Arkadaşlar Bu Siteye Dikkat
-
Arkadaşlar sitenin ne olduğunu bilmiyorum biri bana mail atmış mailimden açtım bişeyler oldu ne olduğunu bilmiyorum ama bilgisi olanlar bakabilir mi virüs keylogger gibi bişi geldi ama ne bilmiyorum
-
"insanın başına ya meraktan ya da yapraktan birşeyler gelirmiş" tıklamayın :D
-
view-source:cattia.com/m28sx.html
yapınca
<head> <meta HTTP-EQUIV="REFRESH" content="0; url=http://gdfgdfgdgdfgdfg.in.ua/undo/red.php"> </head> oluyor
view-source:http://gdfgdfgdgdfgdfg.in.ua/undo/red.php
view-source:http://www.google.com.tr/
-
sahte antivirus tarayıcısı buraya yönlendiriyor:
h++p://46.252.129.81/index.php?eC8X2=S&26b=M0C0813P4N1R&8Aao=64&UIJ=afAVjGAVwemUIfWcsBU0A&l4Ai=HgrAChTfTd0BgMMWVMhBw&uB=RZC11UycAAFNQMQ0yAGAPAXRxeA94ZiRRQkU%3D&05=2W9M1LQF318&LPV=K9JSP4114LPkkxQRM4Ik9BV2dbJ0lVIwk6LztbUCgyOVkuVU&09=82C54DVSKG05QN&JE8=BB&M3hJ4=RNC2g&oW5=cmZzB9IVF#9
ordan buraya h++p://46.252.129.81/?q251=o17fce
pack.exe diye bir şey kurmanı istiyor,çalıstırıp kurmadıysan sorun yok
-
başlat> çalıştır > rstrui.exe
-
çalıştırıp kurmadıysan sorun yok da ne demek eskide kaldı o :) sistemine virüs bulaşmış antivürüs programları bulamayacaktır ama sen yinede avira antivir ile tarat.
virüsün nasıl bulaştığına gelince, büyük ihtimalle tarayıcı, adobe ve ya java ile bulaşmıştır yani eski sürüm kullandığından dolayı otomatik çalışmıştır exe.
-
benim sistemde soruyor,pack.exe calısmadan önce,ondan öyle dedim.Arkadasa bulasmıştır evet.
-
bulaştı yani virüs öyle mi
-
evet % 99. kullandığın sistem xp mi ? kullandığın antivirüs avira' dan başka birşey mi ? cevabın evetse bulaşmıştır
-
site link kaldırsan iyi olur başkaları tıklar onlarada bulaşabilir.
-
http://gdfgdfgdgdfgdfg.in.ua/undo/red.php
<!doctype html><html><head><meta http-equiv="content-type" content="text/html; charset=UTF-8"><title>Google</title> <script>window.google={kEI:"j945TaKANIGO_AabnNxi",kEXPI:"25657,28010,28186,28233",kCSI:{e:"25657,28010,28186,28233",ei:"j945TaKANIGO_AabnNxi",expi:"25657,28010,28186,28233"},ml:function(){},pageState:"#",kHL:"tr",time:function(){return(new Date).getTime()},log:function(c,d, b){var a=new Image,e=google,g=e.lc,f=e.li;a.onerror=(a.onload=(a.onabort=function(){delete g[f]}));g[f]=a;b=b||"/gen_204?atyp=i&ct="+c+"&cad="+d+"&zx="+google.time();a.src=b;e.li=f+1},lc:[],li:0,j:{en:1,l:function(){google.fl=true},e:function(){google.fl=true},b:location.hash&&location.hash!="#",bv:3,pl:[],mc:0,sc:0.5},Toolbelt:{}};(function(){var c=google.j;window.onpopstate=function(){c.psc=1};for(var d=0,b;b=["ad","bc","p","pa","ac","pc","pah","ph","sa","spf","xx","zc","zz"][d++];)(function(a){c[a]=function(){c.pl.push([a,arguments])}})(b)})(); window.google.sn="webhp";var i=window.google.timers={};window.google.startTick=function(a,b){i[a]={t:{start:(new Date).getTime()},bfr:!(!b)}};window.google.tick=function(a,b,c){if(!i[a])google.startTick(a);i[a].t[b]=c||(new Date).getTime()};google.startTick("load",true);try{window.google.pt=window.chrome&&window.chrome.csi&&Math.floor(window.chrome.csi().pageT);}catch(v){} window.google.jsrt_kill=1; </script> <style id=gstyle>body{margin:0}#gog{padding:3px 8px 0}td{line-height:.8em}.gac_m td{line-height:17px}form{margin-bottom:20px}body,td,a,p,.h{font-family:arial,sans-serif}.h{color:#36c;font-size:20px}.q{color:#00c}.ts