Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

reindirizzamento IE su pagina megauploadzz Opzioni
marianocriscuolo
Inviato: Saturday, January 22, 2011 5:15:42 PM
Rank: Member

Iscritto dal : 1/22/2011
Posts: 26
Ciao Amici,
da qualche giorno la home page di Internet Explorer 7 (che è www.google.it) , viene reindirizzata al seguente indirizzo: http://megauploadzz.com/robot/pr/send.php.
Allego log di HijackThis. Potreste aiutarmi per favore ?


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11.02.24, on 22/01/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Programmi\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmi\File comuni\Nokia\MPlatform\NokiaMServer.exe
C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
C:\Programmi\SlySoft\AnyDVD\AnyDVD.exe
C:\Programmi\File comuni\Java\Java Update\jusched.exe
C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\WINDOW~4\Datamngr\DATAMN~1.EXE
C:\Programmi\Lexmark X1100 Series\lxbkbmon.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\Microsoft Student\Microsoft Encarta 2009 - Premium + Student DVD\EDICT.EXE
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\Kerkia\Minimem\minimem.exe
C:\Programmi\WinZip\WZQKPICK.EXE
C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Dati applicazioni\Windows Internet Name Service\wins.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
C:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Programmi\Safari\Safari.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Programmi\MyWebSearch\bar\2.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Programmi\MyWebSearch\bar\2.bin\MWSSRCAS.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Programmi\MyWebSearch\bar\2.bin\MWSBAR.DLL
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Searchqu Toolbar - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\PROGRA~1\WINDOW~4\ToolBar\SearchquDx.dll
O2 - BHO: CQueryRankBHOImpl - {A003AFC5-9C04-459E-8B03-8A5E72B9F059} - C:\Documents and Settings\Administrator\Dati applicazioni\file.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: LTIEHelper Class - {BE8A4424-DC23-4493-A04D-AC20AD8EEBC2} - C:\Programmi\EasyPrediction\2.0\ltie.dll
O2 - BHO: SignatureManagerBHO - {C6CC9344-BC12-4EA7-9E37-46D61866C771} - C:\Programmi\SM\SubsHelperBHO.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Programmi\MyWebSearch\bar\2.bin\MWSBAR.DLL
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Searchster.Net - {F334C7B0-8774-4d5b-BD7A-4F448D03A1AE} - C:\Programmi\Searchster.Net\Searchster.Net.dll
O3 - Toolbar: Searchqu Toolbar - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\PROGRA~1\WINDOW~4\ToolBar\SearchquDx.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NokiaMServer] C:\Programmi\File comuni\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [Nokia FastStart] "C:\Programmi\Nokia\Nokia Music\NokiaMusic.exe" /command:faststart
O4 - HKLM\..\Run: [CloneCDTray] "C:\Programmi\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [AnyDVD] C:\Programmi\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [DRPU Pc Data manager] "C:\Programmi\DRPU PC Data Manager\apcdm.exe" "hd"
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\2.bin\m3SrchMn.exe" /m=2 /w /h
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\WINDOW~4\Datamngr\DATAMN~1.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Packard Bell Software Suite] C:\Programmi\Packard Bell\Packard Bell Software Suite\Launcher.exe /run
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [L09IXLRD_21879812] "C:\Programmi\Microsoft Student\Microsoft Encarta 2009 - Premium + Student DVD\EDICT.EXE" -m
O4 - HKCU\..\Run: [FreeCall] "c:\programmi\freecall.com\freecall\freecall.exe" -nosplash -minimized
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKCU\..\Run: [swg] "C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Minimem] C:\Programmi\Kerkia\Minimem\minimem.exe
O4 - HKCU\..\Run: [RunkQuerier] C:\Programmi\SM\IeLauncher.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?s=100000343&p=ZKxdm200YYIT&si=142522&a=fuEOSohO7kO9ti2bvg4EZw&n=2010041401
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: (no name) - {755B05A7-0770-4185-B5F6-E75A2CA527E2} - C:\Programmi\SM\SubsHelper.dll
O9 - Extra 'Tools' menuitem: Signature Manager options - {755B05A7-0770-4185-B5F6-E75A2CA527E2} - C:\Programmi\SM\SubsHelper.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barra di ricerca di Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/WebfettiInitialSetup1.0.1.1.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5D9B471D-26CA-43A4-944C-AF7340329093}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{5D9B471D-26CA-43A4-944C-AF7340329093}: NameServer = 192.168.1.1
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\progra~1\window~4\datamngr\datamngr.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: ServiceLayer - Nokia - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Windows Internet Name Service - Unknown owner - C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Dati applicazioni\Windows Internet Name Service\wins.exe

--
End of file - 11724 bytes
Sponsor
Inviato: Saturday, January 22, 2011 5:15:42 PM

 
r16
Inviato: Saturday, January 22, 2011 5:22:23 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Hai un'infezione da MyWebSearch. (Adware, e altre infezioni)

Scarica ed installa MalwareBytes:
clicca qui per il download : http://www.aiutamici.com/software?id=80346
Prima di fare la scansione AGGIORNALO. (è molto importante)
Esegui una scansione completa del sistema.
Elimina gli eventuali file infetti trovati.
Posta il log.

E posta anche un nuovo log di HijackThis. (dopo avere eliminato i file trovati da malwarebytes)
marianocriscuolo
Inviato: Sunday, January 23, 2011 4:05:17 PM
Rank: Member

Iscritto dal : 1/22/2011
Posts: 26
Ecco il log di MalwareBytes e, di seguito, quello di HijackThis dopo aver eliminato i files infetti. Grazie ancora


Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Versione database: 5576

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

23/01/2011 14.39.38
mbam-log-2011-01-23 (14-39-38).txt

Tipo di scansione: Scansione completa (C:\|)
Elementi esaminati: 219487
Tempo trascorso: 1 ore, 29 minuti, 57 secondi

Processi infetti in memoria: 0
Moduli di memoria infetti: 4
Chiavi di registro infette: 143
Valori di registro infetti: 14
Voci infette nei dati di registro: 4
Cartelle infette: 23
File infetti: 144

Processi infetti in memoria:
(Non sono stati rilevati elementi nocivi)

Moduli di memoria infetti:
c:\programmi\mywebsearch\bar\2.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Delete on reboot.
c:\programmi\mywebsearch\bar\2.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Delete on reboot.
c:\programmi\mywebsearch\bar\2.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Delete on reboot.
c:\programmi\mywebsearch\bar\2.bin\F3HTMLMU.DLL (PUP.FunWebProducts) -> Not selected for removal.

Chiavi di registro infette:
HKEY_CLASSES_ROOT\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> Not selected for removal.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.2 (PUP.FunWebProducts) -> Not selected for removal.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu (PUP.FunWebProducts) -> Not selected for removal.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> Not selected for removal.
HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D} (PUP.FunWebProducts) -> Not selected for removal.
HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495} (PUP.FunWebProducts) -> Not selected for removal.
HKEY_CLASSES_ROOT\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1093995A-BA37-41D2-836E-091067C4AD17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.DataControl (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{A9571378-68A1-443d-B082-284F960C6D17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{B813095C-81C0-4E40-AA14-67520372B987} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{F334C7B0-8774-4d5b-BD7A-4F448D03A1AE} (Adware.SkyLab) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{70EF8B2A-3A34-4913-AAFC-5A2827E0B1B1} (Adware.SkyLab) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{AD49CE2B-B922-4E2A-AAD9-C1565855C7BC} (Adware.SkyLab) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\KBBar.KBBarBand.1 (Adware.SkyLab) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\KBBar.KBBarBand (Adware.SkyLab) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{F334C7B0-8774-4D5B-BD7A-4F448D03A1AE} (Adware.SkyLab) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{F334C7B0-8774-4D5B-BD7A-4F448D03A1AE} (Adware.SkyLab) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{D518921A-4A03-425E-9873-B9A71756821E} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{2863E737-DD3F-4280-9AF8-E9E79C16F312} (Adware.SkyMediaPack) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{2863E737-DD3F-4280-9AF8-E9E79C16F312} (Adware.SkyMediaPack) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{819FFE22-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{819FFE20-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{799391D3-EB86-4bac-9BD3-CBFEA58A0E15} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{D858DAFC-9573-4811-B323-7011A3AA7E61} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\SkyMedia (Adware.SkyMedia) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Valori di registro infetti:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\My Web Search Bar Search Scope Monitor (Adware.MyWebSearch) -> Value: My Web Search Bar Search Scope Monitor -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44CF-8957-5838F569A31D} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{F334C7B0-8774-4D5B-BD7A-4F448D03A1AE} (Adware.SkyLab) -> Value: {F334C7B0-8774-4D5B-BD7A-4F448D03A1AE} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44cf-8957-5838F569A31D} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{F334C7B0-8774-4d5b-BD7A-4F448D03A1AE} (Adware.SkyLab) -> Value: {F334C7B0-8774-4d5b-BD7A-4F448D03A1AE} -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Value: (default) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value: f3PopularScreensavers -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Value: FunWebProducts -> Quarantined and deleted successfully.

Voci infette nei dati di registro:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (PUM.Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Folder\Hidden\SHOWALL\CheckedValue (PUM.Hijack.System.Hidden) -> Bad: (0) Good: (1) -> Quarantined and deleted successfully.

Cartelle infette:
c:\programmi\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\screensaver (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\Shared (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\Shared\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch (Adware.MyWebSearch) -> Delete on reboot.
c:\programmi\mywebsearch\bar (Adware.MyWebSearch) -> Delete on reboot.
c:\programmi\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\1.bin\chrome (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin (Adware.MyWebSearch) -> Delete on reboot.
c:\programmi\mywebsearch\bar\2.bin\chrome (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Overlay (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\setups (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\dati applicazioni\whitesmoke (PUP.WhiteSmoke) -> Not selected for removal.

