diabolerik

Rimuovere Run.exe Virus Scaricato Da Emule

46 messaggi in questa discussione

salve a tutti...

la mia ragazza ha scaricato da emule un programma dal nome run.exe :) ...chiaramente una volta aperto è andato in tilt il computer...la connessione internet non va...tutti gli antivirus (compreso hijackthis) non si aprono più e la cpu è impegnata al 70-80% di media da vari processi...

potreste consigliarmi qualcosa da fare...sapete se esiste un tool di rimozione di questo virus...insomma qualcosa per eliminarlo senza connettersi ad internet...grazie

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

ciao

scaricalo da un altro computer e vedi se riesci a fare un fix con Combofix

:)

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

purtroppo da problemi anche con combofix...la connessione internet funziona...non è che posso fare una scansione on line?se si su che sito mi consigliate di andare? :omaggi:

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

ciao

Scarica the Avenger(diabolerik)

http://www.freefilehosting.net/download/3elif

lo salvi in una cartella, scompatti il file .zip.

individua "avenger.exe", lo avvii.

inserisci questo script nel box bianco

Registry values to replace with dummy:

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs

Files to delete:

C:\WINDOWS\system32\drivers\hidr.exe

C:\WINDOWS\system32\drivers\srosa.sys

C:\WINDOWS\system32\wintems.exe

C:\WINDOWS\system32\hldrrr.exe

C:\WINDOWS\system32\trusted.exe

C:\WINDOWS\system32\drivers\pci32.sys

C:\WINDOWS\system32\drivers\hldrrr.exe

C:\WINDOWS\system32\mdelk.exe

folders to delete:

C:\WINDOWS\exefqd

C:\WINDOWS\exefnd

C:\WINDOWS\exefld

C:\WINDOWS\system32\drivers\down

C:\WINDOWS\temp

C:\WINDOWS\Tasks

registry keys to delete:

HKEY_LOCAL_MACHINE\system\ControlSet003\Services\srosa

HKLM\SYSTEM\CurrentControlSet\Services\srosa

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA

HKLM\SYSTEM\CurrentControlSet\Services\pci32

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32

Clicca su Execute

Il pc dovrebbe riavviarsi ( se così non fosse, fallo tu)

Posta il log che verrà creato in C:\Avenger

3) Esegui anche una scansione online (usando IE)con Nod32 (elimina ciò che trova)

http://www.eset.com/onlinescan/

spunta le caselle:

-Remove found threats

-Scan unwanted applications

Spunta la casella e clicca su start

(IMG:http://img406.imageshack.us/img406/2...4855uz6.th.png)

Installa il controllo ActiveX

(IMG:http://img233.imageshack.us/img233/8...5016lk2.th.png)

Installa il software

(IMG:http://img106.imageshack.us/img106/2...0443ak1.th.png)

clicca su start e attendi il completamento delle firme antivirali

(IMG:http://img405.imageshack.us/img405/5...0836qc7.th.png)

spunta le due caselle e clicca su scan

(IMG:http://img236.imageshack.us/img236/3...1653pm6.th.png)

:)

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

Platform: Windows Vista

*******************

Script file opened successfully.

Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "srosa" found!

DisplayName: Megadrv3

ImagePath: \??\C:\Windows\system32\drivers\srosa.sys

Start Type: 1 (System)

Rootkit scan completed.

Error: file "C:\WINDOWS\system32\drivers\hidr.exe" not found!

Deletion of file "C:\WINDOWS\system32\drivers\hidr.exe" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

File "C:\WINDOWS\system32\drivers\srosa.sys" deleted successfully.

Error: file "C:\WINDOWS\system32\wintems.exe" not found!

Deletion of file "C:\WINDOWS\system32\wintems.exe" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "C:\WINDOWS\system32\hldrrr.exe" not found!

Deletion of file "C:\WINDOWS\system32\hldrrr.exe" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "C:\WINDOWS\system32\trusted.exe" not found!

Deletion of file "C:\WINDOWS\system32\trusted.exe" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: file "C:\WINDOWS\system32\drivers\pci32.sys" not found!

Deletion of file "C:\WINDOWS\system32\drivers\pci32.sys" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

File "C:\WINDOWS\system32\drivers\hldrrr.exe" deleted successfully.

