Pagina 3 di 5 primaprima 1 2 3 4 5 ultimoultimo
Visualizzazione dei risultati da 21 a 30 su 42
  1. #21
    Moderatore di Sicurezza informatica e virus L'avatar di amvinfe
    Registrato dal
    May 2002
    Messaggi
    6,739
    va già molto meglio
    ho fatto un errore di trascrizione, nello script ho inserito delle cartelle da eliminare sotto il comando file da eliminare, scusami. Provvederemo dopo che avrai postato il nuovo report
    ==
    Visita il mio blog SuspectFile.com
    ==

  2. #22

  3. #23
    Moderatore di Sicurezza informatica e virus L'avatar di amvinfe
    Registrato dal
    May 2002
    Messaggi
    6,739
    stesso procedimento usato in precedenza con avenger

    Folders to delete:
    C:\Programmi\MSN Messenger\bak
    C:\Programmi\Samsung\SamsungMediaStudio4.1\bak
    C:\Documents and Settings\XZRZXC
    C:\Documents and Settings\jdhyC

    Files to delete:
    C:\Documents and Settings\jdhyC.LOG
    C:\Documents and Settings\XZRZXC.LOG
    C:\Programmi\MSN Messenger\usnsvc.exe

    registry values to delete:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run |SPAMfighter Agent

    registry keys to delete:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions|Lgolg
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AdvancedOptions|Niqni
    HKEY_LOCAL_MACHINE\system\controlset002\services|S rvNlh
    HKEY_LOCAL_MACHINE\system\controlset002\services|S ysJle

    Dopo il riavvio, sempre non connesso, crea una nuova cartella in C:\ ed inserisci al suo interno l'eseguibile di HijackThis.
    Apri HijackThis esegui lo scan, metti la spunta al fianco dei valori che ti riporto qui sotto (chiudi il browser), clicca su "Fix checked". Riavvia.

    R3 - Default URLSearchHook is missing
    F2 - REG:system.ini: UserInit=userinit.exe,
    O2 - BHO: (no name) - {DA39029C-D291-A968-3FF4-D0990D5CB5FC} - (no file)
    O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
    PF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
    O23 - Service: pWmnKr - Unknown owner - C:\Programmi\AoXlaByio.exe (file missing)
    O23 - Service: SPAMfighter Update Service - Unknown owner - C:\Programmi\SPAMfighter\sfus.exe (file missing)
    Vai su http://www.pandasoftware.com/actives..._principal.htm
    esegui la scansione online e posta il risultato
    ==
    Visita il mio blog SuspectFile.com
    ==

  4. #24
    Moderatore di Sicurezza informatica e virus L'avatar di amvinfe
    Registrato dal
    May 2002
    Messaggi
    6,739
    finito tutto fai un'ulteriore verifica da

    Start>Esegui scrivi

    control userpasswords2

    dai l'OK. Controlla se è presente l'utente jdhyC, nel caso lo selezioni e lo Rimuovi.
    ==
    Visita il mio blog SuspectFile.com
    ==

  5. #25
    Ho fatto la scansione con panda ma putroppo quanto ha finito non ero in casa e mio fratello non ha salvato il report! Adesso la faccio nuovamente

    Intanto ho visto che era presente l'utente jdhyC e l'ho rimosso.

    Invece è normale che AVG continua a dare un errore all'accensione e non venga aperto?