File infetti:
c:\Programmi\MyWebSearch\bar\2.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Delete on reboot.
c:\Programmi\MyWebSearch\bar\2.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Delete on reboot.
c:\programmi\mywebsearch\bar\2.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3HTMLMU.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\programmi\mywebsearch\bar\2.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\searchster.net\searchster.net.dll (Adware.SkyLab) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3REPROX.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\copia usb disk\scarichi eseguibili\ie-pwd-recovery-demo.exe (Spyware.Keylogger) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\impostazioni locali\Temp\tasks\IPFilter.exe (Worm.AutoIt) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\impostazioni locali\Temp\tasks\OB_IT.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\impostazioni locali\Temp\~nsu.tmp\mosquito.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\impostazioni locali\Temp\~nsu.tmp\wsget.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\power-script\addon\nhtmln_2.95.dll (Trojan.Agent) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\1.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3IMSTUB.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\programmi\mywebsearch\bar\2.bin\F3PSSAVR.SCR (PUP.FunWebProducts) -> Not selected for removal.
c:\programmi\mywebsearch\bar\2.bin\F3REGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3RESTUB.DLL (PUP.FunWebProducts) -> Not selected for removal.
c:\programmi\mywebsearch\bar\2.bin\F3SCHMON.EXE (PUP.FunWebProducts) -> Not selected for removal.
c:\programmi\mywebsearch\bar\2.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3AUXSTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3DLGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\MWSMLBTN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\MWSUABTN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\WINDOWS\system32\f3PSSavr.scr (PUP.FunWebProducts) -> Not selected for removal.
c:\WINDOWS\system32\rmcgv.dll (Worm.Conficker) -> Delete on reboot.
c:\documents and settings\administrator\impostazioni locali\Temp\iexplore.exe (Trojan.Agent) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\Shared\Cache\cursormaniabtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\Shared\Cache\smileycentralbtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\funwebproducts\Shared\Cache\webfettibtn.html (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\1.bin\chrome\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\chrome.manifest (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\INSTALL.RDF (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\2.bin\chrome\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\0001F2B7 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\00032694.bmp (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\000C2281 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\000C3D8B.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\000C4943.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\000C4C31.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\000C4DA8.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\000C4F0F.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\00133F1F (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\001A8C82.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\001A9329.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\001A9665.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\001A9849.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\001A9B09.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\00CDA11D.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\00D92ED0.bmp (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\02465B21.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\02465F38 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Cache\files.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\History\search3 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\8_step1.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\autoup.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\autoup.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkez.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkgr.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkgs.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bklf.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkrg.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkwebfet.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkzc.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkzl.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkzn.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkzq.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkzr.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkzu.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkzv.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkzw.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\bkzwinky.jpg (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\blubtn2d.png (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\blubtn2r.png (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\blubtn3d.png (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\blubtn3r.png (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\center.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\index.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\mid_dots.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\protect.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\rebut4.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\rebut4b.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\rebut4c.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\shield.png (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\shocked.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\stop.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\systray.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\systrayp.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\tp_grad.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Message\COMMON\warn.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Overlay\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Settings\setting2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Settings\settings.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\programmi\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
c:\documents and settings\administrator\dati applicazioni\whitesmoke\stat.log (PUP.WhiteSmoke) -> Not selected for removal.


LOGFILE DI HIJACKTHIS


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15.52.12, on 23/01/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Programmi\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmi\File comuni\Nokia\MPlatform\NokiaMServer.exe
C:\Programmi\SlySoft\AnyDVD\AnyDVD.exe
C:\Programmi\File comuni\Java\Java Update\jusched.exe
C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\WINDOW~4\Datamngr\DATAMN~1.EXE
C:\Programmi\Lexmark X1100 Series\lxbkbmon.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\Messenger\msmsgs.exe
C:\Programmi\Microsoft Student\Microsoft Encarta 2009 - Premium + Student DVD\EDICT.EXE
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\Kerkia\Minimem\minimem.exe
C:\Programmi\WinZip\WZQKPICK.EXE
C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
C:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Dati applicazioni\Windows Internet Name Service\wins.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Searchqu Toolbar - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\PROGRA~1\WINDOW~4\ToolBar\SearchquDx.dll
O2 - BHO: CQueryRankBHOImpl - {A003AFC5-9C04-459E-8B03-8A5E72B9F059} - C:\Documents and Settings\Administrator\Dati applicazioni\file.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: LTIEHelper Class - {BE8A4424-DC23-4493-A04D-AC20AD8EEBC2} - C:\Programmi\EasyPrediction\2.0\ltie.dll
O2 - BHO: SignatureManagerBHO - {C6CC9344-BC12-4EA7-9E37-46D61866C771} - C:\Programmi\SM\SubsHelperBHO.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O3 - Toolbar: Searchqu Toolbar - {7FF99715-3016-4381-84CE-E4E4C9673020} - C:\PROGRA~1\WINDOW~4\ToolBar\SearchquDx.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NokiaMServer] C:\Programmi\File comuni\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [Nokia FastStart] "C:\Programmi\Nokia\Nokia Music\NokiaMusic.exe" /command:faststart
O4 - HKLM\..\Run: [CloneCDTray] "C:\Programmi\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [AnyDVD] C:\Programmi\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [DRPU Pc Data manager] "C:\Programmi\DRPU PC Data Manager\apcdm.exe" "hd"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~1\WINDOW~4\Datamngr\DATAMN~1.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Packard Bell Software Suite] C:\Programmi\Packard Bell\Packard Bell Software Suite\Launcher.exe /run
O4 - HKCU\..\Run: [MSMSGS] "C:\Programmi\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [L09IXLRD_21879812] "C:\Programmi\Microsoft Student\Microsoft Encarta 2009 - Premium + Student DVD\EDICT.EXE" -m
O4 - HKCU\..\Run: [FreeCall] "c:\programmi\freecall.com\freecall\freecall.exe" -nosplash -minimized
O4 - HKCU\..\Run: [swg] "C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Minimem] C:\Programmi\Kerkia\Minimem\minimem.exe
O4 - HKCU\..\Run: [RunkQuerier] C:\Programmi\SM\IeLauncher.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: (no name) - {755B05A7-0770-4185-B5F6-E75A2CA527E2} - C:\Programmi\SM\SubsHelper.dll
O9 - Extra 'Tools' menuitem: Signature Manager options - {755B05A7-0770-4185-B5F6-E75A2CA527E2} - C:\Programmi\SM\SubsHelper.dll
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barra di ricerca di Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5D9B471D-26CA-43A4-944C-AF7340329093}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{5D9B471D-26CA-43A4-944C-AF7340329093}: NameServer = 192.168.1.1
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: c:\progra~1\window~4\datamngr\datamngr.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: ServiceLayer - Nokia - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: Windows Internet Name Service - Unknown owner - C:\WINDOWS\system32\config\systemprofile\Impostazioni locali\Dati applicazioni\Windows Internet Name Service\wins.exe

--
End of file - 10422 bytes
r16
Inviato: Sunday, January 23, 2011 4:09:46 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Scarica Combofix (usa Internet Explorer)

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Salvalo sul desktop. (è obligatorio)

Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.

Doppio click su combofix.exe (se usi Vista: tasto destro su Combofix.exe e clicca su: "Esegui come Amministratore" )

E' probabile che ti siano inviati messaggi dall'antivirus,(o dallo stesso Combofix) tu ignorali.

Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.

Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt.
Postalo qui.
marianocriscuolo
Inviato: Sunday, January 23, 2011 8:11:42 PM
Rank: Member

Iscritto dal : 1/22/2011
Posts: 26
ComboFix 11-01-22.03 - Administrator 23/01/2011 18.48.46.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.502.257 [GMT 1:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix.exe

