare/SearchProtect.j (Adware)
            - G Data as Win32.Application.SearchProtect.AA@gen (Undefined)
            - Vba32 AntiVirus as AdWare.SearchProtect (Adware)
            - Baidu Antivirus as Adware.Win32.ELEX (Adware)
            - ESET NOD32 as Win32/ELEX.BM potentially unwanted (Adware)
            - Reason Heuristics as Threat.Thinknice.GinerTech (Undefined)

---------------------------------------------------------------------------------

File path:         c:\program files (x86)\xtab\browerwatchch.dll
Publisher:         XTab
Signer:         Giner Tech Inc
MD5:             33a33e52e9c7db9063cbac82fa9e28d4
SHA-1:             6e1625e1518b1fb62f58fd89349a2aebecf3c90a
Created:         2.4.2015 06:39:34
Detections:         14
Determination:         Adware
            - Bkav FE as W32.HfsAdware (Adware)
            - Malwarebytes as PUP.Optional.BrowserWatch (Adware)
            - Zillya! Antivirus as Adware.SearchProtect.Win32.21 (Adware)
            - K7 AntiVirus as Trojan  (Undefined)
            - K7 Gateway Antivirus as Trojan  (Undefined)
            - Agnitum Outpost as Riskware.Agent (Adware)
            - Dr.Web as Adware.Mutabaha.119 (Adware)
            - VIPRE Antivirus as Trojan.Win32.Generic (Undefined)
            - Jiangmin as AdWare/SearchProtect.l (Adware)
            - G Data as Win32.Application.SearchProtect.AA@gen (Undefined)
            - Vba32 AntiVirus as AdWare.SearchProtect (Adware)
            - Baidu Antivirus as Adware.Win32.ELEX (Adware)
            - ESET NOD32 as Win32/ELEX.BM potentially unwanted (Adware)
            - Reason Heuristics as PUP.Thinknice (Adware)

---------------------------------------------------------------------------------

File path:         c:\program files (x86)\xtab\cmdshell.exe
Publisher:         SearchProtect
Signer:         Giner Tech Inc
MD5:             7e4e734d5adbbc4026a5db2e63c29d40
SHA-1:             f89f1321002adbca7b6b4d15ad2261d9151ef715
Created:         2.4.2015 06:39:38
Detections:         16
Determination:         Adware
            - Bkav FE as W32.HfsAdware (Adware)
            - Malwarebytes as PUP.Optional.SearchProtect (Adware)
            - Zillya! Antivirus as Adware.SearchProtect.Win32.14 (Adware)
            - K7 Gateway Antivirus as Trojan  (Undefined)
            - K7 AntiVirus as Trojan  (Undefined)
            - F-Prot as W32/SearchProtect.C.gen (Undefined)
            - Kaspersky as not-a-virus:AdWare.Win32.SearchProtect (Adware)
            - Agnitum Outpost as PUA.SearchProtect (Adware)
            - Dr.Web as Adware.Mutabaha.117 (Adware)
            - VIPRE Antivirus as Trojan.Win32.Generic (Undefined)
            - Jiangmin as AdWare/SearchProtect.f (Adware)
            - G Data as Win32.Application.SearchProtect.AA@gen (Undefined)
            - Vba32 AntiVirus as AdWare.SearchProtect (Adware)
            - Baidu Antivirus as Adware.Win32.SearchProtect (Adware)
            - ESET NOD32 as Win32/ELEX.BM potentially unwanted (Adware)
            - Reason Heuristics as PUP.Thinknice (Adware)

---------------------------------------------------------------------------------

File path:         c:\program files\kmspico\service_kms.exe
Publisher:      
MD5:             2aa809fb9c429e2166fa13ea04670992
SHA-1:             ef18b4a280a079e21cccf92c4c4d838f85640cea
Created:         5.1.2015 19:42:34
Detections:         13
Determination:         UndefinedMalware
            - McAfee as Artemis!2AA809FB9C42 (Undefined)
            - K7 AntiVirus as Hacktool
            - K7 Gateway Antivirus as Hacktool
            - Norman as Agent.AOQWC (Undefined)
            - Trend Micro House Call as TROJ_GEN.R0CBB01LR13 (Undefined)
            - Comodo Security as UnclassifiedMalware (Undefined)
            - Avira AntiVirus as TR/Spy.A.1139 (Undefined)
            - McAfee Web Gateway as Artemis!2AA809FB9C42 (Undefined)
            - ESET NOD32 as MSIL/HackTool.IdleKMS (variant) (Undefined)
            - IKARUS anti.virus as Virus.Dropper (Undefined)
            - AVG as Dropper.Msil (Undefined)
            - Bkav FE as W32.Clod142.Trojan (Undefined)
            - VIPRE Antivirus as Trojan.Win32.Generic (Undefined)

---------------------------------------------------------------------------------

File path:         c:\windows\system32\drivers\innfd_1_10_0_14.sys
Publisher:         Infonaut
Signer:         Infonaut
MD5:             9a3a331881a112551748860edd857a26
SHA-1:             3f5eb10b1acc6050134944856c0c9b3ef5bdc4c8
Created:         10.4.2015 22:56:56
Detections:         6
Determination:         Adware
            - Dr.Web as Adware.Plugin.274 (Adware)
            - McAfee Web Gateway as BehavesLike.Win64.Suspicious.qh (Undefined)
            - Jiangmin as AdWare/Vitruvian.j (Adware)
            - Baidu Antivirus as Hacktool.Win64.NetFilter
            - ESET NOD32 as Win64/NetFilter.A potentially unsafe (variant) (Undefined)
            - Fortinet FortiGate as Adware/NetFilter (Adware)

