Condividi:        

pc infettato da virus troyan aiutatemi

Come rimuovere virus e spyware? Le carte di credito sono davvero sicure in rete? È possibile navigare anonimi? Con quali programmi tutelare la propria privacy? Come proteggere i file importanti? Se volete una risposta a queste e altre domande questo è il luogo giusto!

Moderatori: m.paolo, kadosh, Luke57

pc infettato da virus troyan aiutatemi

Postdi claudio61 » 17/01/08 18:06

salve amici da pochi giorni mi sono accorto che il mio pc era diventato molto lento ,ho fatto le dovute procedure ad aware scansione ma il risultato non cambiava il mio antivirus e' nod 32 ma prima voglio dirvi che visto che non sono molto esperto di pc circa un anno fa il mio computer e' stato formattato e sono stati istallati due antivirus nod 32 e avast questi istallati da un tecnico dove lo paortati per formattarlo poimi e' stato consigliato che due antivirus non vanno mai messi e ho tolto avast,,tornando al mio problema ho fatto la scansione con nod ma non e' stato trovato niente,poi leggendo su una rivista consigliava di fare una scansione con kaspersky on line scanner report ,questo alla fine mi ha trovato lo scrivo in inglese come lo stampato NUMBER OF VIRUS FOUND 3 NUMBER OF INFECTED OBJECTS 35 si risconoscono con questa scritta TROYAN WIN 32AGENT DXD PRECEDUTE TUTTE DA UNA LETTERA A DEI NUMERI EXE MA PRIMA DEI NUMERI TEMED ALTRI CON VIRUS PSWTOOLWIN32RAS.A FORSE NON SARO' STATO MOLTO CHIARO MA SE POTETE AIUTARMI AD ELIMINARLI GRAZIE
claudio61
Utente Junior
 
Post: 32
Iscritto il: 13/04/07 20:52

Sponsor
 

Re: pc infettato da virus troyan aiutatemi

Postdi Opensource » 18/01/08 12:22

ciao
posta un log di hijackthis!!!
Avatar utente
Opensource
Utente Senior
 
Post: 684
Iscritto il: 02/11/06 20:45

Re: pc infettato da virus troyan aiutatemi

Postdi claudio61 » 19/01/08 09:22

ti ringrazio come mi hai detto me
Scan saved at 9.18.15, on 19/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programmi\CONITECH\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Programmi\File comuni\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Programmi\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\MSN Messenger\MsnMsgr.Exe
C:\Programmi\Eset\bak\nod32kui.exe
C:\Programmi\CONITECH\Bluetooth Software\BTTray.exe
C:\Programmi\Alice ti aiuta\bin\mpbtn.exe
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\Programmi\Internet Explorer\IEXPLORE.EXE
C:\DOCUME~1\www\IMPOST~1\Temp\Directory temporanea 1 per hijackthis_199[1].zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [nod32kui] "C:\Programmi\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [EPSON Stylus C66 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0S2.EXE /P23 "EPSON Stylus C66 Series" /O6 "USB001" /M "Stylus C66"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [C:\WINDOWS\system32\V0220Cvw.dll] C:\WINDOWS\system32\RegSvr32.exe /s C:\WINDOWS\system32\V0220Cvw.dll
O4 - HKLM\..\Run: [V0220Mon.exe] C:\WINDOWS\V0220Mon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Programmi\File comuni\InstallShield\UpdateService\bak\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Programmi\File comuni\InstallShield\UpdateService\issch.exe" -start
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programmi\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programmi\File comuni\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [AnyDVD] C:\Programmi\SlySoft\AnyDVD\AnyDVD.exe
O4 - Startup: IAMS-CD a 4 zampe-Cane.lnk = C:\Programmi\IAMS-CD a 4 zampe-Cane\Control.exe
O4 - Global Startup: Alice ti aiuta.lnk = C:\Programmi\Alice ti aiuta\bin\matcli.exe
O4 - Global Startup: Avvio veloce di Adobe Reader.lnk = C:\Programmi\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Invia a Bluetooth - C:\Programmi\CONITECH\Bluetooth Software\btsendto_ie.htm
O8 - Extra context menu item: Invia a periferica &Bluetooth... - C:\Programmi\CONITECH\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barra di ricerca di Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\CONITECH\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programmi\CONITECH\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partne ... nicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programmi\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://veri92veronica.spaces.live.com// ... nPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://veri92veronica.spaces.live.com/P ... nPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{F4E75320-8A51-4018-BA3F-1157842114F5}: NameServer = 85.37.17.16 85.38.28.68
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmi\CONITECH\Bluetoothtto il mio log di hijachthis
claudio61
Utente Junior
 
