Valutazione 4.87/ 5 (100.00%) 5838 voti

Condividi:        

Aiuto per Virus BAGLE

Come rimuovere virus e spyware? Le carte di credito sono davvero sicure in rete? È possibile navigare anonimi? Con quali programmi tutelare la propria privacy? Come proteggere i file importanti? Se volete una risposta a queste e altre domande questo è il luogo giusto!

Moderatori: kadosh, Luke57

Aiuto per Virus BAGLE

Postdi pierrot_lunaire » 04/03/08 20:28

Ho scaricato un .exe da emule e stupidamente lo ho avviato senza prima effettuare una scansione...il risultato??? beh firewall e antivirus non funzionanti. Cosi ho provato a disinstallarli e reinstallarli ma nulla da fare.

Ho scaricare Avenger e fatto la scansione con Kaspersky on line, pero' adesso devo inserire gli script in Avenger.
Mi aiutate? grazie
Pier


martedì 4 marzo 2008 20.16.33
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 4/03/2008
Kaspersky Anti-Virus database records: 547882


Scan Settings
Scan using the following antivirus database standard
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\
F:\
G:\
H:\

Scan Statistics
Total number of scanned objects 36665
Number of viruses found 3
Number of infected objects 11
Number of suspicious objects 0
Duration of the scan process 05:35:18

Infected Object Name Virus Name Last Action
C:\ABC\Installa\Movavi\Crack Movavi Video Converter 6.zip/Setup.exe Infected: Trojan-dropper.Win32.Agent.dkn skipped

C:\ABC\Installa\Movavi\Crack Movavi Video Converter 6.zip ZIP: infected - 1 skipped

C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\utente\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\utente\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\utente\Impostazioni locali\Cronologia\History.IE5\MSHist012008030420080305\index.dat Object is locked skipped

C:\Documents and Settings\utente\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\utente\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\utente\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\utente\ntuser.dat Object is locked skipped

C:\Documents and Settings\utente\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\utente\SOUNDMAN.EXE Infected: Trojan-Downloader.Win32.Bagle.jh skipped

C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe Infected: Trojan-Downloader.Win32.Bagle.jh skipped

