Punto informatico Network
Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

bagle: non riesco a eliminarlo

Un virus si è intromesso nel tuo computer? Vuoi navigare in tutta sicurezza? Sono sicure le transazione online? Come impedire a malintenzionati di intromettersi nel tuo pc? Come proteggere i tuoi dati? Qui trovi le risposte a queste ed altre domande

bagle: non riesco a eliminarlo

Messaggioda mikikiki » mar set 04, 2007 11:29 pm

Ho provato seguendo la guida, ma niente, avenger dice che lo ha cancellato ma poi riavvio e si ripresenta

grazie mille per eventuali aiuti

vi do il log di gmer:

GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-09-05 00:22:37
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.13 ----

SSDT \??\C:\WINDOWS\system32\drivers\srosa.sys ZwEnumerateKey <-- ROOTKIT !!!
SSDT \??\C:\WINDOWS\system32\drivers\srosa.sys ZwEnumerateValueKey <-- ROOTKIT !!!
SSDT \??\C:\WINDOWS\system32\drivers\srosa.sys ZwQueryDirectoryFile <-- ROOTKIT !!!
SSDT \??\C:\WINDOWS\system32\drivers\srosa.sys ZwQuerySystemInformation <-- ROOTKIT !!!

---- Devices - GMER 1.0.13 ----

Device \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_READ 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA 89E4C1E8
Device \FileSystem\Ntfs \Ntfs IRP_MJ_PNP 89E4C1E8

---- Processes - GMER 1.0.13 ----

Process C:\WINDOWS\system32\drivers\hidr.exe (*** hidden *** ) 808
Process C:\Documents and Settings\mizkeystudio\Dati applicazioni\m\flec006.exe (*** hidden *** ) 3924

---- Services - GMER 1.0.13 ----

Service C:\WINDOWS\system32\drivers\srosa.sys (*** hidden *** ) [SYSTEM] srosa <-- ROOTKIT !!!

---- EOF - GMER 1.0.13 ----




GMER 1.0.13.12551 - http://www.gmer.net
Autostart scan 2007-09-05 00:22:55
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent@DLLName = Ati2evxx.dll

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
ATI Smart /*ATI Smart*/@ = C:\WINDOWS\system32\ati2sgag.exe
ScsiPort@ = %SystemRoot%\system32\drivers\scsiport.sys
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@SunJavaUpdateSchedC:\Programmi\Java\j2re1.4.2_03\bin\jusched.exe = C:\Programmi\Java\j2re1.4.2_03\bin\jusched.exe
@AVG7_CCC:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP /*file not found*/ = C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP /*file not found*/
@ATICCC"C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay = "C:\Programmi\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
@SoundMAXPnPC:\Programmi\Analog Devices\Core\smax4pnp.exe = C:\Programmi\Analog Devices\Core\smax4pnp.exe
@SoundMAX"C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray = "C:\Programmi\Analog Devices\SoundMAX\Smax4.exe" /tray
@NeroFilterCheckC:\WINDOWS\system32\NeroCheck.exe = C:\WINDOWS\system32\NeroCheck.exe
@JMB36X ConfigureC:\WINDOWS\system32\JMRaidTool.exe boot = C:\WINDOWS\system32\JMRaidTool.exe boot
@QuickTime Task"C:\Programmi\QuickTime\qttask.exe" -atboottime = "C:\Programmi\QuickTime\qttask.exe" -atboottime
@GrooveMonitor"C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe" = "C:\Programmi\Microsoft Office\Office12\GrooveMonitor.exe"

HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@CTFMON.EXEC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@MsnMsgr"C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background = "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
@DAEMON Tools"C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033 = "C:\Programmi\DAEMON Tools\daemon.exe" -lang 1033
@drvsyskitC:\WINDOWS\system32\drivers\hidr.exe = C:\WINDOWS\system32\drivers\hidr.exe
@mule_st_keyC:\Documents and Settings\mizkeystudio\Dati applicazioni\m\flec006.exe = C:\Documents and Settings\mizkeystudio\Dati applicazioni\m\flec006.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad >>>
@WPDShServiceObjC:\WINDOWS\system32\WPDShServiceObj.dll = C:\WINDOWS\system32\WPDShServiceObj.dll
@UPnPMonitorC:\WINDOWS\system32\upnpui.dll = C:\WINDOWS\system32\upnpui.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks@{B5A7F190-DDA6-4420-B3BA-52453494E6CD} = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{32683183-48a0-441b-a342-7c2a440a9478} /*Media Band*/(null) =
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} /*AVG7 Shell Extension*/C:\Programmi\Grisoft\AVG7\avgse.dll = C:\Programmi\Grisoft\AVG7\avgse.dll
@{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} /*AVG7 Find Extension*/C:\Programmi\Grisoft\AVG7\avgse.dll = C:\Programmi\Grisoft\AVG7\avgse.dll
@{5E2121EE-0300-11D4-8D3B-444553540000} /*Catalyst Context Menu extension*/C:\Programmi\ATI Technologies\ATI.ACE\atiacmxx.dll = C:\Programmi\ATI Technologies\ATI.ACE\atiacmxx.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\Programmi\File comuni\Microsoft Shared\Web Folders\MSONSEXT.DLL = C:\Programmi\File comuni\Microsoft Shared\Web Folders\MSONSEXT.DLL
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/C:\Programmi\MSN Messenger\fsshext.8.1.0178.00.dll = C:\Programmi\MSN Messenger\fsshext.8.1.0178.00.dll
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/C:\WINDOWS\System32\twext.dll = C:\WINDOWS\System32\twext.dll
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\system32\extmgr.dll = C:\WINDOWS\system32\extmgr.dll
@{23170F69-40C1-278A-1000-000100020000} /*7-Zip Shell Extension*/C:\Programmi\7-Zip\7-zip.dll = C:\Programmi\7-Zip\7-zip.dll
@{45AC2688-0253-4ED8-97DE-B5370FA7D48A} /*Shell Extension for Malware scanning*/(null) =
@{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BC476F4C-D9D7-4100-8D4E-E043F6DEC409} /*Microsoft Browser Architecture*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} /*OpenOffice.org Column Handler*/"C:\Programmi\OpenOffice.org 2.1\program\shlxthdl.dll" = "C:\Programmi\OpenOffice.org 2.1\program\shlxthdl.dll"
@{087B3AE3-E237-4467-B8DB-5A38AB959AC9} /*OpenOffice.org Infotip Handler*/"C:\Programmi\OpenOffice.org 2.1\program\shlxthdl.dll" = "C:\Programmi\OpenOffice.org 2.1\program\shlxthdl.dll"
@{63542C48-9552-494A-84F7-73AA6A7C99C1} /*OpenOffice.org Property Sheet Handler*/"C:\Programmi\OpenOffice.org 2.1\program\shlxthdl.dll" = "C:\Programmi\OpenOffice.org 2.1\program\shlxthdl.dll"
@{3B092F0C-7696-40E3-A80F-68D74DA84210} /*OpenOffice.org Thumbnail Viewer*/"C:\Programmi\OpenOffice.org 2.1\program\shlxthdl.dll" = "C:\Programmi\OpenOffice.org 2.1\program\shlxthdl.dll"
@{72853161-30C5-4D22-B7F9-0BBC1D38A37E} /*Groove GFS Browser Helper*/C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
@{2A541AE1-5BF6-4665-A8A3-CFA9672E4291} /*Groove GFS Explorer Bar*/C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
@{A449600E-1DC6-4232-B948-9BD794D62056} /*Groove GFS Stub Icon Handler*/C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
@{B5A7F190-DDA6-4420-B3BA-52453494E6CD} /*Groove GFS Stub Execution Hook*/C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
@{6C467336-8281-4E60-8204-430CED96822D} /*Groove GFS Context Menu Handler*/C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
@{387E725D-DC16-4D76-B310-2C93ED4752A0} /*Groove XML Icon Handler*/C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
@{16F3DD56-1AF5-4347-846D-7C10C4192619} /*Groove Explorer Icon Overlay 3 (GFS Folder)*/C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
@{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC} /*Groove Explorer Icon Overlay 2 (GFS Stub)*/C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
@{2916C86E-86A6-43FE-8112-43ABE6BF8DCC} /*Groove Explorer Icon Overlay 4 (GFS Unread Mark)*/C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
@{99FD978C-D287-4F50-827F-B2C658EDA8E7} /*Groove Explorer Icon Overlay 1 (GFS Unread Stub)*/C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
@{920E6DB1-9907-4370-B3A0-BAFC03D81399} /*Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)*/C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Office Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~4\Office12\OLKFSTUB.DLL = C:\PROGRA~1\MICROS~4\Office12\OLKFSTUB.DLL
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/C:\PROGRA~1\MICROS~4\Office12\MLSHEXT.DLL = C:\PROGRA~1\MICROS~4\Office12\MLSHEXT.DLL
@{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C} /*Microsoft Office OneNote Namespace Extension for Windows Desktop Search*/C:\PROGRA~1\MICROS~4\Office12\ONFILTER.DLL = C:\PROGRA~1\MICROS~4\Office12\ONFILTER.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Programmi\Microsoft Office\Office12\msohevi.dll = C:\Programmi\Microsoft Office\Office12\msohevi.dll
@{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} /*Microsoft Office Metadata Handler*/C:\PROGRA~1\FILECO~1\MICROS~1\OFFICE12\msoshext.dll = C:\PROGRA~1\FILECO~1\MICROS~1\OFFICE12\msoshext.dll
@{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} /*Microsoft Office Thumbnail Handler*/C:\PROGRA~1\FILECO~1\MICROS~1\OFFICE12\msoshext.dll = C:\PROGRA~1\FILECO~1\MICROS~1\OFFICE12\msoshext.dll
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{32020A01-506E-484D-A2A8-BE3CF17601C3} /*AlcoholShellEx*/C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll = C:\PROGRA~1\ALCOHO~1\ALCOHO~1\AXShlEx.dll
@{e57ce731-33e8-4c51-8354-bb4de9d215d1} /*Periferiche Plug and Play universali*/C:\WINDOWS\system32\upnpui.dll = C:\WINDOWS\system32\upnpui.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
7-Zip@{23170F69-40C1-278A-1000-000100020000} = C:\Programmi\7-Zip\7-zip.dll
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Programmi\Grisoft\AVG7\avgse.dll
XXX Groove GFS Context Menu Handler XXX@{6C467336-8281-4E60-8204-430CED96822D} = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
7-Zip@{23170F69-40C1-278A-1000-000100020000} = C:\Programmi\7-Zip\7-zip.dll
XXX Groove GFS Context Menu Handler XXX@{6C467336-8281-4E60-8204-430CED96822D} = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Programmi\Grisoft\AVG7\avgse.dll
XXX Groove GFS Context Menu Handler XXX@{6C467336-8281-4E60-8204-430CED96822D} = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll = C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
@{72853161-30C5-4D22-B7F9-0BBC1D38A37E}C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL = C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
@{9030D464-4C02-4ABF-8ECC-5164760863C6}C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll = C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

