+ Rispondi alla Discussione
Risultati da 1 a 16 di 16
  1. #1
    L'Onesto
    Data Registrazione
    27-12-03
    Messaggi
    822

    Predefinito scansione con avira antivir

    trovato in windows/downloaded program files ( non e' la cartella dei programmi scaricati con gli aggiornamenti) un file cab, che sembra essere questo virus, come dice il programma, un harmful backdoor BDS/checkno.buo

    io per il momento l'ho ignorato... che faccio??

  2. #2
    Xan
    ospite

    Predefinito Re: scansione con avira antivir

    Vai su www.virustotal.com e fai un upload del file per una conferma.

  3. #3
    L'Onesto
    Data Registrazione
    27-12-03
    Messaggi
    822

    Predefinito Re: scansione con avira antivir

    non posso farlo, perche' la cartella non contiene il file, o quantomeno non me lo fa vedere, e' una cartella con la e di explorer sopra, se ci clicco mi compare una schermata con i programmi installati, tra l'altro mi risulta solo shockwave

  4. #4
    blue_tech
    ospite

    Predefinito Re: scansione con avira antivir

    strumenti -> opzioni cartella -> visualizzazione -> "visualizza cartelle e file nascosti" e poi togli la spunta da "nascondi file protetti e di sistema"

    vedi che poi lo vedi

  5. #5
    L'Onesto
    Data Registrazione
    27-12-03
    Messaggi
    822

    Predefinito Re: scansione con avira antivir

    cmq. la cartella mi riporta uno shockwawe object danneggiato.... ora provo come dici tu, se non ci riesco, metto in quarantina....

  6. #6
    L'Onesto
    Data Registrazione
    27-12-03
    Messaggi
    822

    Predefinito Re: scansione con avira antivir

    no, non si vede, mi mostra solo una pagina che mi dice che c'e' questo showave flash object che se metto il file e' installato se lo metto in quarantina e' danneggiato.,....

  7. #7
    L'Onesto
    Data Registrazione
    27-12-03
    Messaggi
    822

    Predefinito Re: scansione con avira antivir

    sembrerebbe un controllo di active x.... ho provato anche a fare un aggiornamento, bho.. forse e' un falso, pero' non capisco come posso arrivare al file cab

  8. #8
    L'Onesto
    Data Registrazione
    27-12-03
    Messaggi
    822

    Predefinito Re: scansione con avira antivir

    sembra il flash player di adobe

  9. #9
    blue_tech
    ospite

    Predefinito Re: scansione con avira antivir

    posta il report di avira va là...

  10. #10
    L'Onesto
    Data Registrazione
    27-12-03
    Messaggi
    822

    Predefinito Re: scansione con avira antivir

    Avira AntiVir Personal
    Report file date: sabato 19 luglio 2008 18:02

    Scanning for 1476110 virus strains and unwanted programs.

    Licensed to: Avira AntiVir PersonalEdition Classic
    Serial number: 0000149996-ADJIE-0001
    Platform: Windows XP
    Windows version: (Service Pack 2) [5.1.2600]
    Boot mode: Normally booted
    Username: SYSTEM
    Computer name: MEACCI

