Impossible de télécharger Acrobat Reader

catpeople12 Messages postés 122 Statut Membre -  
 BOB3 -
Bonjour à tous,

J'ai Windows XP Pro Version 2002 Service Pack 3. Après une attaque de Zlob bien nettoyée, mon Acrobat Reader 8.1.2 s'est mis à mal fonctionner. Résultat des courses, je ne peux plus lire des fichiers PDF ou regarder aucune vidéo sur YouTube car je ne peux pas télécharger Flash Player correctement. J'ai essayé plusieurs fois d'en télécharger la dernière version (Flash Player 9), le site me dit que c'est bien téléchargé mais l'icône Adobe Flash Player Plugin qui figure sur la liste de programmes de mon Panneau de Configuration affiche un petit X rouge sur un coin et aucune taille en Mo...

Pour continuer, j'ai consulté des forums qui conseillaient de désinstaller Acrobat et de le re-télécharger après. Comme un bon soldat j'ai donc désinstallé Acrobat de mon ordi et maintenant je ne peux plus le télécharger de nulle part!!! A chaque fois que j'essaie de le faire j'ai un message d'erreur bizarroïde qui me dit que mon ordinateur est sous une version Windows 2000 (!!??) et qu'il faut que j'upgrade mon ordi à Windows 2000 SP 4 (!!??) pour pouvoir télécharger Adobe Reader 8.1.2. Je ne comprends fichtre rien à cette histoire et voudrait savoir si qqn. pouvait m'aider...

Pour la petite histoire, j'ai téléchargé Foxit Reader pour pouvoir lire des fichiers en PDF, j'ai quand même pu télécharger Adobe Air et Adobe Media Player (ce qui n'a pas résolu mon problème de lecture de vidéos sur YouTube!!). Et au cas où qqn pense me poser la question, j'ai Java correctement installé sur mon ordi (même que j'ai la dernière mise à jour!!, oui m'sieur!)

Alors... AU SECOUUUUUUURS!!!!!!!

ET MERCI D'AVANCE!

CP12
Configuration: Windows XP
Internet Explorer 7.0

74 réponses

  • 1
  • 2
  • 3
  • 4
Résumé de la discussion

Le problème survient après le nettoyage d’une infection Zlob: Acrobat Reader 8.1.2 ne lit plus les PDFs et les vidéos ne se lisent pas, Flash Player échoue à s’installer et Windows peut afficher une erreur indiquant Windows 2000 lors des tentatives de réinstallation.
Les conseils préconisent d’abord de supprimer les composants malveillants (notamment Zango), puis d’utiliser SDFix en mode sans échec, d’exécuter HijackThis et d’effectuer un nettoyage complet avec CCleaner.
Des instructions détaillent la fermeture de processus nuisibles, la suppression de fichiers et clés de registre problématiques, la vérification des éléments de démarrage et la correction d’entrées spécifiques dans le navigateur et le fichier Hosts.
Des vérifications complémentaires ciblent des infections persistantes (W32/Zlob.BWLZ et Renos.XS), la vérification d’un fichier lié à Kaspersky, la restauration et la création d’un nouveau point de restauration, ainsi que l’utilisation d’outils comme SmitfraudFix pour un nettoyage final.

Généré automatiquement par IA
sur la base des meilleures réponses
  1. rebitus
     
    Salut,
    Une version Windows 2000 (!!??) et qu'il faut que j'upgrade mon ordi à Windows 2000 SP 4
    Le sp4 pour windows 2000 est presque obligatoire on peu rien faire sans. Il suffit de retrouver se sp4 pour windows 2OOO. Par contre, je sais pas si il est en update direct vu que c 'est vieux et quand general les personnes l ont directement stocker sur le disque dur.
    Pour acrobat ils doivent surement etre en maintenance securite. Il avait des problemes et on fermer certain telechargement. Il son aussi entrain de sortir de nouveau produits online.
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      Merci de ton conseil Rebitus!

      Je vais aller piocher dans le site Windows Update voir ce que je peux trouver sur W 2000 SP4 et je te tiens au courant si ça me permet de télécharger Acrobat.

      (J'espère que l'impossibilité de télécharger la dernière version de ce logiciel est dûe à ce que tu dis à propos de leur site)

      A+

      Catpeople12
      0
    2. catpeople12 Messages postés 122 Statut Membre
       
      Salut Rebitus et tous ceux qui pourraient m'aider!

      J'ai trouvé Windows 2000 SP4 sur le site Windows Update grâce aux conseils de Rebitus, que je remercie.

      J'ai commencé à le télécharger mais avant la fin du téléchargement le message d'erreur suivant est apparu:

      Le programme d'installation n'a pas pu vérifier l'integrité du fichier Update.inf. Assurez-vous que le service de cryptographie est en cours d'exécution sur cet ordinateur.

      Je suis donc allé vérifier dans le Panneau de Configuration / Outils d'administration / Services / Services de cryptographie et les propriétés indiquent que c'est Démarré de manière Automatique

      J'ai donc un problème! Hein?

      Mais je ne sais ni ce que c'est ni comment le résoudre!!!.....

      HEEEEELP!!!!!
      0
  2. catpeople12 Messages postés 122 Statut Membre
     
    Re-salut à tous,

    Je viens également de me rendre compte que je ne peux même pas télécharger Adobe Flash Player. Le site Adobe me dit toujours que le téléchargement a été effectué mais le logiciel n'est nulle part sur mon ordi.

    Il n'y a que Java qui y est et qui fonctionne parfaitement.

    Alors, soit le site Adobe a des problèmes, soit mon ordi a un problème que je n'arrive pas à déceler! Pourtant les services de cryptographie de l'ordi sont activés, la navigation sur Internet et tous les affichages sur mon ordi marchent très rapidement comme d'habitude...

    N'étant pas un pro de l'informatique, j'ai vraiment besoin de l'aide de quelqu'un qui s'y connaît...

    Merci d'avance à tous!

    Catpeople12
    0
  3. catpeople12 Messages postés 122 Statut Membre
     
    Salut à tous,

    Je crois savoir pourquoi je ne peux pas télécharguer Adobe. C'est que mon ordi n'a apparement plus le SP4 pour Windows 2000. Je suis allé le chercher sur Internet et le téléchargement a bien commencé. Mais au moment de l'installation j'ai eu le message d'erreur suivant:

    "Le programme d'installation n'a pas pu vérifier l'intégrité du fichier Update.inf. Assurezvous que le service de cryptographie est en cours d'exécution sur cet ordinateur."

    Selon les instructions données sur ce forum à ceux qui ont le même problème, je suis allé sur le Panneau de Configuration => Outils d'administration=> Services=>Services de cryptographie, j'ai cherché les propriétés du service et il est activé en mode automatique. J'ai quand même redémarré le service et rebooté l'ordi. Mais après une nouvelle tentative de téléchargement du SP4 pour Win 2000 le même message est encore apparu ! Je ne comprends pas ce qui se passe...

    Est-ce que quelqu'un pourrait me conseiller pour résoudre ce problème, SVP?

    Merci!

    CP12
    0
  4. BOB3
     
    Bonjour a vous tous,
    une question catpeople12,

    tu dis que t'es equipé avec xp pro sp3, je vois pas pourquoi tu passes sur xin 2000 + sp4 etc..
    merci confirmer quelle version exacte t'as sur ta machine, je vais essayer de te trouver une solution
    a+
    BOB3
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. catpeople12 Messages postés 122 Statut Membre
     
    Salut BOB3 et merci de ta réponse.

    Je suis sous Windows XP Pro Version 2002 Service Pack 3. J'essaie de télécharger Win 2000 SP4 juste parce qu'à chaque fois que j'ai essayé de télécharger la dernière version d'Acrobat un message du genre "la versoin 2000 sous laquelle vous êtes ne accepte pas ce fichier. Mettez-la à jour avec Windows 2000 sp4 avant de le télécharger".

    Je pensais que Win 2000 SP4 était un composant nécessaire à mon système qui me permettrait de télécharger la dernière version d'Acrobat. Qu'en penses-tu?

    Par la même occas, je n'arrive même pas à télécharger la dernière version d'Acrobat Flash Player sur mon système, ce qui m'empêche de regarder des vidéos sur YouTube.

    Ce serait sympa si tu me trouvais une solution!

    MERCI et à bientôt!

    catpeople12
    0
  7. BOB3
     
    Re catpeople12,

    oubli win2000,

    redemarres en mode sans echec et essayes de desinstaller completement ADOBE--tu le reinstalles apres.

    tu va verifier apres l'integrité de tes fichiers xp
    tu mets ton cd d'installation dans le lecteur cd principal
    tu clic sur demarrer, executer, et tu tapes : sfc /scannow
    regarde le lien
    https://www.pcastuces.com/pratique/windows/xp/default.htm
    et tu laisses faire,
    tu redemarres,
    ensuite tu va lancer Microsoft onecare sur ce lien
    https://www.msn.com/fr-fr/
    tu lances le lien, tu acceptes les activx, et tu clic sur analyse complete.
    ca va prendre tu temps, windows va tout nettoyer et retablir ta base de registre.
    tu laisse terminer, tu reboot, et tu nous tiens au courant.
    a+
    BOB3
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      Salut BOB3!

      Je vais suivre tes indications et je te tiendrai au courant dès que j'ai fini.

      MERCI BEAUCOUP!!

      A+

      catpeople12
      0
    2. catpeople12 Messages postés 122 Statut Membre
       
      Re BOB3,

      La première partie de tes indications a marché du Tonnerre (Merci!)! J'avais en effet des fichiers .dll endommagés à cause d'un cheval de Troie (Zlob) que j'ai choppé il y a une semaine (malgré mon Kaspersky) et que j'ai pu supprimer en suivant des recommendations sur ce Forum. Alors tous les fichiers protégés endommagés ont été réparés ou restaurés avec mon CDROM XP. J'ai aussi complètement supprimé Adobe de mon ordi. Je t'en dois une fière chandelle!

      En revanche, il se passe un truc bizarre avec le second lien pour Windows Onecare que tu m'as donné. Quand je clique sur Analyse complète pour que le scanner se mette en route, la fenêtre de dialogue qui indique le statut de l'analyse s'affiche. Mais il s'affiché quelques secondes après une petite fenêtre de dialogue dans celle de Onecare qui me dit qu'il y a eu une erreur de script sur la page avec Explorer et si je veux quand même continuer. J'appuie sur Oui et la fenêtre W. Onecare devient comme un cadre avec juste les bordures et ne veut plus se fermer; je ne peux que la réduire... Pour qu'elle disparaisse je suis obligé de redémarrer l'ordi. Je me reconnecte sur Onecare, j'essaie à nouveau et la même chose arrive... Je n'ai aucun indice qu'il se passe quelque chose...

      Ne connaissant pas bien W. Onecare, pourrais-tu me dire si c'est normal? Je pense qu'il doit y avoir un schmol, mais je ne suis pas un crack en informatique...

      Dans l'attente de tes conseils et te remerciant encore de ton aide, je te salue bien cordialement.

      catpeople12
      0
  8. BOB3
     
    Bonne soiree catpeople12,

    content pour toi que t'as pu reparer tes fichiers systeme,
    l'erreur du script c'est relatif a ton navigateur IE7, j'espere qu'il n'est pas endommagé.
    ouvre proprieté internet explorer,
    1--dans genetal, puis les 2 parametres recherches+onglets, clic sur parametres et mets par defaut.
    2--dans securité, tu mets tout par defaut
    3--dans confidentialite, mets le par defaut pour acceptes les cookies microsoft en auto-----je te conseilles par la suite de le mettre sur Haute
    4--dans avancés tu clic sur Rétablir les paramètres avancés --- uniquement.

    et tu essayes de te connecté a nouveau sur oncare.
    a+
    BOB3
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      Bonjour BOB3,

      Merci encore de tes bons conseils!!!

      J'ai suivi tes indications concernant IE7 et la même chose est arrivée quand j'ai essayé de télécharger le scanner onecare pou démarrer l'analye complète... Une erreur de script s'est produite et après, ça s'est mis à mouliner sans aucune réaction. J'ai donc dû désactiver la page avec le gestionnaire des tâches.... Pourtant j'ai mis onecare comme site de confiance dans IE7 et Kaspersky...

      Peut-être que IE7 est endommagé comme tu penses et je ne sais pas comment faire pour le réparer si c'est le cas...

      Pourrais-tu encore m'aider, STP?

      Merci!

      catpeople12
      0
  9. BOB3
     
    Bonjour catpeople12,

    telecharge a nouveau IE7, installes le + mise a jour sans oublier de reparametrer comme preciser en 11

    http://www.microsoft.com/downloads/details.aspx?FamilyId=9AE91EBE-3385-447C-8A30-081805B2F90B&displaylang=fr

    tu va sur onecare a nouveau, et tu refaits une verif complete.
    tiens moi au courant.
    BOB3
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      Bonsoir BOB3,

      Bon! Au rapport... J'ai téléchargé à nouveau IE7 et tout s'est bien passé. Tous ses paramètres sont également par défaut conforme à tes conseils. (De toute façon avec le téléchargement tout vient par défaut)

      Cependant, le problème avec Onecare persiste malgré tout... Toujours la bonne vieille erreur de script sur la page qui me bloque tout et qui m'empêche de faire l'analyse complète... Je ne sais plus quoi faire!... Je vais finir par croire que ce site n'aime pas mon ordi, même si mon ordi lui fait confiance...

      Aurais-tu une autre idée sous la manche?...

      Je te remercie une fois de plus de ton aide et te salue bien cordialement,

      catpeople12
      0
  10. BOB3
     
    Bonne soiree catpeople,

    va dans panneau de configuration, clic sur java, mets le a jour,
    toujours sur java, tu desactive la mise ajour auto, et dans Avancé,
    puis, java par defaut des navigateur, tu mets sur Intenet explorer.
    tu reboot, et dans propriete internet explorer, tu ouvres Avancés, tu defiles,
    sous Navigation, tu coches sur les deux case ----desactiver le debogage de script
    on verra bien.
    a+
    BOB3
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      Bonjour BOB3

      Je suis allé sur Java. J'ai cliqué sur mettre à jour maintenant mais il me dit que j'ai la toute dernière version Java d'installée dans mon ordinateur qui est en fonction. J'ai desactivé la mise à jour auto mais Internet Explorer était déjà coché comme navigateur par défaut sur Java.

      Ensuite j'ai rebooté et suis allé voir dans les propriétés internet/avancé/Navigation. Les deux cases de débogage de scripts étaient déjà cochées.

      Je retente le coup avec Onecare et te tiens au courant.

      MERCI encore!

      catpeople12
      0
    2. catpeople12 Messages postés 122 Statut Membre
       
      Re BOB3!

      Eh ben, après exécution des indications pour Java et IE, ça ne marché toujours pas... Il y a encore cette satanée erreur de script sur la page et je suis obligé de la fermer avec le Gestionnaire de Tâches...

      C'est dingue!!!!! ... ...

      Dans l'attente de tes conseils, je te remercie encore et te salue bien Cordialement,

      catpeople12
      0
  11. BOB3
     
    Salut catpeople,
    repostes le message exact que le system te donnes lorsque t'es sur one care.
    a+
    BOB3
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      Salut BOB3!

      Voici le message exact:

      !
      Une erreur est survenue dans le script de cette page
      Ligne: 26
      Caractère : 1
      Erreur : Objet attendu
      Code : 0
      URL : about: blank

      Voulez-vous continuer à exécuter les scripts de cette page?

      Oui Non


      Que j'appuie sur Oui ou Non ne change rien; ça mouline et je n'ai plus rien...

      J'espère que ceci va t'aider à savoir d'où ça vient.