HKCU\Control Panel\Desktop@SCRNSAVE.EXE = C:\WINDOWS\System32\logon.scr

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://go.microsoft.com/fwlink/?LinkId=69157 = http://go.microsoft.com/fwlink/?LinkId=69157
@Start Pagehttp://go.microsoft.com/fwlink/?LinkId=69157 = http://go.microsoft.com/fwlink/?LinkId=69157
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.google.it/ = http://www.google.it/
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm

HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\PROGRA~1\FILECO~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
grooveLocalGWS@CLSID = C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
its@CLSID = C:\WINDOWS\System32\itss.dll
livecall@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mhtml@CLSID = %SystemRoot%\System32\inetcomm.dll
ms-help@CLSID = C:\Programmi\File comuni\Microsoft Shared\Help\hxds.dll
ms-its@CLSID = C:\WINDOWS\System32\itss.dll
msnim@CLSID = C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll

HKLM\Software\Classes\PROTOCOLS\Handler\wia@CLSID = C:\WINDOWS\System32\wiascr.dll

C:\Documents and Settings\mizkeystudio\Menu Avvio\Programmi\Esecuzione automatica >>>
Adobe Gamma.lnk = Adobe Gamma.lnk
OpenOffice.org 2.1.lnk = OpenOffice.org 2.1.lnk
Ritaglio schermata e avvio di OneNote 2007.lnk = Ritaglio schermata e avvio di OneNote 2007.lnk

C:\Documents and Settings\All Users\Menu Avvio\Programmi\Esecuzione automatica >>>
USRobotics Wireless USB Adapter.lnk = USRobotics Wireless USB Adapter.lnk
Adobe Reader Synchronizer.lnk = Adobe Reader Synchronizer.lnk
Avvio veloce di Adobe Reader.lnk = Avvio veloce di Adobe Reader.lnk

