Hi Alexandrul, Now it works !!!! :-) :-) It was a virus ! I have run Malwarebytes Anti-malware 1.41 and it found some virus (I send you the logs in attachment), after removing them the problem disappeared. I have Kaspersky as antivirus, but, although a very good antivirus it failed to identify them. I didn't know this Malwarebytes, but it seems very powerful. Thanks anyhow for your exceptional help, I have really appreciated that !!!! Thanks again Marco
Malwarebytes' Anti-Malware 1.41 Database version: 2863 Windows 6.0.6002 Service Pack 2 26/09/2009 22.26.18 mbam-log-2009-09-26 (22-26-18).txt Scan type: Full Scan (C:\|D:\|) Objects scanned: 341703 Time elapsed: 1 hour(s), 26 minute(s), 14 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 1 Registry Data Items Infected: 0 Folders Infected: 2 Files Infected: 6 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\{ba603215-23f2-42ad-f4e4-00aac39caa53} (Trojan.Ertfor) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{ba603215-23f2-42ad-f4e4-00aac39caa53} (Trojan.Ertfor) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{ba603215-23f2-42ad-f4e4-00aac39caa53} (Trojan.Ertfor) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{ba603215-23f2-42ad-f4e4-00aac39caa53} (Trojan.Ertfor) -> Quarantined and deleted successfully. Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811 (Trojan.Agent) -> Quarantined and deleted successfully. C:\RECYCLER\s-1-5-21-0243936033-3052116371-381863308-1858 (Worm.Autorun) -> Quarantined and deleted successfully. Files Infected: C:\bqegh.exe (Trojan.Dropper) -> Quarantined and deleted successfully. C:\Windows\System32\beep.sys (Rootkit.Agent) -> Quarantined and deleted successfully. C:\Windows\System32\serfing.dll (Rootkit.Agent) -> Delete on reboot. C:\Windows\System32\drivers\serfing.sys (Rootkit.Agent) -> Quarantined and deleted successfully. C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\Desktop.ini (Trojan.Agent) -> Quarantined and deleted successfully. C:\RECYCLER\s-1-5-21-0243936033-3052116371-381863308-1858\Desktop.ini (Worm.Autorun) -> Quarantined and deleted successfully.