      Merci encore et

      A+

      catpeople12
      0
  12. BOB3
     
    Re catpeople,
    telecharge Hijackthis sur ce lien, installes le en mode auto,
    ftp://ftp.commentcamarche.com/download/HJTInstall.exe

    clic sur son icone sur le bureau, et fait: Do a systel scan and save logfile
    copier / coller sur le post
    a+
    BOB3
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      Salut BOB3,

      Voici le résultat du scan:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 08:58:44, on 07/07/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
      Boot mode: Normal

      Running processes:
      C:\windows\System32\smss.exe
      C:\windows\system32\winlogon.exe
      C:\windows\system32\services.exe
      C:\windows\system32\lsass.exe
      C:\windows\System32\Ati2evxx.exe
      C:\windows\system32\svchost.exe
      C:\windows\System32\svchost.exe
      C:\windows\system32\Ati2evxx.exe
      C:\WINDOWS\System32\brsvc01a.exe
      C:\windows\Explorer.EXE
      C:\WINDOWS\System32\brss01a.exe
      C:\windows\system32\spoolsv.exe
      C:\windows\SOUNDMAN.EXE
      C:\Program Files\VIA\RAID\raid_tool.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Logitech\Video\LogiTray.exe
      C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\Program Files\yodm 3D\Yodm3D.exe
      C:\Program Files\Messenger\msmsgs.exe
      C:\PROGRA~1\MI3AA1~1\wcescomm.exe
      C:\windows\system32\ctfmon.exe
      C:\PROGRA~1\MI3AA1~1\rapimgr.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      C:\windows\system32\cisvc.exe
      C:\windows\System32\svchost.exe
      C:\WINDOWS\system32\LVComS.exe
      C:\WINDOWS\system32\inetsrv\inetinfo.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\WINDOWS\system32\PSIService.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
      C:\windows\system32\svchost.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\windows\system32\cidaemon.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: (no name) - {9989F1F6-70DE-4244-AC9F-6672983681A0} - (no file)
      O2 - BHO: (no name) - {A49E097A-D6EF-4B2F-8B0F-1230E998587F} - C:\Program Files\Web Technologies\iebt.dll (file missing)
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O2 - BHO: 238044 helper - {C0F371D7-926D-4700-B65E-63BFF1197205} - C:\WINDOWS\system32\238044\238044.dll (file missing)
      O3 - Toolbar: Internet Service - {F99D0C20-F8E1-43B6-AB24-3F16BFAEA77B} - C:\Program Files\Web Technologies\iebr.dll (file missing)
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
      O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [Yodm3D] C:\Program Files\yodm 3D\Yodm3D.exe
      O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
      O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
      O4 - HKCU\..\Run: [I&F Viewer toolbar] "C:\Program Files\Photo Toolkit\ivbar\phototoolkitmem.exe" -start
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
      O4 - Startup: MyTrashCan.lnk = C:\Program Files\Hiro's tool\MyTrashCan\MyTrashCan.exe
      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
      O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
      O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O15 - Trusted Zone: http://www.1001interims.com
      O15 - Trusted Zone: https://www.adobe.com/
      O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
      O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
      O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
      O15 - Trusted Zone: https://www.ustart.org
      O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
      O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
      O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
      O15 - Trusted Zone: https://www.msn.com/fr-fr/
      O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
      O15 - Trusted Zone: https://fr.yahoo.com/
      O15 - Trusted Zone: https://www.youtube.com/
      O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
      O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
      O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.serviceshub.microsoft.com/supportforbusiness/create
      O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPUpld.cab
      O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
      O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-e84a02c34e2ab3f9.spaces.live.com/PhotoUpload/MsnPUpld.cab
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?e=1214407856230&h=460b6a4386982a6d227dd6ec47e07839/&filename=jinstall-6u6-windows-i586-jc.cab
      O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
      O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
      O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: MicroSoft Media Tools - Unknown owner - C:\WINDOWS\MSmedia.exe (file missing)
      O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
      O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
      0
  13. BOB3
     
    Bonjour catpeople12,
    Pas mal de problemes a regler

    tu telecharge Ccleaner, tu l'installes sans la barre YAHOO
    dans applications tu coches tout
    tu le lances et tu fait un nettoyage complet: nettoyeur puis registre

    1---pour commencer, tu va desinstallé afin de regler un desordre dans la base de registre
    windows live messenger, tu le reinstalles plus tard sans les sponsors de pub.
    windows live onecare
    logitech webcam---tu la reistalles plus tard

    2--tu a un service proxy qu'il faut desactiver
    dans prpriete internet explorer, puis connexions, parametres reseau, et tu desactive tout

    3--tu va dans demarrer, panneau de configuration, options regionales et linguistiques, langues, details, avancé,
    et tu coches arreter les services de textes avances.

    4--tu lance msconfig.exe, puis demarrage, et s'il existe, du desactives
    ctfmon.exe
    LVComS.exe

    tu redemarres ton ordi mode sans echec,
    tu lance Hijackthis en mode Do a system Scan
    tu coches les clefs suivantes, puis tu clic en bas a gauche sur: Fix Checked
    C:\WINDOWS\system32\LVComS.exe

    O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O2 - BHO: (no name) - {9989F1F6-70DE-4244-AC9F-6672983681A0} - (no file)

    O2 - BHO: (no name) - {A49E097A-D6EF-4B2F-8B0F-1230E998587F} - C:\Program Files\Web Technologies\iebt.dll (file missing)
    O2 - BHO: 238044 helper - {C0F371D7-926D-4700-B65E-63BFF1197205} - C:\WINDOWS\system32\238044\238044.dll (file missing)
    O3 - Toolbar: Internet Service - {F99D0C20-F8E1-43B6-AB24-3F16BFAEA77B} - C:\Program Files\Web Technologies\iebr.dll (file missing)

    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe

    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Yodm3D] C:\Program Files\yodm 3D\Yodm3D.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O4 - Startup: MyTrashCan.lnk = C:\Program Files\Hiro's tool\MyTrashCan\MyTrashCan.exe
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

    O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
    O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.serviceshub.microsoft.com/supportforbusiness/create
    O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPUpld.cab
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
    O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-e84a02c34e2ab3f9.spaces.live.com/PhotoUpload/MsnPUpld.cab
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: MicroSoft Media Tools - Unknown owner - C:\WINDOWS\MSmedia.exe (file missing)
    O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)

    Tu lance Ccleaner, tu fait un nettoyage complet

    tu reboot en mode normal, et tu remets un nouveau log Hijackthis.
    a+
    BOB3
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      Re-BOB3 et MERCI encore de ton aide!

      J'ai suivi tes instructions à la lettre. Avant de te soumettre le nouveau log Hijackthis, et au cas où ça pourrait être important, je t'informe qu'après le System Scan de Hijackthis en Mode Sans Echec il manquait les clefs suivantes sur la liste, qui apparaissaient sur celle que tu m'as donné à cocher au préalable:

      C:\WINDOWS\system32\LVComS.exe
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab

      Une fois les clefs trouvées cochées, j'ai lancé Fix Checked et pendant le processus le message suivant est apparu:

      Impossible to repair 010 Winsock LSP entries
      Use LSP Fix, which can be downloaded at http://www.cexx.org/lspfix.htm

      If the 010 item belongs to WebHancer, New.Net or Common/Name, Spybot S&D can remove it automatically.


      J'ai donc profité pour lancer un balayage avec Spybot et aucun mouchard n'a été trouvé.

      J'ai rebooté l'ordi et immédiatement j'ai eu une mise à jour de sécurité Windows (KP950759) pour IE7.

      Et voici maintenant le nouveau log Hijackthis:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:56:38, on 07/07/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
      Boot mode: Normal

      Running processes:
      C:\windows\System32\smss.exe
      C:\windows\system32\winlogon.exe
      C:\windows\system32\services.exe
      C:\windows\system32\lsass.exe
      C:\windows\System32\Ati2evxx.exe
      C:\windows\system32\svchost.exe
      C:\windows\System32\svchost.exe
      C:\WINDOWS\System32\brsvc01a.exe
      C:\WINDOWS\System32\brss01a.exe
      C:\windows\system32\spoolsv.exe
      C:\windows\system32\Ati2evxx.exe
      C:\windows\Explorer.EXE
      C:\Program Files\VIA\RAID\raid_tool.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\PROGRA~1\MI3AA1~1\wcescomm.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
      C:\PROGRA~1\MI3AA1~1\rapimgr.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      C:\windows\system32\cisvc.exe
      C:\windows\System32\svchost.exe
      C:\WINDOWS\system32\inetsrv\inetinfo.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\WINDOWS\system32\msiexec.exe
      C:\WINDOWS\system32\PSIService.exe
      C:\windows\system32\svchost.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      C:\windows\system32\wuauclt.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
      O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
      O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O15 - Trusted Zone: http://www.1001interims.com
      O15 - Trusted Zone: https://www.adobe.com/
      O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
      O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
      O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
      O15 - Trusted Zone: https://www.ustart.org
      O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
      O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
      O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
      O15 - Trusted Zone: https://www.msn.com/fr-fr/
      O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
      O15 - Trusted Zone: https://fr.yahoo.com/
      O15 - Trusted Zone: https://www.youtube.com/
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
      O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
      O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
      0
  14. BOB3
     
    Re catpeople12,

    on avance,
    1--une question a confirmer,
    si j'ai bien compris t'as bien supprimé
    --->C:\WINDOWS\system32\LVComS.exe
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab

    sinon, tu les fix avec Hijackthis en mode normal.

    tu telecharge LSP Fix sur ce lien developpé par (IUP / Indiana University of Pensylvania)
    http://old.www.iup.edu/house/resnet/WinsockXPFix.exe

    MAIS TU NE FAIT RIEN POUR LE MOMENT.
    en attente reponse, je decortique ton log
    a+
    BOB3
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      Re, BOB3!

      Je suis super content que ça avance!!

      Ton aide m'est vraiment précieuse ( même si 90% du temps je ne comprends pas trop ce que je suis en train de faire... ) et je continuerai à suivre tes indications à la lettre.

      Quant à la question que tu souhaitais confirmer:

      Je n'ai pas supprimé les clefs que je t'ai énumérées et que tu mets dans ta question.
      Elles ne figuraient tout simplement pas sur la liste de clefs qui s'est affichée après le scan the Hijackthis en mode sans échec...

      Est-ce grave?

      Je télécharge LSP Fix et j'attends tes consignes.

      A+

      catpeople12
      0
  15. BOB3
     
    Re catpeople12,

    1---a varifier, dans le log je remarque que ton antivirus Kaspersky se lance a 3 reprises
    regarde la liste des services au debut
    a partir de
    Boot mode: Normal ---->jusqu'a c:\program files\trend micro\hijackthis\hijackthis.exe

    2--tu vas dans c:\windows\Downloaded Program Files--->et tu supprimes tout les activex installés
    clic droit, puis supprimé
    a fure et mesure, tu acceptes a nouveau les activx de windows a nouveau

    3---il faut faire la meme manip avec HJT, et faire un Fix checked sur les clefs suivantes
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
    O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
    O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

    tu passe un coup de Ccleaner, tu reboot et tu remets un nouveau log.
    a+
    BOB3
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      Re, BOB3!

      Je viens d'enregistrer LSP Fix sur mon bureau en attendant tes instructions.

      Question importante avant de continuer:

      La suppression des activex dans c:\windows\Downloaded Program Files et la seconde manip avec HJT avec la réparation des clefs, je la fais en Mode sans échec ou tout de suite en mode normal?

      A toi, chef!

      Cordialement,

      catpeople12
      0
    2. catpeople12 Messages postés 122 Statut Membre
       
      Re, BOB3,

      Tu as raison! Kaspersky se lance à 3 reprises selon le log 2 de HJT...
      Y a-t-il une manip à faire pour résoudre ça si c'est anormal?

      J'attends tes instructions pour supprimer les activex dans C:\Windows\Downloaded Program Files, puis pour lancer HJT à nouveau et faire réparer les clefs que tu as identifiées, soit en mode sans échec, soit en mode normal.

      Dans quel mode j'effectue les deux actions STP?

      MERCI!

      A+

      catpeople12
      0
  16. BOB3
     
    Re catepeople,

    1--activex en mode normal
    2--pour le Fix, tu faits en mode normal, si traces restantes, en mode sans echec.

    je te mets d'autres manip a faire, prend ton temps, et procede avec prudence.
    a+
    BOB3
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      Re BOB3,

      Rapport jusqu'au message 28:

      Log HJT 2:


      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:56:38, on 07/07/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
      Boot mode: Normal

      Running processes:
      C:\windows\System32\smss.exe
      C:\windows\system32\winlogon.exe
      C:\windows\system32\services.exe
      C:\windows\system32\lsass.exe
      C:\windows\System32\Ati2evxx.exe
      C:\windows\system32\svchost.exe
      C:\windows\System32\svchost.exe
      C:\WINDOWS\System32\brsvc01a.exe
      C:\WINDOWS\System32\brss01a.exe
      C:\windows\system32\spoolsv.exe
      C:\windows\system32\Ati2evxx.exe
      C:\windows\Explorer.EXE
      C:\Program Files\VIA\RAID\raid_tool.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\PROGRA~1\MI3AA1~1\wcescomm.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
      C:\PROGRA~1\MI3AA1~1\rapimgr.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      C:\windows\system32\cisvc.exe
      C:\windows\System32\svchost.exe
      C:\WINDOWS\system32\inetsrv\inetinfo.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\WINDOWS\system32\msiexec.exe
      C:\WINDOWS\system32\PSIService.exe
      C:\windows\system32\svchost.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      C:\windows\system32\wuauclt.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
      O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
      O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
      O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
      O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O15 - Trusted Zone: http://www.1001interims.com
      O15 - Trusted Zone: https://www.adobe.com/
      O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
      O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
      O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
      O15 - Trusted Zone: https://www.ustart.org
      O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
      O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
      O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
      O15 - Trusted Zone: https://www.msn.com/fr-fr/
      O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
      O15 - Trusted Zone: https://fr.yahoo.com/
      O15 - Trusted Zone: https://www.youtube.com/
      O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
      O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
      O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
      0
  17. BOB3
     
    Re catpeople12,

    traces de trojan a irradiquer

    1---Désinstalle le programme Zango par Ajout/Suppression de programmes (Si tu le trouves)

    2---Télécharge SDFix de AndyManchesta et sauvegarde le sur ton Bureau.
    http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

    Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.
    Redémarre ton ordinateur en mode sans échec.

    Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
    Appuie sur Y pour commencer le processus de nettoyage.

    Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
    Appuie donc sur une touche.

    Ton système sera plus long pour redémarrer que d'habitude car l'outil va continuer à s'exécuter et supprimer des fichiers.

    Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
    Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.

    Une fois les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt. Il faudra coller ce rapport dans ta prochaine réponse.

    3-----Fais Ctrl + Alt + Suppr pour ouvrir le gestionnaire de tâches.
    Choisis l'onglet Processus
    Dans la colonne Nom de l'image, recherche si tu trouves
    le processus zango.exe
    Clique droit dessus et choisis Terminer le processus
    Recherche ensuite le processus mnew1winc4.exe
    Clique droit dessus et choisis Terminer le processus

    4-----Relance HijackThis et coche les lignes suivantes si tu les trouves

    O2 - BHO: Zango Search Assistant Helper /fleok=1D8A83A5C1E0197791AE75760EA83FA5EF80752B94E2DE7E5A7A47203BCF - {56F1D444-11BF-4879-A12B-79CF0177F038} - c:\program files\zango\zangohook.dll
    O4 - HKLM\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe
    O4 - HKLM\..\Run: [Memory manager] C:\WINDOWS\System32\himem32.exe
    O4 - HKLM\..\Run: [zango] "c:\program files\zango\zango.exe"
    O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\System32\rpcc.exe
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
    O4 - HKLM\..\RunServices: [Printer] C:\WINDOWS\System32\auditchk.exe
    O4 - HKCU\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe
    O4 - HKCU\..\Run: [dpr0] C:\WINDOWS\system32\prod.exe
    O4 - HKCU\..\Run: [chsr] C:\WINDOWS\system32\lssrvc.exe
    O4 - HKCU\..\Run: [mlrnew1c4] C:\WINDOWS\system32\mnew1winc4.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O20 - Winlogon Notify: rpcc - C:\WINDOWS\System32\rpcc.dll (file missing)
    O20 - Winlogon Notify: rpccd - C:\WINDOWS\System32\rpccd.dll

    Clique sur Fix Checked et confirme le message qui suit.

    5----Avec l'explorateur Windows, recherche les fichiers/dossiers suivants et supprime les (si toujours présents):
    c:\program files\zango <-- Le dossier
    C:\WINDOWS\System32\auditchk.exe (Attention à l'orthographe)
    C:\WINDOWS\System32\himem32.exe (Là encore, attention à l'orthographe)
    C:\WINDOWS\System32\rpcc.exe
    C:\WINDOWS\system32\prod.exe
    C:\WINDOWS\system32\lssrvc.exe
    C:\WINDOWS\system32\mnew1winc4.exe
    C:\WINDOWS\System32\rpcc.dll
    C:\WINDOWS\System32\rpccd.dll

    6--lance Ccleaner, nettoyage, reboot, et tu postes le log Report.txt de Sdfix.
    a+
    BOB3
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      Salut BOB3!

