<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>cenkut.com &#187; koobface virüsü</title>
	<atom:link href="http://www.cenkut.com/yonlen.php/tag/koobface-virusu/feed/?404;http://www.cenkut.com:80/tag/koobface-virusu/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.cenkut.com</link>
	<description>virus - worm - trojan - spyware - mallware - antivirus LAB</description>
	<lastBuildDate>Thu, 20 May 2010 17:01:56 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.2</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>KoobFace Virüsü Temizlemek</title>
		<link>http://www.cenkut.com/koobface-virusu-temizlemek/</link>
		<comments>http://www.cenkut.com/koobface-virusu-temizlemek/#comments</comments>
		<pubDate>Sat, 15 Aug 2009 20:09:05 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Virüsler]]></category>
		<category><![CDATA[koobface]]></category>
		<category><![CDATA[koobface trojanı]]></category>
		<category><![CDATA[koobface virüsü]]></category>

		<guid isPermaLink="false">http://www.cenkut.com/?p=370</guid>
		<description><![CDATA[




Koobface virüsü adından anlaşılabileceği gibi Facebook benzer ismiyle sahtekarlığa yol açan bir virüstür.Sadece facebook amaçlı olmayıp bilgisayarınıza yüklediğinde trojan özelliğiyle kontrol sahibine vermektedir.Bu virüs shareware veya freeware yazılımlar veya P2P yazılımlarıyla veya sahte sayfalardan bulaşmaktadır.


Aşağıda Koobface virüsünün oluşturduğu dosyaları silin :
[%WINDOWS%]\t55ft3105f44.dat
[%WINDOWS%]\t55ft3165f44.dat
[%WINDOWS%]\freddy43.exe
[%WINDOWS%]\t55ft3192f44.dat
[%WINDOWS%]\mstre19.exe
[%WINDOWS%]\t55ft3601f44.dat
[%WINDOWS%]\010112010146118114.dat
[%WINDOWS%]\0101120101465452.dat
[%WINDOWS%]\0101120101465749.dat
[%WINDOWS%]\0101120101464849.dat
[%WINDOWS%]\0101120101465552.dat
[%WINDOWS%]\ld08.exe
[%WINDOWS%]\pp06.exe
[%WINDOWS%]\pp07.exe
[%WINDOWS%]\0101120101464849.fx
[%PROFILE_TEMP%]\vcru_1247795886.exe
[%PROFILE_TEMP%]\srazo_1250168927.exe
[%PROFILE_TEMP%]\srazo_1250187393.exe
[%WINDOWS%]\0101120101464949.fx
[%PROFILE_TEMP%]\srazo_1250198444.exe
[%PROFILE_TEMP%]\srazo_1250190616.exe
[%PROFILE_TEMP%]\srazo_1250197084.exe
[%PROFILE_TEMP%]\srazo_1250090197.exe
[%PROFILE_TEMP%]\srazo_1250102323.exe
[%WINDOWS%]\st_1242070417.exe
[%WINDOWS%]\st_1242076717.exe
[%WINDOWS%]\st_1242088847.exe
[%WINDOWS%]\nl.exe
[%WINDOWS%]\dk39fi4fe.dat
[%WINDOWS%]\zaponce52597.dat
[%WINDOWS%]\zaponce52689.dat
[%WINDOWS%]\ld09.exe
[%WINDOWS%]\0101120101465752.dat
[%WINDOWS%]\0101120101464850.fx
[%WINDOWS%]\0101120101465553.fx
[%PROFILE_TEMP%]\srazo_1250135222.exe
[%WINDOWS%]\freddy56.exe
[%WINDOWS%]\freddy55.exe
[%WINDOWS%]\0101120101465353.dat
[%WINDOWS%]\freddy53.exe
[%WINDOWS%]\0101120101465453.dat
[%WINDOWS%]\0101120101465153.dat
[%WINDOWS%]\t55ft2772f44.dat
[%WINDOWS%]\t55ft2829f44.dat
[%WINDOWS%]\t55ft2692f44.dat
[%WINDOWS%]\t55ft3223f44.dat
[%WINDOWS%]\t55ft2784f44.dat
[%WINDOWS%]\t55ft2792f44.dat
[%WINDOWS%]\t55ft2803f44.dat
[%WINDOWS%]\t55ft3242f44.dat
[%WINDOWS%]\t55ft3546f44.dat
[%WINDOWS%]\freddy39.exe
[%WINDOWS%]\freddy40.exe
[%WINDOWS%]\t55ft3189f44.dat
[%WINDOWS%]\freddy46.exe
[%WINDOWS%]\zaponce53198.dat
[%WINDOWS%]\zaponce53290.dat
[%WINDOWS%]\zaponce53222.dat
[%WINDOWS%]\sonce123198.dat
[%WINDOWS%]\ro122366.dat
[%WINDOWS%]\ro122390.dat
[%SYSTEM%]\mon32.dll
[%WINDOWS%]\ro122715.dat
[%WINDOWS%]\ro122739.dat
[%WINDOWS%]\sonce123173.dat
[%WINDOWS%]\freddy48.exe
[%WINDOWS%]\freddy49.exe
[%WINDOWS%]\ld02.exe
[%WINDOWS%]\pp04.exe
[%WINDOWS%]\freddy50.exe
[%WINDOWS%]\010112010146120114.dat
[%WINDOWS%]\freddy57.exe
[%WINDOWS%]\ld06.exe
