Ho fatto un a scansione con kaspersky 6 e qualcosa ha eliminato, ma il pc non si accende in modalità provvisoria.
Allego il report di kaspersky online e resto in attesa di un aiuto per debellarlo.
Grazie, pro27
Files to delete:
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\wintems.exe
C:\windows\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\mdelk.exe
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\WinBaglehi23.zip
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\WinBaglehi6.zip
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
Folders to delete:
C:\WINDOWS\system32\drivers\down
Registry keys to delete:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\effnhkxw
*******************
Script file located at: \??\C:\Program Files\xhonchuy.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Could not open file C:\WINDOWS\system32\drivers\srosa.sys for deletion
Deletion of file C:\WINDOWS\system32\drivers\srosa.sys failed!
Could not process line:
C:\WINDOWS\system32\drivers\srosa.sys
Status: 0xc000003a
Could not open file C:\WINDOWS\system32\wintems.exe for deletion
Deletion of file C:\WINDOWS\system32\wintems.exe failed!
Could not process line:
C:\WINDOWS\system32\wintems.exe
Status: 0xc000003a
Could not open file C:\windows\system32\drivers\hldrrr.exe for deletion
Deletion of file C:\windows\system32\drivers\hldrrr.exe failed!
Could not process line:
C:\windows\system32\drivers\hldrrr.exe
Status: 0xc000003a
Could not open file C:\WINDOWS\system32\mdelk.exe for deletion
Deletion of file C:\WINDOWS\system32\mdelk.exe failed!
Could not process line:
C:\WINDOWS\system32\mdelk.exe
Status: 0xc000003a
File C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\WinBaglehi23.zip not found!
Deletion of file C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\WinBaglehi23.zip failed!
Could not process line:
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\WinBaglehi23.zip
Status: 0xc0000034
File C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\WinBaglehi6.zip not found!
Deletion of file C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\WinBaglehi6.zip failed!
Could not process line:
C:\Documents and Settings\All Users\Dati applicazioni\Spybot - Search & Destroy\Recovery\WinBaglehi6.zip
Status: 0xc0000034
File C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe not found!
Deletion of file C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe failed!
Could not process line:
C:\Programmi\Spybot - Search & Destroy\TeaTimer.exe
Status: 0xc0000034
Could not open folder C:\WINDOWS\system32\drivers\down for deletion
Deletion of folder C:\WINDOWS\system32\drivers\down failed!
Could not process line:
C:\WINDOWS\system32\drivers\down
Status: 0xc000003a
Registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa failed!
Could not process line:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
Status: 0xc0000034
Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA failed!
Could not process line:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Status: 0xc0000034
Completed script processing.
*******************
Finished! Terminate.
GMER 1.0.14.14116 - http://www.gmer.net
Rootkit scan 2008-02-04 15:28:56
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT \??\C:\WINNT\system32\drivers\klif.sys (spuper-ptor/Kaspersky Lab) ZwEnumerateKey [0xF3D755B0]
SSDT \??\C:\WINNT\system32\drivers\klif.sys (spuper-ptor/Kaspersky Lab) ZwEnumerateValueKey [0xF3D75660]
SSDT \??\C:\WINNT\system32\drivers\klif.sys (spuper-ptor/Kaspersky Lab) ZwQuerySystemInformation [0xF3D83AD0]
Code \??\C:\WINNT\system32\drivers\klif.sys (spuper-ptor/Kaspersky Lab) FsRtlCheckLockForReadAccess
Code \??\C:\WINNT\system32\drivers\klif.sys (spuper-ptor/Kaspersky Lab) IoIsOperationSynchronous
---- Devices - GMER 1.0.14 ----
Device \FileSystem\Ntfs \Ntfs 87180B60
AttachedDevice \FileSystem\Ntfs \Ntfs klif.sys (spuper-ptor/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Ip kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Tcp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\Udp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
AttachedDevice \Driver\Tcpip \Device\RawIp kl1.sys (Kaspersky Unified Driver/Kaspersky Lab)
---- Modules - GMER 1.0.14 ----
Module _________ F738D000-F73A5000 (98304 bytes)
---- Threads - GMER 1.0.14 ----
Thread 4:136 86E7C330
Thread 4:140 86E7C330
Thread 4:144 86D58F10
Thread 4:148 86D58F10
Thread 4:152 86D58F10
Thread 4:552 86E7C330
Thread 4:764 86E7C330
---- EOF - GMER 1.0.14 ----
pro27 ha scritto:Chiedo scusa credo di aver avuto troppa fretta, sto riscansionando e c'è molta più roba. Aspetta che posto il nuovo log
Visitano il forum: Nessuno e 11 ospiti
megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising