da pucioletta » mer gen 16, 2008 5:06 pm
Per COMBOFIX mi viene detto che l'applicazione non è valida.
Per il momento sembrano non aprirsi più le antipatiche finestre POP up.
Dato che sono sprovvista di antivirus, ora che dovremmo aver debellato quell'antipatico virus, posso scaricarne uno? Quale mi consigli? Prima avevo NOD32.
aH!!!sono riuscita a lanciare VIRTUMONDOBEGONE e questo è quello che ne deriva: (C'è il log -credo si chiami così- sul mio desktop)
[01/16/2008, 16:57:27] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\chiara\Impostazioni locali\Temporary Internet Files\Content.IE5\HC1XOV3F\VirtumundoBeGone[1].exe" )
[01/16/2008, 16:57:34] - Detected System Information:
[01/16/2008, 16:57:34] - Windows Version: 5.1.2600, Service Pack 2
[01/16/2008, 16:57:34] - Current Username: chiara (Admin)
[01/16/2008, 16:57:34] - Windows is in NORMAL mode.
[01/16/2008, 16:57:34] - Searching for Browser Helper Objects:
[01/16/2008, 16:57:34] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[01/16/2008, 16:57:34] - BHO 2: {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} (SWEETIE Class)
[01/16/2008, 16:57:34] - BHO 3: {2C9C06A0-E32D-4585-AB40-176DD72259C3} ()
[01/16/2008, 16:57:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/16/2008, 16:57:34] - Checking for HKLM\...\Winlogon\Notify\ddcya
[01/16/2008, 16:57:34] - Key not found: HKLM\...\Winlogon\Notify\ddcya, continuing.
[01/16/2008, 16:57:34] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[01/16/2008, 16:57:34] - BHO 5: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[01/16/2008, 16:57:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/16/2008, 16:57:34] - No filename found. Continuing.
[01/16/2008, 16:57:34] - BHO 6: {8A406068-D45C-40B9-A096-38AC717FB608} (CBHOBJObj Object)
[01/16/2008, 16:57:34] - BHO 7: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Guida per l'accesso a Windows Live)
[01/16/2008, 16:57:34] - BHO 8: {A95B2816-1D7E-4561-A202-68C0DE02353A} ()
[01/16/2008, 16:57:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/16/2008, 16:57:34] - Checking for HKLM\...\Winlogon\Notify\hyutszrf
[01/16/2008, 16:57:34] - Found: HKLM\...\Winlogon\Notify\hyutszrf - This is probably Virtumundo.
[01/16/2008, 16:57:34] - Assigning {A95B2816-1D7E-4561-A202-68C0DE02353A} MSEvents Object
[01/16/2008, 16:57:34] - BHO list has been changed! Starting over...
[01/16/2008, 16:57:34] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[01/16/2008, 16:57:34] - BHO 2: {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} (SWEETIE Class)
[01/16/2008, 16:57:34] - BHO 3: {2C9C06A0-E32D-4585-AB40-176DD72259C3} ()
[01/16/2008, 16:57:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/16/2008, 16:57:34] - Checking for HKLM\...\Winlogon\Notify\ddcya
[01/16/2008, 16:57:34] - Key not found: HKLM\...\Winlogon\Notify\ddcya, continuing.
[01/16/2008, 16:57:34] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[01/16/2008, 16:57:34] - BHO 5: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[01/16/2008, 16:57:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/16/2008, 16:57:34] - No filename found. Continuing.
[01/16/2008, 16:57:34] - BHO 6: {8A406068-D45C-40B9-A096-38AC717FB608} (CBHOBJObj Object)
[01/16/2008, 16:57:34] - BHO 7: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Guida per l'accesso a Windows Live)
[01/16/2008, 16:57:34] - BHO 8: {A95B2816-1D7E-4561-A202-68C0DE02353A} (MSEvents Object)
[01/16/2008, 16:57:34] - ALERT: Found MSEvents Object!
[01/16/2008, 16:57:34] - BHO 9: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[01/16/2008, 16:57:34] - BHO 10: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[01/16/2008, 16:57:34] - BHO 11: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (Windows Live Toolbar Helper)
[01/16/2008, 16:57:34] - BHO 12: {dbd9c38e-4ad1-4ab8-a7b4-b13282939059} ()
[01/16/2008, 16:57:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/16/2008, 16:57:34] - Checking for HKLM\...\Winlogon\Notify\mpvpdjmk
[01/16/2008, 16:57:34] - Key not found: HKLM\...\Winlogon\Notify\mpvpdjmk, continuing.
