:OTL
SRV - (MSDTC) -- File not found
DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (catchme) -- C:\ComboFix\catchme.sys File not found
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-20\..\SearchScopes\{1921ED09-583B-4B28-84F2-8BBDB35CEF39}: "URL" =
IE - HKU\S-1-5-20\..\SearchScopes\{7DB0124C-1A43-4F77-876C-79EA5BCF12C6}: "URL" =
IE - HKU\S-1-5-21-1078081533-261903793-1801674531-500\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-1078081533-261903793-1801674531-500\..\SearchScopes\{1921ED09-583B-4B28-84F2-8BBDB35CEF39}: "URL" =
IE - HKU\S-1-5-21-1078081533-261903793-1801674531-500\..\SearchScopes\{7DB0124C-1A43-4F77-876C-79EA5BCF12C6}: "URL" =
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
CHR - default_search_provider: search_url =
CHR - default_search_provider: suggest_url =
CHR - homepage:
[2012/10/20 14.38.25 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/10/20 14.35.01 | 004,984,242 | R--- | C] (Swearware) -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2012/10/20 14.38.57 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/10/20 14.38.57 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/10/20 14.38.57 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/10/20 14.38.57 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/10/20 14.38.57 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:C43ED645
@Alternate Data Stream - 111 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:5C321E34
:Files
ipconfig /flushdns /c
:commands
[purity]
[Reboot]