      Pas de traces de zango nulle part; aucun processus dans le Gestionnaire de Tâches, aucune des clefs que tu m'as demandé de cocher ni aucun fichier recherché avec l'explorateur Windows n'a été trouvé... (COOL!)


      Pendant l'analyse de SDFix, le message suivant s'est affiché:

      Note: Protective Host Files such as MVPS/HP hosts or Spybot Immunizers must be applied after SDFix analysis

      J'ai Spybot S&D et il immunize le système. Dois(je le faire?


      Voici le rapport de SD Fix:


      [b]SDFix: Version 1.202 [/b]
      Run by Carlo on 07/07/2008 at 15:56

      Microsoft Windows XP [version 5.1.2600]
      Running From: C:\DOCUME~1\Carlo\Bureau\SDFix

      [b]Checking Services [/b]:

      [b]Name [/b]:
      MicroSoft Media Tools

      [b]Path [/b]:
      "C:\WINDOWS\MSmedia.exe"

      MicroSoft Media Tools - Deleted



      Restoring Default Security Values
      Restoring Default Hosts File

      Rebooting


      [b]Checking Files [/b]:

      Trojan Files Found:

      C:\Documents and Settings\Carlo\Mes documents\My Documents.url - Deleted
      C:\Documents and Settings\Carlo\Mes documents\CARLO\AUDIOVISUEL C & S\Notre Musique\My Music.url - Deleted
      C:\Documents and Settings\Carlo\Mes documents\AUDIOVISUEL C & S\Nos vid‚os\My Video.url - Deleted
      C:\windows\system32\TFTP1684 - Deleted
      C:\windows\system32\TFTP2892 - Deleted
      C:\Program Files\Setup.exe - Deleted
      C:\tmp.reg - Deleted





      Removing Temp Files

      [b]ADS Check [/b]:



      [b]Final Check [/b]:

      catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-07-07 16:04:47
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden services & system hive ...

      scanning hidden registry entries ...

      scanning hidden files ...

      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0


      [b]Remaining Services [/b]:




      Authorized Application Key Export:

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      "c:\\irpll7l.exe"="C:\\irpll7l.exe:*:Enabled:Server"
      "Windows Firewall Monitor"="C:\\dinst.exe:*:enabled:svchost"
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
      "C:\\Program Files\\eChanblard\\emule.exe"="C:\\Program Files\\eChanblard\\emule.exe:*:Enabled:eMule"
      "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.6\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.6\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
      "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.5\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.5\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
      "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.4\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.4\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
      "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.3\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.3\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
      "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.2\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.2\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
      "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\Fp2006.exe:*:Disabled:Spy Shooter 2006"
      "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\FlowService.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\FlowService.exe:*:Disabled:Spy Shooter 2006"
      "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\Fp2006.exe:*:Disabled:SpyShooter2006"
      "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\FlowService.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\FlowService.exe:*:Disabled:SpyShooter2006"
      "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\Fp2006.exe:*:Disabled:Spy Shooter 2006"
      "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\FlowService.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\FlowService.exe:*:Disabled:Spy Shooter 2006"
      "C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"="C:\\Program Files\\VideoLAN\\VLC\\vlc.exe:*:Enabled:VLC media player"
      "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
      "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
      "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
      "C:\\Program Files\\messenger\\msmsgs.exe"="C:\\Program Files\\messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
      "C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019"

      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
      "c:\\irpll7l.exe"="C:\\irpll7l.exe:*:Enabled:Server"
      "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
      "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
      "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
      "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
      "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
      "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
      "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

      [b]Remaining Files [/b]:


      File Backups: - C:\DOCUME~1\Carlo\Bureau\SDFix\backups\backups.zip

      [b]Files with Hidden Attributes [/b]:

      Sat 21 Jun 2008 212 A.SH. --- "C:\BOOT.BAK"
      Fri 13 May 2005 217,073 A.SHR --- "C:\WINDOWS\meta4.exe"
      Mon 24 Oct 2005 66,560 A.SHR --- "C:\WINDOWS\MOTA113.exe"
      Thu 13 Oct 2005 422,400 A.SHR --- "C:\WINDOWS\x2.64.exe"
      Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
      Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
      Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
      Tue 17 Apr 2007 168 ..SHR --- "C:\WINDOWS\system32\0E3DD7342B.sys"
      Fri 28 Oct 2005 308,224 A.SH. --- "C:\WINDOWS\system32\avisynth.dll"
      Thu 14 Jul 2005 27,648 A.SHR --- "C:\WINDOWS\system32\AVSredirect.dll"
      Sun 26 Jun 2005 616,448 A.SHR --- "C:\WINDOWS\system32\cygwin1.dll"
      Tue 21 Jun 2005 45,568 A.SHR --- "C:\WINDOWS\system32\cygz.dll"
      Sun 25 Jan 2004 70,656 A.SHR --- "C:\WINDOWS\system32\i420vfw.dll"
      Tue 17 Apr 2007 2,516 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
      Sun 21 Jan 2001 63,488 A..H. --- "C:\WINDOWS\system32\MMRegOCX.exe"
      Thu 27 Apr 2006 2,945,024 A.SHR --- "C:\WINDOWS\system32\Smab.dll"
      Mon 28 Feb 2005 240,128 A.SHR --- "C:\WINDOWS\system32\x.264.exe"
      Sun 25 Jan 2004 70,656 A.SH. --- "C:\WINDOWS\system32\yv12vfw.dll"
      Sun 14 May 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
      Sat 24 Nov 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
      Fri 18 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4658aca27402c0ea318a0615f08905ca\BIT42.tmp"
      Fri 18 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\6092debe4959b217a6aac6c11cc1dd60\BIT48.tmp"
      Sun 14 May 2006 4,348 A..H. --- "C:\Documents and Settings\Carlo\Mes documents\CARLO\AUDIOVISUEL C & S\Notre Musique\Sauvegarde de la licence\drmv1key.bak"
      Fri 16 Jun 2006 20 A..H. --- "C:\Documents and Settings\Carlo\Mes documents\CARLO\AUDIOVISUEL C & S\Notre Musique\Sauvegarde de la licence\drmv1lic.bak"
      Sun 26 Feb 2006 312 A..H. --- "C:\Documents and Settings\Carlo\Mes documents\CARLO\AUDIOVISUEL C & S\Notre Musique\Sauvegarde de la licence\drmv2key.bak"
      Fri 16 Jun 2006 1,536 A..H. --- "C:\Documents and Settings\Carlo\Mes documents\CARLO\AUDIOVISUEL C & S\Notre Musique\Sauvegarde de la licence\drmv2lic.bak"

      [b]Finished![/b]

      catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
      Rootkit scan 2008-07-07 16:04:47
      Windows 5.1.2600 Service Pack 3 NTFS

      scanning hidden processes ...

      scanning hidden services & system hive ...

      scanning hidden registry entries ...

      scanning hidden files ...

      scan completed successfully
      hidden processes: 0
      hidden services: 0
      hidden files: 0

      Autrement, dois-je faire quelque chose avec WinsockXPFix que j'ai téléchargé?

      Dans l'attente de tes nouvelles instructions, je te salue bien cordialement!

      catpeople12
      0
  18. BOB3
     
    Re catpeople12,

    merci mettre tes reponses dans l'ordre ca m'empeche de faire le yoyo,

    pour resumer,
    1--tu supprimes tout les activx en mode normal
    2--tu laisses de cote le probleme de Kaspesky, on verra plus tard
    3--si t'as pas trouve les autres cles, c'est qu'elles ont ete supprimees

    le plus important
    4--tu lance SDFIX comme indiqué dans 29 et tu mets son rapport --- copier coller

    a+
    BOB3
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      REPONSE AU MESSAGE 33 Par BOB

      Re, BOB3

      Je suis vraiment désolé que tu fasses le yoyo à cause de moi!!...

      Je pensais avoir procédé dans l'ordre de tes messages-conseil...

      Je récapitule pour te rendre la vie plus facile. Il y a deux messages importants pour toi de ma part:

      A - Mon message N° 31, qui répond à tes messages 24, 25 et 28, où je t'ai posté les logs Hijackthis que tu m'as demandés.

      B - Mon message N° 32 , qui répond à ton messsage 29, où tu trouveras le rapport de SDFix que tu m'as demandé. Comme convenu, j'ai supprimé les activex et n'ai rien fait ni avec Kaspersky ni avec LSP Fix que je devais télécharger (Voir ton message N° 24).

      J'attendais juste que tu lises le rapport SDFix pour savoir ce qu'il faut faire ensuite.

      Merci, encore désolé et A+ !

      catpeople12
      0
  19. BOB3
     
    Re catpeople12,

    pour vérification + modification

    1---Les clés de registre suivantes sont ajoutées afin d'exécuter des processus après le redémarrage:
    tu ouvres regedit.exe ----- avec prudence
    tu cherches ces cléfs et tu les supprimes

    – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    • "Printer"="%SYSDIR%\auditchk.exe"

    – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
    • "Printer"="%SYSDIR%\auditchk.exe"

    – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
    • "Printer"="%SYSDIR%\auditchk.exe"

    2--ensuite tu cherches les cléfs suivantes eventuellement tu les modifies
    les clefs doivent etre comme suit:

    – [HKLM\SOFTWARE\Microsoft\Ole]

    Nom Type Valeur

    • "EnableDCOM"= REG_SZ N

    – [HKLM\SYSTEM\CurrentControlSet\Control\Lsa]

    • "restrictanonymous"= REG_DWORD 0X00000002 (2)

    tu fermes,

    3---tu notes tout les fichiers que tu trouves
    tu cherches sur ton disque tout les fichiers qui se trouvent dans Temp, et tu les supprimes
    c:\temp\xxxxxxx.xxxx

    c:\document and settings\administrateur\local settings\temp
    et tu verifies dans les autres comptes qui se trouvent dans c:\document and setting\xxxxxxxx\local settings\temp

    c:\windows\temp
    c:\windows\system32\temp

    et tu me donne la liste
    a+
    BOB3

    tu reboot,

    tu refaits un scan avec Spybot,

    et tu remets un nouveau log hijackthis

    a+
    BOB3
    0
  20. BOB3
     
    Re catpeople12,

    en reprend a partir de 34 + ce post.

    oublis les rapports hijackthis + spybot pour le moment,
    le rapport SDFIX n'est pas fameux

    1---tu fais ce qui est demandé en 34

    2--je t'avais demande de desinstaller windows live messenger en 22 , il figure toujours dans le rapport SDFIX.

    1--est ce que tu as desinstalle microsoft live messenger, sinon desinstalles le
    2--tu desinstalles aussi microsoft active sync--il est infecté----tu le reinstalles aprés le nettoyage
    3--tu desinstalles aussi microsoft network diagnostic --- il sert a rien
    4--tu desinstalles spybot --- il est infecté --- voir plus bas

    tu fait le nettoyage avec Ccleaner, tu supprimes tout

    tu telecharge a nouveau spybot sur ce lien
    ftp://ftp.commentcamarche.com/download/spybotsd152.exe

    tu l'installes, + mise ajour + tu lances la vaccination pour que les compteurs soient identiques

    ensuite tu le parametre comme suit.

    tu lances Spybot, puis tu clic en haut Mode, puis tu coche Mode avancé
    ensuite sur outils et tu coches toutes les cases sous outils.
    tu clic sur Demarrage systeme, qui te permets de virer les programmes indesirables ou superflus que tu peux cocher et supprimer
    tu clic sur Interieur systeme, tu lances verifier, et tu les coches un apres l'autre, et puis tu clic sur corriger les problemes
    tu clic sur fichiers Hosts, pour mettre a jour la liste des sites indesirables, et tu refait ca a chaque mise a jour de spybot
    tu clic sur ajustement IE, et tu coches toutes les cases verrouillage
    tu clic sur pages navigateur, et tu clic 2 fois sur tout les liens, un apres l'autre, et lorsqu'il s'ouvre, tu efface le contenu
    et tu clic Ok
    tu clic sur BHOs, et tu vire tout----> sauf ceux de ton antivirus+Spybot
    tu clic sur ActivX, et tu vire tout----> sauf ceux de windows+office+genuine advantage+Shockwave si presents
    tu clic sur Resident, et tu coches les 2 cases.
    et une fois par jour avant d'arreter ton ordi,
    tu clic sur Effaceur de securité, et tu clic sur Modeles , puis tu clic sur la liste un apres l'autre, et tu clic en bas
    sur Dechiquetér pour tout nettoyer.

    pour finir passes un coup de Ccleaner, et fait un reboot.

    tu lance Spybot pour un scan complet, et tu me donne les resultats.
    a+
    BOB3
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      REPONSE AUX MESSAGES 34 ET 36 PAR BOB3

      Bonjour BOB3!

      Je réponds à tes messages par ordre pour te faciliter la tâche

      MESSAGE 34

      Vérification et modification

      1 - Les clefs de registre "Printer"="%SYSDIR%\auditchk.exe" n'étaient présentes ni sur [HKLM\SOFTWARE\Microsoft\Windows\Current Version\Run] ni sur [....\RunServices], ni sur [HKCU\....\Run]


      2 - Les clés suivantes n'étaient pas correctes et je les ai modifiées selon tes instructions:

      [HKLM\SOFTWARE\Microsoft\Ole] avait une valeur Y que j'ai modifiée à N comme indiqué.

      [HKLM\SYSTEM\CurrentControlSet\Control\Lsa] avait une valeur 0 que j'ai modifié à 2 comme indiqué.


      3 - Liste de fichiers trouvés dans Temp à te soumettre:

      c:\temp
      "debug"
      dossier 38bb9e8aacbb4470e2 contenant %temp%dd_msxml_retMSI
      supprimés

      c:\documents and settings\xxxx\local settings\temp
      WCESCOMM
      ISTMP1.DIR
      sv457.tmp
      supprimés

      WCESLog - IMPOSSIBLE DE LE SUPPRIMER

      c:\windows\temp
      WGAErrlog
      WGANotify.settings
      supprimés

      c:\windows\system32\temp
      dossier URTTemp contenant: fusion.dll; mscoree.dll; mscoree.dll.local; mscorns.dll; mscorwks.dll; msvcr.dll
      JE N'AI PAS OSE LE SUPPRIMER CAR TROP DE FICHIERS .dll INCONNUS POUR MOI. JE PEUX LE SUPPRIMER?

      inetsrv
      ASP Compiled Templates (dossier vide)
      supprimés

      MESSAGE 36

      1 - J'ai fait ce qui était demandé en 34

      2- Désinstallations:
      a) J'ai desinstallé les composants de windows live qui restaient encore installés
      b) J'ai desinstallé microsoft active sync (je n'en ai pas vraiment besoin)
      c) Microsoft Network Diagnostic n'est pas dans mon système
      d) J'ai desinstallé l'ancien Spybot S&D

      J'ai nettoyé avec CCleaner et j'ai tout supprimé

      J'ai téléchargé Spybot S&D sur le lien que tu m'as donné et j'ai suivi tes instructions à la lettre.

      J'ai renettoyé avec CCleaner comme demandé et j'ai rebooté

      J'ai relancé un scan complet avec Spybot, qui n'a rien trouvé d'anormal dans les résultats.

      Ce matin au démarrage de l'ordi Spybot a encore fait un scan complet et il n'y a pas de mouchards.


      P.S.

      Je n'ai pas encore utilisé LSP Fix, je n'ai pas encore téléchargé Windows Live ni reinstallé ma webcam Labtec en attendant tes instructions.

      Bien Cordialement,

      catpeople12
      0
    2. catpeople12 Messages postés 122 Statut Membre
       
      NOUVEAU

      Re BOB3,
      Je me suis permis de refaire un coup de HJT, dont je te soumets le log pour que tu voies l'état actuel du système. J'espère ne pas trop t'embêter...

      Par ailleurs, je ne peux plus accéder aux options internet du navigateur...