Error: file "C:\WINDOWS\system32\mdelk.exe" not found!

Deletion of file "C:\WINDOWS\system32\mdelk.exe" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: folder "C:\WINDOWS\exefqd" not found!

Deletion of folder "C:\WINDOWS\exefqd" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: folder "C:\WINDOWS\exefnd" not found!

Deletion of folder "C:\WINDOWS\exefnd" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: folder "C:\WINDOWS\exefld" not found!

Deletion of folder "C:\WINDOWS\exefld" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: folder "C:\WINDOWS\system32\drivers\down" not found!

Deletion of folder "C:\WINDOWS\system32\drivers\down" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Folder "C:\WINDOWS\temp" deleted successfully.

Folder "C:\WINDOWS\Tasks" deleted successfully.

Error: registry key "HKEY_LOCAL_MACHINE\system\ControlSet003\Services\srosa" not found!

Deletion of registry key "HKEY_LOCAL_MACHINE\system\ControlSet003\Services\srosa" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Registry key "HKLM\SYSTEM\CurrentControlSet\Services\srosa" deleted successfully.

Registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA" deleted successfully.

Error: registry key "HKLM\SYSTEM\CurrentControlSet\Services\pci32" not found!

Deletion of registry key "HKLM\SYSTEM\CurrentControlSet\Services\pci32" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Error: registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32" not found!

Deletion of registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32" failed!

Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)

--> the object does not exist

Registry value "HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs" replaced with dummy successfully.

Completed script processing.

*******************

Finished! Terminate.

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

Ciao, scarica anche

ATF Cleaner (pulizia dei file temporanei)

http://www.atribune.org/ccount/click.php?id=1

Avvia ATF Cleaner, seleziona "Select all" e poi premi "Empty selected". ttendi il messaggio Done cleaning! Ripeti la stessa operazione per le schede Firefox ed Opera (se li hai).

Inoltre, per piacere, puoi ripetere l'operazione con avenger, inserendo questo script?

files to delete:

C:\WINDOWS\system32\drivers\mdelk.exe

folders to delete:

C:\WINDOWS\system32\drivers\downld

Allega poi il report

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

Platform: Windows Vista

*******************

Script file opened successfully.

Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "srosa" found!

DisplayName: Megadrv3

ImagePath: \??\C:\Windows\system32\drivers\srosa.sys

Start Type: 1 (System)

Rootkit scan completed.

File "C:\WINDOWS\system32\drivers\mdelk.exe" deleted successfully.

Folder "C:\WINDOWS\system32\drivers\downld" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

atf cleaner si chiude da solo dopo pochi secondi :locked:

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

sto provvedendo... :)

in tutto ciò sto in linea senza alcuna protezione :ranting2:

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

la scansione ho notato si sta dilungando parecchio su un file:

C:\program Files\microsoft works\WKSv7sbd.sbs

:)

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

lo scan è concluso...ha trovato un file...che faccio?

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

Prima dello scan hai spuntato le due caselle ? se si, il file lo ha eliminato

(IMG:http://img236.imageshack.us/img236/3...1653pm6.th.png)

Disabilita il Ripristino di configurazione su tutte le unità;

(nota che questo ELIMINERà TUTTI i punti di ripristino, ed eventuali virus in esso contenuti..)

Quindi riabilitalo almeno sull'unità dove hai installato il sistema operativo (solitamente il disco C:\) e crea un nuovo punto di ripristino pulito

Ora prova a scaricare il tuo Antivirus e a reinstallarlo

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

grazie sapreste indicarmi come fare tutto il ripristino di configurazione con vista?

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

esiste un modo per disabilitare il ripristino??? è tutto complicato con sto vista!!! :ranting2:

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

seguo tutte le istruzioni fino al punto "annulla il ripristino..." ma in realtà questa opzione non c'è...

