Virus Troj. Downloader.agent. AQG
Résolu/Fermé
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
-
30 mars 2007 à 02:33
doctor jekill Messages postés 64 Date d'inscription vendredi 26 août 2005 Statut Membre Dernière intervention 22 novembre 2007 - 3 avril 2007 à 14:13
doctor jekill Messages postés 64 Date d'inscription vendredi 26 août 2005 Statut Membre Dernière intervention 22 novembre 2007 - 3 avril 2007 à 14:13
A voir également:
- Virus Troj. Downloader.agent. AQG
- Svchost.exe virus - Guide
- Vérificateur de lien virus - Guide
- Produkey virus ✓ - Forum Windows 10
- Faux message virus iphone - Forum iPhone
- Bluestacks virus ✓ - Forum Logiciels
55 réponses
papyber
Messages postés
6406
Date d'inscription
samedi 24 mars 2007
Statut
Contributeur sécurité
Dernière intervention
3 octobre 2010
257
30 mars 2007 à 09:01
30 mars 2007 à 09:01
télécharge GenProc sur ton bureau
http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip
dézippe le dossier, double-clique sur GenProc.bat et poste le contenu du rapport qui s'ouvre
Aide en images : http://www.alt-shift-return.org/Info/GenProc-HowTo.html
http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip
dézippe le dossier, double-clique sur GenProc.bat et poste le contenu du rapport qui s'ouvre
Aide en images : http://www.alt-shift-return.org/Info/GenProc-HowTo.html
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
30 mars 2007 à 13:31
30 mars 2007 à 13:31
Bonjour
Merci de me repondre
voivi le rapport Gen-proc.
Rapport GenProc 0.32 effectué le 30.03.2007 à 13:21:46.03 - SystemRoot = C:\WINDOWS
# Etape 1/ Télécharge :
- CCleaner http://www.filehippo.com/download_ccleaner.html ("Download Latest Version", sur la droite).
Ce logiciel va permettre de supprimer tous les fichiers temporaires. Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires". Ensuite, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.
- lopxpMH2 http://www.alt-shift-return.org/Info/Fichiers/lopxpMH2.zip sur ton bureau.
Dézippe-le (clic droit -> "Extraire ici") et double clique sur le fichier lopxpMH.bat.
Dans ta prochaine réponse, poste :
- le contenu du rapport qui va s'ouvrir ;
- un nouveau rapport GenProc.
Merci de me repondre
voivi le rapport Gen-proc.
Rapport GenProc 0.32 effectué le 30.03.2007 à 13:21:46.03 - SystemRoot = C:\WINDOWS
# Etape 1/ Télécharge :
- CCleaner http://www.filehippo.com/download_ccleaner.html ("Download Latest Version", sur la droite).
Ce logiciel va permettre de supprimer tous les fichiers temporaires. Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires". Ensuite, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.
- lopxpMH2 http://www.alt-shift-return.org/Info/Fichiers/lopxpMH2.zip sur ton bureau.
Dézippe-le (clic droit -> "Extraire ici") et double clique sur le fichier lopxpMH.bat.
Dans ta prochaine réponse, poste :
- le contenu du rapport qui va s'ouvrir ;
- un nouveau rapport GenProc.
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
30 mars 2007 à 13:44
30 mars 2007 à 13:44
allo
je dois suivre les etapes du rapport?
je dois suivre les etapes du rapport?
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
30 mars 2007 à 14:01
30 mars 2007 à 14:01
voila le rapport lopxpmh2
Il y à eu plusieures erreures
Erreur: le systeme n'a pas pus trouver la clef ou la valeur de registre specifié
Erreur: trop de paramètres de ligne de commande
Erreur: trop de paramètres de ligne de commande
Erreur: le système n'a pas pus trouver la clef ou la valeur de registre spécifié
Enfin voila le rapport qui c'est ouvert
Rapport lopxpMH2 version 2.0 fait à 13:50:03.54 le 30.03.2007
C:\Documents and Settings\Maryline-Tino\Bureau
******************************************
## Répertoires Application Data
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\Administrateur\Application Data
06.09.2005 13:48 <REP> .
06.09.2005 13:48 <REP> ..
06.09.2005 13:48 <REP> Adobe
06.09.2005 13:48 <REP> AdobeUM
06.09.2005 13:48 <REP> Ahead
06.09.2005 13:48 <REP> CyberLink
06.09.2005 13:48 <REP> Help
06.09.2005 13:48 <REP> Identities
06.09.2005 13:48 <REP> Macromedia
06.09.2005 13:48 <REP> Microsoft
06.09.2005 13:48 62 desktop.ini
1 fichier(s) 62 octets
10 Rép(s) 22'470'504'448 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\Administrateur\Local Settings\Application Data
06.09.2005 13:48 <REP> .
06.09.2005 13:48 <REP> ..
06.09.2005 13:48 <REP> Adobe
06.09.2005 13:48 <REP> ApplicationHistory
06.09.2005 13:48 <REP> Help
06.09.2005 13:48 <REP> Microsoft
06.09.2005 13:48 <REP> Powercinema
06.09.2005 13:48 <REP> WMTools Downloaded Files
06.09.2005 13:48 3'584 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
06.09.2005 13:48 135 fusioncache.dat
06.09.2005 13:48 55'632 GDIPFONTCACHEV1.DAT
06.09.2005 13:48 4'777'014 IconCache.db
4 fichier(s) 4'836'365 octets
8 Rép(s) 22'470'504'448 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\All Users\Application Data
25.06.2004 18:11 <REP> .
25.06.2004 18:11 <REP> ..
13.02.2007 05:24 <REP> Adobe
25.06.2004 18:46 <REP> Ahead
11.01.2007 04:03 <REP> Apple Computer
11.08.2005 18:15 <REP> Brother
18.03.2007 03:06 <REP> DVD Shrink
25.02.2006 07:07 <REP> Four Once Dash Part
08.03.2007 11:30 <REP> JollyBear
25.06.2004 18:11 <REP> Microsoft
28.12.2006 19:45 <REP> Motive
15.11.2004 10:38 <REP> MSN6
22.08.2005 20:52 <REP> MumboJumbo
14.11.2004 22:14 <REP> nView_Profiles
28.08.2006 03:00 <REP> PACE Anti-Piracy
16.09.2006 17:46 <REP> PlayFirst
24.03.2005 15:18 <REP> QuickTime
31.08.2006 21:18 <REP> Sandlot Games
25.06.2004 17:17 <REP> SBSI
11.08.2005 18:16 <REP> ScanSoft
03.02.2005 15:32 <REP> Spybot - Search & Destroy
13.02.2005 15:01 <REP> Symantec
18.04.2006 02:58 <REP> Synful
04.11.2005 21:44 <REP> Windows Genuine Advantage
10.03.2007 07:32 <REP> Yahoo! Companion
09.06.2006 17:45 <REP> Zylom
25.06.2004 18:11 62 desktop.ini
1 fichier(s) 62 octets
26 Rép(s) 22'470'504'448 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\Default User\Application Data
25.06.2004 18:11 <REP> .
25.06.2004 18:11 <REP> ..
14.11.2004 14:27 <REP> Adobe
14.11.2004 14:27 <REP> AdobeUM
14.11.2004 14:27 <REP> Ahead
14.11.2004 14:27 <REP> CyberLink
14.11.2004 14:27 <REP> Help
25.06.2004 17:14 <REP> Identities
14.11.2004 14:27 <REP> Macromedia
25.06.2004 18:11 <REP> Microsoft
25.06.2004 18:11 62 desktop.ini
1 fichier(s) 62 octets
10 Rép(s) 22'470'500'352 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\Default User\Local Settings\Application Data
25.06.2004 18:11 <REP> .
25.06.2004 18:11 <REP> ..
14.11.2004 14:27 <REP> Adobe
14.11.2004 14:27 <REP> ApplicationHistory
14.11.2004 14:27 <REP> Help
14.11.2004 14:27 <REP> Microsoft
14.11.2004 14:27 <REP> Powercinema
14.11.2004 14:27 <REP> WMTools Downloaded Files
14.11.2004 14:27 3'584 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
14.11.2004 14:27 135 fusioncache.dat
14.11.2004 14:27 55'632 GDIPFONTCACHEV1.DAT
14.11.2004 14:27 4'777'014 IconCache.db
4 fichier(s) 4'836'365 octets
8 Rép(s) 22'470'500'352 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\LocalService\Application Data
25.06.2004 17:16 <REP> .
25.06.2004 17:16 <REP> ..
08.12.2004 20:01 <REP> Help
25.08.2005 17:43 <REP> Kind corn first
25.06.2004 17:16 <REP> Microsoft
01.02.2007 03:12 <REP> Symantec
06.04.2005 21:06 <REP> X10 Commander
0 fichier(s) 0 octets
7 Rép(s) 22'470'500'352 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\LocalService\Local Settings\Application Data
25.06.2004 17:16 <REP> .
25.06.2004 17:16 <REP> ..
08.12.2004 20:01 <REP> Help
25.06.2004 17:16 <REP> Microsoft
0 fichier(s) 0 octets
4 Rép(s) 22'470'500'352 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\Maryline-Tino\Application Data
14.11.2004 14:28 <REP> .
14.11.2004 14:28 <REP> ..
14.11.2004 14:28 <REP> Adobe
14.11.2004 14:28 <REP> AdobeUM
14.11.2004 14:28 <REP> Ahead
25.02.2006 07:07 <REP> Ante book
11.01.2007 04:09 <REP> Apple Computer
12.08.2005 14:12 <REP> Brother
06.07.2005 22:23 <REP> Cakewalk
14.11.2004 14:28 <REP> CyberLink
22.06.2006 14:35 <REP> Cycling '74
17.05.2006 02:10 <REP> FabFilter
05.03.2007 21:44 <REP> Gaijin Ent
22.11.2005 02:00 <REP> GlarySoft
14.11.2004 14:28 <REP> Help
14.11.2004 14:28 <REP> Identities
14.07.2005 19:08 <REP> Lavasoft
12.09.2005 16:33 <REP> Logitech
14.11.2004 14:28 <REP> Macromedia
22.08.2005 15:30 <REP> Media Player Classic
27.09.2005 11:53 <REP> Micro Application
14.11.2004 14:28 <REP> Microsoft
21.11.2006 02:49 <REP> Mopis
04.01.2005 11:00 <REP> Motive
15.06.2006 08:50 <REP> Mozilla
15.11.2004 10:38 <REP> MSN6
09.01.2006 12:07 <REP> MSNInstaller
28.08.2006 03:00 <REP> PACE Anti-Piracy
16.09.2006 17:46 <REP> PlayFirst
25.08.2005 17:39 <REP> Polac
02.09.2005 02:34 <REP> Real
04.10.2005 21:41 <REP> Retro64 Computer Games
11.08.2005 18:30 <REP> ScanSoft
01.02.2006 14:00 <REP> Steinberg
15.06.2006 09:03 <REP> Sun
13.02.2005 15:02 <REP> Symantec
10.01.2005 10:00 <REP> Syntrillium
16.11.2004 15:39 <REP> Template
25.08.2005 22:51 <REP> Trend Micro
28.08.2006 03:00 <REP> Waves Audio
12.10.2006 00:34 <REP> WholeSecurity
04.10.2005 20:48 <REP> Wildfire
08.03.2007 11:18 <REP> Zylom
04.03.2007 14:34 0 .E10FB8D272B730B3.sys
14.11.2004 14:28 62 desktop.ini
07.11.2006 05:37 1'024 WavCodec.wff
3 fichier(s) 1'086 octets
43 Rép(s) 22'470'496'256 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\Maryline-Tino\Local Settings\Application Data
14.11.2004 14:28 <REP> .
14.11.2004 14:28 <REP> ..
14.11.2004 14:28 <REP> Adobe
11.01.2007 04:05 <REP> Apple Computer
14.11.2004 14:28 <REP> ApplicationHistory
16.08.2005 00:26 <REP> Google
14.11.2004 14:28 <REP> Help
21.04.2005 15:16 <REP> Identities
08.03.2007 11:30 <REP> JollyBear
14.11.2004 14:28 <REP> Microsoft
15.06.2006 08:50 <REP> Mozilla
13.09.2005 01:19 <REP> Musicmatch
28.08.2006 03:00 <REP> PACE Anti-Piracy
14.11.2004 14:28 <REP> Powercinema
14.11.2004 14:28 <REP> WMTools Downloaded Files
14.11.2004 14:28 17'920 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
14.11.2004 14:28 136 fusioncache.dat
14.11.2004 14:28 92'792 GDIPFONTCACHEV1.DAT
01.09.2006 05:47 2'116'784 IconCache.db
4 fichier(s) 2'227'632 octets
15 Rép(s) 22'470'496'256 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\NetworkService\Application Data
25.06.2004 17:16 <REP> .
25.06.2004 17:16 <REP> ..
25.06.2004 17:16 <REP> Microsoft
0 fichier(s) 0 octets
3 Rép(s) 22'470'496'256 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\NetworkService\Local Settings\Application Data
25.06.2004 17:16 <REP> .
25.06.2004 17:16 <REP> ..
25.06.2004 17:16 <REP> Microsoft
0 fichier(s) 0 octets
3 Rép(s) 22'470'496'256 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\WINDOWS\system32\config\systemprofile\Application Data
25.06.2004 17:15 <REP> .
25.06.2004 17:15 <REP> ..
14.11.2004 14:27 <REP> Adobe
14.11.2004 14:27 <REP> AdobeUM
14.11.2004 14:27 <REP> Ahead
14.11.2004 14:27 <REP> CyberLink
14.11.2004 14:27 <REP> Help
25.06.2004 17:15 <REP> Identities
14.11.2004 14:27 <REP> Macromedia
25.06.2004 17:15 <REP> Microsoft
25.06.2004 17:15 62 desktop.ini
1 fichier(s) 62 octets
10 Rép(s) 22'470'496'256 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data
25.06.2004 17:15 <REP> .
25.06.2004 17:15 <REP> ..
14.11.2004 14:27 <REP> Adobe
14.11.2004 14:27 <REP> ApplicationHistory
14.11.2004 14:27 <REP> Help
25.06.2004 17:27 <REP> Microsoft
14.11.2004 14:27 <REP> Powercinema
14.11.2004 14:27 <REP> WMTools Downloaded Files
14.11.2004 14:27 3'584 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
14.11.2004 14:27 135 fusioncache.dat
14.11.2004 14:27 55'632 GDIPFONTCACHEV1.DAT
14.11.2004 14:27 4'777'014 IconCache.db
4 fichier(s) 4'836'365 octets
8 Rép(s) 22'470'496'256 octets libres
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks
C:\WINDOWS\Tasks\A6E730379548AEB3.job
s "ˆ!Ö > c : \ d o c u m e ~ 1 \ m a r y l i ~ 1 \ a p p l i c ~ 1 \ k i n d c o ~ 1 \ d e l e t e m e a l p l a t f o r m . e x e M a r y l i n e - T i n o € 0 Í <
******************************************
## Répertoires de C:\Program Files
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Program Files
04.11.2001 09:13 4'608 (key) cakewalk sonar cdkey serial.doc
30.03.2007 13:36 <REP> .
30.03.2007 13:36 <REP> ..
25.11.2004 21:03 <REP> _ArcadeDownloadFolder
07.07.2005 16:17 <REP> 3rd Party MFX
12.09.2006 02:05 <REP> AAMS
14.07.2005 19:06 2'855'080 aawsepersonal.exe
08.04.2006 11:19 <REP> Adobe
25.06.2004 18:48 <REP> Ahead
22.06.2006 14:11 <REP> All That Chords!
04.10.2006 03:43 <REP> Antares
01.06.2006 20:15 <REP> ANWIDA Soft
25.01.2007 00:25 <REP> Apple Software Update
25.08.2005 17:24 <REP> Application Compatibility Toolkit
21.03.2006 05:20 <REP> Arturia
02.06.2006 01:08 <REP> ASIO4ALL v2
30.03.2007 06:02 <REP> a-squared Free
03.08.2005 01:33 <REP> Audio Loops
06.04.2006 02:53 <REP> Avi2Dvd
06.04.2006 02:39 <REP> AviSynth 2.5
06.04.2006 02:06 <REP> AVSMedia
24.08.2006 20:06 <REP> backups
28.12.2006 19:57 <REP> Bluewin
11.08.2005 18:19 <REP> Brother
13.02.2005 14:48 <REP> CA
03.05.2006 20:15 <REP> Cakewalk
30.03.2007 13:36 <REP> CCleaner
25.02.2006 18:52 <REP> Celemony
07.03.2007 08:27 <REP> CleanUp!
27.01.2006 05:31 <REP> CleanUp!(2)
10.06.2006 05:26 <REP> Common Files
25.06.2004 17:13 <REP> ComPlus Applications
15.01.2006 03:07 <REP> Creative
25.06.2004 18:22 <REP> CyberLink
29.03.2007 19:22 <REP> DAEMON Tools
03.05.2006 20:19 <REP> Dasample
28.08.2005 04:39 <REP> dat
22.02.2005 15:43 <REP> DivX
05.05.2005 20:09 24'265'736 dotnetfx.exe
18.11.2005 16:29 <REP> Double Driver
18.03.2007 03:06 <REP> DVD Shrink
21.11.2005 02:54 <REP> Elemental Audio Systems
17.05.2006 02:10 <REP> FabFilter
19.10.2006 03:16 <REP> FC Loader
30.03.2007 12:10 <REP> Fichiers communs
21.09.2005 03:10 <REP> FileZilla
30.11.2006 05:06 <REP> FLStudio4
08.09.2006 02:34 <REP> FX Freeze
27.03.2006 02:06 <REP> FXPANSION
25.06.2004 19:08 <REP> GoBluewin
30.08.2006 18:25 <REP> hardwaredetection
11.01.2007 08:58 <REP> HighMAT CD Writing Wizard
22.11.2004 18:37 174 highscr.qwe
16.02.2005 11:06 218'112 HijackThis.exe
30.03.2007 01:58 12'187 hijackthis.log
02.06.2006 03:00 11'301 hijackthis33
25.06.2004 18:22 <REP> Home Cinema
23.06.2006 02:23 <REP> IK Multimedia
16.08.2005 01:49 <REP> illiminable
26.02.2006 23:52 <REP> IMAGE ISO mode d'emploi
09.12.2006 01:13 <REP> Image-Line2
25.06.2004 17:54 <REP> Intel
29.03.2007 18:14 <REP> Internet Explorer
25.02.2007 04:45 <REP> iZotope
15.06.2006 09:02 <REP> Java
09.09.2006 02:32 <REP> Lavalys
14.07.2005 19:07 <REP> Lavasoft
01.09.2005 00:53 <REP> log de hijack
12.09.2005 16:30 <REP> Logitech
27.02.2006 01:28 <REP> LUXONIX
25.06.2004 19:24 <REP> Make bootable flashcards
08.08.2006 13:34 <REP> M-Audio Firewire Family
10.04.2006 17:47 <REP> Media Player Classic
29.03.2007 19:30 <REP> Messenger
25.06.2004 19:00 <REP> Microsoft Encarta
25.06.2004 17:14 <REP> microsoft frontpage
17.08.2005 14:49 <REP> Microsoft Office
30.06.2005 13:50 <REP> Microsoft Picture It! 9
21.11.2004 16:22 <REP> Microsoft Visual Studio
30.08.2005 11:01 <REP> Microsoft Works
17.08.2005 14:18 <REP> Microsoft.NET
28.12.2006 19:58 <REP> Motive
28.08.2005 16:59 <REP> Movie Maker
30.03.2007 05:14 <REP> Mozilla Firefox
15.07.2006 23:24 <REP> MRU-Blaster
08.06.2005 09:04 <REP> MSN
25.06.2004 17:13 <REP> MSN Gaming Zone
29.03.2007 19:41 <REP> MSN Messenger
06.10.2006 03:21 <REP> MusicLab
13.09.2005 02:36 <REP> MUSICMATCH
07.11.2006 05:34 <REP> NCH Swift Sound
28.08.2005 16:59 <REP> NetMeeting
28.12.2006 04:07 <REP> Netopia
11.12.2006 03:26 <REP> Nomad Factory
29.03.2007 19:41 <REP> Norton Internet Security
17.08.2005 11:44 <REP> OfficeUpdate11
29.12.2004 10:10 <REP> OneClick
06.07.2005 21:29 <REP> Online Docs sonar
05.12.2006 05:46 <REP> Outlook Express
09.12.2005 02:49 <REP> PANDA rapport
31.03.2006 03:46 <REP> PeerCast
29.11.2006 19:26 <REP> Pinnacle
29.11.2006 19:26 <REP> pompage
05.12.2006 05:30 <REP> Propellerhead
17.12.2005 03:35 <REP> PSP PianoVerb
25.01.2007 00:25 <REP> QuickTime
25.08.2006 04:09 <REP> RamBooster 2.0
21.08.2005 06:43 470 Readme.txt
25.11.2004 21:07 <REP> Real
18.08.2006 00:53 <REP> Real Alternative
13.12.2006 04:20 <REP> RegCleaner
22.11.2005 01:58 <REP> Registry Repair
19.03.2006 03:50 <REP> rgcaudio
07.07.2005 16:17 <REP> Sample Content
11.08.2005 18:16 <REP> ScanSoft
25.06.2004 17:13 <REP> Services en ligne
07.11.2006 03:55 <REP> sfArk
20.01.2006 01:54 <REP> SmitfraudFix
19.03.2006 03:52 <REP> SpaceSynthesizer
29.03.2007 18:14 <REP> Spybot - Search & Destroy
15.07.2005 00:26 4'354'084 spybotsd13.exe
14.07.2005 17:44 5'037'072 spybotsd14.exe
25.03.2007 05:46 <REP> SpywareBlaster
26.01.2007 02:55 <REP> Steinberg
19.11.2006 15:15 <REP> Sugar Bytes
24.02.2007 07:30 <REP> Symantec
13.02.2005 15:21 <REP> SymNetDrv
02.03.2007 13:30 <REP> Syncrosoft
18.04.2006 02:58 <REP> Synful
21.11.2004 19:06 <REP> Tap'Touche 3
21.08.2005 20:07 <REP> ToniArts
25.08.2005 22:51 <REP> Trend Micro
12.12.2004 16:30 <REP> Tropico
19.08.2006 17:22 <REP> TrustIn Contextual
05.08.2005 13:27 <REP> TWIXTEL
26.11.2004 14:33 <REP> Ubi Soft
09.03.2005 09:34 <REP> ubi.com
24.02.2006 04:23 <REP> u-he
05.12.2006 13:33 <REP> UltimateSoundBank
25.06.2004 17:58 <REP> USB Wireless Keyboard Driver
22.04.2005 14:51 <REP> UTIL. MUSICAUX
07.07.2005 16:17 <REP> Utilities
16.03.2007 04:54 <REP> VB
26.09.2005 15:15 <REP> Vb_forts
21.03.2006 05:21 <REP> VirSyn Software Synthesizer
24.08.2006 20:08 <REP> Virtools Web Player 3.0
23.03.2005 16:06 <REP> VOB
12.12.2006 19:49 <REP> VstPlugins
13.03.2007 19:50 <REP> Wave Arts
05.12.2006 06:02 <REP> Waves
26.09.2005 14:58 <REP> Web TV
29.03.2007 19:50 <REP> Winamp
25.06.2004 18:35 <REP> Windows Journal Viewer
21.08.2006 00:21 <REP> Windows Media Player
28.08.2005 16:59 <REP> Windows NT
29.03.2007 18:14 <REP> WinRAR
16.08.2005 01:33 <REP> WinRAR 3.0
27.03.2006 01:56 <REP> Wizoo
25.06.2004 17:58 <REP> X10 Hardware
25.06.2004 17:14 <REP> xerox
28.10.2005 09:07 <REP> XP Codec Pack
21.08.2005 06:38 5'667'429 XP Codec Pack 1.2.4.exe
10.03.2007 07:32 <REP> Yahoo!
11.06.2006 23:21 <REP> Zone Labs
11 fichier(s) 42'426'253 octets
153 Rép(s) 22'470'467'584 octets libres
******************************************
## Popups autorisées
* Internet Explorer
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow
zone-media.com REG_SZ
www.zone-media.com REG_SZ
*.zylomgames.com REG_BINARY 00000000
netsearchsoft.com REG_SZ
www.netsearchsoft.com REG_SZ
*.zylom.com REG_BINARY 00000000
adslgo.sso.bluewin.ch REG_BINARY
* Mozilla Firefox (1 autorisé 2 interdit)
---------- C:\DOCUMENTS AND SETTINGS\MARYLINE-TINO\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\SV67YWXI.DEFAULT\HOSTPERM.1
host popup 1 www.pandasoftware.com
host popup 1 www.fruityclub.net
******************************************
## Registre
* [HKEY_CURRENT_USER\\Software\Microsoft\Internet Explorer\Main]
Search Bar REG_SZ http://www.bing.com/spresults.aspx
******************************************
## Zones de sécurité
* HKCU Domains (4)
* P3P History (5)
******************************************
## Recherche C:\WINDOWS\*.htm, "C:\WINDOWS\*.gif"
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\WINDOWS
19.08.2006 17:06 3'214 local.html
1 fichier(s) 3'214 octets
0 Rép(s) 22'470'475'776 octets libres
*************** Fin du rapport ****************
Il y à eu plusieures erreures
Erreur: le systeme n'a pas pus trouver la clef ou la valeur de registre specifié
Erreur: trop de paramètres de ligne de commande
Erreur: trop de paramètres de ligne de commande
Erreur: le système n'a pas pus trouver la clef ou la valeur de registre spécifié
Enfin voila le rapport qui c'est ouvert
Rapport lopxpMH2 version 2.0 fait à 13:50:03.54 le 30.03.2007
C:\Documents and Settings\Maryline-Tino\Bureau
******************************************
## Répertoires Application Data
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\Administrateur\Application Data
06.09.2005 13:48 <REP> .
06.09.2005 13:48 <REP> ..
06.09.2005 13:48 <REP> Adobe
06.09.2005 13:48 <REP> AdobeUM
06.09.2005 13:48 <REP> Ahead
06.09.2005 13:48 <REP> CyberLink
06.09.2005 13:48 <REP> Help
06.09.2005 13:48 <REP> Identities
06.09.2005 13:48 <REP> Macromedia
06.09.2005 13:48 <REP> Microsoft
06.09.2005 13:48 62 desktop.ini
1 fichier(s) 62 octets
10 Rép(s) 22'470'504'448 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\Administrateur\Local Settings\Application Data
06.09.2005 13:48 <REP> .
06.09.2005 13:48 <REP> ..
06.09.2005 13:48 <REP> Adobe
06.09.2005 13:48 <REP> ApplicationHistory
06.09.2005 13:48 <REP> Help
06.09.2005 13:48 <REP> Microsoft
06.09.2005 13:48 <REP> Powercinema
06.09.2005 13:48 <REP> WMTools Downloaded Files
06.09.2005 13:48 3'584 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
06.09.2005 13:48 135 fusioncache.dat
06.09.2005 13:48 55'632 GDIPFONTCACHEV1.DAT
06.09.2005 13:48 4'777'014 IconCache.db
4 fichier(s) 4'836'365 octets
8 Rép(s) 22'470'504'448 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\All Users\Application Data
25.06.2004 18:11 <REP> .
25.06.2004 18:11 <REP> ..
13.02.2007 05:24 <REP> Adobe
25.06.2004 18:46 <REP> Ahead
11.01.2007 04:03 <REP> Apple Computer
11.08.2005 18:15 <REP> Brother
18.03.2007 03:06 <REP> DVD Shrink
25.02.2006 07:07 <REP> Four Once Dash Part
08.03.2007 11:30 <REP> JollyBear
25.06.2004 18:11 <REP> Microsoft
28.12.2006 19:45 <REP> Motive
15.11.2004 10:38 <REP> MSN6
22.08.2005 20:52 <REP> MumboJumbo
14.11.2004 22:14 <REP> nView_Profiles
28.08.2006 03:00 <REP> PACE Anti-Piracy
16.09.2006 17:46 <REP> PlayFirst
24.03.2005 15:18 <REP> QuickTime
31.08.2006 21:18 <REP> Sandlot Games
25.06.2004 17:17 <REP> SBSI
11.08.2005 18:16 <REP> ScanSoft
03.02.2005 15:32 <REP> Spybot - Search & Destroy
13.02.2005 15:01 <REP> Symantec
18.04.2006 02:58 <REP> Synful
04.11.2005 21:44 <REP> Windows Genuine Advantage
10.03.2007 07:32 <REP> Yahoo! Companion
09.06.2006 17:45 <REP> Zylom
25.06.2004 18:11 62 desktop.ini
1 fichier(s) 62 octets
26 Rép(s) 22'470'504'448 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\Default User\Application Data
25.06.2004 18:11 <REP> .
25.06.2004 18:11 <REP> ..
14.11.2004 14:27 <REP> Adobe
14.11.2004 14:27 <REP> AdobeUM
14.11.2004 14:27 <REP> Ahead
14.11.2004 14:27 <REP> CyberLink
14.11.2004 14:27 <REP> Help
25.06.2004 17:14 <REP> Identities
14.11.2004 14:27 <REP> Macromedia
25.06.2004 18:11 <REP> Microsoft
25.06.2004 18:11 62 desktop.ini
1 fichier(s) 62 octets
10 Rép(s) 22'470'500'352 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\Default User\Local Settings\Application Data
25.06.2004 18:11 <REP> .
25.06.2004 18:11 <REP> ..
14.11.2004 14:27 <REP> Adobe
14.11.2004 14:27 <REP> ApplicationHistory
14.11.2004 14:27 <REP> Help
14.11.2004 14:27 <REP> Microsoft
14.11.2004 14:27 <REP> Powercinema
14.11.2004 14:27 <REP> WMTools Downloaded Files
14.11.2004 14:27 3'584 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
14.11.2004 14:27 135 fusioncache.dat
14.11.2004 14:27 55'632 GDIPFONTCACHEV1.DAT
14.11.2004 14:27 4'777'014 IconCache.db
4 fichier(s) 4'836'365 octets
8 Rép(s) 22'470'500'352 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\LocalService\Application Data
25.06.2004 17:16 <REP> .
25.06.2004 17:16 <REP> ..
08.12.2004 20:01 <REP> Help
25.08.2005 17:43 <REP> Kind corn first
25.06.2004 17:16 <REP> Microsoft
01.02.2007 03:12 <REP> Symantec
06.04.2005 21:06 <REP> X10 Commander
0 fichier(s) 0 octets
7 Rép(s) 22'470'500'352 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\LocalService\Local Settings\Application Data
25.06.2004 17:16 <REP> .
25.06.2004 17:16 <REP> ..
08.12.2004 20:01 <REP> Help
25.06.2004 17:16 <REP> Microsoft
0 fichier(s) 0 octets
4 Rép(s) 22'470'500'352 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\Maryline-Tino\Application Data
14.11.2004 14:28 <REP> .
14.11.2004 14:28 <REP> ..
14.11.2004 14:28 <REP> Adobe
14.11.2004 14:28 <REP> AdobeUM
14.11.2004 14:28 <REP> Ahead
25.02.2006 07:07 <REP> Ante book
11.01.2007 04:09 <REP> Apple Computer
12.08.2005 14:12 <REP> Brother
06.07.2005 22:23 <REP> Cakewalk
14.11.2004 14:28 <REP> CyberLink
22.06.2006 14:35 <REP> Cycling '74
17.05.2006 02:10 <REP> FabFilter
05.03.2007 21:44 <REP> Gaijin Ent
22.11.2005 02:00 <REP> GlarySoft
14.11.2004 14:28 <REP> Help
14.11.2004 14:28 <REP> Identities
14.07.2005 19:08 <REP> Lavasoft
12.09.2005 16:33 <REP> Logitech
14.11.2004 14:28 <REP> Macromedia
22.08.2005 15:30 <REP> Media Player Classic
27.09.2005 11:53 <REP> Micro Application
14.11.2004 14:28 <REP> Microsoft
21.11.2006 02:49 <REP> Mopis
04.01.2005 11:00 <REP> Motive
15.06.2006 08:50 <REP> Mozilla
15.11.2004 10:38 <REP> MSN6
09.01.2006 12:07 <REP> MSNInstaller
28.08.2006 03:00 <REP> PACE Anti-Piracy
16.09.2006 17:46 <REP> PlayFirst
25.08.2005 17:39 <REP> Polac
02.09.2005 02:34 <REP> Real
04.10.2005 21:41 <REP> Retro64 Computer Games
11.08.2005 18:30 <REP> ScanSoft
01.02.2006 14:00 <REP> Steinberg
15.06.2006 09:03 <REP> Sun
13.02.2005 15:02 <REP> Symantec
10.01.2005 10:00 <REP> Syntrillium
16.11.2004 15:39 <REP> Template
25.08.2005 22:51 <REP> Trend Micro
28.08.2006 03:00 <REP> Waves Audio
12.10.2006 00:34 <REP> WholeSecurity
04.10.2005 20:48 <REP> Wildfire
08.03.2007 11:18 <REP> Zylom
04.03.2007 14:34 0 .E10FB8D272B730B3.sys
14.11.2004 14:28 62 desktop.ini
07.11.2006 05:37 1'024 WavCodec.wff
3 fichier(s) 1'086 octets
43 Rép(s) 22'470'496'256 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\Maryline-Tino\Local Settings\Application Data
14.11.2004 14:28 <REP> .
14.11.2004 14:28 <REP> ..
14.11.2004 14:28 <REP> Adobe
11.01.2007 04:05 <REP> Apple Computer
14.11.2004 14:28 <REP> ApplicationHistory
16.08.2005 00:26 <REP> Google
14.11.2004 14:28 <REP> Help
21.04.2005 15:16 <REP> Identities
08.03.2007 11:30 <REP> JollyBear
14.11.2004 14:28 <REP> Microsoft
15.06.2006 08:50 <REP> Mozilla
13.09.2005 01:19 <REP> Musicmatch
28.08.2006 03:00 <REP> PACE Anti-Piracy
14.11.2004 14:28 <REP> Powercinema
14.11.2004 14:28 <REP> WMTools Downloaded Files
14.11.2004 14:28 17'920 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
14.11.2004 14:28 136 fusioncache.dat
14.11.2004 14:28 92'792 GDIPFONTCACHEV1.DAT
01.09.2006 05:47 2'116'784 IconCache.db
4 fichier(s) 2'227'632 octets
15 Rép(s) 22'470'496'256 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\NetworkService\Application Data
25.06.2004 17:16 <REP> .
