Ho avviato windows in modalità provvisoria e ho fatto partire l'avg.
L'antivirus individua i file infetti ma non riesce a cancellari
Ecco il log di hijackthis
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\dcmhelp.exe
C:\WINDOWS\commdlg32.exe
C:\Programmi\Internet Explorer\iexplore.exe
C:\Programmi\BitLord\BitLord.exe
C:\Documents and Settings\Danilo\Documenti\zDC++0.668z3Ita\zDCPlusPlus.exe
C:\Documents and Settings\Danilo\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.it/
O2 - BHO: ATLDistrib Object - {2353FCBC-012D-487B-8BF3-865C0929FBEB} - C:\WINDOWS\System32\mljjh.dll
O2 - BHO: (no name) - {EA32FB3B-21C9-42cc-B8EF-01A9B28EDB0D} - C:\WINDOWS\SYSTEM32\vtutt.dll
O4 - HKLM\..\Run: [Services] C:\w3.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{DC140897-C628-4F75-A6D6-190F1169D5A1}: NameServer = 85.37.17.51 151.99.125.1
O20 - Winlogon Notify: mljjh - C:\WINDOWS\System32\mljjh.dll
O20 - Winlogon Notify: vtutt - C:\WINDOWS\SYSTEM32\vtutt.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: commdlg (commdlg32) - Unknown owner - C:\WINDOWS\commdlg32.exe
O23 - Service: DcomHelper Service (DcomHelper) - Unknown owner - C:\WINDOWS\dcmhelp.exe
O23 - Service: Service Hosts (ServiceHost) - Unknown owner - C:\WINDOWS\shost.exe (file missing)
Ho provato a teminare il processo che ho evidenziato in neretto ma si riattiva. W3.exe è uno dei virus pached.gen insieme a tr.bat e tr.exe.