Pagina 1 di 3 1 2 3 ultimoultimo
Visualizzazione dei risultati da 1 a 10 su 26

Discussione: Sempre AMVO...

  1. #1

    Sempre AMVO ... aiuto!

    Salve ragazzi ..intanto vi saluto visto che sono nuovo..
    ho il solito problema con AMVO ..devo riuscire a risolverlo senza formattare ..ho di modelli di word che mi servono ma sono sotto un percorso che non riesco più a visualizzare grazie al mitico AMVO.
    Hoseguito le varie puntate di consigli qui sul forum ho cercato di fare come suggerito da la mitica Deifobe ma pare niente !

    Intanto posto un'analisi del registro in cui sono risultato amvo positivo:
    REGEDIT4
    ; RegSrch.vbs © Bill James

    ; Registry search results for string "amvo" 01/03/2008 17.18.29

    ; NOTE: This file will be deleted when you close WordPad.
    ; You must manually save this file to a new location if you want to refer to it again later.
    ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


    [HKEY_USERS\S-1-5-21-329068152-746137067-1343024091-1003\Software\Microsoft\Windows\ShellNoRoam\MUICac he]
    "C:\\WINDOWS\\system32\\amvo.exe"="amvo"

    poi l'analisi di HijackThis:

    Logfile of HijackThis v1.99.1
    Scan saved at 17.31.21, on 29/02/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\winlogon32.exe
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe
    C:\Programmi\iTunes\iTunesHelper.exe
    C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe
    C:\Programmi\Eset\nod32kui.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Programmi\Messenger\msmsgs.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe
    C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
    C:\Programmi\OpenOffice.org 2.3\program\soffice.exe
    C:\Programmi\OpenOffice.org 2.3\program\soffice.BIN
    C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    C:\Programmi\Eset\nod32krn.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
    C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
    C:\Programmi\File comuni\Ahead\Lib\NMIndexStoreSvr.exe
    C:\Programmi\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Programmi\Mozilla Firefox\firefox.exe
    C:\WINDOWS\system32\taskmgr.exe
    C:\Documents and Settings\Utente\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = 127.0.0.1
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programmi\File comuni\Ahead\Lib\NeroCheck.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_03\bin\jusched.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [EPSON Stylus DX5000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIB VE.EXE /FU "C:\WINDOWS\TEMP\E_S8A.tmp" /EF "HKLM"
    O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programmi\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [nod32kui] C:\Programmi\Eset\nod32kui.exe /WAITSERVICE
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Startup: OpenOffice.org 2.3.lnk = C:\Programmi\OpenOffice.org 2.3\program\quickstart.exe
    O4 - Startup: Reboot.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programmi\File comuni\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Programmi\File comuni\Autodesk Shared\acstart16.exe
    O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_03\bin\ssv.dll
    O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
    O17 - HKLM\System\CCS\Services\Tcpip\..\{818283DD-CC28-4736-889A-E1746F8EBED4}: NameServer = 85.37.17.16 85.38.28.68
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
    O23 - Service: "any name" - Unknown owner - D:\Emule\[CAD ELECTRICAL] AUTODESK Autocad Electrical 2005\[CAD ELECTRICAL] AUTODESK Autocad Electrical 2005\PANTHEON\Autodesk Network License Manager\lmgrd.exe (file missing)
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Symantec pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Programmi\Symantec\pcAnywhere\awhost32.exe
    O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
    O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
    O23 - Service: NBService - Nero AG - C:\Programmi\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: NMIndexingService - Nero AG - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe
    O23 - Service: NOD32 Kernel Service (NOD32krn) - Unknown owner - C:\Programmi\Eset\nod32krn.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: ServiceLayer - Nokia. - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe

    Qualcuno sa aiutarmi ..vi prego !
    ciao e grazie ..intanto ..

  2. #2
    Utente di HTML.it L'avatar di Deifobe
    Registrato dal
    Oct 2007
    Messaggi
    6,072
    dovresti dire cosa hai fatto per quanto riguarda i files nascosti, così non diamo le cose x scontato.
    scarica, installa e aggiorna Virit.

    Disconnetti il pc da internet.