25.06.2004 17:16 <REP> ..
25.06.2004 17:16 <REP> Microsoft
0 fichier(s) 0 octets
3 Rép(s) 22'470'496'256 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Documents and Settings\NetworkService\Local Settings\Application Data
25.06.2004 17:16 <REP> .
25.06.2004 17:16 <REP> ..
25.06.2004 17:16 <REP> Microsoft
0 fichier(s) 0 octets
3 Rép(s) 22'470'496'256 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\WINDOWS\system32\config\systemprofile\Application Data
25.06.2004 17:15 <REP> .
25.06.2004 17:15 <REP> ..
14.11.2004 14:27 <REP> Adobe
14.11.2004 14:27 <REP> AdobeUM
14.11.2004 14:27 <REP> Ahead
14.11.2004 14:27 <REP> CyberLink
14.11.2004 14:27 <REP> Help
25.06.2004 17:15 <REP> Identities
14.11.2004 14:27 <REP> Macromedia
25.06.2004 17:15 <REP> Microsoft
25.06.2004 17:15 62 desktop.ini
1 fichier(s) 62 octets
10 Rép(s) 22'470'496'256 octets libres
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\WINDOWS\system32\config\systemprofile\Local Settings\Application Data
25.06.2004 17:15 <REP> .
25.06.2004 17:15 <REP> ..
14.11.2004 14:27 <REP> Adobe
14.11.2004 14:27 <REP> ApplicationHistory
14.11.2004 14:27 <REP> Help
25.06.2004 17:27 <REP> Microsoft
14.11.2004 14:27 <REP> Powercinema
14.11.2004 14:27 <REP> WMTools Downloaded Files
14.11.2004 14:27 3'584 DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
14.11.2004 14:27 135 fusioncache.dat
14.11.2004 14:27 55'632 GDIPFONTCACHEV1.DAT
14.11.2004 14:27 4'777'014 IconCache.db
4 fichier(s) 4'836'365 octets
8 Rép(s) 22'470'496'256 octets libres
******************************************
Recherche des taches planifiées dans C:\WINDOWS\tasks
C:\WINDOWS\Tasks\A6E730379548AEB3.job
s "ˆ!Ö > c : \ d o c u m e ~ 1 \ m a r y l i ~ 1 \ a p p l i c ~ 1 \ k i n d c o ~ 1 \ d e l e t e m e a l p l a t f o r m . e x e M a r y l i n e - T i n o € 0 Í <
******************************************
## Répertoires de C:\Program Files
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\Program Files
04.11.2001 09:13 4'608 (key) cakewalk sonar cdkey serial.doc
30.03.2007 13:36 <REP> .
30.03.2007 13:36 <REP> ..
25.11.2004 21:03 <REP> _ArcadeDownloadFolder
07.07.2005 16:17 <REP> 3rd Party MFX
12.09.2006 02:05 <REP> AAMS
14.07.2005 19:06 2'855'080 aawsepersonal.exe
08.04.2006 11:19 <REP> Adobe
25.06.2004 18:48 <REP> Ahead
22.06.2006 14:11 <REP> All That Chords!
04.10.2006 03:43 <REP> Antares
01.06.2006 20:15 <REP> ANWIDA Soft
25.01.2007 00:25 <REP> Apple Software Update
25.08.2005 17:24 <REP> Application Compatibility Toolkit
21.03.2006 05:20 <REP> Arturia
02.06.2006 01:08 <REP> ASIO4ALL v2
30.03.2007 06:02 <REP> a-squared Free
03.08.2005 01:33 <REP> Audio Loops
06.04.2006 02:53 <REP> Avi2Dvd
06.04.2006 02:39 <REP> AviSynth 2.5
06.04.2006 02:06 <REP> AVSMedia
24.08.2006 20:06 <REP> backups
28.12.2006 19:57 <REP> Bluewin
11.08.2005 18:19 <REP> Brother
13.02.2005 14:48 <REP> CA
03.05.2006 20:15 <REP> Cakewalk
30.03.2007 13:36 <REP> CCleaner
25.02.2006 18:52 <REP> Celemony
07.03.2007 08:27 <REP> CleanUp!
27.01.2006 05:31 <REP> CleanUp!(2)
10.06.2006 05:26 <REP> Common Files
25.06.2004 17:13 <REP> ComPlus Applications
15.01.2006 03:07 <REP> Creative
25.06.2004 18:22 <REP> CyberLink
29.03.2007 19:22 <REP> DAEMON Tools
03.05.2006 20:19 <REP> Dasample
28.08.2005 04:39 <REP> dat
22.02.2005 15:43 <REP> DivX
05.05.2005 20:09 24'265'736 dotnetfx.exe
18.11.2005 16:29 <REP> Double Driver
18.03.2007 03:06 <REP> DVD Shrink
21.11.2005 02:54 <REP> Elemental Audio Systems
17.05.2006 02:10 <REP> FabFilter
19.10.2006 03:16 <REP> FC Loader
30.03.2007 12:10 <REP> Fichiers communs
21.09.2005 03:10 <REP> FileZilla
30.11.2006 05:06 <REP> FLStudio4
08.09.2006 02:34 <REP> FX Freeze
27.03.2006 02:06 <REP> FXPANSION
25.06.2004 19:08 <REP> GoBluewin
30.08.2006 18:25 <REP> hardwaredetection
11.01.2007 08:58 <REP> HighMAT CD Writing Wizard
22.11.2004 18:37 174 highscr.qwe
16.02.2005 11:06 218'112 HijackThis.exe
30.03.2007 01:58 12'187 hijackthis.log
02.06.2006 03:00 11'301 hijackthis33
25.06.2004 18:22 <REP> Home Cinema
23.06.2006 02:23 <REP> IK Multimedia
16.08.2005 01:49 <REP> illiminable
26.02.2006 23:52 <REP> IMAGE ISO mode d'emploi
09.12.2006 01:13 <REP> Image-Line2
25.06.2004 17:54 <REP> Intel
29.03.2007 18:14 <REP> Internet Explorer
25.02.2007 04:45 <REP> iZotope
15.06.2006 09:02 <REP> Java
09.09.2006 02:32 <REP> Lavalys
14.07.2005 19:07 <REP> Lavasoft
01.09.2005 00:53 <REP> log de hijack
12.09.2005 16:30 <REP> Logitech
27.02.2006 01:28 <REP> LUXONIX
25.06.2004 19:24 <REP> Make bootable flashcards
08.08.2006 13:34 <REP> M-Audio Firewire Family
10.04.2006 17:47 <REP> Media Player Classic
29.03.2007 19:30 <REP> Messenger
25.06.2004 19:00 <REP> Microsoft Encarta
25.06.2004 17:14 <REP> microsoft frontpage
17.08.2005 14:49 <REP> Microsoft Office
30.06.2005 13:50 <REP> Microsoft Picture It! 9
21.11.2004 16:22 <REP> Microsoft Visual Studio
30.08.2005 11:01 <REP> Microsoft Works
17.08.2005 14:18 <REP> Microsoft.NET
28.12.2006 19:58 <REP> Motive
28.08.2005 16:59 <REP> Movie Maker
30.03.2007 05:14 <REP> Mozilla Firefox
15.07.2006 23:24 <REP> MRU-Blaster
08.06.2005 09:04 <REP> MSN
25.06.2004 17:13 <REP> MSN Gaming Zone
29.03.2007 19:41 <REP> MSN Messenger
06.10.2006 03:21 <REP> MusicLab
13.09.2005 02:36 <REP> MUSICMATCH
07.11.2006 05:34 <REP> NCH Swift Sound
28.08.2005 16:59 <REP> NetMeeting
28.12.2006 04:07 <REP> Netopia
11.12.2006 03:26 <REP> Nomad Factory
29.03.2007 19:41 <REP> Norton Internet Security
17.08.2005 11:44 <REP> OfficeUpdate11
29.12.2004 10:10 <REP> OneClick
06.07.2005 21:29 <REP> Online Docs sonar
05.12.2006 05:46 <REP> Outlook Express
09.12.2005 02:49 <REP> PANDA rapport
31.03.2006 03:46 <REP> PeerCast
29.11.2006 19:26 <REP> Pinnacle
29.11.2006 19:26 <REP> pompage
05.12.2006 05:30 <REP> Propellerhead
17.12.2005 03:35 <REP> PSP PianoVerb
25.01.2007 00:25 <REP> QuickTime
25.08.2006 04:09 <REP> RamBooster 2.0
21.08.2005 06:43 470 Readme.txt
25.11.2004 21:07 <REP> Real
18.08.2006 00:53 <REP> Real Alternative
13.12.2006 04:20 <REP> RegCleaner
22.11.2005 01:58 <REP> Registry Repair
19.03.2006 03:50 <REP> rgcaudio
07.07.2005 16:17 <REP> Sample Content
11.08.2005 18:16 <REP> ScanSoft
25.06.2004 17:13 <REP> Services en ligne
07.11.2006 03:55 <REP> sfArk
20.01.2006 01:54 <REP> SmitfraudFix
19.03.2006 03:52 <REP> SpaceSynthesizer
29.03.2007 18:14 <REP> Spybot - Search & Destroy
15.07.2005 00:26 4'354'084 spybotsd13.exe
14.07.2005 17:44 5'037'072 spybotsd14.exe
25.03.2007 05:46 <REP> SpywareBlaster
26.01.2007 02:55 <REP> Steinberg
19.11.2006 15:15 <REP> Sugar Bytes
24.02.2007 07:30 <REP> Symantec
13.02.2005 15:21 <REP> SymNetDrv
02.03.2007 13:30 <REP> Syncrosoft
18.04.2006 02:58 <REP> Synful
21.11.2004 19:06 <REP> Tap'Touche 3
21.08.2005 20:07 <REP> ToniArts
25.08.2005 22:51 <REP> Trend Micro
12.12.2004 16:30 <REP> Tropico
19.08.2006 17:22 <REP> TrustIn Contextual
05.08.2005 13:27 <REP> TWIXTEL
26.11.2004 14:33 <REP> Ubi Soft
09.03.2005 09:34 <REP> ubi.com
24.02.2006 04:23 <REP> u-he
05.12.2006 13:33 <REP> UltimateSoundBank
25.06.2004 17:58 <REP> USB Wireless Keyboard Driver
22.04.2005 14:51 <REP> UTIL. MUSICAUX
07.07.2005 16:17 <REP> Utilities
16.03.2007 04:54 <REP> VB
26.09.2005 15:15 <REP> Vb_forts
21.03.2006 05:21 <REP> VirSyn Software Synthesizer
24.08.2006 20:08 <REP> Virtools Web Player 3.0
23.03.2005 16:06 <REP> VOB
12.12.2006 19:49 <REP> VstPlugins
13.03.2007 19:50 <REP> Wave Arts
05.12.2006 06:02 <REP> Waves
26.09.2005 14:58 <REP> Web TV
29.03.2007 19:50 <REP> Winamp
25.06.2004 18:35 <REP> Windows Journal Viewer
21.08.2006 00:21 <REP> Windows Media Player
28.08.2005 16:59 <REP> Windows NT
29.03.2007 18:14 <REP> WinRAR
16.08.2005 01:33 <REP> WinRAR 3.0
27.03.2006 01:56 <REP> Wizoo
25.06.2004 17:58 <REP> X10 Hardware
25.06.2004 17:14 <REP> xerox
28.10.2005 09:07 <REP> XP Codec Pack
21.08.2005 06:38 5'667'429 XP Codec Pack 1.2.4.exe
10.03.2007 07:32 <REP> Yahoo!
11.06.2006 23:21 <REP> Zone Labs
11 fichier(s) 42'426'253 octets
153 Rép(s) 22'470'467'584 octets libres
******************************************
## Popups autorisées
* Internet Explorer
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow
zone-media.com REG_SZ
www.zone-media.com REG_SZ
*.zylomgames.com REG_BINARY 00000000
netsearchsoft.com REG_SZ
www.netsearchsoft.com REG_SZ
*.zylom.com REG_BINARY 00000000
adslgo.sso.bluewin.ch REG_BINARY
* Mozilla Firefox (1 autorisé 2 interdit)
---------- C:\DOCUMENTS AND SETTINGS\MARYLINE-TINO\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\SV67YWXI.DEFAULT\HOSTPERM.1
host popup 1 www.pandasoftware.com
host popup 1 www.fruityclub.net
******************************************
## Registre
* [HKEY_CURRENT_USER\\Software\Microsoft\Internet Explorer\Main]
Search Bar REG_SZ http://www.bing.com/spresults.aspx
******************************************
## Zones de sécurité
* HKCU Domains (4)
* P3P History (5)
******************************************
## Recherche C:\WINDOWS\*.htm, "C:\WINDOWS\*.gif"
Le volume dans le lecteur C s'appelle BOOT
Le numéro de série du volume est 646C-6A9F
Répertoire de C:\WINDOWS
19.08.2006 17:06 3'214 local.html
1 fichier(s) 3'214 octets
0 Rép(s) 22'470'475'776 octets libres
*************** Fin du rapport ****************
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
papyber
Messages postés
6406
Date d'inscription
samedi 24 mars 2007
Statut
Contributeur sécurité
Dernière intervention
3 octobre 2010
257
30 mars 2007 à 14:08
30 mars 2007 à 14:08
je te prépare la suite
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
30 mars 2007 à 14:23
30 mars 2007 à 14:23
Ok merci pour la disponibilité
papyber
Messages postés
6406
Date d'inscription
samedi 24 mars 2007
Statut
Contributeur sécurité
Dernière intervention
3 octobre 2010
257
30 mars 2007 à 14:25
30 mars 2007 à 14:25
Note comment démarrer en mode sans échec
https://docs.microsoft.com/en-us/?mfr=true
Tu vas t'en servir sans accès à internet.
/ Télécharge : - CCleaner
https://www.pcastuces.com/logitheque/ccleaner.htm
("Download Latest Version", sur la droite).
Ce logiciel va permettre de supprimer tous les fichiers temporaires. Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires". Ensuite, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.
* Crée un nouveau document texte :
clic droit de souris sur le bureau, "Nouveau"> "Document Texte".
Ouvre-le et copie-colle dedans de ce qui est en italique ci-dessous, (copie tout d'un trait) :
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow]
"netsearchsoft.com"=-
"www.netsearchsoft.com"=-
Puis "fichier"/"enregistrer sous" :
dans : sur le bureau
Nom du fichier : reglop.reg
Type de fichier : "tous les fichiers"
clique sur "enregistrer"
*****Copie ce qui suit dans un fichier texte et redémarre en mode sans échec (choisis ta session habituelle, pas le compte "Administrateur" ou autre)*****
/ Assure toi d'avoir accès aux dossiers/fichiers cachés :
Ouvrir un dossier, n'importe lequel. Aller dans :
Outils/Options des dossiers/Affichage et
- cocher "afficher les dossiers et fichiers cachés",
- décocher "masquer les extensions des fichiers dont le type est connu".
- décocher masquer les fichiers protégés du système d'exploitation (recommandé)"
"appliquer" et "ok"
recherche et supprime ces dossiers ou fichiers en gras, si tu les trouves :
C:\Documents and Settings\All Users\Application Data\Four Once Dash Part
C:\Documents and Settings\Maryline-Tino\Application Data \Ante book
\Documents and Settings\LocalService\Application Data \Kind corn first
recache tes dossiers et fichiers en effectuant la manoeuvre inverse
/ démarrer/exécuter, tape cmd et valide par entrée. Colle la ligne suivante dans la fenêtre noire qui s'ouvre :
del /a C:\WINDOWS\Tasks\A6E730379548AEB3.job
valide par entrée, puis ferme la fenêtre de commande.
/ double clique sur reglop.reg => tu dois obligatoirement avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
Si c'est bien le cas, clique sur "oui"
/ Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
*Redémarre normalement et poste un nouveau rapport GenProc, toutes fenêtres et applications fermées. Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
https://docs.microsoft.com/en-us/?mfr=true
Tu vas t'en servir sans accès à internet.
/ Télécharge : - CCleaner
https://www.pcastuces.com/logitheque/ccleaner.htm
("Download Latest Version", sur la droite).
Ce logiciel va permettre de supprimer tous les fichiers temporaires. Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires". Ensuite, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.
* Crée un nouveau document texte :
clic droit de souris sur le bureau, "Nouveau"> "Document Texte".
Ouvre-le et copie-colle dedans de ce qui est en italique ci-dessous, (copie tout d'un trait) :
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\New Windows\Allow]
"netsearchsoft.com"=-
"www.netsearchsoft.com"=-
Puis "fichier"/"enregistrer sous" :
dans : sur le bureau
Nom du fichier : reglop.reg
Type de fichier : "tous les fichiers"
clique sur "enregistrer"
*****Copie ce qui suit dans un fichier texte et redémarre en mode sans échec (choisis ta session habituelle, pas le compte "Administrateur" ou autre)*****
/ Assure toi d'avoir accès aux dossiers/fichiers cachés :
Ouvrir un dossier, n'importe lequel. Aller dans :
Outils/Options des dossiers/Affichage et
- cocher "afficher les dossiers et fichiers cachés",
- décocher "masquer les extensions des fichiers dont le type est connu".
- décocher masquer les fichiers protégés du système d'exploitation (recommandé)"
"appliquer" et "ok"
recherche et supprime ces dossiers ou fichiers en gras, si tu les trouves :
C:\Documents and Settings\All Users\Application Data\Four Once Dash Part
C:\Documents and Settings\Maryline-Tino\Application Data \Ante book
\Documents and Settings\LocalService\Application Data \Kind corn first
recache tes dossiers et fichiers en effectuant la manoeuvre inverse
/ démarrer/exécuter, tape cmd et valide par entrée. Colle la ligne suivante dans la fenêtre noire qui s'ouvre :
del /a C:\WINDOWS\Tasks\A6E730379548AEB3.job
valide par entrée, puis ferme la fenêtre de commande.
/ double clique sur reglop.reg => tu dois obligatoirement avoir un message "voulez-vous vraiment ajouter les informations contenues dans ce fichier .reg au registre ?"
Si c'est bien le cas, clique sur "oui"
/ Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
*Redémarre normalement et poste un nouveau rapport GenProc, toutes fenêtres et applications fermées. Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
30 mars 2007 à 16:03
30 mars 2007 à 16:03
re salut
te colle ce que norton trouve et à la suite le rapport GenProc
merci pour la patience
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8W464QM9\srvpqr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8W464QM9\srvpqr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\TA8KDFGE\srvrou[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\TA8KDFGE\srvrou[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\TA8KDFGE\srvlpa[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\TA8KDFGE\srvlpa[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GTSLYNQ3\srvsin[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GTSLYNQ3\srvsin[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvpkb[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvpkb[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvkyo[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvkyo[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srviny[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srviny[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\SLU3CTUN\srvhku[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\SLU3CTUN\srvhku[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvitr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvitr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvxbk[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvxbk[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvtcs[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvtcs[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvadf[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvadf[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\srvdxy[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\srvdxy[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CZXNDH1S\srvigu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CZXNDH1S\srvigu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CZXNDH1S\srvtby[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CZXNDH1S\srvtby[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvryr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvryr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvlvz[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvlvz[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvdzu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvdzu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CZXNDH1S\srvchy[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CZXNDH1S\srvchy[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvahl[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvahl[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvmww[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvmww[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvqxq[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvqxq[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\SLU3CTUN\srvkpi[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\SLU3CTUN\srvkpi[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\xc29[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\xc29[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\xc23[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\xc23[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvulu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvulu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvupx[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvupx[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\srvjdx[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\srvjdx[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvolq[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvolq[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvhsv[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvhsv[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvkjo[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvkjo[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvbxr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvbxr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvjnu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvjnu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvfgw[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvfgw[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvnsl[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvnsl[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvtie[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvtie[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvlce[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvlce[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\srvwhs[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\srvwhs[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvedk[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvedk[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvdvn[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvdvn[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvzpl[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvzpl[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvwrb[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvwrb[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvidb[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvidb[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvfvo[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvfvo[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\xc29[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\xc29[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\xc23[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\xc23[1].exe
Catégorie de menace : Risque lié à la sécuritéSource :delQueue.exe,Description :Le fichier compressé delQueue.exe dans ????? dans C:\WINDOWS\Downloaded Installations\{942D18AE-8E70-447B-9A24-9A4FC91E16C5}\SpyBouncer.msi est une menace Risque lié à la sécurité.
Catégorie de menace : Risque lié à la sécuritéSource :delmod.dll,Description :Le fichier compressé delmod.dll dans ????? dans C:\WINDOWS\Downloaded Installations\{942D18AE-8E70-447B-9A24-9A4FC91E16C5}\SpyBouncer.msi est une menace Risque lié à la sécurité.
Source :C:\WINDOWS\url.exe
Source :C:\WINDOWS\url.exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WPAZ09ER\url[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WPAZ09ER\url[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ZF64KSI0\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ZF64KSI0\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ZF64KSI0\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ZF64KSI0\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\UHN2RIRE\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\UHN2RIRE\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\89UFC5AZ\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\89UFC5AZ\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\N3PHISZC\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\N3PHISZC\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\N3PHISZC\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\4XY7KDQN\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\4XY7KDQN\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\4XY7KDQN\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\N3PHISZC\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\N3PHISZC\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\N3PHISZC\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\4XY7KDQN\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\4XY7KDQN\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\4XY7KDQN\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\b-trs12a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\b-trs12a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\b-trs12a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ELUF50QP\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ELUF50QP\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ELUF50QP\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ELUF50QP\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ELUF50QP\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ELUF50QP\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\7JTK2L9M\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\7JTK2L9M\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\7JTK2L9M\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\KHIVCHA7\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\KHIVCHA7\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\KHIVCHA7\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\S5QBSPA3\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\S5QBSPA3\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\S5QBSPA3\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ONM3K1M5\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ONM3K1M5\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ONM3K1M5\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ONM3K1M5\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ONM3K1M5\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ONM3K1M5\free[1].anr
Source :C:\DOCUME~1\MARYLI~1\LOCALS~1\Temp\AAWTMP\C10450046\25F92C\crack-inf.exe
Source :C:\DOCUME~1\MARYLI~1\LOCALS~1\Temp\AAWTMP\C10450046\25F92C\crack-inf.exe
Source :C:\DOCUME~1\MARYLI~1\LOCALS~1\Temp\AAWTMP\C10450046\25F92C\crack-inf.exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U1WF4ZC1\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U1WF4ZC1\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U1WF4ZC1\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WXYZODQR\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WXYZODQR\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WXYZODQR\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U1WF4ZC1\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U1WF4ZC1\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U1WF4ZC1\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WXYZODQR\nc[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WXYZODQR\nc[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WXYZODQR\nc[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\C1234H6V\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\C1234H6V\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\C1234H6V\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H0JKL45F\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H0JKL45F\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H0JKL45F\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GZRJ2C4N\nc[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GZRJ2C4N\nc[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GZRJ2C4N\nc[1].anr
Catégorie de menace : Logiciel publicitaireSource :C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe,Description :Le fichier C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe est une menace Logiciel publicitaire.
Catégorie de menace : Logiciel publicitaireSource :C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe,Description :Le fichier C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe est une menace Logiciel publicitaire.
Catégorie de menace : Logiciel publicitaireSource :C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe,Description :Le fichier C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe est une menace Logiciel publicitaire.
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LAK0SZUM\loaderadv698[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LAK0SZUM\loaderadv698[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LAK0SZUM\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LAK0SZUM\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LAK0SZUM\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\O123S5IV\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\O123S5IV\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\O123S5IV\sploit[1].anr
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LP5UZB59\loaderadv698[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LP5UZB59\loaderadv698[1].jar
Catégorie de menace : Logiciel publicitaireSource :C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe,Description :Le fichier C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe est une menace Logiciel publicitaire.
Catégorie de menace : Logiciel publicitaireSource :C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe,Description :Le fichier C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe est une menace Logiciel publicitaire.
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[5].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[5].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[5].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[5].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[5].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[5].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\loaderadv698[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\loaderadv698[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\IXPRDJGF\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\IXPRDJGF\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\IXPRDJGF\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I1KL4N67\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I1KL4N67\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I1KL4N67\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\KA0UA0P0\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\KA0UA0P0\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\KA0UA0P0\sploit[1].anr
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\A9UB01QB\loaderadv698[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\A9UB01QB\loaderadv698[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I1KL4N67\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I1KL4N67\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I1KL4N67\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\VerifierBug[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\VerifierBug[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\VerifierBug[1].class
Source :Installer.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\classload[1].jar
Source :Dummy.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\classload[1].jar
Source :InsecureClassLoader.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\classload[1].jar
Source :GetAccess.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\classload[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\3HR7EGDO\Dummy[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\3HR7EGDO\Dummy[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\3HR7EGDO\Dummy[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CFU9C5C2\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CFU9C5C2\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CFU9C5C2\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\3HR7EGDO\ass[1].html
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\3HR7EGDO\ass[1].html
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\3HR7EGDO\ass[1].html
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\US09Y897\ass[1].html
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\US09Y897\ass[1].html
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\US09Y897\ass[1].html
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CDYRS16V\loaderadv698[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CDYRS16V\loaderadv698[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8LI3KTM7\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8LI3KTM7\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8LI3KTM7\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I7KXM56V\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I7KXM56V\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I7KXM56V\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\loaderadv698[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\loaderadv698[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\loaderadv661[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\loaderadv661[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8LI3KTM7\adv661[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8LI3KTM7\adv661[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8LI3KTM7\adv661[1].htm
Catégorie de menace : Logiciel publicitaireSource :C:\Documents and Settings\Maryline-Tino\Local Settings\Temp\qohfuyhb.ood,Description :Le fichier C:\Documents and Settings\Maryline-Tino\Local Settings\Temp\qohfuyhb.ood est une menace Logiciel publicitaire.
Source :C:\Mes téléchargements\Silent Runners.vbs
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E70MLXFI\Silent%20Runners[1].vbs
Catégorie de menace : Logiciel publicitaireSource :C:\Program Files\NewDotNet\newdotnet6_38.dll,Description :Le fichier C:\Program Files\NewDotNet\newdotnet6_38.dll est une menace Logiciel publicitaire.
**************************************************
VOILA LE RAP. GENPROC:
Rapport GenProc 0.32 effectué le 30.03.2007 à 15:33:22.00 - SystemRoot = C:\WINDOWS
# Etape 1/ Télécharge :
- SmitfrauFix de S!Ri: Moe et Balltrap34 http://siri.urz.free.fr/Fix/SmitfraudFix.exe
* double-clique sur le fichier "smitfraudfix.exe" et choisis l’option 1, il va lister tous les éléments nuisibles dans un rapport : poste le maintenant.
***** Copie ce qui suit dans un fichier texte et redémarre en mode sans échec comme indiqué ici https://docs.microsoft.com/en-us/?mfr=true (choisis ta session courante "Maryline-Tino") *****
# Etape 2/
Double-clique sur le fichier "SmitfraudFix.exe" et choisis l’option 2, réponds oui à tout et laisse-le procéder. Sauvegarde le rapport sur ton bureau.
# Etape 3/
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
# Etape 4/
Redémarre normalement et poste :
- Un nouveau rapport HijackThis, toutes fenêtres et applications fermées si tu ne l'as pas tu trouveras HijackThis ici http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis_v2.exe ;
- Le rapport SmitfraudFix que tu as sauvegardé sur ton bureau ;
Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
te colle ce que norton trouve et à la suite le rapport GenProc
merci pour la patience
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8W464QM9\srvpqr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8W464QM9\srvpqr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\TA8KDFGE\srvrou[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\TA8KDFGE\srvrou[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\TA8KDFGE\srvlpa[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\TA8KDFGE\srvlpa[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GTSLYNQ3\srvsin[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GTSLYNQ3\srvsin[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvpkb[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvpkb[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvkyo[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvkyo[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srviny[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srviny[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\SLU3CTUN\srvhku[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\SLU3CTUN\srvhku[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvitr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvitr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvxbk[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvxbk[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvtcs[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvtcs[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvadf[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvadf[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\srvdxy[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\srvdxy[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CZXNDH1S\srvigu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CZXNDH1S\srvigu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CZXNDH1S\srvtby[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CZXNDH1S\srvtby[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvryr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvryr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvlvz[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvlvz[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvdzu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvdzu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CZXNDH1S\srvchy[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CZXNDH1S\srvchy[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvahl[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvahl[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvmww[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvmww[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvqxq[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvqxq[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\SLU3CTUN\srvkpi[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\SLU3CTUN\srvkpi[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\xc29[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\xc29[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\xc23[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\xc23[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvulu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvulu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvupx[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvupx[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\srvjdx[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\srvjdx[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvolq[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvolq[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvhsv[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvhsv[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvkjo[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvkjo[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvbxr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U7O189G9\srvbxr[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvjnu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvjnu[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvfgw[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvfgw[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvnsl[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvnsl[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvtie[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvtie[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvlce[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvlce[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\srvwhs[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E5DEBU5C\srvwhs[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvedk[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvedk[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvdvn[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GHIJKLMN\srvdvn[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvzpl[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvzpl[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvwrb[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\srvwrb[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvidb[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\NQ0RNT0H\srvidb[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvfvo[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\srvfvo[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\xc29[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\01S70NWZ\xc29[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\xc23[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\HBVBPXKA\xc23[1].exe
Catégorie de menace : Risque lié à la sécuritéSource :delQueue.exe,Description :Le fichier compressé delQueue.exe dans ????? dans C:\WINDOWS\Downloaded Installations\{942D18AE-8E70-447B-9A24-9A4FC91E16C5}\SpyBouncer.msi est une menace Risque lié à la sécurité.
Catégorie de menace : Risque lié à la sécuritéSource :delmod.dll,Description :Le fichier compressé delmod.dll dans ????? dans C:\WINDOWS\Downloaded Installations\{942D18AE-8E70-447B-9A24-9A4FC91E16C5}\SpyBouncer.msi est une menace Risque lié à la sécurité.
Source :C:\WINDOWS\url.exe
Source :C:\WINDOWS\url.exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WPAZ09ER\url[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WPAZ09ER\url[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ZF64KSI0\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ZF64KSI0\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ZF64KSI0\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ZF64KSI0\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\UHN2RIRE\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\UHN2RIRE\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\89UFC5AZ\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\89UFC5AZ\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\N3PHISZC\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\N3PHISZC\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\N3PHISZC\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\4XY7KDQN\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\4XY7KDQN\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\4XY7KDQN\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\N3PHISZC\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\N3PHISZC\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\N3PHISZC\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\4XY7KDQN\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\4XY7KDQN\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\4XY7KDQN\h-sm201a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\b-trs12a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\b-trs12a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\b-trs12a[1].exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\XNMTTDT0\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ELUF50QP\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ELUF50QP\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ELUF50QP\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ELUF50QP\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ELUF50QP\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ELUF50QP\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\7JTK2L9M\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\7JTK2L9M\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\7JTK2L9M\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\KHIVCHA7\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\KHIVCHA7\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\KHIVCHA7\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\S5QBSPA3\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\S5QBSPA3\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\S5QBSPA3\ie0604[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ONM3K1M5\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ONM3K1M5\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ONM3K1M5\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ONM3K1M5\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ONM3K1M5\free[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\ONM3K1M5\free[1].anr
Source :C:\DOCUME~1\MARYLI~1\LOCALS~1\Temp\AAWTMP\C10450046\25F92C\crack-inf.exe
Source :C:\DOCUME~1\MARYLI~1\LOCALS~1\Temp\AAWTMP\C10450046\25F92C\crack-inf.exe
Source :C:\DOCUME~1\MARYLI~1\LOCALS~1\Temp\AAWTMP\C10450046\25F92C\crack-inf.exe
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U1WF4ZC1\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U1WF4ZC1\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U1WF4ZC1\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WXYZODQR\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WXYZODQR\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WXYZODQR\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U1WF4ZC1\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U1WF4ZC1\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\U1WF4ZC1\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WXYZODQR\nc[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WXYZODQR\nc[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\WXYZODQR\nc[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\C1234H6V\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\C1234H6V\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\C1234H6V\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H0JKL45F\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H0JKL45F\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H0JKL45F\zl[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GZRJ2C4N\nc[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GZRJ2C4N\nc[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\GZRJ2C4N\nc[1].anr
Catégorie de menace : Logiciel publicitaireSource :C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe,Description :Le fichier C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe est une menace Logiciel publicitaire.
Catégorie de menace : Logiciel publicitaireSource :C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe,Description :Le fichier C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe est une menace Logiciel publicitaire.
Catégorie de menace : Logiciel publicitaireSource :C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe,Description :Le fichier C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe est une menace Logiciel publicitaire.
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LAK0SZUM\loaderadv698[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LAK0SZUM\loaderadv698[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LAK0SZUM\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LAK0SZUM\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LAK0SZUM\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\O123S5IV\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\O123S5IV\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\O123S5IV\sploit[1].anr
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LP5UZB59\loaderadv698[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\LP5UZB59\loaderadv698[1].jar
Catégorie de menace : Logiciel publicitaireSource :C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe,Description :Le fichier C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe est une menace Logiciel publicitaire.
Catégorie de menace : Logiciel publicitaireSource :C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe,Description :Le fichier C:\Program Files\EA GAMES\Battlefield 1942\fpupdate.exe est une menace Logiciel publicitaire.