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\_NIM4711.TMP
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome.manifest
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\.#searchqutb.js.1.3
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\data\search\engines.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\data\search\search.xsl
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\lib\about.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\lib\dtxpanelwin.xul
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\lib\dtxprefwin.xul
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\lib\dtxwin.xul
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\lib\emailnotifierproviders.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\lib\external.js
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\lib\neterror.xhtml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\lib\wmpstreamer.html
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\modules\datastore.jsm
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\preferences.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\searchqutb.js
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\toolbar.htm
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\toolbar.xul
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\bg-scalable-mdl.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\bg-scalable-tl.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\bg-scalable-tr.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-dragresize.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-close-down.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-close-over.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-close.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-maximize-down.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-maximize-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-maximize.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-minimize-down.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-minimize-over.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-minimize.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btnarrow-next-off.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btnarrow-next.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btnarrow-previous-off.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btnarrow-previous.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\navico-home.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\panel.html
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\powered-mystart.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\tb_icon.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\widget.js
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1227\widget.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\bg-scalable-mdl.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\bg-scalable-tl.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\bg-scalable-tr.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-dragresize.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-close-down.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-close-over.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-close.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-maximize-down.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-maximize-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-maximize.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-minimize-down.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-minimize-over.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-minimize.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btnarrow-next-off.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btnarrow-next.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btnarrow-previous-off.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btnarrow-previous.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\navico-home.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\panel.html
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\powered-mystart.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\tb_icon.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\widget.js
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1255\widget.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\bg-scalable-mdl.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\bg-scalable-tl.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\bg-scalable-tr.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-dragresize.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-close-down.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-close-over.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-close.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-maximize-down.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-maximize-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-maximize.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-minimize-down.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-minimize-over.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-minimize.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btnarrow-next-off.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btnarrow-next.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btnarrow-previous-off.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btnarrow-previous.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\navico-home.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\panel.html
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\powered-mystart.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\tb_icon.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\widget.js
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.Twitter.1257\widget.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217.zip
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\bg-scalable-mdl.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\bg-scalable-tl.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\bg-scalable-tr.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-dragresize.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-close-down.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-close-over.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-close.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-maximize-down.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-maximize-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-maximize.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-minimize-down.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-minimize-over.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-minimize.PNG
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btnarrow-next-off.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btnarrow-next.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btnarrow-previous-off.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btnarrow-previous.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\navico-home.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\panel.html
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\powered-mystart.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\tb_icon.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\widget.js
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\content\widgets\net.vmn.www.3.YouTube.1217\widget.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\bluelite.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\bluesky.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\btn-search-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\btn-search.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\btn-settings-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\btn-settings.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\btn-widgets-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\btn-widgets.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\btn_settings.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-down-back-ff.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-down-back.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-down-left.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-down-right.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-down-splitter.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-drop-back.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-drop-left.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-drop-right.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-drop-splitter.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-hover-back-ff.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-hover-back.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-hover-left.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-hover-right.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\button-hover-splitter.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\ca.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\dictionary.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\divider.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\downloadcom.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\email.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\email_on.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\games.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\graphred0.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\graphred0_5.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\grey.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\headsup.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\ico-shield.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\images.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\add.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\aol.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\arrow-dn.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\arrow-right.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\arrow-up.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\bg-btn-end.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\bg-btn-mdl.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\bg-btn-mdl_ff.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\bg-btn-start.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\bg-btnover-end.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\bg-btnover-mdl.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\bg-btnover-mdl_ff.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\bg-btnover-start.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\blank.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\btnback-down-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\btnback-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\btnleft-down-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\btnleft-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\btnright-down-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\btnright-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\button-splitter-down-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\button-splitter-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\checkmark.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\chevron.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\collapse.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\comcast.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\dtx.css
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\edit-back-hot.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\edit-back.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\expand.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\found.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\gmail.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\highlight.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\highlight_blue.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\highlight_cyan.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\highlight_lime.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\highlight_magenta.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\highlight_yellow.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\hotmail.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\imap.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\lastsearch-thumb-back.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\loadingMid.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\lock.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\mailcom.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\menu_bg-basic.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\menu_separator_bar.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\menuitem-splitter.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\menuitemback-down-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\menuitemback-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\menuitemleft-down-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\menuitemleft-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\menuitemright-down-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\menuitemright-vista.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\move.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\movetarget.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\css\popupAbout.css
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\css\popupGames.css
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\css\popupWidgets.css
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\footer.htm
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\gamecategory.xsl
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\gameData.js
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\gameList.xsl
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\gametype.xsl
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\arrow-sml-drop.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\arrow-sml.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\arrowr-bluew5.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\bg-aboutbox.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\bg-btnover.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\bg-pnl520x390.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\btn-close-grey.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\btn-close-greyover.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\btn-drag.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\btn-next-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\btn-next.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\btn-previous-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\btn-previous.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\btn-search-pnlbtm-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\btn-search-pnlbtm.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\gamethumb-on.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\gamethumb2-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\ico-calendar.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\ico-download.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\ico-joystick24.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\ico-play.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\ico-tags.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\icon-Add.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\icon-download.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\icon-Info.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\icon-play.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\icon-shop.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\menul-bgon.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\menul-bgover.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\panel-botm-noscroll.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\scroll-bg-206.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\scroll-bg.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\scroll-topwin.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\scrollb-disable.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\scrollb-down.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\scrollb-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\scrollb.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\scrollt-disable.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\scrollt-down.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\scrollt-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\scrollt.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\searchbox-pnlbtm.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\star_x_grey.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\star_x_orange.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\TRUSTe_about.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\view-detailed-on.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\view-detailed-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\view-thumb-on.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\view-thumb-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\widgets-square-16px.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\images\widgets-square-24px.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\popupGames.html
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\panels\popupWidgets.html
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\pop.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\css\manager.css
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\css\slider.css
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\bg-pnl.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\btn-close-grey.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\btn-close-greyover.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\collapsed_button.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\expanded_button.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\ico-playstation-down.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\ico-playstation-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\ico-playstation.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\ico-radio.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\music-note.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-btn-pause-on.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-btn-pause.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-btn-play-on.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-btn-play.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-eq-bg.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-eq-busy.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-eq-off.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-eq-on.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-eq-warning.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-options-design-on.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-options-design.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-options-on.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-options.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-volume-0.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-volume-1.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-volume-2.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-volume-3.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\radio-volume-mute.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\scrollbar-handle.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\scrollbar-track.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\slider.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\slideron.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\images\track.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\managerpanel.html
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\radio\volumeslider.html
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\remove.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\rename.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\resize-box.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\rss.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\rsschannelback.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\RSSLogo.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\rsstabdivider.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\scroll-left.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\scroll-right.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\search-go.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\search.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\text-ellipsis.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\throbber.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\toolbarsplitter.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\transparent_1px.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_02.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_03.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_04.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_06.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_07.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_08.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_09.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_10.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_11.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_12.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_13.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_14.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_15.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_16.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_18.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_19.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_20.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\border_21.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\btn-close-grey.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\btn-close-greyover.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\close-hot.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\close-normal.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\loadingMid.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\proxy.html
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\template.html
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\template.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\templateFF.html
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\uwa\throbber.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\icons\cond999.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\icons\drizzle-s.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\icons\icons.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\icons\na-s.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\icons\na.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\icons\partlysunny-s.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\icons\rain-s.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\icons\thunders-s.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\icons\thunders.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\icons\weather.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\add.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\arrowr-bluew5.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\bg-pnl.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue-whitebg.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\box-check.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\box-uncheck.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\btn-close-grey.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\btn-close-greyover.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\btn-delete.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next-off.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous-off.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\ico-check.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid-s.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\options-weather.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\over-blue.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\over-orange.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug2.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\radio-checked.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\radio-unchecked.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\searchbox-pnlbtm.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\images\weather-contour.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\popupWeather.css
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\weatherbutton\panels\popupWeather.html
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lib\yahoo.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\lichen.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\logo-about.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\logo.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\maps.bmp
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\menuseparatorback.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\modify-save.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\modify.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\modifyhot.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\music.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\news.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\options\options-main.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\options\options-search.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\options\options-weather.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\options\options-widgets.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\orange.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\pixsy.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\relatedlinks.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\rss-collapse.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\rss-delete.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\rss-expand.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\rss-feed.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\rss-folder-remove.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\rss-folder-rename.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\rss-folder.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\rss-found.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\rss-reload.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\rss-subscribe.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\rss.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\rssback.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\rsstopback.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\search-over.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\search.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\searchbar\searchbar-background-left.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\searchbar\searchbar-background-middle.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\searchbar\searchbar-background-right.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\searchqutb.css
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\settings.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\shopping.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\siteinfo.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\skin-bluelite.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\skin-bluesky.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\skin-grey.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\skin-lichen.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\skin-orange.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\skin-yellow.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\technorati.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\throbber.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\toolbarsplitter.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\video.bmp
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\weather.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\web.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\widget_allocine.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\widget_bliptv.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\widget_calcal.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\widget_calculator.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\widget_gservices.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\widget_sudoku.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\widget_todo.jpg
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\widget_todo.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\widget_trio.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\widget_uconverter.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\widgets-square-16px.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\widgets.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\wikipedia.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\yahoosearch.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\yellow.gif
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\youtube.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\chrome\skin\zoom.png
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\components\windowmediator.js
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\install.rdf
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\extensions\{7FF99715-3016-4381-84CE-E4E4C9673020}\manifest.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchplugins\SearchquWebSearch.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\games\00d2dfc64c07a4f32824abac1d6f735b
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\games\3e4265e00cbc4a9cf22a105046a46d8a
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\games\44a5d79f5451d3036ba3986425e234c8
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\games\GameCategories.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\games\GameTypes.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\guid.dat
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\preferences.dat
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\stats.dat
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\uninstallFF.dat
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\weather\4fa3e3bf7342c43b5d1722c347974320
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\weather\54ce203b07daab02658234a04d8bd812
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\weather\forecasts_cache.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\weather\observations_cache.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\weatherbutton_prefs.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\widgets_cache\84b70525cff6359fdeca553342c23e4c
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\widgets_cache\bf5b6317ae07da699882fc948f22eda4
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\widgets_cache\category_cache.xml
c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\searchqutb\widgets_cache\widget_cache.xml
c:\documents and settings\Administrator\Dati applicazioni\OfferBox
c:\documents and settings\Administrator\Dati applicazioni\OfferBox\config.dat
c:\documents and settings\Administrator\Dati applicazioni\OfferBox\config.xml
c:\documents and settings\Administrator\Dati applicazioni\searchqutb
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\chrome\skin\lib\weatherbutton\icons\drizzle-s.png
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\chrome\skin\lib\weatherbutton\icons\partlysunny-s.png
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\chrome\skin\lib\weatherbutton\icons\rain-s.png
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\chrome\skin\lib\weatherbutton\icons\rain.png
