ho scoperto questo forum cercando su internet le soluzioni al mio problema.. e visto la disponibilità nell'aiutare chi è in difficoltà, vi posto il mio problema:
mi sono accorto di avere il computer infetto (lanciando un eseguibile preso da emule...)
ho seguito la guida per bagle e ho lanciato kaspersky online e sucessivamente ho inserito le voci dei file infetti nello script da inserire in avast.
Naturalmente ho prima disabilitato il ripristino automatico di Winxp.
KASPERSKY ONLINE SCANNER REPORTKASPERSKY ONLINE SCANNER REPORT
Saturday, January 19, 2008 9:24:24 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build
2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 19/01/2008
Kaspersky Anti-Virus database records: 523903
Scan Settings
Scan using the following antivirus databaseextended
Scan Archivestrue
Scan Mail Basestrue
Scan TargetMy Computer
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Scan Statistics
Total number of scanned objects135395
Number of viruses found6
Number of infected objects17
Number of suspicious objects0
Duration of the scan process01:48:25
Infected Object NameVirus NameLast Action
C:\System Volume Information\MountPointManagerRemoteDatabase Object is
locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is
locked skipped
E:\Documents and Settings\LocalService\Cookies\index.dat Object is locked
skipped
E:\Documents and Settings\LocalService\Impostazioni
locali\Cronologia\History.IE5\index.dat Object is locked skipped
E:\Documents and Settings\LocalService\Impostazioni locali\Dati
applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
E:\Documents and Settings\LocalService\Impostazioni locali\Dati
applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
E:\Documents and Settings\LocalService\Impostazioni locali\Temporary
Internet Files\Content.IE5\index.dat Object is locked skipped
E:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
E:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked
skipped
E:\Documents and Settings\NetworkService\Impostazioni locali\Dati
applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
E:\Documents and Settings\NetworkService\Impostazioni locali\Dati
applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
E:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked
skipped
E:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked
skipped
E:\Documents and Settings\Stefano\Cookies\index.dat Object is locked
skipped
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent
Kit-1-1-2007\WGA Patcher Permanent
Kit-1-1-2007\keyfinder.exe/data.rar/officekey.exe Infected:
not-a-virus:PSWTool.Win32.RAS.a skipped
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent
Kit-1-1-2007\WGA Patcher Permanent Kit-1-1-2007\keyfinder.exe/data.rar
Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent
Kit-1-1-2007\WGA Patcher Permanent Kit-1-1-2007\keyfinder.exe RarSFX:
infected - 2 skipped
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent
Kit-1-1-2007.rar/WGA Patcher Permanent
Kit-1-1-2007/keyfinder.exe/data.rar/officekey.exe Infected:
not-a-virus:PSWTool.Win32.RAS.a skipped
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent
Kit-1-1-2007.rar/WGA Patcher Permanent Kit-1-1-2007/keyfinder.exe/data.rar
Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent
Kit-1-1-2007.rar/WGA Patcher Permanent Kit-1-1-2007/keyfinder.exe
Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent
Kit-1-1-2007.rar RAR: infected - 3 skipped
E:\Documents and Settings\Stefano\Impostazioni
locali\Cronologia\History.IE5\index.dat Object is locked skipped
E:\Documents and Settings\Stefano\Impostazioni locali\Dati
applicazioni\Ahead\Nero Home\bl.db Object is locked skipped
E:\Documents and Settings\Stefano\Impostazioni locali\Dati
applicazioni\Ahead\Nero Home\is2.db Object is locked skipped
E:\Documents and Settings\Stefano\Impostazioni locali\Dati
applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
E:\Documents and Settings\Stefano\Impostazioni locali\Dati
applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
E:\Documents and Settings\Stefano\Impostazioni locali\Temporary Internet
Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is
