ciao e grazie
allora,io fatto tutto quello che hai detto al 100% ( quando ho Avviato XP TCP Repair l'ho fatto con la linea wifi e bluetooth attivata ) ho riavviato e la connessione si è ristabilita ma,
parte scarica e si ferma tipo a 4 oppure a 10 ,se faccio aggiorna con l'antivirus a volte lo aggiorna a volte no xkè appunto non scarica,ma se avvio explorer non si connette per niente.
i numeri di ip router/pc si sono ristabiliti ,di sotto riporto il log del combofix.
ComboFix 11-08-04.02 - 武末志麻 2011/08/07 17:56:29.2.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.932.81.1041.18.1015.484 [GMT 9:00]
Running from: c:\documents and settings\武末志麻\デスクトップ\ComboFix.exe
Command switches used :: c:\documents and settings\武末志麻\デスクトップ\CFScript.txt
AV: Sistema Antivirus NOD32 2.70 *Enabled/Outdated* {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Created a new restore point
* Resident AV is active
.
.
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
FILE ::
"c:\program files\Proxy Labs\ProxyCap\pcapsvc.exe"
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
-------\Legacy_PCAPSVC
-------\Service_pcapsvc
.
.
((((((((((((((((((((((((( Files Created from 2011-07-07 to 2011-08-07 )))))))))))))))))))))))))))))))
.
.
2011-08-03 22:06 . 2011-08-03 22:06 -------- d-----w- c:\documents and settings\武末志麻\Application Data\Malwarebytes
2011-08-03 22:06 . 2011-07-06 10:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-08-03 22:06 . 2011-08-03 22:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-08-03 22:06 . 2011-07-06 10:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-08-03 22:06 . 2011-08-03 22:06 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-08-03 21:09 . 2011-08-03 21:09 388096 ----a-r- c:\documents and settings\武末志麻\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-08-03 21:09 . 2011-08-03 21:09 -------- d-----w- c:\program files\Trend Micro
2011-08-01 13:17 . 2011-08-01 13:17 315392 ----a-w- c:\windows\system32\sbcrreag.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-08-04 08:33 . 2008-05-16 12:00 1294200 ----a-w- c:\windows\system32\drivers\BCMWL5.SYS
2011-07-06 07:21 . 2011-06-01 07:23 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-06 11:35 . 2008-04-15 04:00 1858560 ----a-w- c:\windows\system32\win32k.sys
.
.
(((((((((((((((((((((((((((((
SnapShot@2011-08-05_07.40.51 )))))))))))))))))))))))))))))))))))))))))
.
+ 2011-08-07 09:06 . 2011-08-07 09:06 16384 c:\windows\temp\Perflib_Perfdata_250.dat
- 2008-07-08 05:04 . 2011-08-04 11:54 96736 c:\windows\system32\perfc011.dat
+ 2008-07-08 05:04 . 2011-08-05 08:13 96736 c:\windows\system32\perfc011.dat
- 2008-07-08 05:04 . 2011-08-04 11:54 96742 c:\windows\system32\perfc009.dat
+ 2008-07-08 05:04 . 2011-08-05 08:13 96742 c:\windows\system32\perfc009.dat
+ 2008-07-08 05:04 . 2011-08-05 08:13 294524 c:\windows\system32\perfh011.dat
- 2008-07-08 05:04 . 2011-08-04 11:54 294524 c:\windows\system32\perfh011.dat
- 2008-07-08 05:04 . 2011-08-04 11:54 507796 c:\windows\system32\perfh009.dat
+ 2008-07-08 05:04 . 2011-08-05 08:13 507796 c:\windows\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2010-03-20 23:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2010-03-20 23:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2010-03-20 23:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2010-03-20 23:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2010-03-20 23:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2010-03-20 23:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2010-03-20 23:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2010-03-20 23:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2010-03-20 23:55 87304 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2008-04-15 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2008-04-15 455168]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
"IDTSysTrayApp"="sttray.exe" [2008-08-30 442477]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-08-30 442477]
"AESTFltr"="c:\windows\system32\AESTFltr.exe" [2008-08-28 471040]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-31 1343488]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"HP Mobile Broadband"="c:\swsetup\HPQWWAN\HPMobileBroadband.exe" [2008-07-08 439600]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2008-04-15 488752]
"IME JPN 2007 Migration"="c:\progra~1\COMMON~1\MICROS~1\IME12\IMEJP\IMJPKLMG.EXE" [2009-02-13 63856]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2008-03-11 689488]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-18 1848648]
"OWS Setup CmdLine"="c:\program files\Common Files\Microsoft Shared\Web Server Extensions\40\bin\cfgwiz.exe" [2003-03-24 188480]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2010-03-13 949376]
"UpdateReminder"="c:\program files\Eset\UpdateReminder.exe" [2011-07-19 462848]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-04-08 254696]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-06 449584]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="ctfmon.exe" [2008-04-15 15360]
.
c:\documents and settings\All Users\スタート メニュー\プログラム\スタートアップ\
BTTray.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-7-30 604776]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [2006-7-3 65588]
サービス マネージャ.lnk - c:\mssql7\Binn\sqlmangr.exe [2009-2-21 110592]
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\keyboard layouts\e0200411]
Ime File REG_SZ imjp12.ime
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
.