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\chrome\skin\lib\weatherbutton\icons\showersday-s.png
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\chrome\skin\lib\weatherbutton\icons\thundersday-s.png
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\dtx.ini
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\games\00d2dfc64c07a4f32824abac1d6f735b
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\games\3e4265e00cbc4a9cf22a105046a46d8a
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\games\44a5d79f5451d3036ba3986425e234c8
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\games\GameCategories.xml
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\games\GameTypes.xml
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\guid.dat
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\preferences.dat
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\stats.dat
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\uninstallIE.dat
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\weather\9b7cf66901fac044bb3e1e3a90b9ce06
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\weather\f133e5440f235a90e9b2e67fbd1e3323
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\weather\forecasts_cache.xml
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\weather\observations_cache.xml
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\weatherbutton_prefs.xml
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\widgets_cache\84b70525cff6359fdeca553342c23e4c
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\widgets_cache\bf5b6317ae07da699882fc948f22eda4
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\widgets_cache\category_cache.xml
c:\documents and settings\Administrator\Dati applicazioni\searchqutb\widgets_cache\widget_cache.xml
c:\documents and settings\Administrator\Dati applicazioni\SetupAnyDVD6523.exe
c:\documents and settings\Administrator\Dati applicazioni\WhiteSmoke
c:\documents and settings\Administrator\Dati applicazioni\WhiteSmoke\stat.log
c:\documents and settings\Administrator\Impostazioni locali\Temporary Internet Files\cookies.sqlite
c:\programmi\EasyPrediction\2.0\ltIE.dll
c:\programmi\Mozilla Firefox\searchplugins\SearchquWebSearch.xml
c:\programmi\Windows Searchqu Toolbar
c:\programmi\Windows Searchqu Toolbar\Datamngr\datamngr.dll
c:\programmi\Windows Searchqu Toolbar\Datamngr\datamngrUI.exe
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\.#searchqutb.js.1.3
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\data\search\engines.xml
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\data\search\search.xsl
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\about.xml
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\dtxpanelwin.xul
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\dtxprefwin.xul
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\dtxwin.xul
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\emailnotifierproviders.xml
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\external.js
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\neterror.xhtml
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\lib\wmpstreamer.html
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\modules\datastore.jsm
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\preferences.xml
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\searchqutb.js
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\toolbar.htm
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\toolbar.xul
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\bg-scalable-mdl.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\bg-scalable-tl.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\bg-scalable-tr.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-dragresize.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-close-down.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-close-over.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-close.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-maximize-down.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-maximize-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-maximize.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-minimize-down.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-minimize-over.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btn-wide-minimize.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btnarrow-next-off.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btnarrow-next.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btnarrow-previous-off.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\btnarrow-previous.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\navico-home.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\panel.html
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\powered-mystart.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\tb_icon.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\widget.js
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1227\widget.xml
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\bg-scalable-mdl.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\bg-scalable-tl.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\bg-scalable-tr.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-dragresize.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-close-down.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-close-over.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-close.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-maximize-down.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-maximize-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-maximize.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-minimize-down.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-minimize-over.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btn-wide-minimize.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btnarrow-next-off.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btnarrow-next.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btnarrow-previous-off.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\btnarrow-previous.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\navico-home.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\panel.html
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\powered-mystart.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\tb_icon.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\widget.js
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1255\widget.xml
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\bg-scalable-mdl.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\bg-scalable-tl.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\bg-scalable-tr.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-dragresize.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-close-down.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-close-over.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-close.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-maximize-down.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-maximize-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-maximize.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-minimize-down.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-minimize-over.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btn-wide-minimize.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btnarrow-next-off.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btnarrow-next.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btnarrow-previous-off.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\btnarrow-previous.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\navico-home.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\panel.html
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\powered-mystart.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\tb_icon.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\widget.js
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.Twitter.1257\widget.xml
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217.zip
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\bg-scalable-mdl.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\bg-scalable-tl.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\bg-scalable-tr.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-dragresize.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-close-down.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-close-over.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-close.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-maximize-down.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-maximize-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-maximize.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-minimize-down.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-minimize-over.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btn-wide-minimize.PNG
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btnarrow-next-off.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btnarrow-next.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btnarrow-previous-off.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\btnarrow-previous.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\navico-home.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\panel.html
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\powered-mystart.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\tb_icon.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\widget.js
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\content\widgets\net.vmn.www.3.YouTube.1217\widget.xml
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\bluelite.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\bluesky.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn-search-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn-search.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn-settings-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn-settings.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn-widgets-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn-widgets.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\btn_settings.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-down-back-ff.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-down-back.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-down-left.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-down-right.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-down-splitter.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-drop-back.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-drop-left.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-drop-right.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-drop-splitter.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-hover-back-ff.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-hover-back.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-hover-left.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-hover-right.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\button-hover-splitter.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\ca.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\dictionary.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\divider.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\downloadcom.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\email.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\email_on.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\games.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\graphred0.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\graphred0_5.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\grey.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\headsup.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\ico-shield.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\images.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\add.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\aol.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\arrow-dn.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\arrow-right.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\arrow-up.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btn-end.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btn-mdl.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btn-mdl_ff.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btn-start.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btnover-end.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btnover-mdl.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btnover-mdl_ff.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\bg-btnover-start.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\blank.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\btnback-down-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\btnback-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\btnleft-down-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\btnleft-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\btnright-down-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\btnright-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\button-splitter-down-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\button-splitter-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\checkmark.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\chevron.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\collapse.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\comcast.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\dtx.css
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\edit-back-hot.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\edit-back.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\expand.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\found.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\gmail.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\highlight.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\highlight_blue.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\highlight_cyan.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\highlight_lime.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\highlight_magenta.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\highlight_yellow.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\hotmail.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\imap.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\lastsearch-thumb-back.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\loadingMid.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\lock.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\mailcom.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menu_bg-basic.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menu_separator_bar.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitem-splitter.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitemback-down-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitemback-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitemleft-down-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitemleft-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitemright-down-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\menuitemright-vista.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\move.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\movetarget.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\css\popupAbout.css
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\css\popupGames.css
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\css\popupWidgets.css
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\footer.htm
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\gamecategory.xsl
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\gameData.js
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\gameList.xsl
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\gametype.xsl
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\arrow-sml-drop.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\arrow-sml.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\arrowr-bluew5.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\bg-aboutbox.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\bg-btnover.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\bg-pnl520x390.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-close-grey.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-close-greyover.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-drag.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-next-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-next.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-previous-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-previous.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-search-pnlbtm-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\btn-search-pnlbtm.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\gamethumb-on.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\gamethumb2-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\ico-calendar.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\ico-download.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\ico-joystick24.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\ico-play.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\ico-tags.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\icon-Add.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\icon-download.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\icon-Info.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\icon-play.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\icon-shop.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\menul-bgon.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\menul-bgover.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\panel-botm-noscroll.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scroll-bg-206.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scroll-bg.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scroll-topwin.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollb-disable.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollb-down.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollb-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollb.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollt-disable.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollt-down.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollt-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\scrollt.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\searchbox-pnlbtm.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\star_x_grey.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\star_x_orange.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\TRUSTe_about.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\view-detailed-on.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\view-detailed-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\view-thumb-on.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\view-thumb-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\widgets-square-16px.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\images\widgets-square-24px.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\popupGames.html
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\panels\popupWidgets.html
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\pop.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\css\manager.css
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\css\slider.css
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\bg-pnl.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\btn-close-grey.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\btn-close-greyover.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\collapsed_button.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\expanded_button.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\ico-playstation-down.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\ico-playstation-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\ico-playstation.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\ico-radio.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\music-note.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-btn-pause-on.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-btn-pause.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-btn-play-on.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-btn-play.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-eq-bg.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-eq-busy.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-eq-off.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-eq-on.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-eq-warning.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-options-design-on.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-options-design.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-options-on.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-options.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-volume-0.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-volume-1.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-volume-2.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-volume-3.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\radio-volume-mute.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\scrollbar-handle.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\scrollbar-track.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\slider.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\slideron.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\images\track.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\managerpanel.html
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\radio\volumeslider.html
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\remove.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\rename.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\resize-box.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\rss.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\rsschannelback.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\RSSLogo.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\rsstabdivider.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\scroll-left.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\scroll-right.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\search-go.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\search.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\text-ellipsis.xml
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\throbber.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\toolbarsplitter.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\transparent_1px.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_02.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_03.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_04.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_06.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_07.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_08.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_09.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_10.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_11.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_12.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_13.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_14.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_15.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_16.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_18.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_19.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_20.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\border_21.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\btn-close-grey.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\btn-close-greyover.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\close-hot.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\close-normal.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\loadingMid.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\proxy.html
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\template.html
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\template.xml
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\templateFF.html
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\uwa\throbber.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\icons\cond999.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\icons\icons.xml
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\icons\na-s.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\icons\na.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\icons\weather.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\add.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\arrowr-bluew5.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue-whitebg.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\bg-pnl520x350blue.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\box-check.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\box-uncheck.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-close-grey.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-close-greyover.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-delete.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btn-search-pnlbtm.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next-off.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-next.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous-off.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\btnarrow-previous.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-check.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid-s.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\ico-hotandhumid.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\options-weather.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\over-blue.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\over-orange.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\powered-by-weatherbug2.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\radio-checked.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\radio-unchecked.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\searchbox-pnlbtm.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\images\weather-contour.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\popupWeather.css
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\weatherbutton\panels\popupWeather.html
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lib\yahoo.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\lichen.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\logo-about.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\logo.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\maps.bmp
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\menuseparatorback.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\modify-save.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\modify.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\modifyhot.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\music.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\news.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\options\options-main.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\options\options-search.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\options\options-weather.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\options\options-widgets.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\orange.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\pixsy.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\relatedlinks.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-collapse.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-delete.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-expand.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-feed.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-folder-remove.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-folder-rename.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-folder.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-found.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-reload.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss-subscribe.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\rss.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\rssback.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\rsstopback.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\search-over.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\search.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\searchbar\searchbar-background-left.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\searchbar\searchbar-background-middle.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\searchbar\searchbar-background-right.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\searchqutb.css
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\settings.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\shopping.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\siteinfo.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\skin-bluelite.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\skin-bluesky.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\skin-grey.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\skin-lichen.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\skin-orange.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\skin-yellow.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\technorati.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\throbber.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\toolbarsplitter.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\video.bmp
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\weather.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\web.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_allocine.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_bliptv.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_calcal.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_calculator.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_gservices.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_sudoku.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_todo.jpg
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_todo.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_trio.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\widget_uconverter.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\widgets-square-16px.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\widgets.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\wikipedia.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\yahoosearch.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\yellow.gif
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\youtube.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\chrome\skin\zoom.png
c:\programmi\Windows Searchqu Toolbar\ToolBar\components\windowmediator.js
c:\programmi\Windows Searchqu Toolbar\ToolBar\manifest.xml
c:\programmi\Windows Searchqu Toolbar\ToolBar\SearchquDx.dll
c:\programmi\Windows Searchqu Toolbar\ToolBar\SearchquTb.dll
c:\programmi\Windows Searchqu Toolbar\ToolBar\uninstall.exe
c:\programmi\Windows Searchqu Toolbar\uninstall.exe
c:\windows\Downloaded Program Files\f3initialsetup1.0.1.1.inf
c:\windows\system32\f3PSSavr.scr