    Version information:
    BUILD.DAT : 8.1.0.326 16933 Bytes 11/07/2008 12:57:00
    AVSCAN.EXE : 8.1.4.7 315649 Bytes 17/07/2008 16:35:23
    AVSCAN.DLL : 8.1.4.0 40705 Bytes 17/07/2008 16:35:23
    LUKE.DLL : 8.1.4.5 164097 Bytes 17/07/2008 16:35:23
    LUKERES.DLL : 8.1.4.0 12033 Bytes 17/07/2008 16:35:23
    ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18/07/2007 14:27:15
    ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 24/06/2008 10:12:43
    ANTIVIR2.VDF : 7.0.5.119 1264128 Bytes 15/07/2008 16:35:23
    ANTIVIR3.VDF : 7.0.5.139 325632 Bytes 19/07/2008 15:58:15
    Engineversion : 8.1.1.11
    AEVDF.DLL : 8.1.0.5 102772 Bytes 15/04/2008 07:55:42
    AESCRIPT.DLL : 8.1.0.59 307579 Bytes 19/07/2008 15:58:39
    AESCN.DLL : 8.1.0.23 119156 Bytes 17/07/2008 16:35:24
    AERDL.DLL : 8.1.0.20 418165 Bytes 25/04/2008 07:59:14
    AEPACK.DLL : 8.1.2.1 364917 Bytes 17/07/2008 16:35:24
    AEOFFICE.DLL : 8.1.0.21 192891 Bytes 19/07/2008 15:58:34
    AEHEUR.DLL : 8.1.0.43 1339767 Bytes 19/07/2008 15:58:31
    AEHELP.DLL : 8.1.0.15 115063 Bytes 30/05/2008 08:09:49
    AEGEN.DLL : 8.1.0.29 307573 Bytes 21/06/2008 08:22:10
    AEEMU.DLL : 8.1.0.6 430451 Bytes 08/05/2008 15:59:49
    AECORE.DLL : 8.1.1.6 172405 Bytes 17/07/2008 16:35:23
    AEBB.DLL : 8.1.0.1 53617 Bytes 17/07/2008 16:35:23
    AVWINLL.DLL : 1.0.0.12 15105 Bytes 17/07/2008 16:35:23
    AVPREF.DLL : 8.0.2.0 38657 Bytes 17/07/2008 16:35:23
    AVREP.DLL : 7.0.0.1 155688 Bytes 16/04/2007 13:16:24
    AVREG.DLL : 8.0.0.1 33537 Bytes 17/07/2008 16:35:23
    AVARKT.DLL : 1.0.0.23 307457 Bytes 15/04/2008 07:55:42
    AVEVTLOG.DLL : 8.0.0.16 119041 Bytes 17/07/2008 16:35:23
    SQLITE3.DLL : 3.3.17.1 339968 Bytes 15/04/2008 07:55:42
    SMTPLIB.DLL : 1.2.0.23 28929 Bytes 17/07/2008 16:35:23
    NETNT.DLL : 8.0.0.1 7937 Bytes 15/04/2008 07:55:42
    RCIMAGE.DLL : 8.0.0.51 2371841 Bytes 17/07/2008 16:35:21
    RCTEXT.DLL : 8.0.52.0 86273 Bytes 17/07/2008 16:35:21

    Configuration settings for the scan:
    Jobname..........................: Complete system scan
    Configuration file...............: d:\programmi\avira\antivir personaledition classic\sysscan.avp
    Logging..........................: low
    Primary action...................: interactive
    Secondary action.................: ignore
    Scan master boot sector..........: off
    Scan boot sector.................: on
    Boot sectors.....................: C:, D:,
    Process scan.....................: on
    Scan registry....................: on
    Search for rootkits..............: off
    Scan all files...................: Intelligent file selection
    Scan archives....................: on
    Recursion depth..................: 20
    Smart extensions.................: on
    Macro heuristic..................: on
    File heuristic...................: medium

