Impossible de télécharger Acrobat Reader

Bonjour à tous,

J'ai Windows XP Pro Version 2002 Service Pack 3. Après une attaque de Zlob bien nettoyée, mon Acrobat Reader 8.1.2 s'est mis à mal fonctionner. Résultat des courses, je ne peux plus lire des fichiers PDF ou regarder aucune vidéo sur YouTube car je ne peux pas télécharger Flash Player correctement. J'ai essayé plusieurs fois d'en télécharger la dernière version (Flash Player 9), le site me dit que c'est bien téléchargé mais l'icône Adobe Flash Player Plugin qui figure sur la liste de programmes de mon Panneau de Configuration affiche un petit X rouge sur un coin et aucune taille en Mo...

Pour continuer, j'ai consulté des forums qui conseillaient de désinstaller Acrobat et de le re-télécharger après. Comme un bon soldat j'ai donc désinstallé Acrobat de mon ordi et maintenant je ne peux plus le télécharger de nulle part!!! A chaque fois que j'essaie de le faire j'ai un message d'erreur bizarroïde qui me dit que mon ordinateur est sous une version Windows 2000 (!!??) et qu'il faut que j'upgrade mon ordi à Windows 2000 SP 4 (!!??) pour pouvoir télécharger Adobe Reader 8.1.2. Je ne comprends fichtre rien à cette histoire et voudrait savoir si qqn. pouvait m'aider...

Pour la petite histoire, j'ai téléchargé Foxit Reader pour pouvoir lire des fichiers en PDF, j'ai quand même pu télécharger Adobe Air et Adobe Media Player (ce qui n'a pas résolu mon problème de lecture de vidéos sur YouTube!!). Et au cas où qqn pense me poser la question, j'ai Java correctement installé sur mon ordi (même que j'ai la dernière mise à jour!!, oui m'sieur!)

Alors... AU SECOUUUUUUURS!!!!!!!

ET MERCI D'AVANCE!

CP12
Configuration: Windows XP
Internet Explorer 7.0

74 réponses

Résumé de la discussion

Le problème survient après le nettoyage d’une infection Zlob: Acrobat Reader 8.1.2 ne lit plus les PDFs et les vidéos ne se lisent pas, Flash Player échoue à s’installer et Windows peut afficher une erreur indiquant Windows 2000 lors des tentatives de réinstallation. Les conseils préconisent d’abord de supprimer les composants malveillants (notamment Zango), puis d’utiliser SDFix en mode sans échec, d’exécuter HijackThis et d’effectuer un nettoyage complet avec CCleaner. Des instructions détaillent la fermeture de processus nuisibles, la suppression de fichiers et clés de registre problématiques, la vérification des éléments de démarrage et la correction d’entrées spécifiques dans le navigateur et le fichier Hosts. Des vérifications complémentaires ciblent des infections persistantes (W32/Zlob.BWLZ et Renos.XS), la vérification d’un fichier lié à Kaspersky, la restauration et la création d’un nouveau point de restauration, ainsi que l’utilisation d’outils comme SmitfraudFix pour un nettoyage final.

Bobot (l’IA à votre service)
  1. Salut,
    Une version Windows 2000 (!!??) et qu'il faut que j'upgrade mon ordi à Windows 2000 SP 4
    Le sp4 pour windows 2000 est presque obligatoire on peu rien faire sans. Il suffit de retrouver se sp4 pour windows 2OOO. Par contre, je sais pas si il est en update direct vu que c 'est vieux et quand general les personnes l ont directement stocker sur le disque dur.
    Pour acrobat ils doivent surement etre en maintenance securite. Il avait des problemes et on fermer certain telechargement. Il son aussi entrain de sortir de nouveau produits online.
    0
    1. Merci de ton conseil Rebitus!

      Je vais aller piocher dans le site Windows Update voir ce que je peux trouver sur W 2000 SP4 et je te tiens au courant si ça me permet de télécharger Acrobat.

      (J'espère que l'impossibilité de télécharger la dernière version de ce logiciel est dûe à ce que tu dis à propos de leur site)

      A+

      Catpeople12
      0
    2. Salut Rebitus et tous ceux qui pourraient m'aider!

      J'ai trouvé Windows 2000 SP4 sur le site Windows Update grâce aux conseils de Rebitus, que je remercie.

      J'ai commencé à le télécharger mais avant la fin du téléchargement le message d'erreur suivant est apparu:

      Le programme d'installation n'a pas pu vérifier l'integrité du fichier Update.inf. Assurez-vous que le service de cryptographie est en cours d'exécution sur cet ordinateur.

      Je suis donc allé vérifier dans le Panneau de Configuration / Outils d'administration / Services / Services de cryptographie et les propriétés indiquent que c'est Démarré de manière Automatique

      J'ai donc un problème! Hein?

      Mais je ne sais ni ce que c'est ni comment le résoudre!!!.....

      HEEEEELP!!!!!
      0
  2. Re-salut à tous,

    Je viens également de me rendre compte que je ne peux même pas télécharger Adobe Flash Player. Le site Adobe me dit toujours que le téléchargement a été effectué mais le logiciel n'est nulle part sur mon ordi.

    Il n'y a que Java qui y est et qui fonctionne parfaitement.

    Alors, soit le site Adobe a des problèmes, soit mon ordi a un problème que je n'arrive pas à déceler! Pourtant les services de cryptographie de l'ordi sont activés, la navigation sur Internet et tous les affichages sur mon ordi marchent très rapidement comme d'habitude...

    N'étant pas un pro de l'informatique, j'ai vraiment besoin de l'aide de quelqu'un qui s'y connaît...

    Merci d'avance à tous!

    Catpeople12
    0
    1. Salut à tous,

      Je crois savoir pourquoi je ne peux pas télécharguer Adobe. C'est que mon ordi n'a apparement plus le SP4 pour Windows 2000. Je suis allé le chercher sur Internet et le téléchargement a bien commencé. Mais au moment de l'installation j'ai eu le message d'erreur suivant:

      "Le programme d'installation n'a pas pu vérifier l'intégrité du fichier Update.inf. Assurezvous que le service de cryptographie est en cours d'exécution sur cet ordinateur."

      Selon les instructions données sur ce forum à ceux qui ont le même problème, je suis allé sur le Panneau de Configuration => Outils d'administration=> Services=>Services de cryptographie, j'ai cherché les propriétés du service et il est activé en mode automatique. J'ai quand même redémarré le service et rebooté l'ordi. Mais après une nouvelle tentative de téléchargement du SP4 pour Win 2000 le même message est encore apparu ! Je ne comprends pas ce qui se passe...

      Est-ce que quelqu'un pourrait me conseiller pour résoudre ce problème, SVP?

      Merci!

      CP12
      0
      1. Bonjour a vous tous,
        une question catpeople12,

        tu dis que t'es equipé avec xp pro sp3, je vois pas pourquoi tu passes sur xin 2000 + sp4 etc..
        merci confirmer quelle version exacte t'as sur ta machine, je vais essayer de te trouver une solution
        a+
        BOB3
        0
        1. Salut BOB3 et merci de ta réponse.

          Je suis sous Windows XP Pro Version 2002 Service Pack 3. J'essaie de télécharger Win 2000 SP4 juste parce qu'à chaque fois que j'ai essayé de télécharger la dernière version d'Acrobat un message du genre "la versoin 2000 sous laquelle vous êtes ne accepte pas ce fichier. Mettez-la à jour avec Windows 2000 sp4 avant de le télécharger".

          Je pensais que Win 2000 SP4 était un composant nécessaire à mon système qui me permettrait de télécharger la dernière version d'Acrobat. Qu'en penses-tu?

          Par la même occas, je n'arrive même pas à télécharger la dernière version d'Acrobat Flash Player sur mon système, ce qui m'empêche de regarder des vidéos sur YouTube.

          Ce serait sympa si tu me trouvais une solution!

          MERCI et à bientôt!

          catpeople12
          0
          1. Re catpeople12,

            oubli win2000,

            redemarres en mode sans echec et essayes de desinstaller completement ADOBE--tu le reinstalles apres.

            tu va verifier apres l'integrité de tes fichiers xp
            tu mets ton cd d'installation dans le lecteur cd principal
            tu clic sur demarrer, executer, et tu tapes : sfc /scannow
            regarde le lien
            https://www.pcastuces.com/pratique/windows/xp/default.htm
            et tu laisses faire,
            tu redemarres,
            ensuite tu va lancer Microsoft onecare sur ce lien
            https://www.msn.com/fr-fr/
            tu lances le lien, tu acceptes les activx, et tu clic sur analyse complete.
            ca va prendre tu temps, windows va tout nettoyer et retablir ta base de registre.
            tu laisse terminer, tu reboot, et tu nous tiens au courant.
            a+
            BOB3
            0
            1. Salut BOB3!

              Je vais suivre tes indications et je te tiendrai au courant dès que j'ai fini.

              MERCI BEAUCOUP!!

              A+

              catpeople12
              0
            2. Re BOB3,

              La première partie de tes indications a marché du Tonnerre (Merci!)! J'avais en effet des fichiers .dll endommagés à cause d'un cheval de Troie (Zlob) que j'ai choppé il y a une semaine (malgré mon Kaspersky) et que j'ai pu supprimer en suivant des recommendations sur ce Forum. Alors tous les fichiers protégés endommagés ont été réparés ou restaurés avec mon CDROM XP. J'ai aussi complètement supprimé Adobe de mon ordi. Je t'en dois une fière chandelle!

              En revanche, il se passe un truc bizarre avec le second lien pour Windows Onecare que tu m'as donné. Quand je clique sur Analyse complète pour que le scanner se mette en route, la fenêtre de dialogue qui indique le statut de l'analyse s'affiche. Mais il s'affiché quelques secondes après une petite fenêtre de dialogue dans celle de Onecare qui me dit qu'il y a eu une erreur de script sur la page avec Explorer et si je veux quand même continuer. J'appuie sur Oui et la fenêtre W. Onecare devient comme un cadre avec juste les bordures et ne veut plus se fermer; je ne peux que la réduire... Pour qu'elle disparaisse je suis obligé de redémarrer l'ordi. Je me reconnecte sur Onecare, j'essaie à nouveau et la même chose arrive... Je n'ai aucun indice qu'il se passe quelque chose...

              Ne connaissant pas bien W. Onecare, pourrais-tu me dire si c'est normal? Je pense qu'il doit y avoir un schmol, mais je ne suis pas un crack en informatique...

              Dans l'attente de tes conseils et te remerciant encore de ton aide, je te salue bien cordialement.

              catpeople12
              0
          2. Bonne soiree catpeople12,

            content pour toi que t'as pu reparer tes fichiers systeme,
            l'erreur du script c'est relatif a ton navigateur IE7, j'espere qu'il n'est pas endommagé.
            ouvre proprieté internet explorer,
            1--dans genetal, puis les 2 parametres recherches+onglets, clic sur parametres et mets par defaut.
            2--dans securité, tu mets tout par defaut
            3--dans confidentialite, mets le par defaut pour acceptes les cookies microsoft en auto-----je te conseilles par la suite de le mettre sur Haute
            4--dans avancés tu clic sur Rétablir les paramètres avancés --- uniquement.

            et tu essayes de te connecté a nouveau sur oncare.
            a+
            BOB3
            0
            1. Bonjour BOB3,

              Merci encore de tes bons conseils!!!