      Le message d'erreur suivant apparaît quand j'essaie d'aller dessus:
      X Cette opétarion a été annulée en raison de restrictions en vigueur pour cet ordinateur. Contactez votre Administrateur Système.


      Et voici le tout dernier log HJT :

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:43:15, on 08/07/2008
      Platform: Windows XP SP3 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16674)
      Boot mode: Normal

      Running processes:
      C:\windows\System32\smss.exe
      C:\windows\system32\winlogon.exe
      C:\windows\system32\services.exe
      C:\windows\system32\lsass.exe
      C:\windows\System32\Ati2evxx.exe
      C:\windows\system32\svchost.exe
      C:\windows\System32\svchost.exe
      C:\windows\system32\Ati2evxx.exe
      C:\windows\Explorer.EXE
      C:\WINDOWS\System32\brsvc01a.exe
      C:\WINDOWS\System32\brss01a.exe
      C:\windows\system32\spoolsv.exe
      C:\Program Files\VIA\RAID\raid_tool.exe
      C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      C:\Program Files\Windows Media Player\WMPNSCFG.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
      C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
      C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      C:\windows\system32\cisvc.exe
      C:\windows\System32\svchost.exe
      C:\WINDOWS\system32\inetsrv\inetinfo.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
      C:\windows\system32\svchost.exe
      C:\windows\system32\cidaemon.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
      O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
      O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
      O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
      O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O15 - Trusted Zone: http://www.1001interims.com
      O15 - Trusted Zone: https://www.adobe.com/
      O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
      O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
      O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
      O15 - Trusted Zone: https://www.ustart.org
      O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
      O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
      O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
      O15 - Trusted Zone: https://www.msn.com/fr-fr/
      O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
      O15 - Trusted Zone: https://fr.yahoo.com/
      O15 - Trusted Zone: https://www.youtube.com/
      O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
      O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
      O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
      O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
      O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
      O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
      O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
      O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
      0
  21. BOB3
     
    Bonjour catpeople12,

    WCESLog - IMPOSSIBLE DE LE SUPPRIMER
    supprimes le en mode sans echec,

    laisses LSP Fix de cote pour le moment, j'attends une reponse s'il est compatible avec xp en francais.

    tu vas telecharger Norman Malware Cleaner
    pour ceci, tu va dans le dossier c:\SDFix
    1---en mode normal avec connection internet obligatoire.
    tu lances RunThis.bat, il ouvre un menu sous dos,
    tu tape 2, pour telecharger Norman_Malware_Cleaner
    il va s'installer tout seul dans le meme dossier, sa taille=22268ko
    normalement il se lance tout seul apres le telechargement, sinon tu ouvre le dossier SDFix, et tu lances
    Norman_Malware_Cleaner.exe

    tu le laisse scanner tout tes lecteur, il risque de prendre du temps, il termine et met un log sur ton poste de travail,
    tu le colles sur un nouveau post pour que je puisse jeté un coup d'oeil.
    a+
    BOB3

    P.S.JE SERAI ABSENT ---->16H00
    0
    1. catpeople12 Messages postés 122 Statut Membre
       
      Re-bonjour BOB3 et merci de ta réponse!

      J'ai suivi tes instructions et te laisse regarder le log de Norman Malware Cleaner (4 fichiers infectés supprimés) ci-après.
      (Au fait, à quoi correspond cette adresse IP 127.0.0.1 ?.... Il y a plein de sites bizarroïdes dedans dont j'ignorais l'existence mais qui sont sortis dans le log... ).

      Sinon, je pourrai bientôt retélécharger Windows Live et reinstaller la webcam Labtec?

      J'attends tes instructions après 16h00.

      Bien Cordialement,

      catpeople12


      LOG DU 08/07/2008

      Norman Malware Cleaner
      Copyright © 1990 - 2008, Norman ASA. Built 2008/06/30 19:19:50

      Norman Scanner Engine Version: 5.92.08
      Nvcbin.def Version: 5.92.00, Date: 2008/06/30 19:19:50, Variants: 1812814

      Running pre-scan cleanup routine:
      Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 3
      Logged on user: CARLO\Carlo

      Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLS = "C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll" -> ""
      Removed hosts entry: 127.0.0.1 www.100sexlinks.com
      Removed hosts entry: 127.0.0.1 100sexlinks.com
      Removed hosts entry: 127.0.0.1 www.123topsearch.com
      Removed hosts entry: 127.0.0.1 123topsearch.com
      Removed hosts entry: 127.0.0.1 www.1800searchonline.com
      Removed hosts entry: 127.0.0.1 1800searchonline.com
      Removed hosts entry: 127.0.0.1 www.180searchassistant.com
      Removed hosts entry: 127.0.0.1 180searchassistant.com
      Removed hosts entry: 127.0.0.1 www.1stantivirus.com
      Removed hosts entry: 127.0.0.1 1stantivirus.com
      Removed hosts entry: 127.0.0.1 www.1stsearchportal.com
      Removed hosts entry: 127.0.0.1 1stsearchportal.com
      Removed hosts entry: 127.0.0.1 www.2007-download.com
      Removed hosts entry: 127.0.0.1 2007-download.com
      Removed hosts entry: 127.0.0.1 www.2020search.com
      Removed hosts entry: 127.0.0.1 2020search.com
      Removed hosts entry: 127.0.0.1 www.24-7searching-and-more.com
      Removed hosts entry: 127.0.0.1 24-7searching-and-more.com
      Removed hosts entry: 127.0.0.1 www.2search.com
      Removed hosts entry: 127.0.0.1 2search.com
      Removed hosts entry: 127.0.0.1 www.2search.org
      Removed hosts entry: 127.0.0.1 2search.org
      Removed hosts entry: 127.0.0.1 www.3ebay.it
      Removed hosts entry: 127.0.0.1 3ebay.it
      Removed hosts entry: 127.0.0.1 www.4ebay.it
      Removed hosts entry: 127.0.0.1 4ebay.it
      Removed hosts entry: 127.0.0.1 www.4repubblica.it
      Removed hosts entry: 127.0.0.1 4repubblica.it
      Removed hosts entry: 127.0.0.1 www.5repubblica.it
      Removed hosts entry: 127.0.0.1 5repubblica.it
      Removed hosts entry: 127.0.0.1 www.777search.com
      Removed hosts entry: 127.0.0.1 777search.com
      Removed hosts entry: 127.0.0.1 www.7search.com
      Removed hosts entry: 127.0.0.1 7search.com
      Removed hosts entry: 127.0.0.1 www.971searchbox.com
      Removed hosts entry: 127.0.0.1 971searchbox.com
      Removed hosts entry: 127.0.0.1 www.abccodec.com
      Removed hosts entry: 127.0.0.1 abccodec.com
      Removed hosts entry: 127.0.0.1 www.abcsearch.com
      Removed hosts entry: 127.0.0.1 abcsearch.com
      Removed hosts entry: 127.0.0.1 www.activexmediasoftware.com
      Removed hosts entry: 127.0.0.1 activexmediasoftware.com
      Removed hosts entry: 127.0.0.1 www.activexsoftwares.com
      Removed hosts entry: 127.0.0.1 activexsoftwares.com
      Removed hosts entry: 127.0.0.1 www.activexupdate.com
      Removed hosts entry: 127.0.0.1 activexupdate.com
      Removed hosts entry: 127.0.0.1 www.adasearch.com
      Removed hosts entry: 127.0.0.1 adasearch.com
      Removed hosts entry: 127.0.0.1 www.adipics.com
      Removed hosts entry: 127.0.0.1 adipics.com
      Removed hosts entry: 127.0.0.1 adobe-download-now.com
      Removed hosts entry: 127.0.0.1 www.adobe-downloads.com
      Removed hosts entry: 127.0.0.1 adobe-downloads.com
      Removed hosts entry: 127.0.0.1 ads.searchingbooth.com
      Removed hosts entry: 127.0.0.1 www.adsextend.net
      Removed hosts entry: 127.0.0.1 adsextend.net
      Removed hosts entry: 127.0.0.1 www.adspics.com
      Removed hosts entry: 127.0.0.1 adspics.com
      Removed hosts entry: 127.0.0.1 www.adult18codec.com
      Removed hosts entry: 127.0.0.1 adult18codec.com
      Removed hosts entry: 127.0.0.1 www.adultcodec-2008.com
      Removed hosts entry: 127.0.0.1 adultcodec-2008.com
      Removed hosts entry: 127.0.0.1 www.adultcodecstars.com
      Removed hosts entry: 127.0.0.1 adultcodecstars.com
      Removed hosts entry: 127.0.0.1 www.adult-engine-search.com
      Removed hosts entry: 127.0.0.1 adult-engine-search.com
      Removed hosts entry: 127.0.0.1 affiliate.idownload.com
      Removed hosts entry: 127.0.0.1 www.airtleworld.com
      Removed hosts entry: 127.0.0.1 airtleworld.com
      Removed hosts entry: 127.0.0.1 akamai.downloadv3.com
      Removed hosts entry: 127.0.0.1 alfa-search.com
      Removed hosts entry: 127.0.0.1 www.allcybersearch.com
      Removed hosts entry: 127.0.0.1 allcybersearch.com
      Removed hosts entry: 127.0.0.1 www.all-downloads-now.com
      Removed hosts entry: 127.0.0.1 all-downloads-now.com
      Removed hosts entry: 127.0.0.1 allforadult.com
      Removed hosts entry: 127.0.0.1 www.alltiettantivirus.com
      Removed hosts entry: 127.0.0.1 alltiettantivirus.com
      Removed hosts entry: 127.0.0.1 www.alltruesoftware.com
      Removed hosts entry: 127.0.0.1 alltruesoftware.com
      Removed hosts entry: 127.0.0.1 www.amediasoftware.com
      Removed hosts entry: 127.0.0.1 amediasoftware.com
      Removed hosts entry: 127.0.0.1 www.americanautobargains.com
      Removed hosts entry: 127.0.0.1 americanautobargains.com
      Removed hosts entry: 127.0.0.1 www.ampmsearch.com
      Removed hosts entry: 127.0.0.1 ampmsearch.com
      Removed hosts entry: 127.0.0.1 anarchyporn.com
      Removed hosts entry: 127.0.0.1 www.animepornmag.com
      Removed hosts entry: 127.0.0.1 animepornmag.com
      Removed hosts entry: 127.0.0.1 www.antiespiadorado.com
      Removed hosts entry: 127.0.0.1 antiespiadorado.com
      Removed hosts entry: 127.0.0.1 www.antiespionspack.com
      Removed hosts entry: 127.0.0.1 antiespionspack.com
      Removed hosts entry: 127.0.0.1 www.antigusanos2008.com
      Removed hosts entry: 127.0.0.1 antigusanos2008.com
      Removed hosts entry: 127.0.0.1 www.antispamassistant.com
      Removed hosts entry: 127.0.0.1 antispamassistant.com
      Removed hosts entry: 127.0.0.1 www.antispamdeluxe.com
      Removed hosts entry: 127.0.0.1 antispamdeluxe.com
      Removed hosts entry: 127.0.0.1 www.antispionage.com
      Removed hosts entry: 127.0.0.1 antispionage.com
      Removed hosts entry: 127.0.0.1 www.antispionagepro.com
      Removed hosts entry: 127.0.0.1 antispionagepro.com
      Removed hosts entry: 127.0.0.1 www.antispyadvanced.com
      Removed hosts entry: 127.0.0.1 antispyadvanced.com
      Removed hosts entry: 127.0.0.1 www.antispycheck.com
      Removed hosts entry: 127.0.0.1 antispycheck.com
      Removed hosts entry: 127.0.0.1 www.antispydns.biz
      Removed hosts entry: 127.0.0.1 antispydns.biz
      Removed hosts entry: 127.0.0.1 www.antispykit.com
      Removed hosts entry: 127.0.0.1 antispykit.com
      Removed hosts entry: 127.0.0.1 www.antispylab.com
      Removed hosts entry: 127.0.0.1 antispylab.com
      Removed hosts entry: 127.0.0.1 www.antispyshield.com
      Removed hosts entry: 127.0.0.1 antispyshield.com
      Removed hosts entry: 127.0.0.1 www.antispysolutions.com
      Removed hosts entry: 127.0.0.1 antispysolutions.com
      Removed hosts entry: 127.0.0.1 www.antispyware.com
      Removed hosts entry: 127.0.0.1 antispyware.com
      Removed hosts entry: 127.0.0.1 www.antispywareboot.com
      Removed hosts entry: 127.0.0.1 antispywareboot.com
      Removed hosts entry: 127.0.0.1 www.antispywarebot.com
      Removed hosts entry: 127.0.0.1 antispywarebot.com
      Removed hosts entry: 127.0.0.1 www.antispywarebox.com
      Removed hosts entry: 127.0.0.1 antispywarebox.com
      Removed hosts entry: 127.0.0.1 www.antispywaredownloads.com
      Removed hosts entry: 127.0.0.1 antispywaredownloads.com
      Removed hosts entry: 127.0.0.1 www.antispywaresuite.com
      Removed hosts entry: 127.0.0.1 antispywaresuite.com
      Removed hosts entry: 127.0.0.1 www.antispywareupdates.net
      Removed hosts entry: 127.0.0.1 antispywareupdates.net
      Removed hosts entry: 127.0.0.1 www.antispywarexp.com
      Removed hosts entry: 127.0.0.1 antispywarexp.com
      Removed hosts entry: 127.0.0.1 www.antispyweb.net
      Removed hosts entry: 127.0.0.1 antispyweb.net
      Removed hosts entry: 127.0.0.1 www.antiver2008.com
      Removed hosts entry: 127.0.0.1 antiver2008.com
      Removed hosts entry: 127.0.0.1 www.antivermins.com
      Removed hosts entry: 127.0.0.1 antivermins.com
      Removed hosts entry: 127.0.0.1 www.anti-vermins.com
      Removed hosts entry: 127.0.0.1 anti-vermins.com
      Removed hosts entry: 127.0.0.1 www.antivir2007.com
      Removed hosts entry: 127.0.0.1 antivir2007.com
      Removed hosts entry: 127.0.0.1 www.antivirgear.com
      Removed hosts entry: 127.0.0.1 antivirgear.com
      Removed hosts entry: 127.0.0.1 www.antivirprotect.com
      Removed hosts entry: 127.0.0.1 antivirprotect.com
      Removed hosts entry: 127.0.0.1 www.antivirus.fastfreedownload.com
      Removed hosts entry: 127.0.0.1 antivirus.fastfreedownload.com
      Removed hosts entry: 127.0.0.1 www.antivirus2008pro.com
      Removed hosts entry: 127.0.0.1 antivirus2008pro.com
      Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.com
      Removed hosts entry: 127.0.0.1 antivirus-2008pro.com
      Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.com
      Removed hosts entry: 127.0.0.1 antivirus-2008-pro.com
      Removed hosts entry: 127.0.0.1 www.antivirus2008pro.info
      Removed hosts entry: 127.0.0.1 antivirus2008pro.info
      Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.info
      Removed hosts entry: 127.0.0.1 antivirus-2008pro.info
      Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.info
      Removed hosts entry: 127.0.0.1 antivirus-2008-pro.info
      Removed hosts entry: 127.0.0.1 www.antivirus2008pro.net
      Removed hosts entry: 127.0.0.1 antivirus2008pro.net
      Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.net
      Removed hosts entry: 127.0.0.1 antivirus-2008pro.net
      Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.net
      Removed hosts entry: 127.0.0.1 antivirus-2008-pro.net
      Removed hosts entry: 127.0.0.1 www.antivirus2008pro.org
      Removed hosts entry: 127.0.0.1 antivirus2008pro.org
      Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.org
      Removed hosts entry: 127.0.0.1 antivirus-2008pro.org
      Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.org
      Removed hosts entry: 127.0.0.1 antivirus-2008-pro.org
      Removed hosts entry: 127.0.0.1 www.antivirus2008x.com
      Removed hosts entry: 127.0.0.1 antivirus2008x.com
      Removed hosts entry: 127.0.0.1 www.antivirusadvance.com
      Removed hosts entry: 127.0.0.1 antivirusadvance.com
      Removed hosts entry: 127.0.0.1 www.antivirusaskeladd.com
      Removed hosts entry: 127.0.0.1 antivirusaskeladd.com
      Removed hosts entry: 127.0.0.1 www.antivirusgereedschap.com
      Removed hosts entry: 127.0.0.1 antivirusgereedschap.com
      Removed hosts entry: 127.0.0.1 www.antivirusgolden.com
      Removed hosts entry: 127.0.0.1 antivirusgolden.com
      Removed hosts entry: 127.0.0.1 www.antivirus-hq.net
      Removed hosts entry: 127.0.0.1 antivirus-hq.net
      Removed hosts entry: 127.0.0.1 www.antiviruspcsuite.com
      Removed hosts entry: 127.0.0.1 antiviruspcsuite.com
      Removed hosts entry: 127.0.0.1 www.antiviruspremium.com
      Removed hosts entry: 127.0.0.1 antiviruspremium.com
      Removed hosts entry: 127.0.0.1 www.anti-virus-pro.com
      Removed hosts entry: 127.0.0.1 anti-virus-pro.com
      Removed hosts entry: 127.0.0.1 www.antivirusprotector.com
      Removed hosts entry: 127.0.0.1 antivirusprotector.com
      Removed hosts entry: 127.0.0.1 www.antivirus-scanner.com
      Removed hosts entry: 127.0.0.1 antivirus-scanner.com
      Removed hosts entry: 127.0.0.1 www.antivirusscherm.com
      Removed hosts entry: 127.0.0.1 antivirusscherm.com
      Removed hosts entry: 127.0.0.1 www.antivirussecuritypro.com
      Removed hosts entry: 127.0.0.1 antivirussecuritypro.com
      Removed hosts entry: 127.0.0.1 www.antivirus-stop.com
      Removed hosts entry: 127.0.0.1 antivirus-stop.com
      Removed hosts entry: 127.0.0.1 www.antivirussuite.com
      Removed hosts entry: 127.0.0.1 antivirussuite.com
      Removed hosts entry: 127.0.0.1 www.antiworm2008.com
      Removed hosts entry: 127.0.0.1 antiworm2008.com
      Removed hosts entry: 127.0.0.1 www.antiwurm2008.com
      Removed hosts entry: 127.0.0.1 antiwurm2008.com
      Removed hosts entry: 127.0.0.1 www.archiviosex.net
      Removed hosts entry: 127.0.0.1 archiviosex.net
      Removed hosts entry: 127.0.0.1 www.ares.click-new-download.com
      Removed hosts entry: 127.0.0.1 ares.click-new-download.com
      Removed hosts entry: 127.0.0.1 www.asianpornmag.com
      Removed hosts entry: 127.0.0.1 asianpornmag.com
      Removed hosts entry: 127.0.0.1 www.aucunsvirus.com
      Removed hosts entry: 127.0.0.1 aucunsvirus.com
      Removed hosts entry: 127.0.0.1 www.autobargains.org
      Removed hosts entry: 127.0.0.1 autobargains.org
      Removed hosts entry: 127.0.0.1 www.autobargainsnetwork.com
      Removed hosts entry: 127.0.0.1 autobargainsnetwork.com
      Removed hosts entry: 127.0.0.1 www.autocontext.begun.ru
      Removed hosts entry: 127.0.0.1 autocontext.begun.ru
      Removed hosts entry: 127.0.0.1 autoescrowpay.com
      Removed hosts entry: 127.0.0.1 www.avast.free-software-center.com
      Removed hosts entry: 127.0.0.1 avast.free-software-center.com
      Removed hosts entry: 127.0.0.1 www.avast-downloads.com
      Removed hosts entry: 127.0.0.1 avast-downloads.com
      Removed hosts entry: 127.0.0.1 www.avg.softwarecenterz.com
      Removed hosts entry: 127.0.0.1 avg.softwarecenterz.com
      Removed hosts entry: 127.0.0.1 www.avpcheckupdate.com
      Removed hosts entry: 127.0.0.1 avpcheckupdate.com
      Removed hosts entry: 127.0.0.1 awmcash.biz
      Removed hosts entry: 127.0.0.1 awmdabest.com
      Removed hosts entry: 127.0.0.1 www.axemediasoftware.com
      Removed hosts entry: 127.0.0.1 axemediasoftware.com
      Removed hosts entry: 127.0.0.1 www.axmediasoftware.com
      Removed hosts entry: 127.0.0.1 axmediasoftware.com
      Removed hosts entry: 127.0.0.1 www.axsoftwaretool.com
      Removed hosts entry: 127.0.0.1 axsoftwaretool.com
      Removed hosts entry: 127.0.0.1 www.babespornmag.com
      Removed hosts entry: 127.0.0.1 babespornmag.com
      Removed hosts entry: 127.0.0.1 www.bardownload.com
      Removed hosts entry: 127.0.0.1 bardownload.com
      Removed hosts entry: 127.0.0.1 batsearch.com
      Removed hosts entry: 127.0.0.1 bbbsearch.com
      Removed hosts entry: 127.0.0.1 bb-search.com
      Removed hosts entry: 127.0.0.1 www.bdsmpornmag.com