Post: 32
Iscritto il: 13/04/07 20:52

Re: pc infettato da virus troyan aiutatemi

Postdi Luke57 » 19/01/08 10:34

Ciao, allega direttamente il report della scansione con kaspersky
Luke57
Moderatore
 
Post: 6413
Iscritto il: 11/08/05 19:10

Re: pc infettato da virus troyan aiutatemi

Postdi claudio61 » 19/01/08 14:27

ciao luke ti allego la scansione fatta con kasperski
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 17/01/2008
Kaspersky Anti-Virus database records: 513881


Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true

Scan Target My Computer
C:\
D:\
F:\
G:\
H:\
I:\
J:\
K:\

Scan Statistics
Total number of scanned objects 114946
Number of viruses found 3
Number of infected objects 35
Number of suspicious objects 0
Duration of the scan process 01:07:42

Infected Object Name Virus Name Last Action
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\LocalService\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped

C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped

C:\Documents and Settings\www\Cookies\index.dat Object is locked skipped

C:\Documents and Settings\www\Documenti\claudio varie\installer-65504-34-Audacity-Italian.exe Infected: Backdoor.Win32.Agent.duj skipped

C:\Documents and Settings\www\Documenti\federica varie\installer-41815-34-AVS-Audio-Editor-Italian.exe Infected: Backdoor.Win32.Agent.duj skipped

C:\Documents and Settings\www\Impostazioni locali\Cronologia\History.IE5\index.dat Object is locked skipped

C:\Documents and Settings\www\Impostazioni locali\Cronologia\History.IE5\MSHist012008011720080118\index.dat Object is locked skipped

C:\Documents and Settings\www\Impostazioni locali\Dati applicazioni\Microsoft\Feeds Cache\index.dat Object is locked skipped

C:\Documents and Settings\www\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat Object is locked skipped

C:\Documents and Settings\www\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\1218396163.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\1299927080.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\1657680256.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\1669211156.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\1696768466.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\2065339969.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\2294638112.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\23861681.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\2652861912.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\2889782722.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\2911667319.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\3055270408.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\3071456555.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\3218024864.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\3306642936.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\3507851379.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\4089578238.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\534908820.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\566566443.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\639030969.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\732522680.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temp\743014930.exe Infected: Trojan.Win32.Agent.dxh skipped

C:\Documents and Settings\www\Impostazioni locali\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped

C:\Documents and Settings\www\ntuser.dat Object is locked skipped

C:\Documents and Settings\www\ntuser.dat.LOG Object is locked skipped

C:\Programmi\Alice ti aiuta\log\mpbtn.log Object is locked skipped

C:\Programmi\ESET\cache\CACHE.NDB Object is locked skipped

C:\Programmi\ESET\logs\virlog.dat Object is locked skipped

C:\Programmi\ESET\logs\warnlog.dat Object is locked skipped

C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped

C:\System Volume Information\_restore{FD50688B-99DD-448E-857D-CFA62B70B9A9}\RP295\A0063408.exe Infected: Backdoor.Win32.Agent.duj skipped

C:\System Volume Information\_restore{FD50688B-99DD-448E-857D-CFA62B70B9A9}\RP297\A0063567.exe Infected: Backdoor.Win32.Agent.duj skipped

C:\System Volume Information\_restore{FD50688B-99DD-448E-857D-CFA62B70B9A9}\RP303\A0064382.exe Infected: Backdoor.Win32.Agent.duj skipped

C:\System Volume Information\_restore{FD50688B-99DD-448E-857D-CFA62B70B9A9}\RP304\A0064426.exe Infected: Backdoor.Win32.Agent.duj skipped

