Pagina 1 di 1

Chiedo assistenza per Win32 Bagle

MessaggioInviato: dom feb 03, 2008 1:20 pm
da il Mago di Ot
Gentilissimi redattori di MegaLab,
innanzitutto ringrazio Voi e il Vostro sito per la disponibilità e per l' aiuto.

Ho letto attentamente la Vostra guida, ma non sono sicuro al 100% di cosa includere nello script di avenger, soprattutto in riferimento al passaggio "Nel report di Kaspersky non è detto che sia sempre visibile il rootkit che si nasconde nella cartella C:\WINDOWS\system32\drivers\ includetelo lo stesso nello script. ". Dunque come procedere per l' individuazione ed eliminazione di suddetto rootkit?

Vi riporto lo scan di Kasperky online come ho visto fare ad altri utenti:

Infected Object Name Virus Name Last Action
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\cert8.db Object is locked skipped
C:\Documents and Settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\formhistory.dat Object is locked skipped
C:\Documents and Settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\history.dat Object is locked skipped
C:\Documents and Settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\key3.db Object is locked skipped
C:\Documents and Settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\parent.lock Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\XUL.mfl Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Muestras\HLDRRR.EXE.Muestra EliBagle v10.96 Infected: Trojan-Downloader.Win32.Bagle.jd skipped
C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe Infected: Trojan-Downloader.Win32.Bagle.jd skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Temp\Perflib_Perfdata_5d0.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.

Vi ringrazio anticipatamente per la cortese attenzione.

MessaggioInviato: dom feb 03, 2008 1:33 pm
da crazy.cat
Disattiva il ripristino della configurazione su tutti i dischi poi riavvia il pc
http://www.MegaLab.it/2330

Scarica Avenger http://www.MegaLab.it/forum/viewtopic.p ... 172#325172

Estrailo in una cartella a tua scelta
Esegui il file avenger.exe con la figura di una spada
Metti il pallino su input script manually
Quindi scegli la lente e cliccaci
Ora incolla queste righe nel box bianco che si è aperto:

Codice: Seleziona tutto
Files to delete:
C:\WINDOWS\system32\drivers\hidr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\wintems.exe
C:\WINDOWS\system32\hldrrr.exe
C:\WINDOWS\system32\trusted.exe
C:\WINDOWS\system32\drivers\pci32.sys
C:\windows\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\mdelk.exe
C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe

folders to delete:
c:\WINDOWS\system32\drivers\down
C:\Muestras

registry keys to delete:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA



Adesso devi cliccare su Done in basso nella box
Seleziona il semaforino in alto a destra
Rispondi di Si alle due richieste di Avenger
Adesso il tuo computer dovrebbe riavviarsi, nel caso non succedesse, riavvialo tu manualmente
Al riavvio del computer, copia e incolla qui il contenuto del blocco note che apparirà e prova a reinstallare subito l'antivirus.

MessaggioInviato: dom feb 03, 2008 1:58 pm
da il Mago di Ot
Grazie per la celerità della risposta.
Questo il contenuto del blocco:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\pmchsqpv

*******************

Script file located at: \??\C:\WINDOWS\nuayvnxl.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File C:\WINDOWS\system32\drivers\hidr.exe not found!
Deletion of file C:\WINDOWS\system32\drivers\hidr.exe failed!

Could not process line:
C:\WINDOWS\system32\drivers\hidr.exe
Status: 0xc0000034



File C:\WINDOWS\system32\drivers\srosa.sys not found!
Deletion of file C:\WINDOWS\system32\drivers\srosa.sys failed!

Could not process line:
C:\WINDOWS\system32\drivers\srosa.sys
Status: 0xc0000034



File C:\WINDOWS\system32\wintems.exe not found!
Deletion of file C:\WINDOWS\system32\wintems.exe failed!

Could not process line:
C:\WINDOWS\system32\wintems.exe
Status: 0xc0000034



File C:\WINDOWS\system32\hldrrr.exe not found!
Deletion of file C:\WINDOWS\system32\hldrrr.exe failed!