C:\Programmi\File comuni\Services\ALuSg.exe Object is locked skipped

C:\Programmi\File comuni\Services\avkS.exe Object is locked skipped

C:\Programmi\File comuni\Services\BDHmhd.exe Object is locked skipped

C:\Programmi\File comuni\Services\cgU.exe Object is locked skipped

C:\Programmi\File comuni\Services\CKs.exe Object is locked skipped

C:\Programmi\File comuni\Services\cyr.exe Object is locked skipped

C:\Programmi\File comuni\Services\CzRs.exe Object is locked skipped

C:\Programmi\File comuni\Services\DHbT.exe Object is locked skipped

C:\Programmi\File comuni\Services\dOf.exe Object is locked skipped

C:\Programmi\File comuni\Services\Efc.exe Object is locked skipped

C:\Programmi\File comuni\Services\epIFq.exe Object is locked skipped

C:\Programmi\File comuni\Services\FRVG.exe Object is locked skipped

C:\Programmi\File comuni\Services\idjsM.exe Object is locked skipped

C:\Programmi\File comuni\Services\Ihg.exe Object is locked skipped

C:\Programmi\File comuni\Services\jZe.exe Object is locked skipped

C:\Programmi\File comuni\Services\Len.exe Object is locked skipped

C:\Programmi\File comuni\Services\LuP.exe Object is locked skipped

C:\Programmi\File comuni\Services\lZhg.exe Object is locked skipped

C:\Programmi\File comuni\Services\oXKxBf.exe Object is locked skipped

C:\Programmi\File comuni\Services\qcvHB.exe Object is locked skipped

C:\Programmi\File comuni\Services\qOnDB.exe Object is locked skipped

C:\Programmi\File comuni\Services\rbg.exe Object is locked skipped

C:\Programmi\File comuni\Services\SxBtiY.exe Object is locked skipped

C:\Programmi\File comuni\Services\TcnAfV.exe Object is locked skipped

C:\Programmi\File comuni\Services\uBn.exe Object is locked skipped

C:\Programmi\File comuni\Services\uFu.exe Object is locked skipped

C:\Programmi\File comuni\Services\VZN.exe Object is locked skipped

C:\Programmi\File comuni\Services\whQ.exe Object is locked skipped

C:\Programmi\File comuni\Services\xHxB.exe Object is locked skipped

C:\Programmi\File comuni\Services\xMgA.exe Object is locked skipped

C:\Programmi\File comuni\Services\xOAi.exe Object is locked skipped

C:\Programmi\File comuni\Services\XQT.exe Object is locked skipped

C:\Programmi\File comuni\Services\yKm.exe Object is locked skipped

C:\Programmi\File comuni\Services\YxUy.exe Object is locked skipped

C:\Programmi\File comuni\Services\ZNE.exe Object is locked skipped

C:\System Volume Information\_restore{7A3BB5F6-0E0E-442F-BB30-0CE7D929E299}\RP1\A0000024.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{7A3BB5F6-0E0E-442F-BB30-0CE7D929E299}\RP2\A0000063.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{7A3BB5F6-0E0E-442F-BB30-0CE7D929E299}\RP2\change.log Object is locked skipped

C:\WINDOWS\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$NtServicePackUninstall$\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$NtUninstallKB826939$\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$NtUninstallKB890859$\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Paramete.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\dvdupgod.exe Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\system32\wintems_exe.vir Infected: Email-Worm.Win32.Bagle.of skipped

C:\WINDOWS\system32\wintems_exe.vir0 Infected: Email-Worm.Win32.Bagle.of skipped

C:\WINDOWS\system32\wintems_exe.vir1 Infected: Email-Worm.Win32.Bagle.of skipped

C:\WINDOWS\TEMP\ASHeuristic\mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped

G:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

Scan process completed.
pierrot_lunaire
Utente Junior
 
Post: 32
Iscritto il: 26/01/06 15:12

Sponsor
 

Re: Aiuto per Virus BAGLE

Postdi Luke57 » 05/03/08 08:32

Ciao, oltre al bagle hai anche il gromozon nel computer.
scarica avenger sul desktop
http://swandog46.geekstogo.com/avenger.zip
Decomprimi l'archivio
Avvia il file avenger.exe
Ti si apre una finestra "View/edit script"
All'interno del box bianco,copia e incolla le scritte seguenti:

Files to delete:
C:\WINDOWS\system32\drivers\hidr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\wintems.exe
C:\WINDOWS\system32\hldrrr.exe
C:\WINDOWS\system32\drivers\pci32.sys
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\WINDOWS\System32\mdelk.exe
C:\ABC\Installa\Movavi\Crack Movavi Video Converter 6.zip
C:\Documents and Settings\utente\SOUNDMAN.EXE
C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programmi\File comuni\Services\ALuSg.exe
C:\Programmi\File comuni\Services\avkS.exe
C:\Programmi\File comuni\Services\BDHmhd.exe
C:\Programmi\File comuni\Services\cgU.exe
C:\Programmi\File comuni\Services\CKs.exe
C:\Programmi\File comuni\Services\cyr.exe
C:\Programmi\File comuni\Services\CzRs.exe
C:\Programmi\File comuni\Services\DHbT.exe
C:\Programmi\File comuni\Services\dOf.exe
C:\Programmi\File comuni\Services\Efc.exe
C:\Programmi\File comuni\Services\epIFq.exe
C:\Programmi\File comuni\Services\FRVG.exe
C:\Programmi\File comuni\Services\idjsM.exe
C:\Programmi\File comuni\Services\Ihg.exe
C:\Programmi\File comuni\Services\jZe.exe
C:\Programmi\File comuni\Services\Len.exe
C:\Programmi\File comuni\Services\LuP.exe
C:\Programmi\File comuni\Services\lZhg.exe
C:\Programmi\File comuni\Services\oXKxBf.exe
C:\Programmi\File comuni\Services\qcvHB.exe
C:\Programmi\File comuni\Services\qOnDB.exe
C:\Programmi\File comuni\Services\rbg.exe
C:\Programmi\File comuni\Services\SxBtiY.exe
C:\Programmi\File comuni\Services\TcnAfV.exe
C:\Programmi\File comuni\Services\uBn.exe
C:\Programmi\File comuni\Services\uFu.exe
C:\Programmi\File comuni\Services\VZN.exe
C:\Programmi\File comuni\Services\whQ.exe
C:\Programmi\File comuni\Services\xHxB.exe
C:\Programmi\File comuni\Services\xMgA.exe
C:\Programmi\File comuni\Services\xOAi.exe
C:\Programmi\File comuni\Services\XQT.exe
C:\Programmi\File comuni\Services\yKm.exe
C:\Programmi\File comuni\Services\YxUy.exe
C:\Programmi\File comuni\Services\ZNE.exe

folders to delete:
C:\WINDOWS\exefnd
C:\WINDOWS\exefld
C:\WINDOWS\system32\drivers\down
C:\Documents and Settings\LocalService\Impostazioni locali\Temporary Internet Files\Content.IE5

registry keys to delete:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
HKLM\SYSTEM\CurrentControlSet\Services\pci32
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32

Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs



Clicca sul pulsante Execute


Il pc dovrebbe riavviarsi da solo, se così non fosse riavvialo manualmente.
Allega poi il log generato da avenger, lo trovi in C:\avenger.txt è un file di testo.

