PDA

View Full Version : Trojan.Downloader.Adload.EN


yamimarik
14-11-2006, 05:22
che m consigliate per disinfettarlo? >.> ho gia a disinfettarlo con prevx (consigliato da google ma con risultati nn soddisfacenti)

infatti ogni volta che connetto alla adsl sygate firewall mi avverte che 1 processo si vuole aprire:

c:\WINDOWS\Temp\VRT3.tmp

naturalmente lo tengo bloccato ma dubito risolva la cosa

stamani ho dovuto riavviare il pc forzatamente sikke non mi apriva nessun processo di tipo .exe

sperando che sia questo il motivo che mi si era impallato il pc

il nome esatto del trojans e Trojan.Downloader.Adload.EN e/o Downloader.Adload.gd

hjackthis mi rileva tutto pulito quindi nn e 1 processo che si disinfetta con quest'ultimo

http://original.avira.com/it/threats/TR_Dldr_Adload_FV_details.html

ho provato a istallare avira ma m ha dato il seguente errore..

http://www.image-share.net/image/4557/111.JPG

se qualcuno puo aiutarmi, sn 1 caso davvero disperato

in pratica dopo tot ore... sul taskmanager dottor watsons prende 100% d memoria, se lo chiudo m fa casini... ad ogni modo sia la connessione che tutto non risponde

e nn posso neanche disconetterla e/o far altro

quindi devo sempre riavviare...

adesso sto facendo 1 scansione cn bit defender online..

yamimarik
14-11-2006, 06:23
sn circa meta e m ha disinfettato 3400 file :mbe:

tutti sono di tipo "Win32.Virtob.C"

e strano come ho preso 1 virus cosi simile, 5 mesi fa circa avevo il virus Win32.Virtob.Gen

yamimarik
14-11-2006, 08:54
//-----------------------------------------------------------------
//
// Product: BitDefender 8 Free Edition
// Version: 8.0
//
// Created on: 14/11/2006 08:24:48
//
//-----------------------------------------------------------------


Statistics

Scan path : C:\
D:\
Folders : 3932
Files : 269779
Archives : 3042
Packed files : 21280
Identified viruses : 2
Infected files : 23
Warnings : 0
Suspect files : 0
Disinfected files : 17
Deleted files : 0
Copied files : 0
Moved files : 4
Renamed files : 0
I/O errors : 27
Scan time : 00:55:45
Scan speed (files/sec) : 80

Virus definitions : 315838
Scan plugins : 13
Archive plugins : 38
Unpack plugins : 6
Mail plugins : 6
System plugins : 1

Scan options

Detection
[X] Scan boot sectors
[X] Scan archives
[X] Scan packed files
[X] Scan email

File mask
[ ] Programs
[X] All files
[ ] User defined extensions:
[ ] Exclude extensions: ;

Action

Infected objects
[ ] Ignore
[X] Disinfect
[ ] Delete
[ ] Copy to quarantine
[ ] Move to quarantine
[ ] Rename
[ ] Prompt user

Second action
[ ] Ignore
[ ] Delete
[ ] Copy to quarantine
[X] Move to quarantine
[ ] Rename
[ ] Prompt user

Scan options
[X] Enable warnings
[X] Enable heuristics
[ ] Show all files in log
[X] Report file: vscan.log
[ ] Append to existing report

Summary:

C:\Documents and Settings\All Users\Desktop\BitDefender 8 Free Edition.lnk=>C:\Programmi\Softwin\BitDefender8\bdmcon.exe Infected Win32.Virtob.C
C:\Documents and Settings\All Users\Desktop\BitDefender 8 Free Edition.lnk=>C:\Programmi\Softwin\BitDefender8\bdmcon.exe Disinfected
C:\Documents and Settings\All Users\Desktop\BitDefender 8 Free Edition.lnk Update failed
C:\Documents and Settings\All Users\Menu Avvio\BitDefender 8 Free Edition.lnk=>C:\Programmi\Softwin\BitDefender8\bdmcon.exe Infected Win32.Virtob.C
C:\Documents and Settings\All Users\Menu Avvio\BitDefender 8 Free Edition.lnk=>C:\Programmi\Softwin\BitDefender8\bdmcon.exe Disinfected
C:\Documents and Settings\All Users\Menu Avvio\BitDefender 8 Free Edition.lnk Update failed
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Accessori\Comunicazioni\Creazione guidata nuova connessione.lnk=>C:\WINDOWS\system32\rundll32.exe Infected Win32.Virtob.C
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Accessori\Comunicazioni\Creazione guidata nuova connessione.lnk=>C:\WINDOWS\system32\rundll32.exe Disinfected
C:\Documents and Settings\All Users\Menu Avvio\Programmi\Accessori\Comunicazioni\Creazione guidata nuova connessione.lnk Update
C:\Documents and Settings\All Users\Menu Avvio\Programmi\BitDefender 8\BitDefender Register Online.lnk=>C:\Programmi\Softwin\BitDefender8\register.exe Infected Win32.Virtob.C
C:\Documents and Settings\All Users\Menu Avvio\Programmi\BitDefender 8\BitDefender Register Online.lnk=>C:\Programmi\Softwin\BitDefender8\register.exe Disinfected
C:\Documents and Settings\All Users\Menu Avvio\Programmi\BitDefender 8\BitDefender Register Online.lnk Update
C:\Documents and Settings\Utente\Dati applicazioni\Microsoft\Internet Explorer\Quick Launch\Avvia il browser Internet Explorer.lnk=>C:\Programmi\Internet Explorer\IEXPLORE.EXE Infected Win32.Virtob.C
C:\Documents and Settings\Utente\Dati applicazioni\Microsoft\Internet Explorer\Quick Launch\Avvia il browser Internet Explorer.lnk=>C:\Programmi\Internet Explorer\IEXPLORE.EXE Disinfected
C:\Documents and Settings\Utente\Dati applicazioni\Microsoft\Internet Explorer\Quick Launch\Avvia il browser Internet Explorer.lnk Update
C:\Documents and Settings\Utente\Menu Avvio\Programmi\mirc.lnk=>D:\Program Files\Mirc\mirc.exe Infected Win32.Virtob.C
C:\Documents and Settings\Utente\Menu Avvio\Programmi\mirc.lnk=>D:\Program Files\Mirc\mirc.exe Disinfected
C:\Documents and Settings\Utente\Menu Avvio\Programmi\mirc.lnk Update
C:\Programmi\File comuni\Softwin\BitDefender Scan Server\bdc.exe Infected Win32.Virtob.C
C:\Programmi\File comuni\Softwin\BitDefender Scan Server\bdc.exe Disinfected
C:\Programmi\Softwin\BitDefender8\bdmcon.exe Infected Win32.Virtob.C
C:\Programmi\Softwin\BitDefender8\bdmcon.exe Disinfection failed
C:\Programmi\Softwin\BitDefender8\bdmcon.exe Moved
C:\Programmi\Softwin\BitDefender8\bdnagent.exe Infected Win32.Virtob.C
C:\Programmi\Softwin\BitDefender8\bdnagent.exe Disinfection failed
C:\Programmi\Softwin\BitDefender8\bdnagent.exe Moved
C:\Programmi\Softwin\BitDefender8\bdnews.exe Infected Win32.Virtob.C
C:\Programmi\Softwin\BitDefender8\bdnews.exe Disinfected
C:\Programmi\Softwin\BitDefender8\bdsubmit.exe Infected Win32.Virtob.C
C:\Programmi\Softwin\BitDefender8\bdsubmit.exe Disinfected
C:\Programmi\Softwin\BitDefender8\bdswitch.exe Infected Win32.Virtob.C
C:\Programmi\Softwin\BitDefender8\bdswitch.exe Disinfected
C:\Programmi\Softwin\BitDefender8\rtvr.exe Infected Win32.Virtob.C
C:\Programmi\Softwin\BitDefender8\rtvr.exe Disinfected
C:\Programmi\Softwin\BitDefender8\upgrepl.exe Infected Win32.Virtob.C
C:\Programmi\Softwin\BitDefender8\upgrepl.exe Disinfected
C:\WINDOWS\Installer\{8BFFDBAB-FD81-4137-A98E-A769C828080C}\helpicon.exe Infected Win32.Virtob.C
C:\WINDOWS\Installer\{8BFFDBAB-FD81-4137-A98E-A769C828080C}\helpicon.exe Disinfected
C:\WINDOWS\Installer\{8BFFDBAB-FD81-4137-A98E-A769C828080C}\maintenance_icon.exe Infected Win32.Virtob.C
C:\WINDOWS\Installer\{8BFFDBAB-FD81-4137-A98E-A769C828080C}\maintenance_icon.exe Disinfected
C:\WINDOWS\Installer\{8BFFDBAB-FD81-4137-A98E-A769C828080C}\texticon.exe Infected Win32.Virtob.C
C:\WINDOWS\Installer\{8BFFDBAB-FD81-4137-A98E-A769C828080C}\texticon.exe Disinfected
C:\WINDOWS\system32\ctfmon.exe Infected Win32.Virtob.C
C:\WINDOWS\system32\ctfmon.exe Disinfection failed
C:\WINDOWS\system32\ctfmon.exe Moved
C:\WINDOWS\system32\taskmgr.exe Infected Win32.Virtob.C
C:\WINDOWS\system32\taskmgr.exe Disinfected
C:\WINDOWS\system32\wscntfy.exe Infected Win32.Virtob.C
C:\WINDOWS\system32\wscntfy.exe Disinfection failed
C:\WINDOWS\system32\wscntfy.exe Moved
D:\Program Files\Avatar e Firme\Progetto\shakavssaga.rar=>shakavssaga.exe Infected Win32.Virtob.C
D:\Program Files\Avatar e Firme\Progetto\shakavssaga.rar=>shakavssaga.exe Disinfection failed
D:\Program Files\Avatar e Firme\Progetto\shakavssaga.rar=>shakavssaga.exe Move failed
D:\Programmi\Firefox\firefox.exe Infected Win32.Virtob.C
D:\Programmi\Firefox\firefox.exe Disinfected
D:\RECYCLER\S-1-5-21-583907252-1532298954-725345543-1003\Dd1.rar=>shakavssaga.exe Infected Win32.Virtob.C
D:\RECYCLER\S-1-5-21-583907252-1532298954-725345543-1003\Dd1.rar=>shakavssaga.exe Disinfection failed
D:\RECYCLER\S-1-5-21-583907252-1532298954-725345543-1003\Dd1.rar=>shakavssaga.exe Move failed


ho rimpiazzato C:\WINDOWS\system32\wscntfy.exe e C:\WINDOWS\system32\ctfmon.exe con quelli del cd d winpro cn sp2 tale quale a questo computer

gli altri inutili che ha mosso lo eliminati del tt, il resto sn stati disinfettati.. almeno cosi ha detto

sarebbe fin troppo bello che sia gia finita quindi nn icrocio le dita,

cmq questi 2 file sn utili? wscntfy.exe e ctfmon.exe ? o posso anche cestinarli? ho letto su vari siti che sn abbastanza inutili.-.