Could not process line:
C:\WINDOWS\system32\hldrrr.exe
Status: 0xc0000034

MessaggioInviato: dom feb 03, 2008 2:26 pm
da crazy.cat
il Mago di Ot ha scritto:Grazie per la celerità della risposta.
Questo il contenuto del blocco:

Ne manca un pezzo e da quello che si vede non sembra neanche andato a buon fine.

Hai provato a reinstallare l'antivirus?

MessaggioInviato: dom feb 03, 2008 2:30 pm
da il Mago di Ot
Chiedo venia, ecco il pezzo mancante.

File C:\WINDOWS\system32\trusted.exe not found!
Deletion of file C:\WINDOWS\system32\trusted.exe failed!

Could not process line:
C:\WINDOWS\system32\trusted.exe
Status: 0xc0000034



File C:\WINDOWS\system32\drivers\pci32.sys not found!
Deletion of file C:\WINDOWS\system32\drivers\pci32.sys failed!

Could not process line:
C:\WINDOWS\system32\drivers\pci32.sys
Status: 0xc0000034



File C:\windows\system32\drivers\hldrrr.exe not found!
Deletion of file C:\windows\system32\drivers\hldrrr.exe failed!

Could not process line:
C:\windows\system32\drivers\hldrrr.exe
Status: 0xc0000034



File C:\WINDOWS\system32\mdelk.exe not found!
Deletion of file C:\WINDOWS\system32\mdelk.exe failed!

Could not process line:
C:\WINDOWS\system32\mdelk.exe
Status: 0xc0000034

File C:\Programmi\CyberLink\PowerDVD\PDVDServ.exe deleted successfully.
Folder c:\WINDOWS\system32\drivers\down deleted successfully.
Folder C:\Muestras deleted successfully.


Registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
Status: 0xc0000034



Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.


Si, ho appena provato a reinstallare l' antivirus e non sono riuscito.

MessaggioInviato: dom feb 03, 2008 2:35 pm
da ste_95
Devi riscaricare l'installer dell'antivirus perché il worm lo ha corrotto. Neanche così si reinstalla?

MessaggioInviato: dom feb 03, 2008 2:49 pm
da il Mago di Ot
Qualcosa non è andata a buon fine con l' Avenger.
Per sicurezza sto ripetendo la scansione kaspersky online e i virus sono ancora lì.

Il ripristino di sistema l' avevo disattivato esattamente come indicato da http://www.MegaLab.it/articoli.php?id=510

MessaggioInviato: dom feb 03, 2008 4:30 pm
da il Mago di Ot
Posto il nuovo scan effettuato con Kaspersky online

KASPERSKY ONLINE SCANNER REPORT
Sunday, February 03, 2008 4:31:11 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 3/02/2008
Kaspersky Anti-Virus database records: 546359
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
E:\
F:\
G:\
Scan Statistics
Total number of scanned objects 192664
Number of viruses found 1
Number of infected objects 3
Number of suspicious objects 0
Duration of the scan process 01:32:16

Infected Object Name Virus Name Last Action
C:\avenger\backup.zip/avenger/Muestras/HLDRRR.EXE.Muestra EliBagle v10.96 Infected: Trojan-Downloader.Win32.Bagle.jd skipped
C:\avenger\backup.zip/avenger/PDVDServ.exe Infected: Trojan-Downloader.Win32.Bagle.jd skipped
C:\avenger\backup.zip ZIP: infected - 2 skipped
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\cert8.db Object is locked skipped
C:\Documents and Settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\formhistory.dat Object is locked skipped
C:\Documents and Settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\history.dat Object is locked skipped
C:\Documents and Settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\key3.db Object is locked skipped
C:\Documents and Settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\parent.lock Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Cronologia\History.IE5\MSHist012008020320080204\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\Cache\80E48E31d01 Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Mozilla\Firefox\Profiles\pvoz51rr.Il Mago di Ot 2\XUL.mfl Object is locked skipped
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Administrator\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\CSC\00000001 Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Temp\Perflib_Perfdata_5cc.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.dat Object is locked skipped
C:\WINDOWS\system32\drivers\fidbox2.idx Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
F:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.


