ho un problema con un bagle che non riesco ad eliminare
non vorrei formattare il pc.
vi riporto il log kasperky
se qualcuno puo' aiutarmi ne sarei grato
KASPERSKY ONLINE SCANNER REPORT
Monday, March 03, 2008 6:40:07 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 3/03/2008
Kaspersky Anti-Virus database records: 594132
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
A:\
C:\
D:\
E:\
Scan Statistics
Total number of scanned objects 48354
Number of viruses found 8
Number of infected objects 65
Number of suspicious objects 0
Duration of the scan process 02:08:14
Infected Object Name Virus Name Last Action
C:\Avenger\backup-22.02.2008-20.37.37,51.zip/avenger/temp/ASHeuristic/mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\Avenger\backup-22.02.2008-20.37.37,51.zip ZIP: infected - 1 skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/102296.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/113015.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/14560718.exe Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/14567875.exe Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/14573484.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/29158109.exe Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/42906.exe Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/43740281.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/47734.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/55703.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/58237281.exe Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/58261750.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/70421.exe Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/70796.exe Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/down-ren-129/82687.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/hldrrr.exe-ren-129 Infected: Trojan-Downloader.Win32.Bagle.hi skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/srosa.sys-ren-128 Infected: Trojan-Downloader.Win32.Bagle.iq skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/temp/ASHeuristic/mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip/avenger/wintems.exe-ren-128 Infected: Email-Worm.Win32.Bagle.of skipped
C:\Avenger\backup-22.02.2008-20.49.57,25.zip ZIP: infected - 19 skipped
C:\Avenger\backup-22.02.2008-21.11.18,56.zip/avenger/temp/ASHeuristic/mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\Avenger\backup-22.02.2008-21.11.18,56.zip ZIP: infected - 1 skipped
C:\Avenger\backup.zip/avenger/temp/ASHeuristic/mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\Avenger\backup.zip ZIP: infected - 1 skipped
C:\Avenger\temp\ASHeuristic\mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Amministratore\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Amministratore\Dati applicazioni\Skype\daddo.manu\call256.dbb Object is locked skipped
C:\Documents and Settings\Amministratore\Dati applicazioni\Skype\daddo.manu\callmember256.dbb Object is locked skipped
C:\Documents and Settings\Amministratore\Dati applicazioni\Skype\daddo.manu\contactgroup256.dbb Object is locked skipped
C:\Documents and Settings\Amministratore\Dati applicazioni\Skype\daddo.manu\dyncontent\bundle.dat Object is locked skipped
C:\Documents and Settings\Amministratore\Dati applicazioni\Skype\daddo.manu\index2.dat Object is locked skipped
C:\Documents and Settings\Amministratore\Dati applicazioni\Skype\daddo.manu\profile256.dbb Object is locked skipped
C:\Documents and Settings\Amministratore\Dati applicazioni\Skype\daddo.manu\user1024.dbb Object is locked skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Cronologia\History.IE5\MSHist012008030320080304\index.dat Object is locked skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temp\eraseme_73348.exe Infected: Backdoor.Win32.SdBot.cxo skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\G9QJO5MR\b64_1[1].jpg Infected: Trojan-PSW.Win32.LdPinch.ewq skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\G9QJO5MR\b64_1[2].jpg Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\G9QJO5MR\b64_2[1].jpg Infected: Trojan.Win32.Pakes.bwy skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\G9QJO5MR\b64_2[2].jpg Infected: Trojan.Win32.Pakes.bwy skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\G9QJO5MR\b64_31[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\G9QJO5MR\b64_31[3].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\G9QJO5MR\b64_31[4].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\IAKUVWXG\b64_1[1].jpg Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\IAKUVWXG\b64_1[2].jpg Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\IAKUVWXG\b64_1[3].jpg Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\IAKUVWXG\b64_1[4].jpg Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\IAKUVWXG\b64_1[5].jpg Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\IAKUVWXG\b64_1[6].jpg Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\IAKUVWXG\b64_31[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\IAKUVWXG\b64_31[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\IAKUVWXG\b64_31[3].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\M36DMXSN\b64_1[1].jpg Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\M36DMXSN\b64_1[2].jpg Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\M36DMXSN\b64_2[1].jpg Infected: Trojan.Win32.Pakes.bwy skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\M36DMXSN\b64_2[2].jpg Infected: Trojan.Win32.Pakes.bwy skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\M36DMXSN\b64_31[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\M36DMXSN\b64_31[2].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\M36DMXSN\b64_31[3].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\M36DMXSN\b64_31[4].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\UJZID8OV\b64_1[1].jpg Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\UJZID8OV\b64_1[2].jpg Infected: Trojan-PSW.Win32.Agent.xd skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\UJZID8OV\b64_2[1].jpg Infected: Trojan.Win32.Pakes.bwy skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\UJZID8OV\b64_2[2].jpg Infected: Trojan.Win32.Pakes.bwy skipped
C:\Documents and Settings\Amministratore\Impostazioni locali\Temporary Internet Files\Content.IE5\UJZID8OV\b64_31[1].jpg Infected: Email-Worm.Win32.Bagle.of skipped
C:\Documents and Settings\Amministratore\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Amministratore\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe Infected: Trojan-Downloader.Win32.Bagle.hi skipped
C:\Programmi\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\drivers\hldrrr.exe Infected: Trojan-Downloader.Win32.Bagle.hi skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped
C:\WINDOWS\system32\NTSpool.exe Infected: Backdoor.Win32.SdBot.cxo skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
E:\programmini\mirc621.exe/stream/data0008 Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
E:\programmini\mirc621.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.621 skipped
E:\programmini\mirc621.exe NSIS: infected - 2 skipped
E:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
Scan process completed.
ho disattivato il ripristino automatico
da qui non so piu che fare
vi chiedo cortesemente di aiutarmi
vi ringrazio per il tempo speso
a presto