    Start of the scan: sabato 19 luglio 2008 18:02

    The scan of running processes will be started
    Scan process 'avscan.exe' - '1' Module(s) have been scanned
    Scan process 'avcenter.exe' - '1' Module(s) have been scanned
    Scan process 'avgnt.exe' - '1' Module(s) have been scanned
    Scan process 'alg.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'nvsvc32.exe' - '1' Module(s) have been scanned
    Scan process 'cdrom_mon.exe' - '1' Module(s) have been scanned
    Scan process 'sched.exe' - '1' Module(s) have been scanned
    Scan process 'c6Messenger.exe' - '1' Module(s) have been scanned
    Scan process 'ctfmon.exe' - '1' Module(s) have been scanned
    Scan process 'MSASCui.exe' - '1' Module(s) have been scanned
    Scan process 'rundll32.exe' - '1' Module(s) have been scanned
    Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned
    Scan process 'explorer.exe' - '1' Module(s) have been scanned
    Scan process 'avguard.exe' - '1' Module(s) have been scanned
    Scan process 'spoolsv.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'MsMpEng.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'svchost.exe' - '1' Module(s) have been scanned
    Scan process 'lsass.exe' - '1' Module(s) have been scanned
    Scan process 'services.exe' - '1' Module(s) have been scanned
    Scan process 'winlogon.exe' - '1' Module(s) have been scanned
    Scan process 'csrss.exe' - '1' Module(s) have been scanned
    Scan process 'smss.exe' - '1' Module(s) have been scanned
    27 processes with 27 modules were scanned

    Start scanning boot sectors:
    Boot sector 'C:\'
    [INFO] No virus was found!
    Boot sector 'D:\'
    [INFO] No virus was found!

    Starting to scan the registry.
    The registry was scanned ( '52' files ).


    Starting the file scan:

    Begin scan in 'C:\'
    Begin scan in 'D:\'
    D:\pagefile.sys
    [WARNING] The file could not be opened!
    D:\Documents and Settings\Livio\Documenti\giochi\xcom3.zip
    [0] Archive type: ZIP
    --> apocalypse.part02.rar
    [1] Archive type: RAR
    --> apocalypse\Maps\01senate\Mapunits\Floor.pck
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    --> apocalypse.part03.rar
    [1] Archive type: RAR
    --> apocalypse\Ufopaedi\05autops.pcx
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    --> apocalypse.part04.rar
    [1] Archive type: RAR
    --> apocalypse\Ufopaedi\31water.pcx
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    --> apocalypse.part05.rar
    [1] Archive type: RAR
    --> apocalypse\Ufopaedi\W38.pcx
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    --> apocalypse.part06.rar
    [1] Archive type: RAR
    --> apocalypse\Smk\Lose1.smk
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    --> apocalypse.part07.rar
    [1] Archive type: RAR
    --> apocalypse\Smk\Wingame2.smk
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    --> apocalypse.part09.rar
    [1] Archive type: RAR
    --> apocalypse\Maps\01senate\01sec01.smp
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\Documents and Settings\Livio\Documenti\giochi\xcom3\apocalypse.p art02.rar
    [0] Archive type: RAR
    --> apocalypse\Maps\01senate\Mapunits\Floor.pck
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\Documents and Settings\Livio\Documenti\giochi\xcom3\apocalypse.p art03.rar
    [0] Archive type: RAR
    --> apocalypse\Ufopaedi\05autops.pcx
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\Documents and Settings\Livio\Documenti\giochi\xcom3\apocalypse.p art04.rar
    [0] Archive type: RAR
    --> apocalypse\Ufopaedi\31water.pcx
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\Documents and Settings\Livio\Documenti\giochi\xcom3\apocalypse.p art05.rar
    [0] Archive type: RAR
    --> apocalypse\Ufopaedi\W38.pcx
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\Documents and Settings\Livio\Documenti\giochi\xcom3\apocalypse.p art06.rar
    [0] Archive type: RAR
    --> apocalypse\Smk\Lose1.smk
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\Documents and Settings\Livio\Documenti\giochi\xcom3\apocalypse.p art07.rar
    [0] Archive type: RAR
    --> apocalypse\Smk\Wingame2.smk
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\Documents and Settings\Livio\Documenti\giochi\xcom3\apocalypse.p art09.rar
    [0] Archive type: RAR
    --> apocalypse\Maps\01senate\01sec01.smp
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\livio\xcom3\apocalypse.part02.rar
    [0] Archive type: RAR
    --> apocalypse\Maps\01senate\Mapunits\Floor.pck
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\livio\xcom3\apocalypse.part03.rar
    [0] Archive type: RAR
    --> apocalypse\Ufopaedi\05autops.pcx
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\livio\xcom3\apocalypse.part04.rar
    [0] Archive type: RAR
    --> apocalypse\Ufopaedi\31water.pcx
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\livio\xcom3\apocalypse.part05.rar
    [0] Archive type: RAR
    --> apocalypse\Ufopaedi\W38.pcx
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\livio\xcom3\apocalypse.part06.rar
    [0] Archive type: RAR
    --> apocalypse\Smk\Lose1.smk
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\livio\xcom3\apocalypse.part07.rar
    [0] Archive type: RAR
    --> apocalypse\Smk\Wingame2.smk
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\livio\xcom3\apocalypse.part09.rar
    [0] Archive type: RAR
    --> apocalypse\Maps\01senate\01sec01.smp
    [WARNING] No further files can be extracted from this archive. The archive will be closed
    D:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe
    [DETECTION] Contains a recognition pattern of the (harmful) BDS/Ceckno.buo back-door program
    [WARNING] The file was ignored!