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[5].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[5].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[5].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[5].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[5].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[5].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[4].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[3].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[2].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\sploit[1].anr
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\loaderadv698[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8ZG7SNCJ\loaderadv698[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\OA894QC4\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\IXPRDJGF\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\IXPRDJGF\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\IXPRDJGF\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I1KL4N67\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I1KL4N67\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I1KL4N67\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\KA0UA0P0\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\KA0UA0P0\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\KA0UA0P0\sploit[1].anr
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\A9UB01QB\loaderadv698[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\A9UB01QB\loaderadv698[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I1KL4N67\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I1KL4N67\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I1KL4N67\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\VerifierBug[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\VerifierBug[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\VerifierBug[1].class
Source :Installer.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\classload[1].jar
Source :Dummy.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\classload[1].jar
Source :InsecureClassLoader.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\classload[1].jar
Source :GetAccess.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\H4THKAKH\classload[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\3HR7EGDO\Dummy[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\3HR7EGDO\Dummy[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\3HR7EGDO\Dummy[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CFU9C5C2\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CFU9C5C2\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CFU9C5C2\BlackBox[1].class
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\3HR7EGDO\ass[1].html
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\3HR7EGDO\ass[1].html
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\3HR7EGDO\ass[1].html
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\US09Y897\ass[1].html
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\US09Y897\ass[1].html
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\US09Y897\ass[1].html
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CDYRS16V\loaderadv698[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\CDYRS16V\loaderadv698[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8LI3KTM7\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8LI3KTM7\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8LI3KTM7\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I7KXM56V\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I7KXM56V\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\I7KXM56V\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\loaderadv698[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\loaderadv698[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :Parser.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\loaderadv661[1].jar
Source :Counter.class,Description :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\loaderadv661[1].jar
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8PQ74T6R\sploit[1].anr
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8LI3KTM7\adv661[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8LI3KTM7\adv661[1].htm
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\8LI3KTM7\adv661[1].htm
Catégorie de menace : Logiciel publicitaireSource :C:\Documents and Settings\Maryline-Tino\Local Settings\Temp\qohfuyhb.ood,Description :Le fichier C:\Documents and Settings\Maryline-Tino\Local Settings\Temp\qohfuyhb.ood est une menace Logiciel publicitaire.
Source :C:\Mes téléchargements\Silent Runners.vbs
Source :C:\Documents and Settings\Maryline-Tino\Local Settings\Temporary Internet Files\Content.IE5\E70MLXFI\Silent%20Runners[1].vbs
Catégorie de menace : Logiciel publicitaireSource :C:\Program Files\NewDotNet\newdotnet6_38.dll,Description :Le fichier C:\Program Files\NewDotNet\newdotnet6_38.dll est une menace Logiciel publicitaire.
**************************************************
VOILA LE RAP. GENPROC:
Rapport GenProc 0.32 effectué le 30.03.2007 à 15:33:22.00 - SystemRoot = C:\WINDOWS
# Etape 1/ Télécharge :
- SmitfrauFix de S!Ri: Moe et Balltrap34 http://siri.urz.free.fr/Fix/SmitfraudFix.exe
* double-clique sur le fichier "smitfraudfix.exe" et choisis l’option 1, il va lister tous les éléments nuisibles dans un rapport : poste le maintenant.
***** Copie ce qui suit dans un fichier texte et redémarre en mode sans échec comme indiqué ici https://docs.microsoft.com/en-us/?mfr=true (choisis ta session courante "Maryline-Tino") *****
# Etape 2/
Double-clique sur le fichier "SmitfraudFix.exe" et choisis l’option 2, réponds oui à tout et laisse-le procéder. Sauvegarde le rapport sur ton bureau.
# Etape 3/
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
# Etape 4/
Redémarre normalement et poste :
- Un nouveau rapport HijackThis, toutes fenêtres et applications fermées si tu ne l'as pas tu trouveras HijackThis ici http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis_v2.exe ;
- Le rapport SmitfraudFix que tu as sauvegardé sur ton bureau ;
Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
papyber
Messages postés
6406
Date d'inscription
samedi 24 mars 2007
Statut
Contributeur sécurité
Dernière intervention
3 octobre 2010
257
30 mars 2007 à 16:11
30 mars 2007 à 16:11
as tu fait ce que je t'ai demandé? car si tu avais passé ccleaner tous ces fichiers "temp" et "internet emporary" seraient disparus..
donc
1/ Télécharge : - CCleaner
https://www.pcastuces.com/logitheque/ccleaner.htm
("Download Latest Version", sur la droite).
Ce logiciel va permettre de supprimer tous les fichiers temporaires. Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires". Ensuite, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.
2/ tu fais très exactement ce que te demande GenProc
et tu me postes les rapports demandés
donc
1/ Télécharge : - CCleaner
https://www.pcastuces.com/logitheque/ccleaner.htm
("Download Latest Version", sur la droite).
Ce logiciel va permettre de supprimer tous les fichiers temporaires. Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires". Ensuite, Clique sur "Options", "Avancé" et décoche la case "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.
2/ tu fais très exactement ce que te demande GenProc
et tu me postes les rapports demandés
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
30 mars 2007 à 16:28
30 mars 2007 à 16:28
salut
oui c'est déjà fait avec cc-cleaner en mode sans échec et en mode normal
ce que j'ai posté c'est le journal des alertes de norton désolé
voici le rapport SmidFraudfix:
SmitFraudFix v2.161
Rapport fait à 16:22:54.67, 30.03.2007
Executé à partir de C:\Mes t‚l‚chargements\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\CNYHKey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\WINDOWS\System32\MAFWTray.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\QuickHelpAlert.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Bluewin\Quick Help\bin\mpbtn.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NSMdtr.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Messenger\msmsgs.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
Fichier hosts corrompu !
127.0.0.1 www.legal-at-spybot.info
127.0.0.1 legal-at-spybot.info
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
C:\WINDOWS\ads.js PRESENT !
C:\WINDOWS\local.html PRESENT !
C:\WINDOWS\onlineshopping.ico PRESENT !
C:\WINDOWS\removeadware.ico PRESENT !
C:\WINDOWS\sexpersonals.ico PRESENT !
C:\WINDOWS\videoslots.ico PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Maryline-Tino
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Maryline-Tino\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
C:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url PRESENT !
C:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MARYLI~1\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
C:\Program Files\TrustIn Contextual\ PRESENT !
C:\Program Files\vb\ PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="https://photojournal.jpl.nasa.gov/jpeg/PIA06257.jpg"
"SubscribedURL"="https://photojournal.jpl.nasa.gov/jpeg/PIA06257.jpg"
"FriendlyName"=""
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: VIA VT6105 Rhine III Fast Ethernet Adapter
DNS Server Search Order: 192.168.1.1
Description: VIA VT6105 Rhine III Fast Ethernet Adapter
DNS Server Search Order: 192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{378E37A0-BB36-491C-8DD7-455D17DFA114}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{4CCF018C-46A8-44AC-ADDD-9F30C7F613AA}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{5FB4A896-D660-42B8-A3B3-A3627EA0481D}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{378E37A0-BB36-491C-8DD7-455D17DFA114}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{4CCF018C-46A8-44AC-ADDD-9F30C7F613AA}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{5FB4A896-D660-42B8-A3B3-A3627EA0481D}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{378E37A0-BB36-491C-8DD7-455D17DFA114}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{4CCF018C-46A8-44AC-ADDD-9F30C7F613AA}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{5FB4A896-D660-42B8-A3B3-A3627EA0481D}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»
oui c'est déjà fait avec cc-cleaner en mode sans échec et en mode normal
ce que j'ai posté c'est le journal des alertes de norton désolé
voici le rapport SmidFraudfix:
SmitFraudFix v2.161
Rapport fait à 16:22:54.67, 30.03.2007
Executé à partir de C:\Mes t‚l‚chargements\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode normal
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\CNYHKey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\WINDOWS\System32\MAFWTray.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\QuickHelpAlert.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Bluewin\Quick Help\bin\mpbtn.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NSMdtr.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Messenger\msmsgs.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
Fichier hosts corrompu !
127.0.0.1 www.legal-at-spybot.info
127.0.0.1 legal-at-spybot.info
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
C:\WINDOWS\ads.js PRESENT !
C:\WINDOWS\local.html PRESENT !
C:\WINDOWS\onlineshopping.ico PRESENT !
C:\WINDOWS\removeadware.ico PRESENT !
C:\WINDOWS\sexpersonals.ico PRESENT !
C:\WINDOWS\videoslots.ico PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Maryline-Tino
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Maryline-Tino\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer
C:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url PRESENT !
C:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MARYLI~1\Favoris
»»»»»»»»»»»»»»»»»»»»»»»» Bureau
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
C:\Program Files\TrustIn Contextual\ PRESENT !
C:\Program Files\vb\ PRESENT !
»»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues
»»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="https://photojournal.jpl.nasa.gov/jpeg/PIA06257.jpg"
"SubscribedURL"="https://photojournal.jpl.nasa.gov/jpeg/PIA06257.jpg"
"FriendlyName"=""
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32
»»»»»»»»»»»»»»»»»»»»»»»» DNS
Description: VIA VT6105 Rhine III Fast Ethernet Adapter
DNS Server Search Order: 192.168.1.1
Description: VIA VT6105 Rhine III Fast Ethernet Adapter
DNS Server Search Order: 192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{378E37A0-BB36-491C-8DD7-455D17DFA114}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{4CCF018C-46A8-44AC-ADDD-9F30C7F613AA}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\..\{5FB4A896-D660-42B8-A3B3-A3627EA0481D}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{378E37A0-BB36-491C-8DD7-455D17DFA114}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{4CCF018C-46A8-44AC-ADDD-9F30C7F613AA}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{5FB4A896-D660-42B8-A3B3-A3627EA0481D}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{378E37A0-BB36-491C-8DD7-455D17DFA114}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{4CCF018C-46A8-44AC-ADDD-9F30C7F613AA}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{5FB4A896-D660-42B8-A3B3-A3627EA0481D}:
DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
»»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll
»»»»»
papyber
Messages postés
6406
Date d'inscription
samedi 24 mars 2007
Statut
Contributeur sécurité
Dernière intervention
3 octobre 2010
257
30 mars 2007 à 16:34
30 mars 2007 à 16:34
fais l'option 2 maintenant
Double-clique sur le fichier "SmitfraudFix.exe" et choisis l’option 2, réponds oui à tout et laisse-le procéder. Sauvegarde le rapport sur ton bureau.
# Etape 3/
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
# Etape 4/
Redémarre normalement et poste :
- Un nouveau rapport HijackThis, toutes fenêtres et applications fermées si tu ne l'as pas tu trouveras HijackThis ici http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis_v2.exe ;
- Le rapport SmitfraudFix que tu as sauvegardé sur ton bureau ;
Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
Double-clique sur le fichier "SmitfraudFix.exe" et choisis l’option 2, réponds oui à tout et laisse-le procéder. Sauvegarde le rapport sur ton bureau.
# Etape 3/
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
# Etape 4/
Redémarre normalement et poste :
- Un nouveau rapport HijackThis, toutes fenêtres et applications fermées si tu ne l'as pas tu trouveras HijackThis ici http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis_v2.exe ;
- Le rapport SmitfraudFix que tu as sauvegardé sur ton bureau ;
Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
30 mars 2007 à 19:20
30 mars 2007 à 19:20
Salut
désolé pour la petite pause
j'ai fait ce que tu m'à dit
Toujours des alertes de Norton
voilà le rapport Hijackthis:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 19:18:09, on 30.03.2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\CNYHKey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\WINDOWS\System32\MAFWTray.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\QuickHelpAlert.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Bluewin\Quick Help\bin\mpbtn.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {19F22822-0116-413F-B7F1-66A6F9F7C50E} - C:\WINDOWS\System32\awvvt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
O2 - BHO: (no name) - {904CCFDB-F34A-4A0A-8B09-B2F33A4FBF05} - C:\WINDOWS\System32\awttuvu.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\System32\MAFWTray.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [PSDrvCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\QuickHelpAlert.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quick Help.lnk = C:\Program Files\Bluewin\Quick Help\bin\matcli.exe
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.interdiscount.ch/webapp/wcs/stores/servlet/StoreCatalogDisplay?langId=3&storeId=10001&catalogId=10001
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://www.zonealarm.com/
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://charon777.free.fr/plugins/hardwaredetection.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) - http://acs.pandasoftware.com/activescanpro/as5/asproinst.cab
O20 - Winlogon Notify: awttuvu - C:\WINDOWS\SYSTEM32\awttuvu.dll
O20 - Winlogon Notify: awvvt - C:\WINDOWS\System32\awvvt.dll
O20 - Winlogon Notify: winjyg32 - C:\WINDOWS\SYSTEM32\winjyg32.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe (file missing)
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Philips Semiconductors - (no file)
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Philips Semiconductors - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: DDE réseau (NetDDE) - Unknown owner - C:\WINDOWS\system32\netdde.exe
O23 - Service: DSDM DDE réseau (NetDDEdsdm) - Unknown owner - C:\WINDOWS\system32\netdde.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
désolé pour la petite pause
j'ai fait ce que tu m'à dit
Toujours des alertes de Norton
voilà le rapport Hijackthis:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 19:18:09, on 30.03.2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\CNYHKey.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\WINDOWS\System32\MAFWTray.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\QuickHelpAlert.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Bluewin\Quick Help\bin\mpbtn.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {19F22822-0116-413F-B7F1-66A6F9F7C50E} - C:\WINDOWS\System32\awvvt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
O2 - BHO: (no name) - {904CCFDB-F34A-4A0A-8B09-B2F33A4FBF05} - C:\WINDOWS\System32\awttuvu.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\System32\MAFWTray.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [PSDrvCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\QuickHelpAlert.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quick Help.lnk = C:\Program Files\Bluewin\Quick Help\bin\matcli.exe
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.interdiscount.ch/webapp/wcs/stores/servlet/StoreCatalogDisplay?langId=3&storeId=10001&catalogId=10001
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://www.zonealarm.com/
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://charon777.free.fr/plugins/hardwaredetection.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) - http://acs.pandasoftware.com/activescanpro/as5/asproinst.cab
O20 - Winlogon Notify: awttuvu - C:\WINDOWS\SYSTEM32\awttuvu.dll
O20 - Winlogon Notify: awvvt - C:\WINDOWS\System32\awvvt.dll
O20 - Winlogon Notify: winjyg32 - C:\WINDOWS\SYSTEM32\winjyg32.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe (file missing)
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Philips Semiconductors - (no file)
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Philips Semiconductors - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: DDE réseau (NetDDE) - Unknown owner - C:\WINDOWS\system32\netdde.exe
O23 - Service: DSDM DDE réseau (NetDDEdsdm) - Unknown owner - C:\WINDOWS\system32\netdde.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
30 mars 2007 à 19:26
30 mars 2007 à 19:26
Précision:
les alertes sont du genre Trojan Horse srvfgw[1].exe ou
srvzau[1].exe ou srv...[1].exe ect. ect.
Merci pour la patience
les alertes sont du genre Trojan Horse srvfgw[1].exe ou
srvzau[1].exe ou srv...[1].exe ect. ect.
Merci pour la patience
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
30 mars 2007 à 19:29
30 mars 2007 à 19:29
pardo j'avais oublié voilà aussi
le rapport smidfraudfix:
SmitFraudFix v2.161
Rapport fait à 19:00:50.20, 30.03.2007
Executé à partir de C:\Mes t‚l‚chargements\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode sans echec
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 babe.the-killer.bz
127.0.0.1 www.babe.the-killer.bz
127.0.0.1 babe.k-lined.com
127.0.0.1 www.babe.k-lined.com
127.0.0.1 did.i-used.cc
127.0.0.1 www.did.i-used.cc
127.0.0.1 coolwwwsearch.com
127.0.0.1 www.coolwwwsearch.com
127.0.0.1 coolwebsearch.com
127.0.0.1 www.coolwebsearch.com
127.0.0.1 hi.studioaperto.net
127.0.0.1 www.hi.studioaperto.net
127.0.0.1 webbrowser.tv
127.0.0.1 www.webbrowser.tv
127.0.0.1 wazzupnet.com
127.0.0.1 www.wazzupnet.com
127.0.0.1 gueb.com
127.0.0.1 www.gueb.com
127.0.0.1 kabex.com
127.0.0.1 www.kabex.com
127.0.0.1 hityou.com
127.0.0.1 www.hityou.com
127.0.0.1 miosearch.com
127.0.0.1 www.miosearch.com
127.0.0.1 213.131.225.2
127.0.0.1 blue-elefant.com
127.0.0.1 www.blue-elefant.com
127.0.0.1 babeweb.de
127.0.0.1 www.babeweb.de
127.0.0.1 start-seite.com
127.0.0.1 www.start-seite.com
127.0.0.1 sexolymp.com
127.0.0.1 www.sexolymp.com
127.0.0.1 toriii.cc
127.0.0.1 www.toriii.cc
127.0.0.1 xtipp.de
127.0.0.1 www.xtipp.de
127.0.0.1 urawa.cool.ne.jp
127.0.0.1 777search.com
127.0.0.1 www.777search.com
127.0.0.1 ace-webmaster.com
127.0.0.1 www.ace-webmaster.com
127.0.0.1 aifind.info
127.0.0.1 www.aifind.info
127.0.0.1 amateurliveshow.com
127.0.0.1 www.amateurliveshow.com
127.0.0.1 anarchylolita.com
127.0.0.1 www.anarchylolita.com
127.0.0.1 anarchyporn.com
127.0.0.1 approvedlinks.com
127.0.0.1 www.approvedlinks.com
127.0.0.1 cantfind.com
127.0.0.1 www.cantfind.com
127.0.0.1 castingsamateur.com
127.0.0.1 www.castingsamateur.com
127.0.0.1 cyberrape.com
127.0.0.1 www.cyberrape.com
127.0.0.1 dialerclub.com
127.0.0.1 www.dialerclub.com
127.0.0.1 megago.com
127.0.0.1 exit.megago.com
127.0.0.1 www.megago.com
127.0.0.1 fastmetasearch.com
127.0.0.1 www.fastmetasearch.com
127.0.0.1 findwhatevernow.com
127.0.0.1 www.findwhatevernow.com
127.0.0.1 globesearch.com
127.0.0.1 www.globesearch.com
127.0.0.1 hotfreebies.com
127.0.0.1 www.hotfreebies.com
127.0.0.1 krankin.com
127.0.0.1 www.krankin.com
127.0.0.1 begin2search.com
127.0.0.1 www.begin2search.com
127.0.0.1 mainstreamdollars.com
127.0.0.1 www.mainstreamdollars.com
127.0.0.1 live.sex-explorer.com
127.0.0.1 www.live.sex-explorer.com
127.0.0.1 loveadot.com
127.0.0.1 www.loveadot.com
127.0.0.1 megaseek.net
127.0.0.1 www.megaseek.net
127.0.0.1 mixsearch.com
127.0.0.1 www.mixsearch.com
127.0.0.1 munky.com
127.0.0.1 www.munky.com
127.0.0.1 newtopsites.com
127.0.0.1 www.newtopsites.com
127.0.0.1 noblindlinks.com
127.0.0.1 www.noblindlinks.com
127.0.0.1 babenet.com
127.0.0.1 r.babenet.com
127.0.0.1 www.babenet.com
127.0.0.1 searchresult.net
127.0.0.1 www.searchresult.net
127.0.0.1 sexarena.org
127.0.0.1 www.sexarena.org
127.0.0.1 skeech.com
127.0.0.1 www.skeech.com
127.0.0.1 by.ru
127.0.0.1 www.by.ru
127.0.0.1 superwp.by.ru
127.0.0.1 sureseeker.com
127.0.0.1 www.sureseeker.com
127.0.0.1 wethere.com
127.0.0.1 www.wethere.com
127.0.0.1 wowsearch.org
127.0.0.1 www.wowsearch.org
127.0.0.1 xxx.com
127.0.0.1 www.xxx.com
127.0.0.1 art-xxx.com
127.0.0.1 websearch.com
127.0.0.1 www.websearch.com
127.0.0.1 firehunt.com
127.0.0.1 www.firehunt.com
127.0.0.1 partner23.firehunt.com
127.0.0.1 screensaver.it
127.0.0.1 www.screensaver.it
127.0.0.1 cliks.org
127.0.0.1 www.cliks.org
127.0.0.1 xads.cliks.org
127.0.0.1 xwebsearch.biz
127.0.0.1 www.xwebsearch.biz
127.0.0.1 znext.com
127.0.0.1 www.znext.com
127.0.0.1 rawtocash.net
127.0.0.1 www.rawtocash.net
127.0.0.1 7search.com
127.0.0.1 www.7search.com
127.0.0.1 zestyfind.com
127.0.0.1 www.zestyfind.com
127.0.0.1 ntcor.com
127.0.0.1 www.ntcor.com
127.0.0.1 dev.ntcor.com
127.0.0.1 xrenoder.com
127.0.0.1 www.xrenoder.com
127.0.0.1 search.xrenoder.com
127.0.0.1 193.125.201.50
127.0.0.1 allcybersearch.com
127.0.0.1 www.allcybersearch.com
127.0.0.1 tinybar.com
127.0.0.1 www.tinybar.com
127.0.0.1 topsite.us
127.0.0.1 www.topsite.us
127.0.0.1 topsites.us
127.0.0.1 www.topsites.us
127.0.0.1 topsitez.us
127.0.0.1 www.topsitez.us
127.0.0.1 true-counter.com
127.0.0.1 www.true-counter.com
127.0.0.1 out.true-counter.com
127.0.0.1 cnetadd.com
127.0.0.1 www.cnetadd.com
127.0.0.1 okmmm.com
127.0.0.1 www.okmmm.com
127.0.0.1 139mm.com
127.0.0.1 www.139mm.com
127.0.0.1 008k.com
127.0.0.1 www.008k.com
127.0.0.1 00hq.com
127.0.0.1 www.00hq.com
127.0.0.1 1-domains-registrations.com
127.0.0.1 www.1-domains-registrations.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 157.238.62.14
127.0.0.1 1sexparty.com
127.0.0.1 www.1sexparty.com
127.0.0.1 1stpagehere.com
127.0.0.1 www.1stpagehere.com
127.0.0.1 2020search.com
127.0.0.1 www.2020search.com
127.0.0.1 209.66.114.130
127.0.0.1 24teen.com
127.0.0.1 www.24teen.com
127.0.0.1 36site.com
127.0.0.1 www.36site.com
127.0.0.1 4corn.net
127.0.0.1 www.4corn.net
127.0.0.1 66.117.14.138
127.0.0.1 66.197.100.83
127.0.0.1 66.250.107.99
127.0.0.1 66.250.107.100
127.0.0.1 66.250.107.101
127.0.0.1 66.250.130.194
127.0.0.1 66.250.170.107
127.0.0.1 66.250.57.26
127.0.0.1 66.250.57.27
127.0.0.1 66.250.57.28
127.0.0.1 66.250.74.150
127.0.0.1 777top.com
127.0.0.1 www.777top.com
127.0.0.1 8ad.com
127.0.0.1 www.8ad.com
127.0.0.1 aboutclicker.com
127.0.0.1 www.aboutclicker.com
127.0.0.1 abrp.net
127.0.0.1 www.abrp.net
127.0.0.1 accessthefuture.net
127.0.0.1 www.accessthefuture.net
127.0.0.1 acemedic.com
127.0.0.1 www.acemedic.com
127.0.0.1 actionbreastcancer.org
127.0.0.1 www.actionbreastcancer.org
127.0.0.1 activexupdate.com
127.0.0.1 www.activexupdate.com
127.0.0.1 adamsupportgroup.org
127.0.0.1 www.adamsupportgroup.org
127.0.0.1 adasearch.com
127.0.0.1 www.adasearch.com
127.0.0.1 adipics.com
127.0.0.1 www.adipics.com
127.0.0.1 adspics.com
127.0.0.1 www.adspics.com
127.0.0.1 adult-engine-search.com
127.0.0.1 www.adult-engine-search.com
127.0.0.1 adult-erotic-guide.net
127.0.0.1 www.adult-erotic-guide.net
127.0.0.1 adult-friends-finder.net
127.0.0.1 www.adult-friends-finder.net
127.0.0.1 adulthyperlinks.com
127.0.0.1 www.adulthyperlinks.com
127.0.0.1 adulttds.com
127.0.0.1 www.adulttds.com
127.0.0.1 exaccess.ru
127.0.0.1 www.exaccess.ru
127.0.0.1 advert.exaccess.ru
127.0.0.1 agentstudio.com
127.0.0.1 africaspromise.org
127.0.0.1 akril.com
127.0.0.1 alcatel.ws
127.0.0.1 alfa-search.com
127.0.0.1 all-inet.com
127.0.0.1 allabtcars.com
127.0.0.1 allabtjeeps.com
127.0.0.1 allhyperlinks.com
127.0.0.1 allinternetbusiness.com
127.0.0.1 almarvideos.com
127.0.0.1 amandamountains.com
127.0.0.1 amigeek.com
127.0.0.1 amisbusiness.com
127.0.0.1 analmovi.com
127.0.0.1 anin.org
127.0.0.1 annaromeo.com
127.0.0.1 antrocity.com
127.0.0.1 anything4health.com
127.0.0.1 apsua.com
127.0.0.1 aregay.com
127.0.0.1 arheo.com
127.0.0.1 arizonaweb.org
127.0.0.1 armitageinn.com
127.0.0.1 art-func.com
127.0.0.1 artachnid.com
127.0.0.1 asiankingkong.com
127.0.0.1 ass-gals.com
127.0.0.1 athenrye.com
127.0.0.1 avian-ads.com
127.0.0.1 ayakawamura.com
127.0.0.1 ayumitaniguchi.com
127.0.0.1 bannedhost.net
127.0.0.1 barbudafarms.com
127.0.0.1 barnandfence.com
127.0.0.1 batsearch.com
127.0.0.1 baygraphicsllc.com
127.0.0.1 bb-search.com
127.0.0.1 bbbsearch.com
127.0.0.1 bedhome.com
127.0.0.1 bediadance.com
127.0.0.1 bellabasketsfl.com
127.0.0.1 bernaolatwin.com
