fatto tutto quello che mi hai detto!
dopo la scansione ho fatto rimuovi i file infettati, ma mi ha detto che alcuni di essi non potevano essere rimossi, mi ha chiesto di riavviare il pc e così ho fatto; subito dopo averlo riavviato mi è ricomparsa la stessa icona di avira con scritto TR/Downloader.Gen
cosa posso fare?
Grazieeeee
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.orgVersione database: 4733
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
02/10/2010 16.07.47
mbam-log-2010-10-02 (16-07-47).txt
Tipo di scansione: Scansione completa (C:\|D:\|E:\|)
Elementi esaminati: 208492
Tempo trascorso: 37 minuti, 48 secondi
Processi infetti in memoria: 0
Moduli di memoria infetti: 0
Chiavi di registro infette: 0
Valori di registro infetti: 19
Voci infette nei dati di registro: 2
Cartelle infette: 0
File infetti: 25
Processi infetti in memoria:
(Non sono stati rilevati elementi nocivi)
Moduli di memoria infetti:
(Non sono stati rilevati elementi nocivi)
Chiavi di registro infette:
(Non sono stati rilevati elementi nocivi)
Valori di registro infetti:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\cisvc (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\comrepl (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\rsvp (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ieudinit (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\clipsrv (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\cmstp (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\dllhst (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\logman (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\mqtgsvc (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\mstinit (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\spool (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\cmstp (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\dllhst (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\esent utl (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\ieudinit (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\mqtgsvc (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\mstinit (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\rsvp (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run\spool (Trojan.Agent) -> Quarantined and deleted successfully.
Voci infette nei dati di registro:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Data: d:\windows\system32\drivers\dllhst3g.exe -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\Load (Trojan.Agent) -> Data: system32\drivers\dllhst3g.exe -> Quarantined and deleted successfully.
Cartelle infette:
(Non sono stati rilevati elementi nocivi)
File infetti:
E:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP19\A0008500.exe (Hacktool.Keygen) -> Quarantined and deleted successfully.
E:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP19\A0008781.exe (Malware.Packer.Gen) -> Quarantined and deleted successfully.
D:\Documents and Settings\Administrator\Dati applicazioni\logman.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Documents and Settings\Administrator\Dati applicazioni\Microsoft\cmstp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Documents and Settings\Administrator\Dati applicazioni\Microsoft\logman.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Documents and Settings\Administrator\Dati applicazioni\Microsoft\mstinit.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Documents and Settings\Administrator\Dati applicazioni\mstinit.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Documents and Settings\Administrator\Dati applicazioni\mstsc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Documents and Settings\Administrator\Dati applicazioni\spoolsv.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\drivers\cisvc.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\drivers\comrepl.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\drivers\dllhst3g.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\drivers\logman.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system32\drivers\rsvp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Documents and Settings\Administrator\Impostazioni locali\Temp\mstinit.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\Documents and Settings\Administrator\Impostazioni locali\Temp\spoolsv.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
D:\WINDOWS\mstinit.exe (Trojan.Zaplo) -> Quarantined and deleted successfully.
D:\WINDOWS\rsvp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system\ieudinit.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system\clipsrv.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
D:\WINDOWS\system\logman.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system\cmstp.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\esentutl.exe (Trojan.Agent) -> Delete on reboot.
D:\Documents and Settings\Administrator\Dati applicazioni\Microsoft\ieudinit.exe (Trojan.Agent) -> Quarantined and deleted successfully.
D:\WINDOWS\system\rsvp.exe (Trojan.Agent) -> Quarantined and deleted successfully.