.
((((((((((((((((((((((((( Files Creati Da 2010-12-23 al 2011-01-23 )))))))))))))))))))))))))))))))))))
.

2011-01-23 11:28 . 2011-01-23 11:28 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\Malwarebytes
2011-01-23 11:27 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-23 11:27 . 2011-01-23 11:27 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2011-01-23 11:27 . 2011-01-23 11:27 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2011-01-23 11:27 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-20 08:30 . 2011-01-23 18:03 111104 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\file.dll
2011-01-18 22:59 . 2011-01-21 19:08 -------- d-----w- c:\programmi\Searchster.Net
2011-01-18 22:58 . 2011-01-18 22:59 -------- d-----w- c:\programmi\SM
2011-01-18 18:35 . 2011-01-18 18:35 -------- d-----w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Batchwork
2011-01-18 18:27 . 2011-01-18 18:29 133 ---ha-w- c:\documents and settings\Administrator\Dati applicazioni\lakerda1967.sys
2011-01-18 18:27 . 2011-01-18 18:27 -------- d-----w- c:\programmi\File comuni\eSellerate
2011-01-05 17:56 . 2011-01-05 17:56 -------- d-----w- c:\programmi\iPod
2011-01-05 17:56 . 2011-01-05 17:57 -------- d-----w- c:\programmi\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-18 18:27 . 2009-10-03 08:44 360580 ----a-w- c:\windows\eSellerateEngine.dll
2010-11-29 16:38 . 2010-11-29 16:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 16:38 . 2010-11-29 16:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-12 17:53 . 2010-04-20 18:40 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 15:34 . 2009-10-04 16:33 73728 ----a-w- c:\windows\system32\javacpl.cpl
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A003AFC5-9C04-459E-8B03-8A5E72B9F059}]
2011-01-23 18:03 111104 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\file.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6CC9344-BC12-4EA7-9E37-46D61866C771}]
2010-12-24 16:59 126464 ----a-w- c:\programmi\SM\SubsHelperBHO.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2009-06-26 133104]
"L09IXLRD_21879812"="c:\programmi\Microsoft Student\Microsoft Encarta 2009 - Premium + Student DVD\EDICT.EXE" [2009-03-02 351000]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-12 39408]
"Minimem"="c:\programmi\Kerkia\Minimem\minimem.exe" [2010-08-05 58368]
"RunkQuerier"="c:\programmi\SM\IeLauncher.exe" [2010-12-06 193024]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\programmi\File comuni\Nokia\MPlatform\NokiaMServer" [X]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-10-06 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-10-06 114688]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-10-06 94208]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Nokia FastStart"="c:\programmi\Nokia\Nokia Music\NokiaMusic.exe" [2009-02-26 2376992]
"CloneCDTray"="c:\programmi\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
"AnyDVD"="c:\programmi\SlySoft\AnyDVD\AnyDVD.exe" [2010-05-27 462848]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Lexmark X1100 Series"="c:\programmi\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 57344]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2010-12-13 421160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
WinZip Quick Pick.lnk - c:\programmi\WinZip\WZQKPICK.EXE [2009-6-10 525640]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\Opera\\opera.exe"=
"c:\\WINDOWS\\system32\\config\\systemprofile\\Impostazioni locali\\Dati applicazioni\\Windows Internet Name Service\\wins.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8193:TCP"= 8193:TCP:fipdu

R2 Windows Internet Name Service;Windows Internet Name Service;c:\windows\system32\config\systemprofile\Impostazioni locali\Dati applicazioni\Windows Internet Name Service\wins.exe [07/11/2010 20.58.55 5485056]
S2 gupdate;Google Update Service (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [04/07/2009 20.21.20 133104]
S2 vurkfwil;Image Server;c:\windows\system32\svchost.exe -k netsvcs [19/08/2004 13.00.00 14336]
S3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys --> c:\windows\system32\drivers\SynasUSB.sys [?]
S3 ZMHHPAudioSrv;ZOOM H Series High Performance Audio Driver Service;c:\windows\system32\drivers\zmhhpau.sys [11/08/2008 10.03.22 91136]

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
vurkfwil
.
Contenuto della cartella 'Scheduled Tasks'

2011-01-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2011-01-23 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-07-04 19:21]

2011-01-23 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-07-04 19:21]

2011-01-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-823518204-725345543-500Core.job
- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-06-26 19:38]

2011-01-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-823518204-725345543-500UA.job
- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-06-26 19:38]

2011-01-23 c:\windows\Tasks\User_Feed_Synchronization-{551A3F21-2131-4CC9-B02E-729AFA72DBF1}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.bing.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {{755B05A7-0770-4185-B5F6-E75A2CA527E2} - {755B05A7-0770-4185-B5F6-E75A2CA527E2} - c:\programmi\SM\SubsHelper.dll
TCP: {5D9B471D-26CA-43A4-944C-AF7340329093} = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\
FF - prefs.js: browser.search.selectedEngine - Searchster.Net
FF - prefs.js: browser.startup.homepage - hxxp://it-it.facebook.com/
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZKxdm200YYIT&ptb=fuEOSohO7kO9ti2bvg4EZw&psa=&ind=2010041401&ptnrS=ZKxdm200YYIT&si=142522&st=kwd&n=77cecc39&searchfor=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\programmi\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Firefox Synchronisation Extension: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70} - c:\programmi\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension
FF - Ext: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: Google Search: Search_Toolbar@skywebsearch.com - c:\programmi\Searchster.Net\FF
FF - Ext: Signature Manager: Subscription@helper.com - c:\programmi\SM\FF
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKCU-Run-Packard Bell Software Suite - c:\programmi\Packard Bell\Packard Bell Software Suite\Launcher.exe
HKCU-Run-FreeCall - c:\programmi\freecall.com\freecall\freecall.exe
HKLM-Run-DRPU Pc Data manager - c:\programmi\DRPU PC Data Manager\apcdm.exe
HKLM-Run-DATAMNGR - c:\progra~1\WINDOW~4\Datamngr\DATAMN~1.EXE
AddRemove-{7B63B2922B174135AFC0E1377DD81EC2} - c:\programmi\DivX\DivXCodecUninstall.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-23 19:03
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\vurkfwil]
"ServiceDll"="c:\windows\system32\rmcgv.dll"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_USERS\S-1-5-21-1229272821-823518204-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,79,75,ee,9f,9d,4d,37,44,8c,b6,c4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ed,43,f4,91,13,27,41,40,81,31,69,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,21,69,a9,86,47,d5,5b,4d,bf,fa,08,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'explorer.exe'(3472)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programmi\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programmi\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\programmi\File comuni\Nokia\MPlatform\NokiaMServer.exe
c:\programmi\Lexmark X1100 Series\lxbkbmon.exe
c:\programmi\iPod\bin\iPodService.exe
c:\programmi\PC Connectivity Solution\ServiceLayer.exe
c:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Ora fine scansione: 2011-01-23 19:08:39 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-01-23 18:08

Pre-Run: 5.842.731.008 byte disponibili
Post-Run: 13.553.074.176 byte disponibili

- - End Of File - - 538353558F244318ECE99EED3BE07A19
r16
Inviato: Sunday, January 23, 2011 8:35:14 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Apri un file di testo con il Block Note sul Desktop
Ci incolli il codice che vedi qui sotto, e salvi il file di testo obbligatoriamente con il nome CFScript.txt
Code:
KillAll::

File::
c:\windows\system32\rmcgv.dll
c:\windows\system32\config\systemprofile\Impostazioni locali\Dati applicazioni\Windows Internet Name Service\wins.exe

Driver::
Windows Internet Name Service
vurkfwil

Registry::
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_vurkfwil]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_vurkfwil]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_vurkfwil]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_vurkfwil]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_vurkfwil]
[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\vurkfwil]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\vurkfwil]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\vurkfwil]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\vurkfwil]
[-HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\vurkfwil]

NetSvcs::
vurkfwil


e trascinalo sull'icona di ComboFix.
Attendi la fine dei lavori, senza toccare tastiera, mouse o altro.
Posta il log aggiornato di combofix
marianocriscuolo
Inviato: Monday, January 24, 2011 5:32:49 PM
Rank: Member

Iscritto dal : 1/22/2011
Posts: 26
Ecco il nuovo log di Combofix dopo aver eseguito quanto da te suggerito (durante la procedura ho evitato di aggiornare la versione di Combifix quando me l'ha proposto)

ComboFix 11-01-22.03 - Administrator 24/01/2011 17.11.33.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.502.282 [GMT 1:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Administrator\Desktop\CFScript.txt

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!

FILE ::
"c:\windows\system32\config\systemprofile\Impostazioni locali\Dati applicazioni\Windows Internet Name Service\wins.exe"
"c:\windows\system32\rmcgv.dll"
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\system32\config\systemprofile\Impostazioni locali\Dati applicazioni\Windows Internet Name Service\wins.exe

.
((((((((((((((((((((((((((((((((((((((( Driver/Servizi )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_VURKFWIL
-------\Legacy_WINDOWS_INTERNET_NAME_SERVICE
-------\Service_vurkfwil
-------\Service_Windows Internet Name Service


((((((((((((((((((((((((( Files Creati Da 2010-12-24 al 2011-01-24 )))))))))))))))))))))))))))))))))))
.