127.0.0.1 best-counter.com
127.0.0.1 best-hardpics.com
127.0.0.1 best-winning-casino.com
127.0.0.1 bestcrawler.com
127.0.0.1 bestfor.ru
127.0.0.1 bestporngate.com
127.0.0.1 bestxporno.com
127.0.0.1 blackjack-free.net
127.0.0.1 blender.xu.pl
127.0.0.1 bodaciousbabette.com
127.0.0.1 boobdoll.com
127.0.0.1 boobsandtits.com
127.0.0.1 boobsclub.com
127.0.0.1 boredlife.com
127.0.0.1 bowlofogumbo.com
127.0.0.1 bradcoem.org
127.0.0.1 brandiyoung.com
127.0.0.1 brookeburn.com
127.0.0.1 bucps.com
127.0.0.1 burgerkingbigscreen.com
127.0.0.1 buscards.net
127.0.0.1 bustyrussell.com
127.0.0.1 buttejazz.org
127.0.0.1 buyselldomain.net
127.0.0.1 calcioturris.com
127.0.0.1 canberracricketcoaching.com
127.0.0.1 candycantaloupes.com
127.0.0.1 careers.dulcineasystems.net
127.0.0.1 carsands.com
127.0.0.1 carsrentals.net
127.0.0.1 casino-gambling-1.net
127.0.0.1 casino-gambling-2.net
127.0.0.1 casino-onlines.net
127.0.0.1 casino.com.free.game.pogo.gratisdownloads.nl
127.0.0.1 casino2win.net
127.0.0.1 casinomidas.net
127.0.0.1 casinonline.net
127.0.0.1 catallogue.com
127.0.0.1 catsss.da.ru
127.0.0.1 caxa.ru
127.0.0.1 cclebali.org
127.0.0.1 ceewawires.org
127.0.0.1 certumgroup.com
127.0.0.1 chelancatering.com
127.0.0.1 childrenvilla.com
127.0.0.1 chips-4-free.com
127.0.0.1 chrisswasey.com
127.0.0.1 chriswallace.net
127.0.0.1 ckick4thumbs.com
127.0.0.1 clackamasliteraryreview.com
127.0.0.1 clearsearch.cc
127.0.0.1 clearsearch.net
127.0.0.1 clickaire.com
127.0.0.1 clickyestoenter.net
127.0.0.1 clrsch.com
127.0.0.1 cmtapestry.com
127.0.0.1 cool-homepage.co
127.0.0.1 cool-homepage.com
127.0.0.1 cool-search.net
127.0.0.1 cool-search.netfartpost.com
127.0.0.1 cool-web-search.com
127.0.0.1 coolfetishsite.com
127.0.0.1 coolfreehost.com
127.0.0.1 coolfreepage.com
127.0.0.1 coolfreepages.com
127.0.0.1 coolmoneysearch.com
127.0.0.1 coolpornsearch.com
127.0.0.1 coolsearcher.info
127.0.0.1 coolwebsearsh.com
127.0.0.1 copmtraine.com
127.0.0.1 couldnotfind.com
127.0.0.1 count-all.com
127.0.0.1 cracks.me.uk
127.0.0.1 creamedcutties.com
127.0.0.1 creditsearchonline.com
127.0.0.1 crestring.com
127.0.0.1 crooder.com
127.0.0.1 curvedspaces.com
127.0.0.1 cvs.jps.ru
127.0.0.1 cvsymphony.com
127.0.0.1 cydom.com
127.0.0.1 daily-gals.com
127.0.0.1 dancingbabycd.com
127.0.0.1 datanotary.com
127.0.0.1 datareco.com
127.0.0.1 davemarshall.org
127.0.0.1 dcfitusa.com
127.0.0.1 defaultsearch.net
127.0.0.1 desarrollocreativo.com
127.0.0.1 develip.com
127.0.0.1 dewis.spb.ru
127.0.0.1 dewis.us
127.0.0.1 df809jow4wj2304lfd0sf9fsd0a2t4ldf809jow4wj2304lfd0sf9fsd0a2t4ld.biz
127.0.0.1 dietpills4free.com
127.0.0.1 dietpussy.com
127.0.0.1 digistreamsa.com
127.0.0.1 dionforvalleycouncil.org
127.0.0.1 doctorwaldron.com
127.0.0.1 document-not-found.pornpic.org
127.0.0.1 doggyaction.com
127.0.0.1 domain-your-registration.com
127.0.0.1 domains-for-you-online.com
127.0.0.1 domains2003.net
127.0.0.1 domkrat.com
127.0.0.1 dp-host.com
127.0.0.1 dragqueen.gay-clan.com
127.0.0.1 drug-sources-exposed.com
127.0.0.1 drvvv.com
127.0.0.1 dutch-sex.com
127.0.0.1 dvdbank.org
127.0.0.1 e-localad.com
127.0.0.1 e-plus.cc
127.0.0.1 e-websitesolutions.com
127.0.0.1 eases.net
127.0.0.1 easy-search.net
127.0.0.1 easycategories.com
127.0.0.1 ecosrioplatenses.org
127.0.0.1 ecstasyporn.net
127.0.0.1 eikokoike.com
127.0.0.1 epornsex.com
127.0.0.1 euuu.com
127.0.0.1 evidence-detector.biz
127.0.0.1 evilspidercomics.com
127.0.0.1 ewebsearch.net
127.0.0.1 findloss.com
127.0.0.1 excellentsckin.com
127.0.0.1 extremeseek.net
127.0.0.1 f*ckdenniss.com
127.0.0.1 f*cknicepics.com
127.0.0.1 faithstevens.com
127.0.0.1 fantasiewelten.com
127.0.0.1 farmsteadbandb.com
127.0.0.1 fartpost.com
127.0.0.1 fastwebfinder.com
127.0.0.1 faxporn.com
127.0.0.1 fickenisgeil.de
127.0.0.1 finance-loans.com
127.0.0.1 find-itnow.com
127.0.0.1 find-uk-health.co.uk
127.0.0.1 find4u.net
127.0.0.1 findit-now.com
127.0.0.1 findthesite.com
127.0.0.1 findthewebsiteyouneed.com
127.0.0.1 www.findthewebsiteyouneed.com
127.0.0.1 fionasteel.com
127.0.0.1 firstbookmark.net
127.0.0.1 fitness-free.com
127.0.0.1 foodvacations.net
127.0.0.1 forex.jps.ru
127.0.0.1 forexcredit.com
127.0.0.1 forexcredit.ru
127.0.0.1 formingfusions.com
127.0.0.1 forsythfire.net
127.0.0.1 forthline.com
127.0.0.1 free-chipes.com
127.0.0.1 free-f*cking-video.com
127.0.0.1 free-hit.com
127.0.0.1 free-pics-and-movies.com
127.0.0.1 free-sex-movie-clips.net
127.0.0.1 free4porno.net
127.0.0.1 free64all.com
127.0.0.1 freebookmark.net
127.0.0.1 freebookmarks.net
127.0.0.1 freecategories.com
127.0.0.1 freecoolhost.com
127.0.0.1 freerbhost.com
127.0.0.1 freeshemalepics.net
127.0.0.1 freeyaho.com
127.0.0.1 freshseek.com
127.0.0.1 freshteensite.com
127.0.0.1 gabrielscott.com
127.0.0.1 galpostgirls.com
127.0.0.1 gals-for-free.com
127.0.0.1 gambling-online4you.com
127.0.0.1 gameterror.net
127.0.0.1 gay50.com
127.0.0.1 generalsmeltingofcanada.com
127.0.0.1 geteens.com
127.0.0.1 getpicshere.com
127.0.0.1 gimmezamore.com
127.0.0.1 gimnasiaer.com
127.0.0.1 girls-porn-life.com
127.0.0.1 glbdf.org
127.0.0.1 global-finder.com
127.0.0.1 globe-finder.cc
127.0.0.1 globe-finder.com
127.0.0.1 gocybersearch.com
127.0.0.1 golftennis.net
127.0.0.1 good-mortgages-calculator.com
127.0.0.1 good-mortgages.net
127.0.0.1 goodsexs.com
127.0.0.1 googlebar.jps.ru
127.0.0.1 googlf.com
127.0.0.1 gradforum.org
127.0.0.1 gratis-porn-movie.com
127.0.0.1 gratis-pornopics.com
127.0.0.1 guzzycats.com
127.0.0.1 gzphoenix.com
127.0.0.1 hallnetaccolade.com
127.0.0.1 hand-book.com
127.0.0.1 happyanal.com
127.0.0.1 hard-gals.com
127.0.0.1 hardbodytgp.com
127.0.0.1 hardcoreover.com
127.0.0.1 hardloved.com
127.0.0.1 hardwareseek.net
127.0.0.1 harukaigawa.com
127.0.0.1 hccsolanonapa.org
127.0.0.1 health-protein.com
127.0.0.1 hentai4u.net
127.0.0.1 here4search.com
127.0.0.1 heyrichy.com
127.0.0.1 hi-search.com
127.0.0.1 hiddenguides.com
127.0.0.1 hitlistlyrics.com
127.0.0.1 holidayautostr.com
127.0.0.1 homemortage.ws
127.0.0.1 hostssp.com
127.0.0.1 hot-cartoon-sex.anime.american-teens.net
127.0.0.1 hotbookmark.com
127.0.0.1 hotels-list.net
127.0.0.1 hotelxxxcams.com
127.0.0.1 hotpopup.com
127.0.0.1 hotsearchbox.com
127.0.0.1 hotsex-series.com
127.0.0.1 hotstartpage.com
127.0.0.1 hqsex.biz
127.0.0.1 hugeporn4u.net
127.0.0.1 hunacsa.com
127.0.0.1 hupacasath.com
127.0.0.1 hzsx.com
127.0.0.1 icansearch.net
127.0.0.1 idgsearch.com
127.0.0.1 ie-search.com
127.0.0.1 incestporngate.com
127.0.0.1 infodigger.net
127.0.0.1 infoglobus.com
127.0.0.1 inherhole.com
127.0.0.1 insertthiscock.com
127.0.0.1 insurance-flood.net
127.0.0.1 insuranceall.net
127.0.0.1 internetsearch.ru
127.0.0.1 ionichost.com
127.0.0.1 ionomist.com
127.0.0.1 ipsex.net
127.0.0.1 itsanal.com
127.0.0.1 itseasy.us
127.0.0.1 iweb-commerce.com
127.0.0.1 iwebland.com
127.0.0.1 jeannineoldfield.com
127.0.0.1 jethomepage.com
127.0.0.1 jetseeker.com
127.0.0.1 jmhgallery.org
127.0.0.1 joannelatham.com
127.0.0.1 judin.ru
127.0.0.1 junkysex.com
127.0.0.1 karleyt.narod.ru
127.0.0.1 kathisomers.com
127.0.0.1 kazaa-lite.ws
127.0.0.1 keithgreenpro.com
127.0.0.1 kenmccaul.com
127.0.0.1 kilosex.com
127.0.0.1 kimhines.com
127.0.0.1 kinoru.com
127.0.0.1 ksdspups.org
127.0.0.1 landrape.com
127.0.0.1 lauraroebuck.com
127.0.0.1 leannalovelace.com
127.0.0.1 lesobank.ru
127.0.0.1 libertyonlinehosting.com
127.0.0.1 lingerie-mania.com
127.0.0.1 lisamatthew.com
127.0.0.1 liveholio.com
127.0.0.1 livenewspaper.com
127.0.0.1 louiseleeds.com
127.0.0.1 love-pix.com
127.0.0.1 lovelas.com
127.0.0.1 lovelysearch.com
127.0.0.1 low-taxes.com
127.0.0.1 luckysearch.net
127.0.0.1 lunitaweb.net
127.0.0.1 lustful-porno.com
127.0.0.1 mackinnonsbrook.org
127.0.0.1 madfinder.com
127.0.0.1 madisonmoons.com
127.0.0.1 madisonoilco.com
127.0.0.1 madonalive.com
127.0.0.1 majuozawa.com
127.0.0.1 makin-do.com
127.0.0.1 male4free.com
127.0.0.1 map-quest.org
127.0.0.1 marilynchamber.com
127.0.0.1 martfinder.com
127.0.0.1 massearch.com
127.0.0.1 matetrava.com
127.0.0.1 mature50.com
127.0.0.1 matureporngate.com
127.0.0.1 maxdzines.com
127.0.0.1 mcgeeforlabor.com
127.0.0.1 mdstunisie.org
127.0.0.1 medicare-insurance.net
127.0.0.1 medicare-supplemental.com
127.0.0.1 mega-dating-tips.com
127.0.0.1 megumikanzaki.com
127.0.0.1 meshalynn.com
127.0.0.1 meta-adult.com
127.0.0.1 meta-casino.com
127.0.0.1 meta-mobile.com
127.0.0.1 meta-porn.com
127.0.0.1 metafora.ru
127.0.0.1 metapoisk.ru
127.0.0.1 michiyonakajima.com
127.0.0.1 miconsultamedica.com
127.0.0.1 mikasakamoto.com
127.0.0.1 mikoni.com
127.0.0.1 militarygods.porn4porn.net
127.0.0.1 millennialpeople.org
127.0.0.1 mipham.org
127.0.0.1 missingcommand.com
127.0.0.1 mommykiss.com
127.0.0.1 moneyhunters.com
127.0.0.1 montgomeryhospitalanesthesia.com
127.0.0.1 morflot.com
127.0.0.1 mortgage-debt.net
127.0.0.1 mortismaximus.com
127.0.0.1 moscowwhores.com
127.0.0.1 moviecategories.com
127.0.0.1 mp3-pix.com
127.0.0.1 mrtg.jps.ru
127.0.0.1 msn-info.net
127.0.0.1 multipussy.com
127.0.0.1 mundopolar.com
127.0.0.1 mustv.com
127.0.0.1 mywebsearch.net
127.0.0.1 nativehardcore.com
127.0.0.1 naturalspy.com
127.0.0.1 nbasportsbook.net
127.0.0.1 needf*cknow.com
127.0.0.1 nellyslyrics.com
127.0.0.1 nepgyan.com
127.0.0.1 nesrecords.com
127.0.0.1 netshastra.net
127.0.0.1 nettime.ru
127.0.0.1 nettracker.jps.ru
127.0.0.1 netyellowpages.info
127.0.0.1 new-incest.com
127.0.0.1 newcategories.com
127.0.0.1 newcracks.com
127.0.0.1 newcracks.net
127.0.0.1 newlife-lajolla.com
127.0.0.1 newsexgate.com
127.0.0.1 newtonsracks.com
127.0.0.1 newxpics.com
127.0.0.1 nhlsportsbook.net
127.0.0.1 niagaracapital.com
127.0.0.1 niche-tv.com
127.0.0.1 nmrba.com
127.0.0.1 nocalories.net
127.0.0.1 nocensor.com
127.0.0.1 ormandcompany.com
127.0.0.1 nsbabes.com
127.0.0.1 nuclearwitness.org
127.0.0.1 nursemania.com
127.0.0.1 nvntour.com
127.0.0.1 nvphall.org
127.0.0.1 oborot.com
127.0.0.1 ocalalivestockmarket.com
127.0.0.1 ocsff.com
127.0.0.1 oeatlanta.com
127.0.0.1 oharrowsearch.com
127.0.0.1 ok-search.com
127.0.0.1 okulta.com
127.0.0.1 omegabrains.net
127.0.0.1 online-casino-1.net
127.0.0.1 online-casino-bonus.info
127.0.0.1 online-casinos-x.com
127.0.0.1 online-winning.net
127.0.0.1 onlineserverz.com
127.0.0.1 onlinetradings.net
127.0.0.1 onlycunt.com
127.0.0.1 onlyinsured.com
127.0.0.1 operanabuco.com
127.0.0.1 opsex.com
127.0.0.1 oregoncharters.org
127.0.0.1 otrlives.com
127.0.0.1 ozawamadoka.com
127.0.0.1 paigesummer.com
127.0.0.1 pamelacollections.com
127.0.0.1 panamcup.com
127.0.0.1 pantygirls4u.com
127.0.0.1 pantyhoserealm.com
127.0.0.1 pantyplace.com
127.0.0.1 pastubes.com
127.0.0.1 paulapage.com
127.0.0.1 paulhoover.com
127.0.0.1 payfortraffic.net
127.0.0.1 pedo.ws
127.0.0.1 people.1gb.ru
127.0.0.1 pervertbot.com
127.0.0.1 pharma-diet-pills.com
127.0.0.1 pharmacy2003.com
127.0.0.1 pharmalocator.com
127.0.0.1 phendimetrazine-tenuate-adipex.com
127.0.0.1 pics-videos.com
127.0.0.1 picsdir.com
127.0.0.1 picsforbucks.com
127.0.0.1 picsofseductiveladies.com
127.0.0.1 pills-birth-control.com
127.0.0.1 pillsmall.com
127.0.0.1 pilotronix.com
127.0.0.1 pixpox.com
127.0.0.1 planemusic.com
127.0.0.1 poiska.net
127.0.0.1 poker-casino-free.com
127.0.0.1 poker-games-free.net
127.0.0.1 polradiologia.com
127.0.0.1 pooi.net
127.0.0.1 porn-teacher.com
127.0.0.1 porncamz.com
127.0.0.1 pornfree.info
127.0.0.1 pornnightdreams.com
127.0.0.1 pornokopec.com
127.0.0.1 porntetris.com
127.0.0.1 porntwist.com
127.0.0.1 powerwebsearch.com
127.0.0.1 prblitz.com
127.0.0.1 pretypics.com
127.0.0.1 pribalt.com
127.0.0.1 privacy-support.biz
127.0.0.1 privateporn.net
127.0.0.1 prostactive.com
127.0.0.1 prostol.com
127.0.0.1 protect-yourself.biz
127.0.0.1 prsainlandempire.org
127.0.0.1 put-your-link-here.com
127.0.0.1 pyrocorp.com
127.0.0.1 quick-search.ws
127.0.0.1 quiksearchgenealogy.com
127.0.0.1 radfrall.org
127.0.0.1 ramgo.com
127.0.0.1 ranafrog.ne
127.0.0.1 rapegate.com
127.0.0.1 redbudbmx.com
127.0.0.1 refinance-help.com
127.0.0.1 removeearthkeepers.org
127.0.0.1 rightfinder.net
127.0.0.1 robbsproshop.com
127.0.0.1 robertferencz.com
127.0.0.1 rotocasters.com
127.0.0.1 royalsearch.net
127.0.0.1 runsearch.com
127.0.0.1 russiansponsor.com
127.0.0.1 russogay.com
127.0.0.1 s2.exocrew.com
127.0.0.1 sacitylife.com
127.0.0.1 samplegals.com
127.0.0.1 satisf*cktion.net
127.0.0.1 sbssurvivor.com
127.0.0.1 scarypix.com
127.0.0.1 sccdnet.com
127.0.0.1 schoolforest.com
127.0.0.1 search-1.net
127.0.0.1 search-2003.com
127.0.0.1 search-about.net
127.0.0.1 search-hawk.com
127.0.0.1 search-log.com
127.0.0.1 search-meta.com
127.0.0.1 search-safe.com
127.0.0.1 search.psn.cn
127.0.0.1 searchadultweb.com
127.0.0.1 searchbutler.com
127.0.0.1 searchbuttler.com
127.0.0.1 searchbutler.org
127.0.0.1 searchcomplete.com
127.0.0.1 searchdesire.com
127.0.0.1 searchdot.net
127.0.0.1 searchexpander.com
127.0.0.1 searchfastnet.com
127.0.0.1 searchforge.com
127.0.0.1 searching-the-net.com
127.0.0.1 searchmeta.md
127.0.0.1 searchmeta.net
127.0.0.1 searchmeta.ru
127.0.0.1 searchmeta.webhost.ru
127.0.0.1 searchnow.ws
127.0.0.1 searchonfly.com
127.0.0.1 searchv.com
127.0.0.1 searchxl.com
127.0.0.1 searchxp.com
127.0.0.1 sebot.com
127.0.0.1 securenp.org
127.0.0.1 security-warning.biz
127.0.0.1 seehardcore.com
127.0.0.1 seekwell.net
127.0.0.1 selfbookmark.com
127.0.0.1 selfbookmark.info
127.0.0.1 selfbookmark.net
127.0.0.1 sex.free4porno.net
127.0.0.1 sex-coach.com
127.0.0.1 sex-festival.com
127.0.0.1 sex-video-galleries.com
127.0.0.1 sexgalleries4all.com
127.0.0.1 sexmoviesnet.com
127.0.0.1 sexpatriot.net
127.0.0.1 sexy18.cc
127.0.0.1 sexycat.adult-host.org
127.0.0.1 sfbayfolkboats.com
127.0.0.1 sgirls.net
127.0.0.1 sharempeg.com
127.0.0.1 shopcards.net
127.0.0.1 shopknights.com
127.0.0.1 sic02.com
127.0.0.1 sintrader.com
127.0.0.1 site1.ru
127.0.0.1 sites-in-web.com
127.0.0.1 sitevictoria.com
127.0.0.1 sixroads.com
127.0.0.1 skakalka.ru
127.0.0.1 slawsearch.com
127.0.0.1 slotch.com
127.0.0.1 slotchbar.com
127.0.0.1 smartsumo.com
127.0.0.1 smutarchive.net
127.0.0.1 solongas.com
127.0.0.1 sonomaevents.com
127.0.0.1 spermatrix.com
127.0.0.1 sportbooks-free4you.com
127.0.0.1 spros.com
127.0.0.1 spyass.com
127.0.0.1 spyorgy.net
127.0.0.1 staceyowens.com
127.0.0.1 stacistaxx.com
127.0.0.1 stacystaxx.com
127.0.0.1 start-space.com
127.0.0.1 steamycock.com
127.0.0.1 sterva.com
127.0.0.1 stevecashdollar.com
127.0.0.1 stop-tracking.biz
127.0.0.1 stopvotefraud.com
127.0.0.1 stopxxxpics.com
127.0.0.1 strekoza.com
127.0.0.1 stuffstore.com
127.0.0.1 styleclickink.com
127.0.0.1 summercollins.com
127.0.0.1 summitcross.com
127.0.0.1 super-spider.com
127.0.0.1 super-websearch.com
127.0.0.1 supersexmachine.com
127.0.0.1 superwebsearch.com
127.0.0.1 supret.com
127.0.0.1 suzannebrecht.com
127.0.0.1 sweeteenz.com
127.0.0.1 tacil.org
127.0.0.1 tangounion.com
127.0.0.1 tastethemusic.com
127.0.0.1 tax-refund4you.com
127.0.0.1 tech-jobs.ws
127.0.0.1 technology-related.com
127.0.0.1 teen-biz.com
127.0.0.1 teen-pic-post.com
127.0.0.1 teenpornosex.com
127.0.0.1 teens4free.net
127.0.0.1 teensact.com
127.0.0.1 teensgate.com
127.0.0.1 teensguru.com
127.0.0.1 teenswamp.com
127.0.0.1 testosterone-birth-control.com
127.0.0.1 the-exit.com
127.0.0.1 the-huns-yellow-pages.com
127.0.0.1 thefakejournal.com
127.0.0.1 thehuy.net
127.0.0.1 theproxy.org
127.0.0.1 therealsearch.com
127.0.0.1 thesten.com
127.0.0.1 thornleygroup.com
127.0.0.1 tings.org
127.0.0.1 tit-x.com
127.0.0.1 titanvision.com
127.0.0.1 titsianna.com
127.0.0.1 toddhayes.com
127.0.0.1 toon-comics.com
127.0.0.1 tooncomics.com
127.0.0.1 topsearcher.com
127.0.0.1 trafficback.com
127.0.0.1 trafficswitcher.com
127.0.0.1 travel.picture-posters.com
127.0.0.1 true-portal.com
127.0.0.1 trytechnical.com
127.0.0.1 ufindall.click-now.net
127.0.0.1 umaxsearch.com
127.0.0.1 une-autre-france.com
127.0.0.1 unigays.com
127.0.0.1 unipages.cc
127.0.0.1 up2you.ru
127.0.0.1 urlstat.com
127.0.0.1 urlstat.ru
127.0.0.1 uralitel.ru
127.0.0.1 ursie.net
127.0.0.1 utahsweet.com
127.0.0.1 utopicportal.com
127.0.0.1 uusocialjustice.org
127.0.0.1 v61.com
127.0.0.1 vaginpics.com
127.0.0.1 valmyers.com
127.0.0.1 vegas-free.com
127.0.0.1 vegbuy.com
127.0.0.1 veloventures.com
127.0.0.1 verzila.com
127.0.0.1 victoriaadam.com
127.0.0.1 videocategories.com
127.0.0.1 vitamins-for-each.com
127.0.0.1 votehowe.org
127.0.0.1 vxebony.com
127.0.0.1 wakeupdick.com
127.0.0.1 warnomore.org
127.0.0.1 watersport-specialties.com
127.0.0.1 web-homepage.net
127.0.0.1 web-search.tk
127.0.0.1 webcoolsearch.com
127.0.0.1 websearchdot.com
127.0.0.1 weekend-movies.com
127.0.0.1 wetpornostars.com
127.0.0.1 whatsyoursearch.com
127.0.0.1 white-pages.ws
127.0.0.1 whittierblvd.com
127.0.0.1 win-in-casino.com
127.0.0.1 wiresearch.com
127.0.0.1 wolfpacracing.com
127.0.0.1 wordlist.jps.ru
127.0.0.1 wpc2001.org
127.0.0.1 wspzone.sexpornonline.com
127.0.0.1 wwwbet.net
127.0.0.1 wwwbetting.net
127.0.0.1 wwwpokergames.com
127.0.0.1 wwwpokerplayers.com
127.0.0.1 wwwroulette.net
127.0.0.1 x-library.com
127.0.0.1 x-webdesign.com
127.0.0.1 xcomics4u.com
127.0.0.1 xic-bs.com
127.0.0.1 xldr.com
127.0.0.1 xp18.com
127.0.0.1 xrenosearch.com
127.0.0.1 xtragay.com
127.0.0.1 xu.xu.pl
127.0.0.1 xxxcategories.com
127.0.0.1 xxxemailxxx.com
127.0.0.1 y-e-l-l-o-w.com
127.0.0.1 yellow500.com
127.0.0.1 yezol.com
127.0.0.1 you-search.com
127.0.0.1 you-search.com.ru
127.0.0.1 youfindall.com
127.0.0.1 youfindall.net
127.0.0.1 your-prescriptions.net
127.0.0.1 yourbookmarks.info
127.0.0.1 yourbookmarks.ws
127.0.0.1 ypir.com
127.0.0.1 ysa-info.net
127.0.0.1 yukohamano.com
127.0.0.1 ywebsearch.info
127.0.0.1 zapros.com
127.0.0.1 zesearch.com
127.0.0.1 ziportal.com
127.0.0.1 zipportal.com
127.0.0.1 zoneoffreeporn.com
127.0.0.1 zoomegasite.com
127.0.0.1 zvimigdal.com
127.0.0.1 zyban-zocor-levitra.com
127.0.0.1 t.rack.cc
127.0.0.1 omega-search.com
127.0.0.1 cool-xxx.net
127.0.0.1 revolto3.da.ru
127.0.0.1 dating-search.net
127.0.0.1 linksummary.com
127.0.0.1 duolaimi.net
127.0.0.1 ez-searching.com
127.0.0.1 freehqmovies.com
127.0.0.1 xzoomy.com
127.0.0.1 freescratchandwin.com
127.0.0.1 globalwebsearch.com
127.0.0.1 www.gocybersearch.com
127.0.0.1 mayancasino.com
127.0.0.1 www.hastalavista.com
127.0.0.1 www.free-popup-killer.com
127.0.0.1 www.digitalfan.com
127.0.0.1 google123.web1000.com
127.0.0.1 search.ieplugin.com
127.0.0.1 i-lookup.com
127.0.0.1 spidersearch.com
127.0.0.1 istarthere.com
127.0.0.1 xxxtoolbar.com
127.0.0.1 www.seekporn.org
127.0.0.1 17-plus.com
127.0.0.1 lolita4all1.xrensmagpost.com
127.0.0.1 mafiapics.com
127.0.0.1 www.teenmonster.com
127.0.0.1 ie.marketdart.com
127.0.0.1 masterbar.com
127.0.0.1 search.netzany.co
127.0.0.1 only-virgins.com
127.0.0.1 passthison.com
127.0.0.1 blondetgp.com
127.0.0.1 prolivation.com
127.0.0.1 server-au.imrworldwide.com
127.0.0.1 rocketsearch.com
127.0.0.1 .roar.com
127.0.0.1 searchaccurate.com
127.0.0.1 searchalot.com
127.0.0.1 searchandbrowse.com
127.0.0.1 gtawarehouse.com
127.0.0.1 startium.com
127.0.0.1 searchandclick.com
127.0.0.1 searchby.net
127.0.0.1 searchdot.com
127.0.0.1 search-exe.com
127.0.0.1 secret-crush.com
127.0.0.1 seekseek.com
127.0.0.1 sexarena.com
127.0.0.1 sexocean.play-lolita.com
127.0.0.1 startsurfing.com
127.0.0.1 66.197.138.235
127.0.0.1 srng.net
127.0.0.1 apps.webservicehost.com
127.0.0.1 search.shopnav.com
127.0.0.1 wish7.com
127.0.0.1 216.65.3.68
127.0.0.1 www.supersexpass.com
127.0.0.1 surferbar.com
127.0.0.1 xlola.underagehost.com
127.0.0.1 hotlolitas.underagehost.com
127.0.0.1 loading-lolita.com
127.0.0.1 www.xupiter.com
127.0.0.1 xjupiter.com
127.0.0.1 www.xjupiter.com
127.0.0.1 www.browserwise.com
127.0.0.1 sqwire.com
127.0.0.1 orbitexplorer.com
127.0.0.1 searchcentrix.com
127.0.0.1 categories.mygeek.com
127.0.0.1 web-entrance.co
127.0.0.1 whazit.com
127.0.0.1 windowenhancer.com
127.0.0.1 buz.ru
127.0.0.1 iwon.com
127.0.0.1 www.bonzi.com
127.0.0.1 featured-results.com
127.0.0.1 searchmadesafe.net
127.0.0.1 quicklaunch.com
127.0.0.1 www.cashsurfers.com
127.0.0.1 .lop.com
127.0.0.1 .tjdo.com
127.0.0.1 /tjdo.com
127.0.0.1 .ebav.com
127.0.0.1 /ebav.com
127.0.0.1 .ebgo.com
127.0.0.1 /ebgo.com
127.0.0.1 .ebaw.com
127.0.0.1 /ebaw.com
127.0.0.1 .ebkb.com
127.0.0.1 /ebkb.com
127.0.0.1 .ebmu.com
127.0.0.1 /ebmu.com
127.0.0.1 .ecmp.com
127.0.0.1 /ecmp.com
127.0.0.1 .edhq.com
127.0.0.1 /edhq.com
127.0.0.1 .edty.com
127.0.0.1 /edty.com
127.0.0.1 .sbee.com
127.0.0.1 /sbee.com
127.0.0.1 .aavc.com
127.0.0.1 /aavc.com
127.0.0.1 .acjp.com
127.0.0.1 /acjp.com
127.0.0.1 .ecmh.com
127.0.0.1 /ecmh.com
127.0.0.1 .emch.com
127.0.0.1 /emch.com
127.0.0.1 .ecpm.com
127.0.0.1 /ecpm.com
127.0.0.1 .wabu.com
127.0.0.1 /wabu.com
127.0.0.1 .wabq.com
127.0.0.1 /wabq.com
127.0.0.1 .ebch.com
127.0.0.1 /ebch.com
127.0.0.1 .ebdv.com
127.0.0.1 /ebdv.com
127.0.0.1 .ebdw.com
127.0.0.1 /ebdw.com
127.0.0.1 .ebjp.com
127.0.0.1 /ebjp.com
127.0.0.1 .ebkn.com
127.0.0.1 /ebkn.com
127.0.0.1 .ebky.com
127.0.0.1 /ebky.com
127.0.0.1 .eblv.com
127.0.0.1 /eblv.com
127.0.0.1 .wbkb.com
127.0.0.1 /wbkb.com
127.0.0.1 .ebvr.com
127.0.0.1 /ebvr.com
127.0.0.1 .ecwz.com
127.0.0.1 /ecwz.com
127.0.0.1 .ecyb.com
127.0.0.1 /ecyb.com
127.0.0.1 .eduy.com
127.0.0.1 /eduy.com
127.0.0.1 .eeev.com
127.0.0.1 /eeev.com
127.0.0.1 .farse.com
127.0.0.1 /farse.com
127.0.0.1 .ibmx.com
127.0.0.1 /ibmx.com
127.0.0.1 .icwb.com
127.0.0.1 /icwb.com
127.0.0.1 .icwo.com
127.0.0.1 /icwo.com
127.0.0.1 .icwp.com
127.0.0.1 /icwp.com
127.0.0.1 .iddh.com
127.0.0.1 /iddh.com
127.0.0.1 .idhh.com
127.0.0.1 /idhh.com
127.0.0.1 .ifiz.com
127.0.0.1 /ifiz.com
127.0.0.1 .iguu.com
127.0.0.1 /iguu.com
127.0.0.1 .samz.com
127.0.0.1 /samz.com
127.0.0.1 .saoe.com
127.0.0.1 /saoe.com
127.0.0.1 .sbjr.com
127.0.0.1 /sbjr.com
127.0.0.1 .sbnl.com
127.0.0.1 /sbnl.com
127.0.0.1 .sbnt.com
127.0.0.1 /sbnt.com
127.0.0.1 .sbvr.com
127.0.0.1 /sbvr.com
127.0.0.1 .scbm.com
127.0.0.1 /scbm.com
127.0.0.1 .sckr.com
127.0.0.1 /sckr.com
127.0.0.1 .scrk.com
127.0.0.1 /scrk.com
127.0.0.1 .sdry.com
127.0.0.1 /sdry.com
127.0.0.1 .seld.com
127.0.0.1 /seld.com
127.0.0.1 .sfux.com
127.0.0.1 /sfux.com
127.0.0.1 .sheat.com
127.0.0.1 /sheat.com
127.0.0.1 .sipo.com
127.0.0.1 /sipo.com
127.0.0.1 .smds.com
127.0.0.1 /smds.com
127.0.0.1 .srib.com
127.0.0.1 /srib.com
127.0.0.1 .srox.com
127.0.0.1 /srox.com
127.0.0.1 .srsf.com
127.0.0.1 /srsf.com
127.0.0.1 .ssaw.com
127.0.0.1 /ssaw.com
127.0.0.1 .ssby.com
127.0.0.1 /ssby.com
127.0.0.1 .surj.com
127.0.0.1 /surj.com
127.0.0.1 .tbvg.com
127.0.0.1 /tbvg.com
127.0.0.1 .tdak.com
127.0.0.1 /tdak.com
127.0.0.1 .tdmy.com
127.0.0.1 /tdmy.com
127.0.0.1 .tefs.com
127.0.0.1 /tefs.com
127.0.0.1 .tfil.com
127.0.0.1 /tfil.com
127.0.0.1 .tjar.com
127.0.0.1 /tjar.com
127.0.0.1 .tjaw.com
127.0.0.1 /tjaw.com
127.0.0.1 .tjgo.com
127.0.0.1 /tjgo.com
127.0.0.1 .tjem.com
127.0.0.1 /tjem.com
127.0.0.1 .torc.com
127.0.0.1 /torc.com
127.0.0.1 .wfix.com
127.0.0.1 /wfix.com
127.0.0.1 .wflu.com
127.0.0.1 /wflu.com
127.0.0.1 .tdko.com
127.0.0.1 /tdko.com
127.0.0.1 .thko.com
127.0.0.1 /thko.com
127.0.0.1 H24413.tfil.com
127.0.0.1 germany.rub.to
127.0.0.1 search.rub.to
127.0.0.1 unitedstates.rub.to
127.0.0.1 www.commonname.com
127.0.0.1 www.ezcybersearch.com
127.0.0.1 www.jethomepage.com
127.0.0.1 www.gohip.com
127.0.0.1 hotbar.com
127.0.0.1 www.huntbar.com
127.0.0.1 search.imiserver.com
127.0.0.1 infospace.com/blsrch.dp.toolbar
127.0.0.1 searchenhancement.com
127.0.0.1 newtonknows.com
127.0.0.1 search-explorer.net
127.0.0.1 searchsquire.com
127.0.0.1 secondpower.com
127.0.0.1 2ndpower.com
127.0.0.1 searchgateway.net
127.0.0.1 worldusa.com
127.0.0.1 www.topsearcher.com
127.0.0.1 smutserver.com
127.0.0.1 searchmeup.com
127.0.0.1 cameup.com
127.0.0.1 kliksearch.com
127.0.0.1 realphx.com
127.0.0.1 blazefind.com
127.0.0.1 66.40.16.198
127.0.0.1 zoofil.com
127.0.0.1 terafinder.com
127.0.0.1 008i.com
127.0.0.1 171203.com
127.0.0.1 39-93.com
127.0.0.1 adult-personal.us
127.0.0.1 cashsearch.biz
127.0.0.1 cl55.biz
127.0.0.1 dailyteenspic.com
127.0.0.1 dialer2004.com
127.0.0.1 digital-pornography.com
127.0.0.1 eager-sex.com
127.0.0.1 ergosites.com
127.0.0.1 freecj.com
127.0.0.1 greg-search.com
127.0.0.1 incest-host.com
127.0.0.1 ironcarteam.com
127.0.0.1 is-best.com
127.0.0.1 killerpornstars.com
127.0.0.1 lollitop.com
127.0.0.1 love-host.com
127.0.0.1 myexexex.com
127.0.0.1 my-finder.com
127.0.0.1 onlineclick.net
127.0.0.1 onlysex.ws
127.0.0.1 regfreeze.com
127.0.0.1 ruworld.com
127.0.0.1 selltraffic.biz
127.0.0.1 sexunique.net
127.0.0.1 sinpussy.com
127.0.0.1 teenhost.net
127.0.0.1 ultraload.net
127.0.0.1 vse-moe.biz
127.0.0.1 xsex.ws
127.0.0.1 .75tz.com
127.0.0.1 /75tz.com
127.0.0.1 .iefeadsl.com
127.0.0.1 /iefeadsl.com
127.0.0.1 /rf104.com
127.0.0.1 .rf104.com
127.0.0.1 www.v61.com
127.0.0.1 ads.centralmedia.ws
127.0.0.1 c.centralmedia.ws
127.0.0.1 .count.cc
127.0.0.1 /count.cc
127.0.0.1 .topx.cc
127.0.0.1 /topx.cc
127.0.0.1 sidefind.com
127.0.0.1 thenewsearch.com
127.0.0.1 new-search.net
127.0.0.1 x-google.net
127.0.0.1 adultgambling.org
127.0.0.1 bitchesonline.net
127.0.0.1 girls4rent.net
127.0.0.1 usefullsoft.net
127.0.0.1 livegambling.com
127.0.0.1 adultsgames.net
127.0.0.1 easyantispy.com
127.0.0.1 spybotremover.net
127.0.0.1 winprotect.net
127.0.0.1 funny-girls.com
127.0.0.1 winmsn.com
127.0.0.1 oneclicksearches.com
127.0.0.1 bestweblinks.com
127.0.0.1 iqsearch.net
127.0.0.1 dumpserv.com
127.0.0.1 helpyoursearch.com
127.0.0.1 sgrunt.biz
127.0.0.1 yeak.net
127.0.0.1 u45.cx
127.0.0.1 u46.cx
127.0.0.1 u47.cc
127.0.0.1 u48.cc
127.0.0.1 sfonditalia.biz
127.0.0.1 realarea.biz
127.0.0.1 archiviosex.net
127.0.0.1 agava.com
127.0.0.1 agava.ru
127.0.0.1 hut1.ru
127.0.0.1 hu15.ru
127.0.0.1 winfixer.com
127.0.0.1 3721.com
127.0.0.1 easysearchingtips.com
127.0.0.1 fine-search.net
127.0.0.1 noproblemsurf.com
127.0.0.1 pcspyremover.com
127.0.0.1 search-motor.com
127.0.0.1 searchwhatuwant.com
127.0.0.1 ad25.com
127.0.0.1 ad45.com
127.0.0.1 ad77.com
127.0.0.1 ad86.com
127.0.0.1 full-search.net
127.0.0.1 go2-search.com
127.0.0.1 onemoresearch.net
127.0.0.1 search-777.com
127.0.0.1 search-to-find.com
127.0.0.1 search-what.net
127.0.0.1 winshow.biz
127.0.0.1 lookfor.cc
127.0.0.1 looking-for.cc
127.0.0.1 tgp-4-you.com
127.0.0.1 veryeasysearch.com
127.0.0.1 010402.com
127.0.0.1 20x2p.com
127.0.0.1 db105.com
127.0.0.1 ga31.com
127.0.0.1 mpeg-look.com
127.0.0.1 n-udd.com
127.0.0.1 p-uud.com
127.0.0.1 porn-screen.com
127.0.0.1 rb37.com
127.0.0.1 t058.com
127.0.0.1 u-239.com
127.0.0.1 v-224.com
127.0.0.1 trackhits.cc
127.0.0.1 tracktraff.cc
127.0.0.1 power-cleaner.com
127.0.0.1 yoursitebar.com
127.0.0.1 ysbweb.com
127.0.0.1 www.ysbweb.com
127.0.0.1 installcash.com
127.0.0.1 toolbarcash.com
127.0.0.1 enjoywebsurf.com
127.0.0.1 msnguard.cc
127.0.0.1 searchclick.cc
127.0.0.1 havy.biz
127.0.0.1 ewizard.cc
127.0.0.1 4klm.com
127.0.0.1 camup.net
127.0.0.1 bdsmlibrary.net
127.0.0.1 n-glx.s-redirect.com
127.0.0.1 aaasexypics.com
127.0.0.1 allforadult.com
127.0.0.1 autoescrowpay.com
127.0.0.1 awmcash.biz
127.0.0.1 awmdabest.com
127.0.0.1 buldog-stats.com
127.0.0.1 counter.sexmaniack.com
127.0.0.1 fregat.drocherway.com
127.0.0.1 greg-tut.com
127.0.0.1 iframe.biz
127.0.0.1 megapornix.com
127.0.0.1 newiframe.biz