---- EOF - GMER 1.0.13 ----
Avatar utente
mikikiki
Neo Iscritto
Neo Iscritto
 
Messaggi: 10
Iscritto il: mar set 04, 2007 11:25 pm

Messaggioda mikikiki » mer set 05, 2007 8:02 am

inoltre se cerco di fare lo scan online kaspersky non ci riesco perché l'installer mi chiede questa chiave "002e08d9.key" che non trova...

come posso procedere?
Avatar utente
mikikiki
Neo Iscritto
Neo Iscritto
 
Messaggi: 10
Iscritto il: mar set 04, 2007 11:25 pm

Messaggioda mikikiki » mer set 05, 2007 9:10 am

ho eseguito lo script con avenger di nuovo; mi dà al riavvio questo risultato:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\timtxpyb

*******************

Script file located at: \??\C:\Documents and Settings\moylirof.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\WINDOWS\system32\drivers\hidr.exe deleted successfully.
File C:\WINDOWS\system32\drivers\srosa.sys deleted successfully.


File C:\WINDOWS\system32\wintems.exe not found!
Deletion of file C:\WINDOWS\system32\wintems.exe failed!

Could not process line:
C:\WINDOWS\system32\wintems.exe
Status: 0xc0000034



File C:\WINDOWS\system32\hldrrr.exe not found!
Deletion of file C:\WINDOWS\system32\hldrrr.exe failed!

Could not process line:
C:\WINDOWS\system32\hldrrr.exe
Status: 0xc0000034



File C:\WINDOWS\system32\trusted.exe not found!
Deletion of file C:\WINDOWS\system32\trusted.exe failed!

Could not process line:
C:\WINDOWS\system32\trusted.exe
Status: 0xc0000034



File C:\WINDOWS\system32\drivers\pci32.sys not found!
Deletion of file C:\WINDOWS\system32\drivers\pci32.sys failed!

Could not process line:
C:\WINDOWS\system32\drivers\pci32.sys
Status: 0xc0000034



Folder C:\WINDOWS\exefnd not found!
Deletion of folder C:\WINDOWS\exefnd failed!

Could not process line:
C:\WINDOWS\exefnd
Status: 0xc0000034

Folder C:\WINDOWS\exefld deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA deleted successfully.


Registry key HKLM\SYSTEM\CurrentControlSet\Services\pci32 not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Services\pci32 failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Services\pci32
Status: 0xc0000034



Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32 not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32 failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.


--------------------

poi però quando faccio lo scan con gmer mi ridà tutte le voci e ovviamente l'antivirus non viene installato; il mio dubbio è che possa centrare con la voce flec006.exe...

che faccio lo inserisco nello script di avenger?
Avatar utente
mikikiki
Neo Iscritto
Neo Iscritto
 
Messaggi: 10
Iscritto il: mar set 04, 2007 11:25 pm


Messaggioda crazy.cat » mer set 05, 2007 9:13 am

Aggiungi questa riga allo script dei file da eliminare.
C:\Documents and Settings\mizkeystudio\Dati applicazioni\m\flec006.exe
Quando i molti governano, pensano solo a contentar sé stessi, si ha allora la tirannia più balorda e più odiosa: la tirannia mascherata da libertà.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

Messaggioda crazy.cat » mer set 05, 2007 9:16 am

se proprio non riesce lo scan sul sito della kaspersky (riprovaci dopo aver eliminato quel file) prova ad usare questo
http://housecall.trendmicro.com/
Quando i molti governano, pensano solo a contentar sé stessi, si ha allora la tirannia più balorda e più odiosa: la tirannia mascherata da libertà.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

Messaggioda mikikiki » mer set 05, 2007 9:29 am

grazie per le risposte

ho eseguito avenger con questo script:

Codice: Seleziona tutto
Files to delete:
C\WINDOWS\system32\drivers\hidr.exe
C\WINDOWS\system32\drivers\srosa.sys
C\WINDOWS\system32\wintems.exe
C\WINDOWS\system32\hldrrr.exe
C\WINDOWS\system32\trusted.exe
C\WINDOWS\system32\drivers\pci32.sys
C:\Documents and Settings\mizkeystudio\Dati applicazioni\m\flec006.exe

folders to delete:
C\WINDOWS\exefnd
C\WINDOWS\exefld

registry keys to delete:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
HKLM\SYSTEM\CurrentControlSet\Services\pci32
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32


ottengo questo risultato:


Codice: Seleziona tutto
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\fqbkfqeq

*******************

Script file located at: \??\C:\WINDOWS\xasydaxo.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



Could not open file C\WINDOWS\system32\drivers\hidr.exe for deletion
Deletion of file C\WINDOWS\system32\drivers\hidr.exe failed!