              J'ai suivi tes indications concernant IE7 et la même chose est arrivée quand j'ai essayé de télécharger le scanner onecare pou démarrer l'analye complète... Une erreur de script s'est produite et après, ça s'est mis à mouliner sans aucune réaction. J'ai donc dû désactiver la page avec le gestionnaire des tâches.... Pourtant j'ai mis onecare comme site de confiance dans IE7 et Kaspersky...

              Peut-être que IE7 est endommagé comme tu penses et je ne sais pas comment faire pour le réparer si c'est le cas...

              Pourrais-tu encore m'aider, STP?

              Merci!

              catpeople12
              0
          3. Bonjour catpeople12,

            telecharge a nouveau IE7, installes le + mise a jour sans oublier de reparametrer comme preciser en 11

            http://www.microsoft.com/downloads/details.aspx?FamilyId=9AE91EBE-3385-447C-8A30-081805B2F90B&displaylang=fr

            tu va sur onecare a nouveau, et tu refaits une verif complete.
            tiens moi au courant.
            BOB3
            0
            1. Bonsoir BOB3,

              Bon! Au rapport... J'ai téléchargé à nouveau IE7 et tout s'est bien passé. Tous ses paramètres sont également par défaut conforme à tes conseils. (De toute façon avec le téléchargement tout vient par défaut)

              Cependant, le problème avec Onecare persiste malgré tout... Toujours la bonne vieille erreur de script sur la page qui me bloque tout et qui m'empêche de faire l'analyse complète... Je ne sais plus quoi faire!... Je vais finir par croire que ce site n'aime pas mon ordi, même si mon ordi lui fait confiance...

              Aurais-tu une autre idée sous la manche?...

              Je te remercie une fois de plus de ton aide et te salue bien cordialement,

              catpeople12
              0
          4. Bonne soiree catpeople,

            va dans panneau de configuration, clic sur java, mets le a jour,
            toujours sur java, tu desactive la mise ajour auto, et dans Avancé,
            puis, java par defaut des navigateur, tu mets sur Intenet explorer.
            tu reboot, et dans propriete internet explorer, tu ouvres Avancés, tu defiles,
            sous Navigation, tu coches sur les deux case ----desactiver le debogage de script
            on verra bien.
            a+
            BOB3
            0
            1. Bonjour BOB3

              Je suis allé sur Java. J'ai cliqué sur mettre à jour maintenant mais il me dit que j'ai la toute dernière version Java d'installée dans mon ordinateur qui est en fonction. J'ai desactivé la mise à jour auto mais Internet Explorer était déjà coché comme navigateur par défaut sur Java.

              Ensuite j'ai rebooté et suis allé voir dans les propriétés internet/avancé/Navigation. Les deux cases de débogage de scripts étaient déjà cochées.

              Je retente le coup avec Onecare et te tiens au courant.

              MERCI encore!

              catpeople12
              0
            2. Re BOB3!

              Eh ben, après exécution des indications pour Java et IE, ça ne marché toujours pas... Il y a encore cette satanée erreur de script sur la page et je suis obligé de la fermer avec le Gestionnaire de Tâches...

              C'est dingue!!!!! ... ...

              Dans l'attente de tes conseils, je te remercie encore et te salue bien Cordialement,

              catpeople12
              0
          5. Salut catpeople,
            repostes le message exact que le system te donnes lorsque t'es sur one care.
            a+
            BOB3
            0
            1. Salut BOB3!

              Voici le message exact:

              !
              Une erreur est survenue dans le script de cette page
              Ligne: 26
              Caractère : 1
              Erreur : Objet attendu
              Code : 0
              URL : about: blank

              Voulez-vous continuer à exécuter les scripts de cette page?

              Oui Non


              Que j'appuie sur Oui ou Non ne change rien; ça mouline et je n'ai plus rien...

              J'espère que ceci va t'aider à savoir d'où ça vient.

              Merci encore et

              A+

              catpeople12
              0
          6. Re catpeople,
            telecharge Hijackthis sur ce lien, installes le en mode auto,
            ftp://ftp.commentcamarche.com/download/HJTInstall.exe

            clic sur son icone sur le bureau, et fait: Do a systel scan and save logfile
            copier / coller sur le post
            a+
            BOB3
            0
            1. Salut BOB3,

              Voici le résultat du scan:

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 08:58:44, on 07/07/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16674)
              Boot mode: Normal

              Running processes:
              C:\windows\System32\smss.exe
              C:\windows\system32\winlogon.exe
              C:\windows\system32\services.exe
              C:\windows\system32\lsass.exe
              C:\windows\System32\Ati2evxx.exe
              C:\windows\system32\svchost.exe
              C:\windows\System32\svchost.exe
              C:\windows\system32\Ati2evxx.exe
              C:\WINDOWS\System32\brsvc01a.exe
              C:\windows\Explorer.EXE
              C:\WINDOWS\System32\brss01a.exe
              C:\windows\system32\spoolsv.exe
              C:\windows\SOUNDMAN.EXE
              C:\Program Files\VIA\RAID\raid_tool.exe
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\Logitech\Video\LogiTray.exe
              C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
              C:\Program Files\Windows Media Player\WMPNSCFG.exe
              C:\Program Files\yodm 3D\Yodm3D.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\PROGRA~1\MI3AA1~1\wcescomm.exe
              C:\windows\system32\ctfmon.exe
              C:\PROGRA~1\MI3AA1~1\rapimgr.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\windows\system32\cisvc.exe
              C:\windows\System32\svchost.exe
              C:\WINDOWS\system32\LVComS.exe
              C:\WINDOWS\system32\inetsrv\inetinfo.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              C:\WINDOWS\system32\PSIService.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
              C:\windows\system32\svchost.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              C:\windows\system32\cidaemon.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: (no name) - {9989F1F6-70DE-4244-AC9F-6672983681A0} - (no file)
              O2 - BHO: (no name) - {A49E097A-D6EF-4B2F-8B0F-1230E998587F} - C:\Program Files\Web Technologies\iebt.dll (file missing)
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: 238044 helper - {C0F371D7-926D-4700-B65E-63BFF1197205} - C:\WINDOWS\system32\238044\238044.dll (file missing)
              O3 - Toolbar: Internet Service - {F99D0C20-F8E1-43B6-AB24-3F16BFAEA77B} - C:\Program Files\Web Technologies\iebr.dll (file missing)
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
              O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [Yodm3D] C:\Program Files\yodm 3D\Yodm3D.exe
              O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
              O4 - HKCU\..\Run: [I&F Viewer toolbar] "C:\Program Files\Photo Toolkit\ivbar\phototoolkitmem.exe" -start
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
              O4 - Startup: MyTrashCan.lnk = C:\Program Files\Hiro's tool\MyTrashCan\MyTrashCan.exe
              O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
              O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
              O15 - Trusted Zone: http://www.1001interims.com
              O15 - Trusted Zone: https://www.adobe.com/
              O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
              O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
              O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
              O15 - Trusted Zone: https://www.ustart.org
              O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
              O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
              O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
              O15 - Trusted Zone: https://www.msn.com/fr-fr/
              O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
              O15 - Trusted Zone: https://fr.yahoo.com/
              O15 - Trusted Zone: https://www.youtube.com/
              O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
              O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
              O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.serviceshub.microsoft.com/supportforbusiness/create
              O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPUpld.cab
              O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-e84a02c34e2ab3f9.spaces.live.com/PhotoUpload/MsnPUpld.cab
              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
              O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?e=1214407856230&h=460b6a4386982a6d227dd6ec47e07839/&filename=jinstall-6u6-windows-i586-jc.cab
              O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
              O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
              O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
              O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: MicroSoft Media Tools - Unknown owner - C:\WINDOWS\MSmedia.exe (file missing)
              O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
              O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
              0
          7. Bonjour catpeople12,
            Pas mal de problemes a regler

            tu telecharge Ccleaner, tu l'installes sans la barre YAHOO
            dans applications tu coches tout
            tu le lances et tu fait un nettoyage complet: nettoyeur puis registre

            1---pour commencer, tu va desinstallé afin de regler un desordre dans la base de registre
            windows live messenger, tu le reinstalles plus tard sans les sponsors de pub.
            windows live onecare
            logitech webcam---tu la reistalles plus tard

            2--tu a un service proxy qu'il faut desactiver
            dans prpriete internet explorer, puis connexions, parametres reseau, et tu desactive tout

            3--tu va dans demarrer, panneau de configuration, options regionales et linguistiques, langues, details, avancé,
            et tu coches arreter les services de textes avances.

            4--tu lance msconfig.exe, puis demarrage, et s'il existe, du desactives
            ctfmon.exe
            LVComS.exe

            tu redemarres ton ordi mode sans echec,
            tu lance Hijackthis en mode Do a system Scan
            tu coches les clefs suivantes, puis tu clic en bas a gauche sur: Fix Checked
            C:\WINDOWS\system32\LVComS.exe

            O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

            O2 - BHO: (no name) - {9989F1F6-70DE-4244-AC9F-6672983681A0} - (no file)

            O2 - BHO: (no name) - {A49E097A-D6EF-4B2F-8B0F-1230E998587F} - C:\Program Files\Web Technologies\iebt.dll (file missing)
            O2 - BHO: 238044 helper - {C0F371D7-926D-4700-B65E-63BFF1197205} - C:\WINDOWS\system32\238044\238044.dll (file missing)
            O3 - Toolbar: Internet Service - {F99D0C20-F8E1-43B6-AB24-3F16BFAEA77B} - C:\Program Files\Web Technologies\iebr.dll (file missing)

            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE

            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe

            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

            O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [Yodm3D] C:\Program Files\yodm 3D\Yodm3D.exe
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
            O4 - Startup: MyTrashCan.lnk = C:\Program Files\Hiro's tool\MyTrashCan\MyTrashCan.exe
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

            O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
            O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.serviceshub.microsoft.com/supportforbusiness/create
            O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPUpld.cab
            O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
            O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-e84a02c34e2ab3f9.spaces.live.com/PhotoUpload/MsnPUpld.cab
            O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/
            O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
            O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
            O23 - Service: MicroSoft Media Tools - Unknown owner - C:\WINDOWS\MSmedia.exe (file missing)
            O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)

            Tu lance Ccleaner, tu fait un nettoyage complet

            tu reboot en mode normal, et tu remets un nouveau log Hijackthis.
            a+
            BOB3
            0
            1. Re-BOB3 et MERCI encore de ton aide!

              J'ai suivi tes instructions à la lettre. Avant de te soumettre le nouveau log Hijackthis, et au cas où ça pourrait être important, je t'informe qu'après le System Scan de Hijackthis en Mode Sans Echec il manquait les clefs suivantes sur la liste, qui apparaissaient sur celle que tu m'as donné à cocher au préalable:

              C:\WINDOWS\system32\LVComS.exe
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab

              Une fois les clefs trouvées cochées, j'ai lancé Fix Checked et pendant le processus le message suivant est apparu:

              Impossible to repair 010 Winsock LSP entries
              Use LSP Fix, which can be downloaded at http://www.cexx.org/lspfix.htm

              If the 010 item belongs to WebHancer, New.Net or Common/Name, Spybot S&D can remove it automatically.


              J'ai donc profité pour lancer un balayage avec Spybot et aucun mouchard n'a été trouvé.