---------------------------------------------------------------------------------

File path:         c:\program files (x86)\mbot_tr_221\mbot_tr_221.exe
Publisher:      
Signer:         Tuto4PC.com
MD5:             a802aef6d870cebc32ffce1335beddab
SHA-1:             b38c052bba0d47c1fbe0aa3cecfb98488e770046
Created:         19.4.2015 21:29:13
Detections:         31
Determination:         Adware
            - Reason Heuristics as Threat.Eorezo.Bundler (Undefined)
            - VIPRE Antivirus as Threat.4895339 (Undefined)
            - avast! as Win32:Adware-ASG [PUP] (Adware)
            - Emsisoft Anti-Malware as Adware.Eorezo.BZ (Adware)
            - Dr.Web as Adware.Downware.10601,  Adware.Downware.10880 (Adware)
            - Kaspersky as not-a-virus:AdWare.Win32.Eorezo (Adware)
            - F-Secure as Adware.Eorezo.BZ (Adware)
            - ESET NOD32 as Win32/AdWare.EoRezo.AU application (Adware)
            - Norman as Adware.Eorezo.BZ (Adware)
            - Clam AntiVirus as Win.Adware.Eorezo-198 (Adware)
            - Bkav FE as W32.HfsAdware (Adware)
            - MicroWorld eScan as Adware.Eorezo.BZ (Adware)
            - nProtect as Adware.Eorezo.BZ (Adware)
            - Quick Heal as Adware.Eorezo.S5 (Adware)
            - Zillya! Antivirus as Trojan.Black.Win32.29375 (Undefined)
            - K7 Gateway Antivirus as Adware  (Adware)
            - K7 AntiVirus as Adware  (Adware)
            - Agnitum Outpost as PUA.Eorezo (Adware)
            - Bitdefender as Adware.Eorezo.BZ (Adware)
            - NANO AntiVirus as Riskware.Win32.Eorezo.dqhcld (Adware)
            - Lavasoft Ad-Aware as Adware.Eorezo.BZ (Adware)
            - Sophos as Eorezo (Undefined)
            - Jiangmin as AdWare/Eorezo.eu (Adware)
            - Avira AntiVirus as ADWARE/Adware.Gen7 (Adware)
            - Antiy Labs AVL as GrayWare[AdWare]/Win32.Eorezo.fkz (Adware)
            - G Data as Adware.Eorezo.BZ (Adware)
            - AhnLab V3 Security as PUP/Win32.Eorezo (Adware)
            - Baidu Antivirus as Adware.Win32.EoRezo (Adware)
            - Rising Antivirus as PE:Adware.EoRezo!6.1D0F (Adware)
            - AVG as Generic (Undefined)
            - Qihoo 360 Security as HEUR/QVM10.1.Malware.Gen (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\03000200-1429478965-0500-0006-000700080009\bnsq75c7.exe
Publisher:      
MD5:             54a6331b9d29739ccfac6a9f91fd6815
SHA-1:             5218c80203c1964eeff0caddcf05dba5a9699cf6
Created:         19.4.2015 20:20:42
Detections:         1
Determination:         Adware
            - Reason Heuristics as Threat.Adware.WinCheck.Startup (Adware)

---------------------------------------------------------------------------------

File path:         c:\program files (x86)\anyprotectex\anyprotect.exe
Publisher:         AnyProtect.com
MD5:             2691439fac40f46c937bb684a3ae2e0f
SHA-1:             9abbaf453246d0c43d62e3a372f40807fb500bcd
Created:         20.4.2015 00:10:37
Detections:         15
Determination:         Adware
            - MicroWorld eScan as Adware.Agent.PCA (Adware)
            - nProtect as Adware.Agent.PCA (Adware)
            - K7 AntiVirus as Riskware  (Undefined)
            - K7 Gateway Antivirus as Riskware  (Undefined)
            - Agnitum Outpost as Trojan.BPlug (Undefined)
            - Bitdefender as Adware.Agent.PCA (Adware)
            - Lavasoft Ad-Aware as Adware.Agent.PCA (Adware)
            - Sophos as AnyProtect (Undefined)
            - F-Secure as Adware.Agent.PCA (Adware)
            - Emsisoft Anti-Malware as Adware.Agent.PCA (Adware)
            - G Data as Adware.Agent.PCA (Adware)
            - AhnLab V3 Security as PUP/Win32.AnyProtect (Adware)
            - AVG as Generic_r (Undefined)
            - Qihoo 360 Security as HEUR/QVM10.1.Malware.Gen (Undefined)
            - Reason Heuristics as PUP.Optional.Task (Adware)

---------------------------------------------------------------------------------

File path:         c:\program files\kmspico\autopico.exe
Publisher:      
MD5:             0f94b4386d8d5e2fd028954684a6464e
SHA-1:             121c2ec6220d6c60b562c424d42c1f382ff03622
Created:         5.1.2015 19:42:33
Detections:         15
Determination:         UndefinedMalware
            - Bkav FE as W32.Clod935.Trojan (Undefined)
            - McAfee as Artemis!0F94B4386D8D (Undefined)
            - K7 AntiVirus as Hacktool
            - K7 Gateway Antivirus as Hacktool
            - Agnitum Outpost as TrojanSpy.Agent (Undefined)
            - Norman as Agent.AOQWC (Undefined)
            - Trend Micro House Call as TROJ_GEN.R0CBB01LR13 (Undefined)
            - Comodo Security as UnclassifiedMalware (Undefined)
            - Avira AntiVirus as TR/Spy.A.1046 (Undefined)
            - McAfee Web Gateway as Artemis!0F94B4386D8D (Undefined)
            - ESET NOD32 as MSIL/HackTool.IdleKMS (Undefined)
            - IKARUS anti.virus as Virus.Dropper (Undefined)
            - AVG as Dropper.Msil (Undefined)
            - VIPRE Antivirus as Trojan.Win32.Generic (Undefined)
            - Reason Heuristics as Unnamed.Threat.15 (Undefined)