Could not process line:
C\WINDOWS\system32\drivers\hidr.exe
Status: 0xc000003a



Could not open file C\WINDOWS\system32\drivers\srosa.sys for deletion
Deletion of file C\WINDOWS\system32\drivers\srosa.sys failed!

Could not process line:
C\WINDOWS\system32\drivers\srosa.sys
Status: 0xc000003a



Could not open file C\WINDOWS\system32\wintems.exe for deletion
Deletion of file C\WINDOWS\system32\wintems.exe failed!

Could not process line:
C\WINDOWS\system32\wintems.exe
Status: 0xc000003a



Could not open file C\WINDOWS\system32\hldrrr.exe for deletion
Deletion of file C\WINDOWS\system32\hldrrr.exe failed!

Could not process line:
C\WINDOWS\system32\hldrrr.exe
Status: 0xc000003a



Could not open file C\WINDOWS\system32\trusted.exe for deletion
Deletion of file C\WINDOWS\system32\trusted.exe failed!

Could not process line:
C\WINDOWS\system32\trusted.exe
Status: 0xc000003a



Could not open file C\WINDOWS\system32\drivers\pci32.sys for deletion
Deletion of file C\WINDOWS\system32\drivers\pci32.sys failed!

Could not process line:
C\WINDOWS\system32\drivers\pci32.sys
Status: 0xc000003a

File C:\Documents and Settings\mizkeystudio\Dati applicazioni\m\flec006.exe deleted successfully.


Could not open folder C\WINDOWS\exefnd for deletion
Deletion of folder C\WINDOWS\exefnd failed!

Could not process line:
C\WINDOWS\exefnd
Status: 0xc000003a



Could not open folder C\WINDOWS\exefld for deletion
Deletion of folder C\WINDOWS\exefld failed!

Could not process line:
C\WINDOWS\exefld
Status: 0xc000003a

Registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA deleted successfully.


Registry key HKLM\SYSTEM\CurrentControlSet\Services\pci32 not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Services\pci32 failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Services\pci32
Status: 0xc0000034



Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32 not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32 failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32
Status: 0xc0000034


Completed script processing.

*******************

Finished!  Terminate.



sto provando a fare lo scan trendmicro, quello di kaspersky non va ancora

Dopo avenger, gmer mi rileva ancora quei file[/code]
Avatar utente
mikikiki
Neo Iscritto
Neo Iscritto
 
Messaggi: 10
Iscritto il: mar set 04, 2007 11:25 pm

Messaggioda crazy.cat » mer set 05, 2007 12:01 pm

I file infetti si ricreano perché non vengono tolti tutti in un colpo solo, ne scappa uno e ne ricrea 5.
Non mi ricordo se trendmicro ti lascia salvare il log della scansione, in caso segnati i nomi dei file infetti e dove si trovano e vanno aggiunti allo script di avenger.
Quando i molti governano, pensano solo a contentar sé stessi, si ha allora la tirannia più balorda e più odiosa: la tirannia mascherata da libertà.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

Messaggioda mikikiki » mer set 05, 2007 12:22 pm

ho usato un po' di tool da voi segnalati, tra cui il cleaner...

Mi pare di essere riuscito a fare qualcosa, ho avviato avenger e cancellato tutti i file (pare), fatto la scansione con gmer che non mi da righe rosse e ri installato antivir

Ad ogni modo grazie per i suggerimenti essenziali

Ora però lo scan con antivir mi da ancora dei file infetti, appena finisce posto il risultato
Avatar utente
mikikiki
Neo Iscritto
Neo Iscritto
 
Messaggi: 10
Iscritto il: mar set 04, 2007 11:25 pm

Messaggioda mikikiki » gio set 06, 2007 1:28 pm

mi pareva di aver eliminato tutto, riinstallato l'antivirus, log di gmer pulito

e invece nulla, al riavvio successivo si ripresenta

mi sa che è una variante più coriacea. Probabilmente saranno presnti dei file infetti che non ho cancellato ancora. Come faccio a trovarli?
Avatar utente
mikikiki
Neo Iscritto
Neo Iscritto
 
