
Zararlı İsmi : VirusTrigger
URL: 74.50.110.184 Systemtrigger. com
74.50.110.184 Virtrigger. com
74.50.110.184 Virtriggersupport. com
74.50.110.184 Virus-trigger. com
74.50.110.184 Virus-triggers. com
74.50.110.184 Virustrigger2009. com
Hijackthis raporunda görünen girdileri :
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://windiwsfsearch.com
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://windiwsfsearch.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://windiwsfsearch.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://windiwsfsearch.com/ie6.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://windiwsfsearch.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://windiwsfsearch.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://windiwsfsearch.com/ie6.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://windiwsfsearch.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://windiwsfsearch.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://windiwsfsearch.com
O2 - BHO: VirusTriggerBinWarningBHO Class - {096CBA44-4A4C-49f7-8903-1E75550ABCB7} - C:\Program Files\VirusTriggerBin\VirusTriggerBinWarning.dll
O2 - BHO: 512686 helper - {51B15F5A-E98B-4658-B9CB-9307B74773A7} - C:\WINDOWS\system32\512686\512686.dll
O2 - BHO: (no name) - {8710DF42-3171-4A3B-9079-3F7D7101552B} - C:\Program Files\Applications\iebt.dll
O3 - Toolbar: Internet Service - {E43B6656-814B-4839-8FF8-AFFDE0DA9A3F} - C:\Program Files\Applications\iebr.dll
O4 - HKCU\..\Run: [VirusTriggerBin] "C:\Program Files\VirusTriggerBin\VirusTriggerBin.exe"
O4 - HKCU\..\Run: [wblogon] C:\WINDOWS\system32\algg.exe
O4 - HKLM\..\Policies\Explorer\Run: [smile] C:\Program Files\Applications\wcs.exe
O4 - HKLM\..\Policies\Explorer\Run: [start] C:\Program Files\Applications\iebtm.exe
Temizlik :
http://www.malwarebytes.org/mbam/program/mbam-setup.exe
veyahttp://rapidshare.com/files/156856918/mbam-setup1.30.zipİlk olarak yukarıdan Malwarebytes'Anti Malware'i indirin.(2 mb)
Programı kurun.

Update bölümünden güncelleyin.
Perform full scan diyip bütün sürücüleri işaretleyip ; taramanın bitmesini bekliyorsunuz.
Tarama bittiğinde show results diyince bulduğu zararlıları görebilirsiniz.
Remove selected deyip ; biraz bekliyorsunuz.Bilgisayarınızı yeniden başlatın.
Restart sonunda Bulduğu nesneler karantinaya geldi..
Buradakileri de delete all diyerek uçurabilirsiniz.
Başlat > Programlar menüsünde kalan artıkları ( tıklanınca hatalı kısayol uyarısı veren kısayol ve klasörü el ile silin)
Malwarebytes' Anti-Malware ile temizleyebileceğiniz VirusTrigger girdileri Kayıt Defteri Girdileri:HKEY_CURRENT_USER\Software\VirusTriggerBin
HKEY_CLASSES_ROOT\CLSID\{096CBA44-4A4C-49f7-8903-1E75550ABCB7}
HKEY_CLASSES_ROOT\CLSID\{EE8A3F7B-E4AB-5C41-4926-3FAED82759F5}
HKEY_CLASSES_ROOT\Interface\{967A494A-6AEC-4555-9CAF-FA6EB00ACF91}
HKEY_CLASSES_ROOT\Interface\{9692BE2F-EB8F-49D9-A11C-C24C1EF734D5}
HKEY_CLASSES_ROOT\TypeLib\{A8954909-1F0F-41A5-A7FA-3B376D69E226}
HKEY_CLASSES_ROOT\VirusTriggerBinWarning.WarningBHO
HKEY_CLASSES_ROOT\VirusTriggerBinWarning.WarningBHO.1
HKEY_LOCAL_MACHINE\SOFTWARE\Licenses
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
App Paths\VirusTriggerBin
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
Browser Helper Objects\{096CBA44-4A4C-49f7-8903-1E75550ABCB7}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\
VirusTriggerBin
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "VirusTriggerBin"
Klasörler :
c:\Program Files\VirusTriggerBin c:\Documents and Settings\Kullanıcı Adı\Start Menu\Programs\VirusTrigger 2.1
Dosyalar :
c:\Program Files\VirusTriggerBin\uninst.exe
c:\Program Files\VirusTriggerBin\VirusTriggerBin.exe
c:\Program Files\VirusTriggerBin\VirusTriggerBinWarning.dll
c:\Documents and Settings\Kullanıcı Adı\Application Data\Microsoft\Internet Explorer\Quick Launch\VirusTrigger 2.1.lnk
c:\Documents and Settings\Kullanıcı Adı\Desktop\VirusTrigger 2.1.lnk
c:\Documents and Settings\Kullanıcı Adı\Start Menu\VirusTrigger 2.1.lnk
c:\Documents and Settings\Kullanıcı Adı\Start Menu\Programs\VirusTrigger 2.1\VirusTrigger 2.1.lnk