127.0.0.1 nylonsexy.com
127.0.0.1 pizdato.biz
127.0.0.1 sexfiles.nu
127.0.0.1 slutmania.biz
127.0.0.1 sp2fucked.biz
127.0.0.1 toolbarpartner.com
127.0.0.1 vesbiz.biz
127.0.0.1 virgin-tgp.net
127.0.0.1 vparivalka.com
127.0.0.1 x.full-tgp.net
127.0.0.1 toolbar.cc
127.0.0.1 himen.biz
127.0.0.1 msupdater.net
127.0.0.1 www.msupdater.net
127.0.0.1 1800searchonline.com
127.0.0.1 www.1800searchonline.com
127.0.0.1 1stsearchportal.com
127.0.0.1 www.1stsearchportal.com
127.0.0.1 24-7searching-and-more.com
127.0.0.1 www.24-7searching-and-more.com
127.0.0.1 971searchbox.com
127.0.0.1 www.971searchbox.com
127.0.0.1 aaawebfinder.com
127.0.0.1 www.aaawebfinder.com
127.0.0.1 ampmsearch.com
127.0.0.1 www.ampmsearch.com
127.0.0.1 clickhere4search.com
127.0.0.1 www.clickhere4search.com
127.0.0.1 clicktomakeasearch.com
127.0.0.1 www.clicktomakeasearch.com
127.0.0.1 directsearchzone.com
127.0.0.1 www.directsearchzone.com
127.0.0.1 easysearch4you.com
127.0.0.1 www.easysearch4you.com
127.0.0.1 enterthesearch.com
127.0.0.1 www.enterthesearch.com
127.0.0.1 esearch2005.com
127.0.0.1 www.esearch2005.com
127.0.0.1 eza1netsearch.com
127.0.0.1 www.eza1netsearch.com
127.0.0.1 ezwebsearching.com
127.0.0.1 www.ezwebsearching.com
127.0.0.1 globalefinder.com
127.0.0.1 www.globalefinder.com
127.0.0.1 go2realsearch.com
127.0.0.1 www.go2realsearch.com
127.0.0.1 myseachexplorer.com
127.0.0.1 www.myseachexplorer.com
127.0.0.1 quicksearch360.com
127.0.0.1 www.quicksearch360.com
127.0.0.1 s1s1s1search.com
127.0.0.1 www.s1s1s1search.com
127.0.0.1 search101online.com
127.0.0.1 www.search101online.com
127.0.0.1 search123forme.com
127.0.0.1 www.search123forme.com
127.0.0.1 search345quest.com
127.0.0.1 www.search345quest.com
127.0.0.1 searchmiracle.com
127.0.0.1 www.searchmiracle.com
127.0.0.1 searchtheworld4you.com
127.0.0.1 www.searchtheworld4you.com
127.0.0.1 searchwebzone.com
127.0.0.1 www.searchwebzone.com
127.0.0.1 seektheglobe.com
127.0.0.1 www.seektheglobe.com
127.0.0.1 sitesearchcentral.com
127.0.0.1 www.sitesearchcentral.com
127.0.0.1 the818search-co.com
127.0.0.1 www.the818search-co.com
127.0.0.1 type2find.com
127.0.0.1 www.type2find.com
127.0.0.1 xosearchox.com
127.0.0.1 www.xosearchox.com
127.0.0.1 yoursearchspace.com
127.0.0.1 www.yoursearchspace.com
127.0.0.1 httpwwwads.com
127.0.0.1 www.httpwwwads.com
127.0.0.1 adshttp.com
127.0.0.1 www.adshttp.com
127.0.0.1 adsonwww.com
127.0.0.1 www.adsonwww.com
127.0.0.1 216.152.240.14
127.0.0.1 216.152.240.13
127.0.0.1 216.152.240.10
127.0.0.1 216.152.240.16
127.0.0.1 dnaads.com
127.0.0.1 www.dnaads.com
127.0.0.1 marketengines.com
127.0.0.1 www.marketengines.com
127.0.0.1 ad-w-a-r-e.com
127.0.0.1 www.ad-w-a-r-e.com
127.0.0.1 a-d-w-a-r-e.com
127.0.0.1 www.a-d-w-a-r-e.com
127.0.0.1 securityindex.net
127.0.0.1 www.securityindex.net
127.0.0.1 sexpicsporn.com
127.0.0.1 www.sexpicsporn.com
127.0.0.1 free-spybot.com
127.0.0.1 www.free-spybot.com
127.0.0.1 cashengines.com
127.0.0.1 www.cashengines.com
127.0.0.1 microsoftantispyware.net
127.0.0.1 www.microsoftantispyware.net
127.0.0.1 mircosoftantispy.com
127.0.0.1 www.mircosoftantispy.com
127.0.0.1 msantispy.com
127.0.0.1 www.msantispy.com
127.0.0.1 netspyprotector.com
127.0.0.1 www.netspyprotector.com
127.0.0.1 avforce.com
127.0.0.1 www.avforce.com
127.0.0.1 savehits.com
127.0.0.1 www.savehits.com
127.0.0.1 saveli.com
127.0.0.1 www.saveli.com
127.0.0.1 metastop.com
127.0.0.1 www.metastop.com
127.0.0.1 perlink.biz
127.0.0.1 www.perlink.biz
127.0.0.1 highdialer.com
127.0.0.1 www.highdialer.com
127.0.0.1 66.230.175.129
127.0.0.1 online-more.com
127.0.0.1 www.online-more.com
127.0.0.1 66.117.37.7
127.0.0.1 www.syserrors.com
127.0.0.1 www.vcodec.com
127.0.0.1 toolbartraff.biz
127.0.0.1 www.toolbartraff.biz
127.0.0.1 pcadprotector.cc
127.0.0.1 www.pcadprotector.cc
127.0.0.1 airtleworld.com
127.0.0.1 www.airtleworld.com
127.0.0.1 domaincar.com
127.0.0.1 www.domaincar.com
127.0.0.1 worldray.com
127.0.0.1 www.worldray.com
127.0.0.1 www5.worldray.com
127.0.0.1 www6.worldray.com
127.0.0.1 www.spytrooper.com
127.0.0.1 spytrooper.com
127.0.0.1 dl.ad-ware.cc
127.0.0.1 ad-ware.cc
127.0.0.1 82.179.170.11
127.0.0.1 195.255.177.28
127.0.0.1 downloads.adaware.cc
127.0.0.1 adaware.cc
127.0.0.1 hitscount.net
127.0.0.1 count.hitscount.net
127.0.0.1 fined.biz
127.0.0.1 de.ag
127.0.0.1 games.de.ag
127.0.0.1 www.games.de.ag
127.0.0.1 little-download.net
127.0.0.1 www.little-download.net
127.0.0.1 little-help.com
127.0.0.1 www.little-help.com
127.0.0.1 www.spyaxe.net
127.0.0.1 www.spyaxe.com
127.0.0.1 www.spyaxe.biz
127.0.0.1 www.malwarewipe.com
127.0.0.1 dl.malwarewipe.com
127.0.0.1 www.malwarewipeupdate.com
127.0.0.1 24.244.71.239
127.0.0.1 unionseek.com
127.0.0.1 www.unionseek.com
127.0.0.1 sirh0t.blackhats.tc
127.0.0.1 blackhats.tc
127.0.0.1 www.blackhats.tc
127.0.0.1 ritztours.com
127.0.0.1 www.ritztours.com
127.0.0.1 flashflashmx.3322.org
127.0.0.1 3322.org
127.0.0.1 www.3322.org
127.0.0.1 jupitersatellites.biz
127.0.0.1 www.jupitersatellites.biz
127.0.0.1 yops.biz
127.0.0.1 www.yops.biz
127.0.0.1 69.50.171.122
127.0.0.1 goldengr.hypermart.net
127.0.0.1 web-nexus.net
127.0.0.1 safe-sales.biz
127.0.0.1 www.safe-sales.biz
127.0.0.1 jerrynews.com
127.0.0.1 www.jerrynews.com
127.0.0.1 Teslaplus.com
127.0.0.1 www.Teslaplus.com
127.0.0.1 82.179.170.82
127.0.0.1 WorldAntiSpy.com
127.0.0.1 www.WorldAntiSpy.com
127.0.0.1 www.securitycaution.com
127.0.0.1 securitycaution.com
127.0.0.1 adservs.com
127.0.0.1 csx.adservs.com
127.0.0.1 www.csx.adservs.com
127.0.0.1 toolbarbest.biz
127.0.0.1 www.toolbarbest.biz
127.0.0.1 65.75.151.192
127.0.0.1 game4all.biz
127.0.0.1 www.game4all.biz
127.0.0.1 game4all.biz/adv/018
127.0.0.1 www.game4all.biz/adv/018
127.0.0.1 wm.kannylizaciya.info
127.0.0.1 www.wm.kannylizaciya.info
127.0.0.1 wm.buhartes.info
127.0.0.1 www.wm.buhartes.info
127.0.0.1 login.fric.cn
127.0.0.1 www.login.fric.cn
127.0.0.1 xsremover.com
127.0.0.1 www.xsremover.com
127.0.0.1 spydeface.com
127.0.0.1 www.spydeface.com
127.0.0.1 alfacleaner.com
127.0.0.1 www.alfacleaner.com
127.0.0.1 innovagest2000.com
127.0.0.1 www.innovagest2000.com
127.0.0.1 www.thespyguard.com
127.0.0.1 thespyguard.com
127.0.0.1 www.adwarepunisher.com
127.0.0.1 adwarepunisher.com
127.0.0.1 www.spyiblock.com
127.0.0.1 spyiblock.com
127.0.0.1 www.uvu-channel.com
127.0.0.1 uvu-channel.com
127.0.0.1 www.hachimitsu-lemon.com
127.0.0.1 hachimitsu-lemon.com
127.0.0.1 SEARCHTOFIND.NET
127.0.0.1 www.SEARCHTOFIND.NET
127.0.0.1 www.pestrap.com
127.0.0.1 pestrap.com
127.0.0.1 uptodatesecurity.com
127.0.0.1 www.uptodatesecurity.com
127.0.0.1 thinstall.abetterinternet.com
127.0.0.1 www.3abetterinternet.com
127.0.0.1 download.abetterinternet.com
127.0.0.1 www.abetterinternet.com
127.0.0.1 216.255.179.234
127.0.0.1 qmex.psyche-evolution.com
127.0.0.1 www.qmex.psyche-evolution.com
127.0.0.1 core.psyche-evolution.com
127.0.0.1 www.core.psyche-evolution.com
127.0.0.1 1stantivirus.com
127.0.0.1 www.1stantivirus.com
127.0.0.1 scanandrepair.com
127.0.0.1 www.scanandrepair.com
127.0.0.1 uydsiygeds.com
127.0.0.1 www.uydsiygeds.com
127.0.0.1 pesttrap.com
127.0.0.1 www.pesttrap.com
127.0.0.1 adwarebazooka.com
127.0.0.1 get.adwarebazooka.com
127.0.0.1 www.adwarebazooka.com
127.0.0.1 kliksoftware.com
127.0.0.1 www.kliksoftware.com
127.0.0.1 hitvirus.com
127.0.0.1 get.hitvirus.com
127.0.0.1 www.hitvirus.com
127.0.0.1 promo.dollarrevenue.com
127.0.0.1 www.promo.dollarrevenue.com
127.0.0.1 maxifile.com
127.0.0.1 www.maxifile.com
127.0.0.1 targetsaver.com
127.0.0.1 www.targetsaver.com
127.0.0.1 dl.targetsaver.com
127.0.0.1 www.dl.targetsaver.com
127.0.0.1 nonameforthisdomain.com
127.0.0.1 www.nonameforthisdomain.com
127.0.0.1 hypoteches.com
127.0.0.1 www.hypoteches.com
127.0.0.1 www.earthllnk.net
127.0.0.1 earthllnk.net
127.0.0.1 hostance.net
127.0.0.1 www.hostance.net
127.0.0.1 my-dedik-one.com
127.0.0.1 www.my-dedik-one.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 6sek.com
127.0.0.1 www.6sek.com
127.0.0.1 cashdeluxe.net
127.0.0.1 www.cashdeluxe.net
127.0.0.1 stats.cashdeluxe.net
127.0.0.1 www.stats.cashdeluxe.net
127.0.0.1 www.2006ooo.com
127.0.0.1 www.spyware-stop.com
127.0.0.1 spyware-stop.com
127.0.0.1 www.SpyShield.org
127.0.0.1 SpyShield.org
127.0.0.1 utils.winfixer.com
127.0.0.1 www.utils.winfixer.com
127.0.0.1 toolbarbucks.biz
127.0.0.1 www.toolbarbucks.biz
127.0.0.1 derklaif.biz
127.0.0.1 www.derklaif.biz
127.0.0.1 www.v-codec.com
127.0.0.1 v-codec.com
127.0.0.1 www.emediacodec.com
127.0.0.1 emediacodec.com
127.0.0.1 www.popentertain.com
127.0.0.1 popentertain.com
127.0.0.1 softwareprofit.com
127.0.0.1 www.softwareprofit.com
127.0.0.1 de.winantivirus.com
127.0.0.1 download.winantivirus.com
127.0.0.1 winantivirus.com
127.0.0.1 www.winantivirus.com
127.0.0.1 205.209.152.121
127.0.0.1 offers.bullseye-network.com
127.0.0.1 www.offers.bullseye-network.com
127.0.0.1 bullseye-network.com
127.0.0.1 www.bullseye-network.com
127.0.0.1 sponsor2.ucmore.com
127.0.0.1 www.sponsor2.ucmore.com
127.0.0.1 apps.deskwizz
127.0.0.1 www.apps.deskwizz
127.0.0.1 hostthesky.com
127.0.0.1 www.hostthesky.com
127.0.0.1 dbdecicated.com
127.0.0.1 www.dbdecicated.com
127.0.0.1 readagreement.net
127.0.0.1 www.readagreement.net
127.0.0.1 gl.secdep.info
127.0.0.1 www.gl.secdep.info
127.0.0.1 spyfalcon.com
127.0.0.1 www.spyfalcon.com
127.0.0.1 spyfalconupdate.com
127.0.0.1 www.spyfalconupdate.com
127.0.0.1 spy-shield.com
127.0.0.1 www.spy-shield.com
127.0.0.1 winnanny.com
127.0.0.1 www.winnanny.com
127.0.0.1 winsoftware.com
127.0.0.1 www.winsoftware.com
127.0.0.1 winfirewall.com
127.0.0.1 www.winfirewall.com
127.0.0.1 winantispyware.com
127.0.0.1 www.winantispyware.com
127.0.0.1 udefender.com
127.0.0.1 www.udefender.com
127.0.0.1 bravesentry.com
127.0.0.1 www.bravesentry.com
127.0.0.1 content.dollarrevenue.com
127.0.0.1 www.content.dollarrevenue.com
127.0.0.1 toolbar.azebar.com
127.0.0.1 www.toolbar.azebar.com
127.0.0.1 traffsale1.biz
127.0.0.1 www.traffsale1.biz
127.0.0.1 194.187.45.55
127.0.0.1 82.146.60.36
127.0.0.1 spywaredisinfector.com
127.0.0.1 www.spywaredisinfector.com
127.0.0.1 SpyCut.com
127.0.0.1 www.SpyCut.com
127.0.0.1 almanah.biz
127.0.0.1 www.almanah.biz
127.0.0.1 antispydns.biz
127.0.0.1 www.antispydns.biz
127.0.0.1 spyaxeupdate.com
127.0.0.1 www.spyaxeupdate.com
127.0.0.1 malwarewipesupport.com
127.0.0.1 www.malwarewipesupport.com
127.0.0.1 remedyantispy.com
127.0.0.1 www.remedyantispy.com
127.0.0.1 systemstable.com
127.0.0.1 www.systemstable.com
127.0.0.1 whoisprivacyprotect.com
127.0.0.1 www.whoisprivacyprotect.com
127.0.0.1 85.249.22.240
127.0.0.1 prime.webhancer.com
127.0.0.1 www.prime.webhancer.com
127.0.0.1 webhancer.com
127.0.0.1 www.webhancer.com
127.0.0.1 dr.webhancer.com
127.0.0.1 www.dr.webhancer.com
127.0.0.1 dr2.webhancer.com
127.0.0.1 www.dr2.webhancer.com
127.0.0.1 www.onli-ne.com
127.0.0.1 spycontra.com
127.0.0.1 www.spycontra.com
127.0.0.1 anti-virus-pro.com
127.0.0.1 www.anti-virus-pro.com
127.0.0.1 check.jupitersatellites.biz
127.0.0.1 www.check.jupitersatellites.biz
127.0.0.1 necessaryupdates.com
127.0.0.1 www.necessaryupdates.com
127.0.0.1 bestworldgirls-for-u.net
127.0.0.1 www.bestworldgirls-for-u.net
127.0.0.1 stejax.pl
127.0.0.1 www.stejax.pl
127.0.0.1 kitehosting.com
127.0.0.1 www.kitehosting.com
127.0.0.1 ware2006.com
127.0.0.1 www.ware2006.com
127.0.0.1 filestore.com
127.0.0.1 www.filestore.com
127.0.0.1 systemupdates.net
127.0.0.1 www.systemupdates.net
127.0.0.1 logs.vapochille.com
127.0.0.1 www.logs.vapochille.com
127.0.0.1 goldenfreehost.com
127.0.0.1 www.goldenfreehost.com
127.0.0.1 todaywarnings.com
127.0.0.1 www.todaywarnings.com
127.0.0.1 spywarequake.com
127.0.0.1 spywarequake.info
127.0.0.1 www.spywarequake.info
127.0.0.1 www.spywarequake.com
127.0.0.1 download2.spywarequake.com
127.0.0.1 download3.spywarequake.com
127.0.0.1 download4.spywarequake.com
127.0.0.1 download5.spywarequake.com
127.0.0.1 download7.spywarequake.com
127.0.0.1 download8.spywarequake.com
127.0.0.1 download9.spywarequake.com
127.0.0.1 download10.spywarequake.com
127.0.0.1 download11.spywarequake.com
127.0.0.1 download12.spywarequake.com
127.0.0.1 download13.spywarequake.com
127.0.0.1 download15.spywarequake.com
127.0.0.1 updates.spywarequake.com
127.0.0.1 206.161.124.98
127.0.0.1 69.31.131.82
127.0.0.1 207.226.162.34
127.0.0.1 urgentsystemupdate.com
127.0.0.1 www.urgentsystemupdate.com
127.0.0.1 dl2.spywarestrike.com
127.0.0.1 dl3.spywarestrike.com
127.0.0.1 dl4.spywarestrike.com
127.0.0.1 dl5.spywarestrike.com
127.0.0.1 dl6.spywarestrike.com
127.0.0.1 dl7.spywarestrike.com
127.0.0.1 dl8.spywarestrike.com
127.0.0.1 nospywaresoft.com
127.0.0.1 spywarestrike.com
127.0.0.1 www.nospywaresoft.com
127.0.0.1 www.spywarestrike.com
127.0.0.1 69.31.81.82
127.0.0.1 spyaxesupport.com
127.0.0.1 www.spyaxesupport.com
127.0.0.1 download3.spyaxe.com
127.0.0.1 download4.spyaxe.com
127.0.0.1 download5.spyaxe.com
127.0.0.1 download6.spyaxe.com
127.0.0.1 dl2.spyfalcon.com
127.0.0.1 dl3.spyfalcon.com
127.0.0.1 dl4.spyfalcon.com
127.0.0.1 dl5.spyfalcon.com
127.0.0.1 dl9.spyfalcon.com
127.0.0.1 dl10.spyfalcon.com
127.0.0.1 dl16.spyfalcon.com
127.0.0.1 www.sgrunt.biz
127.0.0.1 traffbest.biz
127.0.0.1 www.traffbest.biz
127.0.0.1 securityfeature.com
127.0.0.1 www.securityfeature.com
127.0.0.1 pimasoft.com
127.0.0.1 www.pimasoft.com
127.0.0.1 blackhawksoftware.com
127.0.0.1 www.blackhawksoftware.com
127.0.0.1 spy-sniper.com
127.0.0.1 www.spy-sniper.com
127.0.0.1 safetydefender.com
127.0.0.1 www.safetydefender.com
127.0.0.1 securitywarnings.net
127.0.0.1 www.securitywarnings.net
127.0.0.1 urgentsystemupdate.biz
127.0.0.1 www.urgentsystemupdate.biz
127.0.0.1 antispylab.com
127.0.0.1 www.antispylab.com
127.0.0.1 spywaresheriff.com
127.0.0.1 www.spywaresheriff.com
127.0.0.1 allmegabucks.com
127.0.0.1 www.allmegabucks.com
127.0.0.1 rizalof.com
127.0.0.1 www.rizalof.com
127.0.0.1 rc.rizalof.com
127.0.0.1 media-codec.com
127.0.0.1 www.media-codec.com
127.0.0.1 SpywareScraper.com
127.0.0.1 www.SpywareScraper.com
127.0.0.1 crystalysmedia.com
127.0.0.1 www.crystalysmedia.com
127.0.0.1 180solutions.com
127.0.0.1 cts.180solutions.com
127.0.0.1 bis.180solutions.com
127.0.0.1 downloads.180solutions.com
127.0.0.1 uploads.180solutions.com
127.0.0.1 installs.180solutions.com
127.0.0.1 config.180solutions.com
127.0.0.1 ping.180solutions.com
127.0.0.1 tv.180solutions.com
127.0.0.1 nowhere.180solutions.com
127.0.0.1 www.180solutions.com
127.0.0.1 180searchassistant.com
127.0.0.1 www.180searchassistant.com
127.0.0.1 theguardservices.com
127.0.0.1 www.theguardservices.com
127.0.0.1 securitybulletin.net
127.0.0.1 www.securitybulletin.net
127.0.0.1 www.supernet.speedserv.com
127.0.0.1 spyonthis.net
127.0.0.1 download.spyonthis.net
127.0.0.1 www.spyonthis.net
127.0.0.1 hijack-this.net
127.0.0.1 www.hijack-this.net
127.0.0.1 errorsafe.com
127.0.0.1 de.errorsafe.com
127.0.0.1 download.errorsafe.com
127.0.0.1 www.errorsafe.com
127.0.0.1 amaena.com
127.0.0.1 trial.updates.winsoftware.com
127.0.0.1 instlog.winfixer.com
127.0.0.1 winfixer2006.com
127.0.0.1 www.winfixer2006.com
127.0.0.1 webtopsecurity.com
127.0.0.1 www.webtopsecurity.com
127.0.0.1 traff5all.biz
127.0.0.1 www.traff5all.biz
127.0.0.1 1-extreme.biz
127.0.0.1 www.1-extreme.biz
127.0.0.1 download.bravesentry.com
127.0.0.1 www.download.bravesentry.com
127.0.0.1 evko.biz
127.0.0.1 www.evko.biz
127.0.0.1 lavasoftupdate.com
127.0.0.1 www.lavasoftupdate.com
127.0.0.1 download.secureyournet.biz
127.0.0.1 www.download.secureyournet.biz
127.0.0.1 secureyournet.biz
127.0.0.1 www.secureyournet.biz
127.0.0.1 windupdates.com
127.0.0.1 asdbiz.biz
127.0.0.1 www.asdbiz.biz
127.0.0.1 spywarelabs.com
127.0.0.1 www.spywarelabs.com
127.0.0.1 traffweb1.biz
127.0.0.1 www.traffweb1.biz
127.0.0.1 newtoolbar.biz
127.0.0.1 www.newtoolbar.biz
127.0.0.1 buytraff.biz
127.0.0.1 www.buytraff.biz
127.0.0.1 safetyuptodate.com
127.0.0.1 www.safetyuptodate.com
127.0.0.1 crazywinnings.com
127.0.0.1 frame.crazywinnings.com
127.0.0.1 www.crazywinnings.com
127.0.0.1 topconverting.com
127.0.0.1 www.topconverting.com
127.0.0.1 casalemedia.com
127.0.0.1 b.casalemedia.com
127.0.0.1 www.casalemedia.com
127.0.0.1 addictivetechnologies.com
127.0.0.1 www.addictivetechnologies.com
127.0.0.1 addictivetechnologies.net
127.0.0.1 www.addictivetechnologies.net
127.0.0.1 admin2cash.biz
127.0.0.1 www.admin2cash.biz
127.0.0.1 advcash.biz
127.0.0.1 www.advcash.biz
127.0.0.1 all4internet.com
127.0.0.1 www.all4internet.com
127.0.0.1 bettersearch.biz
127.0.0.1 www.bettersearch.biz
127.0.0.1 c4tdownload.com
127.0.0.1 www.c4tdownload.com
127.0.0.1 clickspring.net
127.0.0.1 www.clickspring.net
127.0.0.1 contentmatch.net
127.0.0.1 www.contentmatch.net
127.0.0.1 dialer-shop.com
127.0.0.1 www.dialer-shop.com
127.0.0.1 dialoff.com
127.0.0.1 www.dialoff.com
127.0.0.1 energy-factor.com
127.0.0.1 www.energy-factor.com
127.0.0.1 hardcorefantasyland.com
127.0.0.1 www.hardcorefantasyland.com
127.0.0.1 hardfootballbabes.com
127.0.0.1 www.hardfootballbabes.com
127.0.0.1 linkautomatici.com
127.0.0.1 www.linkautomatici.com
127.0.0.1 master69.biz
127.0.0.1 www.master69.biz
127.0.0.1 master70.biz
127.0.0.1 www.master70.biz
127.0.0.1 master71.biz
127.0.0.1 www.master71.biz
127.0.0.1 mcdial.biz
127.0.0.1 www.mcdial.biz
127.0.0.1 mt-download.com
127.0.0.1 www.mt-download.com
127.0.0.1 my-teensex.com
127.0.0.1 overpro.com
127.0.0.1 private-dialer.biz
127.0.0.1 private-iframe.biz
127.0.0.1 redfunny.com
127.0.0.1 scoobidoo.com
127.0.0.1 skoobidoo.com
127.0.0.1 sexvideopro.com
127.0.0.1 storage-tasp.com
127.0.0.1 xbeta69.com
127.0.0.1 securityuptodate.net
127.0.0.1 www.securityuptodate.net
127.0.0.1 troonety.biz
127.0.0.1 www.troonety.biz
127.0.0.1 zurrusco.com
127.0.0.1 www.zurrusco.com
127.0.0.1 breenten.biz
127.0.0.1 www.breenten.biz
127.0.0.1 votreenton.biz
127.0.0.1 www.votreenton.biz
127.0.0.1 ozonung.biz
127.0.0.1 www.ozonung.biz
127.0.0.1 213.21.215.186
127.0.0.1 digikeygen.com
127.0.0.1 www.digikeygen.com
127.0.0.1 5starvideos.com
127.0.0.1 www.5starvideos.com
127.0.0.1 moviereality.com
127.0.0.1 www.moviereality.com
127.0.0.1 perfectedsecurity.com
127.0.0.1 www.perfectedsecurity.com
127.0.0.1 securityprecaution.net
127.0.0.1 www.securityprecaution.net
127.0.0.1 securityupdatesite.com
127.0.0.1 www.securityupdatesite.com
127.0.0.1 dns-look-up.com
127.0.0.1 www.dns-look-up.com
127.0.0.1 ayb.dns-look-up.com
127.0.0.1 search200.com
127.0.0.1 www.search200.com
127.0.0.1 404dns.com
127.0.0.1 www.404dns.com
127.0.0.1 mcboo.com
127.0.0.1 dr.mcboo.com
127.0.0.1 www.mcboo.com
127.0.0.1 appealcircuit.com
127.0.0.1 www.appealcircuit.com
127.0.0.1 balotierra.com
127.0.0.1 www.balotierra.com
127.0.0.1 oldflock.com
127.0.0.1 www.oldflock.com
127.0.0.1 pornmagpass.com
127.0.0.1 www.pornmagpass.com
127.0.0.1 dailypornmag.com
127.0.0.1 www.dailypornmag.com
127.0.0.1 babespornmag.com
127.0.0.1 www.babespornmag.com
127.0.0.1 teenspornmag.com
127.0.0.1 www.teenspornmag.com
127.0.0.1 maturespornmag.com
127.0.0.1 www.maturespornmag.com
127.0.0.1 hardcorepornmag.com
127.0.0.1 www.hardcorepornmag.com
127.0.0.1 gayspornmag.com
127.0.0.1 www.gayspornmag.com
127.0.0.1 topsecuritysite.net
127.0.0.1 www.topsecuritysite.net
127.0.0.1 bestsafetyguide.net
127.0.0.1 www.bestsafetyguide.net
127.0.0.1 searchweb2.com
127.0.0.1 www.searchweb2.com
127.0.0.1 www.lop.com
127.0.0.1 vidscodec.com
127.0.0.1 www.vidscodec.com
127.0.0.1 newvidscodec.net
127.0.0.1 www.newvidscodec.net
127.0.0.1 media-codec.net
127.0.0.1 www.media-codec.net
127.0.0.1 mediacodec.net
127.0.0.1 www.mediacodec.net
127.0.0.1 imediacodec.com
127.0.0.1 www.imediacodec.com
127.0.0.1 emcodec.com
127.0.0.1 www.emcodec.com
127.0.0.1 vicodec.com
127.0.0.1 www.vicodec.com
127.0.0.1 xpasswordmanager.com
127.0.0.1 www.xpasswordmanager.com
127.0.0.1 cracks4all.com
127.0.0.1 www.cracks4all.com
127.0.0.1 media-motor.net
127.0.0.1 mmm.media-motor.net
127.0.0.1 bins.media-motor.net
127.0.0.1 bins2.media-motor.net
127.0.0.1 logs.media-motor.net
127.0.0.1 mmohsix.com
127.0.0.1 www.mmohsix.com
127.0.0.1 pops.mmohsix.com
127.0.0.1 megalocast.net
127.0.0.1 js.megalocast.net
127.0.0.1 www.megalocast.net
127.0.0.1 dl.web-nexus.net
127.0.0.1 movies-etc.com
127.0.0.1 cdn.movies-etc.com
127.0.0.1 cdn2.movies-etc.com
127.0.0.1 internet-optimizer.com
127.0.0.1 www.internet-optimizer.com
127.0.0.1 888.com
127.0.0.1 www.888.com
127.0.0.1 images.888.com
127.0.0.1 surfsidekick.com
127.0.0.1 www.surfsidekick.com
127.0.0.1 sdl.surfsidekick.com
127.0.0.1 kmpads.com
127.0.0.1 www.kmpads.com
127.0.0.1 ads.kmpads.com
127.0.0.1 zipcodec.com
127.0.0.1 www.zipcodec.com
127.0.0.1 ibankis.org
127.0.0.1 www.ibankis.org
127.0.0.1 adwarefinder.com
127.0.0.1 www.adwarefinder.com
127.0.0.1 nbcsearch.com
12
le rapport smidfraudfix:
SmitFraudFix v2.161
Rapport fait à 19:00:50.20, 30.03.2007
Executé à partir de C:\Mes t‚l‚chargements\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Le type du système de fichiers est NTFS
Fix executé en mode sans echec
»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus
»»»»»»»»»»»»»»»»»»»»»»»» hosts
127.0.0.1 babe.the-killer.bz
127.0.0.1 www.babe.the-killer.bz
127.0.0.1 babe.k-lined.com
127.0.0.1 www.babe.k-lined.com
127.0.0.1 did.i-used.cc
127.0.0.1 www.did.i-used.cc
127.0.0.1 coolwwwsearch.com
127.0.0.1 www.coolwwwsearch.com
127.0.0.1 coolwebsearch.com
127.0.0.1 www.coolwebsearch.com
127.0.0.1 hi.studioaperto.net
127.0.0.1 www.hi.studioaperto.net
127.0.0.1 webbrowser.tv
127.0.0.1 www.webbrowser.tv
127.0.0.1 wazzupnet.com
127.0.0.1 www.wazzupnet.com
127.0.0.1 gueb.com
127.0.0.1 www.gueb.com
127.0.0.1 kabex.com
127.0.0.1 www.kabex.com
127.0.0.1 hityou.com
127.0.0.1 www.hityou.com
127.0.0.1 miosearch.com
127.0.0.1 www.miosearch.com
127.0.0.1 213.131.225.2
127.0.0.1 blue-elefant.com
127.0.0.1 www.blue-elefant.com
127.0.0.1 babeweb.de
127.0.0.1 www.babeweb.de
127.0.0.1 start-seite.com
127.0.0.1 www.start-seite.com
127.0.0.1 sexolymp.com
127.0.0.1 www.sexolymp.com
127.0.0.1 toriii.cc
127.0.0.1 www.toriii.cc
127.0.0.1 xtipp.de
127.0.0.1 www.xtipp.de
127.0.0.1 urawa.cool.ne.jp
127.0.0.1 777search.com
127.0.0.1 www.777search.com
127.0.0.1 ace-webmaster.com
127.0.0.1 www.ace-webmaster.com
127.0.0.1 aifind.info
127.0.0.1 www.aifind.info
127.0.0.1 amateurliveshow.com
127.0.0.1 www.amateurliveshow.com
127.0.0.1 anarchylolita.com
127.0.0.1 www.anarchylolita.com
127.0.0.1 anarchyporn.com
127.0.0.1 approvedlinks.com
127.0.0.1 www.approvedlinks.com
127.0.0.1 cantfind.com
127.0.0.1 www.cantfind.com
127.0.0.1 castingsamateur.com
127.0.0.1 www.castingsamateur.com
127.0.0.1 cyberrape.com
127.0.0.1 www.cyberrape.com
127.0.0.1 dialerclub.com
127.0.0.1 www.dialerclub.com
127.0.0.1 megago.com
127.0.0.1 exit.megago.com
127.0.0.1 www.megago.com
127.0.0.1 fastmetasearch.com
127.0.0.1 www.fastmetasearch.com
127.0.0.1 findwhatevernow.com
127.0.0.1 www.findwhatevernow.com
127.0.0.1 globesearch.com
127.0.0.1 www.globesearch.com
127.0.0.1 hotfreebies.com
127.0.0.1 www.hotfreebies.com
127.0.0.1 krankin.com
127.0.0.1 www.krankin.com
127.0.0.1 begin2search.com
127.0.0.1 www.begin2search.com
127.0.0.1 mainstreamdollars.com
127.0.0.1 www.mainstreamdollars.com
127.0.0.1 live.sex-explorer.com
127.0.0.1 www.live.sex-explorer.com
127.0.0.1 loveadot.com
127.0.0.1 www.loveadot.com
127.0.0.1 megaseek.net
127.0.0.1 www.megaseek.net
127.0.0.1 mixsearch.com
127.0.0.1 www.mixsearch.com
127.0.0.1 munky.com
127.0.0.1 www.munky.com
127.0.0.1 newtopsites.com
127.0.0.1 www.newtopsites.com
127.0.0.1 noblindlinks.com
127.0.0.1 www.noblindlinks.com
127.0.0.1 babenet.com
127.0.0.1 r.babenet.com
127.0.0.1 www.babenet.com
127.0.0.1 searchresult.net
127.0.0.1 www.searchresult.net
127.0.0.1 sexarena.org
127.0.0.1 www.sexarena.org
127.0.0.1 skeech.com
127.0.0.1 www.skeech.com
127.0.0.1 by.ru
127.0.0.1 www.by.ru
127.0.0.1 superwp.by.ru
127.0.0.1 sureseeker.com
127.0.0.1 www.sureseeker.com
127.0.0.1 wethere.com
127.0.0.1 www.wethere.com
127.0.0.1 wowsearch.org
127.0.0.1 www.wowsearch.org
127.0.0.1 xxx.com
127.0.0.1 www.xxx.com
127.0.0.1 art-xxx.com
127.0.0.1 websearch.com
127.0.0.1 www.websearch.com
127.0.0.1 firehunt.com
127.0.0.1 www.firehunt.com
127.0.0.1 partner23.firehunt.com
127.0.0.1 screensaver.it
127.0.0.1 www.screensaver.it
127.0.0.1 cliks.org
127.0.0.1 www.cliks.org
127.0.0.1 xads.cliks.org
127.0.0.1 xwebsearch.biz
127.0.0.1 www.xwebsearch.biz
127.0.0.1 znext.com
127.0.0.1 www.znext.com
127.0.0.1 rawtocash.net
127.0.0.1 www.rawtocash.net
127.0.0.1 7search.com
127.0.0.1 www.7search.com
127.0.0.1 zestyfind.com
127.0.0.1 www.zestyfind.com
127.0.0.1 ntcor.com
127.0.0.1 www.ntcor.com
127.0.0.1 dev.ntcor.com
127.0.0.1 xrenoder.com
127.0.0.1 www.xrenoder.com
127.0.0.1 search.xrenoder.com
127.0.0.1 193.125.201.50
127.0.0.1 allcybersearch.com
127.0.0.1 www.allcybersearch.com
127.0.0.1 tinybar.com
127.0.0.1 www.tinybar.com
127.0.0.1 topsite.us
127.0.0.1 www.topsite.us
127.0.0.1 topsites.us
127.0.0.1 www.topsites.us
127.0.0.1 topsitez.us
127.0.0.1 www.topsitez.us
127.0.0.1 true-counter.com
127.0.0.1 www.true-counter.com
127.0.0.1 out.true-counter.com
127.0.0.1 cnetadd.com
127.0.0.1 www.cnetadd.com
127.0.0.1 okmmm.com
127.0.0.1 www.okmmm.com
127.0.0.1 139mm.com
127.0.0.1 www.139mm.com
127.0.0.1 008k.com
127.0.0.1 www.008k.com
127.0.0.1 00hq.com
127.0.0.1 www.00hq.com
127.0.0.1 1-domains-registrations.com
127.0.0.1 www.1-domains-registrations.com
127.0.0.1 100sexlinks.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 157.238.62.14
127.0.0.1 1sexparty.com
127.0.0.1 www.1sexparty.com
127.0.0.1 1stpagehere.com
127.0.0.1 www.1stpagehere.com
127.0.0.1 2020search.com
127.0.0.1 www.2020search.com
127.0.0.1 209.66.114.130
127.0.0.1 24teen.com
127.0.0.1 www.24teen.com
127.0.0.1 36site.com
127.0.0.1 www.36site.com
127.0.0.1 4corn.net
127.0.0.1 www.4corn.net
127.0.0.1 66.117.14.138
127.0.0.1 66.197.100.83
127.0.0.1 66.250.107.99
127.0.0.1 66.250.107.100
127.0.0.1 66.250.107.101
127.0.0.1 66.250.130.194
127.0.0.1 66.250.170.107
127.0.0.1 66.250.57.26
127.0.0.1 66.250.57.27
127.0.0.1 66.250.57.28
127.0.0.1 66.250.74.150
127.0.0.1 777top.com
127.0.0.1 www.777top.com
127.0.0.1 8ad.com
127.0.0.1 www.8ad.com
127.0.0.1 aboutclicker.com
127.0.0.1 www.aboutclicker.com
127.0.0.1 abrp.net
127.0.0.1 www.abrp.net
127.0.0.1 accessthefuture.net
127.0.0.1 www.accessthefuture.net
127.0.0.1 acemedic.com
127.0.0.1 www.acemedic.com
127.0.0.1 actionbreastcancer.org
127.0.0.1 www.actionbreastcancer.org
127.0.0.1 activexupdate.com
127.0.0.1 www.activexupdate.com
127.0.0.1 adamsupportgroup.org
127.0.0.1 www.adamsupportgroup.org
127.0.0.1 adasearch.com
127.0.0.1 www.adasearch.com
127.0.0.1 adipics.com
127.0.0.1 www.adipics.com
127.0.0.1 adspics.com
127.0.0.1 www.adspics.com
127.0.0.1 adult-engine-search.com
127.0.0.1 www.adult-engine-search.com
127.0.0.1 adult-erotic-guide.net
127.0.0.1 www.adult-erotic-guide.net
127.0.0.1 adult-friends-finder.net
127.0.0.1 www.adult-friends-finder.net
127.0.0.1 adulthyperlinks.com
127.0.0.1 www.adulthyperlinks.com
127.0.0.1 adulttds.com
127.0.0.1 www.adulttds.com
127.0.0.1 exaccess.ru
127.0.0.1 www.exaccess.ru
127.0.0.1 advert.exaccess.ru
