Ciao Giovolo,
allora ho fatto un po' di ricerche sul Trojan che ti affligge, non ho trovato molto per eliminarlo definitivamente e credo sia lui a crearti questi problemi. Leggi attentamenti ciò che ho trovato sul sito
www.trendmicro.comJS_EXCEPTION.E
(see also: description and solution)
In the wild: Yes
Payload 1: (changes the IE settings)
Detection available: Oct. 9, 2001
Detected by pattern file #: 953
(still using 900-series pattern files?)
Detected by scan engine #: 5.200
Language:
English
Platform: Windows
Encrypted: No
Size of virus: 31,263 Bytes
Details:
This malicious JavaScript exploits security vulnerability in the Microsoft Virtual Machine that allows a Java applet on an infected Web site to execute any command on a visiting user’s machine. This vulnerability allows ActiveX controls to be created and used from a Web page. If a user visits a malicious Web site that exploits this vulnerability, a Java applet on the Web page could run any ActiveX control, even ones that are marked as unsafe for scripting. This Script virus uses this vulnerability to change the startup page of Internet Explorer. It modifies the registry as follows to execute this:
HKEY_CURRENT_USER\Software\MicrosoftInternet Explorer\Main Start Page =
http://www.farmo.ruIt also uses this vulnerability to drop a FARMO.RU.URL file in any of the following folders:
%Windows%\Desktop
%Windows%\Documents
Settings\[User Name]\Favorites
FARMO.RU.URL contains a link to the Web site,
http://www.farmo.ru Description created: Oct. 19, 2001
JS_EXCEPTION.E
Risk rating:
Virus type: JavaScript
Destructive: No
Aliases:
JS.Exception.Exploit, JS.Trojan.Seeker-based, EXCEPTION.E
Description:
This malicious JavaScript changes the startup page of an infected system’s Internet Explorer.
Solution:
To restore your startup page setting, Click Start>Run, type REGEDIT then hit the Enter key.
Double click the following:
HKEY_CURRENT_USER>Software>Microsoft
>Internet Explorer>Main
In the right panel, right-click the value “Start Page” and then select “Modify”.
Enter the URL of your original startup page.
Scan your system with Trend Micro antivirus and delete all files detected as JS_EXCEPTION.E. To do this Trend Micro customers must download the latest pattern file and scan their system. Other email users may use HouseCall, Trend Micro's free online virus scanner.
Trend Micro offers best-of-breed antivirus and content-security solutions for your corporate network or home PC.
Ciao Marco (amvinfe)