td{padding:0}.ts{border-collapse:collapse}em{font-weight:bold;font-style:normal}.lst{height:25px;width:496px}.tiah{width:458px}.ds{border-bottom:solid 1px #e7e7e7;border-right:solid 1px #e7e7e7;display:-moz-inline-box;display:inline-block;margin:3px 0 4px;margin-left:4px}input{font-family:inherit}.lsb:active,.gac_sb:active{background:-webkit-gradient(linear,left top,left bottom,from(#ccc),to(#ddd))}a.gb1,a.gb2,a.gb3,a.gb4{color:#11c !important}#gog{background:#fff}#gbar,#guser{font-size:13px;padding-top:1px !important}#gbar{float:left;height:22px}#guser{padding-bottom:7px !important;text-align:right}.gbh,.gbd{border-top:1px solid #c9d7f1;font-size:1px}.gbh{height:0;position:absolute;top:24px;width:100%}#gbs,.gbm{background:#fff;left:0;position:absolute;text-align:left;visibility:hidden;z-index:1000}.gbm{border:1px solid;border-color:#c9d7f1 #36c #36c #a2bae7;z-index:1001}.gb1{margin-right:.5em}#gbar .gbsup{color:#c00;font-size:9px;font-weight:normal;line-height:9px;margin-left:-.5em;margin-right:.5em;*margin-left:-.5em;*margin-right:.5em}.gb1,.gb3{zoom:1}.gb2{display:block;padding:.2em .5em}.gb2,.gb3{text-decoration:none;border-bottom:none}a.gb1,a.gb2,a.gb3,a.gb4{color:#00c !important}a.gb2:hover{background:#36c;color:#fff !important}body{background:#fff;color:black}input{-moz-box-sizing:content-box}a{color:#11c;text-decoration:none}a:hover,a:active{text-decoration:underline}.fl a{color:#4272db}a:visited{color:#551a8b}a.gb1,a.gb4{text-decoration:underline}a.gb3:hover{text-decoration:none}#ghead a.gb2:hover{color:#fff!important}.sblc{padding-top:5px}.sblc a{display:block;margin:2px 0;margin-left:13px;font-size:11px;}.lsbb{background:#eee;border:solid 1px;border-color:#ccc #999 #999 #ccc;height:30px;display:block}.ftl,#fll a{display:inline-block;margin:0 12px}.lsb{background:url(/images/srpr/nav_logo27.png) bottom;border:none;color:#000;cursor:pointer;height:30px;margin:0;outline:0;font:15px arial,sans-serif;vertical-align:top}.lsb:active{background:#ccc}.lst:focus{outline:none}#addlang a{padding:0 3px}.gac_v div{display:none}.gac_v .gac_v2,.gac_bt{display:block!important}</style><script>var _gjwl=location;function _gjuc(){var b=_gjwl.href.indexOf("#");if(b>=0){var a=_gjwl.href.substring(b+1);if(/(^|&)q=/.test(a)&&a.indexOf("#")==-1&&!/(^|&)cad=h($|&)/.test(a)){_gjwl.replace("/search?"+a.replace(/(^|&)fp=[^&]*/g,"")+"&cad=h");return 1}}return 0}function _gjp(){!(window._gjwl.hash&&window._gjuc())&&setTimeout(_gjp,500)}; google.y={};google.x=function(e,g){google.y[e.id]=[e,g];return false};if(!window.google)window.google={};window.google.crm={};window.google.cri=0;window.clk=function(e,f,g,k,l,b,m){if(document.images){var a=encodeURIComponent||escape,c=new Image,h=window.google.cri++;window.google.crm[h]=c;c.onerror=(c.onload=(c.onabort=function(){delete window.google.crm[h]}));if(b&&b.substring(0,6)!="&sig2=")b="&sig2="+b;c.src=["/url?sa=T","","&cd=",a(l),google.j&&google.j.pf?"&sqi=2":"","&ved=",a(m),e?"&url="+ a(e.replace(/#.