purtroppo nessun software mi riesce a togliere stà...
mi date una mano,non ho voglia di riformattare...
ciau e grasie in anticipo

Moderatori: m.paolo, kadosh, Luke57
Logfile of HijackThis v1.99.0
Scan saved at 17.53.08, on 13/01/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\Sygate\SPF\smc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
C:\Programmi\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programmi\Messenger Plus! 3\MsgPlus.exe
C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
C:\Programmi\Windows Media Player\wmplayer.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Programmi\WinRAR\WinRAR.exe
C:\DOCUME~1\SUPERD~1\IMPOST~1\Temp\Rar$EX00.943\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yaqvbgmsgrjo.com/3mXPKNJ3gdWixUUgKIVsny6Mplk3DhCqoYoyWYvAbL8BTsb7glJPPRqN6eqtz2wO.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programmi\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O23 - Service: avast! iAVS4 Control Service - Unknown - C:\Programmi\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown - C:\Programmi\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Programmi\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: Sygate Personal Firewall Pro - Sygate Technologies, Inc. - C:\Programmi\Sygate\SPF\smc.exe
Bandolero stanco ha scritto:cmq avevo detto che ne ad-aware ne Spy-bot ne nessun software riusciva...perciò...
Newbold.exe
Real Base.exe
REALBA...(aveva un estensione lunghissima).exe
ArchiveData(3.bckp)
Referencefile : SE1R25 11.01.2005
======================================================
WIN32.TROJANDOWNLOADER.SWIZZOR.BR
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=Process : c:\docume~1\superd~1\impost~1\temp\
ArchiveData(3.bckp)
Referencefile : SE1R25 11.01.2005
======================================================
WIN32.TROJANDOWNLOADER.SWIZZOR.BR
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=Process : c:\docume~1\superd~1\impost~1\temp\ceyludrn.exe
Bandolero stanco ha scritto:il sito http://www.scanspyware.net/info/Win32.Swizzor.br.htm
non và...
Delete the following directories:
Win32.Swizzor.br does not create any directories
Delete the following files:
sta33.exe
sta3c.exe
sta3d.exe
eqstupid.exe
ford bore date.exe
kbelhpmz.exe
lsfjwaej.exe
winsaveaboutpoll.exe
zkumfamz.exe
fork error default.exe
intrastop.exe
bytemess.exe
xyq.exe
exit show.exe
browse glue.exe
debug platform one.exe
1 jugs default.exe
bookslow.exe
sect meow.exe
Delete the following Cookies:
Win32.Swizzor.br does not create any cookies
Delete the following registry keys:
Win32.Swizzor.br does not create any registry keys
Delete the following registry values:
16 web
cash mess
exit bags
fileflap
fragmeta
memo
remotecreative
support two
surfgrid
xpmmsilauncher.exe ,non è una applicazione di win32 valida Autore: alidoro |
Forum: Sistemi Operativi Windows Risposte: 1 |
xpmmsilauncher.exe ,non è una applicazione di win32 valida Autore: alidoro |
Forum: Sistemi Operativi Windows Risposte: 1 |
Trojan individuato ma con problemi di rimozione. Autore: eddiguff |
Forum: Sicurezza e Privacy Risposte: 8 |
Visitano il forum: Nessuno e 19 ospiti