P.S. Se avenger non dovesse funzionare, scaricalo da qui:
http://www.wikifortio.com/630243/AntiBagle.zip

Al riavvio disattiva il ripristino configurazione di sistema (trovi come fare nel forum), scarica questi due files:

scarica questi due tools:

prevx
http://www.prevx.com/gromozon.asp

Tool di rimozione della Symantec:
http://securityresponse.symantec.com/av ... inkopt.exe

Eseguili uno alla volta; disattiva il tuo antivirus durante la scansione.

Quello della prevx fa riavviare il computer e al riavvio viene completata la scansione, al termine della quale viene rilasciato un report che trovi in C:\Gromozon_Removal.log.

Poi esegui il tool della symantec (dalla modalità provvisoria; se
non sai come andarci, premi ripetutamente il tasto F8 all'accensione del computer prima che inizi a caricarsi windows; sulla schermata grigia che appare scegli modalità provvisoria spostandoti con le freccette e premendo invio).

Anche questo tool rilascia un rapporto della scansione nella cartella dove
hai messo il file (Fixlinkopt.log)
Invia anche questo rapporto.
Luke57
Moderatore
 
Post: 6410
Iscritto il: 11/08/05 19:10

Re: Aiuto per Virus BAGLE

Postdi pierrot_lunaire » 05/03/08 10:56

Grazie Luke57 per la risposta,
eseguito script con Avenger:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\kkqixqrs

*******************
Script file located at: \??\C:\Documents and Settings\tcjodfqv.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File C:\WINDOWS\system32\drivers\hidr.exe not found!
Deletion of file C:\WINDOWS\system32\drivers\hidr.exe failed!

Could not process line:
C:\WINDOWS\system32\drivers\hidr.exe
Status: 0xc0000034

File C:\WINDOWS\system32\drivers\srosa.sys deleted successfully.
File C:\WINDOWS\system32\wintems.exe deleted successfully.


File C:\WINDOWS\system32\hldrrr.exe not found!
Deletion of file C:\WINDOWS\system32\hldrrr.exe failed!

Could not process line:
C:\WINDOWS\system32\hldrrr.exe
Status: 0xc0000034



File C:\WINDOWS\system32\drivers\pci32.sys not found!
Deletion of file C:\WINDOWS\system32\drivers\pci32.sys failed!

Could not process line:
C:\WINDOWS\system32\drivers\pci32.sys
Status: 0xc0000034

File C:\WINDOWS\system32\drivers\hldrrr.exe deleted successfully.
File C:\WINDOWS\System32\mdelk.exe deleted successfully.


File C:\ABC\Installa\Movavi\Crack Movavi Video Converter 6.zip not found!
Deletion of file C:\ABC\Installa\Movavi\Crack Movavi Video Converter 6.zip failed!

Could not process line:
C:\ABC\Installa\Movavi\Crack Movavi Video Converter 6.zip
Status: 0xc0000034



File C:\Documents and Settings\utente\SOUNDMAN.EXE not found!
Deletion of file C:\Documents and Settings\utente\SOUNDMAN.EXE failed!

Could not process line:
C:\Documents and Settings\utente\SOUNDMAN.EXE
Status: 0xc0000034