      Removed hosts entry: 127.0.0.1 bdsmpornmag.com
      Removed hosts entry: 127.0.0.1 www.bearshare.click-new-download.com
      Removed hosts entry: 127.0.0.1 bearshare.click-new-download.com
      Removed hosts entry: 127.0.0.1 www.bearshare-download.org
      Removed hosts entry: 127.0.0.1 bearshare-download.org
      Removed hosts entry: 127.0.0.1 www.bearshare-downloads.net
      Removed hosts entry: 127.0.0.1 bearshare-downloads.net
      Removed hosts entry: 127.0.0.1 www.bearshare-music-downloads.com
      Removed hosts entry: 127.0.0.1 bearshare-music-downloads.com
      Removed hosts entry: 127.0.0.1 www.begin2search.com
      Removed hosts entry: 127.0.0.1 begin2search.com
      Removed hosts entry: 127.0.0.1 best-hardpics.com
      Removed hosts entry: 127.0.0.1 www.best-porncollection.com
      Removed hosts entry: 127.0.0.1 best-porncollection.com
      Removed hosts entry: 127.0.0.1 bestporngate.com
      Removed hosts entry: 127.0.0.1 www.bestsearchworld.info
      Removed hosts entry: 127.0.0.1 bestsearchworld.info
      Removed hosts entry: 127.0.0.1 www.bestworldgirls-for-u.net
      Removed hosts entry: 127.0.0.1 bestworldgirls-for-u.net
      Removed hosts entry: 127.0.0.1 bestxporno.com
      Removed hosts entry: 127.0.0.1 www.bettersearch.biz
      Removed hosts entry: 127.0.0.1 bettersearch.biz
      Removed hosts entry: 127.0.0.1 www.bgoogle.it
      Removed hosts entry: 127.0.0.1 bgoogle.it
      Removed hosts entry: 127.0.0.1 www.bigcodecadult.com
      Removed hosts entry: 127.0.0.1 bigcodecadult.com
      Removed hosts entry: 127.0.0.1 www.bigcodecadult2008.com
      Removed hosts entry: 127.0.0.1 bigcodecadult2008.com
      Removed hosts entry: 127.0.0.1 www.bigcodecadult2008-17.com
      Removed hosts entry: 127.0.0.1 bigcodecadult2008-17.com
      Removed hosts entry: 127.0.0.1 www.bighot18codec2008.com
      Removed hosts entry: 127.0.0.1 bighot18codec2008.com
      Removed hosts entry: 127.0.0.1 www.bighot18-codec2008.com
      Removed hosts entry: 127.0.0.1 bighot18-codec2008.com
      Removed hosts entry: 127.0.0.1 www.bittorrent.click-new-download.com
      Removed hosts entry: 127.0.0.1 bittorrent.click-new-download.com
      Removed hosts entry: 127.0.0.1 www.blackcodec.com
      Removed hosts entry: 127.0.0.1 blackcodec.com
      Removed hosts entry: 127.0.0.1 www.black-codec.com
      Removed hosts entry: 127.0.0.1 black-codec.com
      Removed hosts entry: 127.0.0.1 www.blackcodec.net
      Removed hosts entry: 127.0.0.1 blackcodec.net
      Removed hosts entry: 127.0.0.1 www.blackhawksoftware.com
      Removed hosts entry: 127.0.0.1 blackhawksoftware.com
      Removed hosts entry: 127.0.0.1 br.winantivirus.com
      Removed hosts entry: 127.0.0.1 www.braincodec.com
      Removed hosts entry: 127.0.0.1 braincodec.com
      Removed hosts entry: 127.0.0.1 www.brakecodec.com
      Removed hosts entry: 127.0.0.1 brakecodec.com
      Removed hosts entry: 127.0.0.1 bsa.safetydownload.com
      Removed hosts entry: 127.0.0.1 www.bsplaycodec.com
      Removed hosts entry: 127.0.0.1 bsplaycodec.com
      Removed hosts entry: 127.0.0.1 buldog-stats.com
      Removed hosts entry: 127.0.0.1 www.busysearch.net
      Removed hosts entry: 127.0.0.1 busysearch.net
      Removed hosts entry: 127.0.0.1 www.c4tdownload.com
      Removed hosts entry: 127.0.0.1 c4tdownload.com
      Removed hosts entry: 127.0.0.1 carsands.com
      Removed hosts entry: 127.0.0.1 cashsearch.biz
      Removed hosts entry: 127.0.0.1 casino.com.free.game.pogo.gratisdownloads.nl
      Removed hosts entry: 127.0.0.1 cazygirls-world.com
      Removed hosts entry: 127.0.0.1 cdn.winsoftware.com
      Removed hosts entry: 127.0.0.1 www.cinemadownload.com
      Removed hosts entry: 127.0.0.1 cinemadownload.com
      Removed hosts entry: 127.0.0.1 www.citycodec.com
      Removed hosts entry: 127.0.0.1 citycodec.com
      Removed hosts entry: 127.0.0.1 www.cleancodec.com
      Removed hosts entry: 127.0.0.1 cleancodec.com
      Removed hosts entry: 127.0.0.1 www.cleansoftwares.com
      Removed hosts entry: 127.0.0.1 cleansoftwares.com
      Removed hosts entry: 127.0.0.1 clearsearch.net
      Removed hosts entry: 127.0.0.1 www.click-codec.com
      Removed hosts entry: 127.0.0.1 click-codec.com
      Removed hosts entry: 127.0.0.1 www.clickhere4search.com
      Removed hosts entry: 127.0.0.1 clickhere4search.com
      Removed hosts entry: 127.0.0.1 www.click-new-download.com
      Removed hosts entry: 127.0.0.1 click-new-download.com
      Removed hosts entry: 127.0.0.1 www.click-to-download.com
      Removed hosts entry: 127.0.0.1 click-to-download.com
      Removed hosts entry: 127.0.0.1 www.clicktomakeasearch.com
      Removed hosts entry: 127.0.0.1 clicktomakeasearch.com
      Removed hosts entry: 127.0.0.1 client.exeupdate.com
      Removed hosts entry: 127.0.0.1 code.ignphrases.com
      Removed hosts entry: 127.0.0.1 codec.ninoa.com
      Removed hosts entry: 127.0.0.1 www.codecadult18.com
      Removed hosts entry: 127.0.0.1 codecadult18.com
      Removed hosts entry: 127.0.0.1 www.codecbest.com
      Removed hosts entry: 127.0.0.1 codecbest.com
      Removed hosts entry: 127.0.0.1 www.codecbsplay.com
      Removed hosts entry: 127.0.0.1 codecbsplay.com
      Removed hosts entry: 127.0.0.1 www.codecdemo.com
      Removed hosts entry: 127.0.0.1 codecdemo.com
      Removed hosts entry: 127.0.0.1 www.codecdvd.net
      Removed hosts entry: 127.0.0.1 codecdvd.net
      Removed hosts entry: 127.0.0.1 www.codecdvi.com
      Removed hosts entry: 127.0.0.1 codecdvi.com
      Removed hosts entry: 127.0.0.1 www.codec-fun.com
      Removed hosts entry: 127.0.0.1 codec-fun.com
      Removed hosts entry: 127.0.0.1 www.codechard.com
      Removed hosts entry: 127.0.0.1 codechard.com
      Removed hosts entry: 127.0.0.1 www.codechot.net
      Removed hosts entry: 127.0.0.1 codechot.net
      Removed hosts entry: 127.0.0.1 www.codechq.net
      Removed hosts entry: 127.0.0.1 codechq.net
      Removed hosts entry: 127.0.0.1 www.codecmeg.net
      Removed hosts entry: 127.0.0.1 codecmeg.net
      Removed hosts entry: 127.0.0.1 www.codecmega.com
      Removed hosts entry: 127.0.0.1 codecmega.com
      Removed hosts entry: 127.0.0.1 www.codecmega.net
      Removed hosts entry: 127.0.0.1 codecmega.net
      Removed hosts entry: 127.0.0.1 www.codecmoon.com
      Removed hosts entry: 127.0.0.1 codecmoon.com
      Removed hosts entry: 127.0.0.1 www.codecmpg.com
      Removed hosts entry: 127.0.0.1 codecmpg.com
      Removed hosts entry: 127.0.0.1 www.codecnice.net
      Removed hosts entry: 127.0.0.1 codecnice.net
      Removed hosts entry: 127.0.0.1 www.codecnitro.com
      Removed hosts entry: 127.0.0.1 codecnitro.com
      Removed hosts entry: 127.0.0.1 www.codecops.net
      Removed hosts entry: 127.0.0.1 codecops.net
      Removed hosts entry: 127.0.0.1 www.codecplay.com
      Removed hosts entry: 127.0.0.1 codecplay.com
      Removed hosts entry: 127.0.0.1 www.codecpretty.net
      Removed hosts entry: 127.0.0.1 codecpretty.net
      Removed hosts entry: 127.0.0.1 www.codecpro.net
      Removed hosts entry: 127.0.0.1 codecpro.net
      Removed hosts entry: 127.0.0.1 www.codecred.net
      Removed hosts entry: 127.0.0.1 codecred.net
      Removed hosts entry: 127.0.0.1 www.codecsoft.net
      Removed hosts entry: 127.0.0.1 codecsoft.net
      Removed hosts entry: 127.0.0.1 www.codecthe.com
      Removed hosts entry: 127.0.0.1 codecthe.com
      Removed hosts entry: 127.0.0.1 www.codectime.com
      Removed hosts entry: 127.0.0.1 codectime.com
      Removed hosts entry: 127.0.0.1 www.codecultra.net
      Removed hosts entry: 127.0.0.1 codecultra.net
      Removed hosts entry: 127.0.0.1 www.codecvids.com
      Removed hosts entry: 127.0.0.1 codecvids.com
      Removed hosts entry: 127.0.0.1 www.codecvip.com
      Removed hosts entry: 127.0.0.1 codecvip.com
      Removed hosts entry: 127.0.0.1 www.codecviva.com
      Removed hosts entry: 127.0.0.1 codecviva.com
      Removed hosts entry: 127.0.0.1 www.codeczang.net
      Removed hosts entry: 127.0.0.1 codeczang.net
      Removed hosts entry: 127.0.0.1 www.computerpcgames.net
      Removed hosts entry: 127.0.0.1 computerpcgames.net
      Removed hosts entry: 127.0.0.1 www.contra-virus.com
      Removed hosts entry: 127.0.0.1 contra-virus.com
      Removed hosts entry: 127.0.0.1 www.convenient-search.com
      Removed hosts entry: 127.0.0.1 convenient-search.com
      Removed hosts entry: 127.0.0.1 coolmoneysearch.com
      Removed hosts entry: 127.0.0.1 coolpornsearch.com
      Removed hosts entry: 127.0.0.1 cool-search.net
      Removed hosts entry: 127.0.0.1 cool-search.netfartpost.com
      Removed hosts entry: 127.0.0.1 www.coolwebsearch.com
      Removed hosts entry: 127.0.0.1 coolwebsearch.com
      Removed hosts entry: 127.0.0.1 cool-web-search.com
      Removed hosts entry: 127.0.0.1 www.coolwwwsearch.com
      Removed hosts entry: 127.0.0.1 coolwwwsearch.com
      Removed hosts entry: 127.0.0.1 counter.sexmaniack.com
      Removed hosts entry: 127.0.0.1 www.crazygirls-world.com
      Removed hosts entry: 127.0.0.1 crazygirls-world.com
      Removed hosts entry: 127.0.0.1 creditsearchonline.com
      Removed hosts entry: 127.0.0.1 www.dailypornmag.com
      Removed hosts entry: 127.0.0.1 dailypornmag.com
      Removed hosts entry: 127.0.0.1 dating-search.net
      Removed hosts entry: 127.0.0.1 de.winantivirus.com
      Removed hosts entry: 127.0.0.1 www.debay.it
      Removed hosts entry: 127.0.0.1 debay.it
      Removed hosts entry: 127.0.0.1 www.dedsearch.com
      Removed hosts entry: 127.0.0.1 dedsearch.com
      Removed hosts entry: 127.0.0.1 defaultsearch.net
      Removed hosts entry: 127.0.0.1 www.defensaantimalware.com
      Removed hosts entry: 127.0.0.1 defensaantimalware.com
      Removed hosts entry: 127.0.0.1 www.delficodec.com
      Removed hosts entry: 127.0.0.1 delficodec.com
      Removed hosts entry: 127.0.0.1 www.democodec.com
      Removed hosts entry: 127.0.0.1 democodec.com
      Removed hosts entry: 127.0.0.1 www.deskbar.worldtostart.com
      Removed hosts entry: 127.0.0.1 deskbar.worldtostart.com
      Removed hosts entry: 127.0.0.1 www.detectivesearches.com
      Removed hosts entry: 127.0.0.1 detectivesearches.com
      Removed hosts entry: 127.0.0.1 www.digitalcoders.net
      Removed hosts entry: 127.0.0.1 digitalcoders.net
      Removed hosts entry: 127.0.0.1 digital-pornography.com
      Removed hosts entry: 127.0.0.1 www.directsearchzone.com
      Removed hosts entry: 127.0.0.1 directsearchzone.com
      Removed hosts entry: 127.0.0.1 dl1.antivermins.com
      Removed hosts entry: 127.0.0.1 dl1.antivirgear.com
      Removed hosts entry: 127.0.0.1 dl1.virusprotectpro.com
      Removed hosts entry: 127.0.0.1 document-not-found.pornpic.org
      Removed hosts entry: 127.0.0.1 download.abetterinternet.com
      Removed hosts entry: 127.0.0.1 download.adintelligence.net
      Removed hosts entry: 127.0.0.1 www.download.antispywarebot.com
      Removed hosts entry: 127.0.0.1 download.antispywarebot.com
      Removed hosts entry: 127.0.0.1 www.download.bardownload.com
      Removed hosts entry: 127.0.0.1 download.bardownload.com
      Removed hosts entry: 127.0.0.1 www.download.bravesentry.com
      Removed hosts entry: 127.0.0.1 download.bravesentry.com
      Removed hosts entry: 127.0.0.1 download.cdn.drivecleaner.com
      Removed hosts entry: 127.0.0.1 download.cdn.errorsafe.com
      Removed hosts entry: 127.0.0.1 download.cdn.winsoftware.com
      Removed hosts entry: 127.0.0.1 download.contextplus.net
      Removed hosts entry: 127.0.0.1 download.errorsafe.com
      Removed hosts entry: 127.0.0.1 www.download.jupitersatellites.biz
      Removed hosts entry: 127.0.0.1 download.jupitersatellites.biz
      Removed hosts entry: 127.0.0.1 download.malwarealarm.com
      Removed hosts entry: 127.0.0.1 download.searchtabs.net
      Removed hosts entry: 127.0.0.1 www.download.secureyournet.biz
      Removed hosts entry: 127.0.0.1 download.secureyournet.biz
      Removed hosts entry: 127.0.0.1 download.spyonthis.net
      Removed hosts entry: 127.0.0.1 download.spy-shredder.com
      Removed hosts entry: 127.0.0.1 download.systemdoctor.com
      Removed hosts entry: 127.0.0.1 download.winantispyware.com
      Removed hosts entry: 127.0.0.1 download.winantivirus.com
      Removed hosts entry: 127.0.0.1 download.windrivecleaner.com
      Removed hosts entry: 127.0.0.1 download.winfixer.com
      Removed hosts entry: 127.0.0.1 download10.spywarequake.com
      Removed hosts entry: 127.0.0.1 download11.spywarequake.com
      Removed hosts entry: 127.0.0.1 download12.spywarequake.com
      Removed hosts entry: 127.0.0.1 download13.spywarequake.com
      Removed hosts entry: 127.0.0.1 download15.spywarequake.com
      Removed hosts entry: 127.0.0.1 download2.spywarequake.com
      Removed hosts entry: 127.0.0.1 www.download-2007.com
      Removed hosts entry: 127.0.0.1 download-2007.com
      Removed hosts entry: 127.0.0.1 download3.spyaxe.com
      Removed hosts entry: 127.0.0.1 download3.spywarequake.com
      Removed hosts entry: 127.0.0.1 www.download3xpics.com
      Removed hosts entry: 127.0.0.1 download3xpics.com
      Removed hosts entry: 127.0.0.1 download4.spyaxe.com
      Removed hosts entry: 127.0.0.1 download4.spywarequake.com
      Removed hosts entry: 127.0.0.1 download5.spyaxe.com
      Removed hosts entry: 127.0.0.1 download5.spywarequake.com
      Removed hosts entry: 127.0.0.1 download6.spyaxe.com
      Removed hosts entry: 127.0.0.1 download7.spywarequake.com
      Removed hosts entry: 127.0.0.1 download8.spywarequake.com
      Removed hosts entry: 127.0.0.1 download9.spywarequake.com
      Removed hosts entry: 127.0.0.1 www.downloadacceleratorsite.com
      Removed hosts entry: 127.0.0.1 downloadacceleratorsite.com
      Removed hosts entry: 127.0.0.1 www.download-ad-aware.com
      Removed hosts entry: 127.0.0.1 download-ad-aware.com
      Removed hosts entry: 127.0.0.1 www.download-all-4-free.com
      Removed hosts entry: 127.0.0.1 download-all-4-free.com
      Removed hosts entry: 127.0.0.1 www.download-all-area.com
      Removed hosts entry: 127.0.0.1 download-all-area.com
      Removed hosts entry: 127.0.0.1 www.download-antivir.com
      Removed hosts entry: 127.0.0.1 download-antivir.com
      Removed hosts entry: 127.0.0.1 www.downloadanysong.com