127.0.0.1 agentstudio.com
127.0.0.1 africaspromise.org
127.0.0.1 akril.com
127.0.0.1 alcatel.ws
127.0.0.1 alfa-search.com
127.0.0.1 all-inet.com
127.0.0.1 allabtcars.com
127.0.0.1 allabtjeeps.com
127.0.0.1 allhyperlinks.com
127.0.0.1 allinternetbusiness.com
127.0.0.1 almarvideos.com
127.0.0.1 amandamountains.com
127.0.0.1 amigeek.com
127.0.0.1 amisbusiness.com
127.0.0.1 analmovi.com
127.0.0.1 anin.org
127.0.0.1 annaromeo.com
127.0.0.1 antrocity.com
127.0.0.1 anything4health.com
127.0.0.1 apsua.com
127.0.0.1 aregay.com
127.0.0.1 arheo.com
127.0.0.1 arizonaweb.org
127.0.0.1 armitageinn.com
127.0.0.1 art-func.com
127.0.0.1 artachnid.com
127.0.0.1 asiankingkong.com
127.0.0.1 ass-gals.com
127.0.0.1 athenrye.com
127.0.0.1 avian-ads.com
127.0.0.1 ayakawamura.com
127.0.0.1 ayumitaniguchi.com
127.0.0.1 bannedhost.net
127.0.0.1 barbudafarms.com
127.0.0.1 barnandfence.com
127.0.0.1 batsearch.com
127.0.0.1 baygraphicsllc.com
127.0.0.1 bb-search.com
127.0.0.1 bbbsearch.com
127.0.0.1 bedhome.com
127.0.0.1 bediadance.com
127.0.0.1 bellabasketsfl.com
127.0.0.1 bernaolatwin.com
127.0.0.1 best-counter.com
127.0.0.1 best-hardpics.com
127.0.0.1 best-winning-casino.com
127.0.0.1 bestcrawler.com
127.0.0.1 bestfor.ru
127.0.0.1 bestporngate.com
127.0.0.1 bestxporno.com
127.0.0.1 blackjack-free.net
127.0.0.1 blender.xu.pl
127.0.0.1 bodaciousbabette.com
127.0.0.1 boobdoll.com
127.0.0.1 boobsandtits.com
127.0.0.1 boobsclub.com
127.0.0.1 boredlife.com
127.0.0.1 bowlofogumbo.com
127.0.0.1 bradcoem.org
127.0.0.1 brandiyoung.com
127.0.0.1 brookeburn.com
127.0.0.1 bucps.com
127.0.0.1 burgerkingbigscreen.com
127.0.0.1 buscards.net
127.0.0.1 bustyrussell.com
127.0.0.1 buttejazz.org
127.0.0.1 buyselldomain.net
127.0.0.1 calcioturris.com
127.0.0.1 canberracricketcoaching.com
127.0.0.1 candycantaloupes.com
127.0.0.1 careers.dulcineasystems.net
127.0.0.1 carsands.com
127.0.0.1 carsrentals.net
127.0.0.1 casino-gambling-1.net
127.0.0.1 casino-gambling-2.net
127.0.0.1 casino-onlines.net
127.0.0.1 casino.com.free.game.pogo.gratisdownloads.nl
127.0.0.1 casino2win.net
127.0.0.1 casinomidas.net
127.0.0.1 casinonline.net
127.0.0.1 catallogue.com
127.0.0.1 catsss.da.ru
127.0.0.1 caxa.ru
127.0.0.1 cclebali.org
127.0.0.1 ceewawires.org
127.0.0.1 certumgroup.com
127.0.0.1 chelancatering.com
127.0.0.1 childrenvilla.com
127.0.0.1 chips-4-free.com
127.0.0.1 chrisswasey.com
127.0.0.1 chriswallace.net
127.0.0.1 ckick4thumbs.com
127.0.0.1 clackamasliteraryreview.com
127.0.0.1 clearsearch.cc
127.0.0.1 clearsearch.net
127.0.0.1 clickaire.com
127.0.0.1 clickyestoenter.net
127.0.0.1 clrsch.com
127.0.0.1 cmtapestry.com
127.0.0.1 cool-homepage.co
127.0.0.1 cool-homepage.com
127.0.0.1 cool-search.net
127.0.0.1 cool-search.netfartpost.com
127.0.0.1 cool-web-search.com
127.0.0.1 coolfetishsite.com
127.0.0.1 coolfreehost.com
127.0.0.1 coolfreepage.com
127.0.0.1 coolfreepages.com
127.0.0.1 coolmoneysearch.com
127.0.0.1 coolpornsearch.com
127.0.0.1 coolsearcher.info
127.0.0.1 coolwebsearsh.com
127.0.0.1 copmtraine.com
127.0.0.1 couldnotfind.com
127.0.0.1 count-all.com
127.0.0.1 cracks.me.uk
127.0.0.1 creamedcutties.com
127.0.0.1 creditsearchonline.com
127.0.0.1 crestring.com
127.0.0.1 crooder.com
127.0.0.1 curvedspaces.com
127.0.0.1 cvs.jps.ru
127.0.0.1 cvsymphony.com
127.0.0.1 cydom.com
127.0.0.1 daily-gals.com
127.0.0.1 dancingbabycd.com
127.0.0.1 datanotary.com
127.0.0.1 datareco.com
127.0.0.1 davemarshall.org
127.0.0.1 dcfitusa.com
127.0.0.1 defaultsearch.net
127.0.0.1 desarrollocreativo.com
127.0.0.1 develip.com
127.0.0.1 dewis.spb.ru
127.0.0.1 dewis.us
127.0.0.1 df809jow4wj2304lfd0sf9fsd0a2t4ldf809jow4wj2304lfd0sf9fsd0a2t4ld.biz
127.0.0.1 dietpills4free.com
127.0.0.1 dietpussy.com
127.0.0.1 digistreamsa.com
127.0.0.1 dionforvalleycouncil.org
127.0.0.1 doctorwaldron.com
127.0.0.1 document-not-found.pornpic.org
127.0.0.1 doggyaction.com
127.0.0.1 domain-your-registration.com
127.0.0.1 domains-for-you-online.com
127.0.0.1 domains2003.net
127.0.0.1 domkrat.com
127.0.0.1 dp-host.com
127.0.0.1 dragqueen.gay-clan.com
127.0.0.1 drug-sources-exposed.com
127.0.0.1 drvvv.com
127.0.0.1 dutch-sex.com
127.0.0.1 dvdbank.org
127.0.0.1 e-localad.com
127.0.0.1 e-plus.cc
127.0.0.1 e-websitesolutions.com
127.0.0.1 eases.net
127.0.0.1 easy-search.net
127.0.0.1 easycategories.com
127.0.0.1 ecosrioplatenses.org
127.0.0.1 ecstasyporn.net
127.0.0.1 eikokoike.com
127.0.0.1 epornsex.com
127.0.0.1 euuu.com
127.0.0.1 evidence-detector.biz
127.0.0.1 evilspidercomics.com
127.0.0.1 ewebsearch.net
127.0.0.1 findloss.com
127.0.0.1 excellentsckin.com
127.0.0.1 extremeseek.net
127.0.0.1 f*ckdenniss.com
127.0.0.1 f*cknicepics.com
127.0.0.1 faithstevens.com
127.0.0.1 fantasiewelten.com
127.0.0.1 farmsteadbandb.com
127.0.0.1 fartpost.com
127.0.0.1 fastwebfinder.com
127.0.0.1 faxporn.com
127.0.0.1 fickenisgeil.de
127.0.0.1 finance-loans.com
127.0.0.1 find-itnow.com
127.0.0.1 find-uk-health.co.uk
127.0.0.1 find4u.net
127.0.0.1 findit-now.com
127.0.0.1 findthesite.com
127.0.0.1 findthewebsiteyouneed.com
127.0.0.1 www.findthewebsiteyouneed.com
127.0.0.1 fionasteel.com
127.0.0.1 firstbookmark.net
127.0.0.1 fitness-free.com
127.0.0.1 foodvacations.net
127.0.0.1 forex.jps.ru
127.0.0.1 forexcredit.com
127.0.0.1 forexcredit.ru
127.0.0.1 formingfusions.com
127.0.0.1 forsythfire.net
127.0.0.1 forthline.com
127.0.0.1 free-chipes.com
127.0.0.1 free-f*cking-video.com
127.0.0.1 free-hit.com
127.0.0.1 free-pics-and-movies.com
127.0.0.1 free-sex-movie-clips.net
127.0.0.1 free4porno.net
127.0.0.1 free64all.com
127.0.0.1 freebookmark.net
127.0.0.1 freebookmarks.net
127.0.0.1 freecategories.com
127.0.0.1 freecoolhost.com
127.0.0.1 freerbhost.com
127.0.0.1 freeshemalepics.net
127.0.0.1 freeyaho.com
127.0.0.1 freshseek.com
127.0.0.1 freshteensite.com
127.0.0.1 gabrielscott.com
127.0.0.1 galpostgirls.com
127.0.0.1 gals-for-free.com
127.0.0.1 gambling-online4you.com
127.0.0.1 gameterror.net
127.0.0.1 gay50.com
127.0.0.1 generalsmeltingofcanada.com
127.0.0.1 geteens.com
127.0.0.1 getpicshere.com
127.0.0.1 gimmezamore.com
127.0.0.1 gimnasiaer.com
127.0.0.1 girls-porn-life.com
127.0.0.1 glbdf.org
127.0.0.1 global-finder.com
127.0.0.1 globe-finder.cc
127.0.0.1 globe-finder.com
127.0.0.1 gocybersearch.com
127.0.0.1 golftennis.net
127.0.0.1 good-mortgages-calculator.com
127.0.0.1 good-mortgages.net
127.0.0.1 goodsexs.com
127.0.0.1 googlebar.jps.ru
127.0.0.1 googlf.com
127.0.0.1 gradforum.org
127.0.0.1 gratis-porn-movie.com
127.0.0.1 gratis-pornopics.com
127.0.0.1 guzzycats.com
127.0.0.1 gzphoenix.com
127.0.0.1 hallnetaccolade.com
127.0.0.1 hand-book.com
127.0.0.1 happyanal.com
127.0.0.1 hard-gals.com
127.0.0.1 hardbodytgp.com
127.0.0.1 hardcoreover.com
127.0.0.1 hardloved.com
127.0.0.1 hardwareseek.net
127.0.0.1 harukaigawa.com
127.0.0.1 hccsolanonapa.org
127.0.0.1 health-protein.com
127.0.0.1 hentai4u.net
127.0.0.1 here4search.com
127.0.0.1 heyrichy.com
127.0.0.1 hi-search.com
127.0.0.1 hiddenguides.com
127.0.0.1 hitlistlyrics.com
127.0.0.1 holidayautostr.com
127.0.0.1 homemortage.ws
127.0.0.1 hostssp.com
127.0.0.1 hot-cartoon-sex.anime.american-teens.net
127.0.0.1 hotbookmark.com
127.0.0.1 hotels-list.net
127.0.0.1 hotelxxxcams.com
127.0.0.1 hotpopup.com
127.0.0.1 hotsearchbox.com
127.0.0.1 hotsex-series.com
127.0.0.1 hotstartpage.com
127.0.0.1 hqsex.biz
127.0.0.1 hugeporn4u.net
127.0.0.1 hunacsa.com
127.0.0.1 hupacasath.com
127.0.0.1 hzsx.com
127.0.0.1 icansearch.net
127.0.0.1 idgsearch.com
127.0.0.1 ie-search.com
127.0.0.1 incestporngate.com
127.0.0.1 infodigger.net
127.0.0.1 infoglobus.com
127.0.0.1 inherhole.com
127.0.0.1 insertthiscock.com
127.0.0.1 insurance-flood.net
127.0.0.1 insuranceall.net
127.0.0.1 internetsearch.ru
127.0.0.1 ionichost.com
127.0.0.1 ionomist.com
127.0.0.1 ipsex.net
127.0.0.1 itsanal.com
127.0.0.1 itseasy.us
127.0.0.1 iweb-commerce.com
127.0.0.1 iwebland.com
127.0.0.1 jeannineoldfield.com
127.0.0.1 jethomepage.com
127.0.0.1 jetseeker.com
127.0.0.1 jmhgallery.org
127.0.0.1 joannelatham.com
127.0.0.1 judin.ru
127.0.0.1 junkysex.com
127.0.0.1 karleyt.narod.ru
127.0.0.1 kathisomers.com
127.0.0.1 kazaa-lite.ws
127.0.0.1 keithgreenpro.com
127.0.0.1 kenmccaul.com
127.0.0.1 kilosex.com
127.0.0.1 kimhines.com
127.0.0.1 kinoru.com
127.0.0.1 ksdspups.org
127.0.0.1 landrape.com
127.0.0.1 lauraroebuck.com
127.0.0.1 leannalovelace.com
127.0.0.1 lesobank.ru
127.0.0.1 libertyonlinehosting.com
127.0.0.1 lingerie-mania.com
127.0.0.1 lisamatthew.com
127.0.0.1 liveholio.com
127.0.0.1 livenewspaper.com
127.0.0.1 louiseleeds.com
127.0.0.1 love-pix.com
127.0.0.1 lovelas.com
127.0.0.1 lovelysearch.com
127.0.0.1 low-taxes.com
127.0.0.1 luckysearch.net
127.0.0.1 lunitaweb.net
127.0.0.1 lustful-porno.com
127.0.0.1 mackinnonsbrook.org
127.0.0.1 madfinder.com
127.0.0.1 madisonmoons.com
127.0.0.1 madisonoilco.com
127.0.0.1 madonalive.com
127.0.0.1 majuozawa.com
127.0.0.1 makin-do.com
127.0.0.1 male4free.com
127.0.0.1 map-quest.org
127.0.0.1 marilynchamber.com
127.0.0.1 martfinder.com
127.0.0.1 massearch.com
127.0.0.1 matetrava.com
127.0.0.1 mature50.com
127.0.0.1 matureporngate.com
127.0.0.1 maxdzines.com
127.0.0.1 mcgeeforlabor.com
127.0.0.1 mdstunisie.org
127.0.0.1 medicare-insurance.net
127.0.0.1 medicare-supplemental.com
127.0.0.1 mega-dating-tips.com
127.0.0.1 megumikanzaki.com
127.0.0.1 meshalynn.com
127.0.0.1 meta-adult.com
127.0.0.1 meta-casino.com
127.0.0.1 meta-mobile.com
127.0.0.1 meta-porn.com
127.0.0.1 metafora.ru
127.0.0.1 metapoisk.ru
127.0.0.1 michiyonakajima.com
127.0.0.1 miconsultamedica.com
127.0.0.1 mikasakamoto.com
127.0.0.1 mikoni.com
127.0.0.1 militarygods.porn4porn.net
127.0.0.1 millennialpeople.org
127.0.0.1 mipham.org
127.0.0.1 missingcommand.com
127.0.0.1 mommykiss.com
127.0.0.1 moneyhunters.com
127.0.0.1 montgomeryhospitalanesthesia.com
127.0.0.1 morflot.com
127.0.0.1 mortgage-debt.net
127.0.0.1 mortismaximus.com
127.0.0.1 moscowwhores.com
127.0.0.1 moviecategories.com
127.0.0.1 mp3-pix.com
127.0.0.1 mrtg.jps.ru
127.0.0.1 msn-info.net
127.0.0.1 multipussy.com
127.0.0.1 mundopolar.com
127.0.0.1 mustv.com
127.0.0.1 mywebsearch.net
127.0.0.1 nativehardcore.com
127.0.0.1 naturalspy.com
127.0.0.1 nbasportsbook.net
127.0.0.1 needf*cknow.com
127.0.0.1 nellyslyrics.com
127.0.0.1 nepgyan.com
127.0.0.1 nesrecords.com
127.0.0.1 netshastra.net
127.0.0.1 nettime.ru
127.0.0.1 nettracker.jps.ru
127.0.0.1 netyellowpages.info
127.0.0.1 new-incest.com
127.0.0.1 newcategories.com
127.0.0.1 newcracks.com
127.0.0.1 newcracks.net
127.0.0.1 newlife-lajolla.com
127.0.0.1 newsexgate.com
127.0.0.1 newtonsracks.com
127.0.0.1 newxpics.com
127.0.0.1 nhlsportsbook.net
127.0.0.1 niagaracapital.com
127.0.0.1 niche-tv.com
127.0.0.1 nmrba.com
127.0.0.1 nocalories.net
127.0.0.1 nocensor.com
127.0.0.1 ormandcompany.com
127.0.0.1 nsbabes.com
127.0.0.1 nuclearwitness.org
127.0.0.1 nursemania.com
127.0.0.1 nvntour.com
127.0.0.1 nvphall.org
127.0.0.1 oborot.com
127.0.0.1 ocalalivestockmarket.com
127.0.0.1 ocsff.com
127.0.0.1 oeatlanta.com
127.0.0.1 oharrowsearch.com
127.0.0.1 ok-search.com
127.0.0.1 okulta.com
127.0.0.1 omegabrains.net
127.0.0.1 online-casino-1.net
127.0.0.1 online-casino-bonus.info
127.0.0.1 online-casinos-x.com
127.0.0.1 online-winning.net
127.0.0.1 onlineserverz.com
127.0.0.1 onlinetradings.net
127.0.0.1 onlycunt.com
127.0.0.1 onlyinsured.com
127.0.0.1 operanabuco.com
127.0.0.1 opsex.com
127.0.0.1 oregoncharters.org
127.0.0.1 otrlives.com
127.0.0.1 ozawamadoka.com
127.0.0.1 paigesummer.com
127.0.0.1 pamelacollections.com
127.0.0.1 panamcup.com
127.0.0.1 pantygirls4u.com
127.0.0.1 pantyhoserealm.com
127.0.0.1 pantyplace.com
127.0.0.1 pastubes.com
127.0.0.1 paulapage.com
127.0.0.1 paulhoover.com
127.0.0.1 payfortraffic.net
127.0.0.1 pedo.ws
127.0.0.1 people.1gb.ru
127.0.0.1 pervertbot.com
127.0.0.1 pharma-diet-pills.com
127.0.0.1 pharmacy2003.com
127.0.0.1 pharmalocator.com
127.0.0.1 phendimetrazine-tenuate-adipex.com
127.0.0.1 pics-videos.com
127.0.0.1 picsdir.com
127.0.0.1 picsforbucks.com
127.0.0.1 picsofseductiveladies.com
127.0.0.1 pills-birth-control.com
127.0.0.1 pillsmall.com
127.0.0.1 pilotronix.com
127.0.0.1 pixpox.com
127.0.0.1 planemusic.com
127.0.0.1 poiska.net
127.0.0.1 poker-casino-free.com
127.0.0.1 poker-games-free.net
127.0.0.1 polradiologia.com
127.0.0.1 pooi.net
127.0.0.1 porn-teacher.com
127.0.0.1 porncamz.com
127.0.0.1 pornfree.info
127.0.0.1 pornnightdreams.com
127.0.0.1 pornokopec.com
127.0.0.1 porntetris.com
127.0.0.1 porntwist.com
127.0.0.1 powerwebsearch.com
127.0.0.1 prblitz.com
127.0.0.1 pretypics.com
127.0.0.1 pribalt.com
127.0.0.1 privacy-support.biz
127.0.0.1 privateporn.net
127.0.0.1 prostactive.com
127.0.0.1 prostol.com
127.0.0.1 protect-yourself.biz
127.0.0.1 prsainlandempire.org
127.0.0.1 put-your-link-here.com
127.0.0.1 pyrocorp.com
127.0.0.1 quick-search.ws
127.0.0.1 quiksearchgenealogy.com
127.0.0.1 radfrall.org
127.0.0.1 ramgo.com
127.0.0.1 ranafrog.ne
127.0.0.1 rapegate.com
127.0.0.1 redbudbmx.com
127.0.0.1 refinance-help.com
127.0.0.1 removeearthkeepers.org
127.0.0.1 rightfinder.net
127.0.0.1 robbsproshop.com
127.0.0.1 robertferencz.com
127.0.0.1 rotocasters.com
127.0.0.1 royalsearch.net
127.0.0.1 runsearch.com
127.0.0.1 russiansponsor.com
127.0.0.1 russogay.com
127.0.0.1 s2.exocrew.com
127.0.0.1 sacitylife.com
127.0.0.1 samplegals.com
127.0.0.1 satisf*cktion.net
127.0.0.1 sbssurvivor.com
127.0.0.1 scarypix.com
127.0.0.1 sccdnet.com
127.0.0.1 schoolforest.com
127.0.0.1 search-1.net
127.0.0.1 search-2003.com
127.0.0.1 search-about.net
127.0.0.1 search-hawk.com
127.0.0.1 search-log.com
127.0.0.1 search-meta.com
127.0.0.1 search-safe.com
127.0.0.1 search.psn.cn
127.0.0.1 searchadultweb.com
127.0.0.1 searchbutler.com
127.0.0.1 searchbuttler.com
127.0.0.1 searchbutler.org
127.0.0.1 searchcomplete.com
127.0.0.1 searchdesire.com
127.0.0.1 searchdot.net
127.0.0.1 searchexpander.com
127.0.0.1 searchfastnet.com
127.0.0.1 searchforge.com
127.0.0.1 searching-the-net.com
127.0.0.1 searchmeta.md
127.0.0.1 searchmeta.net
127.0.0.1 searchmeta.ru
127.0.0.1 searchmeta.webhost.ru
127.0.0.1 searchnow.ws
127.0.0.1 searchonfly.com
127.0.0.1 searchv.com
127.0.0.1 searchxl.com
127.0.0.1 searchxp.com
127.0.0.1 sebot.com
127.0.0.1 securenp.org
127.0.0.1 security-warning.biz
127.0.0.1 seehardcore.com
127.0.0.1 seekwell.net
127.0.0.1 selfbookmark.com
127.0.0.1 selfbookmark.info
127.0.0.1 selfbookmark.net
127.0.0.1 sex.free4porno.net
127.0.0.1 sex-coach.com
127.0.0.1 sex-festival.com
127.0.0.1 sex-video-galleries.com
127.0.0.1 sexgalleries4all.com
127.0.0.1 sexmoviesnet.com
127.0.0.1 sexpatriot.net
127.0.0.1 sexy18.cc
127.0.0.1 sexycat.adult-host.org
127.0.0.1 sfbayfolkboats.com
127.0.0.1 sgirls.net
127.0.0.1 sharempeg.com
127.0.0.1 shopcards.net
127.0.0.1 shopknights.com
127.0.0.1 sic02.com
127.0.0.1 sintrader.com
127.0.0.1 site1.ru
127.0.0.1 sites-in-web.com
127.0.0.1 sitevictoria.com
127.0.0.1 sixroads.com
127.0.0.1 skakalka.ru
127.0.0.1 slawsearch.com
127.0.0.1 slotch.com
127.0.0.1 slotchbar.com
127.0.0.1 smartsumo.com
127.0.0.1 smutarchive.net
127.0.0.1 solongas.com
127.0.0.1 sonomaevents.com
127.0.0.1 spermatrix.com
127.0.0.1 sportbooks-free4you.com
127.0.0.1 spros.com
127.0.0.1 spyass.com
127.0.0.1 spyorgy.net
127.0.0.1 staceyowens.com
127.0.0.1 stacistaxx.com
127.0.0.1 stacystaxx.com
127.0.0.1 start-space.com
127.0.0.1 steamycock.com
127.0.0.1 sterva.com
127.0.0.1 stevecashdollar.com
127.0.0.1 stop-tracking.biz
127.0.0.1 stopvotefraud.com
127.0.0.1 stopxxxpics.com
127.0.0.1 strekoza.com
127.0.0.1 stuffstore.com
127.0.0.1 styleclickink.com
127.0.0.1 summercollins.com
127.0.0.1 summitcross.com
127.0.0.1 super-spider.com
127.0.0.1 super-websearch.com
127.0.0.1 supersexmachine.com
127.0.0.1 superwebsearch.com
127.0.0.1 supret.com
127.0.0.1 suzannebrecht.com
127.0.0.1 sweeteenz.com
127.0.0.1 tacil.org
127.0.0.1 tangounion.com
127.0.0.1 tastethemusic.com
127.0.0.1 tax-refund4you.com
127.0.0.1 tech-jobs.ws
127.0.0.1 technology-related.com
127.0.0.1 teen-biz.com
127.0.0.1 teen-pic-post.com
127.0.0.1 teenpornosex.com
127.0.0.1 teens4free.net
127.0.0.1 teensact.com
127.0.0.1 teensgate.com
127.0.0.1 teensguru.com
127.0.0.1 teenswamp.com
127.0.0.1 testosterone-birth-control.com
127.0.0.1 the-exit.com
127.0.0.1 the-huns-yellow-pages.com
127.0.0.1 thefakejournal.com
127.0.0.1 thehuy.net
127.0.0.1 theproxy.org
127.0.0.1 therealsearch.com
127.0.0.1 thesten.com
127.0.0.1 thornleygroup.com
127.0.0.1 tings.org
127.0.0.1 tit-x.com
127.0.0.1 titanvision.com
127.0.0.1 titsianna.com
127.0.0.1 toddhayes.com
127.0.0.1 toon-comics.com
127.0.0.1 tooncomics.com
127.0.0.1 topsearcher.com
127.0.0.1 trafficback.com
127.0.0.1 trafficswitcher.com
127.0.0.1 travel.picture-posters.com
127.0.0.1 true-portal.com
127.0.0.1 trytechnical.com
127.0.0.1 ufindall.click-now.net
127.0.0.1 umaxsearch.com
127.0.0.1 une-autre-france.com
127.0.0.1 unigays.com
127.0.0.1 unipages.cc
127.0.0.1 up2you.ru
127.0.0.1 urlstat.com
127.0.0.1 urlstat.ru
127.0.0.1 uralitel.ru
127.0.0.1 ursie.net
127.0.0.1 utahsweet.com
127.0.0.1 utopicportal.com
127.0.0.1 uusocialjustice.org
127.0.0.1 v61.com
127.0.0.1 vaginpics.com
127.0.0.1 valmyers.com
127.0.0.1 vegas-free.com
127.0.0.1 vegbuy.com
127.0.0.1 veloventures.com
127.0.0.1 verzila.com
127.0.0.1 victoriaadam.com
127.0.0.1 videocategories.com
127.0.0.1 vitamins-for-each.com
127.0.0.1 votehowe.org
127.0.0.1 vxebony.com
127.0.0.1 wakeupdick.com
127.0.0.1 warnomore.org
127.0.0.1 watersport-specialties.com
127.0.0.1 web-homepage.net
127.0.0.1 web-search.tk
127.0.0.1 webcoolsearch.com
127.0.0.1 websearchdot.com
127.0.0.1 weekend-movies.com
127.0.0.1 wetpornostars.com
127.0.0.1 whatsyoursearch.com
127.0.0.1 white-pages.ws
127.0.0.1 whittierblvd.com
127.0.0.1 win-in-casino.com
127.0.0.1 wiresearch.com
127.0.0.1 wolfpacracing.com
127.0.0.1 wordlist.jps.ru
127.0.0.1 wpc2001.org
127.0.0.1 wspzone.sexpornonline.com
127.0.0.1 wwwbet.net
127.0.0.1 wwwbetting.net
127.0.0.1 wwwpokergames.com
127.0.0.1 wwwpokerplayers.com
127.0.0.1 wwwroulette.net
127.0.0.1 x-library.com
127.0.0.1 x-webdesign.com
127.0.0.1 xcomics4u.com
127.0.0.1 xic-bs.com
127.0.0.1 xldr.com
127.0.0.1 xp18.com
127.0.0.1 xrenosearch.com
127.0.0.1 xtragay.com
127.0.0.1 xu.xu.pl
127.0.0.1 xxxcategories.com
127.0.0.1 xxxemailxxx.com
127.0.0.1 y-e-l-l-o-w.com
127.0.0.1 yellow500.com
127.0.0.1 yezol.com
127.0.0.1 you-search.com
127.0.0.1 you-search.com.ru
127.0.0.1 youfindall.com
127.0.0.1 youfindall.net
127.0.0.1 your-prescriptions.net
127.0.0.1 yourbookmarks.info
127.0.0.1 yourbookmarks.ws
127.0.0.1 ypir.com
127.0.0.1 ysa-info.net
127.0.0.1 yukohamano.com
127.0.0.1 ywebsearch.info
127.0.0.1 zapros.com
127.0.0.1 zesearch.com
127.0.0.1 ziportal.com
127.0.0.1 zipportal.com
127.0.0.1 zoneoffreeporn.com
127.0.0.1 zoomegasite.com
127.0.0.1 zvimigdal.com
127.0.0.1 zyban-zocor-levitra.com
127.0.0.1 t.rack.cc
127.0.0.1 omega-search.com
127.0.0.1 cool-xxx.net
127.0.0.1 revolto3.da.ru
127.0.0.1 dating-search.net
127.0.0.1 linksummary.com
127.0.0.1 duolaimi.net
127.0.0.1 ez-searching.com
127.0.0.1 freehqmovies.com
127.0.0.1 xzoomy.com
127.0.0.1 freescratchandwin.com
127.0.0.1 globalwebsearch.com
127.0.0.1 www.gocybersearch.com
127.0.0.1 mayancasino.com
127.0.0.1 www.hastalavista.com
127.0.0.1 www.free-popup-killer.com
127.0.0.1 www.digitalfan.com
127.0.0.1 google123.web1000.com
127.0.0.1 search.ieplugin.com
127.0.0.1 i-lookup.com
127.0.0.1 spidersearch.com
127.0.0.1 istarthere.com
127.0.0.1 xxxtoolbar.com
127.0.0.1 www.seekporn.org
127.0.0.1 17-plus.com
127.0.0.1 lolita4all1.xrensmagpost.com
127.0.0.1 mafiapics.com
127.0.0.1 www.teenmonster.com
127.0.0.1 ie.marketdart.com
127.0.0.1 masterbar.com
127.0.0.1 search.netzany.co
127.0.0.1 only-virgins.com
127.0.0.1 passthison.com
127.0.0.1 blondetgp.com
127.0.0.1 prolivation.com
127.0.0.1 server-au.imrworldwide.com
127.0.0.1 rocketsearch.com
127.0.0.1 .roar.com
127.0.0.1 searchaccurate.com
127.0.0.1 searchalot.com
127.0.0.1 searchandbrowse.com
127.0.0.1 gtawarehouse.com
127.0.0.1 startium.com
127.0.0.1 searchandclick.com
127.0.0.1 searchby.net
127.0.0.1 searchdot.com
127.0.0.1 search-exe.com
127.0.0.1 secret-crush.com
127.0.0.1 seekseek.com
127.0.0.1 sexarena.com
127.0.0.1 sexocean.play-lolita.com
127.0.0.1 startsurfing.com
127.0.0.1 66.197.138.235
127.0.0.1 srng.net
127.0.0.1 apps.webservicehost.com
127.0.0.1 search.shopnav.com
127.0.0.1 wish7.com
127.0.0.1 216.65.3.68
127.0.0.1 www.supersexpass.com
127.0.0.1 surferbar.com
127.0.0.1 xlola.underagehost.com
127.0.0.1 hotlolitas.underagehost.com
127.0.0.1 loading-lolita.com
127.0.0.1 www.xupiter.com
127.0.0.1 xjupiter.com
127.0.0.1 www.xjupiter.com
127.0.0.1 www.browserwise.com
127.0.0.1 sqwire.com
127.0.0.1 orbitexplorer.com
127.0.0.1 searchcentrix.com
127.0.0.1 categories.mygeek.com
127.0.0.1 web-entrance.co
127.0.0.1 whazit.com
127.0.0.1 windowenhancer.com
127.0.0.1 buz.ru
127.0.0.1 iwon.com
127.0.0.1 www.bonzi.com
127.0.0.1 featured-results.com
127.0.0.1 searchmadesafe.net
127.0.0.1 quicklaunch.com
127.0.0.1 www.cashsurfers.com
127.0.0.1 .lop.com
127.0.0.1 .tjdo.com
127.0.0.1 /tjdo.com
127.0.0.1 .ebav.com
127.0.0.1 /ebav.com
127.0.0.1 .ebgo.com
127.0.0.1 /ebgo.com
127.0.0.1 .ebaw.com
127.0.0.1 /ebaw.com
127.0.0.1 .ebkb.com
127.0.0.1 /ebkb.com
127.0.0.1 .ebmu.com
127.0.0.1 /ebmu.com
127.0.0.1 .ecmp.com
127.0.0.1 /ecmp.com
127.0.0.1 .edhq.com
127.0.0.1 /edhq.com
127.0.0.1 .edty.com
127.0.0.1 /edty.com
127.0.0.1 .sbee.com
127.0.0.1 /sbee.com
127.0.0.1 .aavc.com
127.0.0.1 /aavc.com
127.0.0.1 .acjp.com
127.0.0.1 /acjp.com
127.0.0.1 .ecmh.com
127.0.0.1 /ecmh.com
127.0.0.1 .emch.com
127.0.0.1 /emch.com
127.0.0.1 .ecpm.com
127.0.0.1 /ecpm.com
127.0.0.1 .wabu.com
127.0.0.1 /wabu.com
127.0.0.1 .wabq.com
127.0.0.1 /wabq.com
127.0.0.1 .ebch.com
127.0.0.1 /ebch.com
127.0.0.1 .ebdv.com
127.0.0.1 /ebdv.com
127.0.0.1 .ebdw.com
127.0.0.1 /ebdw.com
127.0.0.1 .ebjp.com
127.0.0.1 /ebjp.com
127.0.0.1 .ebkn.com
127.0.0.1 /ebkn.com
127.0.0.1 .ebky.com
127.0.0.1 /ebky.com
127.0.0.1 .eblv.com
127.0.0.1 /eblv.com
127.0.0.1 .wbkb.com
127.0.0.1 /wbkb.com
127.0.0.1 .ebvr.com
127.0.0.1 /ebvr.com
127.0.0.1 .ecwz.com
127.0.0.1 /ecwz.com
127.0.0.1 .ecyb.com
127.0.0.1 /ecyb.com
127.0.0.1 .eduy.com
127.0.0.1 /eduy.com
127.0.0.1 .eeev.com
127.0.0.1 /eeev.com
127.0.0.1 .farse.com
127.0.0.1 /farse.com
127.0.0.1 .ibmx.com
127.0.0.1 /ibmx.com
127.0.0.1 .icwb.com
127.0.0.1 /icwb.com
127.0.0.1 .icwo.com
127.0.0.1 /icwo.com
127.0.0.1 .icwp.com
127.0.0.1 /icwp.com
127.0.0.1 .iddh.com
127.0.0.1 /iddh.com
127.0.0.1 .idhh.com
127.0.0.1 /idhh.com
127.0.0.1 .ifiz.com
127.0.0.1 /ifiz.com
127.0.0.1 .iguu.com
127.0.0.1 /iguu.com
127.0.0.1 .samz.com
127.0.0.1 /samz.com
127.0.0.1 .saoe.com
127.0.0.1 /saoe.com
127.0.0.1 .sbjr.com
127.0.0.1 /sbjr.com
127.0.0.1 .sbnl.com
127.0.0.1 /sbnl.com
127.0.0.1 .sbnt.com
127.0.0.1 /sbnt.com
127.0.0.1 .sbvr.com
127.0.0.1 /sbvr.com
127.0.0.1 .scbm.com
127.0.0.1 /scbm.com
127.0.0.1 .sckr.com
127.0.0.1 /sckr.com
127.0.0.1 .scrk.com
127.0.0.1 /scrk.com
127.0.0.1 .sdry.com
127.0.0.1 /sdry.com
127.0.0.1 .seld.com
127.0.0.1 /seld.com
127.0.0.1 .sfux.com
127.0.0.1 /sfux.com
127.0.0.1 .sheat.com
127.0.0.1 /sheat.com
127.0.0.1 .sipo.com
127.0.0.1 /sipo.com
127.0.0.1 .smds.com
127.0.0.1 /smds.com
127.0.0.1 .srib.com
127.0.0.1 /srib.com
127.0.0.1 .srox.com
127.0.0.1 /srox.com
127.0.0.1 .srsf.com
127.0.0.1 /srsf.com
127.0.0.1 .ssaw.com
127.0.0.1 /ssaw.com
127.0.0.1 .ssby.com
127.0.0.1 /ssby.com
127.0.0.1 .surj.com
127.0.0.1 /surj.com
127.0.0.1 .tbvg.com
127.0.0.1 /tbvg.com
127.0.0.1 .tdak.com
127.0.0.1 /tdak.com
127.0.0.1 .tdmy.com
127.0.0.1 /tdmy.com
127.0.0.1 .tefs.com
127.0.0.1 /tefs.com
127.0.0.1 .tfil.com
127.0.0.1 /tfil.com
127.0.0.1 .tjar.com
127.0.0.1 /tjar.com
127.0.0.1 .tjaw.com
127.0.0.1 /tjaw.com
127.0.0.1 .tjgo.com
127.0.0.1 /tjgo.com
127.0.0.1 .tjem.com
127.0.0.1 /tjem.com
127.0.0.1 .torc.com
127.0.0.1 /torc.com
127.0.0.1 .wfix.com
127.0.0.1 /wfix.com
127.0.0.1 .wflu.com
127.0.0.1 /wflu.com
127.0.0.1 .tdko.com
127.0.0.1 /tdko.com
127.0.0.1 .thko.com
127.0.0.1 /thko.com
127.0.0.1 H24413.tfil.com
127.0.0.1 germany.rub.to
127.0.0.1 search.rub.to
127.0.0.1 unitedstates.rub.to
127.0.0.1 www.commonname.com
127.0.0.1 www.ezcybersearch.com
127.0.0.1 www.jethomepage.com
127.0.0.1 www.gohip.com
127.0.0.1 hotbar.com
127.0.0.1 www.huntbar.com
127.0.0.1 search.imiserver.com
127.0.0.1 infospace.com/blsrch.dp.toolbar
127.0.0.1 searchenhancement.com
127.0.0.1 newtonknows.com
127.0.0.1 search-explorer.net
127.0.0.1 searchsquire.com
127.0.0.1 secondpower.com
127.0.0.1 2ndpower.com
127.0.0.1 searchgateway.net
127.0.0.1 worldusa.com
127.0.0.1 www.topsearcher.com
127.0.0.1 smutserver.com
127.0.0.1 searchmeup.com
127.0.0.1 cameup.com
127.0.0.1 kliksearch.com
127.0.0.1 realphx.com
127.0.0.1 blazefind.com
127.0.0.1 66.40.16.198
127.0.0.1 zoofil.com
127.0.0.1 terafinder.com
127.0.0.1 008i.com
127.0.0.1 171203.com
127.0.0.1 39-93.com
127.0.0.1 adult-personal.us
127.0.0.1 cashsearch.biz
127.0.0.1 cl55.biz
127.0.0.1 dailyteenspic.com
127.0.0.1 dialer2004.com
127.0.0.1 digital-pornography.com
127.0.0.1 eager-sex.com
127.0.0.1 ergosites.com
127.0.0.1 freecj.com
127.0.0.1 greg-search.com
127.0.0.1 incest-host.com
127.0.0.1 ironcarteam.com
127.0.0.1 is-best.com
127.0.0.1 killerpornstars.com
127.0.0.1 lollitop.com
127.0.0.1 love-host.com
127.0.0.1 myexexex.com
127.0.0.1 my-finder.com
127.0.0.1 onlineclick.net
127.0.0.1 onlysex.ws
127.0.0.1 regfreeze.com
127.0.0.1 ruworld.com
127.0.0.1 selltraffic.biz
127.0.0.1 sexunique.net
127.0.0.1 sinpussy.com
127.0.0.1 teenhost.net
127.0.0.1 ultraload.net
127.0.0.1 vse-moe.biz
127.0.0.1 xsex.ws
127.0.0.1 .75tz.com
127.0.0.1 /75tz.com
127.0.0.1 .iefeadsl.com
127.0.0.1 /iefeadsl.com
127.0.0.1 /rf104.com
127.0.0.1 .rf104.com
127.0.0.1 www.v61.com
127.0.0.1 ads.centralmedia.ws
127.0.0.1 c.centralmedia.ws
127.0.0.1 .count.cc
127.0.0.1 /count.cc
127.0.0.1 .topx.cc
127.0.0.1 /topx.cc
127.0.0.1 sidefind.com
127.0.0.1 thenewsearch.com
127.0.0.1 new-search.net
127.0.0.1 x-google.net
127.0.0.1 adultgambling.org
127.0.0.1 bitchesonline.net
127.0.0.1 girls4rent.net
127.0.0.1 usefullsoft.net
127.0.0.1 livegambling.com
127.0.0.1 adultsgames.net
127.0.0.1 easyantispy.com
127.0.0.1 spybotremover.net
127.0.0.1 winprotect.net
127.0.0.1 funny-girls.com
127.0.0.1 winmsn.com
127.0.0.1 oneclicksearches.com
127.0.0.1 bestweblinks.com
127.0.0.1 iqsearch.net
127.0.0.1 dumpserv.com
127.0.0.1 helpyoursearch.com
127.0.0.1 sgrunt.biz
127.0.0.1 yeak.net
127.0.0.1 u45.cx
127.0.0.1 u46.cx
127.0.0.1 u47.cc
127.0.0.1 u48.cc
127.0.0.1 sfonditalia.biz
127.0.0.1 realarea.biz
127.0.0.1 archiviosex.net
127.0.0.1 agava.com
127.0.0.1 agava.ru
127.0.0.1 hut1.ru
127.0.0.1 hu15.ru
127.0.0.1 winfixer.com
127.0.0.1 3721.com
127.0.0.1 easysearchingtips.com
127.0.0.1 fine-search.net
127.0.0.1 noproblemsurf.com
127.0.0.1 pcspyremover.com
127.0.0.1 search-motor.com
127.0.0.1 searchwhatuwant.com
127.0.0.1 ad25.com
127.0.0.1 ad45.com
127.0.0.1 ad77.com
127.0.0.1 ad86.com
127.0.0.1 full-search.net
127.0.0.1 go2-search.com
127.0.0.1 onemoresearch.net
127.0.0.1 search-777.com
127.0.0.1 search-to-find.com
127.0.0.1 search-what.net