locked skipped
E:\Documents and Settings\Stefano\Impostazioni locali\Temporary Internet
Files\Content.IE5\index.dat Object is locked skipped
E:\Documents and Settings\Stefano\NTUSER.DAT Object is locked skipped
E:\Documents and Settings\Stefano\ntuser.dat.LOG Object is locked skipped
E:\Documents and
Settings\Stefano\Pavark\RKCL_SEND\02CD138C7C8B6BA35DE34E14EC6B4C8F.fil
Infected: Trojan-Downloader.Win32.Bagle.ii skipped
E:\Documents and
Settings\Stefano\Pavark\RKCL_SEND\607897A67948E794AD5399673FF0E5D6.fil
Infected: Trojan-Downloader.Win32.Bagle.ii skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is
locked skipped
E:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
E:\WINDOWS\SchedLgU.Txt Object is locked skipped
E:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked
skipped
E:\WINDOWS\Sti_Trace.log Object is locked skipped
E:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
E:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
E:\WINDOWS\system32\CnxDslWz.log Object is locked skipped
E:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
E:\WINDOWS\system32\config\default Object is locked skipped
E:\WINDOWS\system32\config\default.LOG Object is locked skipped
E:\WINDOWS\system32\config\Internet.evt Object is locked skipped
E:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
E:\WINDOWS\system32\config\OSession.evt Object is locked skipped
E:\WINDOWS\system32\config\SAM Object is locked skipped
E:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
E:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
E:\WINDOWS\system32\config\SECURITY Object is locked skipped
E:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
E:\WINDOWS\system32\config\software Object is locked skipped
E:\WINDOWS\system32\config\software.LOG Object is locked skipped
E:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
E:\WINDOWS\system32\config\system Object is locked skipped
E:\WINDOWS\system32\config\system.LOG Object is locked skipped
E:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
E:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
E:\WINDOWS\system32\drivers\fidbox2.dat Object is locked skipped
E:\WINDOWS\system32\drivers\fidbox2.idx Object is locked skipped
E:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
E:\WINDOWS\system32\h323log.txt Object is locked skipped
E:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
E:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
E:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked
skipped
E:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked
skipped
E:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked
skipped
E:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked
skipped
E:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked
skipped
E:\WINDOWS\wiadebug.log Object is locked skipped
E:\WINDOWS\wiaservc.log Object is locked skipped
E:\WINDOWS\WindowsUpdate.log Object is locked skipped
H:\System Volume Information\MountPointManagerRemoteDatabase Object is
locked skipped
I:\Helium.Music.Manager.2007.0.0.5505.WinALL-NoPE.zip/setup/Helium_MM_2007(5505)_setup.exe/data.rar/iexplorehk.dll
Infected: not-a-virus:Monitor.Win32.Perflogger.163 skipped
I:\Helium.Music.Manager.2007.0.0.5505.WinALL-NoPE.zip/setup/Helium_MM_2007(5505)_setup.exe/data.rar/iexplore.exe
Infected: not-a-virus:Monitor.Win32.Perflogger.ad skipped
I:\Helium.Music.Manager.2007.0.0.5505.WinALL-NoPE.zip/setup/Helium_MM_2007(5505)_setup.exe/data.rar/rinst.exe
Infected: not-a-virus:Monitor.Win32.Perflogger.bx skipped
I:\Helium.Music.Manager.2007.0.0.5505.WinALL-NoPE.zip/setup/Helium_MM_2007(5505)_setup.exe/data.rar
Infected: not-a-virus:Monitor.Win32.Perflogger.bx skipped
I:\Helium.Music.Manager.2007.0.0.5505.WinALL-NoPE.zip/setup/Helium_MM_2007(5505)_setup.exe
Infected: not-a-virus:Monitor.Win32.Perflogger.bx skipped
I:\Helium.Music.Manager.2007.0.0.5505.WinALL-NoPE.zip ZIP: infected - 5
skipped
I:\Share\mspass-ITA.zip/mspass/mspass.exe Infected:
not-a-virus:PSWTool.Win32.Messen.e skipped
I:\Share\mspass-ITA.zip ZIP: infected - 1 skipped
I:\System Volume Information\MountPointManagerRemoteDatabase Object is
locked skipped
Scan process completed.