  6. #26
    Ecco il log di Panda


    Incidente Stato Percorso

    Spyware:Cookie/bravenetA Non Disinfettato C:\Documents and Settings\AMD64\Cookies\amd64@bravenet[1].txt
    Spyware:Cookie/Server.iad.Liveperson Non Disinfettato C:\Documents and Settings\AMD64\Cookies\amd64@server.iad.liveperson[1].txt
    Spyware:Cookie/YieldManager Non Disinfettato C:\Documents and Settings\AMD64\Dati applicazioni\Mozilla\Firefox\Profiles\n65vxpad.def ault\cookies.txt[ad.yieldmanager.com/]
    Spyware:Cookie/Serving-sys Non Disinfettato C:\Documents and Settings\AMD64\Dati applicazioni\Mozilla\Firefox\Profiles\n65vxpad.def ault\cookies.txt[.serving-sys.com/]
    Spyware:Cookie/Serving-sys Non Disinfettato C:\Documents and Settings\AMD64\Dati applicazioni\Mozilla\Firefox\Profiles\n65vxpad.def ault\cookies.txt[.bs.serving-sys.com/]
    Spyware:Cookie/Serving-sys Non Disinfettato C:\Documents and Settings\AMD64\Dati applicazioni\Mozilla\Firefox\Profiles\n65vxpad.def ault\cookies.txt[.serving-sys.com/]
    Spyware:Cookie/Xiti Non Disinfettato C:\Documents and Settings\AMD64\Dati applicazioni\Mozilla\Firefox\Profiles\n65vxpad.def ault\cookies.txt[.xiti.com/]
    Spyware:Spyware/New.net Non Disinfettato C:\Documents and Settings\AMD64\Desktop\Programmi\Vari\Cliprexdsfre e.exe[nnclx485.exe]
    Adware:Adware/eZula Non Disinfettato C:\Documents and Settings\AMD64\Desktop\Programmi\Vari\Cliprexdsfre e.exe[CliprexTTIL.exe]
    Strumenti indesiderati:Application/MyWay Non Disinfettato C:\Documents and Settings\AMD64\Desktop\Programmi\Vari\Cliprexdsfre e.exe[myBarSp.exe]
    Adware:Adware/nCase Non Disinfettato C:\Documents and Settings\AMD64\Desktop\Programmi\Vari\Cliprexdsfre e.exe[msbb.exe]
    Adware:Adware/eZula Non Disinfettato C:\Documents and Settings\AMD64\Desktop\Programmi\Vari\gozilla1.exe
    Virus:Generic Malware Non Disinfettato C:\Documents and Settings\AMD64\Desktop\sys14453.exe[runme.exe]
    Virus:Generic Malware Non Disinfettato C:\Documents and Settings\AMD64\Desktop\Utility\Nuova cartella\sys.zip[sys14453.exe][runme.exe]
    Virus:Trj/RKDice.A Disinfettato C:\Documents and Settings\AMD64\Impostazioni locali\Temp\PXR3C.tmp
    Virus:Trj/Agent.EHE Disinfettato C:\_cleaned.tmp
    Adware:Adware/Popupdefence Non Disinfettato D:\conservare non cancellare\Programmi\sfg800e.exe[82384D7B-FA4B-475F-BE0E-D27F64737426]

  7. #27
    Moderatore di Sicurezza informatica e virus L'avatar di amvinfe
    Registrato dal
    May 2002
    Messaggi
    6,739
    capita


    per i cookie nessun problema o li elimini svuotando la cache o installi (lo consiglio ) CCleaner http://www.ccleaner.com/download ed esegui una pulizia.

    Per quanto riguarda gli altri file li puoi eliminare a mano (meglio se dalla provvisoria) o usando come al solito The Avenger, vedi tu lo script da inserire in The Avenger (stessa procedura delle altre volte)

    Files to delete:
    C:\Documents and Settings\AMD64\Desktop\Programmi\Vari\Cliprexdsfre e.exe
    C:\Documents and Settings\AMD64\Desktop\Programmi\Vari\gozilla1.exe
    per quanto riguarda:
    Virus:Generic Malware Non Disinfettato C:\Documents and Settings\AMD64\Desktop\sys14453.exe[runme.exe]
    Virus:Generic Malware Non Disinfettato C:\Documents and Settings\AMD64\Desktop\Utility\Nuova cartella\sys.zip[sys14453.exe][runme.exe]
    sono falsi positivi, abbiamo già avvisato Panda Security.

    Prova a reinstallare AVG... magari meglio se decidi di installarne un altro
    www.free-av.com (Avira AntiVir PersonalEdition Classic)
    in ogni caso dopo aver installato l'antivirus aggiorna le definizioni ed esegui una scansione.

    Postami per favore il risultato della scansione ed un nuovo (spero sia l'ultimo che ti faccio fare ) report di SystemScan.

    Ciao
    ==
    Visita il mio blog SuspectFile.com
    ==

  8. #28
    Ok, eseguo tutto alla lettera e ti faccio sapere!

  9. #29
    Ecco il report di Antivir, tra un po posto anche quello di Systemscan!