              J'ai rebooté l'ordi et immédiatement j'ai eu une mise à jour de sécurité Windows (KP950759) pour IE7.

              Et voici maintenant le nouveau log Hijackthis:

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 12:56:38, on 07/07/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16674)
              Boot mode: Normal

              Running processes:
              C:\windows\System32\smss.exe
              C:\windows\system32\winlogon.exe
              C:\windows\system32\services.exe
              C:\windows\system32\lsass.exe
              C:\windows\System32\Ati2evxx.exe
              C:\windows\system32\svchost.exe
              C:\windows\System32\svchost.exe
              C:\WINDOWS\System32\brsvc01a.exe
              C:\WINDOWS\System32\brss01a.exe
              C:\windows\system32\spoolsv.exe
              C:\windows\system32\Ati2evxx.exe
              C:\windows\Explorer.EXE
              C:\Program Files\VIA\RAID\raid_tool.exe
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
              C:\Program Files\Windows Media Player\WMPNSCFG.exe
              C:\PROGRA~1\MI3AA1~1\wcescomm.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
              C:\PROGRA~1\MI3AA1~1\rapimgr.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\windows\system32\cisvc.exe
              C:\windows\System32\svchost.exe
              C:\WINDOWS\system32\inetsrv\inetinfo.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              C:\WINDOWS\system32\msiexec.exe
              C:\WINDOWS\system32\PSIService.exe
              C:\windows\system32\svchost.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\windows\system32\wuauclt.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
              O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
              O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
              O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
              O15 - Trusted Zone: http://www.1001interims.com
              O15 - Trusted Zone: https://www.adobe.com/
              O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
              O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
              O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
              O15 - Trusted Zone: https://www.ustart.org
              O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
              O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
              O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
              O15 - Trusted Zone: https://www.msn.com/fr-fr/
              O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
              O15 - Trusted Zone: https://fr.yahoo.com/
              O15 - Trusted Zone: https://www.youtube.com/
              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
              O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
              O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
              O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
              0
          8. Re catpeople12,

            on avance,
            1--une question a confirmer,
            si j'ai bien compris t'as bien supprimé
            --->C:\WINDOWS\system32\LVComS.exe
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab

            sinon, tu les fix avec Hijackthis en mode normal.

            tu telecharge LSP Fix sur ce lien developpé par (IUP / Indiana University of Pensylvania)
            http://old.www.iup.edu/house/resnet/WinsockXPFix.exe

            MAIS TU NE FAIT RIEN POUR LE MOMENT.
            en attente reponse, je decortique ton log
            a+
            BOB3
            0
            1. Re, BOB3!

              Je suis super content que ça avance!!

              Ton aide m'est vraiment précieuse ( même si 90% du temps je ne comprends pas trop ce que je suis en train de faire... ) et je continuerai à suivre tes indications à la lettre.

              Quant à la question que tu souhaitais confirmer:

              Je n'ai pas supprimé les clefs que je t'ai énumérées et que tu mets dans ta question.
              Elles ne figuraient tout simplement pas sur la liste de clefs qui s'est affichée après le scan the Hijackthis en mode sans échec...

              Est-ce grave?

              Je télécharge LSP Fix et j'attends tes consignes.

              A+

              catpeople12
              0
          9. Re catpeople12,

            1---a varifier, dans le log je remarque que ton antivirus Kaspersky se lance a 3 reprises
            regarde la liste des services au debut
            a partir de
            Boot mode: Normal ---->jusqu'a c:\program files\trend micro\hijackthis\hijackthis.exe

            2--tu vas dans c:\windows\Downloaded Program Files--->et tu supprimes tout les activex installés
            clic droit, puis supprimé
            a fure et mesure, tu acceptes a nouveau les activx de windows a nouveau

            3---il faut faire la meme manip avec HJT, et faire un Fix checked sur les clefs suivantes
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
            O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
            O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
            O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
            O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

            tu passe un coup de Ccleaner, tu reboot et tu remets un nouveau log.
            a+
            BOB3
            0
            1. Re, BOB3!

              Je viens d'enregistrer LSP Fix sur mon bureau en attendant tes instructions.

              Question importante avant de continuer:

              La suppression des activex dans c:\windows\Downloaded Program Files et la seconde manip avec HJT avec la réparation des clefs, je la fais en Mode sans échec ou tout de suite en mode normal?

              A toi, chef!

              Cordialement,

              catpeople12
              0
            2. Re, BOB3,

              Tu as raison! Kaspersky se lance à 3 reprises selon le log 2 de HJT...
              Y a-t-il une manip à faire pour résoudre ça si c'est anormal?

              J'attends tes instructions pour supprimer les activex dans C:\Windows\Downloaded Program Files, puis pour lancer HJT à nouveau et faire réparer les clefs que tu as identifiées, soit en mode sans échec, soit en mode normal.

              Dans quel mode j'effectue les deux actions STP?

              MERCI!

              A+

              catpeople12
              0
          10. Re catepeople,

            1--activex en mode normal
            2--pour le Fix, tu faits en mode normal, si traces restantes, en mode sans echec.

            je te mets d'autres manip a faire, prend ton temps, et procede avec prudence.
            a+
            BOB3
            0
            1. Re BOB3,

              Rapport jusqu'au message 28:

              Log HJT 2:


              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 12:56:38, on 07/07/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16674)
              Boot mode: Normal

              Running processes:
              C:\windows\System32\smss.exe
              C:\windows\system32\winlogon.exe
              C:\windows\system32\services.exe
              C:\windows\system32\lsass.exe
              C:\windows\System32\Ati2evxx.exe
              C:\windows\system32\svchost.exe
              C:\windows\System32\svchost.exe
              C:\WINDOWS\System32\brsvc01a.exe
              C:\WINDOWS\System32\brss01a.exe
              C:\windows\system32\spoolsv.exe
              C:\windows\system32\Ati2evxx.exe
              C:\windows\Explorer.EXE
              C:\Program Files\VIA\RAID\raid_tool.exe
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
              C:\Program Files\Windows Media Player\WMPNSCFG.exe
              C:\PROGRA~1\MI3AA1~1\wcescomm.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
              C:\PROGRA~1\MI3AA1~1\rapimgr.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\windows\system32\cisvc.exe
              C:\windows\System32\svchost.exe
              C:\WINDOWS\system32\inetsrv\inetinfo.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              C:\WINDOWS\system32\msiexec.exe
              C:\WINDOWS\system32\PSIService.exe
              C:\windows\system32\svchost.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\windows\system32\wuauclt.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
              O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
              O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
              O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra 'Tools' menuitem: Créer un favori mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
              O15 - Trusted Zone: http://www.1001interims.com
              O15 - Trusted Zone: https://www.adobe.com/
              O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
              O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
              O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
              O15 - Trusted Zone: https://www.ustart.org
              O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
              O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
              O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
              O15 - Trusted Zone: https://www.msn.com/fr-fr/
              O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
              O15 - Trusted Zone: https://fr.yahoo.com/
              O15 - Trusted Zone: https://www.youtube.com/
              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
              O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
              O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
              O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
              0
          11. Re catpeople12,

            traces de trojan a irradiquer

            1---Désinstalle le programme Zango par Ajout/Suppression de programmes (Si tu le trouves)

            2---Télécharge SDFix de AndyManchesta et sauvegarde le sur ton Bureau.
            http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

            Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau.
            Redémarre ton ordinateur en mode sans échec.

            Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
            Appuie sur Y pour commencer le processus de nettoyage.

            Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
            Appuie donc sur une touche.

            Ton système sera plus long pour redémarrer que d'habitude car l'outil va continuer à s'exécuter et supprimer des fichiers.

            Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
            Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.

            Une fois les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt. Il faudra coller ce rapport dans ta prochaine réponse.

            3-----Fais Ctrl + Alt + Suppr pour ouvrir le gestionnaire de tâches.
            Choisis l'onglet Processus
            Dans la colonne Nom de l'image, recherche si tu trouves
            le processus zango.exe
            Clique droit dessus et choisis Terminer le processus
            Recherche ensuite le processus mnew1winc4.exe
            Clique droit dessus et choisis Terminer le processus

            4-----Relance HijackThis et coche les lignes suivantes si tu les trouves

            O2 - BHO: Zango Search Assistant Helper /fleok=1D8A83A5C1E0197791AE75760EA83FA5EF80752B94E2DE7E5A7A47203BCF - {56F1D444-11BF-4879-A12B-79CF0177F038} - c:\program files\zango\zangohook.dll
            O4 - HKLM\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe
            O4 - HKLM\..\Run: [Memory manager] C:\WINDOWS\System32\himem32.exe
            O4 - HKLM\..\Run: [zango] "c:\program files\zango\zango.exe"
            O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\System32\rpcc.exe
            O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
            O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
            O4 - HKLM\..\RunServices: [Printer] C:\WINDOWS\System32\auditchk.exe
            O4 - HKCU\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe
            O4 - HKCU\..\Run: [dpr0] C:\WINDOWS\system32\prod.exe
            O4 - HKCU\..\Run: [chsr] C:\WINDOWS\system32\lssrvc.exe
            O4 - HKCU\..\Run: [mlrnew1c4] C:\WINDOWS\system32\mnew1winc4.exe
            O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
            O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
            O20 - Winlogon Notify: rpcc - C:\WINDOWS\System32\rpcc.dll (file missing)
            O20 - Winlogon Notify: rpccd - C:\WINDOWS\System32\rpccd.dll

            Clique sur Fix Checked et confirme le message qui suit.

            5----Avec l'explorateur Windows, recherche les fichiers/dossiers suivants et supprime les (si toujours présents):
            c:\program files\zango <-- Le dossier
            C:\WINDOWS\System32\auditchk.exe (Attention à l'orthographe)
            C:\WINDOWS\System32\himem32.exe (Là encore, attention à l'orthographe)
            C:\WINDOWS\System32\rpcc.exe
            C:\WINDOWS\system32\prod.exe
            C:\WINDOWS\system32\lssrvc.exe
            C:\WINDOWS\system32\mnew1winc4.exe
            C:\WINDOWS\System32\rpcc.dll
            C:\WINDOWS\System32\rpccd.dll

            6--lance Ccleaner, nettoyage, reboot, et tu postes le log Report.txt de Sdfix.
            a+
            BOB3
            0
            1. Salut BOB3!

              Pas de traces de zango nulle part; aucun processus dans le Gestionnaire de Tâches, aucune des clefs que tu m'as demandé de cocher ni aucun fichier recherché avec l'explorateur Windows n'a été trouvé... (COOL!)

              Pendant l'analyse de SDFix, le message suivant s'est affiché:

              Note: Protective Host Files such as MVPS/HP hosts or Spybot Immunizers must be applied after SDFix analysis

              J'ai Spybot S&D et il immunize le système. Dois(je le faire?

