di pippo26 » 28/09/10 12:13
Forse ci siamo...oltre tutto nella cartella drivers c'erano due file aec.sys e aec.sys.bak, ovviamente solo editabili in modalità provvisoria.
Ecco il report di virus total:
-----------------------
File name: wgrtiq.sys
Submission date: 2010-09-24 13:26:28 (UTC)
Current status: finished
Result: 38 /43 (88.4%)
"Antivirus", "Version", "Last update", "Result"
"AhnLab-V3", "2010.09.24.00", "2010.09.24", "Win-Trojan/Bubnix.585472"
"AntiVir", "7.10.12.28", "2010.09.24", "Rkit/Agent.biiu"
"Antiy-AVL", "2.0.3.7", "2010.09.24", "-"
"Authentium", "5.2.0.5", "2010.09.24", "W32/Trojan2.NKQF"
"Avast", "4.8.1351.0", "2010.09.23", "Win32:Bubnix-J"
"Avast5", "5.0.594.0", "2010.09.23", "Win32:Bubnix-J"
"AVG", "9.0.0.851", "2010.09.24", "BackDoor.Generic12.CEFS"
"BitDefender", "7.2", "2010.09.24", "Trojan.Krap.H"
"CAT-QuickHeal", "11.00", "2010.09.24", "Rootkit.Agent.biiu"
"ClamAV", "0.96.2.0-git", "2010.09.24", "Trojan.Rootkit-2762"
"Comodo", "6186", "2010.09.24", "EmailWorm.Win32.Joleee.~J1"
"DrWeb", "5.0.2.03300", "2010.09.24", "Trojan.Packed.20819"
"Emsisoft", "5.0.0.37", "2010.09.24", "Rootkit.Win32.Agent!IK"
"eSafe", "7.0.17.0", "2010.09.21", "Win32.Hacktool.Rootk"
"eTrust-Vet", "36.1.7874", "2010.09.24", "-"
"F-Prot", "4.6.2.117", "2010.09.24", "W32/Trojan2.NKQF"
"F-Secure", "9.0.15370.0", "2010.09.24", "Trojan.Krap.H"
"Fortinet", "4.1.143.0", "2010.09.24", "W32/Agent.C198!tr"
"GData", "21", "2010.09.24", "Trojan.Krap.H"
"Ikarus", "T3.1.1.88.0", "2010.09.24", "Rootkit.Win32.Agent"
"Jiangmin", "13.0.900", "2010.09.21", "Rootkit.Agent.ipz"
"K7AntiVirus", "9.63.2589", "2010.09.23", "RootKit"
"Kaspersky", "7.0.0.125", "2010.09.24", "Rootkit.Win32.Agent.biiu"
"McAfee", "5.400.0.1158", "2010.09.24", "Generic.dx!tkd"
"McAfee-GW-Edition", "2010.1C", "2010.09.24", "Generic.dx!tkd"
"Microsoft", "1.6201", "2010.09.24", "Trojan:WinNT/Bubnix.gen!B"
"NOD32", "5476", "2010.09.24", "Win32/Bubnix.AU"
"Norman", "6.06.06", "2010.09.23", "W32/Suspicious_Gen2.BVVWE"
"nProtect", "2010-09-24.02", "2010.09.24", "Trojan/W32.Rootkit.585504"
"Panda", "10.0.2.7", "2010.09.24", "Trj/Downloader.MDW"
"PCTools", "7.0.3.5", "2010.09.24", "Hacktool.Rootkit"
"Prevx", "3.0", "2010.09.24", "-"
"Rising", "22.66.00.07", "2010.09.21", "Trojan.Win32.Generic.5227BBE3"
"Sophos", "4.58.0", "2010.09.24", "Mal/Krap-B"
"Sunbelt", "6922", "2010.09.24", "VirTool.Win32.Obfuscator.FH (v)"
"SUPERAntiSpyware", "4.40.0.1006", "2010.09.24", "-"
"Symantec", "20101.1.1.7", "2010.09.24", "Hacktool.Rootkit"
"TheHacker", "6.7.0.0.029", "2010.09.23", "Trojan/Agent.biiu"
"TrendMicro", "9.120.0.1004", "2010.09.24", "TROJ_AGENT.AVLW"
"TrendMicro-HouseCall", "9.120.0.1004", "2010.09.24", "TROJ_AGENT.AVLW"
"VBA32", "3.12.14.1", "2010.09.24", "Rootkit.Agent.biiu"
"ViRobot", "2010.9.24.4059", "2010.09.24", "Spyware.Agent.RootKit.585504"
"VirusBuster", "12.65.23.0", "2010.09.23", "-"
"MD5", "0bb8cf97b010ad4cbf8d0c14eabc9509"
"SHA1", "640a447a4b9e45789a6fb04d754346eb085156ff"
"SHA256", "e795eb4259138609fd3d7a6e8bb60e625ad552222f07c1634a9909edad24e20c"
"File size", "585504 bytes"
"Scan date", "2010-09-24 13:26:28 (UTC)"
-------------------
Se serve ho anche il report di hijackthis.
Grazie