*/,"")).replace(/\+/g,"%2B"):"","&ei=","j945TaKANIGO_AabnNxi",b].join("")}return true}; window.gbar={qs:function(){},tg:function(e){var o={id:'gbar'};for(i in e)o[i]=e[i];google.x(o,function(){gbar.tg(o)})}};</script></head><body bgcolor=#ffffff text=#000000 link=#0000cc vlink=#551a8b alink=#ff0000 onload="try{!google.j.b&&document.f.q.focus()}catch(e){};if(document.images)new Image().src='/images/srpr/nav_logo27.png'" ><textarea id=csi style=display:none name=csi></textarea><script>if(google.j.b)document.body.style.visibility='hidden';</script><iframe name=wgjf style=display:none src="/blank.html" onload="google.j.l()" onerror="google.j.e()"></iframe><textarea id=wgjc style=display:none name=wgjc></textarea><textarea id=wwcache style=display:none name=wwcache></textarea><textarea id=csi style=display:none name=csi></textarea><textarea id=hcache style=display:none name=hcache></textarea><div id=main><div id=ghead><div id=gog><div id=gbar><nobr><b class=gb1>Web</b> <a href="http://www.google.com.tr/imghp?hl=tr&tab=wi" onclick=gbar.qs(this) class=gb1>Görseller</a> <a href="http://news.google.com.tr/nwshp?hl=tr&tab=wn" onclick=gbar.qs(this) class=gb1>Haberler</a> <a href="http://translate.google.com.tr/?hl=tr&tab=wT" onclick=gbar.qs(this) class=gb1>Çeviri</a> <a href="http://blogsearch.google.com.tr/?hl=tr&tab=wb" onclick=gbar.qs(this) class=gb1>Bloglar</a> <a href="http://www.google.com.tr/realtime?hl=tr&tab=wY" onclick=gbar.qs(this) class=gb1>Gerçek zamanlı</a> <a href="http://mail.google.com/mail/?hl=tr&tab=wm" class=gb1>Gmail</a> <a href="http://www.google.com.tr/intl/tr/options/" onclick="this.blur();gbar.tg(event);return !1" aria-haspopup=true class=gb3><u>Diğer</u> <small>▼</small></a><div class=gbm id=gbi><a href="http://www.google.com/calendar/render?hl=tr&tab=wc" class=gb2>Takvim</a> <a href="http://picasaweb.google.com.tr/home?hl=tr&tab=wq" onclick=gbar.qs(this) class=gb2>Fotoğraflar</a> <a href="http://docs.google.com/?hl=tr&tab=wo&authuser=0" class=gb2>Dokümanlar</a> <a href="http://www.google.com.tr/reader/?hl=tr&tab=wy" class=gb2>Reader</a> <a href="http://sites.google.com/?hl=tr&tab=w3" class=gb2>Sites</a> <a href="http://groups.google.com.tr/grphp?hl=tr&tab=wg" onclick=gbar.qs(this) class=gb2>Gruplar</a> <div class=gb2><div class=gbd></div></div><a href="http://www.google.com.tr/intl/tr/options/" class=gb2>daha fazlası »</a> </div></nobr></div><div id=guser width=100%><nobr><span id=gbn class=gbi></span><span id=gbf class=gbf></span><b class=gb4>angelsdemos@gmail.com</b> | <span id=gbe><a href="/url?sa=p&pref=ig&pval=3&q=http://www.google.com.tr/ig%3Fhl%3Dtr%26source%3Diglk&usg=AFQjCNGtb2M6j0lwBUY2Y_lwPqEGgzQdTw" class=gb4>iGoogle</a> | </span><a href="/preferences?hl=tr" onclick="this.blur();gbar.tg(event);return !1" aria-haspopup=true aria-owns=gbg class=gb3><u>Ayarlar</u> <small>▼</small></a> | <a id="gb_71" href="http://www.google.com.tr/accounts/ClearSID?continue=http%3A%2F%2Fwww.google.com%2Faccounts%2FLogout%3Fcontinue%3Dhttp%3A%2F%2Fwww.google.com.tr%2F" class=gb4>Oturumu kapat</a><div class=gbm id=gbg><a href="/preferences?hl=tr" class=gb2>Arama ayarları</a> <a href="https://www.google.com/accounts/ManageAccount?hl=tr" class=gb2>Google Hesabı ayarları</a> </div></nobr></div><div class=gbh style=left:0></div><div class=gbh style=right:0></div></div></div><center><span id=body><center><br clear=all id=lgpd><div id=lga><div style="padding:28px 0 3px"><div align=left style="background:url(/intl/en_com/images/srpr/logo1w.png) no-repeat;height:110px;width:276px" title="Google" id=logo onload="window.lol&&lol()"><div nowrap