[%WINDOWS%]\pp05.exe
[%WINDOWS%]\st_1241664655.exe
[%WINDOWS%]\st_1242148703.exe
[%WINDOWS%]\t55ft2667f44.dat
[%WINDOWS%]\t55ft3097f44.dat
[%WINDOWS%]\Pp.exe
[%WINDOWS%]\zaponce53173.dat
[%WINDOWS%]\sonce122714.dat
[%WINDOWS%]\sonce122739.dat
[%WINDOWS%]\010112010146118114.lso
[%WINDOWS%]\0101120101465452.lso
[%WINDOWS%]\sonce122715.dat

Koobface virüsünün kayıt defterinde oluşturduğu kayıtları silmek :
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy58.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pp=[%WINDOWS%]\pp11.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre21.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pp=[%WINDOWS%]\pp10.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy57.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre19.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre20.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, [...]]]></description>
			<content:encoded><![CDATA[<!-- Easy AdSense V2.41 -->
<!-- Post[count: 2] -->
<div class="ezAdsense adsense adsense-leadin" style="float:right;margin:12px; "><script type="text/javascript"><!--
google_ad_client = "pub-1213643583738263";
/* Plugin: ezAds 234x60, created 6/21/09 */
google_ad_slot = "5695603233";
google_ad_width = 234;
google_ad_height = 60;
//-->
</script>
<script type="text/javascript"
src="http://pagead2.googlesyndication.com/pagead/show_ads.js">
</script></div><p>Koobface virüsü adından anlaşılabileceği gibi Facebook benzer ismiyle sahtekarlığa yol açan bir virüstür.Sadece facebook amaçlı olmayıp bilgisayarınıza yüklediğinde trojan özelliğiyle kontrol sahibine vermektedir.Bu virüs shareware veya freeware yazılımlar veya P2P yazılımlarıyla veya sahte sayfalardan bulaşmaktadır.</p>
<p><span id="more-370"></span></p>
<p><img class="alignnone" src="http://www.cenkut.com/dosyalar.jpg" alt="" width="400" height="100" /></p>
<p>Aşağıda Koobface virüsünün oluşturduğu dosyaları silin :</p>
<p>[%WINDOWS%]\t55ft3105f44.dat<br />
[%WINDOWS%]\t55ft3165f44.dat<br />
[%WINDOWS%]\freddy43.exe<br />
[%WINDOWS%]\t55ft3192f44.dat<br />
[%WINDOWS%]\mstre19.exe<br />
[%WINDOWS%]\t55ft3601f44.dat<br />
[%WINDOWS%]\010112010146118114.dat<br />
[%WINDOWS%]\0101120101465452.dat<br />
[%WINDOWS%]\0101120101465749.dat<br />
[%WINDOWS%]\0101120101464849.dat<br />
[%WINDOWS%]\0101120101465552.dat<br />
[%WINDOWS%]\ld08.exe<br />
[%WINDOWS%]\pp06.exe<br />
[%WINDOWS%]\pp07.exe<br />
[%WINDOWS%]\0101120101464849.fx<br />
[%PROFILE_TEMP%]\vcru_1247795886.exe<br />
[%PROFILE_TEMP%]\srazo_1250168927.exe<br />
[%PROFILE_TEMP%]\srazo_1250187393.exe<br />
[%WINDOWS%]\0101120101464949.fx<br />
[%PROFILE_TEMP%]\srazo_1250198444.exe<br />
[%PROFILE_TEMP%]\srazo_1250190616.exe<br />
[%PROFILE_TEMP%]\srazo_1250197084.exe<br />
[%PROFILE_TEMP%]\srazo_1250090197.exe<br />
[%PROFILE_TEMP%]\srazo_1250102323.exe<br />
[%WINDOWS%]\st_1242070417.exe<br />
[%WINDOWS%]\st_1242076717.exe<br />
[%WINDOWS%]\st_1242088847.exe<br />
[%WINDOWS%]\nl.exe<br />
[%WINDOWS%]\dk39fi4fe.dat<br />
[%WINDOWS%]\zaponce52597.dat<br />
[%WINDOWS%]\zaponce52689.dat<br />
[%WINDOWS%]\ld09.exe<br />
[%WINDOWS%]\0101120101465752.dat<br />
[%WINDOWS%]\0101120101464850.fx<br />
[%WINDOWS%]\0101120101465553.fx<br />
[%PROFILE_TEMP%]\srazo_1250135222.exe<br />
[%WINDOWS%]\freddy56.exe<br />
[%WINDOWS%]\freddy55.exe<br />
[%WINDOWS%]\0101120101465353.dat<br />
[%WINDOWS%]\freddy53.exe<br />
[%WINDOWS%]\0101120101465453.dat<br />
[%WINDOWS%]\0101120101465153.dat<br />
[%WINDOWS%]\t55ft2772f44.dat<br />
[%WINDOWS%]\t55ft2829f44.dat<br />
