Punto informatico Network
Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

VIRUS BAGLE

Un virus si è intromesso nel tuo computer? Vuoi navigare in tutta sicurezza? Sono sicure le transazione online? Come impedire a malintenzionati di intromettersi nel tuo pc? Come proteggere i tuoi dati? Qui trovi le risposte a queste ed altre domande

VIRUS BAGLE

Messaggioda Ketty86 » gio mar 27, 2008 9:10 am

[cry+] Salve ragazzi anch'io come alcuni di voi sono incappata in questo virus e adesso sono qui a chiede il vostro aiuto. [:-H]

[cry] Vi posto la scansine effettuata online come richiedevate.

Ringrazio anticipatamente , un bacione! [^]

KASPERSKY ONLINE SCANNER REPORT
Thursday, March 20, 2008 12:01:19 AM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 19/03/2008
Kaspersky Anti-Virus database records: 640022


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\
F:\

Scan Statistics
Total number of scanned objects 73992
Number of viruses found 16
Number of infected objects 68
Number of suspicious objects 0
Duration of the scan process 09:59:49

Infected Object Name Virus Name Last Action
C:\Documents and Settings\All Users\Dati applicazioni\Nero\Nero8\Nero BackItUp\Cache\NeroBackItUpScheduler3.log Object is locked skipped

C:\Documents and Settings\ketty86\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\ketty86\Desktop\Mirc\mIRC.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\mirc631.exe/stream/data0014 Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\mirc631.exe/stream Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\mirc631.exe NSIS: infected - 2 skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\Movavi Flash Converter 1.1 KeyGen.exe Infected: Trojan-Downloader.Win32.Bagle.lt skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\NERO13911\Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\~DF7D9D.tmp Object is locked skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\~DF7DB3.tmp Object is locked skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\~freesetup.exe/file01 Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\~freesetup.exe/file02/file01 Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\~freesetup.exe/file02 Infected: not-a-virus:Downloader.Win32.WinFixer.o skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\~freesetup.exe/file18 Infected: not-a-virus:FraudTool.Win32.WinAntiVirus.2006 skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\~freesetup.exe/file44 Infected: not-a-virus:FraudTool.Win32.BestSeller.k skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\~freesetup.exe/file45 Infected: not-a-virus:FraudTool.Win32.BestSeller.a skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\~freesetup.exe/file83 Infected: not-a-virus:Downloader.Win32.WinFixer.x skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temp\~freesetup.exe Inno: infected - 7 skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\ketty86\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\ketty86\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\ketty86\NTUSER.DAT.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Programmi\MessengerSkinner\MessengerSkinner.exe Infected: Trojan-Downloader.Win32.Bagle.lt skipped

C:\Programmi\MessengerSkinner\uninst.exe/stream/data0005 Infected: not-a-virus:AdWare.Win32.NaviPromo.ce skipped

C:\Programmi\MessengerSkinner\uninst.exe/stream Infected: not-a-virus:AdWare.Win32.NaviPromo.ce skipped

C:\Programmi\MessengerSkinner\uninst.exe NSIS: infected - 2 skipped

C:\Programmi\mIRC\mirc.exe Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped

C:\Programmi\mIRC\mirc.exe.BAK Infected: not-a-virus:Client-IRC.Win32.mIRC.631 skipped

