Jump to content

maurocattani

Members
  • Posts

    7
  • Joined

  • Last visited

Reputation

0 Neutral
  1. Here the Extr of Otlist Extras.Txt Extras.Txt
  2. Here the OTlist OTListIt.Txt OTListIt.Txt
  3. Here the HiJack report hijackthis.txt hijackthis.txt
  4. Here the Panda scan ActiveScan.txt ActiveScan.txt
  5. I'm proceding with the scans as per your suggestions. Before any scan I've switched of Kasper and Norton. The scan from Malware is (surprisingly) not reporting any infection! (see the attachment). Now I proceed with Panda. I'll let you know. (thank you) mbam_log_2008_11_26__22_26_08_.txt mbam_log_2008_11_26__22_26_08_.txt
  6. After scanning my computer with Malwarebytes, I got the following report: Elementi dato del registro infetti: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Quarantined and deleted successfully. If I scan the system again I find no further problems. After re-booting the system, I get again the same report. Elementi dato del registro infetti: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\userinit.exe -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\userinit.exe -> Quarantined and deleted successfully. Is it a false positive of the program or the program is not scanning the author of the modifications of the register? I've tryed also Kasper with the following results: C:\WINDOWS\system32\userinit.exe Infected: Exploit.Win32.IMG-WMF.hu 1 Thank you for your support!
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.