:OTL
CHR - homepage:
http://www.searchnu.com/410O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Programmi\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found.
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll File not found
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~1\SEARCH~1\Datamngr\ToolBar\searchqudtx.dll File not found
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Programmi\Orbitdownloader\GrabPro.dll ()
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKU\S-1-5-21-1292428093-790525478-1801674531-1003\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Programmi\Orbitdownloader\GrabPro.dll ()
O4 - HKLM..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" File not found
O4 - HKLM..\Run: [conhost] C:\Documents and Settings\Fabio\Dati applicazioni\Microsoft\conhost.exe File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Programmi\File comuni\Java\Java Update\jusched.exe (Sun Microsystems, Inc.)
O4 - HKU\.DEFAULT..\Run: [userinit] C:\WINDOWS\system32\ntos.exe File not found
O4 - HKU\S-1-5-18..\Run: [userinit] C:\WINDOWS\system32\ntos.exe File not found
O4 - HKU\S-1-5-21-1292428093-790525478-1801674531-1003..\Run: [{CC2ABD7E-11B6-1698-93AC-8EC68EECDAE9}] "C:\Documents and Settings\Fabio\Dati applicazioni\Vei\vimoiqb.exe" File not found
O4 - HKU\S-1-5-21-1292428093-790525478-1801674531-1003..\Run: [FreeCall] "C:\Programmi\FreeCall.com\FreeCall\FreeCall.exe" -nosplash -minimized File not found
F3 - HKU\S-1-5-21-1292428093-790525478-1801674531-1003 WinNT: Load - (C:\DOCUME~1\Fabio\IMPOST~1\Temp\csrss.exe) - File not found
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71}
http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}
http://java.sun.com/products/plugin/autodl/jinstall-1_3_1_13-windows-i586.cab (Java Plug-in 1.3.1_13)
O16 - DPF: {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-1_5_0_14-windows-i586.cab (Java Plug-in 1.5.0_14)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O20 - HKU\S-1-5-21-1292428093-790525478-1801674531-1003 Winlogon: Shell - (C:\Documents and Settings\Fabio\Dati applicazioni\dwm.exe) - File not found
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O33 - MountPoints2\{0ff0bafb-9c2f-11e1-b73d-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{0ff0bafb-9c2f-11e1-b73d-00138fe963dc}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2010/05/09 13.48.36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{1afa3c56-016a-11e1-b68c-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{1afa3c56-016a-11e1-b68c-00138fe963dc}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2010/05/09 13.48.36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{26f96d6c-9a06-11e1-b738-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{26f96d6c-9a06-11e1-b738-00138fe963dc}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2010/05/09 13.48.36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{26f96d6e-9a06-11e1-b738-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{26f96d6e-9a06-11e1-b738-00138fe963dc}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2010/05/09 13.48.36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{316ddcfe-b8ae-11e0-b62e-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{316ddcfe-b8ae-11e0-b62e-00138fe963dc}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2010/05/09 13.48.36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{3faf61be-945b-11e1-b72f-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{3faf61be-945b-11e1-b72f-00138fe963dc}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2010/05/09 13.48.36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{4f86e9c8-3b64-11e0-b57f-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{4f86e9c8-3b64-11e0-b57f-00138fe963dc}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2010/05/09 13.48.36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{4f86e9cb-3b64-11e0-b57f-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{4f86e9cb-3b64-11e0-b57f-00138fe963dc}\Shell\AutoRun\command - "" = G:\AutoRun.exe
O33 - MountPoints2\{784665b6-008d-11e1-b68a-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{784665b6-008d-11e1-b68a-00138fe963dc}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2010/05/09 13.48.36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{94b0754c-04b6-11e2-b7a1-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{94b0754c-04b6-11e2-b7a1-00138fe963dc}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2010/05/09 13.48.36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{aa73c8bc-4030-11e0-b588-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{aa73c8bc-4030-11e0-b588-00138fe963dc}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2010/05/09 13.48.36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{c3201292-9a04-11e1-b737-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{c3201292-9a04-11e1-b737-00138fe963dc}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2010/05/09 13.48.36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{c3201294-9a04-11e1-b737-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{c3201294-9a04-11e1-b737-00138fe963dc}\Shell\AutoRun\command - "" = F:\AutoRun.exe -- [2010/05/09 13.48.36 | 000,126,976 | R--- | M] ()
O33 - MountPoints2\{eec22ea0-e83c-11e0-b66e-00138fe963dc}\Shell - "" = AutoRun
O33 - MountPoints2\{eec22ea0-e83c-11e0-b66e-00138fe963dc}\Shell\AutoRun\command - "" = F:\laucher.exe
[2012/11/19 14.54.16 | 095,023,320 | ---- | C] () -- C:\Documents and Settings\All Users\Dati applicazioni\0tbpw.pad
[2011/01/24 06.53.44 | 000,026,506 | ---- | C] () -- C:\Documents and Settings\Fabio\Dati applicazioni\062E.5A4
[2007/04/07 11.15.11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Messenger Plus!
[2012/06/03 15.43.57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fabio\Dati applicazioni\searchquband
[2011/11/12 12.32.50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fabio\Dati applicazioni\Vei
[2011/01/19 17.27.21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Fabio\Dati applicazioni\VUPlayer
:Files
ipconfig /flushdns /c
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"
:commands
[purity]
[emptytemp]
[Emptyjava]
[RESETHOSTS]
[EMPTYFLASH]
[start explorer]
[Reboot]