C:\Programmi\Nero\Nero8\Nero BackItUp\BIU1.txt Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP154\A0046129.exe Infected: not-a-virus:AdWare.Win32.Trymedia.d skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP154\A0046130.exe Infected: not-a-virus:AdWare.Win32.Trymedia.d skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP155\A0046213.exe Infected: not-a-virus:AdWare.Win32.Trymedia.d skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP202\A0056593.exe Infected: Trojan-Downloader.Win32.Bagle.lt skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP202\A0056642.sys Infected: Trojan-Downloader.Win32.Bagle.lm skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP203\A0056802.sys Infected: Trojan-Downloader.Win32.Bagle.lm skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP203\A0056803.exe Infected: Trojan.Win32.Pakes.ciw skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP204\A0057801.sys Infected: Trojan-Downloader.Win32.Bagle.lm skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP205\A0057831.sys Infected: Trojan-Downloader.Win32.Bagle.lm skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP206\A0057868.sys Infected: Trojan-Downloader.Win32.Bagle.lm skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP206\A0057869.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP206\A0057870.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP207\A0057876.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP207\A0057878.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP207\A0057879.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP207\A0057881.exe Infected: Trojan.Win32.Pakes.ciw skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP207\A0057883.sys Infected: Trojan-Downloader.Win32.Bagle.lm skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP207\A0057895.sys Infected: Trojan-Downloader.Win32.Bagle.lm skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP208\A0057898.sys Infected: Trojan-Downloader.Win32.Bagle.lm skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP208\A0057905.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP208\A0057907.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP208\A0057908.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP208\A0057910.exe Infected: Trojan.Win32.Pakes.ciw skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP208\A0057919.sys Infected: Trojan-Downloader.Win32.Bagle.lm skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP208\A0057920.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP208\A0057921.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP208\A0057970.sys Infected: Trojan-Downloader.Win32.Bagle.lm skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP208\A0057978.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP208\change.log Object is locked skipped

C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntkrnlpa.exe Object is locked skipped

C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntkrnlpa.exe Object is locked skipped

C:\WINDOWS\$NtServicePackUninstall$\ntkrnlpa.exe Object is locked skipped

C:\WINDOWS\$NtUninstallKB885835_0$\ntkrnlpa.exe Object is locked skipped

C:\WINDOWS\$NtUninstallKB890859$\ntkrnlpa.exe Object is locked skipped

C:\WINDOWS\$NtUninstallKB931784$\ntkrnlpa.exe Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\Driver Cache\i386\ntkrnlpa.exe Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\ServicePackFiles\i386\ntkrnlpa.exe Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\LogFiles\WUDF\WUDFTrace.etl Object is locked skipped

C:\WINDOWS\system32\mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\Temp\NSIS_install_msgskinner.exe/stream/data0006 Infected: not-a-virus:AdWare.Win32.NaviPromo.ce skipped

C:\WINDOWS\Temp\NSIS_install_msgskinner.exe/stream Infected: not-a-virus:AdWare.Win32.NaviPromo.ce skipped

C:\WINDOWS\Temp\NSIS_install_msgskinner.exe NSIS: infected - 2 skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

D:\Drivers\DivXPro503.exe/Gain_Trickler.exe Infected: not-a-virus:AdWare.Win32.Gator.3202 skipped

D:\Drivers\DivXPro503.exe Vise: infected - 1 skipped

D:\eMule\Incoming\[APP - ITA] Acca Suite [Primus - Termus - Mantus-p - Certus] updated-fixed 07-2007.rar/setup.exe Infected: P2P-Worm.Win32.Kapucen.b skipped

D:\eMule\Incoming\[APP - ITA] Acca Suite [Primus - Termus - Mantus-p - Certus] updated-fixed 07-2007.rar RAR: infected - 1 skipped

D:\eMule\Temp\004.part/Nero.8.Ultra.Edition.v.8.0.3.0.MULTiLANGUAGE-FiCKDiEBiATCH/nero8-fdb.iso/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe/data0017 Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped

D:\eMule\Temp\004.part/Nero.8.Ultra.Edition.v.8.0.3.0.MULTiLANGUAGE-FiCKDiEBiATCH/nero8-fdb.iso/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped

D:\eMule\Temp\004.part/Nero.8.Ultra.Edition.v.8.0.3.0.MULTiLANGUAGE-FiCKDiEBiATCH/nero8-fdb.iso/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped

D:\eMule\Temp\004.part/Nero.8.Ultra.Edition.v.8.0.3.0.MULTiLANGUAGE-FiCKDiEBiATCH/nero8-fdb.iso Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped

D:\eMule\Temp\004.part RAR: infected - 4 skipped

D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

D:\System Volume Information\_restore{F68AF23F-B683-4086-8B97-BAA541B12186}\RP208\change.log Object is locked skipped

Scan process completed.
Avatar utente
Ketty86
Neo Iscritto
Neo Iscritto
 
Messaggi: 7
Iscritto il: mer mar 19, 2008 11:00 am

Messaggioda crazy.cat » gio mar 27, 2008 9:41 am

Disattiva il ripristino della configurazione su tutti i dischi poi riavvia il pc
http://www.MegaLab.it/2330