              Voici le rapport de SD Fix:

              [b]SDFix: Version 1.202 [/b]
              Run by Carlo on 07/07/2008 at 15:56

              Microsoft Windows XP [version 5.1.2600]
              Running From: C:\DOCUME~1\Carlo\Bureau\SDFix

              [b]Checking Services [/b]:

              [b]Name [/b]:
              MicroSoft Media Tools

              [b]Path [/b]:
              "C:\WINDOWS\MSmedia.exe"

              MicroSoft Media Tools - Deleted

              Restoring Default Security Values
              Restoring Default Hosts File

              Rebooting

              [b]Checking Files [/b]:

              Trojan Files Found:

              C:\Documents and Settings\Carlo\Mes documents\My Documents.url - Deleted
              C:\Documents and Settings\Carlo\Mes documents\CARLO\AUDIOVISUEL C & S\Notre Musique\My Music.url - Deleted
              C:\Documents and Settings\Carlo\Mes documents\AUDIOVISUEL C & S\Nos vid‚os\My Video.url - Deleted
              C:\windows\system32\TFTP1684 - Deleted
              C:\windows\system32\TFTP2892 - Deleted
              C:\Program Files\Setup.exe - Deleted
              C:\tmp.reg - Deleted

              Removing Temp Files

              [b]ADS Check [/b]:

              [b]Final Check [/b]:

              catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2008-07-07 16:04:47
              Windows 5.1.2600 Service Pack 3 NTFS

              scanning hidden processes ...

              scanning hidden services & system hive ...

              scanning hidden registry entries ...

              scanning hidden files ...

              scan completed successfully
              hidden processes: 0
              hidden services: 0
              hidden files: 0

              [b]Remaining Services [/b]:

              Authorized Application Key Export:

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
              "c:\\irpll7l.exe"="C:\\irpll7l.exe:*:Enabled:Server"
              "Windows Firewall Monitor"="C:\\dinst.exe:*:enabled:svchost"
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
              "C:\\Program Files\\eChanblard\\emule.exe"="C:\\Program Files\\eChanblard\\emule.exe:*:Enabled:eMule"
              "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.6\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.6\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
              "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.5\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.5\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
              "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.4\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.4\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
              "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.3\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.3\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
              "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.2\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.2\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
              "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\Fp2006.exe:*:Disabled:Spy Shooter 2006"
              "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\FlowService.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\FlowService.exe:*:Disabled:Spy Shooter 2006"
              "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\Fp2006.exe:*:Disabled:SpyShooter2006"
              "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\FlowService.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\FlowService.exe:*:Disabled:SpyShooter2006"
              "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\Fp2006.exe:*:Disabled:Spy Shooter 2006"
              "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\FlowService.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\FlowService.exe:*:Disabled:Spy Shooter 2006"
              "C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"="C:\\Program Files\\VideoLAN\\VLC\\vlc.exe:*:Enabled:VLC media player"
              "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
              "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
              "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
              "C:\\Program Files\\messenger\\msmsgs.exe"="C:\\Program Files\\messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
              "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
              "C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019"

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
              "c:\\irpll7l.exe"="C:\\irpll7l.exe:*:Enabled:Server"
              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
              "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
              "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
              "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
              "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

              [b]Remaining Files [/b]:

              File Backups: - C:\DOCUME~1\Carlo\Bureau\SDFix\backups\backups.zip

              [b]Files with Hidden Attributes [/b]:

              Sat 21 Jun 2008 212 A.SH. --- "C:\BOOT.BAK"
              Fri 13 May 2005 217,073 A.SHR --- "C:\WINDOWS\meta4.exe"
              Mon 24 Oct 2005 66,560 A.SHR --- "C:\WINDOWS\MOTA113.exe"
              Thu 13 Oct 2005 422,400 A.SHR --- "C:\WINDOWS\x2.64.exe"
              Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
              Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
              Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
              Tue 17 Apr 2007 168 ..SHR --- "C:\WINDOWS\system32\0E3DD7342B.sys"
              Fri 28 Oct 2005 308,224 A.SH. --- "C:\WINDOWS\system32\avisynth.dll"
              Thu 14 Jul 2005 27,648 A.SHR --- "C:\WINDOWS\system32\AVSredirect.dll"
              Sun 26 Jun 2005 616,448 A.SHR --- "C:\WINDOWS\system32\cygwin1.dll"
              Tue 21 Jun 2005 45,568 A.SHR --- "C:\WINDOWS\system32\cygz.dll"
              Sun 25 Jan 2004 70,656 A.SHR --- "C:\WINDOWS\system32\i420vfw.dll"
              Tue 17 Apr 2007 2,516 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
              Sun 21 Jan 2001 63,488 A..H. --- "C:\WINDOWS\system32\MMRegOCX.exe"
              Thu 27 Apr 2006 2,945,024 A.SHR --- "C:\WINDOWS\system32\Smab.dll"
              Mon 28 Feb 2005 240,128 A.SHR --- "C:\WINDOWS\system32\x.264.exe"
              Sun 25 Jan 2004 70,656 A.SH. --- "C:\WINDOWS\system32\yv12vfw.dll"
              Sun 14 May 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
              Sat 24 Nov 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
              Fri 18 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4658aca27402c0ea318a0615f08905ca\BIT42.tmp"
              Fri 18 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\6092debe4959b217a6aac6c11cc1dd60\BIT48.tmp"
              Sun 14 May 2006 4,348 A..H. --- "C:\Documents and Settings\Carlo\Mes documents\CARLO\AUDIOVISUEL C & S\Notre Musique\Sauvegarde de la licence\drmv1key.bak"
              Fri 16 Jun 2006 20 A..H. --- "C:\Documents and Settings\Carlo\Mes documents\CARLO\AUDIOVISUEL C & S\Notre Musique\Sauvegarde de la licence\drmv1lic.bak"
              Sun 26 Feb 2006 312 A..H. --- "C:\Documents and Settings\Carlo\Mes documents\CARLO\AUDIOVISUEL C & S\Notre Musique\Sauvegarde de la licence\drmv2key.bak"
              Fri 16 Jun 2006 1,536 A..H. --- "C:\Documents and Settings\Carlo\Mes documents\CARLO\AUDIOVISUEL C & S\Notre Musique\Sauvegarde de la licence\drmv2lic.bak"

              [b]Finished![/b]

              catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2008-07-07 16:04:47
              Windows 5.1.2600 Service Pack 3 NTFS

              scanning hidden processes ...

              scanning hidden services & system hive ...

              scanning hidden registry entries ...

              scanning hidden files ...

              scan completed successfully
              hidden processes: 0
              hidden services: 0
              hidden files: 0

              Autrement, dois-je faire quelque chose avec WinsockXPFix que j'ai téléchargé?

              Dans l'attente de tes nouvelles instructions, je te salue bien cordialement!

              catpeople12
              0
          12. Re catpeople12,

            merci mettre tes reponses dans l'ordre ca m'empeche de faire le yoyo,

            pour resumer,
            1--tu supprimes tout les activx en mode normal
            2--tu laisses de cote le probleme de Kaspesky, on verra plus tard
            3--si t'as pas trouve les autres cles, c'est qu'elles ont ete supprimees

            le plus important
            4--tu lance SDFIX comme indiqué dans 29 et tu mets son rapport --- copier coller

            a+
            BOB3
            0
            1. REPONSE AU MESSAGE 33 Par BOB

              Re, BOB3

              Je suis vraiment désolé que tu fasses le yoyo à cause de moi!!...

              Je pensais avoir procédé dans l'ordre de tes messages-conseil...

              Je récapitule pour te rendre la vie plus facile. Il y a deux messages importants pour toi de ma part:

              A - Mon message N° 31, qui répond à tes messages 24, 25 et 28, où je t'ai posté les logs Hijackthis que tu m'as demandés.

              B - Mon message N° 32 , qui répond à ton messsage 29, où tu trouveras le rapport de SDFix que tu m'as demandé. Comme convenu, j'ai supprimé les activex et n'ai rien fait ni avec Kaspersky ni avec LSP Fix que je devais télécharger (Voir ton message N° 24).

              J'attendais juste que tu lises le rapport SDFix pour savoir ce qu'il faut faire ensuite.

              Merci, encore désolé et A+ !

              catpeople12
              0
          13. Re catpeople12,

            pour vérification + modification

            1---Les clés de registre suivantes sont ajoutées afin d'exécuter des processus après le redémarrage:
            tu ouvres regedit.exe ----- avec prudence
            tu cherches ces cléfs et tu les supprimes

            – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            • "Printer"="%SYSDIR%\auditchk.exe"

            – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
            • "Printer"="%SYSDIR%\auditchk.exe"

            – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
            • "Printer"="%SYSDIR%\auditchk.exe"

            2--ensuite tu cherches les cléfs suivantes eventuellement tu les modifies
            les clefs doivent etre comme suit:

            – [HKLM\SOFTWARE\Microsoft\Ole]

            Nom Type Valeur

            • "EnableDCOM"= REG_SZ N

            – [HKLM\SYSTEM\CurrentControlSet\Control\Lsa]

            • "restrictanonymous"= REG_DWORD 0X00000002 (2)

            tu fermes,

            3---tu notes tout les fichiers que tu trouves
            tu cherches sur ton disque tout les fichiers qui se trouvent dans Temp, et tu les supprimes
            c:\temp\xxxxxxx.xxxx

            c:\document and settings\administrateur\local settings\temp
            et tu verifies dans les autres comptes qui se trouvent dans c:\document and setting\xxxxxxxx\local settings\temp

            c:\windows\temp
            c:\windows\system32\temp

            et tu me donne la liste
            a+
            BOB3

            tu reboot,

            tu refaits un scan avec Spybot,

            et tu remets un nouveau log hijackthis

            a+
            BOB3
            0
            1. Re catpeople12,

              en reprend a partir de 34 + ce post.

              oublis les rapports hijackthis + spybot pour le moment,
              le rapport SDFIX n'est pas fameux

              1---tu fais ce qui est demandé en 34

              2--je t'avais demande de desinstaller windows live messenger en 22 , il figure toujours dans le rapport SDFIX.

              1--est ce que tu as desinstalle microsoft live messenger, sinon desinstalles le
              2--tu desinstalles aussi microsoft active sync--il est infecté----tu le reinstalles aprés le nettoyage
              3--tu desinstalles aussi microsoft network diagnostic --- il sert a rien
              4--tu desinstalles spybot --- il est infecté --- voir plus bas

              tu fait le nettoyage avec Ccleaner, tu supprimes tout

              tu telecharge a nouveau spybot sur ce lien
              ftp://ftp.commentcamarche.com/download/spybotsd152.exe

              tu l'installes, + mise ajour + tu lances la vaccination pour que les compteurs soient identiques

              ensuite tu le parametre comme suit.

              tu lances Spybot, puis tu clic en haut Mode, puis tu coche Mode avancé
              ensuite sur outils et tu coches toutes les cases sous outils.
              tu clic sur Demarrage systeme, qui te permets de virer les programmes indesirables ou superflus que tu peux cocher et supprimer
              tu clic sur Interieur systeme, tu lances verifier, et tu les coches un apres l'autre, et puis tu clic sur corriger les problemes
              tu clic sur fichiers Hosts, pour mettre a jour la liste des sites indesirables, et tu refait ca a chaque mise a jour de spybot
              tu clic sur ajustement IE, et tu coches toutes les cases verrouillage
              tu clic sur pages navigateur, et tu clic 2 fois sur tout les liens, un apres l'autre, et lorsqu'il s'ouvre, tu efface le contenu
              et tu clic Ok
              tu clic sur BHOs, et tu vire tout----> sauf ceux de ton antivirus+Spybot
              tu clic sur ActivX, et tu vire tout----> sauf ceux de windows+office+genuine advantage+Shockwave si presents
              tu clic sur Resident, et tu coches les 2 cases.
              et une fois par jour avant d'arreter ton ordi,
              tu clic sur Effaceur de securité, et tu clic sur Modeles , puis tu clic sur la liste un apres l'autre, et tu clic en bas
              sur Dechiquetér pour tout nettoyer.

              pour finir passes un coup de Ccleaner, et fait un reboot.

              tu lance Spybot pour un scan complet, et tu me donne les resultats.
              a+
              BOB3
              0
              1. REPONSE AUX MESSAGES 34 ET 36 PAR BOB3

                Bonjour BOB3!