---------------------------------------------------------------------------------

File path:         c:\program files (x86)\crossbrowse\crossbrowse\application\utility.exe
Publisher:      
Signer:         City Center Games (Extreme White Limited)
MD5:             a08a85bb7ef1300806d1b11c9a4885a7
SHA-1:             b86063d1537d3bd8a3b724f48f7aa914524eaf37
Created:         19.4.2015 21:51:32
Detections:         18
Determination:         Adware
            - Reason Heuristics as Threat.Win.Reputation.IMP (Undefined)
            - Dr.Web as Trojan.Crossrider1.25895 (Adware)
            - VIPRE Antivirus as Threat.4789396 (Undefined)
            - avast! as Win32:PUP-gen [PUP] (Adware)
            - ESET NOD32 as Win32/Toolbar.CrossRider.CH potentially unwanted application (Adware)
            - McAfee as Trojan.Artemis!A08A85BB7EF1 (Undefined)
            - Agnitum Outpost as PUA.Toolbar.CrossRider (Adware)
            - Kaspersky as HEUR:Trojan-Downloader.Win32.Generic (Undefined)
            - NANO AntiVirus as Trojan.Win32.Crossrider1.dqjhpi (Adware)
            - Jiangmin as TrojanDownloader.Generic.auhy (Undefined)
            - Avira AntiVirus as ADWARE/CrossRider.1818320 (Adware)
            - Antiy Labs AVL as Trojan[Downloader:HEUR]/Win32.AGeneric (Undefined)
            - AhnLab V3 Security as PUP/Win32.CrossRider (Adware)
            - Vba32 AntiVirus as suspected of Trojan.Downloader.gen.h (Undefined)
            - Baidu Antivirus as Adware.Win32.CrossAd (Adware)
            - AVG as Win32/DH{gRITfWUDICIlV04A} (Undefined)
            - Panda Antivirus as Trj/Genetic.gen (Undefined)
            - Qihoo 360 Security as Win32/Virus.Adware.a2a (Adware)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\3591.exe
Publisher:      
Signer:         City Center Games (Extreme White Limited)
MD5:             a08a85bb7ef1300806d1b11c9a4885a7
SHA-1:             b86063d1537d3bd8a3b724f48f7aa914524eaf37
Created:         19.4.2015 21:44:40
Detections:         18
Determination:         Adware
            - Reason Heuristics as Threat.Win.Reputation.IMP (Undefined)
            - Dr.Web as Trojan.Crossrider1.25895 (Adware)
            - VIPRE Antivirus as Threat.4789396 (Undefined)
            - avast! as Win32:PUP-gen [PUP] (Adware)
            - ESET NOD32 as Win32/Toolbar.CrossRider.CH potentially unwanted application (Adware)
            - McAfee as Trojan.Artemis!A08A85BB7EF1 (Undefined)
            - Agnitum Outpost as PUA.Toolbar.CrossRider (Adware)
            - Kaspersky as HEUR:Trojan-Downloader.Win32.Generic (Undefined)
            - NANO AntiVirus as Trojan.Win32.Crossrider1.dqjhpi (Adware)
            - Jiangmin as TrojanDownloader.Generic.auhy (Undefined)
            - Avira AntiVirus as ADWARE/CrossRider.1818320 (Adware)
            - Antiy Labs AVL as Trojan[Downloader:HEUR]/Win32.AGeneric (Undefined)
            - AhnLab V3 Security as PUP/Win32.CrossRider (Adware)
            - Vba32 AntiVirus as suspected of Trojan.Downloader.gen.h (Undefined)
            - Baidu Antivirus as Adware.Win32.CrossAd (Adware)
            - AVG as Win32/DH{gRITfWUDICIlV04A} (Undefined)
            - Panda Antivirus as Trj/Genetic.gen (Undefined)
            - Qihoo 360 Security as Win32/Virus.Adware.a2a (Adware)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\9589.exe
Publisher:      
Signer:         City Center Games (Extreme White Limited)
MD5:             a08a85bb7ef1300806d1b11c9a4885a7
SHA-1:             b86063d1537d3bd8a3b724f48f7aa914524eaf37
Created:         20.4.2015 00:11:29
Detections:         18
Determination:         Adware
            - Reason Heuristics as Threat.Win.Reputation.IMP (Undefined)
            - Dr.Web as Trojan.Crossrider1.25895 (Adware)
            - VIPRE Antivirus as Threat.4789396 (Undefined)
            - avast! as Win32:PUP-gen [PUP] (Adware)
            - ESET NOD32 as Win32/Toolbar.CrossRider.CH potentially unwanted application (Adware)
            - McAfee as Trojan.Artemis!A08A85BB7EF1 (Undefined)
            - Agnitum Outpost as PUA.Toolbar.CrossRider (Adware)
            - Kaspersky as HEUR:Trojan-Downloader.Win32.Generic (Undefined)
            - NANO AntiVirus as Trojan.Win32.Crossrider1.dqjhpi (Adware)
            - Jiangmin as TrojanDownloader.Generic.auhy (Undefined)
            - Avira AntiVirus as ADWARE/CrossRider.1818320 (Adware)
            - Antiy Labs AVL as Trojan[Downloader:HEUR]/Win32.AGeneric (Undefined)
            - AhnLab V3 Security as PUP/Win32.CrossRider (Adware)
            - Vba32 AntiVirus as suspected of Trojan.Downloader.gen.h (Undefined)
            - Baidu Antivirus as Adware.Win32.CrossAd (Adware)
            - AVG as Win32/DH{gRITfWUDICIlV04A} (Undefined)
            - Panda Antivirus as Trj/Genetic.gen (Undefined)
            - Qihoo 360 Security as Win32/Virus.Adware.a2a (Adware)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\awh85f0.tmp
Publisher:      
MD5:             c51eb4736c80177de95e15847ac46fcf
SHA-1:             576e108b76250bfcc9c7afa99c3ab526cfff568b
Created:         19.4.2015 21:26:14
Detections:         4
Determination:         Ignore detections (false positive)
            - SUPERAntiSpyware as Trojan.Agent/Gen-Swisyn (Undefined)
            - Trend Micro House Call as Suspicious_GEN.F47V1215 (Undefined)
            - ByteHero BDV as Virus.Win32.Heur.l
            - Qihoo 360 Security as HEUR/QVM06.1.Malware.Gen (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\nsh170d.tmp
Publisher:      
MD5:             105a8ff197da1a2b3f7be995ce0832fb
SHA-1:             46c428275a546e5a7422439537983149d6cbcb6d
Created:         19.4.2015 21:41:03
Detections:         2
Determination:         Inconclusive
            - SUPERAntiSpyware as Trojan.Agent/Gen-FakeAlert (Undefined)
            - Kaspersky as UDS:DangerousObject.Multi.Generic (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\nsla21f.tmp