    Entra in modalità provvisoria: all'avvio del pc premi ripetutamente F8.
    Uscirà la finestra del menu Opzioni avanzate di Windows => scegli modalità provvisoria (usa il tasto freccia ^).

    Disattiva il ripristino configurazione di sistema: start -> pannello di controllo -> sistema -> ripristino configurazione di sistema -> spunta "disattiva ripristino configuraz. di sistema"

    Elimina il file:
    C:\WINDOWS\winlogon32.exe

    e, se presenti:
    C:\WINDOWS\winlogon32.dll
    C:\documents and settings\user\impostazioni locali\temp\it_0[numeri casuali]
    C:\documents and settings\user\impostazioni locali\temp\spoolsv32.exe
    (se qualche file non si elimina, controlla non sia attivo nel task manager. Se c'è, termina il processo ed elimina il file)

    Sempre da modalità provvisoria, esegui una scansione con VirIT e posta il rapporto.

    Copia questo in un file di testo e salvalo come opzioni.reg
    Windows Registry Editor Version 5.00

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\policies\Explorer]
    "NoFolderOptions"=dword:00000000

    Clicca sul file 2 volte e riavvia il pc

    Conviene installare hjt in una cartella dedicata (tipo c:\hijackthis)
    Se spybot ti avvisa su modifiche da effettuare non devi accettare (eccetto non le abbia richieste tu).
    ...
    :x:_::_:*:_::_: )(:_:*:_:*:__::_:°FM°:_: )(:_:*:_:x:___

  3. #3
    intanto grazie,
    seguo le tue istruzioni e tifaccio sapere .. ti posto i risultati!

    ciao

  4. #4
    Utente di HTML.it L'avatar di Deifobe
    Registrato dal
    Oct 2007
    Messaggi
    6,072
    fai anche una scansione con Kaspersky_virusscanner e posta il rapporto (salvalo come file di testo).

    Ricordati di inserire pen drive e hd esterni, se li hai.
    ...
    :x:_::_:*:_::_: )(:_:*:_:*:__::_:°FM°:_: )(:_:*:_:x:___

  5. #5

    post Kasper

    Ecco il post di Kasper ..speriamo che risolvi che mi sa che sto inguaito!

    KASPERSKY ONLINE SCANNER REPORT

    Monday, March 03, 2008 5:47:54 PM
    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 3/03/2008
    Kaspersky Anti-Virus database records: 594132


    Scan Settings
    Scan using the following antivirus database extended
    Scan Archives true
    Scan Mail Bases true

    Scan Target My Computer
    A:\
    C:\
    D:\
    E:\
    F:\
    G:\
    H:\

    Scan Statistics
    Total number of scanned objects 75903
    Number of viruses found 13
    Number of infected objects 27
    Number of suspicious objects 0
    Duration of the scan process 03:02:08

    Infected Object Name Virus Name Last Action
    C:\autorun.inf Infected: Trojan-PSW.Win32.OnLineGames.skg skipped

    C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.da t Object is locked skipped

    C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.da t Object is locked skipped

    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\LocalService\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\Utente\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\9wl1wov4.def ault\cert8.db Object is locked skipped

    C:\Documents and Settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\9wl1wov4.def ault\formhistory.dat Object is locked skipped

    C:\Documents and Settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\9wl1wov4.def ault\history.dat Object is locked skipped

    C:\Documents and Settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\9wl1wov4.def ault\key3.db Object is locked skipped

    C:\Documents and Settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\9wl1wov4.def ault\parent.lock Object is locked skipped

    C:\Documents and Settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\9wl1wov4.def ault\search.sqlite Object is locked skipped

    C:\Documents and Settings\Utente\Dati applicazioni\Mozilla\Firefox\Profiles\9wl1wov4.def ault\urlclassifier2.sqlite Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Cronologia\History.IE5\MSHist01200803032008 0304\index.dat Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\Ahead\Nero Home\bl.db Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\Ahead\Nero Home\is2.db Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\Identities\{D7BFEDBE-17DB-4C0F-9F4E-DE1A71E9610D}\Microsoft\Outlook Express\Folders.dbx Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\Identities\{D7BFEDBE-17DB-4C0F-9F4E-DE1A71E9610D}\Microsoft\Outlook Express\Offline.dbx Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\Utente\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\Utente\NTUSER.DAT.LOG Object is locked skipped