                Je réponds à tes messages par ordre pour te faciliter la tâche

                MESSAGE 34

                Vérification et modification

                1 - Les clefs de registre "Printer"="%SYSDIR%\auditchk.exe" n'étaient présentes ni sur [HKLM\SOFTWARE\Microsoft\Windows\Current Version\Run] ni sur [....\RunServices], ni sur [HKCU\....\Run]

                2 - Les clés suivantes n'étaient pas correctes et je les ai modifiées selon tes instructions:

                [HKLM\SOFTWARE\Microsoft\Ole] avait une valeur Y que j'ai modifiée à N comme indiqué.

                [HKLM\SYSTEM\CurrentControlSet\Control\Lsa] avait une valeur 0 que j'ai modifié à 2 comme indiqué.

                3 - Liste de fichiers trouvés dans Temp à te soumettre:

                c:\temp
                "debug"
                dossier 38bb9e8aacbb4470e2 contenant %temp%dd_msxml_retMSI
                supprimés

                c:\documents and settings\xxxx\local settings\temp
                WCESCOMM
                ISTMP1.DIR
                sv457.tmp
                supprimés

                WCESLog - IMPOSSIBLE DE LE SUPPRIMER

                c:\windows\temp
                WGAErrlog
                WGANotify.settings
                supprimés

                c:\windows\system32\temp
                dossier URTTemp contenant: fusion.dll; mscoree.dll; mscoree.dll.local; mscorns.dll; mscorwks.dll; msvcr.dll
                JE N'AI PAS OSE LE SUPPRIMER CAR TROP DE FICHIERS .dll INCONNUS POUR MOI. JE PEUX LE SUPPRIMER?

                inetsrv
                ASP Compiled Templates (dossier vide)
                supprimés

                MESSAGE 36

                1 - J'ai fait ce qui était demandé en 34

                2- Désinstallations:
                a) J'ai desinstallé les composants de windows live qui restaient encore installés
                b) J'ai desinstallé microsoft active sync (je n'en ai pas vraiment besoin)
                c) Microsoft Network Diagnostic n'est pas dans mon système
                d) J'ai desinstallé l'ancien Spybot S&D

                J'ai nettoyé avec CCleaner et j'ai tout supprimé

                J'ai téléchargé Spybot S&D sur le lien que tu m'as donné et j'ai suivi tes instructions à la lettre.

                J'ai renettoyé avec CCleaner comme demandé et j'ai rebooté

                J'ai relancé un scan complet avec Spybot, qui n'a rien trouvé d'anormal dans les résultats.

                Ce matin au démarrage de l'ordi Spybot a encore fait un scan complet et il n'y a pas de mouchards.

                P.S.

                Je n'ai pas encore utilisé LSP Fix, je n'ai pas encore téléchargé Windows Live ni reinstallé ma webcam Labtec en attendant tes instructions.

                Bien Cordialement,

                catpeople12
                0
              2. NOUVEAU

                Re BOB3,
                Je me suis permis de refaire un coup de HJT, dont je te soumets le log pour que tu voies l'état actuel du système. J'espère ne pas trop t'embêter...

                Par ailleurs, je ne peux plus accéder aux options internet du navigateur...

                Le message d'erreur suivant apparaît quand j'essaie d'aller dessus:
                X Cette opétarion a été annulée en raison de restrictions en vigueur pour cet ordinateur. Contactez votre Administrateur Système.

                Et voici le tout dernier log HJT :

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 11:43:15, on 08/07/2008
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                Boot mode: Normal

                Running processes:
                C:\windows\System32\smss.exe
                C:\windows\system32\winlogon.exe
                C:\windows\system32\services.exe
                C:\windows\system32\lsass.exe
                C:\windows\System32\Ati2evxx.exe
                C:\windows\system32\svchost.exe
                C:\windows\System32\svchost.exe
                C:\windows\system32\Ati2evxx.exe
                C:\windows\Explorer.EXE
                C:\WINDOWS\System32\brsvc01a.exe
                C:\WINDOWS\System32\brss01a.exe
                C:\windows\system32\spoolsv.exe
                C:\Program Files\VIA\RAID\raid_tool.exe
                C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                C:\Program Files\Windows Media Player\WMPNSCFG.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                C:\windows\system32\cisvc.exe
                C:\windows\System32\svchost.exe
                C:\WINDOWS\system32\inetsrv\inetinfo.exe
                C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
                C:\windows\system32\svchost.exe
                C:\windows\system32\cidaemon.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
                O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
                O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
                O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                O8 - Extra context menu item: Ajouter à Kaspersky Anti-Bannière - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                O15 - Trusted Zone: http://www.1001interims.com
                O15 - Trusted Zone: https://www.adobe.com/
                O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
                O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
                O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
                O15 - Trusted Zone: https://www.ustart.org
                O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
                O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
                O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
                O15 - Trusted Zone: https://www.msn.com/fr-fr/
                O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
                O15 - Trusted Zone: https://fr.yahoo.com/
                O15 - Trusted Zone: https://www.youtube.com/
                O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
                O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
                O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
                0
            2. Bonjour catpeople12,

              WCESLog - IMPOSSIBLE DE LE SUPPRIMER
              supprimes le en mode sans echec,

              laisses LSP Fix de cote pour le moment, j'attends une reponse s'il est compatible avec xp en francais.

              tu vas telecharger Norman Malware Cleaner
              pour ceci, tu va dans le dossier c:\SDFix
              1---en mode normal avec connection internet obligatoire.
              tu lances RunThis.bat, il ouvre un menu sous dos,
              tu tape 2, pour telecharger Norman_Malware_Cleaner
              il va s'installer tout seul dans le meme dossier, sa taille=22268ko
              normalement il se lance tout seul apres le telechargement, sinon tu ouvre le dossier SDFix, et tu lances
              Norman_Malware_Cleaner.exe

              tu le laisse scanner tout tes lecteur, il risque de prendre du temps, il termine et met un log sur ton poste de travail,
              tu le colles sur un nouveau post pour que je puisse jeté un coup d'oeil.
              a+
              BOB3

              P.S.JE SERAI ABSENT ---->16H00
              0
              1. Re-bonjour BOB3 et merci de ta réponse!

                J'ai suivi tes instructions et te laisse regarder le log de Norman Malware Cleaner (4 fichiers infectés supprimés) ci-après.
                (Au fait, à quoi correspond cette adresse IP 127.0.0.1 ?.... Il y a plein de sites bizarroïdes dedans dont j'ignorais l'existence mais qui sont sortis dans le log... ).

                Sinon, je pourrai bientôt retélécharger Windows Live et reinstaller la webcam Labtec?

                J'attends tes instructions après 16h00.

                Bien Cordialement,

                catpeople12

                LOG DU 08/07/2008

                Norman Malware Cleaner
                Copyright © 1990 - 2008, Norman ASA. Built 2008/06/30 19:19:50

                Norman Scanner Engine Version: 5.92.08
                Nvcbin.def Version: 5.92.00, Date: 2008/06/30 19:19:50, Variants: 1812814

                Running pre-scan cleanup routine:
                Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 3
                Logged on user: CARLO\Carlo

                Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLS = "C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll" -> ""
                Removed hosts entry: 127.0.0.1 www.100sexlinks.com
                Removed hosts entry: 127.0.0.1 100sexlinks.com
                Removed hosts entry: 127.0.0.1 www.123topsearch.com
                Removed hosts entry: 127.0.0.1 123topsearch.com
                Removed hosts entry: 127.0.0.1 www.1800searchonline.com
                Removed hosts entry: 127.0.0.1 1800searchonline.com
                Removed hosts entry: 127.0.0.1 www.180searchassistant.com
                Removed hosts entry: 127.0.0.1 180searchassistant.com
                Removed hosts entry: 127.0.0.1 www.1stantivirus.com
                Removed hosts entry: 127.0.0.1 1stantivirus.com
                Removed hosts entry: 127.0.0.1 www.1stsearchportal.com
                Removed hosts entry: 127.0.0.1 1stsearchportal.com
                Removed hosts entry: 127.0.0.1 www.2007-download.com
                Removed hosts entry: 127.0.0.1 2007-download.com
                Removed hosts entry: 127.0.0.1 www.2020search.com
                Removed hosts entry: 127.0.0.1 2020search.com
                Removed hosts entry: 127.0.0.1 www.24-7searching-and-more.com
                Removed hosts entry: 127.0.0.1 24-7searching-and-more.com
                Removed hosts entry: 127.0.0.1 www.2search.com
                Removed hosts entry: 127.0.0.1 2search.com
                Removed hosts entry: 127.0.0.1 www.2search.org
                Removed hosts entry: 127.0.0.1 2search.org
                Removed hosts entry: 127.0.0.1 www.3ebay.it
                Removed hosts entry: 127.0.0.1 3ebay.it
                Removed hosts entry: 127.0.0.1 www.4ebay.it
                Removed hosts entry: 127.0.0.1 4ebay.it
                Removed hosts entry: 127.0.0.1 www.4repubblica.it
                Removed hosts entry: 127.0.0.1 4repubblica.it
                Removed hosts entry: 127.0.0.1 www.5repubblica.it
                Removed hosts entry: 127.0.0.1 5repubblica.it
                Removed hosts entry: 127.0.0.1 www.777search.com
                Removed hosts entry: 127.0.0.1 777search.com
                Removed hosts entry: 127.0.0.1 www.7search.com
                Removed hosts entry: 127.0.0.1 7search.com
                Removed hosts entry: 127.0.0.1 www.971searchbox.com
                Removed hosts entry: 127.0.0.1 971searchbox.com
                Removed hosts entry: 127.0.0.1 www.abccodec.com
                Removed hosts entry: 127.0.0.1 abccodec.com
                Removed hosts entry: 127.0.0.1 www.abcsearch.com
                Removed hosts entry: 127.0.0.1 abcsearch.com
                Removed hosts entry: 127.0.0.1 www.activexmediasoftware.com
                Removed hosts entry: 127.0.0.1 activexmediasoftware.com
                Removed hosts entry: 127.0.0.1 www.activexsoftwares.com
                Removed hosts entry: 127.0.0.1 activexsoftwares.com
                Removed hosts entry: 127.0.0.1 www.activexupdate.com
                Removed hosts entry: 127.0.0.1 activexupdate.com
                Removed hosts entry: 127.0.0.1 www.adasearch.com
                Removed hosts entry: 127.0.0.1 adasearch.com
                Removed hosts entry: 127.0.0.1 www.adipics.com
                Removed hosts entry: 127.0.0.1 adipics.com
                Removed hosts entry: 127.0.0.1 adobe-download-now.com
                Removed hosts entry: 127.0.0.1 www.adobe-downloads.com
                Removed hosts entry: 127.0.0.1 adobe-downloads.com
                Removed hosts entry: 127.0.0.1 ads.searchingbooth.com
                Removed hosts entry: 127.0.0.1 www.adsextend.net
                Removed hosts entry: 127.0.0.1 adsextend.net
                Removed hosts entry: 127.0.0.1 www.adspics.com
                Removed hosts entry: 127.0.0.1 adspics.com
                Removed hosts entry: 127.0.0.1 www.adult18codec.com
                Removed hosts entry: 127.0.0.1 adult18codec.com
                Removed hosts entry: 127.0.0.1 www.adultcodec-2008.com
                Removed hosts entry: 127.0.0.1 adultcodec-2008.com
                Removed hosts entry: 127.0.0.1 www.adultcodecstars.com
                Removed hosts entry: 127.0.0.1 adultcodecstars.com
                Removed hosts entry: 127.0.0.1 www.adult-engine-search.com
                Removed hosts entry: 127.0.0.1 adult-engine-search.com
                Removed hosts entry: 127.0.0.1 affiliate.idownload.com
                Removed hosts entry: 127.0.0.1 www.airtleworld.com
                Removed hosts entry: 127.0.0.1 airtleworld.com
                Removed hosts entry: 127.0.0.1 akamai.downloadv3.com
                Removed hosts entry: 127.0.0.1 alfa-search.com
                Removed hosts entry: 127.0.0.1 www.allcybersearch.com
                Removed hosts entry: 127.0.0.1 allcybersearch.com
                Removed hosts entry: 127.0.0.1 www.all-downloads-now.com
                Removed hosts entry: 127.0.0.1 all-downloads-now.com
                Removed hosts entry: 127.0.0.1 allforadult.com
                Removed hosts entry: 127.0.0.1 www.alltiettantivirus.com
                Removed hosts entry: 127.0.0.1 alltiettantivirus.com
                Removed hosts entry: 127.0.0.1 www.alltruesoftware.com
                Removed hosts entry: 127.0.0.1 alltruesoftware.com
                Removed hosts entry: 127.0.0.1 www.amediasoftware.com
                Removed hosts entry: 127.0.0.1 amediasoftware.com
                Removed hosts entry: 127.0.0.1 www.americanautobargains.com
                Removed hosts entry: 127.0.0.1 americanautobargains.com
                Removed hosts entry: 127.0.0.1 www.ampmsearch.com
                Removed hosts entry: 127.0.0.1 ampmsearch.com
                Removed hosts entry: 127.0.0.1 anarchyporn.com
                Removed hosts entry: 127.0.0.1 www.animepornmag.com
                Removed hosts entry: 127.0.0.1 animepornmag.com
                Removed hosts entry: 127.0.0.1 www.antiespiadorado.com
                Removed hosts entry: 127.0.0.1 antiespiadorado.com
                Removed hosts entry: 127.0.0.1 www.antiespionspack.com
                Removed hosts entry: 127.0.0.1 antiespionspack.com
                Removed hosts entry: 127.0.0.1 www.antigusanos2008.com
                Removed hosts entry: 127.0.0.1 antigusanos2008.com
                Removed hosts entry: 127.0.0.1 www.antispamassistant.com
                Removed hosts entry: 127.0.0.1 antispamassistant.com
                Removed hosts entry: 127.0.0.1 www.antispamdeluxe.com
                Removed hosts entry: 127.0.0.1 antispamdeluxe.com
                Removed hosts entry: 127.0.0.1 www.antispionage.com
                Removed hosts entry: 127.0.0.1 antispionage.com
                Removed hosts entry: 127.0.0.1 www.antispionagepro.com
                Removed hosts entry: 127.0.0.1 antispionagepro.com
                Removed hosts entry: 127.0.0.1 www.antispyadvanced.com
                Removed hosts entry: 127.0.0.1 antispyadvanced.com
                Removed hosts entry: 127.0.0.1 www.antispycheck.com
                Removed hosts entry: 127.0.0.1 antispycheck.com
                Removed hosts entry: 127.0.0.1 www.antispydns.biz
                Removed hosts entry: 127.0.0.1 antispydns.biz
                Removed hosts entry: 127.0.0.1 www.antispykit.com
                Removed hosts entry: 127.0.0.1 antispykit.com
                Removed hosts entry: 127.0.0.1 www.antispylab.com
                Removed hosts entry: 127.0.0.1 antispylab.com
                Removed hosts entry: 127.0.0.1 www.antispyshield.com
                Removed hosts entry: 127.0.0.1 antispyshield.com
                Removed hosts entry: 127.0.0.1 www.antispysolutions.com
                Removed hosts entry: 127.0.0.1 antispysolutions.com
                Removed hosts entry: 127.0.0.1 www.antispyware.com
                Removed hosts entry: 127.0.0.1 antispyware.com
                Removed hosts entry: 127.0.0.1 www.antispywareboot.com
                Removed hosts entry: 127.0.0.1 antispywareboot.com
                Removed hosts entry: 127.0.0.1 www.antispywarebot.com
                Removed hosts entry: 127.0.0.1 antispywarebot.com
                Removed hosts entry: 127.0.0.1 www.antispywarebox.com
                Removed hosts entry: 127.0.0.1 antispywarebox.com
                Removed hosts entry: 127.0.0.1 www.antispywaredownloads.com
                Removed hosts entry: 127.0.0.1 antispywaredownloads.com
                Removed hosts entry: 127.0.0.1 www.antispywaresuite.com
                Removed hosts entry: 127.0.0.1 antispywaresuite.com
                Removed hosts entry: 127.0.0.1 www.antispywareupdates.net
                Removed hosts entry: 127.0.0.1 antispywareupdates.net
                Removed hosts entry: 127.0.0.1 www.antispywarexp.com
                Removed hosts entry: 127.0.0.1 antispywarexp.com
                Removed hosts entry: 127.0.0.1 www.antispyweb.net
                Removed hosts entry: 127.0.0.1 antispyweb.net
                Removed hosts entry: 127.0.0.1 www.antiver2008.com
                Removed hosts entry: 127.0.0.1 antiver2008.com
                Removed hosts entry: 127.0.0.1 www.antivermins.com
                Removed hosts entry: 127.0.0.1 antivermins.com
                Removed hosts entry: 127.0.0.1 www.anti-vermins.com
                Removed hosts entry: 127.0.0.1 anti-vermins.com
                Removed hosts entry: 127.0.0.1 www.antivir2007.com
                Removed hosts entry: 127.0.0.1 antivir2007.com
                Removed hosts entry: 127.0.0.1 www.antivirgear.com
                Removed hosts entry: 127.0.0.1 antivirgear.com
                Removed hosts entry: 127.0.0.1 www.antivirprotect.com
                Removed hosts entry: 127.0.0.1 antivirprotect.com
                Removed hosts entry: 127.0.0.1 www.antivirus.fastfreedownload.com
                Removed hosts entry: 127.0.0.1 antivirus.fastfreedownload.com
                Removed hosts entry: 127.0.0.1 www.antivirus2008pro.com
                Removed hosts entry: 127.0.0.1 antivirus2008pro.com
                Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.com
                Removed hosts entry: 127.0.0.1 antivirus-2008pro.com
                Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.com
                Removed hosts entry: 127.0.0.1 antivirus-2008-pro.com
                Removed hosts entry: 127.0.0.1 www.antivirus2008pro.info
                Removed hosts entry: 127.0.0.1 antivirus2008pro.info
                Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.info
                Removed hosts entry: 127.0.0.1 antivirus-2008pro.info
                Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.info
                Removed hosts entry: 127.0.0.1 antivirus-2008-pro.info
                Removed hosts entry: 127.0.0.1 www.antivirus2008pro.net
                Removed hosts entry: 127.0.0.1 antivirus2008pro.net
                Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.net
                Removed hosts entry: 127.0.0.1 antivirus-2008pro.net
                Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.net
                Removed hosts entry: 127.0.0.1 antivirus-2008-pro.net
                Removed hosts entry: 127.0.0.1 www.antivirus2008pro.org
                Removed hosts entry: 127.0.0.1 antivirus2008pro.org
                Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.org
                Removed hosts entry: 127.0.0.1 antivirus-2008pro.org
                Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.org
                Removed hosts entry: 127.0.0.1 antivirus-2008-pro.org
                Removed hosts entry: 127.0.0.1 www.antivirus2008x.com
                Removed hosts entry: 127.0.0.1 antivirus2008x.com
                Removed hosts entry: 127.0.0.1 www.antivirusadvance.com
                Removed hosts entry: 127.0.0.1 antivirusadvance.com