Scarica Avenger nuova versione http://swandog46.geekstogo.com/avenger.zip

Se non dovesse funzionare (Applicazione non valida) utilizza questi
http://www.MegaLab.it/forum/viewtopic.p ... 172#325172

Estrailo in una cartella a tua scelta
Esegui il file avenger.exe con la figura di una spada
Ora incolla queste righe nella box bianca che si è aperta:

Codice: Seleziona tutto
Files to delete:
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\wintems.exe
C:\WINDOWS\system32\trusted.exe
C:\windows\system32\drivers\hldrrr.exe
C:\WINDOWS\system32\mdelk.exe
C:\Documents and Settings\ketty86\Impostazioni locali\Temp\Movavi Flash Converter 1.1 KeyGen.exe
C:\Documents and Settings\ketty86\Impostazioni locali\Temp\NERO13911\Toolbar.exe
C:\Documents and Settings\ketty86\Impostazioni locali\Temp\~freesetup.exe
C:\Programmi\MessengerSkinner\MessengerSkinner.exe
C:\Programmi\MessengerSkinner\uninst.exe
C:\WINDOWS\Temp\NSIS_install_msgskinner.exe 
D:\Drivers\DivXPro503.exe
D:\eMule\Incoming\[APP - ITA] Acca Suite [Primus - Termus - Mantus-p - Certus] updated-fixed 07-2007.rar 
D:\eMule\Temp\004.part 

folders to delete:
c:\WINDOWS\system32\drivers\down

registry keys to delete:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA


Togli il segno di spunta dalla voce Scan for Rootkits
Premi il pulsante Execute
Rispondi di Si alle due richieste di Avenger
Adesso il tuo computer dovrebbe riavviarsi, nel caso non succedesse, riavvialo tu manualmente
Al riavvio del computer, copia e incolla qui il contenuto del blocco note che apparirà.

Dopo prova a reinstallare subito l'antivirus e cancella la cartella c:\avenger.

Dovrai, quasi sicuramente, riscaricare i file d'installazione dei programmi di sicurezza perché danneggiati dal virus.
Quando i molti governano, pensano solo a contentar sé stessi, si ha allora la tirannia più balorda e più odiosa: la tirannia mascherata da libertà.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

che succede?

Messaggioda Ketty86 » gio mar 27, 2008 11:18 am

ho provato a fare ciò che mi hai detto, però mi da questo errore e non parte con la pulizia.

Che faccio? io ho copiato e incollato tutte le righe ma nulla.

Aspetto notizie

ERROR: INVALID SCRIPT. A VALID SCRIPT MUST BEGIN WITH A COMMAND DIRECTIVE.
ABORTING EXECUTION.

Purtroppo non riesco ad allegare l'immagine dell'errore.
Avatar utente
Ketty86
Neo Iscritto
Neo Iscritto
 
Messaggi: 7
Iscritto il: mer mar 19, 2008 11:00 am


Re: che succede?

Messaggioda spitfire10 » gio mar 27, 2008 11:45 am

Ketty86 ha scritto:ho provato a fare ciò che mi hai detto, però mi da questo errore e non parte con la pulizia.

Che faccio? io ho copiato e incollato tutte le righe ma nulla.

Aspetto notizie

ERROR: INVALID SCRIPT. A VALID SCRIPT MUST BEGIN WITH A COMMAND DIRECTIVE.
ABORTING EXECUTION.

Purtroppo non riesco ad allegare l'immagine dell'errore.




