Ciao fatto tutto tranne l'aggiornamento di malwarebytes perchè non posso connetermi.
Ti allego il log di avenger:
//////////////////////////////////////////
Avenger Pre-Processor log
//////////////////////////////////////////
Platform: Windows XP (build 2600, Service Pack 3)
Sun Jan 04 22:56:30 2009
22:56:30: Error: Invalid script. A valid script must begin with a command directive.
Aborting execution!
//////////////////////////////////////////
Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.comPlatform: Windows XP
*******************
Script file opened successfully.
Script file read successfully.
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
Rootkit scan active.
Hidden driver "TDSSserv.sys" found!
ImagePath: \systemroot\system32\drivers\TDSSpaxt.sys
Driver disabled successfully.
Rootkit scan completed.
File "C:\WINDOWS\system32\csrcs.exe" deleted successfully.
File "c:\WINDOWS\system32\sysmgr.exe" deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
E quindi quello di malwarebytes:
Malwarebytes' Anti-Malware 1.31
Versione del database: 1456
Windows 5.1.2600 Service Pack 3
04/01/2009 23.39.19
mbam-log-2009-01-04 (23-39-12).txt
Tipo di scansione: Scansione completa (C:\|)
Elementi scansionati: 84486
Tempo trascorso: 20 minute(s), 48 second(s)
Processi delle memoria infetti: 0
Moduli della memoria infetti: 4
Chiavi di registro infette: 35
Valori di registro infetti: 5
Elementi dato del registro infetti: 7
Cartelle infette: 6
File infetti: 44
Processi delle memoria infetti:
(Nessun elemento malevolo rilevato)
Moduli della memoria infetti:
C:\WINDOWS\system32\gadonesi.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\panosuba.dll (Trojan.Vundo.H) -> No action taken.
c:\WINDOWS\system32\seregapo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\jkse73hedfdgf.dll (Trojan.BHO) -> No action taken.
Chiavi di registro infette:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3f14a731-697b-4873-bece-1b50a7db0bbf} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{3f14a731-697b-4873-bece-1b50a7db0bbf} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.Zlob.H) -> No action taken.
HKEY_CLASSES_ROOT\CLSID\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> No action taken.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\bho_myjavacore.mjcore.1 (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{17e44256-51e0-4d46-a0c8-44e80ab4ba5b} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{50a1aa3b-80e3-15cf-0f1a-83a98ad98fe9} (Adware.Agent) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{7f68785e-4894-7bb2-5fde-cc3eee2ebc82} (Adware.Agent) -> No action taken.
HKEY_CLASSES_ROOT\Interface\{e698e657-649e-5d40-752d-9a3b78ea832a} (Adware.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{e0f01490-dcf3-4357-95aa-169a8c2b2190} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\Typelib\{fe3af205-54df-b146-1f0e-c9262829ed18} (Adware.Agent) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{80ef304a-b1c4-425c-8535-95ab6f1eefb8} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{ff46f4ab-a85f-487e-b399-3f191ac0fe23} (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{84d39d08-a551-a4e5-c8d1-3327573d4640} (Adware.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d88e1558-7c2d-407a-953a-c044f5607cea} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{f608c2d0-846d-4f0e-e47a-88367c887707} (Trojan.BHO) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d0661233-42d4-f7f1-80e1-8a9e0e99e71d} (Adware.Agent) -> No action taken.
HKEY_CLASSES_ROOT\AppID\BHO_MyJavaCore.DLL (Trojan.BHO) -> No action taken.
HKEY_CLASSES_ROOT\AppID\testCPV6.DLL (Trojan.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\SpeedRunner (Adware.SurfAccuracy) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Mirar (Adware.Mirar) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\BrowsingTool (Adware.Agent) -> No action taken.
HKEY_CLASSES_ROOT\AppID\BrowsingTool.DLL (Adware.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\FBrowsingAdvisor (Trojan.FBrowsingAdvisor) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\fbrowsingadvisor_is1 (Trojan.FBrowsingAdvisor) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\dslcnnct (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> No action taken.
Valori di registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\cpm67c6cc21 (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wibezudoge (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.Zlob.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ec43e3fd-5c60-46a6-97d7-e0b85dbdd6c4} (Trojan.Vundo.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\ssodl (Trojan.Vundo.H) -> No action taken.
Elementi dato del registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\gadonesi.dll -> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\gadonesi.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\gadonesi.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: c:\windows\system32\seregapo.dll -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs (Trojan.Vundo.H) -> Data: system32\seregapo.dll -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Internet Explorer\Control Panel\Homepage (Hijack.Homepage) -> Bad: (1) Good: (0) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> No action taken.
