ho fatto alla lettera tutto quello che mi hai detto!!
l'unica cosa che non è riuscita è stato attivare questa voce:
Zero Configuration reti senza fili...mi da l'errore 1068 !! quindi per il momento il problema della connessione senza fili è rimasto. ....confido in te!! )
ho anche disattivato il punto di ripristino.
di seguito ti posto il file che mi hai chiesto di creare con conbofix:
ComboFix 09-06-26.02 - Michele Marini 28/06/2009 22.18.08.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.39.1040.18.1015.601 [GMT 2:00]
Eseguito da: c:\documents and settings\Michele Marini\Desktop\abc.exe
Opzioni usate :: c:\documents and settings\Michele Marini\Desktop\CFScript.txt
AV: avast! antivirus 4.8.1335 [VPS 090628-0] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D}
.
((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\All Users\Dati applicazioni\Macrovision\FLEXnet Connect\6\ISUSPM.exe
c:\documents and settings\Michele Marini\Dati applicazioni\drivers\downld
c:\windows\temp\Perflib_Perfdata_70c.dat
c:\windows\temp\Perflib_Perfdata_75c.dat
c:\windows\temp\WGAErrLog.txt
c:\windows\temp . . . . Eliminazione Fallita
c:\windows\temp\Perflib_Perfdata_4bc.dat . . . . Eliminazione Fallita
.
((((((((((((((((((((((((( Files Creati Da 2009-05-28 al 2009-06-28 )))))))))))))))))))))))))))))))))))
.
2009-07-27 00:51 . 2009-07-27 09:01 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\avg8
2009-07-27 00:51 . 2009-07-27 00:51 -------- d-----w- c:\programmi\AVG
2009-07-26 11:50 . 2009-06-28 20:20 -------- d--h--w- c:\documents and settings\Michele Marini\Dati applicazioni\drivers
2009-07-25 11:24 . 2009-07-26 08:21 -------- d-----w- c:\windows\SxsCaPendDel
2009-07-25 08:08 . 2009-07-25 08:08 152576 ----a-w- c:\documents and settings\Michele Marini\Dati applicazioni\Sun\Java\jre1.6.0_13\lzma.dll
2009-06-28 19:33 . 2009-02-05 20:08 94032 ----a-w- c:\windows\system32\drivers\aswmon2.sys
2009-06-28 19:33 . 2009-02-05 20:07 114768 ----a-w- c:\windows\system32\drivers\aswSP.sys
2009-06-28 19:33 . 2009-02-05 20:07 20560 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
2009-06-28 19:33 . 2009-02-05 20:06 51376 ----a-w- c:\windows\system32\drivers\aswTdi.sys
2009-06-28 19:33 . 2009-02-05 20:06 23152 ----a-w- c:\windows\system32\drivers\aswRdr.sys
2009-06-28 19:33 . 2009-02-05 20:05 26944 ----a-w- c:\windows\system32\drivers\aavmker4.sys
2009-06-28 18:48 . 2009-06-28 18:48 -------- dc----w- c:\windows\system32\dllcache\cache
2009-06-27 15:13 . 2009-06-27 16:33 -------- d-----w- c:\windows\BDOSCAN8
2009-06-27 12:40 . 2009-02-05 20:04 97480 ----a-w- c:\windows\system32\AvastSS.scr
2009-06-27 12:40 . 2009-02-05 20:08 93296 ----a-w- c:\windows\system32\drivers\aswmon.sys
2009-06-27 12:39 . 2009-02-05 20:11 1256296 ----a-w- c:\windows\system32\aswBoot.exe
2009-06-17 10:21 . 2009-06-17 10:31 -------- d-----w- c:\documents and settings\Michele Marini\Dati applicazioni\Software Informer
2009-06-17 10:21 . 2009-06-17 10:21 -------- d-----w- c:\programmi\Software Informer
2009-06-15 16:19 . 2009-06-15 16:19 -------- d-----w- c:\documents and settings\Michele Marini\Impostazioni locali\Dati applicazioni\PCHealth
2009-06-10 11:56 . 2009-06-10 12:00 -------- d-----w- C:\TEMP
2009-06-10 11:43 . 2009-06-10 11:43 -------- d-----w- c:\documents and settings\Michele Marini\Dati applicazioni\GPass
2009-06-10 07:21 . 2009-06-10 07:21 -------- d-----w- c:\programmi\Your Company Name
2009-06-10 07:21 . 2009-06-10 07:21 -------- d-----w- C:\DIGITALGRAPH
2009-06-06 12:08 . 2009-06-06 12:08 -------- d-----w- c:\programmi\QuickTime