Ciao, prova più volte, se non riesci utilizza la "vecchia" versione di Avenger, il collegamento è sul post che ti ha inviato Crazy.
Buona fortuna!!
Avatar utente
spitfire10
Senior Member
Senior Member
 
Messaggi: 307
Iscritto il: dom ott 07, 2007 5:26 pm
Località: GORIZIA

Messaggioda Ketty86 » gio mar 27, 2008 12:11 pm

ciao grazie per la risposta avevo già provveduto a scaricare la nuova versione di Avenger nell'apposito link ed era proprio quella che non mi permetteva di fare la pulizia, ma dopo vari tentativi ce l'ho fatta.
Adesso ti posto il risultato:

//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Thu Mar 27 11:00:13 2008

11:00:13: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Thu Mar 27 11:04:34 2008

11:04:34: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Thu Mar 27 11:06:45 2008

11:06:45: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Thu Mar 27 11:07:24 2008

11:07:24: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Thu Mar 27 11:23:04 2008

11:23:04: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Thu Mar 27 11:27:50 2008

11:27:50: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Thu Mar 27 11:30:02 2008

11:30:02: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Thu Mar 27 11:44:12 2008

11:44:12: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////

Platform: Windows XP (build 2600, Service Pack 2)
Thu Mar 27 11:48:02 2008

11:48:02: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!


//////////////////////////////////////////


Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File "C:\WINDOWS\system32\drivers\srosa.sys" deleted successfully.
File "C:\WINDOWS\system32\wintems.exe" deleted successfully.

Error: file "C:\WINDOWS\system32\trusted.exe" not found!
Deletion of file "C:\WINDOWS\system32\trusted.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist

File "C:\windows\system32\drivers\hldrrr.exe" deleted successfully.
File "C:\WINDOWS\system32\mdelk.exe" deleted successfully.
File "C:\Documents and Settings\ketty86\Impostazioni locali\Temp\Movavi Flash Converter 1.1 KeyGen.exe" deleted successfully.
File "C:\Documents and Settings\ketty86\Impostazioni locali\Temp\NERO13911\Toolbar.exe" deleted successfully.
File "C:\Documents and Settings\ketty86\Impostazioni locali\Temp\~freesetup.exe" deleted successfully.
File "C:\Programmi\MessengerSkinner\MessengerSkinner.exe" deleted successfully.
File "C:\Programmi\MessengerSkinner\uninst.exe" deleted successfully.
File "C:\WINDOWS\Temp\NSIS_install_msgskinner.exe" deleted successfully.
File "D:\Drivers\DivXPro503.exe" deleted successfully.
File "D:\eMule\Incoming\[APP - ITA] Acca Suite [Primus - Termus - Mantus-p - Certus] updated-fixed 07-2007.rar" deleted successfully.
File "D:\eMule\Temp\004.part" deleted successfully.
Folder "c:\WINDOWS\system32\drivers\down" deleted successfully.
Registry key "HKLM\SYSTEM\CurrentControlSet\Services\srosa" deleted successfully.
Registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA" deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

Adesso ho installato l'antivirus avg 8, anche se non riesco a scaricare l'aggiornamento dei virus e il programma spybot che ho installato quando il pc era infetto, ancora adesso non mi funziona. Pensi che dovrei disinstallarlo e reinstallare dinuovo spybot? Io avevo in mente di scaricare spyware Doctor, che mi consigli?

Grazie ciao [:)]
Avatar utente
Ketty86
Neo Iscritto
Neo Iscritto
 
Messaggi: 7
Iscritto il: mer mar 19, 2008 11:00 am

Messaggioda Ketty86 » gio mar 27, 2008 12:23 pm

Ho risolto il problema. [^]
[:x] Grazie di cuore a tutti siete magnificiiiiiiii! Un bacioneeeeeeeee!
Avatar utente
Ketty86
Neo Iscritto
Neo Iscritto
 
Messaggi: 7
Iscritto il: mer mar 19, 2008 11:00 am

Messaggioda spitfire10 » gio mar 27, 2008 8:19 pm

Ketty86 ha scritto:Ho risolto il problema. [^]
[:x] Grazie di cuore a tutti siete magnificiiiiiiii! Un bacioneeeeeeeee!



Sono contento che sei riuscita ad eliminare il virus. Quello che posso consigliarti è di dare una passata con CCleaner, per il resto dipende da ciò con cui ti trovi meglio.
Ciao.
Avatar utente
spitfire10
Senior Member
Senior Member
 
Messaggi: 307
Iscritto il: dom ott 07, 2007 5:26 pm
Località: GORIZIA


Torna a Sicurezza

Chi c’è in linea

Visitano il forum: Nessuno e 35 ospiti

Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising