da trilly80 » mer gen 09, 2008 11:32 am
carissima ste 95, ho seguito alla lettera tutti i tuoi passsaggi, e qui di seguito ti copio e incollo il testo di avenger.
grazie mille per il tuo aiuto, e vorrei chiederti ancora di seguirmi, nel senso che se tutto e' andato a buon fine posso installare un nuovo antivirus?me ne puoi consigliare qualcuno che sia free?
inoltre il riprisitino del computer lo posso riattivare?
da dove vedo se la nostra cosa è andata a buon fine?
scusami per le troppe domandeeeeeee!!!!
mi sei di grande aiuto e voglio capirci di piu' anche per una prox volta (speriamo mai) dove voglio cavarmela da sola...
ma lo script come lo costruisci?
in base a cosa prendi quei file, quelle cartelle?
attendo con ansia le tue riposte, e scusami per prima ...non intendevo affatto offenderti!!
ciao!
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\qftmqqua
*******************
Script file located at: \??\C:\WINDOWS\system32\pkcvlxyr.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\WINDOWS\system32\drivers\hidr.exe not found!
Deletion of file C:\WINDOWS\system32\drivers\hidr.exe failed!
Could not process line:
C:\WINDOWS\system32\drivers\hidr.exe
Status: 0xc0000034
File C:\WINDOWS\system32\drivers\srosa.sys deleted successfully.
File C:\WINDOWS\system32\wintems.exe deleted successfully.
File C:\WINDOWS\system32\hldrrr.exe not found!
Deletion of file C:\WINDOWS\system32\hldrrr.exe failed!
Could not process line:
C:\WINDOWS\system32\hldrrr.exe
Status: 0xc0000034
File C:\WINDOWS\system32\trusted.exe not found!
Deletion of file C:\WINDOWS\system32\trusted.exe failed!
Could not process line:
C:\WINDOWS\system32\trusted.exe
Status: 0xc0000034
File C:\WINDOWS\system32\drivers\pci32.sys not found!
Deletion of file C:\WINDOWS\system32\drivers\pci32.sys failed!
Could not process line:
C:\WINDOWS\system32\drivers\pci32.sys
Status: 0xc0000034
File C:\windows\system32\drivers\hldrrr.exe deleted successfully.
File C:\WINDOWS\system32\drivers\down\2679484.exe deleted successfully.
File C:\WINDOWS\system32\drivers\down\29432109.exe deleted successfully.
File C:\WINDOWS\system32\drivers\down\70921.exe deleted successfully.
File C:\WINDOWS\system32\drivers\down\68718.exe deleted successfully.
File C:\WINDOWS\system32\drivers\down\268062.exe deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temp\NERO13359\Toolbar.exe deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\CD5KVOEC\b64_2[1].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\JKGWKCTA\b64_2[1].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\JKGWKCTA\b64_2[2].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\JKGWKCTA\b64_1[2].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\P7L38EF1\b64_3[1].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\P7L38EF1\b64_2[1].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\P7L38EF1\b64_1[1].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\P7L38EF1\b64_2[2].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\OV0PCKF6\b64_2[1].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\OV0PCKF6\b64_1[1].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\OV0PCKF6\b64_1[2].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\OV0PCKF6\b64_2[2].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\OV0PCKF6\b64_3[1].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\OV0PCKF6\b64_3[2].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\MRU769IZ\b64_1[1].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\CB7JQ819\b64_2[1].jpg deleted successfully.
File C:\Documents and Settings\Trilly\Impostazioni locali\Temporary Internet Files\Content.IE5\CB7JQ819\b64_3[1].jpg deleted successfully.
File C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe deleted successfully.
Folder C:\WINDOWS\exefnd not found!
Deletion of folder C:\WINDOWS\exefnd failed!
Could not process line:
C:\WINDOWS\exefnd
Status: 0xc0000034
Folder C:\WINDOWS\exefld not found!
Deletion of folder C:\WINDOWS\exefld failed!
Could not process line:
C:\WINDOWS\exefld
Status: 0xc0000034
Registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Services\pci32 not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Services\pci32 failed!
Could not process line:
HKLM\SYSTEM\CurrentControlSet\Services\pci32
Status: 0xc0000034
Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32 not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32 failed!
Could not process line:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32
Status: 0xc0000034
Completed script processing.
*******************
Finished! Terminate.