Ho eseguito the avenger mettendogli lo script segnato in quella pagina, ma non tutto è stato trovato e l'antivirus ancora non parte.
Allego il log.
Cos'altro posso fare?
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com
Platform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
No rootkits found!
Error: file "C:\WINDOWS\system32\drivers\srosa.sys" not found!
Deletion of file "C:\WINDOWS\system32\drivers\srosa.sys" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
the object does not exist
File "C:\WINDOWS\system32\wintems.exe" deleted successfully.
Error: file "C:\WINDOWS\system32\drivers\hldrrr.exe" not found!
Deletion of file "C:\WINDOWS\system32\drivers\hldrrr.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
the object does not exist
File "C:\WINDOWS\system32\mdelk.exe" deleted successfully.
File "C:\WINDOWS\system32\drivers\mdelk.exe" deleted successfully.
Folder "C:\WINDOWS\system32\drivers\downld" deleted successfully.
Folder "C:\Documents and Settings\Windows\Dati Applicazioni\m" deleted successfully.
Error: registry key "HKLM\SYSTEM\CurrentControlSet\Services\srosa" not found!
Deletion of registry key "HKLM\SYSTEM\CurrentControlSet\Services\srosa" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
the object does not exist
Error: registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA" not found!
Deletion of registry key "HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
the object does not exist
Completed script processing.
*******************
Finished! Terminate.
GMER 1.0.14.14205 - http://www.gmer.net
Rootkit scan 2008-05-22 19:38:29
Windows 5.1.2600 Service Pack 2
---- Kernel code sections - GMER 1.0.14 ----
? ssxbhbwd.sys Impossibile trovare il file specificato. !
---- Registry - GMER 1.0.14 ----
Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts@Asphodel\x2122 (TrueType) ASPHODEL.TTF
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{65722674-B9C2-332B-D149-74BDEE5E7F39}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{65722674-B9C2-332B-D149-74BDEE5E7F39}@iaonddcnbdhlnjhein 0x6B 0x61 0x65 0x70 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{65722674-B9C2-332B-D149-74BDEE5E7F39}@haapnmbjnicjomhm 0x6B 0x61 0x65 0x70 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8E5C8142-01D0-B92E-D232-9F6FE8C45EB9}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8E5C8142-01D0-B92E-D232-9F6FE8C45EB9}@oaachfjipipngbbbdbndcheboajdjh 0x62 0x61 0x63 0x68 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8E5C8142-01D0-B92E-D232-9F6FE8C45EB9}@oamgpiilmfadpibipamdojhnelkaid 0x6A 0x61 0x64 0x68 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8E5C8142-01D0-B92E-D232-9F6FE8C45EB9}@nagbjeahojjaekpiinjkahljflhl 0x6A 0x61 0x61 0x69 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8E5C8142-01D0-B92E-D232-9F6FE8C45EB9}@eaebpcdobo 0x61 0x61 0x00 0xCD
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{8E5C8142-01D0-B92E-D232-9F6FE8C45EB9}@cabcoj 0x6B 0x62 0x6F 0x68 ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A9AE5B88-6B65-8288-414B-02A3577F6361}
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A9AE5B88-6B65-8288-414B-02A3577F6361}@iadkdhpcioechfhabm 0x6B 0x61 0x62 0x6C ...
Reg HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{A9AE5B88-6B65-8288-414B-02A3577F6361}@hanljoaeeobmfnfa 0x6B 0x61 0x62 0x6C ...
---- EOF - GMER 1.0.14 ----
Visitano il forum: Nessuno e 39 ospiti
megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising