:OTL
SRV - (wscsvc) -- %SYSTEMROOT%\system32\wscsvc.dll File not found
SRV - (Guard.Mail.ru) -- File not found
SRV - (ERSvc) -- %SystemRoot%\System32\ersvc.dll File not found
SRV - (CiSvc) -- C:\WINDOWS\system32\cisvc.exe File not found
DRV - (zlportio) -- C:\Documents and Settings\Giuseppe\Desktop\NDZ\StudioNds211diMicrom ax\zlportio.sys File not found
DRV - (WDICA) -- File not found
DRV - (SANDRA) -- C:\Programmi\SiSoftware\SiSoftware Sandra Lite 2010c\WNt500x86\Sandra.sys File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (NSNDIS5) -- C:\WINDOWS\system32\NSNDIS5.SYS File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (catchme) -- C:\DOCUME~1\Giuseppe\IMPOST~1\Temp\catchme.sys File not found
IE - HKLM\..\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}: "URL" =
http://www.searchya.com/?q={searchTerms}&s=1&a=foxtab&chnl=tc-100&cd=2XzuyEtN2Y1L1QzutDtDtCtAtDtByB0DyE0C0BzztCy E0FtAtN0D0Tzu0StByEyBtN1L2XzutBtFtCtFtCtFtAtCtB&cr =1748634089
IE - HKU\S-1-5-21-1960408961-261478967-527237240-1003\..\SearchScopes\{30F5AB16-9F1E-4E99-93F2-ECB9ABB0EC12}: "URL" =
http://www.searchya.com/?q={searchTerms}&s=1&a=foxtab&chnl=tc-100&cd=2XzuyEtN2Y1L1QzutDtDtCtAtDtByB0DyE0C0BzztCy E0FtAtN0D0Tzu0StByEyBtN1L2XzutBtFtCtFtCtFtAtCtB&cr =1748634089
IE - HKU\S-1-5-21-1960408961-261478967-527237240-1003\..\SearchScopes\{C7576B9D-B442-46bc-AF74-080A9E723E01}: "URL" =
http://websearch.search-results.com/...705&src=crm&q={searchTerms}&locale=it_IT&apn_ptnrs=2R&apn_dtid=g et004YYIT&apn_uid=69004FC1-2BC5-4213-A88D-608D62495BF8&apn_sauid=2F2E8413-853F-4D73-AA5D-844C05BD9339
IE - HKU\S-1-5-21-1960408961-261478967-527237240-1003\..\SearchScopes\{E88E0043-C9D4-4e33-8555-FEE4F5B63060}: "URL" =
http://go.mail.ru/search?q={searchTerms}&utf8in=1&fr=ietb
FF - prefs.js..browser.search.defaulturl: "http://go.mail.ru/search?fr=fftb&utf8in&q="
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..extensions.enabledItems:
engine@conduit.com:3.2.5.2
FF - prefs.js..sweetim.toolbar.previous.browser.search. defaultenginename: "Search the web (Babylon)"
[2008/12/30 23.20.18 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Giuseppe\Dati applicazioni\Mozilla\Extensions
[2012/09/16 17.14.14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Giuseppe\Dati applicazioni\Mozilla\Firefox\Profiles\tzceetpe.def ault\extensions
[2012/07/25 19.06.20 | 000,741,958 | ---- | M] () (No name found) -- C:\Documents and Settings\Giuseppe\Dati applicazioni\Mozilla\Firefox\Profiles\tzceetpe.def ault\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2012/01/22 20.36.57 | 000,010,606 | ---- | M] () (No name found) -- C:\Documents and Settings\Giuseppe\Dati applicazioni\Mozilla\Firefox\Profiles\tzceetpe.def ault\extensions\{e8f509f0-b677-11de-8a39-0800200c9a66}.xpi
[2012/09/04 20.57.04 | 000,002,223 | ---- | M] () -- C:\Documents and Settings\Giuseppe\Dati applicazioni\Mozilla\Firefox\Profiles\tzceetpe.def ault\searchplugins\BabylonMngr.xml
[2011/11/29 20.58.45 | 000,001,867 | ---- | M] () -- C:\Documents and Settings\Giuseppe\Dati applicazioni\Mozilla\Firefox\Profiles\tzceetpe.def ault\searchplugins\findeer.xml
[2012/02/07 19.41.25 | 000,001,533 | ---- | M] () -- C:\Documents and Settings\Giuseppe\Dati applicazioni\Mozilla\Firefox\Profiles\tzceetpe.def ault\searchplugins\mailru---.xml
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfac es\{A51545C4-FC39-45C9-A823-A77F433623F7}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfac es\{B6BBE167-87B9-466F-BDE3-B375382844F0}: NameServer = 176.31.229.24,176.31.229.25
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
[2012/10/12 19.17.08 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/10/04 20.22.19 | 004,981,633 | R--- | C] (Swearware) -- C:\Documents and Settings\Giuseppe\Desktop\ComboFix.exe
[2012/09/04 20.56.57 | 000,384,835 | ---- | M] () -- C:\Documents and Settings\Giuseppe\Impostazioni locali\Dati applicazioni\speeddial.crx
[2012/10/17 17.56.03 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2012/10/17 17.56.03 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2012/10/17 17.56.03 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2012/10/17 17.56.03 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2012/10/17 17.56.03 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2012/07/06 20.22.56 | 000,384,844 | ---- | C] () -- C:\Documents and Settings\Giuseppe\Impostazioni locali\Dati applicazioni\funmoods-speeddial.crx
[2012/07/06 20.22.54 | 000,031,465 | ---- | C] () -- C:\Documents and Settings\Giuseppe\Impostazioni locali\Dati applicazioni\funmoods.crx
:Files
ipconfig /flushdns /c
:commands
[purity]
[Reboot]