R1 nod32drv;nod32drv;c:\windows\system32\drivers\nod32drv.sys [2010/03/13 22:06 15424]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [2011/08/04 7:06 366640]
R2 MSSQL$YDR3MSSQL;SQL Server (YDR3MSSQL);c:\program files\Microsoft SQL Server\MSSQL10.YDR3MSSQL\MSSQL\Binn\sqlservr.exe [2009/03/30 3:25 43010392]
R2 RELNITRO;Datalight Reliance Nitro File System;c:\program files\Datalight\Reliance Nitro Windows Driver\driver\wxp\relnitro.sys [2010/10/27 15:52 410880]
R3 AESTAud;AE Audio Service;c:\windows\system32\drivers\AESTAud.sys [2008/11/13 20:27 112128]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2011/08/04 7:06 22712]
S3 Rockey_USB;Feitian ROCKEY4 USB Service;c:\windows\system32\drivers\Rockey4USB.sys [2009/06/12 18:42 12928]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\sqladhlp.exe [2009/03/31 13:58 47128]
S4 RsFx0103;RsFx0103 Driver;c:\windows\system32\drivers\RsFx0103.sys [2009/03/30 3:09 239336]
S4 SQLAgent$YDR3MSSQL;SQL Server Agent (YDR3MSSQL);c:\program files\Microsoft SQL Server\MSSQL10.YDR3MSSQL\MSSQL\Binn\SQLAGENT.EXE [2009/03/30 3:23 366936]
.
Contents of the 'Scheduled Tasks' folder
.
2011-05-04 c:\windows\Tasks\User_Feed_Synchronization-{C5F5F60E-C82F-44B5-B9ED-DD5CA8D5EEAF}.job
- c:\windows\system32\msfeedssync.exe [2007-08-13 19:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
IE: Bluetooth デバイスに送信(&B) - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Bluetooth ヘ送る - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
LSP: c:\windows\system32\imon.dll
LSP: pcapwsp.dll
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-08-07 18:09
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
.
[HKEY_USERS\LocalService\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
.
[HKEY_USERS\S-1-5-20\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
.
[HKEY_USERS\S-1-5-21-3161500679-3779893021-49558662-1006\AppEvents\Schemes\Apps\Conf\*・^\.Current]
@="c:\\Program Files\\NetMeeting\\Blip.wav"
.
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*ウ0・ン0・ヘ0・ネ0\CLSID]
@="{809B6661-94C4-49E6-B6EC-3F0F862215AA}"
.
[HKEY_LOCAL_MACHINE\software\Classes\B*D*A*T*u*n*e*r*.*ウ0・ン0・ヘ0・ネ0\CurVer]
@="BDATuner.コンポーネント.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{6af09ec9-b429-11d4-a1fb-0090960218cb}\Shell\B*l*u*e*t*o*o*t*h* *ヌ0ミ0、0ケ0n0匠R\Command]
@="rundll32.exe c:\\WINDOWS\\system32\\BtWizard.dll,ShowWizard"
.
[HKEY_LOCAL_MACHINE\software\HPQ\{4264742F-0322-4ba5-9657-A798C5C37AD6}\Main\・・カ0・ *ャ0、0ノ0]
"Description"="ユーザー ガイド"
"Command"="c:\\Program Files\\Hewlett-Packard\\Documentation\\HpDocViewer.exe"
"Parameters"=""
"IconPath"="c:\\Program Files\\Hewlett-Packard\\Documentation\\hp_user_guides_on_state.gif"
"IconHoverPath"="c:\\Program Files\\Hewlett-Packard\\Documentation\\hp_user_guides_over_state.gif"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(448)
c:\windows\system32\imjp12.ime
c:\windows\system32\imjp12k.dll
c:\progra~1\COMMON~1\MICROS~1\IME12\IMEJP\IMJPAPI.DLL
c:\progra~1\COMMON~1\MICROS~1\IME12\SHARED\IMJKAPI.DLL
c:\progra~1\COMMON~1\MICROS~1\IME12\IMEJP\IMJPPRED.DLL
.
- - - - - - - > 'explorer.exe'(4048)
c:\windows\system32\imjp12.ime
c:\windows\system32\imjp12k.dll
c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
c:\program files\TortoiseSVN\bin\TortoiseStub.dll
c:\program files\TortoiseSVN\bin\TortoiseSVN.dll
c:\program files\TortoiseSVN\bin\intl3_tsvn.dll
c:\progra~1\COMMON~1\MICROS~1\IME12\IMEJP\IMJPAPI.DLL
c:\progra~1\COMMON~1\MICROS~1\IME12\SHARED\IMJKAPI.DLL
c:\progra~1\COMMON~1\MICROS~1\IME12\IMEJP\IMJPPRED.DLL
c:\windows\system32\btmmhook.dll
c:\windows\system32\wpdshext.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\Audiodev.dll
c:\windows\system32\WMVCore.DLL
c:\windows\system32\WMASF.DLL
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\windows\system32\PortableDeviceTypes.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
c:\program files\IDT\WDM\STacSV.exe
c:\windows\system32\conime.exe
c:\program files\Canon\IJPLM\IJPLMSVC.EXE
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\TortoiseSVN\bin\TSVNCache.exe
c:\mssql7\binn\sqlservr.exe
c:\program files\Eset\nod32krn.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\windows\sttray.exe
c:\windows\system32\igfxsrvc.exe
c:\mssql7\binn\sqlagent.exe
c:\program files\Hewlett-Packard\Shared\hpqwmiex.exe
c:\program files\Hewlett-Packard\Shared\HpqToaster.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2011-08-07 18:13:12 - machine was rebooted
ComboFix-quarantined-files.txt 2011-08-07 09:13
ComboFix2.txt 2011-08-05 07:43
.
Pre-Run: 32,408,895,488 バイトの空き領域
Post-Run: 32,292,470,784 バイトの空き領域
.
- - End Of File - - 78D7EE98B2B6CDA9DB696010130F77CE