2009-06-06 12:08 . 2009-06-06 12:08 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Apple Computer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-27 09:13 . 2009-01-14 06:09 -------- d--h--w- c:\programmi\InstallShield Installation Information
2009-07-25 11:47 . 2009-01-14 06:17 -------- d-----w- c:\programmi\Windows Live
2009-07-25 08:34 . 2009-01-14 06:27 -------- d-----w- c:\programmi\Java
2009-06-27 12:39 . 2009-03-23 21:09 -------- d-----w- c:\programmi\Alwil Software
2009-06-22 12:39 . 2009-03-27 18:00 -------- d-----w- c:\documents and settings\Michele Marini\Dati applicazioni\Skype
2009-06-22 09:27 . 2009-03-27 18:03 -------- d-----w- c:\documents and settings\Michele Marini\Dati applicazioni\skypePM
2009-06-15 15:02 . 2009-03-24 13:47 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Microsoft Help
2009-06-04 00:40 . 2009-01-14 04:10 75606 ----a-w- c:\windows\system32\perfc010.dat
2009-06-04 00:40 . 2009-01-14 04:10 450968 ----a-w- c:\windows\system32\perfh010.dat
2009-05-26 16:21 . 2009-05-26 16:21 -------- d-----w- c:\programmi\Trend Micro
2009-05-26 15:23 . 2009-04-29 18:57 -------- d-----w- c:\programmi\eMule AdunanzA
2009-05-26 07:55 . 2009-05-20 08:17 -------- d-----w- c:\programmi\File comuni\Ahead
2009-05-26 07:55 . 2009-05-20 08:17 -------- d-----w- c:\programmi\Ahead
2009-05-21 16:01 . 2009-05-21 16:01 -------- d-----w- c:\programmi\BurnAware Free
2009-05-18 11:07 . 2009-05-16 16:06 -------- d-----w- c:\documents and settings\Michele Marini\Dati applicazioni\dvdcss
2009-05-13 12:10 . 2009-05-13 12:09 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\EPSON
2009-05-13 12:09 . 2009-05-13 12:09 -------- d-----w- c:\programmi\EPSON
2009-05-12 12:04 . 2009-05-12 12:03 -------- d-----w- c:\documents and settings\Michele Marini\Dati applicazioni\vlc
2009-05-12 12:02 . 2009-05-12 12:02 -------- d-----w- c:\programmi\VideoLAN
2009-05-07 15:32 . 2009-01-14 04:10 347648 ----a-w- c:\windows\system32\localspl.dll
2009-05-05 22:22 . 2009-05-05 22:22 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\InstallShield
2009-05-05 22:21 . 2009-05-05 22:21 -------- d-----w- c:\programmi\H3G
2009-05-05 22:21 . 2009-01-14 06:08 -------- d-----w- c:\programmi\File comuni\InstallShield
2009-05-02 09:32 . 2009-05-02 09:32 -------- d-----w- c:\programmi\Google
2009-04-30 00:53 . 2009-04-29 19:10 -------- d-----w- c:\documents and settings\Michele Marini\Dati applicazioni\DivX
2009-04-29 04:45 . 2009-01-14 04:10 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:44 . 2009-01-14 04:10 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-28 14:49 . 2009-04-28 14:49 0 ----a-w- c:\windows\nsreg.dat
2009-04-19 19:47 . 2009-01-14 04:10 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 20:25 . 2009-04-29 19:08 9464 ------w- c:\windows\system32\drivers\cdralw2k.sys
2009-04-15 20:25 . 2009-04-29 19:08 9336 ------w- c:\windows\system32\drivers\cdr4_xp.sys
2009-04-15 20:25 . 2009-04-29 19:08 43528 ------w- c:\windows\system32\drivers\PxHelp20.sys
2009-04-15 20:25 . 2009-04-29 19:08 129784 ------w- c:\windows\system32\pxafs.dll
2009-04-15 20:25 . 2009-04-29 19:08 120056 ------w- c:\windows\system32\pxcpyi64.exe
2009-04-15 20:25 . 2009-04-29 19:08 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-04-15 20:24 . 2009-04-15 20:24 90112 ----a-w- c:\windows\system32\dpl100.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w- c:\windows\system32\divx_xx0c.dll
2009-04-15 20:24 . 2009-04-15 20:24 823296 ----a-w- c:\windows\system32\divx_xx07.dll
2009-04-15 20:24 . 2009-04-15 20:24 815104 ----a-w- c:\windows\system32\divx_xx0a.dll
2009-04-15 20:24 . 2009-04-15 20:24 802816 ----a-w- c:\windows\system32\divx_xx11.dll
2009-04-15 20:24 . 2009-04-15 20:24 684032 ----a-w- c:\windows\system32\DivX.dll