File C:\Programmi\ATI Technologies\ATI Control Panel\atiptaxx.exe deleted successfully.
File C:\Programmi\File comuni\Services\ALuSg.exe deleted successfully.
File C:\Programmi\File comuni\Services\avkS.exe deleted successfully.
File C:\Programmi\File comuni\Services\BDHmhd.exe deleted successfully.
File C:\Programmi\File comuni\Services\cgU.exe deleted successfully.
File C:\Programmi\File comuni\Services\CKs.exe deleted successfully.
File C:\Programmi\File comuni\Services\cyr.exe deleted successfully.
File C:\Programmi\File comuni\Services\CzRs.exe deleted successfully.
File C:\Programmi\File comuni\Services\DHbT.exe deleted successfully.
File C:\Programmi\File comuni\Services\dOf.exe deleted successfully.
File C:\Programmi\File comuni\Services\Efc.exe deleted successfully.
File C:\Programmi\File comuni\Services\epIFq.exe deleted successfully.
File C:\Programmi\File comuni\Services\FRVG.exe deleted successfully.
File C:\Programmi\File comuni\Services\idjsM.exe deleted successfully.
File C:\Programmi\File comuni\Services\Ihg.exe deleted successfully.
File C:\Programmi\File comuni\Services\jZe.exe deleted successfully.
File C:\Programmi\File comuni\Services\Len.exe deleted successfully.
File C:\Programmi\File comuni\Services\LuP.exe deleted successfully.
File C:\Programmi\File comuni\Services\lZhg.exe deleted successfully.
File C:\Programmi\File comuni\Services\oXKxBf.exe deleted successfully.
File C:\Programmi\File comuni\Services\qcvHB.exe deleted successfully.
File C:\Programmi\File comuni\Services\qOnDB.exe deleted successfully.
File C:\Programmi\File comuni\Services\rbg.exe deleted successfully.
File C:\Programmi\File comuni\Services\SxBtiY.exe deleted successfully.
File C:\Programmi\File comuni\Services\TcnAfV.exe deleted successfully.
File C:\Programmi\File comuni\Services\uBn.exe deleted successfully.
File C:\Programmi\File comuni\Services\uFu.exe deleted successfully.
File C:\Programmi\File comuni\Services\VZN.exe deleted successfully.
File C:\Programmi\File comuni\Services\whQ.exe deleted successfully.
File C:\Programmi\File comuni\Services\xHxB.exe deleted successfully.
File C:\Programmi\File comuni\Services\xMgA.exe deleted successfully.
File C:\Programmi\File comuni\Services\xOAi.exe deleted successfully.
File C:\Programmi\File comuni\Services\XQT.exe deleted successfully.
File C:\Programmi\File comuni\Services\yKm.exe deleted successfully.
File C:\Programmi\File comuni\Services\YxUy.exe deleted successfully.
File C:\Programmi\File comuni\Services\ZNE.exe deleted successfully.


Folder C:\WINDOWS\exefnd not found!
Deletion of folder C:\WINDOWS\exefnd failed!

Could not process line:
C:\WINDOWS\exefnd
Status: 0xc0000034



Folder C:\WINDOWS\exefld not found!
Deletion of folder C:\WINDOWS\exefld failed!

Could not process line:
C:\WINDOWS\exefld
Status: 0xc0000034

Folder C:\WINDOWS\system32\drivers\down deleted successfully.
Folder C:\Documents and Settings\LocalService\Impostazioni locali\Temporary Internet Files\Content.IE5 deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA deleted successfully.


Registry key HKLM\SYSTEM\CurrentControlSet\Services\pci32 not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Services\pci32 failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Services\pci32
Status: 0xc0000034



Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32 not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32 failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32
Status: 0xc0000034

Registry value HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs replaced with dummy successfully.

Completed script processing.
*******************
Finished! Terminate.

NOTA: Un paio di virus - MOVAVI e SOUNDMAN li avevo tolti precedentemente a nano.

Scansione con GROMOZOM:

Removal tool loaded into memory
Gromozon rootkit component not detected - searching for other components
Scanning: C:\WINDOWS
Scanning: C:\Programmi\File comuni

Trojan.Gromozon does not exist - your system is clean.

NOTA: IL LINK PER IL TOOL DELLA SYMANTEC NON E' CORRETTO

Grazie di nuovo
pier
pierrot_lunaire
Utente Junior
 
Post: 32
Iscritto il: 26/01/06 15:12

Re: Aiuto per Virus BAGLE

Postdi Luke57 » 05/03/08 11:20

Ciao, con il gromozon preferisco fare un controllo più approfondito:
scarica systemscan da qui http://www.suspectfile.com/systemscan , avvialo, deseleziona l'aggiornamento, vai avanti, seleziona tutte le opzioni e premi su "Scan now". Alla fine della scansione recati in c:\suspectfile, qui troverai un file del tipo data+ora.zip,
caricalo su un sito di hosting (easyshare,sendmefile o affini) senza postarlo perchè è troppo lungo e non entrerebbe in una risposta..
Fornisci il link che ti sarà dato in modo che lo possa vedere.
Luke57
Moderatore
 
Post: 6410
Iscritto il: 11/08/05 19:10

Re: Aiuto per Virus BAGLE

Postdi pierrot_lunaire » 05/03/08 11:38

Grazie Luke57,

scaricato da systemscan, all'avvio mi dice:

Warning you don't have theSeDebugPrivilege, .....etc...will be restart to amministrator group...

