codice:
:OTL
DRV - (Winsock - Google Desktop Search Backup Before Last Install) -- File not found
DRV - (Winsock - Google Desktop Search Backup Before First Install) -- File not found
DRV - (mbr) -- C:\DOCUME~1\pc\IMPOST~1\Temp\mbr.sys File not found
DRV - (avgtp) -- C:\WINDOWS\system32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (SrvcEPECioctl) -- C:\WINDOWS\system32\drivers\ECioctl.sys ()
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.findeer.com
IE - HKU\S-1-5-21-3746504194-3368175464-857427351-1006\..\SearchScopes\{12F29037-9B62-464F-9BC9-94BD28FD551E}: "URL" = http://search.zonealarm.com/search?src=sp&tbid=goughGA&Lan=en&q={searchTerms}&gu=d10a5dbb8b774314b1d6b5d49dd41720&tu=10G9y00BL2C01g0&sku=&tstsId=&ver=&&r=390
IE - HKU\S-1-5-21-3746504194-3368175464-857427351-1006\..\SearchScopes\{F5330079-B8B5-4DA9-A238-DAC6996CBF13}: "URL" = http://start.mysearchdial.com/results.php?f=4&q={searchTerms}&a=irmsd103&cd=2XzuyEtN2Y1L1QzutDtDtD0F0BtDyD0AyCzztCtBzz0FyB0FtN0D0Tzu0CyCyBtAtN1L2XzutBtFtBtFzztFtCtByEyBtN1L1Czu1L1C1H1B1QtCtDtA&cr=1681495981&ir=
CHR - Extension: Bitdefender QuickScan = C:\Documents and Settings\pc\Impostazioni locali\Dati applicazioni\Google\Chrome\User Data\Default\Extensions\pdnkcidphdcakpkheohlhocaicfamjie\0.9.9.131_0\
O3 - HKU\S-1-5-21-3746504194-3368175464-857427351-1006\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
O3 - HKU\S-1-5-21-3746504194-3368175464-857427351-1006\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No CLSID value found.
O3 - HKU\S-1-5-21-3746504194-3368175464-857427351-1006\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No CLSID value found.
[2013/12/11 23.53.45 | 000,010,244 | ---- | M] () -- C:\Documents and Settings\pc\Desktop\cc_20131211_235339.reg
[2013/12/05 15.17.39 | 000,000,724 | ---- | M] () -- C:\Documents and Settings\pc\Desktop\cc_20131205_151729.reg
[2013/10/21 13.59.25 | 000,001,955 | ---- | C] () -- C:\Documents and Settings\pc\Desktop\SpyHunter.lnk
[2010/10/21 01.00.22 | 000,000,024 | ---- | C] () -- C:\Documents and Settings\NetworkService\Dati applicazioni\sprkwi.dat
[2011/11/12 12.07.49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Edda\Dati applicazioni\AVG2012
[2012/12/01 23.48.36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Dati applicazioni\AVG
[2013/11/18 10.19.29 | 104,837,737 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\�鹸善6
[2013/11/18 10.19.29 | 104,837,737 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\�鹸善6
[2013/11/13 09.41.00 | 104,004,073 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\�扊善6
[2013/11/13 09.41.00 | 104,004,073 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\�扊善6
[2013/11/09 14.28.17 | 103,378,319 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\�善6
[2013/11/09 14.28.17 | 103,378,319 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\�善6
[2013/11/08 11.38.52 | 103,148,646 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\쎏⺭善6
[2013/11/08 11.38.52 | 103,148,646 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\쎏⺭善6
[2013/11/07 23.14.58 | 103,000,967 | ---- | M] ()(C:\WINDOWS\System32\í??6) -- C:\WINDOWS\System32\íꑤ善6
[2013/11/07 23.14.58 | 103,000,967 | ---- | C] ()(C:\WINDOWS\System32\í??6) -- C:\WINDOWS\System32\íꑤ善6
[2013/11/07 00.24.49 | 102,857,300 | ---- | M] ()(C:\WINDOWS\System32\?R?6) -- C:\WINDOWS\System32\ᘉŖ善6
[2013/11/07 00.24.49 | 102,857,300 | ---- | C] ()(C:\WINDOWS\System32\?R?6) -- C:\WINDOWS\System32\ᘉŖ善6
[2013/11/03 11.30.07 | 104,760,586 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ꓧ䤳善6
[2013/11/03 11.30.07 | 104,760,586 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ꓧ䤳善6
[2013/11/01 18.02.21 | 104,569,497 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\撤⑬善6
[2013/11/01 18.02.21 | 104,569,497 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\撤⑬善6
[2013/10/29 21.49.46 | 103,932,228 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\߳봜善6
[2013/10/29 21.49.46 | 103,932,228 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\߳봜善6
[2013/10/28 19.23.51 | 103,792,972 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\聞쫧善6
[2013/10/28 19.23.51 | 103,792,972 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\聞쫧善6
[2013/10/25 10.22.33 | 102,895,398 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\⽱善6
[2013/10/25 10.22.33 | 102,895,398 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\⽱善6
[2013/10/24 20.54.41 | 102,837,954 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\拨㾌善6
[2013/10/24 20.54.41 | 102,837,954 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\拨㾌善6
[2013/10/24 09.15.16 | 102,758,948 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\゚祁善6
[2013/10/24 09.15.16 | 102,758,948 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\゚祁善6
[2013/10/23 20.20.53 | 102,674,996 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\彆駷善6
[2013/10/23 20.20.53 | 102,674,996 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\彆駷善6
