TuLKaS85
06-11-2006, 15:19
allora ho da poco fatto una bella pulizia con ativir avg anti-spyware ho anche zone alarm....
il problema è che antivir trova parecchi warning (file che non riesce ad aprire),
allego il log, facendo notare che in programmi c'è una cartella windows nt (penso sia infetta ) che se la cancello da modalità provvisoria(in modalità normale impossibile rimuoverla) al riavvio ricompare !!
ecco il log :
Starting the file scan:
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\_cleaned.tmp
[WARNING] The file could not be opened!
C:\Documents and Settings\Fabio\NTUSER.DAT
[WARNING] The file could not be opened!
C:\Documents and Settings\Fabio\ntuser.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\Fabio\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\Fabio\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\Fabio\Impostazioni locali\Temp\PXR5.tmp
[WARNING] The file could not be opened!
C:\Documents and Settings\Fabio\Impostazioni locali\Temporary Internet Files\Content.IE5\YPGVYTU5\d[2].gif
[DETECTION] The file name contains an executable file extension disguised as a harmless one HEUR-DBLEXT/Crypted
[INFO] The file was moved to '4580f2bd.qua'!
C:\Documents and Settings\NetworkService\NTUSER.DAT
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\ntuser.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG
[WARNING] The file could not be opened!
C:\Programmi\File comuni\System\ZQtEelL.exe
[WARNING] The file could not be opened!
C:\Programmi\windows nt\PxlUS.exe
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\default
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\default.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\software
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\software.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\system
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\system.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\atapi.sys
[WARNING] The file could not be opened!
il problema è che antivir trova parecchi warning (file che non riesce ad aprire),
allego il log, facendo notare che in programmi c'è una cartella windows nt (penso sia infetta ) che se la cancello da modalità provvisoria(in modalità normale impossibile rimuoverla) al riavvio ricompare !!
ecco il log :
Starting the file scan:
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\_cleaned.tmp
[WARNING] The file could not be opened!
C:\Documents and Settings\Fabio\NTUSER.DAT
[WARNING] The file could not be opened!
C:\Documents and Settings\Fabio\ntuser.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\Fabio\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\Fabio\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\Fabio\Impostazioni locali\Temp\PXR5.tmp
[WARNING] The file could not be opened!
C:\Documents and Settings\Fabio\Impostazioni locali\Temporary Internet Files\Content.IE5\YPGVYTU5\d[2].gif
[DETECTION] The file name contains an executable file extension disguised as a harmless one HEUR-DBLEXT/Crypted
[INFO] The file was moved to '4580f2bd.qua'!
C:\Documents and Settings\NetworkService\NTUSER.DAT
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\ntuser.dat.LOG
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat
[WARNING] The file could not be opened!
C:\Documents and Settings\NetworkService\Impostazioni locali\Dati applicazioni\Microsoft\Windows\UsrClass.dat.LOG
[WARNING] The file could not be opened!
C:\Programmi\File comuni\System\ZQtEelL.exe
[WARNING] The file could not be opened!
C:\Programmi\windows nt\PxlUS.exe
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\default
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\default.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SAM.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\SECURITY.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\software
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\software.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\system
[WARNING] The file could not be opened!
C:\WINDOWS\system32\config\system.LOG
[WARNING] The file could not be opened!
C:\WINDOWS\system32\drivers\atapi.sys
[WARNING] The file could not be opened!