    C:\Documents and Settings\Utente\UserData\index.dat Object is locked skipped

    C:\Documents and Settings\Utente\vjczsxjj.exe Infected: Trojan.Win32.Dialer.aeh skipped

    C:\Documents and Settings\Utente\xiizfqwe.exe Infected: Trojan.Win32.Dialer.aeh skipped

    C:\fppg1.exe Infected: Trojan-PSW.Win32.OnLineGames.scx skipped

    C:\Programmi\Eset\infected\F1FWLJAA.NQF Infected: Trojan-PSW.Win32.OnLineGames.skw skipped

    C:\Programmi\Eset\infected\MXOJ3HCA.NQF Infected: Trojan-PSW.Win32.OnLineGames.skg skipped

    C:\Programmi\Eset\logs\virlog.dat Object is locked skipped

    C:\Programmi\Eset\logs\warnlog.dat Object is locked skipped

    C:\Programmi\RegCleaner\Backups\Amvo0.dll Infected: Trojan-PSW.Win32.OnLineGames.scw skipped

    C:\Programmi\RegCleaner\Backups\Amvo1.dll Infected: Trojan-PSW.Win32.OnLineGames.snn skipped

    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    C:\VEXPLITE\reg_ecc.dat Object is locked skipped

    C:\VEXPLITE\Utente\reg.dat Object is locked skipped

    C:\VEXPLITE\VIRITMON.LOG Object is locked skipped

    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

    C:\WINDOWS\SchedLgU.Txt Object is locked skipped

    C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked skipped

    C:\WINDOWS\Sti_Trace.log Object is locked skipped

    C:\WINDOWS\system32\amvo.exe Infected: Trojan-PSW.Win32.OnLineGames.scx skipped

    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\default Object is locked skipped

    C:\WINDOWS\system32\config\default.LOG Object is locked skipped

    C:\WINDOWS\system32\config\Paramete.evt Object is locked skipped

    C:\WINDOWS\system32\config\SAM Object is locked skipped

    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

    C:\WINDOWS\system32\config\software Object is locked skipped

    C:\WINDOWS\system32\config\software.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\system Object is locked skipped

    C:\WINDOWS\system32\config\system.LOG Object is locked skipped

    C:\WINDOWS\system32\h323log.txt Object is locked skipped

    C:\WINDOWS\system32\kas.exe Infected: Backdoor.Win32.PcClient.wi skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

    C:\WINDOWS\system32\yqfprhqr.d1l Infected: Backdoor.Win32.PcClient.xp skipped

    C:\WINDOWS\wiadebug.log Object is locked skipped

    C:\WINDOWS\wiaservc.log Object is locked skipped

    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    D:\autorun.inf Infected: Trojan-PSW.Win32.OnLineGames.skg skipped

    D:\Emule\Nero Burning Rom 7.8.5.0 Ita + keygen(1).rar/Nero-7.8.5.0_ita_trial.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped

    D:\Emule\Nero Burning Rom 7.8.5.0 Ita + keygen(1).rar/Nero-7.8.5.0_ita_trial.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped

    D:\Emule\Nero Burning Rom 7.8.5.0 Ita + keygen(1).rar RAR: infected - 2 skipped

    D:\fppg1.exe Infected: Trojan-PSW.Win32.OnLineGames.scx skipped

    D:\Musica\Davide\I pod DATI\Java Avanzato\vnc-4_1_2-x86_win32.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

    D:\Musica\Davide\I pod DATI\Java Avanzato\vnc-4_1_2-x86_win32.exe/file2 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

    D:\Musica\Davide\I pod DATI\Java Avanzato\vnc-4_1_2-x86_win32.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

    D:\Musica\Davide\I pod DATI\Java Avanzato\vnc-4_1_2-x86_win32.exe/file5 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

    D:\Musica\Davide\I pod DATI\Java Avanzato\vnc-4_1_2-x86_win32.exe Inno: infected - 4 skipped

    D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    G:\Back Up Roma\Musica\Generatore di codici per ricariche OMNITEL\Omnitel.exe Infected: not-virus:Hoax.DOS.Omnitel.a skipped