[2013/10/21 15.36.41 | 102,154,219 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\縡윻善6
[2013/10/21 15.36.41 | 102,154,219 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\縡윻善6
[2013/10/19 17.25.25 | 101,983,560 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\퓮햧善6
[2013/10/19 17.25.25 | 101,983,560 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\퓮햧善6
[2013/10/19 02.52.00 | 101,890,677 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㫋�善6
[2013/10/19 02.52.00 | 101,890,677 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㫋�善6
[2013/10/18 02.24.18 | 101,681,232 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\冪봶善6
[2013/10/18 02.24.18 | 101,681,232 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\冪봶善6
[2013/10/17 00.51.41 | 101,413,064 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\纖짼善6
[2013/10/17 00.51.41 | 101,413,064 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\纖짼善6
[2013/10/15 12.40.36 | 101,104,284 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\骨澬善6
[2013/10/15 12.40.36 | 101,104,284 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\骨澬善6
[2013/10/15 01.13.54 | 101,076,544 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ꩂƝ善6
[2013/10/15 01.13.54 | 101,076,544 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ꩂƝ善6
[2013/10/14 01.44.48 | 100,742,045 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\뽖짰善6
[2013/10/14 01.44.48 | 100,742,045 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\뽖짰善6
[2013/10/13 12.25.52 | 100,717,913 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\闡善6
[2013/10/13 12.25.52 | 100,717,913 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\闡善6
[2013/10/12 17.56.55 | 100,651,105 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\첣ܵ善6
[2013/10/12 17.56.55 | 100,651,105 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\첣ܵ善6
[2013/10/09 10.16.10 | 100,120,694 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\苩善6
[2013/10/09 10.16.10 | 100,120,694 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\苩善6
[2013/10/06 23.08.50 | 099,477,982 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\麧隿善6
[2013/10/06 23.08.50 | 099,477,982 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\麧隿善6
[2013/10/05 16.48.14 | 099,386,337 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\놢㭛善6
[2013/10/05 16.48.14 | 099,386,337 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\놢㭛善6
[2013/10/03 20.33.09 | 099,160,839 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\綒ጰ善6
[2013/10/03 20.33.09 | 099,160,839 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\綒ጰ善6
[2013/10/03 02.36.42 | 098,878,632 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㮏꣰善6
[2013/10/03 02.36.42 | 098,878,632 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\㮏꣰善6
[2013/10/02 14.36.16 | 098,743,931 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\唪욎善6
[2013/10/02 14.36.16 | 098,743,931 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\唪욎善6
[2013/10/01 19.41.33 | 098,612,549 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\渝⪪善6
[2013/10/01 19.41.33 | 098,612,549 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\渝⪪善6
[2013/09/29 19.57.14 | 098,466,785 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\䋨ﵚ善6
[2013/09/29 19.57.14 | 098,466,785 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\䋨ﵚ善6
[2013/09/29 14.01.23 | 098,462,899 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\讣韟善6
[2013/09/29 14.01.23 | 098,462,899 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\讣韟善6
[2013/09/28 18.49.49 | 098,442,955 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\吞ᕝ善6
[2013/09/28 18.49.49 | 098,442,955 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\吞ᕝ善6
[2013/09/26 15.32.52 | 097,961,477 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\뗞ᐒ善6
[2013/09/26 15.32.52 | 097,961,477 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\뗞ᐒ善6
[2013/09/25 20.36.53 | 097,858,179 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\廁ᱢ善6
[2013/09/24 22.05.35 | 097,858,179 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\廁ᱢ善6
[2013/09/16 19.02.47 | 097,787,879 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ओ튞善6
[2013/09/16 19.02.47 | 097,787,879 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ओ튞善6
[2013/09/13 09.46.31 | 097,446,370 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ྃ善6
[2013/09/13 09.46.31 | 097,446,370 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\ྃ善6
[2013/09/12 23.03.29 | 097,412,816 | ---- | M] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\矴틡善6
[2013/09/12 23.03.29 | 097,412,816 | ---- | C] ()(C:\WINDOWS\System32\???6) -- C:\WINDOWS\System32\矴틡善6
:Files
C:\WINDOWS\system32\drivers\avgtpx86.sys
C:\WINDOWS\system32\drivers\ECioctl.sys
C:\WINDOWS\System32\ESGScanner.sys
ipconfig /flushdns /c
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"
:commands
[purity]
[emptytemp]
[Emptyjava]
[RESETHOSTS]
[EMPTYFLASH]
[start explorer]
[Reboot]
Clicca sul pulsante