[B]:OTL
PRC - C:\Programmi\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
[/B][B]SRV - (Application Updater) -- C:\Programmi\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)[/B]
[B]DRV - (XDva397) -- C:\Windows\system32\XDva397.sys File not found[/B]
[B]DRV - (NVHDA) -- system32\drivers\nvhda32v.sys File not found[/B]
[B]DRV - (catchme) -- C:\Users\Sato\AppData\Local\Temp\catchme.sys File not found
[/B][B]IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.chatzum.com/[/B]
[B]IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.chatzum.com/?q={searchTerms}[/B]
[B]IE - HKU\S-1-5-21-1980460026-2577785494-1219628389-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.chatzum.com/?q={searchTerms}[/B]
[B]IE - HKU\S-1-5-21-1980460026-2577785494-1219628389-1000\..\SearchScopes\{96bd48dd-741b-41ae-ac4a-aff96ba00f7e}: "URL" = http://search.chatzum.com/?q={SearchTerms} [/B]
[B]IE - HKU\S-1-5-21-1980460026-2577785494-1219628389-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.chatzum.com/
FF - prefs.js..browser.startup.homepage: "searchsafer.com"
[/B][B]FF - prefs.js..extensions.enabledAddons: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:4.2.1.7[/B]
[B]FF - prefs.js..keyword.URL: "http://it.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=685749&p="
FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&ilc=12&type=685749"
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
[/B][B]FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Sato\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)[/B]
[B]FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)[/B]
[B][2012/06/26 00:05:37 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sato\AppData\Roaming\mozilla\Extensions[/B]
[B][2012/12/09 14:54:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sato\AppData\Roaming\mozilla\Firefox\Profiles\xde4bmlx.default\extensions[/B]
[B][2012/12/09 14:54:44 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Sato\AppData\Roaming\mozilla\Firefox\Profiles\xde4bmlx.default\extensions\staged
[2012/07/02 17:51:46 | 000,000,641 | ---- | M] () -- C:\Users\Sato\AppData\Roaming\mozilla\firefox\profiles\xde4bmlx.default\searchplugins\search-web.xml
[/B][B][2012/06/15 01:09:20 | 000,001,393 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-it.xml[/B]
[B][2012/11/18 14:38:26 | 000,002,465 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml[/B]
[B][2012/06/15 01:09:20 | 000,000,744 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-it.xml[/B]
[B][2012/06/15 01:09:20 | 000,000,817 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\hoepli.xml[/B]
[B][2012/06/15 01:09:20 | 000,001,182 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-it.xml[/B]
[B][2012/06/15 01:09:21 | 000,000,953 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-it.xml
[/B][B][2012/12/04 22:31:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Spigot[/B]
[B][2012/12/04 22:31:29 | 000,000,000 | ---D | C] -- C:\Program Files\IObit Toolbar[/B]
[B][2012/12/04 22:31:29 | 000,000,000 | ---D | C] -- C:\Program Files\Application Updater
[/B][B][2012/12/02 12:15:06 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PingPlotter Standard[/B]
[B][2012/12/02 12:15:06 | 000,000,000 | ---D | C] -- C:\Program Files\PingPlotter Standard[/B]
[B][2012/12/02 12:15:06 | 000,000,000 | ---D | C] -- C:\Users\Sato\AppData\Roaming\PingPlotter
[/B][B][2012/10/11 16:08:53 | 000,000,000 | ---D | C] -- C:\Users\Sato\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bullfrog[/B]
[B][2012/10/11 16:08:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bullfrog
[2012/10/11 15:49:48 | 000,000,000 | ---D | C] -- C:\Program Files\Bullfrog
[2012/12/07 17:45:58 | 000,000,000 | ---- | M] () -- C:\asc_rdflag
[/B][B]:Files[/B]
[B]ipconfig /flushdns /c[/B]
[B]:reg[/B]
[B][HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open\command][/B]
[B]""=""%1" %*" [/B]
[B]:commands[/B]
[B][purity][/B]
[B][emptytemp][/B]
[B][RESETHOSTS][/B]
[B][EMPTYFLASH][/B]
[B][start explorer][/B]
[B][CLEARALLRESTOREPOINTS][/B]
[B][Reboot][/B]