2009-04-15 14:52 . 2009-01-14 04:10 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2008-05-07 08:34 . 2009-01-14 06:20 15523560 ----a-w- c:\programmi\U1 Setup.exe
2009-04-15 20:24 . 2009-04-15 20:24 1044480 ----a-w- c:\programmi\mozilla firefox\plugins\libdivx.dll
2009-04-15 20:24 . 2009-04-15 20:24 200704 ----a-w- c:\programmi\mozilla firefox\plugins\ssldivx.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-06-28_18.47.37 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-28 20:22 . 2009-06-28 20:22 16384 c:\windows\Temp\Perflib_Perfdata_73c.dat
+ 2009-06-28 20:22 . 2009-06-28 20:22 16384 c:\windows\Temp\Perflib_Perfdata_4bc.dat
+ 2009-06-28 18:48 . 2008-10-16 13:09 51224 c:\windows\system32\dllcache\cache\wuauclt.exe
+ 2009-06-28 18:48 . 2008-04-14 12:00 82432 c:\windows\system32\dllcache\cache\ws2_32.dll
+ 2009-06-28 18:48 . 2008-04-14 12:00 26624 c:\windows\system32\dllcache\cache\userinit.exe
+ 2009-06-28 18:48 . 2008-04-14 12:00 14336 c:\windows\system32\dllcache\cache\svchost.exe
+ 2009-06-28 18:48 . 2008-04-14 12:00 57856 c:\windows\system32\dllcache\cache\spoolsv.exe
+ 2009-06-28 18:48 . 2008-04-14 12:00 17408 c:\windows\system32\dllcache\cache\powrprof.dll
+ 2009-06-28 18:48 . 2008-04-14 12:00 13312 c:\windows\system32\dllcache\cache\lsass.exe
+ 2009-06-28 18:48 . 2008-04-14 12:00 25088 c:\windows\system32\dllcache\cache\kbdclass.sys
+ 2009-06-28 18:48 . 2008-04-14 12:00 36608 c:\windows\system32\dllcache\cache\ip6fw.sys
+ 2009-06-28 18:48 . 2008-04-14 12:00 15360 c:\windows\system32\dllcache\cache\ctfmon.exe
+ 2009-06-28 18:48 . 2008-04-14 12:00 510464 c:\windows\system32\dllcache\cache\winlogon.exe
+ 2009-06-28 18:48 . 2009-04-29 04:45 827392 c:\windows\system32\dllcache\cache\wininet.dll
+ 2009-06-28 18:48 . 2008-04-14 12:00 579584 c:\windows\system32\dllcache\cache\user32.dll
+ 2009-06-28 18:48 . 2008-04-14 12:00 296960 c:\windows\system32\dllcache\cache\termsrv.dll
+ 2009-06-28 18:48 . 2008-06-20 11:51 361600 c:\windows\system32\dllcache\cache\tcpip.sys
+ 2009-06-28 18:48 . 2009-02-09 11:22 111104 c:\windows\system32\dllcache\cache\services.exe
+ 2009-06-28 18:48 . 2008-04-14 12:00 182656 c:\windows\system32\dllcache\cache\ndis.sys
+ 2009-06-28 18:48 . 2008-04-14 12:00 110080 c:\windows\system32\dllcache\cache\imm32.dll
+ 2009-06-28 18:48 . 2008-04-14 12:00 1571840 c:\windows\system32\dllcache\cache\sfcfiles.dll
+ 2009-06-28 18:48 . 2009-02-09 11:22 2148864 c:\windows\system32\dllcache\cache\ntoskrnl.exe
+ 2009-06-28 18:48 . 2009-02-09 11:23 2027520 c:\windows\system32\dllcache\cache\ntkrnlpa.exe
+ 2009-06-28 18:48 . 2009-03-21 14:06 1033728 c:\windows\system32\dllcache\cache\kernel32.dll
+ 2009-06-28 18:48 . 2008-04-14 12:00 1036288 c:\windows\system32\dllcache\cache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="c:\programmi\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"googletalk"="c:\programmi\Google\Google Talk\googletalk.exe" [2007-11-21 3293184]
"Google Update"="c:\documents and settings\Michele Marini\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2009-06-11 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-12-19 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-12-19 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2007-12-19 131072]
"AsusTray"="c:\programmi\EeePC\ACPI\AsTray.exe" [2008-12-04 114688]
"AsusACPIServer"="c:\programmi\EeePC\ACPI\AsAcpiSvr.exe" [2008-12-17 622592]
"AsusEPCMonitor"="c:\programmi\EeePC\ACPI\AsEPCMon.exe" [2008-05-21 94208]
"ETDWare"="c:\programmi\Elantech\ETDCtrl.exe" [2008-11-24 329728]
"GrooveMonitor"="c:\programmi\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
"QuickTime Task"="c:\programmi\QuickTime\QTTask.exe" [2009-05-26 413696]