    G:\Back Up Roma\Varie\Audio\RosoftAudioToolsFree.exe/data0015 Infected: not-a-virus:AdWare.Win32.MyWay.ac skipped

    G:\Back Up Roma\Varie\Audio\RosoftAudioToolsFree.exe/data0018 Infected: not-a-virus:AdWare.Win32.180Solutions skipped

    G:\Back Up Roma\Varie\Audio\RosoftAudioToolsFree.exe Inno: infected - 2 skipped

    G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    H:\autorun.inf Infected: Trojan-PSW.Win32.OnLineGames.skg skipped

    H:\fppg1.exe Infected: Trojan-PSW.Win32.OnLineGames.scx skipped

    grazie Davide

  6. #6
    Utente di HTML.it L'avatar di Deifobe
    Registrato dal
    Oct 2007
    Messaggi
    6,072
    cominciamo da questi.
    scarica Avenger e CCleaner

    Disattiva il ripristino configurazione di sistema: start -> pannello di controllo -> sistema -> ripristino configurazione di sistema -> spunta "disattiva ripristino configuraz. di sistema"

    Collega nuovamente pen, HD ecc ecc

    Esegui avenger, seleziona l'opzione "Input Script Manually" e clicca sulla lente d'ingrandimento. All'interno della finestra "Wiew/edit script", nel box bianco, copia/incolla:
    files to delete:
    C:\Documents and Settings\Utente\vjczsxjj.exe
    C:\Documents and Settings\Utente\xiizfqwe.exe
    C:\fppg1.exe
    C:\WINDOWS\system32\amvo.exe
    C:\WINDOWS\system32\kas.exe
    C:\WINDOWS\system32\yqfprhqr.d1l
    H:\autorun.inf
    D:\autorun.inf
    C:\autorun.inf
    H:\fppg1.exe
    Clicca sul pulsante "Done", poi sul semaforo verde, rispondi 2 volte Yes. Il pc dovrebbe riavviarsi da solo, altrimenti riavvialo tu. Posta il report rilasciato

    svuota i backups degli antivirus, li trovi qui:
    C:\Programmi\Eset => infected
    C:\Programmi\RegCleaner => backups

    Esegui CCleaner e ripulisci sia i file temporanei e cookie (2 volte) che il registro.

    rifai la scansione con kaspersky. Puoi disconnettere il pc da internet solo dopo aver selezionato "my computer".
    ...
    :x:_::_:*:_::_: )(:_:*:_:*:__::_:°FM°:_: )(:_:*:_:x:___

  7. #7
    Fatto quello che mi hai chiesto con Avenger .. i file mi sembrano cancellati tutti !
    Per quanto riguarda la pennete USB che era al drive H:\ l'ho formattata ieri sera causa disperazione, quindi forse per questo nel log non è stato trovato niente. Ti posto il risultato di Avenger:

    Logfile of The Avenger Version 2.0, (c) by Swandog46
    http://swandog46.geekstogo.com

    Platform: Windows XP

    *******************

    Script file opened successfully.
    Script file read successfully.

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Rootkit scan active.
    No rootkits found!

    File "C:\Documents and Settings\Utente\vjczsxjj.exe" deleted successfully.
    File "C:\Documents and Settings\Utente\xiizfqwe.exe" deleted successfully.
    File "C:\fppg1.exe" deleted successfully.
    File "C:\WINDOWS\system32\amvo.exe" deleted successfully.
    File "C:\WINDOWS\system32\kas.exe" deleted successfully.
    File "C:\WINDOWS\system32\yqfprhqr.d1l" deleted successfully.

    Error: could not open file "H:\autorun.inf"
    Deletion of file "H:\autorun.inf" failed!
    Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
    --> bad path / the parent directory does not exist

    File "D:\autorun.inf" deleted successfully.
    File "C:\autorun.inf" deleted successfully.

    Error: could not open file "H:\fppg1.exe"
    Deletion of file "H:\fppg1.exe" failed!
    Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
    --> bad path / the parent directory does not exist


    Completed script processing.

    *******************

    Finished! Terminate.

