R3 - URLSearchHook: (no name) - {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - C:\Programmi\AskTBar\SrchAstt\1.bin\A5SRCHAS.DLL
F2 - REG:system.ini: Shell=Explorer.exe csrcs.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,
O2 - BHO: C:\WINDOWS\system32\jkshfuiehi.dll - {C2BA40A1-74F3-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\jkshfuiehi.dll (file missing)
O4 - HKLM\..\Run: [] scvhost.exe
O4 - HKLM\..\Run: [sysldtray] c:\windows\ld12.exe
O4 - HKLM\..\Run: [ISTray] "C:\Programmi\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [PrevxRootkitRemovalTool] "C:\Documents and Settings\Proprietario\Desktop\PrevxFixGrom.exe" -scan
O4 - HKLM\..\RunServices: [] scvhost.exe
O4 - HKCU\..\Run: [] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\tcnoqa.exe
O4 - HKCU\..\Run: [Diagnostic Manager] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\3543206064.exe
O4 - HKCU\..\Run: [AdobeUpdater] "C:\Programmi\File comuni\Adobe\Updater5\AdobeUpdater.exe"
O4 - HKCU\..\Run: [uidenhiufgsduiazghs] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\jlwh28213.exe
O4 - HKCU\..\Run: [A00F9C363.exe] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\_A00F9C363.exe
O4 - HKCU\..\Run: [A00F92C82.exe] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\_A00F92C82.exe
O4 - HKCU\..\Run: [Windows Management Interface] "c:\windows\winmanx.exe" *
O4 - HKCU\..\Run: [hsf7husjnfg98gi498aejhiugjkdg4] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\tcnoqa.exe
O4 - HKCU\..\Run: [uk6lexfptndh2h65] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\tcnoqa.exe
O4 - HKCU\..\Run: [o46nykhg3zf3ou0awimdgm] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\tcnoqa.exe
O4 - HKCU\..\Run: [zwhpos4x4c8prg984bxi256vng9eco] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\tcnoqa.exe
O4 - HKCU\..\Run: [sm2fznhl9ct3aijf5hqw2scg864a] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\tcnoqa.exe
O4 - HKCU\..\Run: [gghq6n6rgn7n7yo9zehjg] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\tcnoqa.exe
O4 - HKCU\..\Run: [ijv72f6h5uy6] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\tcnoqa.exe
O4 - HKCU\..\Run: [jmt6817xq1usir1fm5xghpvn0] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\tcnoqa.exe
O4 - HKCU\..\Run: [hg2441k2ypom59sicuw] C:\DOCUME~1\PROPRI~1\IMPOST~1\Temp\tcnoqa.exe
O4 - HKLM\..\Policies\Explorer\Run: [csrcs] C:\WINDOWS\system32\csrcs.exe
O4 - HKLM\..\Policies\Explorer\Run: [exec] C:\WINDOWS\system32\msfandv.exe