seleziona a sinistra queste voci e premi in basso fix checked:

F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\printer.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDO WS\system32\gcc.exe,C:\WINDOWS\system32\gcc.exe,C: \WINDOWS\system32\codeblocks.exe,C:\WINDOWS\system 32\vmware-ufad.exe,C:\WINDOWS\system32\undname.exe,
O4 - HKLM\..\Run: [C:\DOCUME~1\Guido\IMPOST~1\Temp\update.exe] C:\DOCUME~1\Guido\IMPOST~1\Temp\update.exe
O4 - HKLM\..\Run: [System] C:\WINDOWS\system32\kernelwind32.exe
O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
O4 - HKCU\..\Run: [autoload] C:\WINDOWS\system32\drivers\svchost.exe
O4 - HKCU\..\Run: [autorun] C:\Documents and Settings\Guido\svchost.exe
O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe
O4 - HKCU\..\Run: [WinAble] C:\Programmi\WinAble\winable.exe
O4 - HKLM\..\Policies\Explorer\Run: [4F27V1D89M] C:\WINDOWS\service32.exe
O4 - HKLM\..\Policies\Explorer\Run: [Service] C:\WINDOWS\sysnet32.exe
O4 - Startup: system.exe
O4 - Global Startup: autorun.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Pol icies\System, DisableRegedit=1
O20 - AppInit_DLLs: C:\WINDOWS\system32\systems.txt
O20 - Winlogon Notify: botreg - C:\Documents and Settings\All Users\Documenti\Settings\bot.dll

poi scarica avenger, link nella mia firma, aprilo, vai su input script manually, poi sulla lente e copia quanto segue:

Files to delete:
C:\DOCUME~1\Guido\IMPOST~1\Temp\
C:\WINDOWS\system32\kernelwind32.exe
C:\WINDOWS\system32\WinAvXX.exe
C:\WINDOWS\system32\drivers\svchost.exe
C:\Documents and Settings\Guido\svchost.exe
C:\Programmi\WinAble\winable.exe
C:\WINDOWS\service32.exe
C:\WINDOWS\sysnet32.exe
C:\WINDOWS\system32\systems.txt
C:\Documents and Settings\All Users\Documenti\Settings\bot.dll
C:\WINDOWS\AutoUpdateWin32.exe
C:\WINDOWS\system32\gcc.exe
C:\WINDOWS\system32\winavxx.exe
C:\WINDOWS\system32\dllh8jkd1q2.exe
C:\WINDOWS\system32\vedxg4am1et2.exe
C:\DOCUME~1\Guido\IMPOST~1\Temp\pa_0172.exe
C:\DOCUME~1\Guido\IMPOST~1\Temp\1.exe
C:\WINDOWS\TEMP\hd455.tmp
C:\WINDOWS\system32\codeblocks.exe
C:\WINDOWS\system32\vmware-ufad.exe
C:\WINDOWS\system32\undname.exe

Folders to delete:
C:\WINDOWS\TEMP
C:\DOCUME~1\Guido\IMPOST~1\Temp
C:\Programmi\WinAble


poi vai su done, poi sul semaforino, acconsenti, a questo punto il computer dovrebbe riavviarsi, altrimenti fallo tu. al riavvio posta il contenuto del blocco note che apparirà..

come va?