2011-01-24 15:52 . 2011-01-24 15:54 -------- d-----w- c:\programmi\File comuni\Adobe
2011-01-23 20:14 . 2011-01-23 20:14 -------- d-----w- c:\programmi\MSXML 4.0
2011-01-23 19:18 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-01-23 19:18 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2011-01-23 19:16 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2011-01-23 19:16 . 2010-08-27 08:02 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2011-01-23 19:16 . 2009-10-15 16:29 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2011-01-23 19:16 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2011-01-23 19:16 . 2010-11-06 00:21 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-01-23 19:16 . 2010-11-06 00:21 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-01-23 19:16 . 2010-11-06 00:21 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-01-23 19:16 . 2009-06-21 21:47 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2011-01-23 19:15 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-01-23 19:09 . 2010-06-18 13:36 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2011-01-23 19:05 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2011-01-23 11:28 . 2011-01-23 11:28 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\Malwarebytes
2011-01-23 11:27 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-23 11:27 . 2011-01-23 11:27 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2011-01-23 11:27 . 2011-01-23 11:27 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2011-01-23 11:27 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-20 08:30 . 2011-01-24 16:20 111104 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\file.dll
2011-01-18 22:59 . 2011-01-21 19:08 -------- d-----w- c:\programmi\Searchster.Net
2011-01-18 22:58 . 2011-01-18 22:59 -------- d-----w- c:\programmi\SM
2011-01-18 18:35 . 2011-01-18 18:35 -------- d-----w- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Batchwork
2011-01-18 18:27 . 2011-01-18 18:29 133 ---ha-w- c:\documents and settings\Administrator\Dati applicazioni\lakerda1967.sys
2011-01-18 18:27 . 2011-01-18 18:27 -------- d-----w- c:\programmi\File comuni\eSellerate
2011-01-05 17:56 . 2011-01-05 17:56 -------- d-----w- c:\programmi\iPod
2011-01-05 17:56 . 2011-01-05 17:57 -------- d-----w- c:\programmi\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-18 18:27 . 2009-10-03 08:44 360580 ----a-w- c:\windows\eSellerateEngine.dll
2010-11-29 16:38 . 2010-11-29 16:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 16:38 . 2010-11-29 16:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-18 18:12 . 2008-10-15 10:34 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-12 17:53 . 2010-04-20 18:40 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 15:34 . 2009-10-04 16:33 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-09 14:51 . 2004-08-19 12:00 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:21 . 2006-03-04 03:34 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:21 . 2004-08-19 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:21 . 2004-08-19 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:26 . 2004-08-19 12:00 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2004-08-19 12:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
2010-10-28 13:13 . 2004-08-19 12:00 290048 ----a-w- c:\windows\system32\atmfd.dll
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A003AFC5-9C04-459E-8B03-8A5E72B9F059}]
2011-01-24 16:20 111104 ----a-w- c:\documents and settings\Administrator\Dati applicazioni\file.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6CC9344-BC12-4EA7-9E37-46D61866C771}]
2010-12-24 16:59 126464 ----a-w- c:\programmi\SM\SubsHelperBHO.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2009-06-26 133104]
"L09IXLRD_21879812"="c:\programmi\Microsoft Student\Microsoft Encarta 2009 - Premium + Student DVD\EDICT.EXE" [2009-03-02 351000]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-12 39408]
"Minimem"="c:\programmi\Kerkia\Minimem\minimem.exe" [2010-08-05 58368]
"RunkQuerier"="c:\programmi\SM\IeLauncher.exe" [2010-12-06 193024]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\programmi\File comuni\Nokia\MPlatform\NokiaMServer" [X]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-10-06 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-10-06 114688]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-10-06 94208]
"Nokia FastStart"="c:\programmi\Nokia\Nokia Music\NokiaMusic.exe" [2009-02-26 2376992]
"CloneCDTray"="c:\programmi\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
"AnyDVD"="c:\programmi\SlySoft\AnyDVD\AnyDVD.exe" [2010-05-27 462848]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Lexmark X1100 Series"="c:\programmi\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 57344]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
WinZip Quick Pick.lnk - c:\programmi\WinZip\WZQKPICK.EXE [2009-6-10 525640]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\Opera\\opera.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8193:TCP"= 8193:TCP:fipdu

S2 gupdate;Google Update Service (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [04/07/2009 20.21.20 133104]
S3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys --> c:\windows\system32\drivers\SynasUSB.sys [?]
S3 ZMHHPAudioSrv;ZOOM H Series High Performance Audio Driver Service;c:\windows\system32\drivers\zmhhpau.sys [11/08/2008 10.03.22 91136]
.
Contenuto della cartella 'Scheduled Tasks'

2011-01-19 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2011-01-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-07-04 19:21]

2011-01-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-07-04 19:21]

2011-01-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-823518204-725345543-500Core.job
- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-06-26 19:38]

2011-01-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-823518204-725345543-500UA.job
- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-06-26 19:38]

2011-01-24 c:\windows\Tasks\User_Feed_Synchronization-{551A3F21-2131-4CC9-B02E-729AFA72DBF1}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.bing.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {{755B05A7-0770-4185-B5F6-E75A2CA527E2} - {755B05A7-0770-4185-B5F6-E75A2CA527E2} - c:\programmi\SM\SubsHelper.dll
TCP: {5D9B471D-26CA-43A4-944C-AF7340329093} = 192.168.1.1
FF - ProfilePath - c:\documents and settings\Administrator\Dati applicazioni\Mozilla\Firefox\Profiles\y5lon9rz.default\
FF - prefs.js: browser.search.selectedEngine - Searchster.Net
FF - prefs.js: browser.startup.homepage - hxxp://it-it.facebook.com/
FF - prefs.js: keyword.URL - hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=ZKxdm200YYIT&ptb=fuEOSohO7kO9ti2bvg4EZw&psa=&ind=2010041401&ptnrS=ZKxdm200YYIT&si=142522&st=kwd&n=77cecc39&searchfor=
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\programmi\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\programmi\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: Java Quick Starter: jqs@sun.com - c:\programmi\Java\jre6\lib\deploy\jqs\ff
FF - Ext: Firefox Synchronisation Extension: {A27F3FEF-1113-4cfb-A032-8E12D7D8EE70} - c:\programmi\Nokia\Nokia Ovi Suite\Connectors\Bookmarks Connector\FirefoxExtension
FF - Ext: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - %profile%\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
FF - Ext: Google Search: Search_Toolbar@skywebsearch.com - c:\programmi\Searchster.Net\FF
FF - Ext: Signature Manager: Subscription@helper.com - c:\programmi\SM\FF
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-24 17:19
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_USERS\S-1-5-21-1229272821-823518204-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,79,75,ee,9f,9d,4d,37,44,8c,b6,c4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ed,43,f4,91,13,27,41,40,81,31,69,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,21,69,a9,86,47,d5,5b,4d,bf,fa,08,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'explorer.exe'(1324)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programmi\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programmi\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\windows\system32\wscntfy.exe
c:\programmi\File comuni\Nokia\MPlatform\NokiaMServer.exe
c:\programmi\Lexmark X1100 Series\lxbkbmon.exe
c:\programmi\iPod\bin\iPodService.exe
c:\programmi\PC Connectivity Solution\ServiceLayer.exe
c:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Ora fine scansione: 2011-01-24 17:24:55 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-01-24 16:24
ComboFix2.txt 2011-01-23 18:08

Pre-Run: 11.427.176.448 byte disponibili
Post-Run: 11.484.241.920 byte disponibili

- - End Of File - - E87E8A36C5F7413FAA88806A89D0536D


r16
Inviato: Monday, January 24, 2011 6:16:06 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Mi puoi per cortesia dirmi cosa sono, cosa contengono, e se li conosci questi programmi? (quelli segnati in rosso)
c:\programmi\SM
c:\programmi\Searchster.Net
c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Batchwork
c:\programmi\File comuni\eSellerate
marianocriscuolo
Inviato: Monday, January 24, 2011 8:09:04 PM
Rank: Member

Iscritto dal : 1/22/2011
Posts: 26
Dei quattro solo Searchster.net mi ricorda proprio quello che succedeva in origine quando aprivo IE. Di preciso non so dirti in che modo ma sono sicuro che ha a che fare con il mio problema. Brick wall
Gli altri non so, per me si possono anche cancellare.
Grazie ancora dell'aiuto che mi stai dando, speriamo di riuscire a risolvere Applause Applause
r16
Inviato: Monday, January 24, 2011 10:20:56 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Disistalla Firefox. (lo reistalli in un secondo momento)

Poi:

Apri un file di testo con il Block Note sul Desktop .
Ci incolli il codice che vedi qui sotto, e salvi il file di testo obbligatoriamente con il nome CFScript.txt
Code:
KillAll::
File::
c:\documents and settings\Administrator\Dati applicazioni\file.dll
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-823518204-725345543-500UA.job
c:\documents and settings\Administrator\Dati applicazioni\lakerda1967.sys

Folder::
c:\programmi\Searchster.Net
c:\programmi\SM
c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Batchwork
c:\programmi\File comuni\eSellerate

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A003AFC5-9C04-459E-8B03-8A5E72B9F059}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RunkQuerier"=-
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6CC9344-BC12-4EA7-9E37-46D61866C771}]
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8193:TCP"=-

e trascinalo sull'icona di ComboFix.
Attendi la fine dei lavori, senza toccare tastiera, mouse o altro.
Posta il log aggiornato di combofix
marianocriscuolo
Inviato: Tuesday, January 25, 2011 8:41:09 PM
Rank: Member

Iscritto dal : 1/22/2011
Posts: 26
Prima di farlo, devo disinstallare solo Firefox o anche Opera, Safari e Chrome?
r16
Inviato: Tuesday, January 25, 2011 8:53:28 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Solo Firefox.
marianocriscuolo
Inviato: Wednesday, January 26, 2011 10:40:04 PM
Rank: Member

Iscritto dal : 1/22/2011
Posts: 26
ComboFix 11-01-22.03 - Administrator 26/01/2011 21.36.04.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.502.328 [GMT 1:00]
Eseguito da: c:\documents and settings\Administrator\Desktop\ComboFix.exe
Opzioni usate :: c:\documents and settings\Administrator\Desktop\CFScript.txt

ATTENZIONE - QUESTO PC NON HA LA CONSOLE DI RIPRISTINO DI EMERGENZA INSTALLATA !!

