Pagina 1 di 1

IL WORM BAGLE NON SI ELIMINA

MessaggioInviato: ven gen 04, 2008 7:27 pm
da GIGISGREEN
SALVE A TUTTI, NONOSTANTE ABBIA FATTO LA VOSTRA PROCEDURA AL RIGUARDO DEL WORM BAGLE E, NONOSTANTE MI SIA FATTO AIUTARE DA VOI NEL COMPORRE GLI SCRIPT IN AVENGER, MI SONO ACCORTO , FACENDO UNA NUOVA SCANSIONE CON KASPERSKY CHE IL VIRUS NON è STTO ELIMINATO DEL TUTTO. E' POSSIBILE COMPORRE UN NUOVO SCRIPT IN AVENGER ALLA LUCE DEI RISULTATI DI KASPERSKY?
DI SEGUITO INSERISCO LA SCANSIONE EFFETTUATA :

Friday, January 04, 2008 7:18:09 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 4/01/2008
Kaspersky Anti-Virus database records: 502526


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
E:\

Scan Statistics
Total number of scanned objects 102883
Number of viruses found 3
Number of infected objects 7
Number of suspicious objects 0
Duration of the scan process 01:15:25

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Dati applicazioni\avg7\Log\emc.log Object is locked skipped

C:\Documents and Settings\All Users\Dati applicazioni\Grisoft\Avg7Data\avg7log.log Object is locked skipped

C:\Documents and Settings\All Users\Dati applicazioni\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped

C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\ligu\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\ligu\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\ligu\Impostazioni locali\Dati applicazioni\ApplicationHistory\cli.exe.af01e8cc.ini.inuse Object is locked skipped

C:\Documents and Settings\ligu\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\ligu\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\ligu\Impostazioni locali\Temp\Perflib_Perfdata_354.dat Object is locked skipped

C:\Documents and Settings\ligu\Impostazioni locali\Temp\Perflib_Perfdata_bc4.dat Object is locked skipped

C:\Documents and Settings\ligu\Impostazioni locali\Temp\Perflib_Perfdata_bcc.dat Object is locked skipped

C:\Documents and Settings\ligu\Impostazioni locali\Temp\~DFCDCB.tmp Object is locked skipped

C:\Documents and Settings\ligu\Impostazioni locali\Temp\~DFCDD6.tmp Object is locked skipped

C:\Documents and Settings\ligu\Impostazioni locali\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\ligu\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\ligu\ntuser.dat Object is locked skipped

C:\Documents and Settings\ligu\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Temp\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Temp\History\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Temp\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\System Volume Information\_restore{00228FAC-3D60-4E3D-A9AA-E6622D9240A7}\RP3\A0000346.exe Infected: not-a-virus:Dialer.Win32.InterDialer.a skipped

C:\System Volume Information\_restore{00228FAC-3D60-4E3D-A9AA-E6622D9240A7}\RP3\A0000349.exe Infected: not-a-virus:Dialer.Win32.InterDialer.a skipped

C:\System Volume Information\_restore{00228FAC-3D60-4E3D-A9AA-E6622D9240A7}\RP3\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\ModemLog_Motorola USB Modem.txt Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\config\ACEEvent.evt Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

E:\System Volume Information\_restore{00228FAC-3D60-4E3D-A9AA-E6622D9240A7}\RP3\A0000357.exe/file12 Infected: Trojan.Win32.Inject.ba skipped

E:\System Volume Information\_restore{00228FAC-3D60-4E3D-A9AA-E6622D9240A7}\RP3\A0000357.exe Inno: infected - 1 skipped

E:\System Volume Information\_restore{00228FAC-3D60-4E3D-A9AA-E6622D9240A7}\RP3\A0000359.exe/WISE0018.BIN/cd_clint.dll Infected: not-a-virus:AdWare.Win32.Cydoor skipped

E:\System Volume Information\_restore{00228FAC-3D60-4E3D-A9AA-E6622D9240A7}\RP3\A0000359.exe/WISE0018.BIN Infected: not-a-virus:AdWare.Win32.Cydoor skipped

E:\System Volume Information\_restore{00228FAC-3D60-4E3D-A9AA-E6622D9240A7}\RP3\A0000359.exe WiseSFX: infected - 2 skipped

Scan process completed.
[/b]

MessaggioInviato: ven gen 04, 2008 8:30 pm
da ziofil
C'è un regolamento che dice di non scrivere in maiuscolo!!!Grazie!

MessaggioInviato: ven gen 04, 2008 8:58 pm
da GIGISGREEN
chi mi aiuta a comporre lo script???

MessaggioInviato: ven gen 04, 2008 9:10 pm
da GIGISGREEN
perche nel mio pc non riesco a visualizzare la cartella C:system volume information?

MessaggioInviato: ven gen 04, 2008 10:39 pm
da rescueland
Sono al mio primo messaggio
E' possibile che BAGLE mi impedisca di installare AVENGER ?
Ho provato anche a scaricare il solo Avenger.exe direttamente dal sito dell'ideatore ma non riesco a salvarlo sul pc
Compare una schermata velocissima di di ANTIVIR (che tra l'altro non funziona in quanto disabilitato da BAGLE) e il file non viene salvato o estratto dal file zip

MessaggioInviato: sab gen 05, 2008 8:18 am
da crazy.cat
GIGISGREEN ha scritto:perche nel mio pc non riesco a visualizzare la cartella C:system volume information?

Qualcuno ti aveva detto di disattivare il ripristino della configurazione
http://www.MegaLab.it/forum/viewtopic.p ... 527#317527
basta questo per eliminare quei virus.