Messaggi: 10
Iscritto il: mar set 04, 2007 11:25 pm

Messaggioda mikikiki » gio set 06, 2007 1:40 pm

sono riuscito ainstallare l'antivirus per l'ennesima volta (antivir)

quando faccio lo scan mi trova dei virus in file che non ho mai scaricato! (tipo crack, gioche per il pc ecc.... o almeno i file hanno quei nomi...)

non so più che fare, ho anche eliminato le chiavi di registro come consigliato nella vostra guida, ma quando riavvio puntualmente si ripresenta...
Avatar utente
mikikiki
Neo Iscritto
Neo Iscritto
 
Messaggi: 10
Iscritto il: mar set 04, 2007 11:25 pm

Messaggioda Amantide » gio set 06, 2007 1:45 pm

Se il log di Gmer risulta pulito proviamo a vedere cosa si cela dietro con un altro programma.
Scarica ed avvia Systemscan, spunta tutte le voci e clicca su Scan Now. A scansione terminata trova in C:\suspectfile il file report.txt, comprimilo in un archivio rar o zip ed allegalo qui.
...per volare alto, bisogna saper cadere...
Avatar utente
Amantide
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 8126
Iscritto il: lun feb 06, 2006 4:13 pm
Località: Abruzzo

Messaggioda mikikiki » gio set 06, 2007 6:37 pm

ecco il report
Avatar utente
mikikiki
Neo Iscritto
Neo Iscritto
 
Messaggi: 10
Iscritto il: mar set 04, 2007 11:25 pm

Messaggioda Amantide » gio set 06, 2007 7:20 pm

Questo file, immagino, è uno di quelli che viene segnalato come infetto:
C:\Documents and Settings\mizkeystudio\Dati applicazioni\m\shared\BiblePromise : Scripture Verses for your Daily Bread 2.2 [Patch].zip 709574 bytes hidden from API
Nel registro di sistema si vede un residuo di servizio srosa, direi che è un buon segno, perché se il rootkit era ancora attivo, in teoria il Systemscan non avrebbe potuto vederlo [uhm]
Prova a fare un altra volta la scansione completa dalla modalità provvisoria con antivirus ed anche con CCleaner.
...per volare alto, bisogna saper cadere...
Avatar utente
Amantide
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 8126
Iscritto il: lun feb 06, 2006 4:13 pm
Località: Abruzzo

Messaggioda mikikiki » gio set 13, 2007 9:54 am

niente è tornato

ecco lo scan gmer:



Codice: Seleziona tutto
GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-09-13 10:53:06
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.13 ----

SSDT     \??\C:\WINDOWS\system32\drivers\srosa.sys                                       ZwEnumerateKey             <-- ROOTKIT !!!
SSDT     \??\C:\WINDOWS\system32\drivers\srosa.sys                                       ZwEnumerateValueKey        <-- ROOTKIT !!!
SSDT     \??\C:\WINDOWS\system32\drivers\srosa.sys                                       ZwQueryDirectoryFile       <-- ROOTKIT !!!
SSDT     \??\C:\WINDOWS\system32\drivers\srosa.sys                                       ZwQuerySystemInformation   <-- ROOTKIT !!!

---- Devices - GMER 1.0.13 ----

Device   \FileSystem\Ntfs \Ntfs IRP_MJ_CREATE                                            89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_CLOSE                                             89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_READ                                              89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_WRITE                                             89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_INFORMATION                                 89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_SET_INFORMATION                                   89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_EA                                          89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_SET_EA                                            89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_FLUSH_BUFFERS                                     89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_VOLUME_INFORMATION                          89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_SET_VOLUME_INFORMATION                            89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_DIRECTORY_CONTROL                                 89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_FILE_SYSTEM_CONTROL                               89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_DEVICE_CONTROL                                    89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_SHUTDOWN                                          89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_LOCK_CONTROL                                      89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_CLEANUP                                           89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_SECURITY                                    89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_SET_SECURITY                                      89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_QUERY_QUOTA                                       89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_SET_QUOTA                                         89E4B1E8
Device   \FileSystem\Ntfs \Ntfs IRP_MJ_PNP                                               89E4B1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_CREATE                                          88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_CLOSE                                           88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_READ                                            85962378
Device   \FileSystem\Fastfat \Fat IRP_MJ_WRITE                                           88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_QUERY_INFORMATION                               88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_SET_INFORMATION                                 88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_QUERY_EA                                        88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_SET_EA                                          88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_FLUSH_BUFFERS                                   88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION                        88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION                          88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_DIRECTORY_CONTROL                               88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL                             88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_DEVICE_CONTROL                                  88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_SHUTDOWN                                        88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_LOCK_CONTROL                                    88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_CLEANUP                                         88CCE1E8
Device   \FileSystem\Fastfat \Fat IRP_MJ_PNP                                             88CCE1E8