FILE ::
"c:\documents and settings\Administrator\Dati applicazioni\file.dll"
"c:\documents and settings\Administrator\Dati applicazioni\lakerda1967.sys"
"c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-823518204-725345543-500UA.job"
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Administrator\Dati applicazioni\file.dll
c:\documents and settings\Administrator\Dati applicazioni\lakerda1967.sys
c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Batchwork
c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Batchwork\Doc-2-Doc\doc2doc.exe.log
c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Batchwork\Doc-2-Doc\doc2doc.ext
c:\programmi\File comuni\eSellerate
c:\programmi\File comuni\eSellerate\eWebClient.dll
c:\programmi\Searchster.Net
c:\programmi\Searchster.Net\BrowserStartPage.dll
c:\programmi\Searchster.Net\ChrExt.crx
c:\programmi\Searchster.Net\ChrExt\index.htm
c:\programmi\Searchster.Net\ChrExt\manifest.json
c:\programmi\Searchster.Net\ChrExt\redirect.html
c:\programmi\Searchster.Net\Config.dat
c:\programmi\Searchster.Net\FF\chrome.manifest
c:\programmi\Searchster.Net\FF\chrome\content\about.xul
c:\programmi\Searchster.Net\FF\chrome\content\registerdialog.js
c:\programmi\Searchster.Net\FF\chrome\content\registerdialog.xul
c:\programmi\Searchster.Net\FF\chrome\content\settings.js
c:\programmi\Searchster.Net\FF\chrome\content\skysearchtoolbar.js
c:\programmi\Searchster.Net\FF\chrome\content\skysearchtoolbar.xul
c:\programmi\Searchster.Net\FF\chrome\content\startAbout.js
c:\programmi\Searchster.Net\FF\chrome\content\tabs.html
c:\programmi\Searchster.Net\FF\chrome\content\unregister.xul
c:\programmi\Searchster.Net\FF\chrome\locale\en-US\skysearchtoolbar.dtd
c:\programmi\Searchster.Net\FF\chrome\locale\en-US\toolbar.properties
c:\programmi\Searchster.Net\FF\chrome\skin\about.png
c:\programmi\Searchster.Net\FF\chrome\skin\aboutDlg.png
c:\programmi\Searchster.Net\FF\chrome\skin\addvideo.png
c:\programmi\Searchster.Net\FF\chrome\skin\bigbutton.png
c:\programmi\Searchster.Net\FF\chrome\skin\burnaudio.png
c:\programmi\Searchster.Net\FF\chrome\skin\burnit.png
c:\programmi\Searchster.Net\FF\chrome\skin\gripper.png
c:\programmi\Searchster.Net\FF\chrome\skin\icon.png
c:\programmi\Searchster.Net\FF\chrome\skin\icon16-16.png
c:\programmi\Searchster.Net\FF\chrome\skin\iphone.png
c:\programmi\Searchster.Net\FF\chrome\skin\premium.png
c:\programmi\Searchster.Net\FF\chrome\skin\register.png
c:\programmi\Searchster.Net\FF\chrome\skin\savevideo.png
c:\programmi\Searchster.Net\FF\chrome\skin\savevideo2.png
c:\programmi\Searchster.Net\FF\chrome\skin\search.png
c:\programmi\Searchster.Net\FF\chrome\skin\settings.png
c:\programmi\Searchster.Net\FF\chrome\skin\showstatus.png
c:\programmi\Searchster.Net\FF\chrome\skin\skysearchtoolbar.css
c:\programmi\Searchster.Net\FF\chrome\skin\smile!.png
c:\programmi\Searchster.Net\FF\chrome\skin\videooftheday.png
c:\programmi\Searchster.Net\FF\components\ISwslib.xpt
c:\programmi\Searchster.Net\FF\components\nsIRdsHistoryService.js
c:\programmi\Searchster.Net\FF\components\nsIRdsHistoryService.xpt
c:\programmi\Searchster.Net\FF\components\rdstb-autocomplete.js
c:\programmi\Searchster.Net\FF\components\swslib.dll
c:\programmi\Searchster.Net\FF\install.rdf
c:\programmi\Searchster.Net\FF\Search_Toolbar@skywebsearch.com
c:\programmi\Searchster.Net\InstallHelper.exe
c:\programmi\Searchster.Net\StarBurnRDS.dll
c:\programmi\Searchster.Net\tabs.html
c:\programmi\Searchster.Net\unins000.dat
c:\programmi\Searchster.Net\unins000.exe
c:\programmi\SM
c:\programmi\SM\FF\chrome.manifest
c:\programmi\SM\FF\content\addDialog.xul
c:\programmi\SM\FF\content\firefoxOverlay.xul
c:\programmi\SM\FF\content\globals.js
c:\programmi\SM\FF\content\main.js
c:\programmi\SM\FF\content\overlay.js
c:\programmi\SM\FF\content\prefs.xul
c:\programmi\SM\FF\defaults\preferences\my_addon.js
c:\programmi\SM\FF\install.rdf
c:\programmi\SM\FF\locale\en-US\manyffaddon.dtd
c:\programmi\SM\FF\locale\en-US\manyffaddon.properties
c:\programmi\SM\FF\locale\en-US\my_addon.dtd
c:\programmi\SM\FF\skin\my_addon.css
c:\programmi\SM\FF\skin\overlay.css
c:\programmi\SM\IeLauncher.exe
c:\programmi\SM\SubsHelper.dll
c:\programmi\SM\SubsHelperBHO.dll
c:\programmi\SM\unins000.dat
c:\programmi\SM\unins000.exe
c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-823518204-725345543-500UA.job

.
((((((((((((((((((((((((( Files Creati Da 2010-12-26 al 2011-01-26 )))))))))))))))))))))))))))))))))))
.

2011-01-24 15:52 . 2011-01-24 15:54 -------- d-----w- c:\programmi\File comuni\Adobe
2011-01-23 20:14 . 2011-01-23 20:14 -------- d-----w- c:\programmi\MSXML 4.0
2011-01-23 19:18 . 2010-09-18 06:53 953856 -c----w- c:\windows\system32\dllcache\mfc40u.dll
2011-01-23 19:18 . 2010-09-18 06:53 974848 -c----w- c:\windows\system32\dllcache\mfc42.dll
2011-01-23 19:16 . 2010-06-14 14:31 744448 -c----w- c:\windows\system32\dllcache\helpsvc.exe
2011-01-23 19:16 . 2010-08-27 08:02 119808 -c----w- c:\windows\system32\dllcache\t2embed.dll
2011-01-23 19:16 . 2009-10-15 16:29 81920 -c----w- c:\windows\system32\dllcache\fontsub.dll
2011-01-23 19:16 . 2010-02-12 10:03 293376 ------w- c:\windows\system32\browserchoice.exe
2011-01-23 19:16 . 2010-11-06 00:21 602112 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2011-01-23 19:16 . 2010-11-06 00:21 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2011-01-23 19:16 . 2010-11-06 00:21 743424 -c----w- c:\windows\system32\dllcache\iedvtool.dll
2011-01-23 19:16 . 2009-06-21 21:47 153088 -c----w- c:\windows\system32\dllcache\triedit.dll
2011-01-23 19:15 . 2010-11-02 15:17 40960 -c----w- c:\windows\system32\dllcache\ndproxy.sys
2011-01-23 19:09 . 2010-06-18 13:36 3558912 -c----w- c:\windows\system32\dllcache\moviemk.exe
2011-01-23 19:05 . 2010-10-11 14:59 45568 -c----w- c:\windows\system32\dllcache\wab.exe
2011-01-23 11:28 . 2011-01-23 11:28 -------- d-----w- c:\documents and settings\Administrator\Dati applicazioni\Malwarebytes
2011-01-23 11:27 . 2010-12-20 17:09 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-01-23 11:27 . 2011-01-23 11:27 -------- d-----w- c:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2011-01-23 11:27 . 2011-01-23 11:27 -------- d-----w- c:\programmi\Malwarebytes' Anti-Malware
2011-01-23 11:27 . 2010-12-20 17:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-01-05 17:56 . 2011-01-05 17:56 -------- d-----w- c:\programmi\iPod
2011-01-05 17:56 . 2011-01-05 17:57 -------- d-----w- c:\programmi\iTunes

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-01-18 18:27 . 2009-10-03 08:44 360580 ----a-w- c:\windows\eSellerateEngine.dll
2010-11-29 16:38 . 2010-11-29 16:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 16:38 . 2010-11-29 16:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-18 18:12 . 2008-10-15 10:34 86016 ----a-w- c:\windows\system32\isign32.dll
2010-11-12 17:53 . 2010-04-20 18:40 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 15:34 . 2009-10-04 16:33 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-11-09 14:51 . 2004-08-19 12:00 249856 ----a-w- c:\windows\system32\odbc32.dll
2010-11-06 00:21 . 2006-03-04 03:34 916480 ----a-w- c:\windows\system32\wininet.dll
2010-11-06 00:21 . 2004-08-19 12:00 43520 ----a-w- c:\windows\system32\licmgr10.dll
2010-11-06 00:21 . 2004-08-19 12:00 1469440 ----a-w- c:\windows\system32\inetcpl.cpl
2010-11-03 12:26 . 2004-08-19 12:00 385024 ----a-w- c:\windows\system32\html.iec
2010-11-02 15:17 . 2004-08-19 12:00 40960 ----a-w- c:\windows\system32\drivers\ndproxy.sys
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" [2009-06-26 133104]
"L09IXLRD_21879812"="c:\programmi\Microsoft Student\Microsoft Encarta 2009 - Premium + Student DVD\EDICT.EXE" [2009-03-02 351000]
"swg"="c:\programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-09-12 39408]
"Minimem"="c:\programmi\Kerkia\Minimem\minimem.exe" [2010-08-05 58368]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NokiaMServer"="c:\programmi\File comuni\Nokia\MPlatform\NokiaMServer" [X]
"SoundMAXPnP"="c:\programmi\Analog Devices\Core\smax4pnp.exe" [2006-05-01 843776]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2006-10-06 98304]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2006-10-06 114688]
"Persistence"="c:\windows\system32\igfxpers.exe" [2006-10-06 94208]
"Nokia FastStart"="c:\programmi\Nokia\Nokia Music\NokiaMusic.exe" [2009-02-26 2376992]
"CloneCDTray"="c:\programmi\SlySoft\CloneCD\CloneCDTray.exe" [2009-01-29 57344]
"AnyDVD"="c:\programmi\SlySoft\AnyDVD\AnyDVD.exe" [2010-05-27 462848]
"SunJavaUpdateSched"="c:\programmi\File comuni\Java\Java Update\jusched.exe" [2010-05-14 248552]
"Lexmark X1100 Series"="c:\programmi\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 57344]
"QuickTime Task"="c:\programmi\QuickTime\qttask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\programmi\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"Adobe Reader Speed Launcher"="c:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-23 35760]
"Adobe ARM"="c:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]

c:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
WinZip Quick Pick.lnk - c:\programmi\WinZip\WZQKPICK.EXE [2009-6-10 525640]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Programmi\\Messenger\\msmsgs.exe"=
"c:\\Programmi\\Skype\\Plugin Manager\\skypePM.exe"=
"c:\\Programmi\\Opera\\opera.exe"=
"c:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"c:\\Programmi\\iTunes\\iTunes.exe"=
"c:\\Programmi\\Skype\\Phone\\Skype.exe"=