Publisher:         BaiSix
Signer:         Taiming Li
MD5:             9443ecb7709136ac88b93c5149bc90d1
SHA-1:             4f47bef5d7e5ae44e5d233ab35980beac93fa4c6
Created:         19.4.2015 21:46:01
Detections:         11
Determination:         Adware
            - Bkav FE as W32.HfsAdware (Adware)
            - Quick Heal as PUA.MSJDGBTIR.OD6 (Adware)
            - Malwarebytes as PUP.Optional.LuckySearches.A (Adware)
            - K7 AntiVirus as Unwanted-Program  (Adware)
            - K7 Gateway Antivirus as Unwanted-Program  (Adware)
            - NANO AntiVirus as Riskware.Win32.Mutabaha.dqesbj (Adware)
            - Antiy Labs AVL as RiskWare[Downloader:not-a-virus]/Win32.AdLoad (Adware)
            - G Data as Win32.Application.Limo (Undefined)
            - ESET NOD32 as Win32/LiMo.C potentially unwanted (variant) (Adware)
            - Baidu Antivirus as PUA.Win32.LiMo (Adware)
            - Reason Heuristics as Threat.Ma Lin.TaimingLi (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\nsn3dc7.tmp
Publisher:         HTabp.com
Signer:         Taiming Li
MD5:             f13cc1f4eb77099b77575918fe84e310
SHA-1:             2477ed7d0f9f03f68158e6305269bd07cbe4df94
Created:         20.4.2015 00:13:02
Detections:         10
Determination:         Adware
            - Reason Heuristics as PUP.Ma Lin (Adware)
            - ESET NOD32 as Win32/ELEX.CF potentially unwanted application (Adware)
            - Quick Heal as PUA.MSJDGBTIR.OD6 (Adware)
            - Malwarebytes as PUP.Optional.IStartSurf.A (Adware)
            - K7 Gateway Antivirus as Adware  (Adware)
            - K7 AntiVirus as Adware  (Adware)
            - Baidu Antivirus as Adware.Win32.ELEX (Adware)
            - Dr.Web as Adware.Mutabaha.220 (Adware)
            - Sophos as Elex (Undefined)
            - Fortinet FortiGate as Riskware/Elex (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\nsnea3e.tmp
Publisher:      
MD5:             17ccabc1c7cf31b41a09f78a05d7912c
SHA-1:             30bbc824521424780e864cb450c2f1f403813593
Created:         19.4.2015 21:32:07
Detections:         1
Determination:         Ignore detections (false positive)
            - McAfee Web Gateway as BehavesLike.Win32.BrowseFox.fc (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\nsqaf4a.tmp
Publisher:      
MD5:             105a8ff197da1a2b3f7be995ce0832fb
SHA-1:             46c428275a546e5a7422439537983149d6cbcb6d
Created:         19.4.2015 21:59:11
Detections:         2
Determination:         Inconclusive
            - SUPERAntiSpyware as Trojan.Agent/Gen-FakeAlert (Undefined)
            - Kaspersky as UDS:DangerousObject.Multi.Generic (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\ubi714.tmp.exe
Publisher:      
Signer:         UBISOFT ENTERTAINMENT INC.
MD5:             769f1ca01fac15df35154199e1571eac
SHA-1:             fe227aff65b0c03e6d0237d6b21ace04720ac5f3
Created:         19.4.2015 02:06:49
Detections:         3
Determination:         Ignore detections (false positive)
            - Antiy Labs AVL as Trojan/Win32.SGeneric (Undefined)
            - Vba32 AntiVirus as TrojanPSW.OnLineGames.xa (Undefined)
            - Rising Antivirus as PE:Malware.XPACK-LNR/Heur!1.5594 (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\is-0o72u.tmp\quickref_p_.exe
Publisher:      
MD5:             4695b80541663751db98a4ded480fd41
SHA-1:             2378434549792b0a8031f117a796c3a51027800b
Created:         20.4.2015 00:37:36
Detections:         1
Determination:         Inconclusive
            - ESET NOD32 as Detection.Undefined (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\is-4rhe1.tmp\itdownload.dll
Publisher:      
MD5:             d82a429efd885ca0f324dd92afb6b7b8
SHA-1:             86bbdaa15e6fc5c7779ac69c84e53c43c9eb20ea
Created:         19.4.2015 21:43:23
Detections:         2
Determination:         Inconclusive
            - The Hacker as Trojan/Downloader.Murlo.dyr (Undefined)
            - Reason Heuristics as Unnamed.Threat.12 (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\is-9tj2s.tmp\itdownload.dll
Publisher:      
MD5:             d82a429efd885ca0f324dd92afb6b7b8
SHA-1:             86bbdaa15e6fc5c7779ac69c84e53c43c9eb20ea
Created:         19.4.2015 21:34:09
Detections:         2
Determination:         Inconclusive
            - The Hacker as Trojan/Downloader.Murlo.dyr (Undefined)
            - Reason Heuristics as Unnamed.Threat.12 (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\is-afppu.tmp\gentlemjmp_ieu.exe
Publisher:                                                                  
Signer:         Tuto4PC.com
MD5:             bd71fc4e9af8b3244a67f66c4c345784
SHA-1:             661836d7bf656f596e3fcbbb29ba72bfac0ec313
Created:         19.4.2015 21:33:21
Detections:         22
Determination:         Adware
            - Bkav FE as W32.HfsAdware (Adware)
            - MicroWorld eScan as Adware.Eorezo.BZ (Adware)
            - nProtect as Adware.Eorezo.BZ (Adware)
            - Quick Heal as PUA.AdwareEorezo.DC8 (Adware)
            - K7 AntiVirus as Adware  (Adware)
            - K7 Gateway Antivirus as Adware  (Adware)
            - NANO AntiVirus as Riskware.Text.Text.dozbeo (Adware)
            - F-Prot as W32/Trojan2.OOJS (Undefined)
            - avast! as Win32:Adware-ASG [PUP] (Adware)
            - Kaspersky as not-a-virus:AdWare.Win32.Eorezo (Adware)
            - Bitdefender as Adware.Eorezo.BZ (Adware)
            - Agnitum Outpost as PUA.Eorezo (Adware)
            - Lavasoft Ad-Aware as Adware.Eorezo.BZ (Adware)
            - Emsisoft Anti-Malware as Adware.Eorezo.BZ (Adware)
            - F-Secure as Adware.Eorezo.BZ (Adware)
            - Dr.Web as Adware.Eorezo.414 (Adware)
            - VIPRE Antivirus as Tuto4PC (Undefined)
            - G Data as Adware.Eorezo.BZ (Adware)