      Removed hosts entry: 127.0.0.1 downloadanysong.com
      Removed hosts entry: 127.0.0.1 www.downloadaresnow.com
      Removed hosts entry: 127.0.0.1 downloadaresnow.com
      Removed hosts entry: 127.0.0.1 www.download-avast.com
      Removed hosts entry: 127.0.0.1 download-avast.com
      Removed hosts entry: 127.0.0.1 www.downloadcorporation.com
      Removed hosts entry: 127.0.0.1 downloadcorporation.com
      Removed hosts entry: 127.0.0.1 www.download-dvdshrink.com
      Removed hosts entry: 127.0.0.1 download-dvdshrink.com
      Removed hosts entry: 127.0.0.1 www.download-for-free.net
      Removed hosts entry: 127.0.0.1 download-for-free.net
      Removed hosts entry: 127.0.0.1 www.downloadfreesoft.com
      Removed hosts entry: 127.0.0.1 downloadfreesoft.com
      Removed hosts entry: 127.0.0.1 www.downloadfreeway.com
      Removed hosts entry: 127.0.0.1 downloadfreeway.com
      Removed hosts entry: 127.0.0.1 www.downloadimesh.com
      Removed hosts entry: 127.0.0.1 downloadimesh.com
      Removed hosts entry: 127.0.0.1 www.download-itunes-now.com
      Removed hosts entry: 127.0.0.1 download-itunes-now.com
      Removed hosts entry: 127.0.0.1 www.download-limewire.org
      Removed hosts entry: 127.0.0.1 download-limewire.org
      Removed hosts entry: 127.0.0.1 www.downloadmax.net
      Removed hosts entry: 127.0.0.1 downloadmax.net
      Removed hosts entry: 127.0.0.1 www.download-mcafee.com
      Removed hosts entry: 127.0.0.1 download-mcafee.com
      Removed hosts entry: 127.0.0.1 www.downloadmediaax.com
      Removed hosts entry: 127.0.0.1 downloadmediaax.com
      Removed hosts entry: 127.0.0.1 www.downloadpics.net
      Removed hosts entry: 127.0.0.1 downloadpics.net
      Removed hosts entry: 127.0.0.1 www.downloadprovider.net
      Removed hosts entry: 127.0.0.1 downloadprovider.net
      Removed hosts entry: 127.0.0.1 www.download-real-player.com
      Removed hosts entry: 127.0.0.1 download-real-player.com
      Removed hosts entry: 127.0.0.1 downloads.180solutions.com
      Removed hosts entry: 127.0.0.1 www.downloadservicearea.com
      Removed hosts entry: 127.0.0.1 downloadservicearea.com
      Removed hosts entry: 127.0.0.1 www.downloads-free.org
      Removed hosts entry: 127.0.0.1 downloads-free.org
      Removed hosts entry: 127.0.0.1 www.downloadsglobe.com
      Removed hosts entry: 127.0.0.1 downloadsglobe.com
      Removed hosts entry: 127.0.0.1 www.download-trillian.com
      Removed hosts entry: 127.0.0.1 download-trillian.com
      Removed hosts entry: 127.0.0.1 www.downloadv3.com
      Removed hosts entry: 127.0.0.1 downloadv3.com
      Removed hosts entry: 127.0.0.1 www.downloadvax.com
      Removed hosts entry: 127.0.0.1 downloadvax.com
      Removed hosts entry: 127.0.0.1 download-video.12w.net
      Removed hosts entry: 127.0.0.1 www.download-windvd.com
      Removed hosts entry: 127.0.0.1 download-windvd.com
      Removed hosts entry: 127.0.0.1 www.download-winrar.com
      Removed hosts entry: 127.0.0.1 download-winrar.com
      Removed hosts entry: 127.0.0.1 downloadwizard.com
      Removed hosts entry: 127.0.0.1 www.downloadxmoveis.com
      Removed hosts entry: 127.0.0.1 downloadxmoveis.com
      Removed hosts entry: 127.0.0.1 www.downloadxvids.com
      Removed hosts entry: 127.0.0.1 downloadxvids.com
      Removed hosts entry: 127.0.0.1 downloadzcenter.com
      Removed hosts entry: 127.0.0.1 downloadzcentral.com
      Removed hosts entry: 127.0.0.1 www.downloadzfree.com
      Removed hosts entry: 127.0.0.1 downloadzfree.com
      Removed hosts entry: 127.0.0.1 downloadznow.net
      Removed hosts entry: 127.0.0.1 www.download-zone-free.com
      Removed hosts entry: 127.0.0.1 download-zone-free.com
      Removed hosts entry: 127.0.0.1 www.download-zone-free.net
      Removed hosts entry: 127.0.0.1 download-zone-free.net
      Removed hosts entry: 127.0.0.1 www.drepubblica.it
      Removed hosts entry: 127.0.0.1 drepubblica.it
      Removed hosts entry: 127.0.0.1 drocherway.com
      Removed hosts entry: 127.0.0.1 dutch-sex.com
      Removed hosts entry: 127.0.0.1 www.dvd-codec.com
      Removed hosts entry: 127.0.0.1 dvd-codec.com
      Removed hosts entry: 127.0.0.1 www.dvdcodec.net
      Removed hosts entry: 127.0.0.1 dvdcodec.net
      Removed hosts entry: 127.0.0.1 www.dvicodec.com
      Removed hosts entry: 127.0.0.1 dvicodec.com
      Removed hosts entry: 127.0.0.1 eager-sex.com
      Removed hosts entry: 127.0.0.1 easyantispy.com
      Removed hosts entry: 127.0.0.1 www.easypspdownloads.com
      Removed hosts entry: 127.0.0.1 easypspdownloads.com
      Removed hosts entry: 127.0.0.1 easy-search.net
      Removed hosts entry: 127.0.0.1 www.easysearch4you.com
      Removed hosts entry: 127.0.0.1 easysearch4you.com
      Removed hosts entry: 127.0.0.1 easysearchingtips.com
      Removed hosts entry: 127.0.0.1 www.ebay6.it
      Removed hosts entry: 127.0.0.1 ebay6.it
      Removed hosts entry: 127.0.0.1 www.ebay7.it
      Removed hosts entry: 127.0.0.1 ebay7.it
      Removed hosts entry: 127.0.0.1 www.ebayg.it
      Removed hosts entry: 127.0.0.1 ebayg.it
      Removed hosts entry: 127.0.0.1 www.ebayh.it
      Removed hosts entry: 127.0.0.1 ebayh.it
      Removed hosts entry: 127.0.0.1 www.ebayj.it
      Removed hosts entry: 127.0.0.1 ebayj.it
      Removed hosts entry: 127.0.0.1 www.ebayt.it
      Removed hosts entry: 127.0.0.1 ebayt.it
      Removed hosts entry: 127.0.0.1 www.ebayu.it
      Removed hosts entry: 127.0.0.1 ebayu.it
      Removed hosts entry: 127.0.0.1 ebonypornmag.com
      Removed hosts entry: 127.0.0.1 www.ebonypornmag.com
      Removed hosts entry: 127.0.0.1 ebony-pornmag.com
      Removed hosts entry: 127.0.0.1 www.ebony-pornmag.com
      Removed hosts entry: 127.0.0.1 ecstasyporn.net
      Removed hosts entry: 127.0.0.1 www.eebay.it
      Removed hosts entry: 127.0.0.1 eebay.it
      Removed hosts entry: 127.0.0.1 www.eepubblica.it
      Removed hosts entry: 127.0.0.1 eepubblica.it
      Removed hosts entry: 127.0.0.1 www.efcsoftware.com
      Removed hosts entry: 127.0.0.1 efcsoftware.com
      Removed hosts entry: 127.0.0.1 www.elitecodec.com
      Removed hosts entry: 127.0.0.1 elitecodec.com
      Removed hosts entry: 127.0.0.1 www.emcodec.com
      Removed hosts entry: 127.0.0.1 emcodec.com
      Removed hosts entry: 127.0.0.1 www.emediacodec.com
      Removed hosts entry: 127.0.0.1 emediacodec.com
      Removed hosts entry: 127.0.0.1 www.emule.click-new-download.com
      Removed hosts entry: 127.0.0.1 emule.click-new-download.com
      Removed hosts entry: 127.0.0.1 www.emuledownloadhome.com
      Removed hosts entry: 127.0.0.1 emuledownloadhome.com
      Removed hosts entry: 127.0.0.1 www.encodeinstrument.com
      Removed hosts entry: 127.0.0.1 encodeinstrument.com
      Removed hosts entry: 127.0.0.1 www.endcodec.com
      Removed hosts entry: 127.0.0.1 endcodec.com
      Removed hosts entry: 127.0.0.1 www.enterthesearch.com
      Removed hosts entry: 127.0.0.1 enterthesearch.com
      Removed hosts entry: 127.0.0.1 epornsex.com
      Removed hosts entry: 127.0.0.1 www.erepubblica.it
      Removed hosts entry: 127.0.0.1 erepubblica.it
      Removed hosts entry: 127.0.0.1 es.winantivirus.com
      Removed hosts entry: 127.0.0.1 www.esearch2005.com
      Removed hosts entry: 127.0.0.1 esearch2005.com
      Removed hosts entry: 127.0.0.1 www.etomi.all-downloads-now.com
      Removed hosts entry: 127.0.0.1 etomi.all-downloads-now.com
      Removed hosts entry: 127.0.0.1 www.eupdatepage.com
      Removed hosts entry: 127.0.0.1 eupdatepage.com
      Removed hosts entry: 127.0.0.1 www.every-game.com
      Removed hosts entry: 127.0.0.1 every-game.com
      Removed hosts entry: 127.0.0.1 ewebsearch.net
      Removed hosts entry: 127.0.0.1 www.exeupdate.com
      Removed hosts entry: 127.0.0.1 exeupdate.com
      Removed hosts entry: 127.0.0.1 www.eza1netsearch.com
      Removed hosts entry: 127.0.0.1 eza1netsearch.com
      Removed hosts entry: 127.0.0.1 www.ezcybersearch.com
      Removed hosts entry: 127.0.0.1 ezcybersearch.com
      Removed hosts entry: 127.0.0.1 ez-searching.com
      Removed hosts entry: 127.0.0.1 www.ezwebsearching.com
      Removed hosts entry: 127.0.0.1 ezwebsearching.com
      Removed hosts entry: 127.0.0.1 www.fairsearcher.com
      Removed hosts entry: 127.0.0.1 fairsearcher.com
      Removed hosts entry: 127.0.0.1 fastfreedownload.com
      Removed hosts entry: 127.0.0.1 www.fastmetasearch.com
      Removed hosts entry: 127.0.0.1 fastmetasearch.com
      Removed hosts entry: 127.0.0.1 www.fastpspdownloads.com
      Removed hosts entry: 127.0.0.1 fastpspdownloads.com
      Removed hosts entry: 127.0.0.1 www.fastssearch.com
      Removed hosts entry: 127.0.0.1 fastssearch.com
      Removed hosts entry: 127.0.0.1 www.fasttvdownloads.com
      Removed hosts entry: 127.0.0.1 fasttvdownloads.com
      Removed hosts entry: 127.0.0.1 faxporn.com
      Removed hosts entry: 127.0.0.1 www.febay.it
      Removed hosts entry: 127.0.0.1 febay.it
      Removed hosts entry: 127.0.0.1 feed.dedsearch.com
      Removed hosts entry: 127.0.0.1 www.feeds.2search.com
      Removed hosts entry: 127.0.0.1 feeds.2search.com
      Removed hosts entry: 127.0.0.1 www.feeds2.2search.org
      Removed hosts entry: 127.0.0.1 feeds2.2search.org
      Removed hosts entry: 127.0.0.1 www.fgoogle.it
      Removed hosts entry: 127.0.0.1 fgoogle.it
      Removed hosts entry: 127.0.0.1 www.filesharing-downloads.com
      Removed hosts entry: 127.0.0.1 filesharing-downloads.com
      Removed hosts entry: 127.0.0.1 www.filetretporn.com
      Removed hosts entry: 127.0.0.1 filetretporn.com
      Removed hosts entry: 127.0.0.1 fine-search.net
      Removed hosts entry: 127.0.0.1 www.firecodec.com
      Removed hosts entry: 127.0.0.1 firecodec.com
      Removed hosts entry: 127.0.0.1 www.firefoxdownload-now.com
      Removed hosts entry: 127.0.0.1 firefoxdownload-now.com
      Removed hosts entry: 127.0.0.1 www.firstgoodsearch.com
      Removed hosts entry: 127.0.0.1 firstgoodsearch.com
      Removed hosts entry: 127.0.0.1 www.fixerantispy.com
      Removed hosts entry: 127.0.0.1 fixerantispy.com
      Removed hosts entry: 127.0.0.1 www.flwupdate.com
      Removed hosts entry: 127.0.0.1 flwupdate.com
      Removed hosts entry: 127.0.0.1 www.flycodecs.com
      Removed hosts entry: 127.0.0.1 flycodecs.com
      Removed hosts entry: 127.0.0.1 fr.winantivirus.com
      Removed hosts entry: 127.0.0.1 frame.crazywinnings.com
      Removed hosts entry: 127.0.0.1 free4porno.net
      Removed hosts entry: 127.0.0.1 www.free-adobe-download-support.com
      Removed hosts entry: 127.0.0.1 free-adobe-download-support.com
      Removed hosts entry: 127.0.0.1 www.free-avg-download.com
      Removed hosts entry: 127.0.0.1 free-avg-download.com
      Removed hosts entry: 127.0.0.1 www.freedownloadhq.com
      Removed hosts entry: 127.0.0.1 freedownloadhq.com
      Removed hosts entry: 127.0.0.1 www.freedownloadpage.com
      Removed hosts entry: 127.0.0.1 freedownloadpage.com
      Removed hosts entry: 127.0.0.1 www.free-download-place.com
      Removed hosts entry: 127.0.0.1 free-download-place.com
      Removed hosts entry: 127.0.0.1 www.free-download-support.com
      Removed hosts entry: 127.0.0.1 free-download-support.com
      Removed hosts entry: 127.0.0.1 www.freedownloadzone.com
      Removed hosts entry: 127.0.0.1 freedownloadzone.com
      Removed hosts entry: 127.0.0.1 www.freeimageheaven.com
      Removed hosts entry: 127.0.0.1 freeimageheaven.com
      Removed hosts entry: 127.0.0.1 free-pics-and-movies.com
      Removed hosts entry: 127.0.0.1 www.free-program-download.com
      Removed hosts entry: 127.0.0.1 free-program-download.com
      Removed hosts entry: 127.0.0.1 free-sex-movie-clips.net
      Removed hosts entry: 127.0.0.1 freeshemalepics.net
      Removed hosts entry: 127.0.0.1 www.free-software-center.com
      Removed hosts entry: 127.0.0.1 free-software-center.com
      Removed hosts entry: 127.0.0.1 www.free-spyware-downloads.com
      Removed hosts entry: 127.0.0.1 free-spyware-downloads.com
      Removed hosts entry: 127.0.0.1 fregat.drocherway.com
      Removed hosts entry: 127.0.0.1 www.frepubblica.it
      Removed hosts entry: 127.0.0.1 frepubblica.it
      Removed hosts entry: 127.0.0.1 www.frostwire.click-new-download.com
      Removed hosts entry: 127.0.0.1 frostwire.click-new-download.com
      Removed hosts entry: 127.0.0.1 www.fullmusicdownload.com
      Removed hosts entry: 127.0.0.1 fullmusicdownload.com
      Removed hosts entry: 127.0.0.1 full-search.net
      Removed hosts entry: 127.0.0.1 www.fullsoftwarecenter.com
      Removed hosts entry: 127.0.0.1 fullsoftwarecenter.com
      Removed hosts entry: 127.0.0.1 www.fullsoftwaredownloadz.com
      Removed hosts entry: 127.0.0.1 fullsoftwaredownloadz.com
      Removed hosts entry: 127.0.0.1 www.fulltvdownloading.com
      Removed hosts entry: 127.0.0.1 fulltvdownloading.com
      Removed hosts entry: 127.0.0.1 www.funcodec.com
      Removed hosts entry: 127.0.0.1 funcodec.com
      Removed hosts entry: 127.0.0.1 www.galleriesforporn.com
      Removed hosts entry: 127.0.0.1 galleriesforporn.com
      Removed hosts entry: 127.0.0.1 www.gallsforporn.com
      Removed hosts entry: 127.0.0.1 gallsforporn.com
      Removed hosts entry: 127.0.0.1 www.game4all.biz
      Removed hosts entry: 127.0.0.1 game4all.biz
      Removed hosts entry: 127.0.0.1 www.gamecodec.com
      Removed hosts entry: 127.0.0.1 gamecodec.com
      Removed hosts entry: 127.0.0.1 www.games.de.ag
      Removed hosts entry: 127.0.0.1 games.de.ag
      Removed hosts entry: 127.0.0.1 games.uzoogle.com
      Removed hosts entry: 127.0.0.1 www.games-desktop.com
      Removed hosts entry: 127.0.0.1 games-desktop.com
      Removed hosts entry: 127.0.0.1 www.games-u-spiele.de
      Removed hosts entry: 127.0.0.1 games-u-spiele.de
      Removed hosts entry: 127.0.0.1 gameterror.net
      Removed hosts entry: 127.0.0.1 www.gayspornmag.com
      Removed hosts entry: 127.0.0.1 gayspornmag.com
      Removed hosts entry: 127.0.0.1 get.hitvirus.com
      Removed hosts entry: 127.0.0.1 www.getanysoftware.com
      Removed hosts entry: 127.0.0.1 getanysoftware.com
      Removed hosts entry: 127.0.0.1 www.getfreepornvideo.com
      Removed hosts entry: 127.0.0.1 getfreepornvideo.com