S2 gupdate;Google Update Service (gupdate);c:\programmi\Google\Update\GoogleUpdate.exe [04/07/2009 20.21.20 133104]
S3 SynasUSB;SynasUSB;c:\windows\system32\drivers\SynasUSB.sys --> c:\windows\system32\drivers\SynasUSB.sys [?]
S3 ZMHHPAudioSrv;ZOOM H Series High Performance Audio Driver Service;c:\windows\system32\drivers\zmhhpau.sys [11/08/2008 10.03.22 91136]
.
Contenuto della cartella 'Scheduled Tasks'

2011-01-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\programmi\Apple Software Update\SoftwareUpdate.exe [2008-07-30 10:34]

2011-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-07-04 19:21]

2011-01-26 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\programmi\Google\Update\GoogleUpdate.exe [2009-07-04 19:21]

2011-01-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1229272821-823518204-725345543-500Core.job
- c:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe [2009-06-26 19:38]

2011-01-26 c:\windows\Tasks\User_Feed_Synchronization-{551A3F21-2131-4CC9-B02E-729AFA72DBF1}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 02:31]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.bing.com/
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Google Sidewiki... - c:\programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
IE: {{755B05A7-0770-4185-B5F6-E75A2CA527E2} - {755B05A7-0770-4185-B5F6-E75A2CA527E2} - c:\programmi\SM\SubsHelper.dll
TCP: {5D9B471D-26CA-43A4-944C-AF7340329093} = 192.168.1.1
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

AddRemove-Searchster.Net_is1 - c:\programmi\Searchster.Net\unins000.exe
AddRemove-{654986E1-B6C9-4CA4-A478-B13025E739DE}_is1 - c:\programmi\SM\unins000.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-01-26 21:43
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_USERS\S-1-5-21-1229272821-823518204-725345543-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,79,75,ee,9f,9d,4d,37,44,8c,b6,c4,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,ed,43,f4,91,13,27,41,40,81,31,69,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,21,69,a9,86,47,d5,5b,4d,bf,fa,08,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10l_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'explorer.exe'(3112)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\programmi\Nokia\Nokia PC Suite 7\PhoneBrowser.dll
c:\programmi\Nokia\Nokia PC Suite 7\NGSCM.DLL
c:\programmi\Nokia\Nokia PC Suite 7\Lang\PhoneBrowser_ita.nlr
c:\programmi\Nokia\Nokia PC Suite 7\Resource\PhoneBrowser_Nokia.ngr
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Altri processi in esecuzione ------------------------
.
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\programmi\Bonjour\mDNSResponder.exe
c:\programmi\Java\jre6\bin\jqs.exe
c:\programmi\File comuni\Nokia\MPlatform\NokiaMServer.exe
c:\programmi\Lexmark X1100 Series\lxbkbmon.exe
c:\programmi\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
c:\programmi\PC Connectivity Solution\ServiceLayer.exe
c:\programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
c:\programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
.
**************************************************************************
.
Ora fine scansione: 2011-01-26 21:50:31 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2011-01-26 20:50
ComboFix2.txt 2011-01-24 16:24
ComboFix3.txt 2011-01-23 18:08

Pre-Run: 11.894.067.200 byte disponibili
Post-Run: 11.904.466.944 byte disponibili

- - End Of File - - 315DA6827DC6B7A39841FBF1221EDCAA
r16
Inviato: Wednesday, January 26, 2011 10:48:23 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Dimmi i problemi che riscontri.
marianocriscuolo
Inviato: Thursday, January 27, 2011 8:50:42 PM
Rank: Member

Iscritto dal : 1/22/2011
Posts: 26
Il problema originale di redirect di IE non c'è più !!
Altre anomalie non ne vedo ma, grazie al tuo aiuto, è venuto fuori che il mio PC era messo maluccio.
Ti sarei ulteriormente grato se mi consigliassi come proteggerlo preventivamente da virus, spyware, malware e similari.
Grazie per la tua dedizione e professionalità Applause
cbbusto
Inviato: Friday, January 28, 2011 4:36:54 PM

Rank: AiutAmico

Iscritto dal : 11/8/2008
Posts: 13,964
Ciao, come antivirus installa QUESTO uno dei
migliori, fa anche da antispyware e antimalware, quindi è sufficiente.
r16
Inviato: Friday, January 28, 2011 5:34:20 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Posta un log aggiornato di HiJackThis.
marianocriscuolo
Inviato: Friday, January 28, 2011 9:55:35 PM
Rank: Member

Iscritto dal : 1/22/2011
Posts: 26
Grazie per il link dell'antivirus
Ecco l'ultimo log di HiJackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21.53.05, on 28/01/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Programmi\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Programmi\File comuni\Nokia\MPlatform\NokiaMServer.exe
C:\Programmi\SlySoft\AnyDVD\AnyDVD.exe
C:\Programmi\File comuni\Java\Java Update\jusched.exe
C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe
C:\Programmi\iTunes\iTunesHelper.exe
C:\Programmi\Lexmark X1100 Series\lxbkbmon.exe
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe
C:\Programmi\Microsoft Student\Microsoft Encarta 2009 - Premium + Student DVD\EDICT.EXE
C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programmi\Kerkia\Minimem\minimem.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\WinZip\WZQKPICK.EXE
C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Programmi\Bonjour\mDNSResponder.exe
C:\Programmi\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programmi\PC Connectivity Solution\ServiceLayer.exe
C:\Programmi\PC Connectivity Solution\Transports\NclUSBSrv.exe
C:\Programmi\PC Connectivity Solution\Transports\NclRSSrv.exe
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Chrome\Application\chrome.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programmi\Google\GoogleToolbarNotifier\5.6.5805.1910\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programmi\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Programmi\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programmi\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [NokiaMServer] C:\Programmi\File comuni\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [Nokia FastStart] "C:\Programmi\Nokia\Nokia Music\NokiaMusic.exe" /command:faststart
O4 - HKLM\..\Run: [CloneCDTray] "C:\Programmi\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [AnyDVD] C:\Programmi\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programmi\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [L09IXLRD_21879812] "C:\Programmi\Microsoft Student\Microsoft Encarta 2009 - Premium + Student DVD\EDICT.EXE" -m
O4 - HKCU\..\Run: [swg] "C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Minimem] C:\Programmi\Kerkia\Minimem\minimem.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki... - res://C:\Programmi\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html
O9 - Extra button: (no name) - {755B05A7-0770-4185-B5F6-E75A2CA527E2} - C:\Programmi\SM\SubsHelper.dll (file missing)
O9 - Extra 'Tools' menuitem: Signature Manager options - {755B05A7-0770-4185-B5F6-E75A2CA527E2} - C:\Programmi\SM\SubsHelper.dll (file missing)
O9 - Extra button: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Barra di ricerca di Encarta - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programmi\File comuni\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5D9B471D-26CA-43A4-944C-AF7340329093}: NameServer = 192.168.1.1
O17 - HKLM\System\CS1\Services\Tcpip\..\{5D9B471D-26CA-43A4-944C-AF7340329093}: NameServer = 192.168.1.1
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Programmi\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Inc. - C:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Programmi\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programmi\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: ServiceLayer - Nokia - C:\Programmi\PC Connectivity Solution\ServiceLayer.exe

--
End of file - 8994 bytes

r16
Inviato: Friday, January 28, 2011 10:42:38 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Disattiva il ripristino configurazione di sistema, e tienilo disattivato.
http://guide.aiutamici.com/guide?C1=7&C2=68&ID=80121

Avvia hijackthis, metti la spunta alle voci che andrò ad elencarti e con tutte le applicazioni chiuse e disconnesso da Internet,premi su "fix checked":
Commenta:
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [NokiaMServer] C:\Programmi\File comuni\Nokia\MPlatform\NokiaMServer /watchfiles startup
O4 - HKLM\..\Run: [Nokia FastStart] "C:\Programmi\Nokia\Nokia Music\NokiaMusic.exe" /command:faststart
O4 - HKLM\..\Run: [CloneCDTray] "C:\Programmi\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [AnyDVD] C:\Programmi\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programmi\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Administrator\Impostazioni locali\Dati applicazioni\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [swg] "C:\Programmi\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [Minimem] C:\Programmi\Kerkia\Minimem\minimem.exe
O9 - Extra button: (no name) - {755B05A7-0770-4185-B5F6-E75A2CA527E2} - C:\Programmi\SM\SubsHelper.dll (file missing)
O9 - Extra 'Tools' menuitem: Signature Manager options - {755B05A7-0770-4185-B5F6-E75A2CA527E2} - C:\Programmi\SM\SubsHelper.dll (file missing)


Dai una pulita (registro compreso)con CCleaner: http://www.aiutamici.com/software?ID=11223
Nella schermata iniziale di CCleaner, clicca su Opzioni e poi Avanzate, togli il segno di spunta a: Cancella i file in Windows Temp solo se più vecchi di 48 ore. (poi esegui le pulizie)

Segui questo percorso e svuota la cartella Prefetch : (non eliminare la cartella)
C:\Windows\Prefetch


Per eliminare i vari Tooll scaricati: (combofix)
Scarica OTC by OldTimer sul desktop:
http://oldtimer.geekstogo.com/OTC.exe
doppio clic per eseguirlo
Clicca su CleanUp.
Ti chiederà di riavviare il pc.
Clicca sì.

Esegui anche uno Scandisk.
Fai una deframmentazione del HD.

Riattiva il ripristino configurazione di sistema.
Se non riscontri problemi, dovresti essere a posto.

Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.