127.0.0.1 winshow.biz
127.0.0.1 lookfor.cc
127.0.0.1 looking-for.cc
127.0.0.1 tgp-4-you.com
127.0.0.1 veryeasysearch.com
127.0.0.1 010402.com
127.0.0.1 20x2p.com
127.0.0.1 db105.com
127.0.0.1 ga31.com
127.0.0.1 mpeg-look.com
127.0.0.1 n-udd.com
127.0.0.1 p-uud.com
127.0.0.1 porn-screen.com
127.0.0.1 rb37.com
127.0.0.1 t058.com
127.0.0.1 u-239.com
127.0.0.1 v-224.com
127.0.0.1 trackhits.cc
127.0.0.1 tracktraff.cc
127.0.0.1 power-cleaner.com
127.0.0.1 yoursitebar.com
127.0.0.1 ysbweb.com
127.0.0.1 www.ysbweb.com
127.0.0.1 installcash.com
127.0.0.1 toolbarcash.com
127.0.0.1 enjoywebsurf.com
127.0.0.1 msnguard.cc
127.0.0.1 searchclick.cc
127.0.0.1 havy.biz
127.0.0.1 ewizard.cc
127.0.0.1 4klm.com
127.0.0.1 camup.net
127.0.0.1 bdsmlibrary.net
127.0.0.1 n-glx.s-redirect.com
127.0.0.1 aaasexypics.com
127.0.0.1 allforadult.com
127.0.0.1 autoescrowpay.com
127.0.0.1 awmcash.biz
127.0.0.1 awmdabest.com
127.0.0.1 buldog-stats.com
127.0.0.1 counter.sexmaniack.com
127.0.0.1 fregat.drocherway.com
127.0.0.1 greg-tut.com
127.0.0.1 iframe.biz
127.0.0.1 megapornix.com
127.0.0.1 newiframe.biz
127.0.0.1 nylonsexy.com
127.0.0.1 pizdato.biz
127.0.0.1 sexfiles.nu
127.0.0.1 slutmania.biz
127.0.0.1 sp2fucked.biz
127.0.0.1 toolbarpartner.com
127.0.0.1 vesbiz.biz
127.0.0.1 virgin-tgp.net
127.0.0.1 vparivalka.com
127.0.0.1 x.full-tgp.net
127.0.0.1 toolbar.cc
127.0.0.1 himen.biz
127.0.0.1 msupdater.net
127.0.0.1 www.msupdater.net
127.0.0.1 1800searchonline.com
127.0.0.1 www.1800searchonline.com
127.0.0.1 1stsearchportal.com
127.0.0.1 www.1stsearchportal.com
127.0.0.1 24-7searching-and-more.com
127.0.0.1 www.24-7searching-and-more.com
127.0.0.1 971searchbox.com
127.0.0.1 www.971searchbox.com
127.0.0.1 aaawebfinder.com
127.0.0.1 www.aaawebfinder.com
127.0.0.1 ampmsearch.com
127.0.0.1 www.ampmsearch.com
127.0.0.1 clickhere4search.com
127.0.0.1 www.clickhere4search.com
127.0.0.1 clicktomakeasearch.com
127.0.0.1 www.clicktomakeasearch.com
127.0.0.1 directsearchzone.com
127.0.0.1 www.directsearchzone.com
127.0.0.1 easysearch4you.com
127.0.0.1 www.easysearch4you.com
127.0.0.1 enterthesearch.com
127.0.0.1 www.enterthesearch.com
127.0.0.1 esearch2005.com
127.0.0.1 www.esearch2005.com
127.0.0.1 eza1netsearch.com
127.0.0.1 www.eza1netsearch.com
127.0.0.1 ezwebsearching.com
127.0.0.1 www.ezwebsearching.com
127.0.0.1 globalefinder.com
127.0.0.1 www.globalefinder.com
127.0.0.1 go2realsearch.com
127.0.0.1 www.go2realsearch.com
127.0.0.1 myseachexplorer.com
127.0.0.1 www.myseachexplorer.com
127.0.0.1 quicksearch360.com
127.0.0.1 www.quicksearch360.com
127.0.0.1 s1s1s1search.com
127.0.0.1 www.s1s1s1search.com
127.0.0.1 search101online.com
127.0.0.1 www.search101online.com
127.0.0.1 search123forme.com
127.0.0.1 www.search123forme.com
127.0.0.1 search345quest.com
127.0.0.1 www.search345quest.com
127.0.0.1 searchmiracle.com
127.0.0.1 www.searchmiracle.com
127.0.0.1 searchtheworld4you.com
127.0.0.1 www.searchtheworld4you.com
127.0.0.1 searchwebzone.com
127.0.0.1 www.searchwebzone.com
127.0.0.1 seektheglobe.com
127.0.0.1 www.seektheglobe.com
127.0.0.1 sitesearchcentral.com
127.0.0.1 www.sitesearchcentral.com
127.0.0.1 the818search-co.com
127.0.0.1 www.the818search-co.com
127.0.0.1 type2find.com
127.0.0.1 www.type2find.com
127.0.0.1 xosearchox.com
127.0.0.1 www.xosearchox.com
127.0.0.1 yoursearchspace.com
127.0.0.1 www.yoursearchspace.com
127.0.0.1 httpwwwads.com
127.0.0.1 www.httpwwwads.com
127.0.0.1 adshttp.com
127.0.0.1 www.adshttp.com
127.0.0.1 adsonwww.com
127.0.0.1 www.adsonwww.com
127.0.0.1 216.152.240.14
127.0.0.1 216.152.240.13
127.0.0.1 216.152.240.10
127.0.0.1 216.152.240.16
127.0.0.1 dnaads.com
127.0.0.1 www.dnaads.com
127.0.0.1 marketengines.com
127.0.0.1 www.marketengines.com
127.0.0.1 ad-w-a-r-e.com
127.0.0.1 www.ad-w-a-r-e.com
127.0.0.1 a-d-w-a-r-e.com
127.0.0.1 www.a-d-w-a-r-e.com
127.0.0.1 securityindex.net
127.0.0.1 www.securityindex.net
127.0.0.1 sexpicsporn.com
127.0.0.1 www.sexpicsporn.com
127.0.0.1 free-spybot.com
127.0.0.1 www.free-spybot.com
127.0.0.1 cashengines.com
127.0.0.1 www.cashengines.com
127.0.0.1 microsoftantispyware.net
127.0.0.1 www.microsoftantispyware.net
127.0.0.1 mircosoftantispy.com
127.0.0.1 www.mircosoftantispy.com
127.0.0.1 msantispy.com
127.0.0.1 www.msantispy.com
127.0.0.1 netspyprotector.com
127.0.0.1 www.netspyprotector.com
127.0.0.1 avforce.com
127.0.0.1 www.avforce.com
127.0.0.1 savehits.com
127.0.0.1 www.savehits.com
127.0.0.1 saveli.com
127.0.0.1 www.saveli.com
127.0.0.1 metastop.com
127.0.0.1 www.metastop.com
127.0.0.1 perlink.biz
127.0.0.1 www.perlink.biz
127.0.0.1 highdialer.com
127.0.0.1 www.highdialer.com
127.0.0.1 66.230.175.129
127.0.0.1 online-more.com
127.0.0.1 www.online-more.com
127.0.0.1 66.117.37.7
127.0.0.1 www.syserrors.com
127.0.0.1 www.vcodec.com
127.0.0.1 toolbartraff.biz
127.0.0.1 www.toolbartraff.biz
127.0.0.1 pcadprotector.cc
127.0.0.1 www.pcadprotector.cc
127.0.0.1 airtleworld.com
127.0.0.1 www.airtleworld.com
127.0.0.1 domaincar.com
127.0.0.1 www.domaincar.com
127.0.0.1 worldray.com
127.0.0.1 www.worldray.com
127.0.0.1 www5.worldray.com
127.0.0.1 www6.worldray.com
127.0.0.1 www.spytrooper.com
127.0.0.1 spytrooper.com
127.0.0.1 dl.ad-ware.cc
127.0.0.1 ad-ware.cc
127.0.0.1 82.179.170.11
127.0.0.1 195.255.177.28
127.0.0.1 downloads.adaware.cc
127.0.0.1 adaware.cc
127.0.0.1 hitscount.net
127.0.0.1 count.hitscount.net
127.0.0.1 fined.biz
127.0.0.1 de.ag
127.0.0.1 games.de.ag
127.0.0.1 www.games.de.ag
127.0.0.1 little-download.net
127.0.0.1 www.little-download.net
127.0.0.1 little-help.com
127.0.0.1 www.little-help.com
127.0.0.1 www.spyaxe.net
127.0.0.1 www.spyaxe.com
127.0.0.1 www.spyaxe.biz
127.0.0.1 www.malwarewipe.com
127.0.0.1 dl.malwarewipe.com
127.0.0.1 www.malwarewipeupdate.com
127.0.0.1 24.244.71.239
127.0.0.1 unionseek.com
127.0.0.1 www.unionseek.com
127.0.0.1 sirh0t.blackhats.tc
127.0.0.1 blackhats.tc
127.0.0.1 www.blackhats.tc
127.0.0.1 ritztours.com
127.0.0.1 www.ritztours.com
127.0.0.1 flashflashmx.3322.org
127.0.0.1 3322.org
127.0.0.1 www.3322.org
127.0.0.1 jupitersatellites.biz
127.0.0.1 www.jupitersatellites.biz
127.0.0.1 yops.biz
127.0.0.1 www.yops.biz
127.0.0.1 69.50.171.122
127.0.0.1 goldengr.hypermart.net
127.0.0.1 web-nexus.net
127.0.0.1 safe-sales.biz
127.0.0.1 www.safe-sales.biz
127.0.0.1 jerrynews.com
127.0.0.1 www.jerrynews.com
127.0.0.1 Teslaplus.com
127.0.0.1 www.Teslaplus.com
127.0.0.1 82.179.170.82
127.0.0.1 WorldAntiSpy.com
127.0.0.1 www.WorldAntiSpy.com
127.0.0.1 www.securitycaution.com
127.0.0.1 securitycaution.com
127.0.0.1 adservs.com
127.0.0.1 csx.adservs.com
127.0.0.1 www.csx.adservs.com
127.0.0.1 toolbarbest.biz
127.0.0.1 www.toolbarbest.biz
127.0.0.1 65.75.151.192
127.0.0.1 game4all.biz
127.0.0.1 www.game4all.biz
127.0.0.1 game4all.biz/adv/018
127.0.0.1 www.game4all.biz/adv/018
127.0.0.1 wm.kannylizaciya.info
127.0.0.1 www.wm.kannylizaciya.info
127.0.0.1 wm.buhartes.info
127.0.0.1 www.wm.buhartes.info
127.0.0.1 login.fric.cn
127.0.0.1 www.login.fric.cn
127.0.0.1 xsremover.com
127.0.0.1 www.xsremover.com
127.0.0.1 spydeface.com
127.0.0.1 www.spydeface.com
127.0.0.1 alfacleaner.com
127.0.0.1 www.alfacleaner.com
127.0.0.1 innovagest2000.com
127.0.0.1 www.innovagest2000.com
127.0.0.1 www.thespyguard.com
127.0.0.1 thespyguard.com
127.0.0.1 www.adwarepunisher.com
127.0.0.1 adwarepunisher.com
127.0.0.1 www.spyiblock.com
127.0.0.1 spyiblock.com
127.0.0.1 www.uvu-channel.com
127.0.0.1 uvu-channel.com
127.0.0.1 www.hachimitsu-lemon.com
127.0.0.1 hachimitsu-lemon.com
127.0.0.1 SEARCHTOFIND.NET
127.0.0.1 www.SEARCHTOFIND.NET
127.0.0.1 www.pestrap.com
127.0.0.1 pestrap.com
127.0.0.1 uptodatesecurity.com
127.0.0.1 www.uptodatesecurity.com
127.0.0.1 thinstall.abetterinternet.com
127.0.0.1 www.3abetterinternet.com
127.0.0.1 download.abetterinternet.com
127.0.0.1 www.abetterinternet.com
127.0.0.1 216.255.179.234
127.0.0.1 qmex.psyche-evolution.com
127.0.0.1 www.qmex.psyche-evolution.com
127.0.0.1 core.psyche-evolution.com
127.0.0.1 www.core.psyche-evolution.com
127.0.0.1 1stantivirus.com
127.0.0.1 www.1stantivirus.com
127.0.0.1 scanandrepair.com
127.0.0.1 www.scanandrepair.com
127.0.0.1 uydsiygeds.com
127.0.0.1 www.uydsiygeds.com
127.0.0.1 pesttrap.com
127.0.0.1 www.pesttrap.com
127.0.0.1 adwarebazooka.com
127.0.0.1 get.adwarebazooka.com
127.0.0.1 www.adwarebazooka.com
127.0.0.1 kliksoftware.com
127.0.0.1 www.kliksoftware.com
127.0.0.1 hitvirus.com
127.0.0.1 get.hitvirus.com
127.0.0.1 www.hitvirus.com
127.0.0.1 promo.dollarrevenue.com
127.0.0.1 www.promo.dollarrevenue.com
127.0.0.1 maxifile.com
127.0.0.1 www.maxifile.com
127.0.0.1 targetsaver.com
127.0.0.1 www.targetsaver.com
127.0.0.1 dl.targetsaver.com
127.0.0.1 www.dl.targetsaver.com
127.0.0.1 nonameforthisdomain.com
127.0.0.1 www.nonameforthisdomain.com
127.0.0.1 hypoteches.com
127.0.0.1 www.hypoteches.com
127.0.0.1 www.earthllnk.net
127.0.0.1 earthllnk.net
127.0.0.1 hostance.net
127.0.0.1 www.hostance.net
127.0.0.1 my-dedik-one.com
127.0.0.1 www.my-dedik-one.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 6sek.com
127.0.0.1 www.6sek.com
127.0.0.1 cashdeluxe.net
127.0.0.1 www.cashdeluxe.net
127.0.0.1 stats.cashdeluxe.net
127.0.0.1 www.stats.cashdeluxe.net
127.0.0.1 www.2006ooo.com
127.0.0.1 www.spyware-stop.com
127.0.0.1 spyware-stop.com
127.0.0.1 www.SpyShield.org
127.0.0.1 SpyShield.org
127.0.0.1 utils.winfixer.com
127.0.0.1 www.utils.winfixer.com
127.0.0.1 toolbarbucks.biz
127.0.0.1 www.toolbarbucks.biz
127.0.0.1 derklaif.biz
127.0.0.1 www.derklaif.biz
127.0.0.1 www.v-codec.com
127.0.0.1 v-codec.com
127.0.0.1 www.emediacodec.com
127.0.0.1 emediacodec.com
127.0.0.1 www.popentertain.com
127.0.0.1 popentertain.com
127.0.0.1 softwareprofit.com
127.0.0.1 www.softwareprofit.com
127.0.0.1 de.winantivirus.com
127.0.0.1 download.winantivirus.com
127.0.0.1 winantivirus.com
127.0.0.1 www.winantivirus.com
127.0.0.1 205.209.152.121
127.0.0.1 offers.bullseye-network.com
127.0.0.1 www.offers.bullseye-network.com
127.0.0.1 bullseye-network.com
127.0.0.1 www.bullseye-network.com
127.0.0.1 sponsor2.ucmore.com
127.0.0.1 www.sponsor2.ucmore.com
127.0.0.1 apps.deskwizz
127.0.0.1 www.apps.deskwizz
127.0.0.1 hostthesky.com
127.0.0.1 www.hostthesky.com
127.0.0.1 dbdecicated.com
127.0.0.1 www.dbdecicated.com
127.0.0.1 readagreement.net
127.0.0.1 www.readagreement.net
127.0.0.1 gl.secdep.info
127.0.0.1 www.gl.secdep.info
127.0.0.1 spyfalcon.com
127.0.0.1 www.spyfalcon.com
127.0.0.1 spyfalconupdate.com
127.0.0.1 www.spyfalconupdate.com
127.0.0.1 spy-shield.com
127.0.0.1 www.spy-shield.com
127.0.0.1 winnanny.com
127.0.0.1 www.winnanny.com
127.0.0.1 winsoftware.com
127.0.0.1 www.winsoftware.com
127.0.0.1 winfirewall.com
127.0.0.1 www.winfirewall.com
127.0.0.1 winantispyware.com
127.0.0.1 www.winantispyware.com
127.0.0.1 udefender.com
127.0.0.1 www.udefender.com
127.0.0.1 bravesentry.com
127.0.0.1 www.bravesentry.com
127.0.0.1 content.dollarrevenue.com
127.0.0.1 www.content.dollarrevenue.com
127.0.0.1 toolbar.azebar.com
127.0.0.1 www.toolbar.azebar.com
127.0.0.1 traffsale1.biz
127.0.0.1 www.traffsale1.biz
127.0.0.1 194.187.45.55
127.0.0.1 82.146.60.36
127.0.0.1 spywaredisinfector.com
127.0.0.1 www.spywaredisinfector.com
127.0.0.1 SpyCut.com
127.0.0.1 www.SpyCut.com
127.0.0.1 almanah.biz
127.0.0.1 www.almanah.biz
127.0.0.1 antispydns.biz
127.0.0.1 www.antispydns.biz
127.0.0.1 spyaxeupdate.com
127.0.0.1 www.spyaxeupdate.com
127.0.0.1 malwarewipesupport.com
127.0.0.1 www.malwarewipesupport.com
127.0.0.1 remedyantispy.com
127.0.0.1 www.remedyantispy.com
127.0.0.1 systemstable.com
127.0.0.1 www.systemstable.com
127.0.0.1 whoisprivacyprotect.com
127.0.0.1 www.whoisprivacyprotect.com
127.0.0.1 85.249.22.240
127.0.0.1 prime.webhancer.com
127.0.0.1 www.prime.webhancer.com
127.0.0.1 webhancer.com
127.0.0.1 www.webhancer.com
127.0.0.1 dr.webhancer.com
127.0.0.1 www.dr.webhancer.com
127.0.0.1 dr2.webhancer.com
127.0.0.1 www.dr2.webhancer.com
127.0.0.1 www.onli-ne.com
127.0.0.1 spycontra.com
127.0.0.1 www.spycontra.com
127.0.0.1 anti-virus-pro.com
127.0.0.1 www.anti-virus-pro.com
127.0.0.1 check.jupitersatellites.biz
127.0.0.1 www.check.jupitersatellites.biz
127.0.0.1 necessaryupdates.com
127.0.0.1 www.necessaryupdates.com
127.0.0.1 bestworldgirls-for-u.net
127.0.0.1 www.bestworldgirls-for-u.net
127.0.0.1 stejax.pl
127.0.0.1 www.stejax.pl
127.0.0.1 kitehosting.com
127.0.0.1 www.kitehosting.com
127.0.0.1 ware2006.com
127.0.0.1 www.ware2006.com
127.0.0.1 filestore.com
127.0.0.1 www.filestore.com
127.0.0.1 systemupdates.net
127.0.0.1 www.systemupdates.net
127.0.0.1 logs.vapochille.com
127.0.0.1 www.logs.vapochille.com
127.0.0.1 goldenfreehost.com
127.0.0.1 www.goldenfreehost.com
127.0.0.1 todaywarnings.com
127.0.0.1 www.todaywarnings.com
127.0.0.1 spywarequake.com
127.0.0.1 spywarequake.info
127.0.0.1 www.spywarequake.info
127.0.0.1 www.spywarequake.com
127.0.0.1 download2.spywarequake.com
127.0.0.1 download3.spywarequake.com
127.0.0.1 download4.spywarequake.com
127.0.0.1 download5.spywarequake.com
127.0.0.1 download7.spywarequake.com
127.0.0.1 download8.spywarequake.com
127.0.0.1 download9.spywarequake.com
127.0.0.1 download10.spywarequake.com
127.0.0.1 download11.spywarequake.com
127.0.0.1 download12.spywarequake.com
127.0.0.1 download13.spywarequake.com
127.0.0.1 download15.spywarequake.com
127.0.0.1 updates.spywarequake.com
127.0.0.1 206.161.124.98
127.0.0.1 69.31.131.82
127.0.0.1 207.226.162.34
127.0.0.1 urgentsystemupdate.com
127.0.0.1 www.urgentsystemupdate.com
127.0.0.1 dl2.spywarestrike.com
127.0.0.1 dl3.spywarestrike.com
127.0.0.1 dl4.spywarestrike.com
127.0.0.1 dl5.spywarestrike.com
127.0.0.1 dl6.spywarestrike.com
127.0.0.1 dl7.spywarestrike.com
127.0.0.1 dl8.spywarestrike.com
127.0.0.1 nospywaresoft.com
127.0.0.1 spywarestrike.com
127.0.0.1 www.nospywaresoft.com
127.0.0.1 www.spywarestrike.com
127.0.0.1 69.31.81.82
127.0.0.1 spyaxesupport.com
127.0.0.1 www.spyaxesupport.com
127.0.0.1 download3.spyaxe.com
127.0.0.1 download4.spyaxe.com
127.0.0.1 download5.spyaxe.com
127.0.0.1 download6.spyaxe.com
127.0.0.1 dl2.spyfalcon.com
127.0.0.1 dl3.spyfalcon.com
127.0.0.1 dl4.spyfalcon.com
127.0.0.1 dl5.spyfalcon.com
127.0.0.1 dl9.spyfalcon.com
127.0.0.1 dl10.spyfalcon.com
127.0.0.1 dl16.spyfalcon.com
127.0.0.1 www.sgrunt.biz
127.0.0.1 traffbest.biz
127.0.0.1 www.traffbest.biz
127.0.0.1 securityfeature.com
127.0.0.1 www.securityfeature.com
127.0.0.1 pimasoft.com
127.0.0.1 www.pimasoft.com
127.0.0.1 blackhawksoftware.com
127.0.0.1 www.blackhawksoftware.com
127.0.0.1 spy-sniper.com
127.0.0.1 www.spy-sniper.com
127.0.0.1 safetydefender.com
127.0.0.1 www.safetydefender.com
127.0.0.1 securitywarnings.net
127.0.0.1 www.securitywarnings.net
127.0.0.1 urgentsystemupdate.biz
127.0.0.1 www.urgentsystemupdate.biz
127.0.0.1 antispylab.com
127.0.0.1 www.antispylab.com
127.0.0.1 spywaresheriff.com
127.0.0.1 www.spywaresheriff.com
127.0.0.1 allmegabucks.com
127.0.0.1 www.allmegabucks.com
127.0.0.1 rizalof.com
127.0.0.1 www.rizalof.com
127.0.0.1 rc.rizalof.com
127.0.0.1 media-codec.com
127.0.0.1 www.media-codec.com
127.0.0.1 SpywareScraper.com
127.0.0.1 www.SpywareScraper.com
127.0.0.1 crystalysmedia.com
127.0.0.1 www.crystalysmedia.com
127.0.0.1 180solutions.com
127.0.0.1 cts.180solutions.com
127.0.0.1 bis.180solutions.com
127.0.0.1 downloads.180solutions.com
127.0.0.1 uploads.180solutions.com
127.0.0.1 installs.180solutions.com
127.0.0.1 config.180solutions.com
127.0.0.1 ping.180solutions.com
127.0.0.1 tv.180solutions.com
127.0.0.1 nowhere.180solutions.com
127.0.0.1 www.180solutions.com
127.0.0.1 180searchassistant.com
127.0.0.1 www.180searchassistant.com
127.0.0.1 theguardservices.com
127.0.0.1 www.theguardservices.com
127.0.0.1 securitybulletin.net
127.0.0.1 www.securitybulletin.net
127.0.0.1 www.supernet.speedserv.com
127.0.0.1 spyonthis.net
127.0.0.1 download.spyonthis.net
127.0.0.1 www.spyonthis.net
127.0.0.1 hijack-this.net
127.0.0.1 www.hijack-this.net
127.0.0.1 errorsafe.com
127.0.0.1 de.errorsafe.com
127.0.0.1 download.errorsafe.com
127.0.0.1 www.errorsafe.com
127.0.0.1 amaena.com
127.0.0.1 trial.updates.winsoftware.com
127.0.0.1 instlog.winfixer.com
127.0.0.1 winfixer2006.com
127.0.0.1 www.winfixer2006.com
127.0.0.1 webtopsecurity.com
127.0.0.1 www.webtopsecurity.com
127.0.0.1 traff5all.biz
127.0.0.1 www.traff5all.biz
127.0.0.1 1-extreme.biz
127.0.0.1 www.1-extreme.biz
127.0.0.1 download.bravesentry.com
127.0.0.1 www.download.bravesentry.com
127.0.0.1 evko.biz
127.0.0.1 www.evko.biz
127.0.0.1 lavasoftupdate.com
127.0.0.1 www.lavasoftupdate.com
127.0.0.1 download.secureyournet.biz
127.0.0.1 www.download.secureyournet.biz
127.0.0.1 secureyournet.biz
127.0.0.1 www.secureyournet.biz
127.0.0.1 windupdates.com
127.0.0.1 asdbiz.biz
127.0.0.1 www.asdbiz.biz
127.0.0.1 spywarelabs.com
127.0.0.1 www.spywarelabs.com
127.0.0.1 traffweb1.biz
127.0.0.1 www.traffweb1.biz
127.0.0.1 newtoolbar.biz
127.0.0.1 www.newtoolbar.biz
127.0.0.1 buytraff.biz
127.0.0.1 www.buytraff.biz
127.0.0.1 safetyuptodate.com
127.0.0.1 www.safetyuptodate.com
127.0.0.1 crazywinnings.com
127.0.0.1 frame.crazywinnings.com
127.0.0.1 www.crazywinnings.com
127.0.0.1 topconverting.com
127.0.0.1 www.topconverting.com
127.0.0.1 casalemedia.com
127.0.0.1 b.casalemedia.com
127.0.0.1 www.casalemedia.com
127.0.0.1 addictivetechnologies.com
127.0.0.1 www.addictivetechnologies.com
127.0.0.1 addictivetechnologies.net
127.0.0.1 www.addictivetechnologies.net
127.0.0.1 admin2cash.biz
127.0.0.1 www.admin2cash.biz
127.0.0.1 advcash.biz
127.0.0.1 www.advcash.biz
127.0.0.1 all4internet.com
127.0.0.1 www.all4internet.com
127.0.0.1 bettersearch.biz
127.0.0.1 www.bettersearch.biz
127.0.0.1 c4tdownload.com
127.0.0.1 www.c4tdownload.com
127.0.0.1 clickspring.net
127.0.0.1 www.clickspring.net
127.0.0.1 contentmatch.net
127.0.0.1 www.contentmatch.net
127.0.0.1 dialer-shop.com
127.0.0.1 www.dialer-shop.com
127.0.0.1 dialoff.com
127.0.0.1 www.dialoff.com
127.0.0.1 energy-factor.com
127.0.0.1 www.energy-factor.com
127.0.0.1 hardcorefantasyland.com
127.0.0.1 www.hardcorefantasyland.com
127.0.0.1 hardfootballbabes.com
127.0.0.1 www.hardfootballbabes.com
127.0.0.1 linkautomatici.com
127.0.0.1 www.linkautomatici.com
127.0.0.1 master69.biz
127.0.0.1 www.master69.biz
127.0.0.1 master70.biz
127.0.0.1 www.master70.biz
127.0.0.1 master71.biz
127.0.0.1 www.master71.biz
127.0.0.1 mcdial.biz
127.0.0.1 www.mcdial.biz
127.0.0.1 mt-download.com
127.0.0.1 www.mt-download.com
127.0.0.1 my-teensex.com
127.0.0.1 overpro.com
127.0.0.1 private-dialer.biz
127.0.0.1 private-iframe.biz
127.0.0.1 redfunny.com
127.0.0.1 scoobidoo.com
127.0.0.1 skoobidoo.com
127.0.0.1 sexvideopro.com
127.0.0.1 storage-tasp.com
127.0.0.1 xbeta69.com
127.0.0.1 securityuptodate.net
127.0.0.1 www.securityuptodate.net
127.0.0.1 troonety.biz
127.0.0.1 www.troonety.biz
127.0.0.1 zurrusco.com
127.0.0.1 www.zurrusco.com
127.0.0.1 breenten.biz
127.0.0.1 www.breenten.biz
127.0.0.1 votreenton.biz
127.0.0.1 www.votreenton.biz
127.0.0.1 ozonung.biz
127.0.0.1 www.ozonung.biz
127.0.0.1 213.21.215.186
127.0.0.1 digikeygen.com
127.0.0.1 www.digikeygen.com
127.0.0.1 5starvideos.com
127.0.0.1 www.5starvideos.com
127.0.0.1 moviereality.com
127.0.0.1 www.moviereality.com
127.0.0.1 perfectedsecurity.com
127.0.0.1 www.perfectedsecurity.com
127.0.0.1 securityprecaution.net
127.0.0.1 www.securityprecaution.net
127.0.0.1 securityupdatesite.com
127.0.0.1 www.securityupdatesite.com
127.0.0.1 dns-look-up.com
127.0.0.1 www.dns-look-up.com
127.0.0.1 ayb.dns-look-up.com
127.0.0.1 search200.com
127.0.0.1 www.search200.com
127.0.0.1 404dns.com
127.0.0.1 www.404dns.com
127.0.0.1 mcboo.com
127.0.0.1 dr.mcboo.com
127.0.0.1 www.mcboo.com
127.0.0.1 appealcircuit.com
127.0.0.1 www.appealcircuit.com
127.0.0.1 balotierra.com
127.0.0.1 www.balotierra.com
127.0.0.1 oldflock.com
127.0.0.1 www.oldflock.com
127.0.0.1 pornmagpass.com
127.0.0.1 www.pornmagpass.com
127.0.0.1 dailypornmag.com
127.0.0.1 www.dailypornmag.com
127.0.0.1 babespornmag.com
127.0.0.1 www.babespornmag.com
127.0.0.1 teenspornmag.com
127.0.0.1 www.teenspornmag.com
127.0.0.1 maturespornmag.com
127.0.0.1 www.maturespornmag.com
127.0.0.1 hardcorepornmag.com
127.0.0.1 www.hardcorepornmag.com
127.0.0.1 gayspornmag.com
127.0.0.1 www.gayspornmag.com
127.0.0.1 topsecuritysite.net
127.0.0.1 www.topsecuritysite.net
127.0.0.1 bestsafetyguide.net
127.0.0.1 www.bestsafetyguide.net
127.0.0.1 searchweb2.com
127.0.0.1 www.searchweb2.com
127.0.0.1 www.lop.com
127.0.0.1 vidscodec.com
127.0.0.1 www.vidscodec.com
127.0.0.1 newvidscodec.net
127.0.0.1 www.newvidscodec.net
127.0.0.1 media-codec.net
127.0.0.1 www.media-codec.net
127.0.0.1 mediacodec.net
127.0.0.1 www.mediacodec.net
127.0.0.1 imediacodec.com
127.0.0.1 www.imediacodec.com
127.0.0.1 emcodec.com
127.0.0.1 www.emcodec.com
127.0.0.1 vicodec.com
127.0.0.1 www.vicodec.com
127.0.0.1 xpasswordmanager.com
127.0.0.1 www.xpasswordmanager.com
127.0.0.1 cracks4all.com
127.0.0.1 www.cracks4all.com
127.0.0.1 media-motor.net
127.0.0.1 mmm.media-motor.net
127.0.0.1 bins.media-motor.net
127.0.0.1 bins2.media-motor.net
127.0.0.1 logs.media-motor.net
127.0.0.1 mmohsix.com
127.0.0.1 www.mmohsix.com
127.0.0.1 pops.mmohsix.com
127.0.0.1 megalocast.net
127.0.0.1 js.megalocast.net
127.0.0.1 www.megalocast.net
127.0.0.1 dl.web-nexus.net
127.0.0.1 movies-etc.com
127.0.0.1 cdn.movies-etc.com
127.0.0.1 cdn2.movies-etc.com
127.0.0.1 internet-optimizer.com
127.0.0.1 www.internet-optimizer.com
127.0.0.1 888.com
127.0.0.1 www.888.com
127.0.0.1 images.888.com
127.0.0.1 surfsidekick.com
127.0.0.1 www.surfsidekick.com
127.0.0.1 sdl.surfsidekick.com
127.0.0.1 kmpads.com
127.0.0.1 www.kmpads.com
127.0.0.1 ads.kmpads.com
127.0.0.1 zipcodec.com
127.0.0.1 www.zipcodec.com
127.0.0.1 ibankis.org
127.0.0.1 www.ibankis.org
127.0.0.1 adwarefinder.com
127.0.0.1 www.adwarefinder.com
127.0.0.1 nbcsearch.com
12
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
30 mars 2007 à 20:37
30 mars 2007 à 20:37
pourquoi le rapport de nettoyage de smidfraudfix ne s'affiche pas en entier
j'ai déja éssayé de corriger ça quand je l'édite il est en entiers mais après quand je regarde il en manque un bout
j'ai déja éssayé de corriger ça quand je l'édite il est en entiers mais après quand je regarde il en manque un bout
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
30 mars 2007 à 21:53
30 mars 2007 à 21:53
salut
voilà le nouveau rapport GenProc:
Rapport GenProc 0.32 effectué le 30.03.2007 à 21:50:01.10 - SystemRoot = C:\WINDOWS
# Etape 1/ Télécharge :
- SDfix http://downloads.andymanchesta.com/RemovalTools/SDFix.exe (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
***** Copie ce qui suit dans un fichier texte et redémarre en mode sans échec comme indiqué ici https://docs.microsoft.com/en-us/?mfr=true (choisis ta session courante "Maryline-Tino") *****
# Etape 2/
Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et double clique sur "RunThis.bat" pour lancer le script.
- Appuie sur "Y" pour commencer le processus de nettoyage.
- Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
- Appuie sur une touche pour redémarrer le PC.
- Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
- Après le chargement du Bureau, l'outil terminera son travail et affichera "Finished".
- Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
- Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom "Report.txt".
~ Le fichier "SDFIX_README.htm" (dans le dossier SDFix) contient la liste des malwares pris en compte par l'outil.
~ Andy fait plusieurs mises à jour, souvent plus d'une par jour... N'hésite donc pas à télécharger une nouvelle version lorsque le nettoyage dure et que l'outil ne semble pas tout voir.
# Etape 3/
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
# Etape 4/
Redémarre normalement et poste :
- Un nouveau rapport HijackThis, toutes fenêtres et applications fermées si tu ne l'as pas tu trouveras HijackThis ici http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis_v2.exe ;
- Le contenu du fichier Report.txt ;
Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
voilà le nouveau rapport GenProc:
Rapport GenProc 0.32 effectué le 30.03.2007 à 21:50:01.10 - SystemRoot = C:\WINDOWS
# Etape 1/ Télécharge :
- SDfix http://downloads.andymanchesta.com/RemovalTools/SDFix.exe (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
***** Copie ce qui suit dans un fichier texte et redémarre en mode sans échec comme indiqué ici https://docs.microsoft.com/en-us/?mfr=true (choisis ta session courante "Maryline-Tino") *****
# Etape 2/
Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et double clique sur "RunThis.bat" pour lancer le script.
- Appuie sur "Y" pour commencer le processus de nettoyage.
- Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
- Appuie sur une touche pour redémarrer le PC.
- Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
- Après le chargement du Bureau, l'outil terminera son travail et affichera "Finished".
- Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
- Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom "Report.txt".
~ Le fichier "SDFIX_README.htm" (dans le dossier SDFix) contient la liste des malwares pris en compte par l'outil.
~ Andy fait plusieurs mises à jour, souvent plus d'une par jour... N'hésite donc pas à télécharger une nouvelle version lorsque le nettoyage dure et que l'outil ne semble pas tout voir.
# Etape 3/
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
# Etape 4/
Redémarre normalement et poste :
- Un nouveau rapport HijackThis, toutes fenêtres et applications fermées si tu ne l'as pas tu trouveras HijackThis ici http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis_v2.exe ;
- Le contenu du fichier Report.txt ;
Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
31 mars 2007 à 00:10
31 mars 2007 à 00:10
Voilà j'ai tout fait
Mais toujours de alertes je suis vraiment découragé
maudit Trojan downloader 6 alertes en 4 mn j'y crois pas
Aidez moi svp.
voilà le rap. SDFIX:
SDFix: Version 1.75
Run by Maryline-Tino - 30.03.2007 - 22:39:38.53
Microsoft Windows XP [version 5.1.2600]
Running From: C:\Documents and Settings\Maryline-Tino\Bureau\SDFIX\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Entries
Restoring Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\WINDOWS\Temp\winC.tmp.exe - Deleted
C:\WINDOWS\Temp\winC.tmp.exe - Deleted
C:\WINDOWS\Temp\win*.tmp - Deleted
ADS Check:
C:\WINDOWS\system32
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
Remaining Files:
---------------
Backups Folder: - C:\DOCUME~1\MARYLI~1\Bureau\SDFIX\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes :
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c509 Packet\3C5X9PD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c556 Packet\3C556.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c59x Packet\3C59XPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1200 Packet\EC32PD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1203 Packet\PCIPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1204 Packet\VLNWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207 Packet\PCIPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207C Packet\PCIPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207D Packet\ACCPKT.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207F Packet\EN5251PD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207TX Packet\PCIPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1208 Packet\1208PD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1625 Packet\NEPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1640 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1650 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1651 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1652 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1653 Packet\NE2PD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1656 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1657 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1658 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN166X Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2216 Packet\PCMPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2218 Packet\PCMPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2228 Packet\PCMPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2320 Packet\EN5251PD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DEVICE.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\KEYB.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MODE.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MOUSE.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\NETBIND.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\Paralink.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\command.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\IBMBIO.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\IBMDOS.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE450 Packet\DE450.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE500 Packet\DE500.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWorks ISA (DE305) Packet\DE305.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DE400 Packet\De400pd.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DMF560-TX Packet\Lmpd.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DT620 Packet\Dt620pd.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\IBM Crystal LAN Packet\Epktisa.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Kingston EtheRx KNE110TX Packet\Ktc110p.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD 10-100AL Packet\L100al.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD-CDF Packet\Ldcdt.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD-PCI2TL Packet\Ldpcil.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Melco LPC2-T\Lpchkat2.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FNW9x00T - ENW8300T Packet\fetpkt.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\FETPKT.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\Rtspkt.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\PXE Packet Driver\Undipd.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\SN 2000p Packet\PNPPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\WaveLAN Packet\Wvlan42.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX Packet\Cbepd.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS Packet\Xpspd.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom RE10 - RE100 Packet\Ce3pd.com
C:\WINDOWS\system32\awvvt.dll
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS16.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\E.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\GUEST.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MSCDEX.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\Net.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\OHCI.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\PROTMAN.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\UHCI.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX\Cbendis.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet 10-100 + Modem\Cbendis.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS\Xpsndis.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom PE3-10Bx\Pe3ndis.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Re-100Btx + Ce3B-100Btx\Ce3ndis.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom RE10BT\Ce3ndis.exe
C:\Program Files\Ahead\Nero Wave Editor\DXEnum.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Elndis.sys
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Usbd.sys
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI1394.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI2DOS.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI4DOS.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI8DOS.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI8U2.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPICD.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIEHCI.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIOHCI.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIUHCI.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BOOTSRV.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\bootsrv16.sys
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BTCDROM.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BTDOSM.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\COUNTRY.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DISPLAY.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DLSHELP.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\FLASHPT.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\HIMEM.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\KEYBOARD.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\msbootsrv16.sys
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\OAKCDROM.SYS
C:\Documents and Settings\Maryline-Tino\Application Data\.E10FB8D272B730B3.sys
C:\Program Files\Common Files\X10\Common\x10prod.sys
C:\WINDOWS\LastGood.Tmp\INF\oem28.inf
C:\WINDOWS\LastGood.Tmp\INF\oem28.PNF
C:\WINDOWS\LastGood.Tmp\INF\oem29.inf
C:\WINDOWS\LastGood.Tmp\INF\oem29.PNF
C:\WINDOWS\LastGood.Tmp\INF\oem30.inf
C:\WINDOWS\LastGood.Tmp\INF\oem30.PNF
C:\WINDOWS\LastGood.Tmp\INF\oem31.inf
C:\WINDOWS\LastGood.Tmp\INF\oem31.PNF
Finished
**********************
Voilà le rapport hijackthis:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 00:08:41, on 31.03.2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\CNYHKey.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\WINDOWS\System32\MAFWTray.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\QuickHelpAlert.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Bluewin\Quick Help\bin\mpbtn.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
O2 - BHO: (no name) - {904CCFDB-F34A-4A0A-8B09-B2F33A4FBF05} - C:\WINDOWS\System32\awttuvu.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {CCB0A08E-9738-4B80-9126-695226A1EE58} - C:\WINDOWS\System32\awvvt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\System32\MAFWTray.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [PSDrvCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\QuickHelpAlert.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quick Help.lnk = C:\Program Files\Bluewin\Quick Help\bin\matcli.exe
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.interdiscount.ch/webapp/wcs/stores/servlet/StoreCatalogDisplay?langId=3&storeId=10001&catalogId=10001
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://www.zonealarm.com/
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://charon777.free.fr/plugins/hardwaredetection.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) - http://acs.pandasoftware.com/activescanpro/as5/asproinst.cab
O20 - Winlogon Notify: awttuvu - C:\WINDOWS\SYSTEM32\awttuvu.dll
O20 - Winlogon Notify: awvvt - C:\WINDOWS\System32\awvvt.dll
O20 - Winlogon Notify: winjyg32 - C:\WINDOWS\SYSTEM32\winjyg32.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe (file missing)
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Philips Semiconductors - (no file)
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Philips Semiconductors - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: DDE réseau (NetDDE) - Unknown owner - C:\WINDOWS\system32\netdde.exe
O23 - Service: DSDM DDE réseau (NetDDEdsdm) - Unknown owner - C:\WINDOWS\system32\netdde.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
Mais toujours de alertes je suis vraiment découragé
maudit Trojan downloader 6 alertes en 4 mn j'y crois pas
Aidez moi svp.
voilà le rap. SDFIX:
SDFix: Version 1.75
Run by Maryline-Tino - 30.03.2007 - 22:39:38.53
Microsoft Windows XP [version 5.1.2600]
Running From: C:\Documents and Settings\Maryline-Tino\Bureau\SDFIX\SDFix
Safe Mode:
Checking Services:
Restoring Windows Registry Entries
Restoring Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\WINDOWS\Temp\winC.tmp.exe - Deleted
C:\WINDOWS\Temp\winC.tmp.exe - Deleted
C:\WINDOWS\Temp\win*.tmp - Deleted
ADS Check:
C:\WINDOWS\system32
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
Remaining Files:
---------------
Backups Folder: - C:\DOCUME~1\MARYLI~1\Bureau\SDFIX\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes :
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c509 Packet\3C5X9PD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c556 Packet\3C556.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\3COM 3c59x Packet\3C59XPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1200 Packet\EC32PD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1203 Packet\PCIPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1204 Packet\VLNWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207 Packet\PCIPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207C Packet\PCIPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207D Packet\ACCPKT.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207F Packet\EN5251PD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1207TX Packet\PCIPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1208 Packet\1208PD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1625 Packet\NEPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1640 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1650 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1651 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1652 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1653 Packet\NE2PD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1656 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1657 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN1658 Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN166X Packet\NWPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2216 Packet\PCMPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2218 Packet\PCMPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2228 Packet\PCMPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\ACCTON EN2320 Packet\EN5251PD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DEVICE.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\KEYB.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MODE.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MOUSE.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\NETBIND.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\Paralink.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\command.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\IBMBIO.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\pcdos\IBMDOS.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE450 Packet\DE450.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWORKS DE500 Packet\DE500.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DEC EtherWorks ISA (DE305) Packet\DE305.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DE400 Packet\De400pd.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DMF560-TX Packet\Lmpd.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\DLink DT620 Packet\Dt620pd.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\IBM Crystal LAN Packet\Epktisa.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Kingston EtheRx KNE110TX Packet\Ktc110p.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD 10-100AL Packet\L100al.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD-CDF Packet\Ldcdt.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Laneed LD-PCI2TL Packet\Ldpcil.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Melco LPC2-T\Lpchkat2.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FNW9x00T - ENW8300T Packet\fetpkt.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\FETPKT.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Planex FW-100TX Fast Ethernet Packet\Rtspkt.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\PXE Packet Driver\Undipd.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\SN 2000p Packet\PNPPD.COM
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\WaveLAN Packet\Wvlan42.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX Packet\Cbepd.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS Packet\Xpspd.com
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom RE10 - RE100 Packet\Ce3pd.com
C:\WINDOWS\system32\awvvt.dll
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\CMDS16.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\E.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\GUEST.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\MSCDEX.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\Net.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\OHCI.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\PROTMAN.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\UHCI.EXE
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom CBE10-100BTX\Cbendis.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet 10-100 + Modem\Cbendis.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Ethernet II PS\Xpsndis.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom PE3-10Bx\Pe3ndis.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom Re-100Btx + Ce3B-100Btx\Ce3ndis.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\Xircom RE10BT\Ce3ndis.exe
C:\Program Files\Ahead\Nero Wave Editor\DXEnum.exe
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Elndis.sys
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\CATC USB Ethernet\Usbd.sys
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI1394.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI2DOS.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI4DOS.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI8DOS.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPI8U2.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPICD.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIEHCI.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIOHCI.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\ASPIUHCI.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BOOTSRV.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\bootsrv16.sys
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BTCDROM.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\BTDOSM.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\COUNTRY.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DISPLAY.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\DLSHELP.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\FLASHPT.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\HIMEM.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\KEYBOARD.SYS
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\msbootsrv16.sys
C:\Documents and Settings\All Users\Application Data\Symantec\Ghost\Template\common\OAKCDROM.SYS
C:\Documents and Settings\Maryline-Tino\Application Data\.E10FB8D272B730B3.sys
C:\Program Files\Common Files\X10\Common\x10prod.sys
C:\WINDOWS\LastGood.Tmp\INF\oem28.inf
C:\WINDOWS\LastGood.Tmp\INF\oem28.PNF
C:\WINDOWS\LastGood.Tmp\INF\oem29.inf
C:\WINDOWS\LastGood.Tmp\INF\oem29.PNF
C:\WINDOWS\LastGood.Tmp\INF\oem30.inf
C:\WINDOWS\LastGood.Tmp\INF\oem30.PNF
C:\WINDOWS\LastGood.Tmp\INF\oem31.inf
C:\WINDOWS\LastGood.Tmp\INF\oem31.PNF
Finished
**********************
Voilà le rapport hijackthis:
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 00:08:41, on 31.03.2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\brss01a.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\Dit.exe
C:\WINDOWS\mHotkey.exe
C:\WINDOWS\CNYHKey.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Home Cinema\PowerCinema\PCMService.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\DitExp.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\WINDOWS\System32\MAFWTray.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\QuickHelpAlert.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Logitech\SetPoint\KEM.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Logitech\SetPoint\KHALMNPR.EXE
C:\Program Files\Bluewin\Quick Help\bin\mpbtn.exe
C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NSMdtr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HiJackThis_v2.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~2\SDHelper.dll
O2 - BHO: (no name) - {904CCFDB-F34A-4A0A-8B09-B2F33A4FBF05} - C:\WINDOWS\System32\awttuvu.dll
O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {CCB0A08E-9738-4B80-9126-695226A1EE58} - C:\WINDOWS\System32\awvvt.dll
O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Home Cinema\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Fichiers communs\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Fichiers communs\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [MAFWTaskbarApp] C:\WINDOWS\System32\MAFWTray.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [PSDrvCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Bluewin\QUICKH~1\SMARTB~1\QuickHelpAlert.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Lancement rapide de Microsoft Office OneNote 2003.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\KEM.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quick Help.lnk = C:\Program Files\Bluewin\Quick Help\bin\matcli.exe
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O14 - IERESET.INF: START_PAGE_URL=http://www.interdiscount.ch/webapp/wcs/stores/servlet/StoreCatalogDisplay?langId=3&storeId=10001&catalogId=10001
O16 - DPF: {1754A1BA-A1DF-4F10-B199-AA55AA1A120F} (InstallerBehaviorFactory Class) - https://www.msn.com/fr-fr/
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan8/oscan8.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - https://www.zonealarm.com/
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://charon777.free.fr/plugins/hardwaredetection.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {D6376DD2-C2BD-49B2-A1B1-138F869633F3} (ASPRO Installer Class) - http://acs.pandasoftware.com/activescanpro/as5/asproinst.cab
O20 - Winlogon Notify: awttuvu - C:\WINDOWS\SYSTEM32\awttuvu.dll
O20 - Winlogon Notify: awvvt - C:\WINDOWS\System32\awvvt.dll
O20 - Winlogon Notify: winjyg32 - C:\WINDOWS\SYSTEM32\winjyg32.dll
O22 - SharedTaskScheduler: Pré-chargeur Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Démon de cache des catégories de composant - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Unknown owner - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe (file missing)
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Brother Industries, Ltd. - C:\WINDOWS\system32\Brmfrmps.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Client de licence CA (CA_LIC_CLNT) - Philips Semiconductors - (no file)
O23 - Service: Serveur de licence CA (CA_LIC_SRVR) - Philips Semiconductors - (no file)
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
O23 - Service: Service d'administration du Gestionnaire de disque logique (dmadmin) - Unknown owner - C:\WINDOWS\System32\dmadmin.exe
O23 - Service: Journal des événements (Eventlog) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Fax - Unknown owner - C:\WINDOWS\system32\fxssvc.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost 2003\GhostStartService.exe
O23 - Service: Service COM de gravage de CD IMAPI (ImapiService) - Unknown owner - C:\WINDOWS\System32\imapi.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Event Log Watch (LogWatch) - Computer Associates - C:\Program Files\CA\SharedComponents\CA_LIC\LogWatNT.exe
O23 - Service: Partage de Bureau à distance NetMeeting (mnmsrvc) - Unknown owner - C:\WINDOWS\System32\mnmsrvc.exe
O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: DDE réseau (NetDDE) - Unknown owner - C:\WINDOWS\system32\netdde.exe
O23 - Service: DSDM DDE réseau (NetDDEdsdm) - Unknown owner - C:\WINDOWS\system32\netdde.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Plug-and-Play (PlugPlay) - Unknown owner - C:\WINDOWS\system32\services.exe
O23 - Service: Gestionnaire de session d'aide sur le Bureau à distance (RDSessMgr) - Unknown owner - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\FICHIE~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Carte à puce (SCardSvr) - Unknown owner - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Journaux et alertes de performance (SysmonLog) - Unknown owner - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Cliché instantané de volume (VSS) - Unknown owner - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Carte de performance WMI (WmiApSrv) - Unknown owner - C:\WINDOWS\System32\wbem\wmiapsrv.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
31 mars 2007 à 02:49
31 mars 2007 à 02:49
SVP aidez moi c'est ma station de travail avec laquelle je travaille mes compos. et j'ai pas les moyens se m'en acheter un autre
Il doit y avoir un processus qui continue à me télécharger des Trojans j'ai tout fait ce que GenProc disait de faire
et ça nettoye, puis dès que j'ouvre I-explorer des alertes de norton s'ouvrent ne me disant: Trojan, Trojan...Trojan
c'est la deuxième nuit que j'y passe trop nerveux et anxieux pour dormir
Aidez-moi svp.
Il doit y avoir un processus qui continue à me télécharger des Trojans j'ai tout fait ce que GenProc disait de faire
et ça nettoye, puis dès que j'ouvre I-explorer des alertes de norton s'ouvrent ne me disant: Trojan, Trojan...Trojan
c'est la deuxième nuit que j'y passe trop nerveux et anxieux pour dormir
Aidez-moi svp.
papyber
Messages postés
6406
Date d'inscription
samedi 24 mars 2007
Statut
Contributeur sécurité
Dernière intervention
3 octobre 2010
257
31 mars 2007 à 09:56
31 mars 2007 à 09:56
il en reste
télécharge GenProc sur ton bureau
http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip
dézippe le dossier, double-clique sur GenProc.bat et poste le contenu du rapport qui s'ouvre
Aide en images : http://www.alt-shift-return.org/Info/GenProc-HowTo.html
par contre j'ai des soucis d'internet ne t'affole pas
télécharge GenProc sur ton bureau
http://www.alt-shift-return.org/Info/Fichiers/GenProc.zip
dézippe le dossier, double-clique sur GenProc.bat et poste le contenu du rapport qui s'ouvre
Aide en images : http://www.alt-shift-return.org/Info/GenProc-HowTo.html
par contre j'ai des soucis d'internet ne t'affole pas
doctor jekill
Messages postés
64
Date d'inscription
vendredi 26 août 2005
Statut
Membre
Dernière intervention
22 novembre 2007
31 mars 2007 à 14:05
31 mars 2007 à 14:05
Bonjour et salut je rentre a peine du travail
merci de m'aider
je poste le rapport en précisant que j'ai déja fait trois fois ce qu'il y à écrit bon une fois de plus car il en reste je crois au fait qu'il reviennent!
Rapport GenProc 0.32 effectué le 31.03.2007 à 13:59:15.42 - SystemRoot = C:\WINDOWS
# Etape 1/ Télécharge :
- SDfix http://downloads.andymanchesta.com/RemovalTools/SDFix.exe (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
***** Copie ce qui suit dans un fichier texte et redémarre en mode sans échec comme indiqué ici https://docs.microsoft.com/en-us/?mfr=true (choisis ta session courante "Maryline-Tino") *****
# Etape 2/
Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et double clique sur "RunThis.bat" pour lancer le script.
- Appuie sur "Y" pour commencer le processus de nettoyage.
- Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
- Appuie sur une touche pour redémarrer le PC.
- Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
- Après le chargement du Bureau, l'outil terminera son travail et affichera "Finished".
- Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
- Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom "Report.txt".
~ Le fichier "SDFIX_README.htm" (dans le dossier SDFix) contient la liste des malwares pris en compte par l'outil.
~ Andy fait plusieurs mises à jour, souvent plus d'une par jour... N'hésite donc pas à télécharger une nouvelle version lorsque le nettoyage dure et que l'outil ne semble pas tout voir.
# Etape 3/
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
# Etape 4/
Redémarre normalement et poste :
- Un nouveau rapport HijackThis, toutes fenêtres et applications fermées si tu ne l'as pas tu trouveras HijackThis ici http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis_v2.exe ;
- Le contenu du fichier Report.txt ;
Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
merci de m'aider
je poste le rapport en précisant que j'ai déja fait trois fois ce qu'il y à écrit bon une fois de plus car il en reste je crois au fait qu'il reviennent!
Rapport GenProc 0.32 effectué le 31.03.2007 à 13:59:15.42 - SystemRoot = C:\WINDOWS
# Etape 1/ Télécharge :
- SDfix http://downloads.andymanchesta.com/RemovalTools/SDFix.exe (créé par AndyManchesta) et sauvegarde le sur ton Bureau.
***** Copie ce qui suit dans un fichier texte et redémarre en mode sans échec comme indiqué ici https://docs.microsoft.com/en-us/?mfr=true (choisis ta session courante "Maryline-Tino") *****
# Etape 2/
Ouvre le dossier SDFix qui vient d'être créé sur le Bureau et double clique sur "RunThis.bat" pour lancer le script.
- Appuie sur "Y" pour commencer le processus de nettoyage.
- Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
- Appuie sur une touche pour redémarrer le PC.
- Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
- Après le chargement du Bureau, l'outil terminera son travail et affichera "Finished".
- Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
- Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom "Report.txt".
~ Le fichier "SDFIX_README.htm" (dans le dossier SDFix) contient la liste des malwares pris en compte par l'outil.
~ Andy fait plusieurs mises à jour, souvent plus d'une par jour... N'hésite donc pas à télécharger une nouvelle version lorsque le nettoyage dure et que l'outil ne semble pas tout voir.
# Etape 3/
Lance CCleaner : "Nettoyeur"/"lancer le nettoyage" et c'est tout.
# Etape 4/
Redémarre normalement et poste :
- Un nouveau rapport HijackThis, toutes fenêtres et applications fermées si tu ne l'as pas tu trouveras HijackThis ici http://www.trendsecure.com/portal/en-US/threat_analytics/HiJackThis_v2.exe ;
- Le contenu du fichier Report.txt ;
Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.