:OTL
SRV - (Util GreyGray) -- C:\Programmi\GreyGray\bin\utilGreyGray.exe File not found
SRV - (Update GreyGray) -- C:\Programmi\GreyGray\updateGreyGray.exe File not found
DRV - (esgiguard) -- C:\Programmi\Enigma Software Group\SpyHunter\esgiguard.sys File not found
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://do-search.com/web/?type=ds&ts=1384264020&from=ild&uid=WDCXWD3200AAJS-00VWA0_WD-WCARW194429044290&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://do-search.com/web/?type=ds&ts=1384264020&from=ild&uid=WDCXWD3200AAJS-00VWA0_WD-WCARW194429044290&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://do-search.com/web/?type=ds&ts=1384264020&from=ild&uid=WDCXWD3200AAJS-00VWA0_WD-WCARW194429044290&q={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://do-search.com/web/?type=ds&ts=1384264020&from=ild&uid=WDCXWD3200AAJS-00VWA0_WD-WCARW194429044290&q={searchTerms}
[2013/11/14 15.46.23 | 000,000,000 | ---D | M] (DealPly Shopping) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\{e53a26f5-7199-4a5b-86f5-d2e86854b979}
[2013/11/15 14.45.11 | 000,000,000 | ---D | M] (SearchNewTab) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\08k-qtoi@nr-nbaiuxi.net
[2013/11/15 14.44.53 | 000,000,000 | ---D | M] (surf aNd keep) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\a9sfq@fmatsmthgdw.org
[2013/11/14 15.17.11 | 000,000,000 | ---D | M] (YoutubeAdblocker) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\acz5nl@ef.org
[2013/11/15 14.44.52 | 000,000,000 | ---D | M] (SearchNewTab) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\b4vreb@gzvkb.edu
[2013/11/15 14.45.05 | 000,000,000 | ---D | M] (siurf annDa akEepe) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\cgm3.p@lwioedcbvvmsj.net
[2013/11/14 15.17.10 | 000,000,000 | ---D | M] (suiRf aaNd kEep) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\cmfzkwlo@uua-.co.uk
[2013/11/15 14.45.11 | 000,000,000 | ---D | M] (surf. anid keeep) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\eimk@uooi-.co.uk
[2013/11/15 14.50.02 | 000,000,000 | ---D | M] (SearchNewTab) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\fwo2cl8@baava.com
[2013/11/15 14.44.53 | 000,000,000 | ---D | M] (surrf anda! Keep) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\gewajprtcu@ouu-.co.uk
[2013/11/14 15.17.10 | 000,000,000 | ---D | M] (ShoppingChip) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\jaoiyeoia@z-hr.org
[2013/11/15 14.45.11 | 000,000,000 | ---D | M] (surf And keeEp) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\paa.oa@avgmmaa.org
[2013/11/14 15.17.10 | 000,000,000 | ---D | M] (SearchNewTab) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\slr8.mcp@ayyvlthryoaoi.edu
[2013/11/15 14.44.53 | 000,000,000 | ---D | M] (SearchNewTab) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\tjcw6ywiimn@c-hsn.com
[2013/11/15 14.44.53 | 000,000,000 | ---D | M] (SearchNewTab) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\trcpl2v@jpglyjc-.co.uk
[2013/11/15 14.44.52 | 000,000,000 | ---D | M] (surf and kueep) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\uuuufaea@uoiyuygcjd.com
[2013/11/15 14.45.05 | 000,000,000 | ---D | M] (SearchNewTab) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\z2.ofk@qtdg-mbdbjazt.com
[2013/03/14 17.28.54 | 000,005,958 | ---- | M] () (No name found) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\extensions\4sharedCopyLinks.xpi
[2013/11/15 14.18.39 | 000,001,369 | ---- | M] () -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\Mozilla\Firefox\Profiles\fsyy225f.default\searchplugins\iminent.xml
O2 - BHO: (surrf anda! Keep) - {1609BF54-5728-19AE-8679-D47C40D19974} - C:\Programmi\surrf anda! Keep\KFQc.dll ()
O2 - BHO: (SearchNewTab) - {35560492-EEFA-8368-7D0E-0540E01F90AE} - C:\Programmi\SearchNewTab\ZXMPiEHl7.dll File not found
O2 - BHO: (suiRf aaNd kEep) - {382FCB13-86DC-D5FD-04DF-28E00F7A7740} - C:\Programmi\suiRf aaNd kEep\bW_4xn1WAe.dll ()
O2 - BHO: (SearchNewTab) - {468A8D93-0F38-C141-F61C-7A7E0724AF1A} - C:\Programmi\SearchNewTab\dymd60rc.dll File not found
O2 - BHO: (surf. anid keeep) - {6604ADC7-AC07-2F7F-79F0-F094843CF310} - C:\Programmi\surf. anid keeep\t2P.dll ()
O2 - BHO: (SearchNewTab) - {6E9EAB86-F07D-2E84-25D8-2820FAFD6C5F} - C:\Programmi\SearchNewTab\0lccqXjwK_.dll File not found
O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (siurf annDa akEepe) - {77B7048C-5536-2E99-9FFB-03CF8A21A559} - C:\Programmi\siurf annDa akEepe\ThLH.dll ()
O2 - BHO: (SearchNewTab) - {85573A54-C6B9-4AC2-BFB3-2A38AAD39533} - C:\Programmi\SearchNewTab\SY.dll File not found
O2 - BHO: (surf and kueep) - {8BF0762E-CFDB-D443-1145-B3CBF1BEE700} - C:\Programmi\surf and kueep\H_k7K8Oi.dll ()
O2 - BHO: (YoutubeAdblocker) - {8FB90BD8-FE2A-CC27-0035-F45767457223} - C:\Programmi\YoutubeAdblocker\OpMe.dll ()
O2 - BHO: (SearchNewTab) - {BE263DBD-AB68-2616-8299-1C5EE432D892} - C:\Programmi\SearchNewTab\y2eX.dll File not found
O2 - BHO: (ShinyProfile Class) - {C8B7D03D-30D7-493A-95E5-6547E2FAC2FE} - C:\Documents and Settings\rozzato.DIDATTIC-89C370\Dati applicazioni\ShinyProfile\shinyprofile.dll (TODO: <Company name>)
O2 - BHO: (SearchNewTab) - {ED631C61-A290-FEA1-7D7C-C1734D300839} - C:\Programmi\SearchNewTab\TuvLvYA.dll File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [TNOD UP] C:\Programmi\TNod User & Password Finder\TNODUP.exe (Tukero[X]Team)
O20 - Winlogon\Notify\WgaLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
[2013/11/21 18.45.12 | 001,034,531 | ---- | C] (Thisisu) -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Desktop\JRT.exe
[2013/11/15 14.32.19 | 000,000,000 | ---D | C] -- C:\Programmi\surf And keeEp
[2013/11/14 14.20.39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS2\Dati applicazioni\ShoppingChip
[2013/11/14 14.20.39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS2\Dati applicazioni\dd82884e5116070d
[2013/11/14 14.20.38 | 000,000,000 | ---D | C] -- C:\Programmi\ShoppingChip
[2013/10/21 15.15.56 | 000,000,000 | ---D | C] -- C:\Programmi\SUPERAntiSpyware
[2013/10/21 15.15.56 | 000,000,000 | ---D | C] -- C:\Programmi\Sophos
[2013/10/16 17.33.42 | 000,000,000 | ---D | C] -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Impostazioni locali\Dati applicazioni\DealPlyLive
[2013/10/31 13.22.16 | 000,351,124 | ---- | M] () -- C:\Documents and Settings\rozzato.DIDATTIC-89C370\Impostazioni locali\Dati applicazioni\mysearchdial-speeddial.crx
[2013/07/12 15.10.14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Babylon
[2010/03/19 15.22.54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\PrevxCSI
[2010/01/12 19.39.36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\SITEguard
[2010/01/13 13.43.17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\STOPzilla!
[2013/05/27 12.12.25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Tarma Installer
[2008/11/24 16.34.09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\Winferno
[2012/06/05 09.07.41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Matilde\Dati applicazioni\ZalmanInstaller_otshot
[2012/03/08 19.31.00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rozzato\Dati applicazioni\Eqazew
[2008/12/09 12.42.09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rozzato\Dati applicazioni\LG Electronics
[2010/07/20 14.24.03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rozzato\Dati applicazioni\NotMyIp
[2013/04/03 14.18.51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rozzato\Dati applicazioni\OfferBox
[2013/07/12 18.44.34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rozzato\Dati applicazioni\OpenCandy
[2009/03/04 17.37.30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Rozzato\Dati applicazioni\vghd
[2011/04/01 14.56.41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Tecnico\Dati applicazioni\facemoods.com
@Alternate Data Stream - 97 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:2A81F9CE
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:DFC5A2B2
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:890CC2F3
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:373E1720
:Files
C:\Programmi\Enigma Software Group\SpyHunter
C:\Programmi\Enigma Software Group
C:\Documents and Settings\All Users.WINDOWS2\Dati applicazioni\McAfee
C:\Programmi\Lavasoft
ipconfig /flushdns /c
:reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command]
""=""%1" %*"
:commands
[purity]
[emptytemp]
[Emptyjava]
[RESETHOSTS]
[EMPTYFLASH]
[start explorer]
[Reboot]