style="color:#777;font-size:16px;font-weight:bold;left:214px;position:relative;top:70px">Türkiye</div></div></div><br></div><form action="/search" name=f><table cellpadding=0 cellspacing=0><tr valign=top><td width=25%> </td><td align=center nowrap><input name=hl type=hidden value=tr><input name=source type=hidden value=hp><input type=hidden name=biw><input type=hidden name=bih><div class=ds style="height:32px;margin:4px 0"><div style="position:relative;zoom:1"><input autocomplete="off" maxlength=2048 name=q class="lst tiah" title="Google'da Ara" value="" size=57 style="background:#fff;border:1px solid #ccc;border-bottom-color:#999;border-right-color:#999;color:#000;font:18px arial,sans-serif bold;margin:0;padding:5px 8px 0 6px;padding-right:38px;vertical-align:top"><img src="/textinputassistant/tia.png" width=27 height=23 alt="" style="position:absolute;cursor:pointer;right:5px;top:4px;z-index:300" onclick="var s=document.createElement('script');s.src='/textinputassistant/0/tr_tia.js';google.append(s);"/></div></div><br style="line-height:0"><span class=ds ><span class=lsbb><input name=btnG type=submit value="Google'da Ara" class=lsb onclick="this.checked=1"></span></span><span class=ds><span class=lsbb><input name=btnI type=submit value="Kendimi Şanslı Hissediyorum" class=lsb onclick="this.checked=1"></span></span></td><td nowrap width=25% align=left class="fl sblc"><a href="/advanced_search?hl=tr">Gelişmiş arama</a><a href="/language_tools?hl=tr">Dil araçları</a></td></tr></table></form><div style="font-size:83%;min-height:3.5em"><br></div><div id=res></div></center></span> <span id=footer><center id=fctr><div style="font-size:10pt"><div id=fll style="margin:19px auto 19px auto;text-align:center"><a href="/intl/tr/ads/">Google'la Reklam Fırsatları</a><a href="/services/">İşletme Çözümleri</a><a href="/intl/tr/about.html">Google Hakkında</a><a href="http://www.google.com/ncr">Google.com in English</a></div></div><p style="color:#767676;font-size:8pt">© 2011 - <a href="/intl/tr/privacy.html">Gizlilik</a></p></center></span> </div> <script>function _gjp(){!(location.hash&&_gjuc())&&setTimeout(_gjp,500);}google.j[1]={cc:[],co:['ghead','body','footer','xjsi'],pc:[],css:document.getElementById('gstyle').innerHTML,main:'<div id=ghead></div>'+'<span id=body></span>'+'<span id=footer></span>'+'<span id=xjsi></span>'};</script><script>function wgjp(){var xjs=document.createElement('script');xjs.src='/extern_chrome/4caaad3836c1bb30.js';(document.getElementById('xjsd')||document.body).appendChild(xjs)};</script></center><div id=xjsd></div><div id=xjsi><script>if(google.y)google.y.first=[];google.dlj=function(b){window.setTimeout(function(){var a=document.createElement("script");a.src=b;document.getElementById("xjsd").appendChild(a)},0)}; if(google.y)google.y.first=[];if(!google.xjs){google.dstr=[];google.rein=[];if(google.timers&&google.timers.load.t){google.timers.load.t.xjsls=new Date().getTime();}google.dlj('/extern_js/f/CgJ0chICdHIrMEU4ACwrMFo4ACwrMA44ACwrMBc4ACwrMCc4ACwrMDw4ACwrMFE4ACwrMAo4AEAdLCswFjgALCswGTgALCswITgAQAEsKzAlOM-IASwrMCo4ACwrMCs4ACwrMDU4ACwrMEA4ACwrMEE4ACwrME04ACwrME44ACwrMFM4ACwrMFQ4ACwrMF84ACwrMGk4ACwrMB04ASwrMBg4ACwrMCY4ACyAAiiQAiw/J0WBBWoZ4Ts.js');google.xjs=1}google.neegg=1;google.mc = [];google.mc = google.mc.concat([[14,{}],[81,{}],[95,{"kfe":{"kfeHost":"clients1.google.com.tr","kfeUrlPrefix":"/webpagethumbnail?c=11\u0026r=2\u0026f=2\u0026s=300:585\u0026query=\u0026hl=tr\u0026gl=tr","maxPrefetchConnections":2,"prefetch":90,"slowConnection":false},"logging":{"csiFraction":0.05,"gen204Fraction":0.05},"msgs":{"noPreview":"Önizleme yok","sound":"Ses:","soundOff":"kapat","soundOn":"aç"},"pb":{"desiredHeight":585,"desiredWidth":300,"minHeight":200,"minWidth":300},"time":{"loading":100,"timeout":2500}}],[78,{}],[64,{}],[105,{}],[22,{"m_error":"\u003Cfont color=red\u003EHata:\u003C/font\u003E Sunucu isteğinizi tamamlayamadı. 30 saniye sonra tekrar deneyin.","m_tip":"Daha fazla bilgi tıklayın"}],[84,{}],[29,{}],[24,{}]]);google.y.first.push(function(){try{var form=document.f||document.f||document.gs;google.ac.i(form,form.q,'','','',{o:1,sw:1});(function(){ function e(){var a=null;if(window.ActiveXObject){a=new ActiveXObject("Msxml2.XMLHTTP");if(!a)a=new ActiveXObject("Microsoft.XMLHTTP")}else if(window.XMLHttpRequest)a=new XMLHttpRequest;return a}function f(a){if(window.execScript)window.execScript(a,"JavaScript");else if(window.eval){var b=null;window.eval("var _et_ = 1;");if(typeof window._et_!="undefined"){delete window._et_;b=true}else b=false;if(b)window.eval(a);else{var d=window.document,c=d.createElement("script");c.type="text/javascript";c.defer= false;c.appendChild(d.createTextNode(a));d.body.appendChild(c);d.body.removeChild(c)}}}function g(a){var b=a;if(b&&b.length>0){b=b.substring(27);if(b.substring(0,6)=="initcp")b="google.cp."+b}f(b)}function h(a){if(a.readyState==4&&(a.status==200||a.status==304))try{g(a.responseText)}catch(b){}}function i(){if(window.google&&(!window.google.cp||window.google.cp.initcp&&!window.google.cp.o)){window.google.cp=window.google.cp||{};window.google.cp.o={l:"/intl/en_com/images/srpr/logo1w.png", h:false,a:"Google",u:"",d:false};var a=e();if(a){a.open("GET","/ig/cp/get?hl=tr&gl=tr&bundleJs=1",true);a.onreadystatechange=function(){h(a)};a.send(null)}}}i(); })(); ;}catch(e){google.ml(e,false,{'cause':'defer'});}if(google.med) {google.med('init');google.initHistory();google.med('history');}google.History&&google.History.initialize('/')});if(google.j&&google.j.en&&google.j.xi){window.setTimeout(google.j.xi,0);}</script></div><script>(function(){ var b,d,e,f;function g(a,c){if(a.removeEventListener){a.removeEventListener("load",c,false);a.removeEventListener("error",c,false)}else{a.detachEvent("onload",c);a.detachEvent("onerror",c)}}function h(a){f=(new Date).getTime();++d;a=a||window.event;var c=a.target||a.srcElement;g(c,h)}var i=document.getElementsByTagName("img");b=i.length;d=0;for(var j=0,k;j<b;++j){k=i[j];if(k.complete||typeof k.src!="string"||!k.src)++d;else if(k.addEventListener){k.addEventListener("load",h,false);k.addEventListener("error", h,false)}else{k.attachEvent("onload",h);k.attachEvent("onerror",h)}}e=b-d;function l(){if(!google.timers.load.t)return;google.timers.load.t.ol=(new Date).getTime();google.timers.load.t.iml=f;google.kCSI.imc=d;google.kCSI.imn=b;google.kCSI.imp=e;google.timers.load.t.xjs&&google.report&&google.report(google.timers.load,google.kCSI)}if(window.addEventListener)window.addEventListener("load",l,false);else if(window.attachEvent)window.attachEvent("onload",l);google.timers.load.t.prt=(f=(new Date).getTime()); })(); </script>