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

CI sono riuscito ma non me la fa eseguire...dice "errore non specificato del ripristino..." e siamo punto e a capo...il virus sta sempre li...mannagg :)

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

KASPERSKY ONLINE SCANNER REPORT Monday, April 07, 2008 11:31:06 PM

Operating System: Microsoft Windows Vista Home Edition, (Build 6000)

Kaspersky Online Scanner version: 5.0.98.0

Kaspersky Anti-Virus database last update: 7/04/2008

Kaspersky Anti-Virus database records: 688619

Scan Settings Scan using the following antivirus database extended Scan Archives true Scan Mail Bases true

Scan Target My Computer C:\

D:\

F:\

Scan Statistics Total number of scanned objects 83005 Number of viruses found 3 Number of infected objects 8 Number of suspicious objects 0 Duration of the scan process 05:16:20

Infected Object Name Virus Name Last Action C:\Acer\Empowering Technology\Logs\ETF.log Object is locked skipped

C:\Boot\BCD Object is locked skipped

C:\Boot\BCD.LOG Object is locked skipped

C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\ae82cc9d2311d41fffe8baf014058d61_14bf1acf-9b10-44b4-b88b-9f4bf91b928a Object is locked skipped

C:\ProgramData\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\ProgramData\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.151.Crwl Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\GatherLogs\SystemIndex\SystemIndex.151.gthr Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.log Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSStmp.log Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010001.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010002.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010003.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010004.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010005.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010006.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010007.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010008.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010009.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000A.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000B.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000C.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001000F.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010010.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010013.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010014.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010015.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010017.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010026.ci Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010026.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\00010026.wsb Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\0001002F.wid Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\Indexer\CiFiles\INDEX.000 Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\CiPT0000.000 Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\PropMap\Used0000.000 Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SecStore\CiST0000.000 Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk1.gthr Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.chk2.gthr Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Projects\SystemIndex\SystemIndex.Ntfy336.gthr Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\tmp.edb Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Applications\Windows\Windows.edb Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf3590.tmp Object is locked skipped

C:\ProgramData\Microsoft\Search\Data\Temp\usgthrsvc\Ntf3591.tmp Object is locked skipped

C:\ProgramData\Microsoft\Windows\DRM\drmstore.hds Object is locked skipped

C:\ProgramData\Spyware Terminator\setup.dat Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\SystemRestore\FRStaging\Windows\bthservsdp.dat Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Feeds Cache\index.dat Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Media Player\CurrentDatabase_360.wmdb Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\Explorer\thumbcache_1024.db Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\Explorer\thumbcache_256.db Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\Explorer\thumbcache_32.db Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\Explorer\thumbcache_96.db Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\Explorer\thumbcache_idx.db Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\Explorer\thumbcache_sr.db Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008040720080408\index.dat Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ADSPIU06\b64_3[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ADSPIU06\b64_3[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CRHHSOD1\b64_1[1].jpg Infected: Trojan-Downloader.Win32.Bagle.ij skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CRHHSOD1\b64_3[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VE54TKDJ\b64_3[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1 Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2 Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\UsrClass.dat{575be989-8bbe-11dc-94de-001b24558dc0}.TM.blf Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\UsrClass.dat{575be989-8bbe-11dc-94de-001b24558dc0}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows\UsrClass.dat{575be989-8bbe-11dc-94de-001b24558dc0}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped

C:\Users\VALE\AppData\Local\Microsoft\Windows Sidebar\Settings.ini Object is locked skipped

C:\Users\VALE\AppData\Local\Mozilla\Firefox\Profiles\vntmr4i9.default\Cache\_CACHE_001_ Object is locked skipped

C:\Users\VALE\AppData\Local\Mozilla\Firefox\Profiles\vntmr4i9.default\Cache\_CACHE_002_ Object is locked skipped

C:\Users\VALE\AppData\Local\Mozilla\Firefox\Profiles\vntmr4i9.default\Cache\_CACHE_003_ Object is locked skipped

C:\Users\VALE\AppData\Local\Mozilla\Firefox\Profiles\vntmr4i9.default\Cache\_CACHE_MAP_ Object is locked skipped

C:\Users\VALE\AppData\Local\Temp\SmitfraudFix.zip/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\Users\VALE\AppData\Local\Temp\SmitfraudFix.zip ZIP: infected - 1 skipped

C:\Users\VALE\AppData\Roaming\Application Data\Spyware Terminator\setup.dat Object is locked skipped

C:\Users\VALE\AppData\Roaming\Microsoft\Windows\Cookies\index.dat Object is locked skipped

C:\Users\VALE\AppData\Roaming\Mozilla\Firefox\Profiles\vntmr4i9.default\cert8.db Object is locked skipped

