:OTL
IE - HKU\S-1-5-21-1547161642-152049171-839522115-1003\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" =
http://start.facemoods.com/?a=ddr&s={searchTerms}&f=4
IE - HKU\S-1-5-21-1547161642-152049171-839522115-1003\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" =
http://websearch.ask.com/redirect?client=ie&tb=UT2V5&o=15158&src=crm&q={searchTerms}&locale=it_IT
IE - HKU\S-1-5-21-1547161642-152049171-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1:9421
[2011/03/30 14.55.49 | 000,000,000 | ---D | M] (Facemoods) -- C:\Documents and Settings\principale\Dati applicazioni\Mozilla\Firefox\Profiles\lmdaexq5.default\extensions\ffxtlbr@Facemoods.com
O3 - HKU\S-1-5-21-1547161642-152049171-839522115-1003\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found.
O3 - HKU\S-1-5-21-1547161642-152049171-839522115-1003\..\Toolbar\WebBrowser: (no name) - {472734EA-242A-422B-ADF8-83D1E48CC825} - No CLSID value found.
O3 - HKU\S-1-5-21-1547161642-152049171-839522115-1003\..\Toolbar\WebBrowser: (no name) - {89FDCC4B-8D91-49B0-81A6-18BCFF582735} - No CLSID value found.
O3 - HKU\S-1-5-21-1547161642-152049171-839522115-1003\..\Toolbar\WebBrowser: (no name) - {A057A204-BACC-4D26-9990-79A187E2698E} - No CLSID value found.
O3 - HKU\S-1-5-21-1547161642-152049171-839522115-1003\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKU\S-1-5-21-1547161642-152049171-839522115-1003\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKU\S-1-5-21-1547161642-152049171-839522115-1003..\Run: [AlcoholAutomount] C:\Documents and Settings\principale\Documenti\Alcohol 120\axcmd.exe (Alcohol Soft Development Team)
O8 - Extra context menu item: &Search - Reg Error: Value error. File not found
O8 - Extra context menu item: Google Sidewiki... - res://C:\Programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Programmi\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O8 - Extra context menu item: Translate with Babylon - res://C:\Programmi\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - mswsock.dll File not found
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24}
http://messenger.zone.msn.com/MessengerGamesContent/GameContent/it/uno1/GAME_UNO1.cab (UnoCtrl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1244314161562 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
http://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072}
http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-1_6_0_21-windows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48}
http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab (Minesweeper Flags Class)
[2012/03/12 11.51.41 | 000,000,000 | ---D | C] -- C:\Programmi\20F31
[2012/03/12 11.50.50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\principale\Dati applicazioni\70520
[2012/01/16 10.42.32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\principale\Dati applicazioni\AVG2012
[2012/01/16 10.40.45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\AVG2012
[2012/01/16 10.17.58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Dati applicazioni\AVAST Software
[2012/01/16 10.34.03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\AVAST Software
[2012/03/13 19.22.11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\AVG2012
[2010/12/30 13.55.47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Dati applicazioni\avg9
[2010/12/21 22.36.55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\principale\Dati applicazioni\OfferBox
[2011/11/01 10.12.40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\principale\Dati applicazioni\PriceGong
@Alternate Data Stream - 98 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:FC2D0F32
@Alternate Data Stream - 97 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:BF2E2F0E
@Alternate Data Stream - 96 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:D48500F8
@Alternate Data Stream - 94 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:5D351BC6
@Alternate Data Stream - 240 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:E2CFA9CD
@Alternate Data Stream - 223 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:A4E7D25F
@Alternate Data Stream - 196 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:943971F5
@Alternate Data Stream - 195 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:ECF3C50F
@Alternate Data Stream - 195 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:8E5EA40F
@Alternate Data Stream - 183 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:012BC84F
@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:F26F5952
@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:4A8EB1C4
@Alternate Data Stream - 181 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:1A15E356
@Alternate Data Stream - 180 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:4CD3F344
@Alternate Data Stream - 179 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:C78DADEA
@Alternate Data Stream - 177 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:2D133896
@Alternate Data Stream - 173 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:587F3582
@Alternate Data Stream - 171 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:6EE8565A
@Alternate Data Stream - 169 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:DDCD5068
@Alternate Data Stream - 165 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:B4258C5D
@Alternate Data Stream - 159 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:1604D047
@Alternate Data Stream - 158 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:FB4262DE
@Alternate Data Stream - 158 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:E0888117
@Alternate Data Stream - 158 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:DD6F157A
@Alternate Data Stream - 156 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:DFC5A2B2
@Alternate Data Stream - 147 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:87B05421
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:C2F24DB5
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:BD34FFC5
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:B38BEEEE
@Alternate Data Stream - 142 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:AA0017FD
@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:F5FC5DCE
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:CA23BCFD
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:52C24010
@Alternate Data Stream - 139 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:2398E95B
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:A752D3DB
@Alternate Data Stream - 136 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:5FF74A17
@Alternate Data Stream - 135 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:C36D0DFD
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:F5D01D7C
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:3B454A5C
@Alternate Data Stream - 134 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:2AE74FF9
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:ED2D63E4
@Alternate Data Stream - 133 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:2AF322BF
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:17EB5BAE
@Alternate Data Stream - 131 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:E5496666
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:A819A132
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:14B2E0BD
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:65C4D44A
@Alternate Data Stream - 129 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:61B54B15
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:B2CD146E
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:B0456F0C
@Alternate Data Stream - 128 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:3D922890
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:E5B07840
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:6E2D80C8
@Alternate Data Stream - 126 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:6A0A47E7
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:84744B34
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:8401B6D5
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:474022C7
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:26499772
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:114C90CA
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:0785072C
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:2B9555D8
@Alternate Data Stream - 123 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:183A9046
@Alternate Data Stream - 122 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:40D8F125
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:9603033A
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:83E716F0
@Alternate Data Stream - 121 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:1DA424AA
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:E80802C7
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:AD2DB2F9
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:16F4BC64
@Alternate Data Stream - 120 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:164561C8
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:ED0B32CA
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:E8C44CB4
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:CF61CE5A
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:902C848D
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:7E95B6FD
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:4C3D5A8B
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:E6BEADB7
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:B6FD7157
@Alternate Data Stream - 117 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:2652902F
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:7B52659E
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:3B5038B1
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:A8ADE5D8
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:981456CB
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:569CEE83
@Alternate Data Stream - 114 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:207C4C79
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:774C075A
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:774A0E14
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:75798D9A
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:02CC0035
@Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:FFFCB9A9
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:8944C195
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:797D7632
@Alternate Data Stream - 107 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:E690114B
@Alternate Data Stream - 105 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:6FD3C973
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:ECCE99EF
@Alternate Data Stream - 104 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:1A5207FA
@Alternate Data Stream - 103 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:98DFF516
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:C31F31E6
@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Dati applicazioni\TEMP:3D36932D
:Files
ipconfig /flushdns /c
:commands
[purity]
[emptytemp]
[Emptyjava]
[RESETHOSTS]
[EMPTYFLASH]
[start explorer]
[Reboot]