    Poi ho pulito tutto con CCleaner come chiesto dopo aver svuatato i due path:
    C:\Programmi\Eset => infected
    C:\Programmi\RegCleaner => backups

    Ora rifaccio la scansione con Kaspersky come finisco te la posto ok ?!? ..credo ci vorrà un pò , ma questo già lo sai no ?!?

    Ciao e RI-grazie ..pare che stiamo progredendo!

  8. #8
    Utente di HTML.it L'avatar di Deifobe
    Registrato dal
    Oct 2007
    Messaggi
    6,072
    ok. fammi una cortesia (e fai quello che ti scrivo, esattamente )

    Apri il registro (start - esegui - digita regedit e dai l'ok)
    Portati in questa chiave:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2

    Clicca su MountPoints2 con il tasto dx del mouse e seleziona "esporta".
    Devi salvarla così:
    nome: mount.txt
    Tipo: file di testo
    salvala in c:\

    Carica il file su Freefilehosting e posta il link ottenuto.
    ...
    :x:_::_:*:_::_: )(:_:*:_:*:__::_:°FM°:_: )(:_:*:_:x:___

  9. #9
    Allora:
    File Information:
    File Name: mount.txt
    File Size: 156 kilobytes
    Upload Date: March 4, 2008 00:18 AM PST

    Link to this page:

    Direct Link: http://www.freefilehosting.net/download/3d3fm
    HTML Code: mount.txt
    Forum Link: mount.txt

    Sono stato abbastanza preciso ?!?

    Questo il post di Kaspersky fatto prima che salvassi \mount del registro:

    KASPERSKY ONLINE SCANNER REPORT
    Tuesday, March 04, 2008 8:43:20 AM
    Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
    Kaspersky Online Scanner version: 5.0.98.0
    Kaspersky Anti-Virus database last update: 3/03/2008
    Kaspersky Anti-Virus database records: 594708


    Scan Settings
    Scan using the following antivirus database extended
    Scan Archives true
    Scan Mail Bases true

    Scan Target My Computer
    A:\
    C:\
    D:\
    E:\
    F:\
    G:\
    H:\

    Scan Statistics
    Total number of scanned objects 75446
    Number of viruses found 9
    Number of infected objects 17
    Number of suspicious objects 0
    Duration of the scan process 02:58:28

    Infected Object Name Virus Name Last Action
    C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.da t Object is locked skipped

    C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.da t Object is locked skipped

    C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\LocalService\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

    C:\Documents and Settings\Utente\Cookies\index.dat Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Cronologia\History.IE5\MSHist01200803032008 0304\index.dat Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\Ahead\Nero Home\bl.db Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\Ahead\Nero Home\is2.db Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\Identities\{D7BFEDBE-17DB-4C0F-9F4E-DE1A71E9610D}\Microsoft\Outlook Express\Folders.dbx Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\Identities\{D7BFEDBE-17DB-4C0F-9F4E-DE1A71E9610D}\Microsoft\Outlook Express\Offline.dbx Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

    C:\Documents and Settings\Utente\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

    C:\Documents and Settings\Utente\NTUSER.DAT Object is locked skipped

    C:\Documents and Settings\Utente\NTUSER.DAT.LOG Object is locked skipped

    C:\Programmi\Eset\logs\virlog.dat Object is locked skipped

    C:\Programmi\Eset\logs\warnlog.dat Object is locked skipped

    C:\Programmi\RegCleaner\Backups\Amvo0.dll Infected: Trojan-PSW.Win32.OnLineGames.scw skipped

    C:\Programmi\RegCleaner\Backups\Amvo1.dll Infected: Trojan-PSW.Win32.OnLineGames.snn skipped

    C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    C:\VEXPLITE\reg_ecc.dat Object is locked skipped

    C:\VEXPLITE\Utente\reg.dat Object is locked skipped

    C:\VEXPLITE\VIRITMON.LOG Object is locked skipped

    C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

    C:\WINDOWS\SchedLgU.Txt Object is locked skipped

    C:\WINDOWS\SoftwareDistribution\ReportingEvents.lo g Object is locked skipped

    C:\WINDOWS\Sti_Trace.log Object is locked skipped

    C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\default Object is locked skipped