Cartelle infette:
C:\Programmi\FBrowsingAdvisor (Trojan.FBrowsingAdvisor) -> No action taken.
C:\Programmi\FBrowserAdvisor (Trojan.FBrowsingAdvisor) -> No action taken.
C:\Programmi\Webtools (Trojan.Agent) -> No action taken.
C:\Programmi\Mjcore (Trojan.BHO) -> No action taken.
C:\Documents and Settings\PASQUALE\Dati applicazioni\gadcom (Trojan.Agent) -> No action taken.
C:\Documents and Settings\PASQUALE\Dati applicazioni\speedrunner (Adware.SurfAccuracy) -> No action taken.
File infetti:
C:\WINDOWS\system32\gifepujo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\ojupefig.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\motufoyo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\oyofutom.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\nogilini.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\iniligon.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\sekanawo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\owanakes.ini (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\wazuloro.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\oroluzaw.ini (Trojan.Vundo.H) -> No action taken.
c:\WINDOWS\system32\seregapo.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\panosuba.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\jkse73hedfdgf.dll (Trojan.Zlob.H) -> No action taken.
C:\WINDOWS\system32\gadonesi.dll (Trojan.Vundo.H) -> No action taken.
C:\regxpcom.exe (Trojan.FBrowsingAdvisor) -> No action taken.
C:\Documents and Settings\PASQUALE\Desktop\Nuovi programmi PAPY\HiJackThis\backups\backup-20090102-024937-931.dll (Trojan.Vundo.H) -> No action taken.
C:\Documents and Settings\PASQUALE\Desktop\Nuovi programmi PAPY\HiJackThis\backups\backup-20090104-230756-973.dll (Trojan.Vundo.H) -> No action taken.
C:\Programmi\FBrowsingAdvisor\XPCOMEvents.dll (Trojan.FBrowsingAdvisor) -> No action taken.
C:\System Volume Information\_restore{908AD44F-A1AD-4BB2-ABD3-176C91A68107}\RP434\A0087899.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\TDSScfum.dll (Trojan.TDSS) -> No action taken.
C:\WINDOWS\system32\TDSSnrsr.dll (Trojan.TDSS) -> No action taken.
C:\WINDOWS\system32\TDSSofxh.dll (Trojan.TDSS) -> No action taken.
C:\WINDOWS\system32\TDSSriqp.dll (Trojan.TDSS) -> No action taken.
C:\WINDOWS\system32\zesifimi.dll (Trojan.Vundo.H) -> No action taken.
C:\WINDOWS\system32\drivers\TDSSpaxt.sys (Trojan.TDSS) -> No action taken.
C:\Programmi\FBrowsingAdvisor\IXPCOMEvents.xpt (Trojan.FBrowsingAdvisor) -> No action taken.
C:\Programmi\FBrowsingAdvisor\Logo.png (Trojan.FBrowsingAdvisor) -> No action taken.
C:\Programmi\FBrowsingAdvisor\main.db (Trojan.FBrowsingAdvisor) -> No action taken.
C:\Programmi\FBrowsingAdvisor\unins000.dat (Trojan.FBrowsingAdvisor) -> No action taken.
C:\Programmi\FBrowsingAdvisor\unins000.exe (Trojan.FBrowsingAdvisor) -> No action taken.
C:\Documents and Settings\PASQUALE\Dati applicazioni\gadcom\gadcom.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\PASQUALE\Dati applicazioni\gadcom\gadcom.exe6g0 (Trojan.Agent) -> No action taken.
C:\Documents and Settings\PASQUALE\Dati applicazioni\speedrunner\config.cfg (Adware.SurfAccuracy) -> No action taken.
C:\WINDOWS\system32\ieupdates.exe (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\msvcrt2.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\winsrc.dll (Adware.Toolbar) -> No action taken.
C:\WINDOWS\system32\Explorer32.exe (Backdoor.PoisonIvy) -> No action taken.
C:\WINDOWS\system32\tugokubu.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\hgGvwtTK.dll (Trojan.Vundo) -> No action taken.
C:\WINDOWS\system32\yayxyWPf.dll (Trojan.Vundo) -> No action taken.
C:\Documents and Settings\PASQUALE\Impostazioni locali\Temp\TDSS8d1e.tmp (Trojan.FakeAlert) -> No action taken.
C:\Documents and Settings\PASQUALE\Impostazioni locali\Temp\TDSS8dba.tmp (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\TDSSfxwp.dll (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\TDSStkdv.log (Trojan.TDSS) -> No action taken.
Grazie tante. A presto ...spero.