                Removed hosts entry: 127.0.0.1 www.antivirusaskeladd.com
                Removed hosts entry: 127.0.0.1 antivirusaskeladd.com
                Removed hosts entry: 127.0.0.1 www.antivirusgereedschap.com
                Removed hosts entry: 127.0.0.1 antivirusgereedschap.com
                Removed hosts entry: 127.0.0.1 www.antivirusgolden.com
                Removed hosts entry: 127.0.0.1 antivirusgolden.com
                Removed hosts entry: 127.0.0.1 www.antivirus-hq.net
                Removed hosts entry: 127.0.0.1 antivirus-hq.net
                Removed hosts entry: 127.0.0.1 www.antiviruspcsuite.com
                Removed hosts entry: 127.0.0.1 antiviruspcsuite.com
                Removed hosts entry: 127.0.0.1 www.antiviruspremium.com
                Removed hosts entry: 127.0.0.1 antiviruspremium.com
                Removed hosts entry: 127.0.0.1 www.anti-virus-pro.com
                Removed hosts entry: 127.0.0.1 anti-virus-pro.com
                Removed hosts entry: 127.0.0.1 www.antivirusprotector.com
                Removed hosts entry: 127.0.0.1 antivirusprotector.com
                Removed hosts entry: 127.0.0.1 www.antivirus-scanner.com
                Removed hosts entry: 127.0.0.1 antivirus-scanner.com
                Removed hosts entry: 127.0.0.1 www.antivirusscherm.com
                Removed hosts entry: 127.0.0.1 antivirusscherm.com
                Removed hosts entry: 127.0.0.1 www.antivirussecuritypro.com
                Removed hosts entry: 127.0.0.1 antivirussecuritypro.com
                Removed hosts entry: 127.0.0.1 www.antivirus-stop.com
                Removed hosts entry: 127.0.0.1 antivirus-stop.com
                Removed hosts entry: 127.0.0.1 www.antivirussuite.com
                Removed hosts entry: 127.0.0.1 antivirussuite.com
                Removed hosts entry: 127.0.0.1 www.antiworm2008.com
                Removed hosts entry: 127.0.0.1 antiworm2008.com
                Removed hosts entry: 127.0.0.1 www.antiwurm2008.com
                Removed hosts entry: 127.0.0.1 antiwurm2008.com
                Removed hosts entry: 127.0.0.1 www.archiviosex.net
                Removed hosts entry: 127.0.0.1 archiviosex.net
                Removed hosts entry: 127.0.0.1 www.ares.click-new-download.com
                Removed hosts entry: 127.0.0.1 ares.click-new-download.com
                Removed hosts entry: 127.0.0.1 www.asianpornmag.com
                Removed hosts entry: 127.0.0.1 asianpornmag.com
                Removed hosts entry: 127.0.0.1 www.aucunsvirus.com
                Removed hosts entry: 127.0.0.1 aucunsvirus.com
                Removed hosts entry: 127.0.0.1 www.autobargains.org
                Removed hosts entry: 127.0.0.1 autobargains.org
                Removed hosts entry: 127.0.0.1 www.autobargainsnetwork.com
                Removed hosts entry: 127.0.0.1 autobargainsnetwork.com
                Removed hosts entry: 127.0.0.1 www.autocontext.begun.ru
                Removed hosts entry: 127.0.0.1 autocontext.begun.ru
                Removed hosts entry: 127.0.0.1 autoescrowpay.com
                Removed hosts entry: 127.0.0.1 www.avast.free-software-center.com
                Removed hosts entry: 127.0.0.1 avast.free-software-center.com
                Removed hosts entry: 127.0.0.1 www.avast-downloads.com
                Removed hosts entry: 127.0.0.1 avast-downloads.com
                Removed hosts entry: 127.0.0.1 www.avg.softwarecenterz.com
                Removed hosts entry: 127.0.0.1 avg.softwarecenterz.com
                Removed hosts entry: 127.0.0.1 www.avpcheckupdate.com
                Removed hosts entry: 127.0.0.1 avpcheckupdate.com
                Removed hosts entry: 127.0.0.1 awmcash.biz
                Removed hosts entry: 127.0.0.1 awmdabest.com
                Removed hosts entry: 127.0.0.1 www.axemediasoftware.com
                Removed hosts entry: 127.0.0.1 axemediasoftware.com
                Removed hosts entry: 127.0.0.1 www.axmediasoftware.com
                Removed hosts entry: 127.0.0.1 axmediasoftware.com
                Removed hosts entry: 127.0.0.1 www.axsoftwaretool.com
                Removed hosts entry: 127.0.0.1 axsoftwaretool.com
                Removed hosts entry: 127.0.0.1 www.babespornmag.com
                Removed hosts entry: 127.0.0.1 babespornmag.com
                Removed hosts entry: 127.0.0.1 www.bardownload.com
                Removed hosts entry: 127.0.0.1 bardownload.com
                Removed hosts entry: 127.0.0.1 batsearch.com
                Removed hosts entry: 127.0.0.1 bbbsearch.com
                Removed hosts entry: 127.0.0.1 bb-search.com
                Removed hosts entry: 127.0.0.1 www.bdsmpornmag.com
                Removed hosts entry: 127.0.0.1 bdsmpornmag.com
                Removed hosts entry: 127.0.0.1 www.bearshare.click-new-download.com
                Removed hosts entry: 127.0.0.1 bearshare.click-new-download.com
                Removed hosts entry: 127.0.0.1 www.bearshare-download.org
                Removed hosts entry: 127.0.0.1 bearshare-download.org
                Removed hosts entry: 127.0.0.1 www.bearshare-downloads.net
                Removed hosts entry: 127.0.0.1 bearshare-downloads.net
                Removed hosts entry: 127.0.0.1 www.bearshare-music-downloads.com
                Removed hosts entry: 127.0.0.1 bearshare-music-downloads.com
                Removed hosts entry: 127.0.0.1 www.begin2search.com
                Removed hosts entry: 127.0.0.1 begin2search.com
                Removed hosts entry: 127.0.0.1 best-hardpics.com
                Removed hosts entry: 127.0.0.1 www.best-porncollection.com
                Removed hosts entry: 127.0.0.1 best-porncollection.com
                Removed hosts entry: 127.0.0.1 bestporngate.com
                Removed hosts entry: 127.0.0.1 www.bestsearchworld.info
                Removed hosts entry: 127.0.0.1 bestsearchworld.info
                Removed hosts entry: 127.0.0.1 www.bestworldgirls-for-u.net
                Removed hosts entry: 127.0.0.1 bestworldgirls-for-u.net
                Removed hosts entry: 127.0.0.1 bestxporno.com
                Removed hosts entry: 127.0.0.1 www.bettersearch.biz
                Removed hosts entry: 127.0.0.1 bettersearch.biz
                Removed hosts entry: 127.0.0.1 www.bgoogle.it
                Removed hosts entry: 127.0.0.1 bgoogle.it
                Removed hosts entry: 127.0.0.1 www.bigcodecadult.com
                Removed hosts entry: 127.0.0.1 bigcodecadult.com
                Removed hosts entry: 127.0.0.1 www.bigcodecadult2008.com
                Removed hosts entry: 127.0.0.1 bigcodecadult2008.com
                Removed hosts entry: 127.0.0.1 www.bigcodecadult2008-17.com
                Removed hosts entry: 127.0.0.1 bigcodecadult2008-17.com
                Removed hosts entry: 127.0.0.1 www.bighot18codec2008.com
                Removed hosts entry: 127.0.0.1 bighot18codec2008.com
                Removed hosts entry: 127.0.0.1 www.bighot18-codec2008.com
                Removed hosts entry: 127.0.0.1 bighot18-codec2008.com
                Removed hosts entry: 127.0.0.1 www.bittorrent.click-new-download.com
                Removed hosts entry: 127.0.0.1 bittorrent.click-new-download.com
                Removed hosts entry: 127.0.0.1 www.blackcodec.com
                Removed hosts entry: 127.0.0.1 blackcodec.com
                Removed hosts entry: 127.0.0.1 www.black-codec.com
                Removed hosts entry: 127.0.0.1 black-codec.com
                Removed hosts entry: 127.0.0.1 www.blackcodec.net
                Removed hosts entry: 127.0.0.1 blackcodec.net
                Removed hosts entry: 127.0.0.1 www.blackhawksoftware.com
                Removed hosts entry: 127.0.0.1 blackhawksoftware.com
                Removed hosts entry: 127.0.0.1 br.winantivirus.com
                Removed hosts entry: 127.0.0.1 www.braincodec.com
                Removed hosts entry: 127.0.0.1 braincodec.com
                Removed hosts entry: 127.0.0.1 www.brakecodec.com
                Removed hosts entry: 127.0.0.1 brakecodec.com
                Removed hosts entry: 127.0.0.1 bsa.safetydownload.com
                Removed hosts entry: 127.0.0.1 www.bsplaycodec.com
                Removed hosts entry: 127.0.0.1 bsplaycodec.com
                Removed hosts entry: 127.0.0.1 buldog-stats.com
                Removed hosts entry: 127.0.0.1 www.busysearch.net
                Removed hosts entry: 127.0.0.1 busysearch.net
                Removed hosts entry: 127.0.0.1 www.c4tdownload.com
                Removed hosts entry: 127.0.0.1 c4tdownload.com
                Removed hosts entry: 127.0.0.1 carsands.com
                Removed hosts entry: 127.0.0.1 cashsearch.biz
                Removed hosts entry: 127.0.0.1 casino.com.free.game.pogo.gratisdownloads.nl
                Removed hosts entry: 127.0.0.1 cazygirls-world.com
                Removed hosts entry: 127.0.0.1 cdn.winsoftware.com
                Removed hosts entry: 127.0.0.1 www.cinemadownload.com
                Removed hosts entry: 127.0.0.1 cinemadownload.com
                Removed hosts entry: 127.0.0.1 www.citycodec.com
                Removed hosts entry: 127.0.0.1 citycodec.com
                Removed hosts entry: 127.0.0.1 www.cleancodec.com
                Removed hosts entry: 127.0.0.1 cleancodec.com
                Removed hosts entry: 127.0.0.1 www.cleansoftwares.com
                Removed hosts entry: 127.0.0.1 cleansoftwares.com
                Removed hosts entry: 127.0.0.1 clearsearch.net
                Removed hosts entry: 127.0.0.1 www.click-codec.com
                Removed hosts entry: 127.0.0.1 click-codec.com
                Removed hosts entry: 127.0.0.1 www.clickhere4search.com
                Removed hosts entry: 127.0.0.1 clickhere4search.com
                Removed hosts entry: 127.0.0.1 www.click-new-download.com
                Removed hosts entry: 127.0.0.1 click-new-download.com
                Removed hosts entry: 127.0.0.1 www.click-to-download.com
                Removed hosts entry: 127.0.0.1 click-to-download.com
                Removed hosts entry: 127.0.0.1 www.clicktomakeasearch.com
                Removed hosts entry: 127.0.0.1 clicktomakeasearch.com
                Removed hosts entry: 127.0.0.1 client.exeupdate.com
                Removed hosts entry: 127.0.0.1 code.ignphrases.com
                Removed hosts entry: 127.0.0.1 codec.ninoa.com
                Removed hosts entry: 127.0.0.1 www.codecadult18.com
                Removed hosts entry: 127.0.0.1 codecadult18.com
                Removed hosts entry: 127.0.0.1 www.codecbest.com
                Removed hosts entry: 127.0.0.1 codecbest.com
                Removed hosts entry: 127.0.0.1 www.codecbsplay.com
                Removed hosts entry: 127.0.0.1 codecbsplay.com
                Removed hosts entry: 127.0.0.1 www.codecdemo.com
                Removed hosts entry: 127.0.0.1 codecdemo.com
                Removed hosts entry: 127.0.0.1 www.codecdvd.net
                Removed hosts entry: 127.0.0.1 codecdvd.net
                Removed hosts entry: 127.0.0.1 www.codecdvi.com
                Removed hosts entry: 127.0.0.1 codecdvi.com
                Removed hosts entry: 127.0.0.1 www.codec-fun.com
                Removed hosts entry: 127.0.0.1 codec-fun.com
                Removed hosts entry: 127.0.0.1 www.codechard.com
                Removed hosts entry: 127.0.0.1 codechard.com
                Removed hosts entry: 127.0.0.1 www.codechot.net
                Removed hosts entry: 127.0.0.1 codechot.net
                Removed hosts entry: 127.0.0.1 www.codechq.net
                Removed hosts entry: 127.0.0.1 codechq.net
                Removed hosts entry: 127.0.0.1 www.codecmeg.net
                Removed hosts entry: 127.0.0.1 codecmeg.net
                Removed hosts entry: 127.0.0.1 www.codecmega.com
                Removed hosts entry: 127.0.0.1 codecmega.com
                Removed hosts entry: 127.0.0.1 www.codecmega.net
                Removed hosts entry: 127.0.0.1 codecmega.net
