Hai una variante del bagle (o dei residui) ed il Worm SDBot. Quest'ultimo ha la caratteristica di camuffarsi con nomi che sembrano legittimi, ma non lo sono..


Elimina questo file:


C:\WINDOWS\system32\syntax2.exe



Fixa questi:


R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://2uid.info

O4 - HKLM\..\Run: [Syntax2 Positive] syntax2.exe

O4 - HKLM\..\Run: [SYSTEM] winmgrd.exe

O4 - HKLM\..\RunServices: [File Mapping Services] hp-1003.exe

O4 - HKCU\..\Run: [hldrrr] C:\WINDOWS\system32\hldrrr.exe

O4 - HKCU\..\RunServices: [File Mapping Services] hp-1003.exe

O4 - HKUS\S-1-5-18\..\RunServices: [SYSTEM] winmgrd.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\RunServices: [SYSTEM] winmgrd.exe (User 'Default user')

O23 - Service: Network helper Service (MSDisk) - Unknown owner - C:\WINDOWS\System32\irdvxc.exe (file missing)

O23 - Service: Network Windows Service (MSWindows) - Unknown owner - C:\WINDOWS\System32\urdvxc.exe (file missing)

O23 - Service: Windows Tune service - Unknown owner - C:\WINDOWS\tune.exe (file missing)