            - AhnLab V3 Security as PUP/Win32.Eorezo (Adware)
            - Vba32 AntiVirus as AdWare.Eorezo (Adware)
            - AVG as Generic (Undefined)
            - Reason Heuristics as Threat.Eorezo.Bundler (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\is-hjh20.tmp\quickref_p_.exe
Publisher:      
MD5:             4695b80541663751db98a4ded480fd41
SHA-1:             2378434549792b0a8031f117a796c3a51027800b
Created:         19.4.2015 21:34:38
Detections:         1
Determination:         Inconclusive
            - ESET NOD32 as Detection.Undefined (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\is-o0mhj.tmp\itdownload.dll
Publisher:      
MD5:             d82a429efd885ca0f324dd92afb6b7b8
SHA-1:             86bbdaa15e6fc5c7779ac69c84e53c43c9eb20ea
Created:         20.4.2015 00:11:11
Detections:         2
Determination:         Inconclusive
            - The Hacker as Trojan/Downloader.Murlo.dyr (Undefined)
            - Reason Heuristics as Unnamed.Threat.12 (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\is-qethc.tmp\gentlemjmp_ieu.exe
Publisher:                                                                  
Signer:         Tuto4PC.com
MD5:             bd71fc4e9af8b3244a67f66c4c345784
SHA-1:             661836d7bf656f596e3fcbbb29ba72bfac0ec313
Created:         20.4.2015 00:33:18
Detections:         22
Determination:         Adware
            - Bkav FE as W32.HfsAdware (Adware)
            - MicroWorld eScan as Adware.Eorezo.BZ (Adware)
            - nProtect as Adware.Eorezo.BZ (Adware)
            - Quick Heal as PUA.AdwareEorezo.DC8 (Adware)
            - K7 AntiVirus as Adware  (Adware)
            - K7 Gateway Antivirus as Adware  (Adware)
            - NANO AntiVirus as Riskware.Text.Text.dozbeo (Adware)
            - F-Prot as W32/Trojan2.OOJS (Undefined)
            - avast! as Win32:Adware-ASG [PUP] (Adware)
            - Kaspersky as not-a-virus:AdWare.Win32.Eorezo (Adware)
            - Bitdefender as Adware.Eorezo.BZ (Adware)
            - Agnitum Outpost as PUA.Eorezo (Adware)
            - Lavasoft Ad-Aware as Adware.Eorezo.BZ (Adware)
            - Emsisoft Anti-Malware as Adware.Eorezo.BZ (Adware)
            - F-Secure as Adware.Eorezo.BZ (Adware)
            - Dr.Web as Adware.Eorezo.414 (Adware)
            - VIPRE Antivirus as Tuto4PC (Undefined)
            - G Data as Adware.Eorezo.BZ (Adware)
            - AhnLab V3 Security as PUP/Win32.Eorezo (Adware)
            - Vba32 AntiVirus as AdWare.Eorezo (Adware)
            - AVG as Generic (Undefined)
            - Reason Heuristics as Threat.Eorezo.Bundler (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\is-s73ga.tmp\itdownload.dll
Publisher:      
MD5:             d82a429efd885ca0f324dd92afb6b7b8
SHA-1:             86bbdaa15e6fc5c7779ac69c84e53c43c9eb20ea
Created:         19.4.2015 21:33:30
Detections:         2
Determination:         Inconclusive
            - The Hacker as Trojan/Downloader.Murlo.dyr (Undefined)
            - Reason Heuristics as Unnamed.Threat.12 (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\is-u2hda.tmp\itdownload.dll
Publisher:      
MD5:             d82a429efd885ca0f324dd92afb6b7b8
SHA-1:             86bbdaa15e6fc5c7779ac69c84e53c43c9eb20ea
Created:         19.4.2015 22:01:08
Detections:         2
Determination:         Inconclusive
            - The Hacker as Trojan/Downloader.Murlo.dyr (Undefined)
            - Reason Heuristics as Unnamed.Threat.12 (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\nsc5149.tmp\nsweb_dispoffr.dll
Publisher:      
MD5:             98bd2ebc8800a00bdf52b793c1210edd
SHA-1:             5cbe6cf1cde5c7a24c3349a77afb05257e7edccc
Created:         19.4.2015 21:50:06
Detections:         5
Determination:         Adware
            - K7 Gateway Antivirus as Trojan  (Undefined)
            - K7 AntiVirus as Trojan  (Undefined)
            - Avira AntiVirus as APPL/Downloader.Gen (Adware)
            - Baidu Antivirus as PUA.Win32.InstallMonetizer (Adware)
            - ESET NOD32 as Win32/InstallMonetizer.BC potentially unwanted (variant) (Adware)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\nsdd9ea.tmp\nsweb_dispoffr.dll
Publisher:      
MD5:             98bd2ebc8800a00bdf52b793c1210edd
SHA-1:             5cbe6cf1cde5c7a24c3349a77afb05257e7edccc
Created:         19.4.2015 21:34:18
Detections:         5
Determination:         Adware
            - K7 Gateway Antivirus as Trojan  (Undefined)
            - K7 AntiVirus as Trojan  (Undefined)
            - Avira AntiVirus as APPL/Downloader.Gen (Adware)
            - Baidu Antivirus as PUA.Win32.InstallMonetizer (Adware)
            - ESET NOD32 as Win32/InstallMonetizer.BC potentially unwanted (variant) (Adware)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\temp\nsgb471.tmp\nsweb_dispoffr.dll
Publisher:      
MD5:             98bd2ebc8800a00bdf52b793c1210edd
SHA-1:             5cbe6cf1cde5c7a24c3349a77afb05257e7edccc
Created:         20.4.2015 00:15:47
Detections:         5
Determination:         Adware
            - K7 Gateway Antivirus as Trojan  (Undefined)
            - K7 AntiVirus as Trojan  (Undefined)
            - Avira AntiVirus as APPL/Downloader.Gen (Adware)
            - Baidu Antivirus as PUA.Win32.InstallMonetizer (Adware)
            - ESET NOD32 as Win32/InstallMonetizer.BC potentially unwanted (variant) (Adware)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\downloads\herdprotectscan_setup.exe
Publisher:         Reason Company Software Inc.
Signer:         Reason Software Company Inc.
MD5:             172ed33198484df87fa015b695eaad80
SHA-1:             1df2124a741afc2ee0b2e90e904a3201e5cb3c3d
Created:         20.4.2015 01:58:36
Detections:         1
Determination:         Ignore detections (false positive)
            - Rising Antivirus as PE:Malware.ArcadeWeb!6.727 (Undefined)

---------------------------------------------------------------------------------

File path:         c:\windows\syswow64\ext-ms-win-cluster-clusapi-l1-1-1.dll
Publisher:         Microsoft Corporation
MD5:             6f5557e3f97cb2a957da5dcdaf1e22c1
SHA-1:             c2a27e776fbfc3666642425dcc5f2b34bb41cb10
Created:         22.8.2013 07:14:14
Detections:         1
Determination:         Ignore detections (false positive)
            - The Hacker as Backdoor/Bifrose.fxu (Undefined)

---------------------------------------------------------------------------------

File path:         c:\windows\syswow64\kbdcherp.dll
Publisher:         Microsoft Corporation
MD5:             f992fe1d923f59f806442449f3ea557b
SHA-1:             d216f5bc5d466c1c9d94aa57a28c5226b214bdbc
Created:         22.8.2013 07:15:06
Detections:         1
Determination:         Ignore detections (false positive)
            - The Hacker as Trojan/Kryptik.ahcy (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\nseeddc.tmp
Publisher:         CMI Limited
MD5:             bed1902af249bf3bc269420021a03d0b
SHA-1:             6fa07c781b84151c862a8facd4e2efb7d8da3e2f
Created:         20.4.2015 00:10:36
Detections:         1
Determination:         Adware
            - Reason Heuristics as PUP.Installer.ironSource (Adware)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\nst1c0b.tmp
Publisher:         CMI Limited
MD5:             bed1902af249bf3bc269420021a03d0b
SHA-1:             6fa07c781b84151c862a8facd4e2efb7d8da3e2f
Created:         19.4.2015 22:06:20
Detections:         1
Determination:         Adware
            - Reason Heuristics as PUP.Installer.ironSource (Adware)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\03000200-1429479130-0500-0006-000700080009\ansbff50.exe
Publisher:      
MD5:             7efc6124f1436e7f3552bb95447ffd6e
SHA-1:             796c9e27148a12183687ce33b25ec028f3baf4fc
Created:         19.4.2015 20:16:54
Detections:         2
Determination:         Adware
            - Reason Heuristics as Threat.Adware.ConvertAd (Adware)
            - Panda Antivirus as Trj/Genetic.gen (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\03000200-1429479147-0500-0006-000700080009\onsi42e2.tmp
Publisher:      
MD5:             9642450929b3de32607ac267388ed5fa
SHA-1:             14f77b9863afd2982a1db6760c0c1201321b2c2f
Created:         19.4.2015 21:32:31
Detections:         1
Determination:         Ignore detections (false positive)
            - Qihoo 360 Security as HEUR/QVM10.1.Malware.Gen (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\03000200-1429479147-0500-0006-000700080009\pnsi4331.exe
Publisher:      
MD5:             d061173776c84cb83d9be9b3b604e251
SHA-1:             0c0ed1521c125329a54ba2a3423e755b73acad9b
Created:         19.4.2015 10:13:18
Detections:         3
Determination:         Adware
            - Reason Heuristics as Threat.Adware.ConvertAd.Installer (Adware)
            - F-Secure as Gen:Variant.Graftor.181023 (Undefined)
            - SUPERAntiSpyware as Trojan.Agent/Gen-FakeAlert (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\03000200-1429479147-0500-0006-000700080009\rnsi42e1.exe
Publisher:      
MD5:             2e8a4d0584a1d3021b0541b250f5c66e
SHA-1:             3b56f5cc15559331f960fdcdf0357b285aeb4698
Created:         19.4.2015 21:32:30
Detections:         8
Determination:         Adware
            - Reason Heuristics as Threat.Adware.ConvertAd (Adware)
            - Emsisoft Anti-Malware as Gen:Variant.Mikey.11715 (Undefined)
            - F-Secure as Adware.Mplug.HU (Adware)
            - Lavasoft Ad-Aware as Gen:Variant.Mikey.11715 (Undefined)
            - MicroWorld eScan as Gen:Variant.Mikey.11715 (Undefined)
            - Kaspersky as UDS:DangerousObject.Multi.Generic (Undefined)
            - Bitdefender as Gen:Variant.Mikey.11715 (Undefined)
            - G Data as Gen:Variant.Mikey.11715 (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\03000200-1429488820-0500-0006-000700080009\jnsyd969.exe
Publisher:      
MD5:             cb06a89dafbefe7af0e5f675ad4a0a7f
SHA-1:             ff37cd6e9ce27f20221e50856ce268b0a29b75dd