    AntiVir PersonalEdition Classic
    Report file date: mercoledì 31 ottobre 2007 19:53

    Scanning for 911601 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Username: SYSTEM
    Computer name: AMD3500

    Version information:
    BUILD.DAT : 270 15603 Bytes 19/09/2007 13:32:00
    AVSCAN.EXE : 7.0.6.1 290856 Bytes 23/08/2007 13:16:29
    AVSCAN.DLL : 7.0.6.0 49192 Bytes 16/08/2007 12:23:51
    LUKE.DLL : 7.0.5.3 147496 Bytes 14/08/2007 15:32:47
    LUKERES.DLL : 7.0.6.1 10280 Bytes 21/08/2007 12:35:20
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 18:25:33
    ANTIVIR1.VDF : 7.0.0.0 1640448 Bytes 13/09/2007 18:25:33
    ANTIVIR2.VDF : 7.0.0.140 940544 Bytes 26/10/2007 18:25:33
    ANTIVIR3.VDF : 7.0.0.160 106496 Bytes 31/10/2007 18:25:33
    AVEWIN32.DLL : 7.6.0.30 3056128 Bytes 31/10/2007 18:25:34
    AVWINLL.DLL : 1.0.0.7 14376 Bytes 26/02/2007 10:36:26
    AVPREF.DLL : 7.0.2.2 25640 Bytes 18/07/2007 07:39:17
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
    AVPACK32.DLL : 7.3.0.15 360488 Bytes 03/08/2007 08:46:00
    AVREG.DLL : 7.0.1.6 30760 Bytes 18/07/2007 07:17:06
    AVARKT.DLL : 1.0.0.20 278568 Bytes 28/08/2007 12:26:33
    AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 18/07/2007 07:10:18
    NETNT.DLL : 7.0.0.0 7720 Bytes 08/03/2007 11:09:42
    RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 07/08/2007 12:38:13
    RCTEXT.DLL : 7.0.62.0 86056 Bytes 21/08/2007 12:50:37
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 23/07/2007 09:37:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: c:\programmi\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: D:,
    Scan memory......................: on
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: mercoledì 31 ottobre 2007 19:53

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
    Scan process 'firefox.exe' - '1' Module(s) have been scanned
    Scan process 'wuauclt.exe' - '1' Module(s) have been scanned
    Scan process 'skypePM.exe' - '1' Module(s) have been scanned
    Scan process 'wscntfy.exe' - '1' Module(s) have been scanned
    Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned
    Scan process 'alg.exe' - '1' Module(s) have been scanned
    Scan process 'reader_sl.exe' - '1' Module(s) have been scanned
    Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned
    Scan process 'Skype.exe' - '1' Module(s) have been scanned
    Scan process 'wdfmgr.exe' - '1' Module(s) have been scanned
    Scan process 'SERVIC~1.EXE' - '1' Module(s) have been scanned
    Scan process 'ULCDRSvr.exe' - '1' Module(s) have been scanned
    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
    Scan process 'MDM.EXE' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'BTNtService.exe' - '1' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 'guard.exe' - '1' Module(s) have been scanned
    Scan process 'SSAAD.exe' - '1' Module(s) have been scanned
    Scan process 'LaunchApplication.exe' - '1' Module(s) have been scanned
    Scan process 'DataLayer.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'rundll32.exe' - '1' Module(s) have been scanned
    Scan process 'SOUNDMAN.EXE' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'aawservice.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'ati2evxx.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    43 processes with 43 modules were scanned

    Start scanning boot sectors:
    Boot sector 'C:\'
    [NOTE] No virus was found!
    Boot sector 'D:\'
    [NOTE] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '25' files ).


    Starting the file scan:

