Ciao ragazzi,
il mio pc ha beccato dei virus che ho rimosso molto facilmente con Malwarebytes adesso ho i seguenti problemi:
- la console di rispristino da cd xp non rileva alcun disco rigido, ma a windows accedo tranquillamente
-il pc risulta connesso in rete va su msn e pinga qualsiasi host ma il broswer non naviga anche se le impostazioni di sicurezza e proxy sono a posto
questo è il log di Malwarebytes
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Versione database: 5162
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
21/11/2010 11.25.08
mbam-log-2010-11-21 (11-25-08).txt
Tipo di scansione: Scansione veloce
Elementi esaminati: 145667
Tempo trascorso: 7 minuti, 40 secondi
Processi infetti in memoria: 3
Moduli di memoria infetti: 0
Chiavi di registro infette: 5
Valori di registro infetti: 4
Voci infette nei dati di registro: 1
Cartelle infette: 0
File infetti: 28
Processi infetti in memoria:
C:\WINDOWS\Hqabah.exe (Trojan.FraudPack) -> Unloaded process successfully.
C:\Documents and Settings\Maurizio\Dati applicazioni\Microsoft\svchost.exe (Backdoor.Bot) -> Unloaded process successfully.
C:\Documents and Settings\Maurizio\Dati applicazioni\Microsoft\Windows\shell.exe (Trojan.Shell) -> Failed to unload process.
Moduli di memoria infetti:
(Non sono stati rilevati elementi nocivi)
Chiavi di registro infette:
HKEY_CURRENT_USER\SOFTWARE\MNTK1K67YO (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\U36VRSFLG6 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Internet Settings\Zones\ (Hijack.Zones) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\HJRUDZ5DT2 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Valori di registro infetti:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\mntk1k67yo (Trojan.FraudPack) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\hjrudz5dt2 (Trojan.FraudPack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\svchost (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\load (Trojan.Agent) -> Quarantined and deleted successfully.
Voci infette nei dati di registro:
HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell (Hijack.Shell) -> Bad: (explorer.exe,C:\Documents and Settings\Maurizio\Dati applicazioni\Microsoft\Windows\shell.exe) Good: (Explorer.exe) -> Quarantined and deleted successfully.
Cartelle infette:
(Non sono stati rilevati elementi nocivi)
File infetti:
C:\WINDOWS\Hqabah.exe (Trojan.FraudPack) -> Delete on reboot.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\Hp6.exe (Trojan.FraudPack) -> Delete on reboot.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\tpkcuci.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\Hp0.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\Hp1.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\Hp2.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\Hp3.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\Hp4.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\Hp5.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\Hp7.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\Hp8.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\Hp9.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\Hpz.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\uqeye.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\mswanoexcr.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\WINDOWS\Hqabaa.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\WINDOWS\Hqabab.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\WINDOWS\Hqabac.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\WINDOWS\Hqabad.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\WINDOWS\Hqabae.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\WINDOWS\Hqabaf.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\WINDOWS\Hqabag.exe (Trojan.FraudPack) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Dati applicazioni\Microsoft\stor.cfg (Malware.Trace) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Dati applicazioni\Microsoft\svchost.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Maurizio\Dati applicazioni\Microsoft\Windows\shell.exe (Trojan.Shell) -> Delete on reboot.
C:\Documents and Settings\Maurizio\Impostazioni locali\Temp\dwm.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\Tasks\{22116563-108C-42c0-A7CE-60161B75E508}.job (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\{62C40AA6-4406-467a-A5A5-DFDF1B559B7A}.job (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Vi ringrazio in anticipo e se esiste gia una discussione simile scusatemi ma non sono riuscito a trovarla, nel caso reindirizzatemi per favore....
Saluti a tutti

Rispondi quotando
La vita è fatta a scale, c'è chi scende e c'è chi cade.
Se avrei studiato, avessi imparato. [Cit. Leone di Lernia ] 