Created:         19.4.2015 22:04:38
Detections:         2
Determination:         Adware
            - Reason Heuristics as Threat.Adware.ConvertAd (Adware)
            - ESET NOD32 as Win32/Adware.ConvertAd.HF application (Adware)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\mbot_tr_221\download\majmp_gentleeu.exe
Publisher:                                                                  
Signer:         Tuto4PC.com
MD5:             eb5079575f62d072860a3adcd8f865a4
SHA-1:             0483ffc3465d8ab86bd46d6850ef5e1282f3886a
Created:         19.4.2015 21:32:29
Detections:         22
Determination:         Adware
            - Bkav FE as W32.HfsAdware (Adware)
            - MicroWorld eScan as Adware.Eorezo.BZ (Adware)
            - nProtect as Adware.Eorezo.BZ (Adware)
            - Quick Heal as PUA.AdwareEorezo.DC8 (Adware)
            - VIPRE Antivirus as Tuto4PC (Undefined)
            - Bitdefender as Adware.Eorezo.BZ (Adware)
            - K7 Gateway Antivirus as Adware  (Adware)
            - K7 AntiVirus as Adware  (Adware)
            - NANO AntiVirus as Riskware.Text.Text.dozbeo (Adware)
            - F-Prot as W32/Trojan2.OOJS (Undefined)
            - avast! as Win32:Adware-ASG [PUP] (Adware)
            - Kaspersky as not-a-virus:AdWare.Win32.Eorezo (Adware)
            - Lavasoft Ad-Aware as Adware.Eorezo.BZ (Adware)
            - Emsisoft Anti-Malware as Adware.Eorezo.BZ (Adware)
            - F-Secure as Adware.Eorezo.BZ (Adware)
            - Dr.Web as Adware.Eorezo.414 (Adware)
            - Avira AntiVirus as PUA/InstallCore.Gen7 (Adware)
            - AhnLab V3 Security as PUP/Win32.Eorezo (Adware)
            - G Data as Adware.Eorezo.BZ (Adware)
            - Vba32 AntiVirus as AdWare.Eorezo (Adware)
            - AVG as Generic (Undefined)
            - Reason Heuristics as Threat.Eorezo.Bundler (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\mediaget2\mediaget-admin-proxy.exe
Publisher:      
Signer:         Media Get LLC
MD5:             424c83ae5385ad3b66d036f40d0df9f7
SHA-1:             500a13fc5cbc0124b9659506f972995876a06e78
Created:         17.1.2015 04:45:36
Detections:         1
Determination:         Inconclusive
            - Reason Heuristics as PUP.Optional.MediaGet.U (Adware)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\roaming\03000200-1429468100-0500-0006-000700080009\vnso7234.tmp
Publisher:       
MD5:             fa8987a025fdd47ab2f18e6bc068727b
SHA-1:             2f22a8695fe325192efc2ca2698e734fe9727af2
Created:         19.4.2015 21:28:20
Detections:         2
Determination:         Ignore detections (false positive)
            - McAfee Web Gateway as BehavesLike.Win32.AdwareSweet.fc (Adware)
            - Qihoo 360 Security as HEUR/QVM42.0.Malware.Gen (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\roaming\istartsurf\uninstallmanager.exe
Publisher:         Skytech Co., Ltd.
MD5:             a5bfd6a87161d5dfa81cb5c2c6d29488
SHA-1:             e463acfe9829a72ab2e222bafadb1c3f7bd6785b
Created:         20.4.2015 00:13:31
Detections:         2
Determination:         Adware
            - Sophos as Elex (Undefined)
            - Reason Heuristics as PUP.SkytechCo (Adware)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\roaming\luckysearches\uninstallmanager.exe
Publisher:         Skytech Co., Ltd.
MD5:             a5bfd6a87161d5dfa81cb5c2c6d29488
SHA-1:             e463acfe9829a72ab2e222bafadb1c3f7bd6785b
Created:         19.4.2015 21:46:32
Detections:         2
Determination:         Adware
            - Sophos as Elex (Undefined)
            - Reason Heuristics as PUP.SkytechCo (Adware)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\roaming\rheng\5cd44eab57ad403194b9be051677925a\syesubc3_p2v3.exe
Publisher:      
Signer:         Syndacato
MD5:             7d92f9cf0e121e7fb72da522f7fcd6cb
SHA-1:             466ca470652f231b3b4a3e226f6690db4faf9371
Created:         5.1.2015 19:37:59
Detections:         1
Determination:         Ignore detections (false positive)
            - SUPERAntiSpyware as Trojan.Agent/Gen-Downloader (Undefined)