[01/16/2008, 16:57:34] - BHO 13: {F1E96EDC-E0C8-BE98-1F15-C29DBED83B53} (BrowsingAdvisor)
[01/16/2008, 16:57:34] - BHO 14: {FC1B64D9-3499-4791-82D5-AABAC3FAEA45} ()
[01/16/2008, 16:57:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/16/2008, 16:57:34] - Checking for HKLM\...\Winlogon\Notify\urqqrom
[01/16/2008, 16:57:34] - Key not found: HKLM\...\Winlogon\Notify\urqqrom, continuing.
[01/16/2008, 16:57:34] - Finished Searching Browser Helper Objects
[01/16/2008, 16:57:34] - *** Detected MSEvents Object
[01/16/2008, 16:57:34] - Trying to remove MSEvents Object...
[01/16/2008, 16:57:35] - Terminating Process: IEXPLORE.EXE
[01/16/2008, 16:57:35] - Terminating Process: RUNDLL32.EXE
[01/16/2008, 16:57:35] - Disabling Automatic Shell Restart
[01/16/2008, 16:57:35] - Terminating Process: EXPLORER.EXE
[01/16/2008, 16:57:35] - Suspending the NT Session Manager System Service
[01/16/2008, 16:57:35] - Terminating Windows NT Logon/Logoff Manager
[01/16/2008, 16:57:36] - Re-enabling Automatic Shell Restart
[01/16/2008, 16:57:36] - File to disable: C:\WINDOWS\system32\hyutszrf.dll
[01/16/2008, 16:57:36] - Renaming C:\WINDOWS\system32\hyutszrf.dll -> C:\WINDOWS\system32\hyutszrf.dll.vir
[01/16/2008, 16:57:36] - File successfully renamed!
[01/16/2008, 16:57:36] - Removing HKLM\...\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[01/16/2008, 16:57:36] - Removing HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[01/16/2008, 16:57:36] - Adding Kill Bit for ActiveX for GUID: {A95B2816-1D7E-4561-A202-68C0DE02353A}
[01/16/2008, 16:57:36] - Deleting ATLEvents/MSEvents Registry entries
[01/16/2008, 16:57:36] - Removing HKLM\...\Winlogon\Notify\hyutszrf
[01/16/2008, 16:57:36] - Searching for Browser Helper Objects:
[01/16/2008, 16:57:36] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[01/16/2008, 16:57:36] - BHO 2: {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} (SWEETIE Class)
[01/16/2008, 16:57:36] - BHO 3: {2C9C06A0-E32D-4585-AB40-176DD72259C3} ()
[01/16/2008, 16:57:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/16/2008, 16:57:36] - Checking for HKLM\...\Winlogon\Notify\ddcya
[01/16/2008, 16:57:36] - Key not found: HKLM\...\Winlogon\Notify\ddcya, continuing.
[01/16/2008, 16:57:36] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[01/16/2008, 16:57:36] - BHO 5: {7E853D72-626A-48EC-A868-BA8D5E23E045} ()
[01/16/2008, 16:57:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/16/2008, 16:57:36] - No filename found. Continuing.
[01/16/2008, 16:57:36] - BHO 6: {8A406068-D45C-40B9-A096-38AC717FB608} (CBHOBJObj Object)
[01/16/2008, 16:57:36] - BHO 7: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Guida per l'accesso a Windows Live)
[01/16/2008, 16:57:36] - BHO 8: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[01/16/2008, 16:57:36] - BHO 9: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[01/16/2008, 16:57:36] - BHO 10: {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} (Windows Live Toolbar Helper)
[01/16/2008, 16:57:36] - BHO 11: {dbd9c38e-4ad1-4ab8-a7b4-b13282939059} ()
[01/16/2008, 16:57:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/16/2008, 16:57:36] - Checking for HKLM\...\Winlogon\Notify\mpvpdjmk
[01/16/2008, 16:57:36] - Key not found: HKLM\...\Winlogon\Notify\mpvpdjmk, continuing.
[01/16/2008, 16:57:36] - BHO 12: {F1E96EDC-E0C8-BE98-1F15-C29DBED83B53} (BrowsingAdvisor)
[01/16/2008, 16:57:36] - BHO 13: {FC1B64D9-3499-4791-82D5-AABAC3FAEA45} ()
[01/16/2008, 16:57:36] - WARNING: BHO has no default name. Checking for Winlogon reference.
[01/16/2008, 16:57:36] - Checking for HKLM\...\Winlogon\Notify\urqqrom
[01/16/2008, 16:57:36] - Key not found: HKLM\...\Winlogon\Notify\urqqrom, continuing.
[01/16/2008, 16:57:36] - Finished Searching Browser Helper Objects
[01/16/2008, 16:57:36] - Finishing up...
[01/16/2008, 16:57:36] - A restart is needed.
[01/16/2008, 16:57:47] - Attempting to Restart via STOP error (Blue Screen!)