"SunJavaUpdateSched"="c:\programmi\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-02-05 81000]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2008-09-18 16855040]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
BTTray.lnk - c:\programmi\WIDCOMM\Bluetooth Software\BTTray.exe [2008-9-2 604776]
VPN Client.lnk - c:\windows\Installer\{B5CB0955-2A43-42F4-A44F-5C2BFC52E977}\Icon3E5562ED7.ico [2009-3-24 6144]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Programmi\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Programmi\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"c:\\Programmi\\Google\\Google Talk\\googletalk.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [28/06/2009 21.33.51 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [28/06/2009 21.33.51 20560]
R3 AsusACPI;ASUS ACPI Driver;c:\windows\system32\drivers\ASUSACPI.SYS [14/01/2009 8.12.10 10752]
R3 Ktp;Elantech Smart-Pad;c:\windows\system32\drivers\ETD.sys [01/08/2008 4.24.18 25216]
R3 L1e;Miniport Driver for Atheros AR8121/AR8113/AR8114 PCI-E Ethernet Controller;c:\windows\system32\drivers\l1e51x86.sys [04/11/2008 11.28.53 38400]
S3 bsusbser;H3G USB Device for Legacy Serial Communication;c:\windows\system32\drivers\bsusbser.sys [06/05/2009 0.20.51 94848]
.
Contenuto della cartella 'Scheduled Tasks'
2009-06-20 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]
2009-07-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1220309626-2181335416-4134540385-1006.job
- c:\documents and settings\Michele Marini\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-06-11 08:57]
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
HKCU-Run-ISUSPM - c:\documents and settings\All Users\Dati applicazioni\Macrovision\FLEXnet Connect\6\ISUSPM.exe
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.google.it/
uInternet Connection Wizard,ShellNext = hxxp://www.eeestorage.com/tutorial/quickstart/?c=0
uInternet Settings,ProxyOverride = local
IE: E&sporta in Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Invia a Bluetooth - c:\programmi\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: Invia a periferica &Bluetooth... - c:\programmi\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
TCP: {620CA131-E5FF-42F9-A6A7-B9D1A0D2F4F5} = 151.99.125.1,151.100.8.33
FF - ProfilePath - c:\documents and settings\Michele Marini\Dati applicazioni\Mozilla\Firefox\Profiles\e1mqdyvc.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.it/
FF - plugin: c:\documents and settings\Michele Marini\Impostazioni locali\Dati applicazioni\Google\Update\1.2.145.5\npGoogleOneClick8.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-06-28 22:23
Windows 5.1.2600 Service Pack 3 NTFS
scansione processi nascosti ...
scansione entrate autostart nascoste ...
Scansione files nascosti ...
Scansione completata con successo
Files nascosti: 0
**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------
- - - - - - - > 'explorer.exe'(136)
c:\windows\system32\btmmhook.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\programmi\Alwil Software\Avast4\aswUpdSv.exe
c:\programmi\Alwil Software\Avast4\ashServ.exe
c:\programmi\Cisco Systems\VPN Client\cvpnd.exe
c:\programmi\File comuni\InterVideo\RegMgr\iviRegMgr.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\programmi\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\WgaTray.exe
c:\windows\system32\igfxsrvc.exe
c:\windows\system32\igfxext.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Ora fine scansione: 2009-06-28 22.26.31 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2009-06-28 20:26
ComboFix2.txt 2009-06-28 18:50
Pre-Run: 61.486.440.448 byte disponibili
Post-Run: 61.465.718.784 byte disponibili
236 --- E O F --- 2009-06-15 15:03