Pc lento, virus tr/agent scasioni con avira e rogue killer

Risolto/Chiuso
susanna76 Posti 51 Data di registrazione sabato 30 agosto 2014 Stato Membri Ultimo intervento giovedì 28 aprile 2016 - 11 set 2014 alle 21:52
Noureddine Bouzidi Posti 22674 Data di registrazione giovedì 19 marzo 2009 Stato Moderatore Ultimo intervento giovedì 7 gennaio 2021 - 16 set 2014 alle 12:47
Ciao,
ho il computer lentissimo,
ho fatto scansioni con avira che trova virus e lo mette in quarantena ma poi questo torna sempre!

C:\Users\F550c\AppData\Roaming\Microsoft\Windows\IEUpdate\JETCOMP.exe
[RILEVAMENTO] Si tratta del cavallo di Troia TR/Agent.ahhiv

ho fatto delle scasioni con rogue killer e questo è il log:

RogueKiller V9.2.9.0 (x64) [Jul 11 2014] by Adlice Software
mail : https://www.adlice.com/contact/
Feedback : https://forum.adlice.com/
Website : https://www.adlice.com/roguekiller/
Blog : https://www.adlice.com/

Operating System : Windows 8.1 (6.3.9200 ) 64 bits version
Started in : Normal mode
User : F550c [Admin rights]
Mode : Remove -- Date : 09/11/2014 18:57:18

¤¤¤ Bad processes : 1 ¤¤¤
[Proc.Hidden] -- [x] -> Chiuso [TermThr]

¤¤¤ Registry Entries : 6 ¤¤¤
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-130126266-3837534747-1370213360-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.msn.com/fr-fr/?cobrand=asus13.msn.com&ocid=ASUDHP&pc=ASU2JS -> NON SELEZIONATO
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-130126266-3837534747-1370213360-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.msn.com/fr-fr/?cobrand=asus13.msn.com&ocid=ASUDHP&pc=ASU2JS -> NON SELEZIONATO
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-130126266-3837534747-1370213360-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.msn.com/fr-fr/?cobrand=asus13.msn.com&ocid=ASUDHP&pc=ASU2JS -> Sostituito (https://www.msn.com/fr-fr/?ocid=iehp
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-130126266-3837534747-1370213360-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.msn.com/fr-fr/?cobrand=asus13.msn.com&ocid=ASUDHP&pc=ASU2JS -> Sostituito (https://www.msn.com/fr-fr/?ocid=iehp
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-130126266-3837534747-1370213360-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.msn.com/fr-fr/?cobrand=asus13.msn.com&ocid=ASUDHP&pc=ASU2JS -> Sostituito (https://www.msn.com/fr-fr/?ocid=iehp
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-130126266-3837534747-1370213360-501-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Software\Microsoft\Internet Explorer\Main | Start Page : https://www.msn.com/fr-fr/?cobrand=asus13.msn.com&ocid=ASUDHP&pc=ASU2JS -> Sostituito (https://www.msn.com/fr-fr/?ocid=iehp

¤¤¤ Le attività pianificate : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ HOSTS File : 2 ¤¤¤
[C:\WINDOWS\System32\drivers\etc\hosts] 127.0.0.1 localhost
[C:\WINDOWS\System32\drivers\etc\hosts] ::1 localhost


AIUTO!
¤¤¤ Antirootkit : 0 (Driver: LOADED) ¤¤¤

¤¤¤ I browser Web : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: HGST HTS545050A7E680 +++++
--- User ---
[MBR] 79dde02c62ccb3198f48838cfc02a4b3
[BSP] d28e338c2261577215d19a426d664c81 : Empty MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 2097152 MB
User = LL1 ... OK
User = LL2 ... OK


============================================
RKreport_DEL_09012014_130857.log - RKreport_DEL_09012014_144052.log - RKreport_DEL_09012014_171104.log - RKreport_DEL_09012014_183351.log
RKreport_DEL_09102014_082353.log - RKreport_DEL_09112014_164337.log - RKreport_SCN_08302014_164941.log - RKreport_SCN_08312014_104834.log
RKreport_SCN_09012014_130627.log - RKreport_SCN_09012014_143729.log - RKreport_SCN_09012014_163003.log - RKreport_SCN_09012014_172727.log
RKreport_SCN_09012014_183343.log - RKreport_SCN_09012014_183817.log - RKreport_SCN_09012014_185311.log - RKreport_SCN_09022014_082027.log
RKreport_SCN_09102014_075254.log - RKreport_SCN_09102014_080548.log - RKreport_SCN_09102014_081658.log - RKreport_SCN_09102014_083659.log
RKreport_SCN_09112014_161401.log - RKreport_SCN_09112014_164252.log - RKreport_SCN_09112014_185656.log





22 risposte

susanna76 Posti 51 Data di registrazione sabato 30 agosto 2014 Stato Membri Ultimo intervento giovedì 28 aprile 2016
16 set 2014 alle 12:30
scusa, non ho la voce CURE ma DELETE or COPY TO QUARANTINE.
QUALE SCELGO?
0
Noureddine Bouzidi Posti 22674 Data di registrazione giovedì 19 marzo 2009 Stato Moderatore Ultimo intervento giovedì 7 gennaio 2021 15.419
16 set 2014 alle 12:47
scegli "delete"
0