      Scan started: 08/07/2008 13:05:47


      Scanning running processes and process memory...

      Number of processes/threads found: 1692
      Number of processes/threads scanned: 1692
      Number of processes/threads not scanned: 0
      Number of infected processes/threads terminated: 0
      Total scanning time: 29s


      Scanning file system...

      Scanning: C:\*.*

      C:\Program Files\WebMediaPlayer\WebMediaPlayer.exe (Infected with W32/Smalltroj.CDIP)
      Deleted file

      C:\System Volume Information\_RESTO~1\RP371\A0103062.exe (Infected with Renos.XS)
      Deleted file

      C:\System Volume Information\_RESTO~1\RP379\A0103828.exe (Infected with W32/Zlob.BWLZ)
      Deleted file

      C:\System Volume Information\_RESTO~1\RP406\A0115214.exe (Infected with W32/Smalltroj.CDIP)
      Deleted file

      Scanning: c:\System Volume Information\*.*


      Running post-scan cleanup routine:
      Removed hosts entry: 127.0.0.1 getpicshere.com
      Removed hosts entry: 127.0.0.1 www.getpornmag.com
      Removed hosts entry: 127.0.0.1 getpornmag.com
      Removed hosts entry: 127.0.0.1 www.getpornvideoz.com
      Removed hosts entry: 127.0.0.1 getpornvideoz.com
      Removed hosts entry: 127.0.0.1 www.gigacodec.net
      Removed hosts entry: 127.0.0.1 gigacodec.net
      Removed hosts entry: 127.0.0.1 girls-porn-life.com
      Removed hosts entry: 127.0.0.1 www.givemepornvids.com
      Removed hosts entry: 127.0.0.1 givemepornvids.com
      Removed hosts entry: 127.0.0.1 www.globalfreesearch.com
      Removed hosts entry: 127.0.0.1 globalfreesearch.com
      Removed hosts entry: 127.0.0.1 www.globalsoftwareagreement.com
      Removed hosts entry: 127.0.0.1 globalsoftwareagreement.com
      Removed hosts entry: 127.0.0.1 globalwebsearch.com
      Removed hosts entry: 127.0.0.1 www.globesearch.com
      Removed hosts entry: 127.0.0.1 globesearch.com
      Removed hosts entry: 127.0.0.1 go.winantispyware.com
      Removed hosts entry: 127.0.0.1 go.winantivirus.com
      Removed hosts entry: 127.0.0.1 www.go2realsearch.com
      Removed hosts entry: 127.0.0.1 go2realsearch.com
      Removed hosts entry: 127.0.0.1 go2-search.com
      Removed hosts entry: 127.0.0.1 www.gocodec.com
      Removed hosts entry: 127.0.0.1 gocodec.com
      Removed hosts entry: 127.0.0.1 www.gocybersearch.com
      Removed hosts entry: 127.0.0.1 gocybersearch.com
      Removed hosts entry: 127.0.0.1 www.goldcodec.com
      Removed hosts entry: 127.0.0.1 goldcodec.com
      Removed hosts entry: 127.0.0.1 www.goldenantispy.com
      Removed hosts entry: 127.0.0.1 goldenantispy.com
      Removed hosts entry: 127.0.0.1 goodsexs.com
      Removed hosts entry: 127.0.0.1 google.panet.org
      Removed hosts entry: 127.0.0.1 google123.web1000.com
      Removed hosts entry: 127.0.0.1 googlebar.jps.ru
      Removed hosts entry: 127.0.0.1 www.googlebawt.com
      Removed hosts entry: 127.0.0.1 googlebawt.com
      Removed hosts entry: 127.0.0.1 gratis-porn-movie.com
      Removed hosts entry: 127.0.0.1 gratis-pornopics.com
      Removed hosts entry: 127.0.0.1 www.greatcodec.com
      Removed hosts entry: 127.0.0.1 greatcodec.com
      Removed hosts entry: 127.0.0.1 greg-search.com
      Removed hosts entry: 127.0.0.1 greg-tut.com
      Removed hosts entry: 127.0.0.1 www.grepubblica.it
      Removed hosts entry: 127.0.0.1 grepubblica.it
      Removed hosts entry: 127.0.0.1 www.hacker.com.cn
      Removed hosts entry: 127.0.0.1 hacker.com.cn
      Removed hosts entry: 127.0.0.1 www.hardcorepornmag.com
      Removed hosts entry: 127.0.0.1 hardcorepornmag.com
      Removed hosts entry: 127.0.0.1 hardpornmpg.com
      Removed hosts entry: 127.0.0.1 www.hastalavista.com
      Removed hosts entry: 127.0.0.1 hastalavista.com
      Removed hosts entry: 127.0.0.1 www.helpcodec.com
      Removed hosts entry: 127.0.0.1 helpcodec.com
      Removed hosts entry: 127.0.0.1 helpyoursearch.com
      Removed hosts entry: 127.0.0.1 www.here4search.biz
      Removed hosts entry: 127.0.0.1 here4search.biz
      Removed hosts entry: 127.0.0.1 www.here4search.com
      Removed hosts entry: 127.0.0.1 here4search.com
      Removed hosts entry: 127.0.0.1 www.herocodec.com
      Removed hosts entry: 127.0.0.1 herocodec.com
      Removed hosts entry: 127.0.0.1 www.hgoogle.it
      Removed hosts entry: 127.0.0.1 hgoogle.it
      Removed hosts entry: 127.0.0.1 hi-search.com
      Removed hosts entry: 127.0.0.1 www.hitvirus.com
      Removed hosts entry: 127.0.0.1 hitvirus.com
      Removed hosts entry: 127.0.0.1 hk.winantivirus.com
      Removed hosts entry: 127.0.0.1 www.hobbypesca.com.br
      Removed hosts entry: 127.0.0.1 hobbypesca.com.br
      Removed hosts entry: 127.0.0.1 holidayautostr.com
      Removed hosts entry: 127.0.0.1 www.host-codec.com
      Removed hosts entry: 127.0.0.1 host-codec.com
      Removed hosts entry: 127.0.0.1 www.hot18-codec2008.com
      Removed hosts entry: 127.0.0.1 hot18-codec2008.com
      Removed hosts entry: 127.0.0.1 www.hot200818codec.com
      Removed hosts entry: 127.0.0.1 hot200818codec.com
      Removed hosts entry: 127.0.0.1 www.hot2008-18codec.com
      Removed hosts entry: 127.0.0.1 hot2008-18codec.com
      Removed hosts entry: 127.0.0.1 www.hot2008codec.com
      Removed hosts entry: 127.0.0.1 hot2008codec.com
      Removed hosts entry: 127.0.0.1 hot-cartoon-sex.anime.american-teens.net
      Removed hosts entry: 127.0.0.1 www.hotcodec.net
      Removed hosts entry: 127.0.0.1 hotcodec.net
      Removed hosts entry: 127.0.0.1 www.hot-codec18.com
      Removed hosts entry: 127.0.0.1 hot-codec18.com
      Removed hosts entry: 127.0.0.1 www.hotcodecstars.com
      Removed hosts entry: 127.0.0.1 hotcodecstars.com
      Removed hosts entry: 127.0.0.1 www.hotecodec18.com
      Removed hosts entry: 127.0.0.1 hotecodec18.com
      Removed hosts entry: 127.0.0.1 www.hotelcodec.com
      Removed hosts entry: 127.0.0.1 hotelcodec.com
      Removed hosts entry: 127.0.0.1 www.hotmp3download.com
      Removed hosts entry: 127.0.0.1 hotmp3download.com
      Removed hosts entry: 127.0.0.1 hotsearchbox.com
      Removed hosts entry: 127.0.0.1 hotsex-series.com
      Removed hosts entry: 127.0.0.1 www.hotwinupdates.com
      Removed hosts entry: 127.0.0.1 hotwinupdates.com
      Removed hosts entry: 127.0.0.1 www.hqcodectime.net
      Removed hosts entry: 127.0.0.1 hqcodectime.net
      Removed hosts entry: 127.0.0.1 www.hqcodecvip.com
      Removed hosts entry: 127.0.0.1 hqcodecvip.com
      Removed hosts entry: 127.0.0.1 www.hq-downloads.com
      Removed hosts entry: 127.0.0.1 hq-downloads.com
      Removed hosts entry: 127.0.0.1 hqsex.biz
      Removed hosts entry: 127.0.0.1 hugeporn4u.net
      Removed hosts entry: 127.0.0.1 www.iaxobjectdownload.com
      Removed hosts entry: 127.0.0.1 iaxobjectdownload.com
      Removed hosts entry: 127.0.0.1 icansearch.net
      Removed hosts entry: 127.0.0.1 idgsearch.com
      Removed hosts entry: 127.0.0.1 www.idownload.com
      Removed hosts entry: 127.0.0.1 idownload.com
      Removed hosts entry: 127.0.0.1 ie-search.com
      Removed hosts entry: 127.0.0.1 iframe.biz
      Removed hosts entry: 127.0.0.1 www.iframebiz.com
      Removed hosts entry: 127.0.0.1 iframebiz.com
      Removed hosts entry: 127.0.0.1 www.imcodec.com
      Removed hosts entry: 127.0.0.1 imcodec.com
      Removed hosts entry: 127.0.0.1 www.imediacodec.com
      Removed hosts entry: 127.0.0.1 imediacodec.com
      Removed hosts entry: 127.0.0.1 www.imesh.click-new-download.com
      Removed hosts entry: 127.0.0.1 imesh.click-new-download.com
      Removed hosts entry: 127.0.0.1 www.imp3download.com
      Removed hosts entry: 127.0.0.1 imp3download.com
      Removed hosts entry: 127.0.0.1 imrworldwide.com
      Removed hosts entry: 127.0.0.1 www.inc-codec.com
      Removed hosts entry: 127.0.0.1 inc-codec.com
      Removed hosts entry: 127.0.0.1 incestporngate.com
      Removed hosts entry: 127.0.0.1 www.incredimail-download-now.com
      Removed hosts entry: 127.0.0.1 incredimail-download-now.com
      Removed hosts entry: 127.0.0.1 install.searchtab.net
      Removed hosts entry: 127.0.0.1 instlog.winantivirus.com
      Removed hosts entry: 127.0.0.1 www.intcodec.com
      Removed hosts entry: 127.0.0.1 intcodec.com
      Removed hosts entry: 127.0.0.1 www.internetgamebox.com
      Removed hosts entry: 127.0.0.1 internetgamebox.com
      Removed hosts entry: 127.0.0.1 www.internet-media-download.com
      Removed hosts entry: 127.0.0.1 internet-media-download.com
      Removed hosts entry: 127.0.0.1 internetsearch.ru
      Removed hosts entry: 127.0.0.1 www.internetsearchservice.com
      Removed hosts entry: 127.0.0.1 internetsearchservice.com
      Removed hosts entry: 127.0.0.1 www.ipoddownloadingpro.com
      Removed hosts entry: 127.0.0.1 ipoddownloadingpro.com
      Removed hosts entry: 127.0.0.1 www.ipod-itunes-download-now.com
      Removed hosts entry: 127.0.0.1 ipod-itunes-download-now.com
      Removed hosts entry: 127.0.0.1 www.ipod-tunes-download.com
      Removed hosts entry: 127.0.0.1 ipod-tunes-download.com
      Removed hosts entry: 127.0.0.1 ipsex.net
      Removed hosts entry: 127.0.0.1 www.ipspdownload.com
      Removed hosts entry: 127.0.0.1 ipspdownload.com
      Removed hosts entry: 127.0.0.1 iqsearch.net
      Removed hosts entry: 127.0.0.1 www.irfanview-download-now.com
      Removed hosts entry: 127.0.0.1 irfanview-download-now.com
      Removed hosts entry: 127.0.0.1 www.itvdownload.com
      Removed hosts entry: 127.0.0.1 itvdownload.com
      Removed hosts entry: 127.0.0.1 www.ivideocodec.com
      Removed hosts entry: 127.0.0.1 ivideocodec.com
      Removed hosts entry: 127.0.0.1 www.iwantsearch.net
      Removed hosts entry: 127.0.0.1 iwantsearch.net
      Removed hosts entry: 127.0.0.1 www.ixcodec.com
      Removed hosts entry: 127.0.0.1 ixcodec.com
      Removed hosts entry: 127.0.0.1 www.ixcodec.net
      Removed hosts entry: 127.0.0.1 ixcodec.net
      Removed hosts entry: 127.0.0.1 www.jetcodec.com
      Removed hosts entry: 127.0.0.1 jetcodec.com
      Removed hosts entry: 127.0.0.1 www.jmsn.it
      Removed hosts entry: 127.0.0.1 jmsn.it
      Removed hosts entry: 127.0.0.1 junkysex.com
      Removed hosts entry: 127.0.0.1 www.katasearch.com
      Removed hosts entry: 127.0.0.1 katasearch.com
      Removed hosts entry: 127.0.0.1 kb.winantivirus.com
      Removed hosts entry: 127.0.0.1 www.keycodec.com
      Removed hosts entry: 127.0.0.1 keycodec.com
      Removed hosts entry: 127.0.0.1 www.key-codec.com
      Removed hosts entry: 127.0.0.1 key-codec.com
      Removed hosts entry: 127.0.0.1 killerpornstars.com
      Removed hosts entry: 127.0.0.1 kilosex.com
      Removed hosts entry: 127.0.0.1 www.kimsoftware.com
      Removed hosts entry: 127.0.0.1 kimsoftware.com
      Removed hosts entry: 127.0.0.1 kliksearch.com
      Removed hosts entry: 127.0.0.1 www.kliksoftware.com
      Removed hosts entry: 127.0.0.1 kliksoftware.com
      Removed hosts entry: 127.0.0.1 www.kmsn.it
      Removed hosts entry: 127.0.0.1 kmsn.it
      Removed hosts entry: 127.0.0.1 l.mezzicodec.net
      Removed hosts entry: 127.0.0.1 www.lastsoftwares.com
      Removed hosts entry: 127.0.0.1 lastsoftwares.com
      Removed hosts entry: 127.0.0.1 www.lavasoftupdate.com
      Removed hosts entry: 127.0.0.1 lavasoftupdate.com
      Removed hosts entry: 127.0.0.1 www.lesbianpornmag.com
      Removed hosts entry: 127.0.0.1 lesbianpornmag.com
      Removed hosts entry: 127.0.0.1 www.lesbianspornmag.com
      Removed hosts entry: 127.0.0.1 lesbianspornmag.com
      Removed hosts entry: 127.0.0.1 www.lightcodec.com
      Removed hosts entry: 127.0.0.1 lightcodec.com
      Removed hosts entry: 127.0.0.1 www.light-codec.com
      Removed hosts entry: 127.0.0.1 light-codec.com
      Removed hosts entry: 127.0.0.1 www.lightcodec.net
      Removed hosts entry: 127.0.0.1 lightcodec.net
      Removed hosts entry: 127.0.0.1 www.lightspeedsearch.net
      Removed hosts entry: 127.0.0.1 lightspeedsearch.net
      Removed hosts entry: 127.0.0.1 www.limewire.click-new-download.com
      Removed hosts entry: 127.0.0.1 limewire.click-new-download.com
      Removed hosts entry: 127.0.0.1 www.limewire-download-pro.com
      Removed hosts entry: 127.0.0.1 limewire-download-pro.com
      Removed hosts entry: 127.0.0.1 www.limewire-pro-downloads.com
      Removed hosts entry: 127.0.0.1 limewire-pro-downloads.com
      Removed hosts entry: 127.0.0.1 www.linkautomatici.com
      Removed hosts entry: 127.0.0.1 linkautomatici.com
      Removed hosts entry: 127.0.0.1 www.little-download.net
      Removed hosts entry: 127.0.0.1 little-download.net
      Removed hosts entry: 127.0.0.1 www.live.sex-explorer.com
      Removed hosts entry: 127.0.0.1 live.sex-explorer.com
      Removed hosts entry: 127.0.0.1 lovelysearch.com
      Removed hosts entry: 127.0.0.1 luckysearch.net
      Removed hosts entry: 127.0.0.1 lustful-porno.com
      Removed hosts entry: 127.0.0.1 www.macrovirus.com
      Removed hosts entry: 127.0.0.1 macrovirus.com
      Removed hosts entry: 127.0.0.1 www.madsexxx.com
      Removed hosts entry: 127.0.0.1 madsexxx.com
      Removed hosts entry: 127.0.0.1 mafiapics.com
      Removed hosts entry: 127.0.0.1 www.malwarewipeupdate.com
      Removed hosts entry: 127.0.0.1 malwarewipeupdate.com
      Removed hosts entry: 127.0.0.1 massearch.com
      Removed hosts entry: 127.0.0.1 matureporngate.com
      Removed hosts entry: 127.0.0.1 www.maturepornmag.com
      Removed hosts entry: 127.0.0.1 maturepornmag.com
      Removed hosts entry: 127.0.0.1 www.maturespornmag.com
      Removed hosts entry: 127.0.0.1 maturespornmag.com
      Removed hosts entry: 127.0.0.1 www.mcafee-antivirus-2007.com
      Removed hosts entry: 127.0.0.1 mcafee-antivirus-2007.com
      Removed hosts entry: 127.0.0.1 www.medcodec.com
      Removed hosts entry: 127.0.0.1 medcodec.com
      Removed hosts entry: 127.0.0.1 www.media-codec.com
      Removed hosts entry: 127.0.0.1 media-codec.com
      Removed hosts entry: 127.0.0.1 www.mediacodec.net
      Removed hosts entry: 127.0.0.1 mediacodec.net
      Removed hosts entry: 127.0.0.1 www.media-codec.net
      Removed hosts entry: 127.0.0.1 media-codec.net
      Removed hosts entry: 127.0.0.1 www.mediacodec2007.com
      Removed hosts entry: 127.0.0.1 mediacodec2007.com
      Removed hosts entry: 127.0.0.1 www.mediaplayer-download.org
      Removed hosts entry: 127.0.0.1 mediaplayer-download.org
      Removed hosts entry: 127.0.0.1 www.mediaplayer-download-now.com
      Removed hosts entry: 127.0.0.1 mediaplayer-download-now.com
      Removed hosts entry: 127.0.0.1 www.mega-codec.com
      Removed hosts entry: 127.0.0.1 mega-codec.com
      Removed hosts entry: 127.0.0.1 www.mega-codec.net
      Removed hosts entry: 127.0.0.1 mega-codec.net
      Removed hosts entry: 127.0.0.1 www.mega-downloads.net
      Removed hosts entry: 127.0.0.1 mega-downloads.net
      Removed hosts entry: 127.0.0.1 megapornix.com
      Removed hosts entry: 127.0.0.1 www.megasearchbar.com
      Removed hosts entry: 127.0.0.1 megasearchbar.com
      Removed hosts entry: 127.0.0.1 www.megaviruskit.com
      Removed hosts entry: 127.0.0.1 megaviruskit.com
      Removed hosts entry: 127.0.0.1 www.megcodec.com
      Removed hosts entry: 127.0.0.1 megcodec.com
      Removed hosts entry: 127.0.0.1 meta-porn.com
      Removed hosts entry: 127.0.0.1 www.mezzicodec.net
      Removed hosts entry: 127.0.0.1 mezzicodec.net
      Removed hosts entry: 127.0.0.1 miconsultamedica.com
      Removed hosts entry: 127.0.0.1 www.microantivirus.com
      Removed hosts entry: 127.0.0.1 microantivirus.com
      Removed hosts entry: 127.0.0.1 www.microantivirusxp.com
      Removed hosts entry: 127.0.0.1 microantivirusxp.com
      Removed hosts entry: 127.0.0.1 www.micro-codec.com
      Removed hosts entry: 127.0.0.1 micro-codec.com
      Removed hosts entry: 127.0.0.1 www.microsoftantispyware.net
      Removed hosts entry: 127.0.0.1 microsoftantispyware.net
      Removed hosts entry: 127.0.0.1 militarygods.porn4porn.net
      Removed hosts entry: 127.0.0.1 www.miosearch.com
      Removed hosts entry: 127.0.0.1 miosearch.com
      Removed hosts entry: 127.0.0.1 www.mirarsearch.com
      Removed hosts entry: 127.0.0.1 mirarsearch.com
      Removed hosts entry: 127.0.0.1 www.mircosoftantispy.com
      Removed hosts entry: 127.0.0.1 mircosoftantispy.com
      Removed hosts entry: 127.0.0.1 www.mixsearch.com
      Removed hosts entry: 127.0.0.1 mixsearch.com
      Removed hosts entry: 127.0.0.1 www.mmcodec.com
      Removed hosts entry: 127.0.0.1 mmcodec.com
      Removed hosts entry: 127.0.0.1 www.mmcodecs.com
      Removed hosts entry: 127.0.0.1 mmcodecs.com
      Removed hosts entry: 127.0.0.1 moneyhunters.com
      Removed hosts entry: 127.0.0.1 www.mooncodec.com
      Removed hosts entry: 127.0.0.1 mooncodec.com
      Removed hosts entry: 127.0.0.1 www.mooncodec.net
      Removed hosts entry: 127.0.0.1 mooncodec.net
      Removed hosts entry: 127.0.0.1 www.morpheus.click-new-download.com
      Removed hosts entry: 127.0.0.1 morpheus.click-new-download.com
      Removed hosts entry: 127.0.0.1 www.motioncodecs.com
      Removed hosts entry: 127.0.0.1 motioncodecs.com
      Removed hosts entry: 127.0.0.1 www.moviecodec.net
      Removed hosts entry: 127.0.0.1 moviecodec.net
      Removed hosts entry: 127.0.0.1 www.moviecodecs.net
      Removed hosts entry: 127.0.0.1 moviecodecs.net
      Removed hosts entry: 127.0.0.1 www.moviedownloadreview.biz
      Removed hosts entry: 127.0.0.1 moviedownloadreview.biz
      Removed hosts entry: 127.0.0.1 www.movies-codecs.com
      Removed hosts entry: 127.0.0.1 movies-codecs.com
      Removed hosts entry: 127.0.0.1 www.movscodec.com
      Removed hosts entry: 127.0.0.1 movscodec.com
      Removed hosts entry: 127.0.0.1 www.movupdate.com
      Removed hosts entry: 127.0.0.1 movupdate.com
      Removed hosts entry: 127.0.0.1 www.mp3downloadin.net
      Removed hosts entry: 127.0.0.1 mp3downloadin.net
      Removed hosts entry: 127.0.0.1 www.mp3downloadpro.com
      Removed hosts entry: 127.0.0.1 mp3downloadpro.com
      Removed hosts entry: 127.0.0.1 www.mp3downloadsnow.com
      Removed hosts entry: 127.0.0.1 mp3downloadsnow.com
      Removed hosts entry: 127.0.0.1 www.mpegcodec.net
      Removed hosts entry: 127.0.0.1 mpegcodec.net
      Removed hosts entry: 127.0.0.1 www.mpegupdate.com
      Removed hosts entry: 127.0.0.1 mpegupdate.com
      Removed hosts entry: 127.0.0.1 www.mpgcodec.net
      Removed hosts entry: 127.0.0.1 mpgcodec.net
      Removed hosts entry: 127.0.0.1 www.mrantispy.com
      Removed hosts entry: 127.0.0.1 mrantispy.com
      Removed hosts entry: 127.0.0.1 www.msantispy.com
      Removed hosts entry: 127.0.0.1 msantispy.com
      Removed hosts entry: 127.0.0.1 www.msupdate.net
      Removed hosts entry: 127.0.0.1 msupdate.net
      Removed hosts entry: 127.0.0.1 www.msupdater.net
      Removed hosts entry: 127.0.0.1 msupdater.net
      Removed hosts entry: 127.0.0.1 www.mt-download.com
      Removed hosts entry: 127.0.0.1 mt-download.com
      Removed hosts entry: 127.0.0.1 www.musicmatch.free-software-center.com
      Removed hosts entry: 127.0.0.1 musicmatch.free-software-center.com
      Removed hosts entry: 127.0.0.1 www.mybestsearch2007.com
      Removed hosts entry: 127.0.0.1 mybestsearch2007.com
      Removed hosts entry: 127.0.0.1 www.myeasymp3downloadsnow.com
      Removed hosts entry: 127.0.0.1 myeasymp3downloadsnow.com
      Removed hosts entry: 127.0.0.1 www.mymysticporn.com
      Removed hosts entry: 127.0.0.1 mymysticporn.com
      Removed hosts entry: 127.0.0.1 www.mypornmagpass.com
      Removed hosts entry: 127.0.0.1 mypornmagpass.com
      Removed hosts entry: 127.0.0.1 www.mypspdownloading.com
      Removed hosts entry: 127.0.0.1 mypspdownloading.com
      Removed hosts entry: 127.0.0.1 www.mysoftwareprovider.com
      Removed hosts entry: 127.0.0.1 mysoftwareprovider.com
      Removed hosts entry: 127.0.0.1 www.my-software-
      0
  • 1
  • 2
  • 3
  • 4