---- Processes - GMER 1.0.13 ----

Process  C:\WINDOWS\system32\drivers\HIDR.EXE.VIR\exefile\shell\open\ (*** hidden *** )  1164                     
Process  C:\WINDOWS\system32\WINTEMS.EXE.VIRasses\exefile\shell\open? (*** hidden *** )  3724                     

---- Services - GMER 1.0.13 ----

Service  C:\WINDOWS\system32\drivers\srosa.sys (*** hidden *** )                         [SYSTEM] srosa             <-- ROOTKIT !!!

---- EOF - GMER 1.0.13 ----



inserisco in avenger i comandi:

Codice: Seleziona tutto
Files to delete:
C\WINDOWS\system32\drivers\hidr.exe
C\WINDOWS\system32\drivers\srosa.sys
C\WINDOWS\system32\wintems.exe
C\WINDOWS\system32\hldrrr.exe
C\WINDOWS\system32\trusted.exe
C\WINDOWS\system32\drivers\pci32.sys
C:\Documents and Settings\mizkeystudio\Dati applicazioni\m\flec006.exe

folders to delete:
C\WINDOWS\exefnd
C\WINDOWS\exefld

registry keys to delete:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
HKLM\SYSTEM\CurrentControlSet\Services\pci32
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32


ma non mi trova i file da eliminare; effettivamente non li vedo anche se posso visualizzare cartelle e file nascosti. Se cerco questi file con la ricerca non li trovo...

Ho provato elibagla, mi ha cancellato 3 file, ma poi metto gmer e siamo da capo

che fare?
Avatar utente
mikikiki
Neo Iscritto
Neo Iscritto
 
Messaggi: 10
Iscritto il: mar set 04, 2007 11:25 pm

Messaggioda crazy.cat » gio set 13, 2007 1:09 pm

scan online sul sito della kaspersky e posta il risultato finale, evidentemente c'è qualche altro file infetto che ricrea il tutto ogni volta.
Quando i molti governano, pensano solo a contentar sé stessi, si ha allora la tirannia più balorda e più odiosa: la tirannia mascherata da libertà.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

Messaggioda mikikiki » gio set 13, 2007 3:36 pm

ok ecco il report di kaspersky

sembra che i da .exe son diventati .vir...
Avatar utente
mikikiki
Neo Iscritto
Neo Iscritto
 
Messaggi: 10
Iscritto il: mar set 04, 2007 11:25 pm

Messaggioda crazy.cat » gio set 13, 2007 4:40 pm

Disattiva subito il ripristino della configurazione e riavvia il pc
http://www.MegaLab.it/2330
se proprio devi lo riabiliti solo dopo la pulizia completa.

Dai questo script ad avenger e posta il txt che esce dopo il riavvio

Files to delete:
C:\WINDOWS\system32\drivers\hidr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\wintems.exe
C:\WINDOWS\system32\hldrrr.exe
C:\WINDOWS\system32\trusted.exe
C:\WINDOWS\system32\drivers\pci32.sys
C:\Documents and Settings\mizkeystudio\Dati applicazioni\m\flec006.exe
C:\qoobox\Quarantine\C\WINDOWS\system32\drivers\srosa.sys.vir
C:\WINDOWS\exefld\14465421.exe
C:\WINDOWS\system32\drivers\HIDR.EXE.VIR
C:\WINDOWS\system32\WINTEMS.EXE.VIR

folders to delete:
C:\WINDOWS\exefnd
C:\WINDOWS\exefld
C:\Documents and Settings\mizkeystudio\.housecall6.6\Quarantine

registry keys to delete:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
HKLM\SYSTEM\CurrentControlSet\Services\pci32
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32

Alla fine cancella anche la cartella dei backup di avenger

dopo il riavvio prova a reinstallare l'antivirus.
Quando i molti governano, pensano solo a contentar sé stessi, si ha allora la tirannia più balorda e più odiosa: la tirannia mascherata da libertà.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre


Torna a Sicurezza

Chi c’è in linea

Visitano il forum: Nessuno e 7 ospiti

Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising