Condividi:        

Problemi con BAGLE

Come rimuovere virus e spyware? Le carte di credito sono davvero sicure in rete? È possibile navigare anonimi? Con quali programmi tutelare la propria privacy? Come proteggere i file importanti? Se volete una risposta a queste e altre domande questo è il luogo giusto!

Moderatori: m.paolo, kadosh, Luke57

Problemi con BAGLE

Postdi vlady » 15/03/08 15:24

Ho riscontrato problemi simili a Dreamer83 e Newbie ("non valido per win32").
Ho provveduto a scansionare il PC con Kaspersky (report che accludo), ma non sono in grado di derivarne le directory, i files, le chiavi sulle quali intervenire e come intervenire.
Prima di usare Avenger ecc. ecc. gradirei sapere cosa fare.
Grazie

KASPERSKY ONLINE SCANNER REPORT
Friday, March 14, 2008 2:46:23 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 13/03/2008
Kaspersky Anti-Virus database records: 627505


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
A:\
C:\
D:\
E:\
F:\

Scan Statistics
Total number of scanned objects 126602
Number of viruses found 11
Number of infected objects 33
Number of suspicious objects 0
Duration of the scan process 23:05:38

Infected Object Name Virus Name Last Action
C:\Documents and Settings\Administrator\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\Administrator\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Administrator\Impostazioni locali\Cronologia\History.IE5\MSHist012008031320080314\index.dat Object is locked skipped

C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Microsoft\Feeds Cache\index.dat Object is locked skipped

C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\Administrator\Impostazioni locali\Temp\hpotdd001.log Object is locked skipped

C:\Documents and Settings\Administrator\Impostazioni locali\Temp\~DF96FB.tmp Object is locked skipped

C:\Documents and Settings\Administrator\Impostazioni locali\Temp\~DF9708.tmp Object is locked skipped

C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped

C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\Administrator\ntuser.dat Object is locked skipped

C:\Documents and Settings\Administrator\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\Administrator\UserData\index.dat Object is locked skipped

C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped

C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped

C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Windows NT\MSFax\ActivityLog\InboxLOG.txt Object is locked skipped

C:\Documents and Settings\All Users\Dati applicazioni\Microsoft\Windows NT\MSFax\ActivityLog\OutboxLOG.txt Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Programmi\Hewlett-Packard\Digital Imaging\HPIdeas\common\content.dll Object is locked skipped

C:\Programmi\IncrediMail\bin\IncrediMail_Install.exe Infected: not-a-virus:Downloader.Win32.ImLoader.e skipped

C:\Programmi\TopSearch\ls_update.exe/stream/data0002 Infected: not-a-virus:AdWare.Win32.TopSearch.a skipped

C:\Programmi\TopSearch\ls_update.exe/stream Infected: not-a-virus:AdWare.Win32.TopSearch.a skipped

C:\Programmi\TopSearch\ls_update.exe NSIS: infected - 2 skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP1\A0000127.sys Infected: Trojan-Downloader.Win32.Bagle.kh skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP1\A0000944.sys Infected: Trojan-Downloader.Win32.Bagle.kh skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP1\A0001061.sys Infected: Trojan-Downloader.Win32.Bagle.kh skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP1\A0001079.sys Infected: Trojan-Downloader.Win32.Bagle.kh skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP2\A0001100.sys Infected: Trojan-Downloader.Win32.Bagle.kh skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP2\A0001106.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP2\A0001221.sys Infected: Trojan-Downloader.Win32.Bagle.kh skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP3\A0001257.sys Infected: Trojan-Downloader.Win32.Bagle.kh skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP3\A0001401.exe Infected: Trojan.Win32.Agent.ftz skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP3\A0001402.exe Infected: P2P-Worm.Win32.Archivarius.a skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP4\A0001557.sys Infected: Trojan-Downloader.Win32.Bagle.kh skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP4\A0001558.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP4\A0001559.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP4\A0001561.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP6\A0001781.exe Infected: not-a-virus:FraudTool.Win32.AdvancedCleaner.a skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP7\A0001802.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP8\A0002024.sys Infected: Trojan-Downloader.Win32.Bagle.kh skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP8\A0002026.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP8\A0002027.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP8\A0002028.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP8\A0002042.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP8\change.log Object is locked skipped

C:\WINDOWS\$Aggiornamenti\$hf_mig$\KB890859\SP2QFE\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$Aggiornamenti\$NtServicePackUninstall$\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$Aggiornamenti\$NtUninstallKB890859$\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$hf_mig$\KB929338\SP2QFE\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$hf_mig$\KB931784\SP2QFE\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$NtUninstallKB929338$\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\$NtUninstallKB931784$\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\Driver Cache\i386\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\ModemLog_SoftK56 Data Fax Voice Speakerphone CARP.txt Object is locked skipped

C:\WINDOWS\ServicePackFiles\i386\ntoskrnl.exe Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped

C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\mdelk.exe Infected: Email-Worm.Win32.Bagle.of skipped

C:\WINDOWS\system32\nsinet.exe Infected: not-a-virus:Porn-Dialer.Win32.InstantAccess.be skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

D:\RECYCLER\S-1-5-21-1409082233-362288127-839522115-500\Dd1: Live In the Uk (2008).rar:$DATA/Installer-Crack-Keygen.exe Infected: P2P-Worm.Win32.Archivarius.a skipped

D:\RECYCLER\S-1-5-21-1409082233-362288127-839522115-500\Dd1: Live In the Uk (2008).rar:$DATA CAB: infected - 1 skipped

D:\RECYCLER\S-1-5-21-1409082233-362288127-839522115-500\Dd17.exe Infected: not-a-virus:Downloader.Win32.Keylogger.a skipped

D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

D:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP3\A0001405.exe Infected: Trojan-Downloader.Win32.Bagle.jh skipped

D:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP3\A0001406.exe Infected: Trojan-Downloader.Win32.Bagle.jh skipped

D:\System Volume Information\_restore{357FAD77-0E54-4266-8DDF-F130D2FAF211}\RP8\change.log Object is locked skipped

F:\Knight.exe Infected: Worm.Win32.AutoRun.aul skipped

Scan process completed.
vlady
Newbie
 
Post: 4
Iscritto il: 14/03/08 09:20
Località: IVREA

Sponsor
 

Re: Problemi con BAGLE

Postdi Luke57 » 15/03/08 15:43

Ciao, innanzi tutto prendi questo tool:
http://www.plusexpert.cl/download/AntiKnight.rar
estrai tutti i file in una cartella
inserisci la pendrive nel pc
apri il file AntiKnight
clicca su "buscar y reparar"
poi togli la pendrive e riavvi il pc

Poi scarica avenger sul desktop
http://swandog46.geekstogo.com/avenger.zip
Decomprimi l'archivio
Avvia il file avenger.exe


Ti si apre una finestra "View/edit script"

All'interno del box bianco,copia e incolla le scritte seguenti:

Files to delete:
C:\WINDOWS\system32\drivers\hidr.exe
C:\WINDOWS\system32\drivers\srosa.sys
C:\WINDOWS\system32\wintems.exe
C:\WINDOWS\system32\hldrrr.exe
C:\WINDOWS\system32\trusted.exe
C:\WINDOWS\system32\drivers\pci32.sys
C:\WINDOWS\system32\drivers\hldrrr.exe
C:\Programmi\IncrediMail\bin\IncrediMail_Install.exe
C:\WINDOWS\system32\mdelk.exe
C:\WINDOWS\system32\nsinet.exe

folders to delete:
C:\WINDOWS\exefnd
C:\WINDOWS\exefld
C:\WINDOWS\system32\drivers\down
C:\Documents and Settings\Administrator\Impostazioni locali\Temp
C:\Programmi\TopSearch
C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5

registry keys to delete:
HKLM\SYSTEM\CurrentControlSet\Services\srosa
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
HKLM\SYSTEM\CurrentControlSet\Services\pci32
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32

Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs


Clicca sul pulsante Execute
Il pc dovrebbe riavviarsi da solo, se così non fosse riavvialo manualmente.
Allega poi il log generato da avenger, lo trovi in C:\avenger.txt è un file di testo.


Se avenger non dovesse funzionare scaricalo da qui:
http://www.wikifortio.com/630243/AntiBagle.zip
una volta estratto i file, funziona diversamente:
avvii avenger.exe
Seleziona l'opzione "Input Script Manually"
Clicca sulla lente di ingrandimento

Ti si apre una finestra "View/edit script"
All'interno del box bianco,copia e incolla lo script suddetto.

Clicca sul pulsante Done
Clicca sull'icona del semaforo verde
Rispondi ok e poi yes.
Il pc dovrebbe riavviarsi da solo, se così non fosse riavvialo manualmente.
Allega poi il log generato da avenger, lo trovi in C:\avenger.txt è un file di testo.

Spero di essere stato chiaro
Poi disattiva il ripristino configurazione di sistema, se consulti il forum troverai come fare.
Luke57
Moderatore
 
Post: 6415
Iscritto il: 11/08/05 19:10

Re: Problemi con BAGLE

Postdi vlady » 15/03/08 16:11

OK il computer si è riavviato da solo (e anche la mia tastiera adesso funziona decetemente).
Il file di Avenger è questo:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\kuwcvwkh

*******************

Script file located at: \??\C:\WINDOWS\system32\crbrvrky.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File C:\WINDOWS\system32\drivers\hidr.exe not found!
Deletion of file C:\WINDOWS\system32\drivers\hidr.exe failed!

Could not process line:
C:\WINDOWS\system32\drivers\hidr.exe
Status: 0xc0000034

File C:\WINDOWS\system32\drivers\srosa.sys deleted successfully.
File C:\WINDOWS\system32\wintems.exe deleted successfully.


File C:\WINDOWS\system32\hldrrr.exe not found!
Deletion of file C:\WINDOWS\system32\hldrrr.exe failed!

Could not process line:
C:\WINDOWS\system32\hldrrr.exe
Status: 0xc0000034



File C:\WINDOWS\system32\trusted.exe not found!
Deletion of file C:\WINDOWS\system32\trusted.exe failed!

Could not process line:
C:\WINDOWS\system32\trusted.exe
Status: 0xc0000034



File C:\WINDOWS\system32\drivers\pci32.sys not found!
Deletion of file C:\WINDOWS\system32\drivers\pci32.sys failed!

Could not process line:
C:\WINDOWS\system32\drivers\pci32.sys
Status: 0xc0000034

File C:\WINDOWS\system32\drivers\hldrrr.exe deleted successfully.
File C:\Programmi\IncrediMail\bin\IncrediMail_Install.exe deleted successfully.
File C:\WINDOWS\system32\mdelk.exe deleted successfully.
File C:\WINDOWS\system32\nsinet.exe deleted successfully.


Folder C:\WINDOWS\exefnd not found!
Deletion of folder C:\WINDOWS\exefnd failed!

Could not process line:
C:\WINDOWS\exefnd
Status: 0xc0000034



Folder C:\WINDOWS\exefld not found!
Deletion of folder C:\WINDOWS\exefld failed!

Could not process line:
C:\WINDOWS\exefld
Status: 0xc0000034

Folder C:\WINDOWS\system32\drivers\down deleted successfully.
Folder C:\Documents and Settings\Administrator\Impostazioni locali\Temp deleted successfully.
Folder C:\Programmi\TopSearch deleted successfully.
Folder C:\Documents and Settings\Administrator\Impostazioni locali\Temporary Internet Files\Content.IE5 deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Services\srosa deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA deleted successfully.


Registry key HKLM\SYSTEM\CurrentControlSet\Services\pci32 not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Services\pci32 failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Services\pci32
Status: 0xc0000034



Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32 not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32 failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_PCI32
Status: 0xc0000034



Could not get size of registry value HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs
Replacement with dummy of registry value HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs failed!
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.

Adesso disattivo il ripristino delle configurazioni di sistema, spengo e riavvio.
Poi le riattivo?

Comunque ti ringrazio a lot
vlady
Newbie
 
Post: 4
Iscritto il: 14/03/08 09:20
Località: IVREA

Re: Problemi con BAGLE

Postdi Luke57 » 15/03/08 17:47

Ciao, sì, ritogli il segno di spunta precedentemente immesso. Poi elimini le cartelle di backup in C:\avenger.
Inoltre vai qui:
http://www.zonavirus.com/datos/descarga ... ibagla.asp
scarichi elibagla in fondo alla pagina, spunti la casella "elimina ficheros automaticamente...." e fai una scansione.
Posta il report che trovi in C:\infosat.txt.
Luke57
Moderatore
 
Post: 6415
Iscritto il: 11/08/05 19:10

Re: Problemi con BAGLE

Postdi vlady » 15/03/08 18:40

Ho provveduto a lanciare EliBagle e mi sembra che sia tutto OK.
Ora riesco nuovamente a lanciar nuovi programmi senza che appaia la scritta "non valido per win32".
Mi sono nuovamente dotato di un antivirus e ... ho imparato che prima di scaricare qualcosa da e-mule bisogna fare un minimo di controlli (ad esempio nelle informazioni sul file per vedere se tutte le fonti hanno il nome del file compatibile con quello che si vuole scaricare).
Ti ringrazio per la competenza e la sollecitudine con le quali mi hai seguito.

