:OTL
MOD - C:\Programmi\cacaoweb\cacaoweb.exe ()
SRV - (HidServ) -- %SystemRoot%\System32\hidserv.dll File not found
SRV - (AppMgmt) -- %SystemRoot%\System32\appmgmts.dll File not found
SRV - (Skype C2C Service) -- C:\Documents and Settings\All Users\Dati applicazioni\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (PowerOffer Service) -- C:\Documents and Settings\Ilenia\Impostazioni locali\Dati applicazioni\PosService\Pos.exe (PowerOfferService)
SRV - (ServUpdater) -- C:\Documents and Settings\Ilenia\Impostazioni locali\Dati applicazioni\ServUpdater\ServiceUpd.exe (ServiceUpd)
DRV - (WDICA) -- File not found
DRV - (PDRFRAME) -- File not found
DRV - (PDRELI) -- File not found
DRV - (PDFRAME) -- File not found
DRV - (PDCOMP) -- File not found
DRV - (PCIDump) -- File not found
DRV - (lbrtfdc) -- File not found
DRV - (i2omgmt) -- File not found
DRV - (Changer) -- File not found
DRV - (adiusbaw) -- System32\DRIVERS\adiusbaw.sys File not found
DRV - (ADILOADER) -- System32\Drivers\adildr.sys File not found
IE - HKLM\..\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}: "URL" =
http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=lBX5hKhNy65ynTa3CoP_cQ&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=sb&searchfor={searchTerms}
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.findeer.comIE - HKU\.DEFAULT\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.findeer.comIE - HKU\S-1-5-18\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.findeer.comIE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://search.findeer.comIE - HKU\S-1-5-21-823518204-1767777339-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page =
http://search.babylon.com/?affID=114874&tt=120912_cpc_3912_5&babsrc=HP_ss&mntrId=78be7b25000000000000000b0d626b72IE - HKU\S-1-5-21-823518204-1767777339-839522115-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.claro-search.com/?affID=116199&tt=3912_8&babsrc=HP_ss&mntrId=78be7b25000000000000000b0d626b72IE - HKU\S-1-5-21-823518204-1767777339-839522115-1004\..\SearchScopes\{0D7562AE-8EF6-416d-A838-AB665251703A}: "URL" =
http://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4
IE - HKU\S-1-5-21-823518204-1767777339-839522115-1004\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" =
http://search.babylon.com/?q={searchTerms}&affID=114874&tt=120912_cpc_3912_5&babsrc=SP_ss&mntrId=78be7b25000000000000000b0d626b72
IE - HKU\S-1-5-21-823518204-1767777339-839522115-1004\..\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}: "URL" =
http://www.mywebsearch.com/jsp/cfg_redir2.jsp?id=ZNfox000&fl=0&ptb=lBX5hKhNy65ynTa3CoP_cQ&url=http://search.mywebsearch.com/mywebsearch/dft_redir.jhtml&st=sb&searchfor={searchTerms}
FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)"
FF - prefs.js..browser.search.order.1: "Search the web (Babylon)"
FF - prefs.js..browser.search.selectedEngine: "Search the web (Babylon)"
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
[2010/08/29 18.51.02 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ilenia\Dati applicazioni\Mozilla\Extensions
[2010/08/29 20.14.01 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ilenia\Dati applicazioni\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/11/22 09.05.19 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Ilenia\Dati applicazioni\Mozilla\Firefox\Profiles\efjz9l1h.default\extensions
[2011/12/17 14.07.09 | 000,000,000 | ---D | M] (cacaoweb) -- C:\Documents and Settings\Ilenia\Dati applicazioni\Mozilla\Firefox\Profiles\efjz9l1h.default\extensions\cacaoweb@cacaoweb(2).org
[2012/11/11 22.25.21 | 000,000,000 | ---D | M] (cacaoweb) -- C:\Documents and Settings\Ilenia\Dati applicazioni\Mozilla\Firefox\Profiles\efjz9l1h.default\extensions\cacaoweb@cacaoweb.org
[2012/09/26 11.11.35 | 000,002,223 | ---- | M] () -- C:\Documents and Settings\Ilenia\Dati applicazioni\Mozilla\Firefox\Profiles\efjz9l1h.default\searchplugins\BabylonMngr.xml
[2011/11/18 01.46.34 | 000,001,867 | ---- | M] () -- C:\Documents and Settings\Ilenia\Dati applicazioni\Mozilla\Firefox\Profiles\efjz9l1h.default\searchplugins\findeer.xml
[2009/05/10 22.33.40 | 000,009,895 | ---- | M] () -- C:\Documents and Settings\Ilenia\Dati applicazioni\Mozilla\Firefox\Profiles\efjz9l1h.default\searchplugins\mywebsearch.xml
[2010/08/25 15.23.52 | 000,003,915 | ---- | M] () -- C:\Documents and Settings\Ilenia\Dati applicazioni\Mozilla\Firefox\Profiles\efjz9l1h.default\searchplugins\sweetim.xml
[2012/09/26 11.29.52 | 000,006,520 | ---- | M] () -- C:\Programmi\mozilla firefox\searchplugins\babylon.xml
O2 - BHO: (no name) - {2EECD738-5844-4a99-B4B6-146BF802613B} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programmi\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Programmi\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Programmi\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION / CyCom Technology Corp.)
O3 - HKLM\..\Toolbar: (no name) - {98889811-442D-49dd-99D7-DC866BE87DBC} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (EPSON Web-To-Page) - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programmi\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKU\S-1-5-21-823518204-1767777339-839522115-1004..\Run: [cacaoweb] C:\Programmi\cacaoweb\cacaoweb.exe ()
O4 - HKU\S-1-5-21-823518204-1767777339-839522115-1004..\Run: [download beast] "C:\Programmi\Download Beast\DownloadBeast.exe" -h File not found
O4 - HKU\S-1-5-21-823518204-1767777339-839522115-1004..\Run: [Media Finder] "C:\Programmi\Media Finder\MF.exe" /opentotray File not found
O9 - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0FB6073E-0AC1-40EB-912F-47AF00DE9B44}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{238FD933-4775-4659-94ED-044ECBABE6F1}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{33553D8C-88D8-4B33-8D2E-06C98B4FC5EC}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{6BE16D97-18C8-493C-A482-32A2A4CE93A8}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B9751194-2491-4150-99BE-0B8C24EE072A}: NameServer = 176.31.229.24,176.31.229.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FDF7975D-6FC3-4FFB-AC48-2F6AE5E24675}: NameServer = 176.31.229.24,176.31.229.25
:Files
C:\Programmi\cacaoweb
C:\Documents and Settings\All Users\Dati applicazioni\Babylon
C:\Documents and Settings\Ilenia\Dati applicazioni\Babylon
C:\Documents and Settings\Ilenia\Dati applicazioni\cacaoweb
C:\Documents and Settings\Ilenia\Dati applicazioni\OfferBox
C:\Documents and Settings\Ilenia\Impostazioni locali\Dati applicazioni\PosService
C:\Documents and Settings\Ilenia\Impostazioni locali\Dati applicazioni\ServUpdater
C:\Programmi\cacaoweb
ipconfig /flushdns /c
:commands
[purity]
[Reboot]