[%WINDOWS%]\t55ft2692f44.dat<br />
[%WINDOWS%]\t55ft3223f44.dat<br />
[%WINDOWS%]\t55ft2784f44.dat<br />
[%WINDOWS%]\t55ft2792f44.dat<br />
[%WINDOWS%]\t55ft2803f44.dat<br />
[%WINDOWS%]\t55ft3242f44.dat<br />
[%WINDOWS%]\t55ft3546f44.dat<br />
[%WINDOWS%]\freddy39.exe<br />
[%WINDOWS%]\freddy40.exe<br />
[%WINDOWS%]\t55ft3189f44.dat<br />
[%WINDOWS%]\freddy46.exe<br />
[%WINDOWS%]\zaponce53198.dat<br />
[%WINDOWS%]\zaponce53290.dat<br />
[%WINDOWS%]\zaponce53222.dat<br />
[%WINDOWS%]\sonce123198.dat<br />
[%WINDOWS%]\ro122366.dat<br />
[%WINDOWS%]\ro122390.dat<br />
[%SYSTEM%]\mon32.dll<br />
[%WINDOWS%]\ro122715.dat<br />
[%WINDOWS%]\ro122739.dat<br />
[%WINDOWS%]\sonce123173.dat<br />
[%WINDOWS%]\freddy48.exe<br />
[%WINDOWS%]\freddy49.exe<br />
[%WINDOWS%]\ld02.exe<br />
[%WINDOWS%]\pp04.exe<br />
[%WINDOWS%]\freddy50.exe<br />
[%WINDOWS%]\010112010146120114.dat<br />
[%WINDOWS%]\freddy57.exe<br />
[%WINDOWS%]\ld06.exe<br />
[%WINDOWS%]\pp05.exe<br />
[%WINDOWS%]\st_1241664655.exe<br />
[%WINDOWS%]\st_1242148703.exe<br />
[%WINDOWS%]\t55ft2667f44.dat<br />
[%WINDOWS%]\t55ft3097f44.dat<br />
[%WINDOWS%]\Pp.exe<br />
[%WINDOWS%]\zaponce53173.dat<br />
[%WINDOWS%]\sonce122714.dat<br />
[%WINDOWS%]\sonce122739.dat<br />
[%WINDOWS%]\010112010146118114.lso<br />
[%WINDOWS%]\0101120101465452.lso<br />
[%WINDOWS%]\sonce122715.dat</p>
<p><img src="http://www.cenkut.com/kayit.jpg" alt="" width="400" height="100" /></p>
<p>Koobface virüsünün kayıt defterinde oluşturduğu kayıtları silmek :</p>
<p>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy58.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pp=[%WINDOWS%]\pp11.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre21.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pp=[%WINDOWS%]\pp10.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy57.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre19.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre20.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pp=[%WINDOWS%]\pp06.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy55.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysberay2=[%WINDOWS%]\romeo15.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy54.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy53.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy42.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre18.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy50.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy46.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy49.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysmstray=[%WINDOWS%]\mstre15.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy48.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, systgray2=[%WINDOWS%]\tag07.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysberay2=[%WINDOWS%]\romeo14.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy47.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy45.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysberay2=[%WINDOWS%]\romeo12.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, systgray2=C:\windows\tag12.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, pp=[%WINDOWS%]\pp04.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, systgray2=[%WINDOWS%]\tag12.exe<br />
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, sysfbtray=[%WINDOWS%]\freddy44.exe</p>
]]></content:encoded>
			<wfw:commentRss>http://www.cenkut.com/koobface-virusu-temizlemek/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
{\rtf1} 