e questo è lo script usato:
Files to delete:
e:\WINDOWS\system32\drivers\hidr.exe
e:\WINDOWS\system32\drivers\srosa.sys
e:\WINDOWS\system32\wintems.exe
e:\WINDOWS\system32\hldrrr.exe
e:\WINDOWS\system32\trusted.exe
e:\WINDOWS\system32\drivers\pci32.sys
e:\WINDOWS\system32\drivers\hldrrr.exe
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent Kit-1-1-2007\WGA Patcher Permanent Kit-1-1-2007\keyfinder.exe/data.rar/officekey.exe
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent Kit-1-1-2007\WGA Patcher Permanent Kit-1-1-2007\keyfinder.exe/data.rar
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent Kit-1-1-2007\WGA Patcher Permanent Kit-1-1-2007\keyfinder.exe
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent Kit-1-1-2007.rar/WGA Patcher Permanent Kit-1-1-2007/keyfinder.exe/data.rar/officekey.exe
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent Kit-1-1-2007.rar/WGA Patcher Permanent Kit-1-1-2007/keyfinder.exe/data.rar
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent Kit-1-1-2007.rar/WGA Patcher Permanent Kit-1-1-2007/keyfinder.exe
E:\Documents and Settings\Stefano\Desktop\WGA Patcher Permanent Kit-1-1-2007.rar
E:\Documents and Settings\Stefano\Pavark\RKCL_SEND\02CD138C7C8B6BA35DE34E14EC6B4C8F.fil
E:\Documents and Settings\Stefano\Pavark\RKCL_SEND\607897A67948E794AD5399673FF0E5D6.fil
folders to delete:
e:\WINDOWS\exefnd
e:\WINDOWS\exefld
e:\WINDOWS\system32\drivers\down
registry keys to delete:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
HKLM\SYSTEM\CurrentControlSet\Services\pci32
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32
al riavvio del pc, era di nuovo infetto!
ieri sera ora ho fatto un'altra scansione:
KASPERSKY ONLINE SCANNER REPORTKASPERSKY ONLINE SCANNER REPORT
Sunday, January 20, 2008 1:47:50 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build
2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 19/01/2008
Kaspersky Anti-Virus database records: 524076
Scan Settings
Scan using the following antivirus databaseextended
Scan Archivestrue
Scan Mail Basestrue
Scan TargetMy Computer
A:\
C:\
D:\
E:\
F:\
G:\
H:\
I:\
J:\
Scan Statistics
Total number of scanned objects136372
Number of viruses found6
Number of infected objects15
Number of suspicious objects0
Duration of the scan process01:49:53
Infected Object NameVirus NameLast Action
C:\System Volume Information\MountPointManagerRemoteDatabase Object is
locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is
locked skipped
E:\avenger\backup-19.01.2008-22.00.24,09.zip/avenger/02CD138C7C8B6BA35DE34E14EC6B4C8F.fil
Infected: Trojan-Downloader.Win32.Bagle.ii skipped
E:\avenger\backup-19.01.2008-22.00.24,09.zip/avenger/607897A67948E794AD5399673FF0E5D6.fil
Infected: Trojan-Downloader.Win32.Bagle.ii skipped
E:\avenger\backup-19.01.2008-22.00.24,09.zip ZIP: infected - 2 skipped
E:\avenger\backup-19.01.2008-22.57.08,26.zip/avenger/keyfinder.exe/data.rar/officekey.exe
Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\avenger\backup-19.01.2008-22.57.08,26.zip/avenger/keyfinder.exe/data.rar
Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\avenger\backup-19.01.2008-22.57.08,26.zip/avenger/keyfinder.exe
Infected: not-a-virus:PSWTool.Win32.RAS.a skipped
E:\avenger\backup-19.01.2008-22.57.08,26.zip ZIP: infected - 3 skipped
E:\Documents and Settings\LocalService\Cookies\index.dat Object is locked
skipped
E:\Documents and Settings\LocalService\Impostazioni
locali\Cronologia\History.IE5\index.dat Object is locked skipped
E:\Documents and Settings\LocalService\Impostazioni locali\Dati
applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
E:\Documents and Settings\LocalService\Impostazioni locali\Dati
applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
E:\Documents and Settings\LocalService\Impostazioni locali\Temporary
Internet Files\Content.IE5\index.dat Object is locked skipped
E:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
E:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked
skipped
E:\Documents and Settings\NetworkService\Impostazioni locali\Dati
applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
E:\Documents and Settings\NetworkService\Impostazioni locali\Dati
applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
E:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked
skipped
E:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked
skipped
E:\Documents and Settings\Stefano\Cookies\index.dat Object is locked
skipped
E:\Documents and Settings\Stefano\Impostazioni
locali\Cronologia\History.IE5\index.dat Object is locked skipped
E:\Documents and Settings\Stefano\Impostazioni
locali\Cronologia\History.IE5\MSHist012008011920080120\index.dat Object is