    End of the scan: sabato 19 luglio 2008 18:51
    Used time: 49:12 Minute(s)

    The scan has been done completely.

    9584 Scanning directories
    291584 Files were scanned
    1 viruses and/or unwanted programs were found
    0 Files were classified as suspicious:
    0 files were deleted
    0 files were repaired
    0 files were moved to quarantine
    0 files were renamed
    1 Files cannot be scanned
    291582 Files not concerned
    2095 Archives were scanned
    23 Warnings
    0 Notes

  11. #11
    blue_tech
    ospite

    Predefinito Re: scansione con avira antivir

    D:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe

    questo è il nome del file e come vedi non è un file cab ma è un eseguibile
    senza contare che non si trova in una cartella di sistema e che se cerchi su google lo riconoscono come virus

    metti in quarantena e così non ci pensi più
    alla peggio se poi hai problemi lo ripristini

  12. #12
    L'Onesto
    Data Registrazione
    27-12-03
    Messaggi
    822

    Predefinito Re: scansione con avira antivir

    ma perche' se apro la cartella non lo vedo, ma vedo quella pagina strana??

  13. #13
    L'Onesto
    Data Registrazione
    27-12-03
    Messaggi
    822

    Predefinito Re: scansione con avira antivir

    ...e che pizza peraltro... non vado per siti strani, sto attento a tutto.. e becco il virus....

  14. #14
    L'Onesto
    Data Registrazione
    27-12-03
    Messaggi
    822

    Predefinito Re: scansione con avira antivir

    Codice:
    C:\WINDOWS\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe Infected: Backdoor.Win32.Ceckno.buo 1



    Essendo un programma di download kaspersky lo ha preso sì com' è ma che possa scaricare materiale illecito nel tuo PC!!!




    ho trovato questo su google... quindi pare forse un falso?

  15. #15
    L'Onesto
    Data Registrazione
    27-12-03
    Messaggi
    822

    Predefinito Re: scansione con avira antivir

    cmq, innanzitutto come al solito vi ringrazio, ho aggiornado il flash di adobe, rifatto la scansione e non risulta piu' nulla, quindi o era un falso, o adesso il virus si e' spostato chissa dove, ma per adesso penso che possiamo chiudere....

    grazie

  16. #16
    Shogun Assoluto L'avatar di Sticky©
    Data Registrazione
    09-08-04
    Località
    Roma
    Messaggi
    36,491

    Predefinito Re: scansione con avira antivir

    Vada per il falso positivo.

+ Rispondi alla Discussione

Permessi di Scrittura

  • Tu non puoi inviare nuove discussioni
  • Tu non puoi inviare risposte
  • Tu non puoi inviare allegati
  • Tu non puoi modificare i tuoi messaggi
  • Il codice BB è Attivato
  • Le faccine sono Attivato
  • Il codice [IMG] è Attivato
  • Il codice HTML è Disattivato