    Begin scan in 'C:\'
    C:\pagefile.sys
    [WARNING] The file could not be opened!
    C:\Documents and Settings\AMD64\Desktop\Mario\N70\Giochi\Pack Kaosone\NOKIA KaosONE Selecta 2006\Gamez\3D Motoracer V 1[1].09\keygen.exe
    [DETECTION] Is the Trojan horse TR/Agent.50696
    [INFO] The file was moved to '47a1d256.qua'!
    C:\Documents and Settings\AMD64\Desktop\Programmi\software\antispyw are\InstallPREVX102000223.exe
    [0] Archive type: ACE SFX (self extracting)
    --> img\bins\2k_2k3_xp\lclbrk.cache.2k
    [WARNING] Error creating the file
    --> img\bins\2k_2k3_xp\rksig.bin
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    C:\Documents and Settings\AMD64\Desktop\Programmi\Vari\Softcam Download.exe
    [DETECTION] Contains detection pattern of the dial-up program DIAL/300252
    [INFO] The file was moved to '478ed328.qua'!
    C:\Documents and Settings\AMD64\Desktop\Programmi\Vari\Softcam_Down load.zip
    [0] Archive type: ZIP
    --> Softcam Download.exe
    [DETECTION] Contains detection pattern of the dial-up program DIAL/300252
    [INFO] The file was moved to '46e7b3f9.qua'!
    C:\Documents and Settings\AMD64\Impostazioni locali\Temp\UpdatePREVX102000337.exe
    [0] Archive type: ACE SFX (self extracting)
    --> img\bins\2k_2k3_xp\lclbrk.cache.2k
    [WARNING] Error creating the file
    --> img\bins\2k_2k3_xp\rksig.bin
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    C:\Documents and Settings\AMD64\Impostazioni locali\Temp\UpdatePREVX102000419.exe
    [0] Archive type: ACE SFX (self extracting)
    --> img\bins\2k_2k3_xp\lclbrk.cache.2k
    [WARNING] Error creating the file
    --> img\bins\2k_2k3_xp\rksig.bin
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    C:\Documents and Settings\AMD64\Impostazioni locali\Temp\UpdatePREVX102000506.exe
    [0] Archive type: ACE SFX (self extracting)
    --> img\bins\2k_2k3_xp\lclbrk.cache.2k
    [WARNING] Error creating the file
    --> img\bins\2k_2k3_xp\rksig.bin
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\Quarantine\fil3D55A400.dat
    [0] Archive type: GZ
    --> fil3D55A400
    [DETECTION] Is the Trojan horse TR/Agent.aox
    [INFO] The file was moved to '4794d8c1.qua'!
    C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\Quarantine\fil5404B100.dat
    [0] Archive type: GZ
    --> fil5404B100
    [DETECTION] Is the Trojan horse TR/Agent.aox
    [INFO] The file was moved to '4794d8c2.qua'!
    C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\Quarantine\fil64D54241.dat
    [0] Archive type: GZ
    --> fil64D54241
    [DETECTION] Is the Trojan horse TR/Agent.aox
    [INFO] The file was moved to '46fc838b.qua'!
    C:\Programmi\Grisoft\AVG Anti-Spyware 7.5\Quarantine\filF7130B44.dat
    [0] Archive type: GZ
    --> filF7130B44
    [DETECTION] Is the Trojan horse TR/Agent.aox
    [INFO] The file was moved to '4794d8c3.qua'!
    C:\Programmi\Panda Security\NanoScan\Engine\psnflg.dll
    [DETECTION] Is the Trojan horse TR/Agent.bux.1
    [INFO] The file was moved to '4796da4a.qua'!
    C:\Programmi\Panda Security\TotalScan\pskavs.dll
    [DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
    [INFO] The file was moved to '4793da4c.qua'!
    C:\WINDOWS\system32\ActiveScan\pskavs.dll
    [DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
    [INFO] The file was moved to '4793dbd5.qua'!
    Begin scan in 'D:\'
    D:\conservare non cancellare\Programmi\Clone CD_6 versions + Serials + Keygens(8).zip
    [0] Archive type: ZIP
    --> Clone CD_6 versions + Serials + Keygens/Clone CD 3.06.01 + crack + db.zip
    [DETECTION] Contains code of the Windows virus W95/Hybris.PI.003
    [INFO] The file was moved to '4797dc3d.qua'!


    End of the scan: mercoledì 31 ottobre 2007 20:56
    Used time: 1:03:25 min

    The scan has been done completely.

    9312 Scanning directories
    518234 Files were scanned
    11 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    0 files were deleted
    0 files were repaired
    11 files were moved to quarantine
    0 files were renamed
    1 Files cannot be scanned
    518223 Files not concerned
    8352 Archives were scanned
    13 Warnings
    25 Notes


  10. #30
    Ecco il report di systemscan

    http://www.sendmefile.com/00591713

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2026 vBulletin Solutions, Inc. All rights reserved.