---------------------------------------------------------------------------------

File path:         c:\program files\kmspico\uninshs.exe
Publisher:         Han-soft
MD5:             245824502aefe21b01e42f61955aa7f4
SHA-1:             a58682a8aae6302f1c934709c5aa1f6c86b2be99
Created:         5.1.2015 19:42:34
Detections:         1
Determination:         Ignore detections (false positive)
            - The Hacker as Posible_Worm32 (Undefined)

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\google\chrome\user data\default\extensions\eofcbnmajmjmplflapaojjnihcjkigck\10.2.0.190_0\common\scripts\bal.js
Publisher:      
MD5:             72d9a35388206ad8418a84fa758f1a65
SHA-1:             03400ae690cd24766115f1a0c1fa397c802d3197
Created:         14.3.2015 02:43:59
Detections:         1
Determination:         Inconclusive
            - Avira AntiVirus as TR/Crypt.XPACK.Gen

---------------------------------------------------------------------------------

File path:         c:\users\firad kılıçkap\appdata\local\google\chrome\user data\default\extensions\gomekmidlodglbbmalcneegieacbdmki\10.2.0.190_0\common\scripts\ava_connector.js
Publisher:      
MD5:             e6bc475c483cebde26bcddcfbd4f6a68
SHA-1:             0053d85da21859d980ea1fe70132fbb57a364aba
Created:         14.3.2015 02:44:02
Detections:         1
Determination:         Inconclusive
            - Avira AntiVirus as TR/Trash.Gen (Undefined)
 
Son düzenleme:
Herdprotect rehberine göre bunlar hariç hepsini silin;


Kod:
c:\windows\syswow64\ext-ms-win-cluster-clusapi-l1-1-1.dll
c:\windows\syswow64\kbdcherp.dll
____________
Malwarebyte ile de tarama yapıp bulunanları silin. Altta yazdığım klasör içlerini de yukarıda söylediklerimi yaptıktan sonra silin;

Kod:
c:\program files (x86)\xtab\
C:\Program Files (x86)\Infonaut_1.10.0.14
c:\program files\kmspico
C:\ProgramData\WindowsMangerProtect
c:\program files (x86)\mbot_tr_221
c:\program files (x86)\anyprotectex
c:\program files (x86)\crossbrowse
c:\users\firad kılıçkap\appdata\local\temp\
c:\users\firad kılıçkap\appdata\local\03000200-1429479147-0500-0006-000700080009
c:\users\firad kılıçkap\appdata\local\03000200-1429488820-0500-0006-000700080009\
c:\users\firad kılıçkap\appdata\local\03000200-1429479130-0500-0006-000700080009
c:\users\firad kılıçkap\appdata\local\03000200-1429478965-0500-0006-000700080009
c:\users\firad kılıçkap\appdata\local\mbot_tr_221\
c:\users\firad kılıçkap\appdata\local\mediaget2\
c:\users\firad kılıçkap\appdata\roaming\03000200-1429468100-0500-0006-000700080009
c:\users\firad kılıçkap\appdata\roaming\istartsurf\
c:\users\firad kılıçkap\appdata\roaming\luckysearches
c:\users\firad kılıçkap\appdata\roaming\rheng\
c:\users\firad kılıçkap\appdata\local\google\chrome\user data\default\extensions\eofcbnmajmjmplflapaojjnihcjkigck
c:\users\firad kılıçkap\appdata\local\google\chrome\user data\default\extensions\gomekmidlodglbbmalcneegieacbdmki

Denetim masasında bunlar varsa kaldırın;
Kod:
AnyProtect
Crossbrowse
Infonaut 1.10.0.14
istartsurf uninstall
luckysearches uninstall
MyBestOffersToday 010.221

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main
Startpage kısmından zararlı web adresini google olarak değiştir.
Bundan başka yapabileceğin birşey gerekmiyor. Sorun düzelmiş olması lazım düzeldi mi?
 
İnternetim olmadiğı için bakamiyorum en geç cuma akşamı dediklerinizi yapacağım.

Denetim masasında kaldırmam gereken dosyaları bulamadım. Explorer'a tıkladığımda hala aynı sayfaya giriyor (istartsurf.com). Ve sayfanızın forum sayfasını tıkladığımda HTTP 500 iç hatası veriyor.
 
Uyarı! Bu konu 9 yıl önce açıldı.
Muhtemelen daha fazla tartışma gerekli değildir ki bu durumda yeni bir konu başlatmayı öneririz. Eğer yine de cevabınızın gerekli olduğunu düşünüyorsanız buna rağmen cevap verebilirsiniz.

Geri
Yukarı