C:\Users\VALE\AppData\Roaming\Mozilla\Firefox\Profiles\vntmr4i9.default\history.dat Object is locked skipped

C:\Users\VALE\AppData\Roaming\Mozilla\Firefox\Profiles\vntmr4i9.default\key3.db Object is locked skipped

C:\Users\VALE\AppData\Roaming\Mozilla\Firefox\Profiles\vntmr4i9.default\parent.lock Object is locked skipped

C:\Users\VALE\AppData\Roaming\Mozilla\Firefox\Profiles\vntmr4i9.default\search.sqlite Object is locked skipped

C:\Users\VALE\AppData\Roaming\Mozilla\Firefox\Profiles\vntmr4i9.default\urlclassifier2.sqlite Object is locked skipped

C:\Users\VALE\Desktop\SmitfraudFix\Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped

C:\Users\VALE\NTUSER.DAT Object is locked skipped

C:\Users\VALE\ntuser.dat.LOG1 Object is locked skipped

C:\Users\VALE\ntuser.dat.LOG2 Object is locked skipped

C:\Users\VALE\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped

C:\Users\VALE\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped

C:\Users\VALE\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped

C:\Windows\bthservsdp.dat Object is locked skipped

C:\Windows\Debug\PASSWD.LOG Object is locked skipped

C:\Windows\Debug\sam.log Object is locked skipped

C:\Windows\Debug\WIA\wiatrace.log Object is locked skipped

C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat Object is locked skipped

C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat Object is locked skipped

C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT Object is locked skipped

C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1 Object is locked skipped

C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG2 Object is locked skipped

C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped

C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped

C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped

C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT Object is locked skipped

C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1 Object is locked skipped

C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG2 Object is locked skipped

C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TM.blf Object is locked skipped

C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped

C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped

C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped

C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 Object is locked skipped

C:\Windows\System32\catroot2\edb.log Object is locked skipped

C:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdb Object is locked skipped

C:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdb Object is locked skipped

C:\Windows\System32\config\COMPONENTS Object is locked skipped

C:\Windows\System32\config\COMPONENTS.LOG1 Object is locked skipped

C:\Windows\System32\config\COMPONENTS.LOG2 Object is locked skipped

C:\Windows\System32\config\DEFAULT Object is locked skipped

C:\Windows\System32\config\DEFAULT.LOG1 Object is locked skipped

C:\Windows\System32\config\DEFAULT.LOG2 Object is locked skipped

C:\Windows\System32\config\RegBack\COMPONENTS Object is locked skipped

C:\Windows\System32\config\RegBack\DEFAULT Object is locked skipped

C:\Windows\System32\config\RegBack\SAM Object is locked skipped

C:\Windows\System32\config\RegBack\SECURITY Object is locked skipped

C:\Windows\System32\config\RegBack\SOFTWARE Object is locked skipped

C:\Windows\System32\config\RegBack\SYSTEM Object is locked skipped

C:\Windows\System32\config\SAM Object is locked skipped

C:\Windows\System32\config\SAM.LOG1 Object is locked skipped

C:\Windows\System32\config\SAM.LOG2 Object is locked skipped

C:\Windows\System32\config\SECURITY Object is locked skipped

C:\Windows\System32\config\SECURITY.LOG1 Object is locked skipped

C:\Windows\System32\config\SECURITY.LOG2 Object is locked skipped

C:\Windows\System32\config\SOFTWARE Object is locked skipped

C:\Windows\System32\config\SOFTWARE.LOG1 Object is locked skipped

C:\Windows\System32\config\SOFTWARE.LOG2 Object is locked skipped

C:\Windows\System32\config\SYSTEM Object is locked skipped

C:\Windows\System32\config\SYSTEM.LOG1 Object is locked skipped

C:\Windows\System32\config\SYSTEM.LOG2 Object is locked skipped

C:\Windows\System32\config\systemprofile\AppData\Roaming\Application Data\Spyware Terminator\setup.dat Object is locked skipped

C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.blf Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TM.blf Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms Object is locked skipped

C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms Object is locked skipped

C:\Windows\System32\DriverStore\FileRepository\vsdatant.inf_dfad73d0\vsdatant.sys Object is locked skipped