Ecco il report di Elibagle

Thu Mar 13 14:41:49 2008
EliBagle v11.14 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Acción Directa):
C:\WINDOWS\SYSTEM32\WINTEMS.EXE --> Bagle Acceso Denegado.
C:\WINDOWS\SYSTEM32\BAN_LIST.TXT --> Eliminado Bagle
C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado.
C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado.
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\DATI APPLICAZIONI\M\FLEC006.EXE --> Bagle.dldr Acceso Denegado.
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\DATI APPLICAZIONI\M\LIST.OCT --> Eliminado Bagle
Reinicie para Completar la Limpieza.

Thu Mar 13 14:42:39 2008
EliBagle v11.14 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\
C:\WINDOWS\system32\MDELK.EXE --> Acceso Denegado, Bagle (Reiniciar para completar la Limpieza)

Nº Total de Directorios: 9411
Nº Total de Ficheros: 100753
Nº de Ficheros Analizados: 16376
Nº de Ficheros Infectados: 1
Nº de Ficheros Limpiados: 1

Thu Mar 13 15:23:42 2008
EliBagle v11.14 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Acción Directa):
C:\WINDOWS\SYSTEM32\WINTEMS.EXE --> Bagle Acceso Denegado.
C:\WINDOWS\SYSTEM32\BAN_LIST.TXT --> Eliminado Bagle
C:\WINDOWS\SYSTEM32\DRIVERS\SROSA.SYS --> Bagle (rootkit) Acceso Denegado.
C:\WINDOWS\SYSTEM32\DRIVERS\HLDRRR.EXE --> Bagle.dldr Acceso Denegado.
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\DATI APPLICAZIONI\M\FLEC006.EXE --> Bagle.dldr Acceso Denegado.
Restaurada Clave: "SafeBoot\Minimal y Network"
Reinicie para Completar la Limpieza.

Thu Mar 13 15:24:22 2008
EliBagle v11.14 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\
C:\WINDOWS\system32\MDELK.EXE --> Acceso Denegado, Bagle (Reiniciar para completar la Limpieza)

Nº Total de Directorios: 9385
Nº Total de Ficheros: 101104
Nº de Ficheros Analizados: 16256
Nº de Ficheros Infectados: 1
Nº de Ficheros Limpiados: 1

Sat Mar 15 17:52:38 2008
EliBagle v11.14 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Acción Directa):
C:\WINDOWS\SYSTEM32\BAN_LIST.TXT --> Eliminado Bagle
C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\DATI APPLICAZIONI\M\LIST.OCT --> Eliminado Bagle
Restaurada Clave: "SafeBoot\Minimal y Network"

Sat Mar 15 17:52:52 2008
EliBagle v11.14 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad C:\

Nº Total de Directorios: 9438
Nº Total de Ficheros: 101100
Nº de Ficheros Analizados: 16345
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
vlady
Newbie
 
Post: 4
Iscritto il: 14/03/08 09:20
Località: IVREA

Re: Problemi con BAGLE

Postdi vlady » 15/03/08 19:05

Hoops. Avev dimenticato la scansione relativa a D: :-?
Ma sembra che venga confermato quanto visto prima.
Chiedo scusa, Che farci? Niente, dipende dall'età!
(come si è notato avevo già cercato di usare EliBagle già l'altro giorno, ma senza aver messo in atto tutte le altre azioni non serviva a niente)


Sat Mar 15 18:52:58 2008
EliBagle v11.14 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Acción Directa):
Eliminada Carpeta "%AppData%\M"

Sat Mar 15 18:53:03 2008
EliBagle v11.14 (c)2008 S.G.H. / Satinfo S.L.
----------------------------------------------
Lista de Acciones (por Exploración):
Explorando Unidad D:\

Nº Total de Directorios: 320
Nº Total de Ficheros: 18344
Nº de Ficheros Analizados: 246
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
vlady
Newbie
 
Post: 4
Iscritto il: 14/03/08 09:20
Località: IVREA


Torna a Sicurezza e Privacy


Topic correlati a "Problemi con BAGLE":


Chi c’è in linea

Visitano il forum: Nessuno e 38 ospiti