C:\System Volume Information\_restore{FD50688B-99DD-448E-857D-CFA62B70B9A9}\RP311\A0065490.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped

C:\System Volume Information\_restore{FD50688B-99DD-448E-857D-CFA62B70B9A9}\RP311\A0065490.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped

C:\System Volume Information\_restore{FD50688B-99DD-448E-857D-CFA62B70B9A9}\RP311\A0065490.exe RarSFX: infected - 2 skipped

C:\System Volume Information\_restore{FD50688B-99DD-448E-857D-CFA62B70B9A9}\RP311\A0065497.exe/data.rar/officekey.exe Infected: not-a-virus:PSWTool.Win32.RAS.a skipped

C:\System Volume Information\_restore{FD50688B-99DD-448E-857D-CFA62B70B9A9}\RP311\A0065497.exe/data.rar Infected: not-a-virus:PSWTool.Win32.RAS.a skipped

C:\System Volume Information\_restore{FD50688B-99DD-448E-857D-CFA62B70B9A9}\RP311\A0065497.exe RarSFX: infected - 2 skipped

C:\System Volume Information\_restore{FD50688B-99DD-448E-857D-CFA62B70B9A9}\RP325\A0071221.exe Infected: Backdoor.Win32.Agent.duj skipped

C:\System Volume Information\_restore{FD50688B-99DD-448E-857D-CFA62B70B9A9}\RP327\change.log Object is locked skipped

C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped

C:\WINDOWS\SchedLgU.Txt Object is locked skipped

C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped

C:\WINDOWS\Sti_Trace.log Object is locked skipped

C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\default Object is locked skipped

C:\WINDOWS\system32\config\default.LOG Object is locked skipped

C:\WINDOWS\system32\config\Internet.evt Object is locked skipped

C:\WINDOWS\system32\config\SAM Object is locked skipped

C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped

C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\SECURITY Object is locked skipped

C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped

C:\WINDOWS\system32\config\software Object is locked skipped

C:\WINDOWS\system32\config\software.LOG Object is locked skipped

C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped

C:\WINDOWS\system32\config\system Object is locked skipped

C:\WINDOWS\system32\config\system.LOG Object is locked skipped

C:\WINDOWS\system32\h323log.txt Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped

C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped

C:\WINDOWS\wiadebug.log Object is locked skipped

C:\WINDOWS\wiaservc.log Object is locked skipped

C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.
claudio61
Utente Junior
 
Post: 32
Iscritto il: 13/04/07 20:52

Re: pc infettato da virus troyan aiutatemi

Postdi Luke57 » 19/01/08 15:27

Ciao, vai qui:
http://alexsandra.wordpress.com/2007/03 ... da-alluso/
utilizza atfcleaner per come spiegato.
Poi disattiva il ripristino configurazione di sistema (click tasto dx su risorse del computer>proprietà>ripristino configurazione di sistema>metti la spunta a "disattiva.......">OK.
Al riavvio, mediante la solita procedura, togli la spunta precedentemente immessa>OK.
Luke57
Moderatore
 
Post: 6413
Iscritto il: 11/08/05 19:10

Re: pc infettato da virus troyan aiutatemi

Postdi claudio61 » 21/01/08 07:50

grazie luke ho fatto come mi dici tu ma la pulizia lo esegiuta con cc cleaner e' la stessa cosa? adesso devo rifare la scansione con kaspersky? poi volevo chiederti un altro favore sempre se puoi aiutarmi avevo scritto sempre sul forum se qualcuno poteva aiutarmi ha risolvere questo problema con msn chiedevo se qualcuno poteva indicarmi come si poteva togliere definitivamente il salvataggio delle mie conversazioni su msn e anche dati recenti visto che anche la si possono leggere ,per me e' molto importante perche' le uso per il mio lavoro grazie
claudio61
Utente Junior
 
Post: 32
Iscritto il: 13/04/07 20:52


Torna a Sicurezza e Privacy


Topic correlati a "pc infettato da virus troyan aiutatemi":


Chi c’è in linea

Visitano il forum: Nessuno e 5 ospiti