:OTL
SRV - (Application Updater) -- C:\Programmi\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
IE - HKLM\..\URLSearchHook: {9bb815eb-3f9f-4e11-9150-cb70e29b40fc} - C:\Programmi\Radio_Bar_2\tbRadi.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-1964839612-41541757-475487781-1000\..\URLSearchHook: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Programmi\IObit Toolbar\IE\6.9\iobitToolbarIE.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-1964839612-41541757-475487781-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\offerboxffx@offerbox.com: C:\Users\Benetollo\AppData\Roaming\OfferBox\offerboxffx@offerbox.com [2013/03/03 12.03.04 | 000,000,000 | ---D | M]
O2 - BHO: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Programmi\IObit Toolbar\IE\6.9\iobitToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (Radio Bar 2 Toolbar) - {9bb815eb-3f9f-4e11-9150-cb70e29b40fc} - C:\Programmi\Radio_Bar_2\tbRadi.dll (Conduit Ltd.)
O2 - BHO: (OfferBox) - {FC0D62C2-9640-4AEB-A5D5-CF25DF11FA8C} - C:\Programmi\OfferBox\OfferBoxBHO.dll (Secure Digital Services Limited)
O3 - HKLM\..\Toolbar: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Programmi\IObit Toolbar\IE\6.9\iobitToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Cercato Toolbar) - {545D2280-F50E-4F81-BF5A-CD04A6512CE2} - C:\Programmi\PopCorn\it\Toolbar\PopCorn.dll (E-Kanopi)
O3 - HKLM\..\Toolbar: (Radio Bar 2 Toolbar) - {9bb815eb-3f9f-4e11-9150-cb70e29b40fc} - C:\Programmi\Radio_Bar_2\tbRadi.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-1964839612-41541757-475487781-1000\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-1964839612-41541757-475487781-1000\..\Toolbar\WebBrowser: (Radio Bar 2 Toolbar) - {9BB815EB-3F9F-4E11-9150-CB70E29B40FC} - C:\Programmi\Radio_Bar_2\tbRadi.dll (Conduit Ltd.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKU\S-1-5-21-1964839612-41541757-475487781-1000..\Run: [Ylizulynke] C:\Users\Benetollo\AppData\Roaming\Fiurxi\uqudz.exe ()
O13 - gopher Prefix: missing
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL) - File not found
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL File not found
[2013/03/06 19.58.57 | 000,000,000 | ---D | C] -- C:\Users\Benetollo\AppData\Roaming\SpeedyPC Software
[2013/03/06 19.54.38 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedyPC Software
[2013/03/01 20.34.27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Spigot(4289)
[2013/03/01 20.34.27 | 000,000,000 | ---D | C] -- C:\Program Files\IObit Toolbar(4386)
[2013/02/13 13.36.04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Spigot
[2013/02/13 13.36.04 | 000,000,000 | ---D | C] -- C:\Program Files\IObit Toolbar
[2011/07/15 18.43.41 | 000,011,658 | -HS- | C] () -- C:\Users\Benetollo\AppData\Local\hw1bknq874beni6e51i228tag
[2011/07/15 18.43.41 | 000,011,658 | -HS- | C] () -- C:\ProgramData\hw1bknq874beni6e51i228tag
[2012/10/23 11.06.46 | 000,000,000 | -H-D | M] -- C:\Users\Benetollo\AppData\Roaming\EmoticoonsToolbar
[2012/11/08 15.53.40 | 000,000,000 | ---D | M] -- C:\Users\Benetollo\AppData\Roaming\OfferBox
[2013/03/06 19.58.57 | 000,000,000 | ---D | M] -- C:\Users\Benetollo\AppData\Roaming\SpeedyPC Software
@Alternate Data Stream - 568 bytes -> C:\Windows\System32\drivers\ycarakha.sys:changelist
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:430C6D84
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:DFC5A2B2
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:5C321E34
:Files
C:\Users\Benetollo\AppData\Roaming\Fiurxi
C:\Users\Benetollo\AppData\Roaming\Uspywe
C:\Users\Benetollo\AppData\Roaming\Syopi
C:\Users\Benetollo\AppData\Roaming\Beugl
C:\Users\Benetollo\AppData\Roaming\Acwimo
C:\Users\Benetollo\AppData\Roaming\Arwup
C:\Users\Benetollo\AppData\Roaming\Eqamev
C:\Users\Benetollo\AppData\Roaming\Fudol
C:\Users\Benetollo\AppData\Roaming\Fyebo
C:\Users\Benetollo\AppData\Roaming\Geko
C:\Users\Benetollo\AppData\Roaming\HiYo
C:\Users\Benetollo\AppData\Roaming\Izsox
C:\Users\Benetollo\AppData\Roaming\Wepuga
C:\ProgramData\RbPBJipVqHrR
C:\ProgramData\-RbPBJipVqHrRr
C:\ProgramData\-RbPBJipVqHrR
C:\ProgramData\5606191.pad
C:\ProgramData\-RbPBJipVqHrRr
C:\ProgramData\-RbPBJipVqHrR
C:\ProgramData\RbPBJipVqHrR
C:\ProgramData\5606191.js
C:\ProgramData\5606191.pad
C:\ProgramData\87_fg.pad
C:\ProgramData\0tbpw.pad
C:\Users\Benetollo\AppData\Roaming\Qiis
ipconfig /flushdns /c
:commands
[purity]
[emptytemp]
[Reboot]