locked skipped
E:\Documents and Settings\Stefano\Impostazioni locali\Dati
applicazioni\Ahead\Nero Home\bl.db Object is locked skipped
E:\Documents and Settings\Stefano\Impostazioni locali\Dati
applicazioni\Ahead\Nero Home\is2.db Object is locked skipped
E:\Documents and Settings\Stefano\Impostazioni locali\Dati
applicazioni\Microsoft\Feeds Cache\index.dat Object is locked skipped
E:\Documents and Settings\Stefano\Impostazioni locali\Dati
applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
E:\Documents and Settings\Stefano\Impostazioni locali\Dati
applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
E:\Documents and Settings\Stefano\Impostazioni locali\Temporary Internet
Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is
locked skipped
E:\Documents and Settings\Stefano\Impostazioni locali\Temporary Internet
Files\Content.IE5\index.dat Object is locked skipped
E:\Documents and Settings\Stefano\NTUSER.DAT Object is locked skipped
E:\Documents and Settings\Stefano\ntuser.dat.LOG Object is locked skipped
E:\Documents and Settings\Stefano\UserData\index.dat Object is locked
skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is
locked skipped
E:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
E:\WINDOWS\SchedLgU.Txt Object is locked skipped
E:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked
skipped
E:\WINDOWS\Sti_Trace.log Object is locked skipped
E:\WINDOWS\system32\CnxDslWz.log Object is locked skipped
E:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
E:\WINDOWS\system32\config\default Object is locked skipped
E:\WINDOWS\system32\config\default.LOG Object is locked skipped
E:\WINDOWS\system32\config\Internet.evt Object is locked skipped
E:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
E:\WINDOWS\system32\config\OSession.evt Object is locked skipped
E:\WINDOWS\system32\config\SAM Object is locked skipped
E:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
E:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
E:\WINDOWS\system32\config\SECURITY Object is locked skipped
E:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
E:\WINDOWS\system32\config\software Object is locked skipped
E:\WINDOWS\system32\config\software.LOG Object is locked skipped
E:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
E:\WINDOWS\system32\config\system Object is locked skipped
E:\WINDOWS\system32\config\system.LOG Object is locked skipped
E:\WINDOWS\system32\drivers\fidbox.dat Object is locked skipped
E:\WINDOWS\system32\drivers\fidbox.idx Object is locked skipped
E:\WINDOWS\system32\drivers\fidbox2.dat Object is locked skipped
E:\WINDOWS\system32\drivers\fidbox2.idx Object is locked skipped
E:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped
E:\WINDOWS\system32\h323log.txt Object is locked skipped
E:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
E:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
E:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked
skipped
E:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked
skipped
E:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked
skipped
E:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked
skipped
E:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked
skipped
E:\WINDOWS\wiadebug.log Object is locked skipped
E:\WINDOWS\wiaservc.log Object is locked skipped
E:\WINDOWS\WindowsUpdate.log Object is locked skipped
H:\System Volume Information\MountPointManagerRemoteDatabase Object is
locked skipped
I:\Helium.Music.Manager.2007.0.0.5505.WinALL-NoPE.zip/setup/Helium_MM_2007(5505)_setup.exe/data.rar/iexplorehk.dll
Infected: not-a-virus:Monitor.Win32.Perflogger.163 skipped
I:\Helium.Music.Manager.2007.0.0.5505.WinALL-NoPE.zip/setup/Helium_MM_2007(5505)_setup.exe/data.rar/iexplore.exe
Infected: not-a-virus:Monitor.Win32.Perflogger.ad skipped
I:\Helium.Music.Manager.2007.0.0.5505.WinALL-NoPE.zip/setup/Helium_MM_2007(5505)_setup.exe/data.rar/rinst.exe
Infected: not-a-virus:Monitor.Win32.Perflogger.bx skipped
I:\Helium.Music.Manager.2007.0.0.5505.WinALL-NoPE.zip/setup/Helium_MM_2007(5505)_setup.exe/data.rar
Infected: not-a-virus:Monitor.Win32.Perflogger.bx skipped
I:\Helium.Music.Manager.2007.0.0.5505.WinALL-NoPE.zip/setup/Helium_MM_2007(5505)_setup.exe
Infected: not-a-virus:Monitor.Win32.Perflogger.bx skipped
I:\Helium.Music.Manager.2007.0.0.5505.WinALL-NoPE.zip ZIP: infected - 5
skipped
I:\Share\mspass-ITA.zip/mspass/mspass.exe Infected:
not-a-virus:PSWTool.Win32.Messen.e skipped
I:\Share\mspass-ITA.zip ZIP: infected - 1 skipped
I:\System Volume Information\MountPointManagerRemoteDatabase Object is
locked skipped
Scan process completed.
potete aiutarmi con lo script di avenger? sbaglio qualcosa?
Grazie mille