Mi e' poco chiaro, io accendo il pc e non ho password ne' scelte di utenti.
Grazie
pier
pierrot_lunaire
Utente Junior
 
Post: 32
Iscritto il: 26/01/06 15:12

Re: Aiuto per Virus BAGLE

Postdi Luke57 » 05/03/08 13:07

Ciao, il gromozon modifica i privilegi. Scarica questo tool:
http://download.bleepingcomputer.com/sU ... estore.exe
eseguilo e poi riavvia. Systemscan dovrebbe essere in grado di funzionare.
Se così non fosse, in questa pagina:
http://www.pcalsicuro.com/main/?p=50
trovi come fare manualmente per riacquisire i privilegi.
Luke57
Moderatore
 
Post: 6410
Iscritto il: 11/08/05 19:10

Re: Aiuto per Virus BAGLE

Postdi pierrot_lunaire » 05/03/08 14:04

riacuistati i privilegi a mano,
scan con systemdisk

Download link: http://w13.easy-share.com/1699771035.html

ciao e grazie
pier
pierrot_lunaire
Utente Junior
 
Post: 32
Iscritto il: 26/01/06 15:12

Re: Aiuto per Virus BAGLE

Postdi pierrot_lunaire » 05/03/08 14:57

Ho trovato una cosa un po' strana girando in proprita' di sistema:

Proprieta' di sistema >>
Avanzate >>
Prestazioni >>
Impostazioni >>
Protezione esecuzione programmi >>
Esecuzione di tutti i programmi e i servizi tranne quelli selezionati (flaggato) >>
DVDFab - The ultimate dvd copy converting burning software (flaggato)

Magari non e' niente ma ....non e' strano che sia l'unico software non protetto?

ciao e grazie
pier
pierrot_lunaire
Utente Junior
 
Post: 32
Iscritto il: 26/01/06 15:12

Re: Aiuto per Virus BAGLE

Postdi Luke57 » 05/03/08 15:46

Ciao, riavvia avenger e inserisci questo script:

Files to delete:
C:\WINDOWS\system32\wintems.exe

folders to delete:
C:\DOCUME~1\utente\IMPOST~1\Temp

registry keys to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
HKLM\SYSTEM\CurrentControlSet\Services\SrvXxa

registry values to delete:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Winlogon\SpecialAccounts\UserList | bcTEmMhlpKvHWfa


premi Execute.

Al riavvio del computer
copia questo codice:

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"drvsyskit"=-
"german.exe"=-


incollalo in un file di testo, salva il file di testo e modifica la sua estensione in .reg
Cliccaci due volte e acconsenti i permessi necessari.

Inoltre da start>esegui>control userpasswords2 (lo digiti nello spazio)>OK

se nella finestra Accoun trovi ancora:
bcTEmMhlpKvHWfa
lo evidenzi e lo elimini
Luke57
Moderatore
 
Post: 6410
Iscritto il: 11/08/05 19:10

Re: Aiuto per Virus BAGLE

Postdi pierrot_lunaire » 05/03/08 17:32

Grazie Luke57,
eseguito come da tue istruzioni molto precise e alla fine cancellato bcTEmMhlpKvHWfa.

ciao
pier
p.s. mi sapresti indicare un buon antivirus per Pc, free?
p.p.s. il caricamento di win all'accensione e' notevolmente migliorato :-)
pierrot_lunaire
Utente Junior
 
Post: 32
Iscritto il: 26/01/06 15:12

Re: Aiuto per Virus BAGLE

Postdi pierrot_lunaire » 08/03/08 13:15

mi ritrovo in c:/ i seguenti files:

boot.ini
Bootfont.bin
IO.SYS
MSDOS.SYS
NTDETECT.COM
ntldr

naturalmente nelle opzioni cartella >> visualizzazioni >>> ho flaggato "non visualizzare cartelle e file nascosti" e "nascondi i file protetti di sistema".

grazie
pier
pierrot_lunaire
Utente Junior
 
Post: 32
Iscritto il: 26/01/06 15:12

Re: Aiuto per Virus BAGLE

Postdi Luke57 » 08/03/08 13:24

Ciao, sono file legittimi di sistema. Opta per antivir personal edition.
Luke57
Moderatore
 
Post: 6410
Iscritto il: 11/08/05 19:10

Re: Aiuto per Virus BAGLE

Postdi pierrot_lunaire » 08/03/08 13:50

grazie,
si, volevo dire che prima del virus non li vedevo >>> ora hanno perso l'attributo nascosto credo.
cmq non mi danno fastidio -:)

grazie
pier
pierrot_lunaire
Utente Junior
 
Post: 32
Iscritto il: 26/01/06 15:12


Torna a Sicurezza e Privacy


Topic correlati a "Aiuto per Virus BAGLE":


Chi c’è in linea

Visitano il forum: Nessuno e 6 ospiti