Non so se sia rilevante ai fini del problema, ad ogni avvio di windows il blocco note si apre con il file desktop.ini contenente
[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787

MessaggioInviato: dom feb 03, 2008 4:33 pm
da ste_95
Scarica Avenger
Estrailo in una cartella a tua scelta
Esegui il file avenger.exe con la figura di una spada
Metti il pallino su input script manually
Quindi scegli la lente e cliccaci
Ora incolla queste righe nella box bianca che si è aperta:

Files to delete:
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\wintems.exe
C:\windows\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\mdelk.exe
C:\avenger\backup.zip

Folders to delete:
C:\WINDOWS\system32\drivers\down

Registry keys to delete:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA


Adesso devi cliccare su Done in basso nella box
Seleziona il semaforino in alto a destra
Rispondi di Si alle due richieste di Avenger
Adesso il tuo computer dovrebbe riavviarsi, nel caso non succedesse, riavvialo tu manualmente
Al riavvio del computer, copia e incolla qui il contenuto del blocco note che apparirà.

Ora, se tutto è andato a buon fine, dovresti riuscire a reinstallare un valido antivirus.

MessaggioInviato: dom feb 03, 2008 4:54 pm
da il Mago di Ot
Questo è il risultato:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\umcwtbbu

*******************

Script file located at: \??\C:\Documents and Settings\ybodygmb.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File C:\WINDOWS\system32\drivers\srosa.sys not found!
Deletion of file C:\WINDOWS\system32\drivers\srosa.sys failed!

Could not process line:
C:\WINDOWS\system32\drivers\srosa.sys
Status: 0xc0000034



File C:\WINDOWS\system32\wintems.exe not found!
Deletion of file C:\WINDOWS\system32\wintems.exe failed!

Could not process line:
C:\WINDOWS\system32\wintems.exe
Status: 0xc0000034



File C:\windows\system32\drivers\hldrrr.exe not found!
Deletion of file C:\windows\system32\drivers\hldrrr.exe failed!

Could not process line:
C:\windows\system32\drivers\hldrrr.exe
Status: 0xc0000034



File C:\WINDOWS\system32\mdelk.exe not found!
Deletion of file C:\WINDOWS\system32\mdelk.exe failed!

Could not process line:
C:\WINDOWS\system32\mdelk.exe
Status: 0xc0000034

File C:\avenger\backup.zip deleted successfully.


Folder C:\WINDOWS\system32\drivers\down not found!
Deletion of folder C:\WINDOWS\system32\drivers\down failed!

Could not process line:
C:\WINDOWS\system32\drivers\down
Status: 0xc0000034



Registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
Status: 0xc0000034



Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.

MessaggioInviato: dom feb 03, 2008 4:55 pm
da ste_95
Riscarica gli installer dei programmi di sicurezza e prova a reinstallare un antivirus.

PS. Non sembra avessi il Bagle...

MessaggioInviato: dom feb 03, 2008 5:15 pm
da il Mago di Ot
Sono appena riuscito ad reinstallare l' antivirus.

Ringrazio tutti per il cortese aiuto.

Mi sono rimasti un paio di dubbi.. Credevo che il problema fosse "Trojan-Downloader.Win32.Bagle.jd", quindi il Bagle, se non era lui, cos'era?

Non riesco a capire perché all' avvio si continua ad parire il blocco note con la stringa "[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787"

Con quali programmi si suggerite di fare un' analisi approfondita del sistema?

MessaggioInviato: dom feb 03, 2008 5:19 pm
da ste_95
Verifica che nella cartella di esecuzione automatica non vi sia un file desktop.ini.

Ripristina la modalità provvisoria utilizzando questo file.