:OTL
PRC - C:\Program Files (x86)\System Security Guard\SystemSecurityGuardTray.exe (SystemSecurityGuard.com)
SRV - (McComponentHostService) -- C:\Programmi\McAfee Security Scan\3.8.130\McCHSvc.exe (McAfee, Inc.)
IE:[b]64bit:[/b] - HKLM\..\SearchScopes\{2810F65D-F57A-4EE9-B1FD-70FF4A22B4D4}: "URL" =
http://it.kelkoopartners.net/ctl/do/search?siteSearchQuery={searchTerms}&fromform=true&x=true&y=true&partner=hp&partnerId=96913930
2012/04/06 17.12.45 | 000,000,000 | ---D | M] ("urn:mozilla:install-manifest" em:id="ssg@igeared" em:name="System Security Guard Toolbar" em:version="2.103.030.001" em:displayname="System Security Guard Toolbar" em:iconURL="chrome://ssgigearedp/skin/logo.ico" em:creator="iGeared LLC" em:description="System Security Guard Toolbar!" em:homepageURL="http://www.SystemSecurityGuard.com" >) -- C:\Users\Claudio\AppData\Roaming\mozilla\Firefox\Profiles\plh0fbhs.default\extensions\ssg@igeared
[2012/09/04 23.40.07 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Claudio\AppData\Roaming\mozilla\Firefox\Profiles\plh0fbhs.default\extensions\staged(110)
[2012/06/03 00.35.45 | 000,019,291 | ---- | M] () (No name found) -- C:\Users\Claudio\AppData\Roaming\mozilla\firefox\profiles\plh0fbhs.default\extensions\magnetiser@hotsexgary.com.xpi
[2011/02/10 17.57.23 | 000,001,858 | ---- | M] () -- C:\Users\Claudio\AppData\Roaming\mozilla\firefox\profiles\plh0fbhs.default\searchplugins\xweasel.xml
[2010/11/07 12.51.31 | 000,002,039 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml
[2012/02/12 13.26.59 | 000,001,467 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\ssg_igeared.xml
O2:[b]64bit:[/b] - BHO: (LyricsSay-16) - {11111111-1111-1111-1111-110411411158} - C:\Program Files (x86)\LyricsSay-16\LyricsSay-16-bho64.dll File not found
O2:[b]64bit:[/b] - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2 - BHO: (MSS+ Identifier) - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.130\McAfeeMSS_IE.dll File not found
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:[b]64bit:[/b] - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll File not found
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (System Security Guard Toolbar) - {2793FB58-DCE3-4A83-97DE-7208CAD0341C} - C:\Program Files (x86)\SystemSecurityGuardToolbar\IEToolbar.dll File not found
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (no name) - {1BB22D38-A411-4B13-A746-C2A4F4EC7344} - No CLSID value found.
O3 - HKU\S-1-5-18\..\Toolbar\WebBrowser: (System Security Guard Toolbar) - {2793FB58-DCE3-4A83-97DE-7208CAD0341C} - C:\Program Files (x86)\SystemSecurityGuardToolbar\IEToolbar.dll File not found
O3 - HKU\S-1-5-21-2445695516-1122754217-2747420058-1000\..\Toolbar\WebBrowser: (System Security Guard Toolbar) - {2793FB58-DCE3-4A83-97DE-7208CAD0341C} - C:\Program Files (x86)\SystemSecurityGuardToolbar\IEToolbar.dll File not found
O3 - HKU\S-1-5-21-2445695516-1122754217-2747420058-1000\..\Toolbar\WebBrowser: (Grab Pro) - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files (x86)\Orbitdownloader\GrabPro.dll File not found
O4 - HKU\S-1-5-21-2445695516-1122754217-2747420058-1000..\Run: [SystemSecurityGuardAutoStart] C:\Program Files (x86)\System Security Guard\SystemSecurityGuardTray.exe (SystemSecurityGuard.com)
O18:[b]64bit:[/b] - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:[b]64bit:[/b] - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:[b]64bit:[/b] - Protocol\Handler\systemsecurityguardtoolbar - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlmailhtml - No CLSID value found
O18:[b]64bit:[/b] - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\systemsecurityguardtoolbar {89EECF8F-484D-4786-909C-83E5285003ED} - C:\Program Files (x86)\SystemSecurityGuardToolbar\IEToolbar.dll File not found
[2013/10/21 00.14.58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Orbit
[2013/10/21 00.02.10 | 005,528,480 | ---- | C] (www.orbitdownloader.com
[2013/10/19 22.24.49 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus
[2013/09/16 14.56.09 | 000,000,000 | ---D | C] -- C:\ProgramData\Uniblue
@Alternate Data Stream - 368 bytes -> C:\Users\Claudio\AppData\Local\desktop.ini:722b2b1c349a06abf0e866180e5a7e63
@Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:E8BE05FA
@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:0B4227B4
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:890CC2F3
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:D1B5B4F1
:Files
C:\Program Files (x86)\SystemSecurityGuardToolbar
C:\Users\Claudio\Desktop\OrbitSetup4.1.19(1).exe
ipconfig /flushdns /c
:commands
[emptytemp]
[start explorer]
[Reboot]