C:\Windows\System32\LogFiles\HTTPERR\httperr1.log Object is locked skipped

C:\Windows\System32\LogFiles\Scm\SCM.EVM Object is locked skipped

C:\Windows\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession.etl Object is locked skipped

C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped

C:\Windows\System32\Msdtc\KtmRmTm.blf Object is locked skipped

C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000001 Object is locked skipped

C:\Windows\System32\Msdtc\KtmRmTmContainer00000000000000000002 Object is locked skipped

C:\Windows\System32\spool\SpoolerETW.etl Object is locked skipped

C:\Windows\System32\wbem\Logs\WMITracing.log Object is locked skipped

C:\Windows\System32\wbem\Repository\INDEX.BTR Object is locked skipped

C:\Windows\System32\wbem\Repository\MAPPING1.MAP Object is locked skipped

C:\Windows\System32\wbem\Repository\MAPPING2.MAP Object is locked skipped

C:\Windows\System32\wbem\Repository\OBJECTS.DATA Object is locked skipped

C:\Windows\System32\WDI\LogFiles\WdiContextLog.etl.003 Object is locked skipped

C:\Windows\System32\wfp\wfpdiag.etl Object is locked skipped

C:\Windows\System32\winevt\Logs\Antivirus.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Application.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\DFS Replication.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\HardwareEvents.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Internet Explorer.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Key Management Service.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Media Center.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Bits-Client%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-CodeIntegrity%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnosis-DPS%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Diagnostics-Performance%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-DriverFrameworks-UserMode%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-GroupPolicy%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-International%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Kernel-WHEA.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-LanguagePackSetup%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-NetworkAccessProtection%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReadyBoost%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-ReliabilityAnalysisComponent%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Detector%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Exhaustion-Resolver%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-Resource-Leak-Diagnostic%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-RestartManager%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Microsoft-Windows-TaskScheduler%4Operational.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\ODiag.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\OSession.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\Security.evtx Object is locked skipped

C:\Windows\System32\winevt\Logs\System.evtx Object is locked skipped

C:\Windows\Tasks\SCHEDLGU.TXT Object is locked skipped

C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16386_none_69f99fa4b7380194\ntkrnlpa.exe Object is locked skipped

C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16575_none_6a037312b730c69a\ntkrnlpa.exe Object is locked skipped

C:\Windows\winsxs\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.20697_none_6a797099d05cd0f4\ntkrnlpa.exe Object is locked skipped

Scan process completed.

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

Ripeti l'operazione con avenger

inserisci questo script nel box bianco

Files to delete:

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ADSPIU06\b64_3[1].jpg

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ADSPIU06\b64_3[2].jpg

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CRHHSOD1\b64_1[1].jpg

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CRHHSOD1\b64_3[1].jpg

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VE54TKDJ\b64_3[1].jpg

Clicca su Execute

Il pc dovrebbe riavviarsi ( se così non fosse, fallo tu)

Posta il log che verrà creato in C:\Avenger

Ora Scarica ATF Cleaner

http://www.atribune.org/ccount/click.php?id=1

- Avvia ATF Cleaner.exe con un doppio click

- clicca sul menu main

- seleziona la casella Select All

- clicca sul pulsante Empty selected

- aspetta l'avviso Done Cleaning.

(se usi opera o firefox,spunta anche le loro sezioni)

Reinstalla il tuo antivirus

:)

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

Logfile of The Avenger Version 2.0, © by Swandog46

http://swandog46.geekstogo.com

Platform: Windows Vista

*******************

Script file opened successfully.

Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "srosa" found!

DisplayName: Megadrv3

ImagePath: \??\C:\Windows\system32\drivers\srosa.sys

Start Type: 1 (System)

Rootkit scan completed.

File "C:\WINDOWS\system32\drivers\mdelk.exe" deleted successfully.

Folder "C:\WINDOWS\system32\drivers\downld" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

dopo il riavvio di avenger e una scansione con spyware terminator dove mi ha tolto un pò di tracce di virus la cpu viaggia a ritmi "cristiani" ma mi è comparsa la schermata blu e il servizio di informazione di microsoft mi dice ciò:

Virus alert: Microsoft detected the WinNT / Bagle.gen virus on your computer

This problem was caused by WinNT / Bagle.gen, a known computer virus.