    C:\WINDOWS\system32\config\default.LOG Object is locked skipped

    C:\WINDOWS\system32\config\Paramete.evt Object is locked skipped

    C:\WINDOWS\system32\config\SAM Object is locked skipped

    C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY Object is locked skipped

    C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

    C:\WINDOWS\system32\config\software Object is locked skipped

    C:\WINDOWS\system32\config\software.LOG Object is locked skipped

    C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

    C:\WINDOWS\system32\config\system Object is locked skipped

    C:\WINDOWS\system32\config\system.LOG Object is locked skipped

    C:\WINDOWS\system32\h323log.txt Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MA P Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MA P Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DAT A Object is locked skipped

    C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

    C:\WINDOWS\wiadebug.log Object is locked skipped

    C:\WINDOWS\wiaservc.log Object is locked skipped

    C:\WINDOWS\WindowsUpdate.log Object is locked skipped

    D:\Emule\Nero Burning Rom 7.8.5.0 Ita + keygen(1).rar/Nero-7.8.5.0_ita_trial.exe/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped

    D:\Emule\Nero Burning Rom 7.8.5.0 Ita + keygen(1).rar/Nero-7.8.5.0_ita_trial.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped

    D:\Emule\Nero Burning Rom 7.8.5.0 Ita + keygen(1).rar RAR: infected - 2 skipped

    D:\fppg1.exe Infected: Trojan-PSW.Win32.OnLineGames.scx skipped

    D:\Musica\Davide\I pod DATI\Java Avanzato\vnc-4_1_2-x86_win32.exe/file1 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

    D:\Musica\Davide\I pod DATI\Java Avanzato\vnc-4_1_2-x86_win32.exe/file2 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

    D:\Musica\Davide\I pod DATI\Java Avanzato\vnc-4_1_2-x86_win32.exe/file3 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

    D:\Musica\Davide\I pod DATI\Java Avanzato\vnc-4_1_2-x86_win32.exe/file5 Infected: not-a-virus:RemoteAdmin.Win32.WinVNC.4 skipped

    D:\Musica\Davide\I pod DATI\Java Avanzato\vnc-4_1_2-x86_win32.exe Inno: infected - 4 skipped

    D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    G:\Back Up Roma\Musica\Generatore di codici per ricariche OMNITEL\Omnitel.exe Infected: not-virus:Hoax.DOS.Omnitel.a skipped

    G:\Back Up Roma\Varie\Audio\RosoftAudioToolsFree.exe/data0015 Infected: not-a-virus:AdWare.Win32.MyWay.ac skipped

    G:\Back Up Roma\Varie\Audio\RosoftAudioToolsFree.exe/data0018 Infected: not-a-virus:AdWare.Win32.180Solutions skipped

    G:\Back Up Roma\Varie\Audio\RosoftAudioToolsFree.exe Inno: infected - 2 skipped

    G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

    H:\autorun.inf Infected: Trojan-PSW.Win32.OnLineGames.skg skipped

    H:\fppg1.exe Infected: Trojan-PSW.Win32.OnLineGames.scx skipped

    Scan process completed.

    Grazie ... anche perchè sto seguendo quello che mi stai facendo fare !
    Ciao Davide ..aspetto notizie.

  10. #10
    Utente di HTML.it L'avatar di Deifobe
    Registrato dal
    Oct 2007
    Messaggi
    6,072
    solo dei backups
    C:\Programmi\RegCleaner\Backups
    (cmq devo ancora controllare gli latri exe che risultano infetti, giusto x sicurezza)

    entra nuovamente nel registro e segui questo percorso:
    HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Explorer\MountPoints2\{f3e20c89-ac75-11dc-b3bc-000d870882f4}

    Clicca su {f3e20c89-ac75-11dc-b3bc-000d870882f4} con il tasto dx del mouse e seleziona "elimina". Poi chiudi il registro e riavvia il pc.

    Le unita' F:\ e G:\ cosa sono?
    ...
    :x:_::_:*:_::_: )(:_:*:_:*:__::_:°FM°:_: )(:_:*:_:x:___

Permessi di invio

  • Non puoi inserire discussioni
  • Non puoi inserire repliche
  • Non puoi inserire allegati
  • Non puoi modificare i tuoi messaggi
  •  
Powered by vBulletin® Version 4.2.1
Copyright © 2026 vBulletin Solutions, Inc. All rights reserved.