WinNT / Bagle.gen is also known by the following names:

  • Win32/Ursnif
  • Trojan-Downloader.Win32.Bagle.cu
  • W32.Beagle.GM
  • Troj/BagleDl-DB
  • Troj/Bagle-TH

Solution

To prevent this problem from occurring again, go to Windows Live OneCare safety scanner online and click Full Service Scan.

right.gifWhat to do if you can't access Windows Live OneCare

Sometimes, a virus can damage your Internet connection or prevent you from visiting a specific website. If you have access to the Internet but are unable to scan your computer at the Windows Live OneCare website, you can try to download the Malicious Software Removal tool to the computer with the virus.

To download and run the Malicious Software Removal Tool, follow these steps:

  1. Go online to the Malicious Software Removal Tool download site, and then download the tool.
  2. Double-click the tool named Windows-KB890830-V1.18 Self-Extracting Cabinet. Note that the name of the tool might be slightly different because the version numbers change.
  3. Click Run to start the tool, and then follow the installation wizard.
  4. When you are asked to choose a Scan Type, choose Full Scan.

If you are unable to download this tool because of a damaged Internet connection and you have access to another computer with an Internet connection, download the tool to removable media. You can then copy the tool to the computer with the virus using the removable media.

right.gifExamples of removable media

  • USB flash drive
  • CD-RW disc
  • DVD-RW disc

To download, copy, and run the Malicious Software Removal Tool, follow these steps:

  1. Go online to the Malicious Software Removal Tool download site, and then download the tool named Windows-KB890830-V1.18 Self-Extracting Cabinet to removable media. Note that the name of the tool might be slightly different because the version numbers change.
  2. On the infected computer, insert the removable media with the Malicious Software Removal Tool, open the removable media, and then double-click the tool named Windows-KB890830-V1.18 Self-Extracting Cabinet.
  3. Click Run to start the tool, and then follow the installation wizard.
  4. When you are asked to choose a Scan Type, choose Full Scan.

right.gifAdditional information

To keep yourself informed of the latest security issues, visit the Microsoft security website.

To see a list of Microsoft and third-party solutions for spyware, adware, and antivirus software, go to the following webpage online.

check.gifSecurity software: Downloads and trials

Note: You can avoid this and many other errors by running Automatic Update and running an up-to-date anti-virus application. Automatic Update keeps your computer up-to-date and secure by notifying you as soon as updates become available.

Rate this response:Provide Feedback

purtroppo nè hijack nè avast vanno ancora...volevo fare un log e postarvelo ma non me lo permette

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

provo a fare la scansione con il software di microsoft (dovrebbe eliminarlo) ma si blocca ad un certo punto...dopo ci riprovo...se avete soluzioni alternative sietei benvenuti :omaggi:

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

devi fare questa operazione e postare il log di essa...

Con avenger inserisci questo script nel box bianco

Files to delete:

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ADSPIU06\b64_3[1].jpg

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ADSPIU06\b64_3[2].jpg

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CRHHSOD1\b64_1[1].jpg

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CRHHSOD1\b64_3[1].jpg

C:\Users\VALE\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VE54TKDJ\b64_3[1].jpg

Togli il segno di spunta dalla voce Scan for Rootkits

Clicca su Execute

Il pc dovrebbe riavviarsi ( se così non fosse, fallo tu)

Posta il log che verrà creato in C:\Avenger

Fai anche questo:

Scarica ELIBAGLA

http://www.zonavirus.com/datos/descargas/95/elibagla.asp

Assicurati che la casella Eliminar Ficheros Automaticamente sia spuntata e clicca su Explorar

Posta il log C:\InfoSat.txt

Il download lo trovi in fondo alla pagina:

http://img406.imageshack.us/img406/3298/foton001ro1.jpg

Condividi questo messaggio


Link di questo messaggio
Condividi su altri siti

Crea un account o accedi per lasciare un commento

Devi essere un utente registrato per partecipare

Crea un account

Iscriviti per un nuovo account nella nostra community. È facile!


Registra un nuovo account

Accedi

Sei già registrato? Accedi qui.


Accedi Ora