                Removed hosts entry: 127.0.0.1 www.codecmoon.com
                Removed hosts entry: 127.0.0.1 codecmoon.com
                Removed hosts entry: 127.0.0.1 www.codecmpg.com
                Removed hosts entry: 127.0.0.1 codecmpg.com
                Removed hosts entry: 127.0.0.1 www.codecnice.net
                Removed hosts entry: 127.0.0.1 codecnice.net
                Removed hosts entry: 127.0.0.1 www.codecnitro.com
                Removed hosts entry: 127.0.0.1 codecnitro.com
                Removed hosts entry: 127.0.0.1 www.codecops.net
                Removed hosts entry: 127.0.0.1 codecops.net
                Removed hosts entry: 127.0.0.1 www.codecplay.com
                Removed hosts entry: 127.0.0.1 codecplay.com
                Removed hosts entry: 127.0.0.1 www.codecpretty.net
                Removed hosts entry: 127.0.0.1 codecpretty.net
                Removed hosts entry: 127.0.0.1 www.codecpro.net
                Removed hosts entry: 127.0.0.1 codecpro.net
                Removed hosts entry: 127.0.0.1 www.codecred.net
                Removed hosts entry: 127.0.0.1 codecred.net
                Removed hosts entry: 127.0.0.1 www.codecsoft.net
                Removed hosts entry: 127.0.0.1 codecsoft.net
                Removed hosts entry: 127.0.0.1 www.codecthe.com
                Removed hosts entry: 127.0.0.1 codecthe.com
                Removed hosts entry: 127.0.0.1 www.codectime.com
                Removed hosts entry: 127.0.0.1 codectime.com
                Removed hosts entry: 127.0.0.1 www.codecultra.net
                Removed hosts entry: 127.0.0.1 codecultra.net
                Removed hosts entry: 127.0.0.1 www.codecvids.com
                Removed hosts entry: 127.0.0.1 codecvids.com
                Removed hosts entry: 127.0.0.1 www.codecvip.com
                Removed hosts entry: 127.0.0.1 codecvip.com
                Removed hosts entry: 127.0.0.1 www.codecviva.com
                Removed hosts entry: 127.0.0.1 codecviva.com
                Removed hosts entry: 127.0.0.1 www.codeczang.net
                Removed hosts entry: 127.0.0.1 codeczang.net
                Removed hosts entry: 127.0.0.1 www.computerpcgames.net
                Removed hosts entry: 127.0.0.1 computerpcgames.net
                Removed hosts entry: 127.0.0.1 www.contra-virus.com
                Removed hosts entry: 127.0.0.1 contra-virus.com
                Removed hosts entry: 127.0.0.1 www.convenient-search.com
                Removed hosts entry: 127.0.0.1 convenient-search.com
                Removed hosts entry: 127.0.0.1 coolmoneysearch.com
                Removed hosts entry: 127.0.0.1 coolpornsearch.com
                Removed hosts entry: 127.0.0.1 cool-search.net
                Removed hosts entry: 127.0.0.1 cool-search.netfartpost.com
                Removed hosts entry: 127.0.0.1 www.coolwebsearch.com
                Removed hosts entry: 127.0.0.1 coolwebsearch.com
                Removed hosts entry: 127.0.0.1 cool-web-search.com
                Removed hosts entry: 127.0.0.1 www.coolwwwsearch.com
                Removed hosts entry: 127.0.0.1 coolwwwsearch.com
                Removed hosts entry: 127.0.0.1 counter.sexmaniack.com
                Removed hosts entry: 127.0.0.1 www.crazygirls-world.com
                Removed hosts entry: 127.0.0.1 crazygirls-world.com
                Removed hosts entry: 127.0.0.1 creditsearchonline.com
                Removed hosts entry: 127.0.0.1 www.dailypornmag.com
                Removed hosts entry: 127.0.0.1 dailypornmag.com
                Removed hosts entry: 127.0.0.1 dating-search.net
                Removed hosts entry: 127.0.0.1 de.winantivirus.com
                Removed hosts entry: 127.0.0.1 www.debay.it
                Removed hosts entry: 127.0.0.1 debay.it
                Removed hosts entry: 127.0.0.1 www.dedsearch.com
                Removed hosts entry: 127.0.0.1 dedsearch.com
                Removed hosts entry: 127.0.0.1 defaultsearch.net
                Removed hosts entry: 127.0.0.1 www.defensaantimalware.com
                Removed hosts entry: 127.0.0.1 defensaantimalware.com
                Removed hosts entry: 127.0.0.1 www.delficodec.com
                Removed hosts entry: 127.0.0.1 delficodec.com
                Removed hosts entry: 127.0.0.1 www.democodec.com
                Removed hosts entry: 127.0.0.1 democodec.com
                Removed hosts entry: 127.0.0.1 www.deskbar.worldtostart.com
                Removed hosts entry: 127.0.0.1 deskbar.worldtostart.com
                Removed hosts entry: 127.0.0.1 www.detectivesearches.com
                Removed hosts entry: 127.0.0.1 detectivesearches.com
                Removed hosts entry: 127.0.0.1 www.digitalcoders.net
                Removed hosts entry: 127.0.0.1 digitalcoders.net
                Removed hosts entry: 127.0.0.1 digital-pornography.com
                Removed hosts entry: 127.0.0.1 www.directsearchzone.com
                Removed hosts entry: 127.0.0.1 directsearchzone.com
                Removed hosts entry: 127.0.0.1 dl1.antivermins.com
                Removed hosts entry: 127.0.0.1 dl1.antivirgear.com
                Removed hosts entry: 127.0.0.1 dl1.virusprotectpro.com
                Removed hosts entry: 127.0.0.1 document-not-found.pornpic.org
                Removed hosts entry: 127.0.0.1 download.abetterinternet.com
                Removed hosts entry: 127.0.0.1 download.adintelligence.net
                Removed hosts entry: 127.0.0.1 www.download.antispywarebot.com
                Removed hosts entry: 127.0.0.1 download.antispywarebot.com
                Removed hosts entry: 127.0.0.1 www.download.bardownload.com
                Removed hosts entry: 127.0.0.1 download.bardownload.com
                Removed hosts entry: 127.0.0.1 www.download.bravesentry.com
                Removed hosts entry: 127.0.0.1 download.bravesentry.com
                Removed hosts entry: 127.0.0.1 download.cdn.drivecleaner.com
                Removed hosts entry: 127.0.0.1 download.cdn.errorsafe.com
                Removed hosts entry: 127.0.0.1 download.cdn.winsoftware.com
                Removed hosts entry: 127.0.0.1 download.contextplus.net
                Removed hosts entry: 127.0.0.1 download.errorsafe.com
                Removed hosts entry: 127.0.0.1 www.download.jupitersatellites.biz
                Removed hosts entry: 127.0.0.1 download.jupitersatellites.biz
                Removed hosts entry: 127.0.0.1 download.malwarealarm.com
                Removed hosts entry: 127.0.0.1 download.searchtabs.net
                Removed hosts entry: 127.0.0.1 www.download.secureyournet.biz
                Removed hosts entry: 127.0.0.1 download.secureyournet.biz
                Removed hosts entry: 127.0.0.1 download.spyonthis.net
                Removed hosts entry: 127.0.0.1 download.spy-shredder.com
                Removed hosts entry: 127.0.0.1 download.systemdoctor.com
                Removed hosts entry: 127.0.0.1 download.winantispyware.com
                Removed hosts entry: 127.0.0.1 download.winantivirus.com
                Removed hosts entry: 127.0.0.1 download.windrivecleaner.com
                Removed hosts entry: 127.0.0.1 download.winfixer.com
                Removed hosts entry: 127.0.0.1 download10.spywarequake.com
                Removed hosts entry: 127.0.0.1 download11.spywarequake.com
                Removed hosts entry: 127.0.0.1 download12.spywarequake.com
                Removed hosts entry: 127.0.0.1 download13.spywarequake.com
                Removed hosts entry: 127.0.0.1 download15.spywarequake.com
                Removed hosts entry: 127.0.0.1 download2.spywarequake.com
                Removed hosts entry: 127.0.0.1 www.download-2007.com
                Removed hosts entry: 127.0.0.1 download-2007.com
                Removed hosts entry: 127.0.0.1 download3.spyaxe.com
                Removed hosts entry: 127.0.0.1 download3.spywarequake.com
                Removed hosts entry: 127.0.0.1 www.download3xpics.com
                Removed hosts entry: 127.0.0.1 download3xpics.com
                Removed hosts entry: 127.0.0.1 download4.spyaxe.com
                Removed hosts entry: 127.0.0.1 download4.spywarequake.com
                Removed hosts entry: 127.0.0.1 download5.spyaxe.com
                Removed hosts entry: 127.0.0.1 download5.spywarequake.com
                Removed hosts entry: 127.0.0.1 download6.spyaxe.com
                Removed hosts entry: 127.0.0.1 download7.spywarequake.com
                Removed hosts entry: 127.0.0.1 download8.spywarequake.com
                Removed hosts entry: 127.0.0.1 download9.spywarequake.com
                Removed hosts entry: 127.0.0.1 www.downloadacceleratorsite.com
                Removed hosts entry: 127.0.0.1 downloadacceleratorsite.com
                Removed hosts entry: 127.0.0.1 www.download-ad-aware.com
                Removed hosts entry: 127.0.0.1 download-ad-aware.com
                Removed hosts entry: 127.0.0.1 www.download-all-4-free.com
                Removed hosts entry: 127.0.0.1 download-all-4-free.com
                Removed hosts entry: 127.0.0.1 www.download-all-area.com
                Removed hosts entry: 127.0.0.1 download-all-area.com
                Removed hosts entry: 127.0.0.1 www.download-antivir.com
                Removed hosts entry: 127.0.0.1 download-antivir.com
                Removed hosts entry: 127.0.0.1 www.downloadanysong.com
                Removed hosts entry: 127.0.0.1 downloadanysong.com
                Removed hosts entry: 127.0.0.1 www.downloadaresnow.com
                Removed hosts entry: 127.0.0.1 downloadaresnow.com
                Removed hosts entry: 127.0.0.1 www.download-avast.com
                Removed hosts entry: 127.0.0.1 download-avast.com
                Removed hosts entry: 127.0.0.1 www.downloadcorporation.com
                Removed hosts entry: 127.0.0.1 downloadcorporation.com
                Removed hosts entry: 127.0.0.1 www.download-dvdshrink.com
                Removed hosts entry: 127.0.0.1 download-dvdshrink.com
                Removed hosts entry: 127.0.0.1 www.download-for-free.net
                Removed hosts entry: 127.0.0.1 download-for-free.net
                Removed hosts entry: 127.0.0.1 www.downloadfreesoft.com
                Removed hosts entry: 127.0.0.1 downloadfreesoft.com
                Removed hosts entry: 127.0.0.1 www.downloadfreeway.com
                Removed hosts entry: 127.0.0.1 downloadfreeway.com
                Removed hosts entry: 127.0.0.1 www.downloadimesh.com
                Removed hosts entry: 127.0.0.1 downloadimesh.com
                Removed hosts entry: 127.0.0.1 www.download-itunes-now.com
                Removed hosts entry: 127.0.0.1 download-itunes-now.com
                Removed hosts entry: 127.0.0.1 www.download-limewire.org
                Removed hosts entry: 127.0.0.1 download-limewire.org
                Removed hosts entry: 127.0.0.1 www.downloadmax.net
                Removed hosts entry: 127.0.0.1 downloadmax.net
                Removed hosts entry: 127.0.0.1 www.download-mcafee.com
                Removed hosts entry: 127.0.0.1 download-mcafee.com
                Removed hosts entry: 127.0.0.1 www.downloadmediaax.com
                Removed hosts entry: 127.0.0.1 downloadmediaax.com
                Removed hosts entry: 127.0.0.1 www.downloadpics.net
                Removed hosts entry: 127.0.0.1 downloadpics.net
                Removed hosts entry: 127.0.0.1 www.downloadprovider.net
                Removed hosts entry: 127.0.0.1 downloadprovider.net
                Removed hosts entry: 127.0.0.1 www.download-real-player.com
                Removed hosts entry: 127.0.0.1 download-real-player.com
                Removed hosts entry: 127.0.0.1 downloads.180solutions.com
                Removed hosts entry: 127.0.0.1 www.downloadservicearea.com
                Removed hosts entry: 127.0.0.1 downloadservicearea.com
                Removed hosts entry: 127.0.0.1 www.downloads-free.org
                Removed hosts entry: 127.0.0.1 downloads-free.org
                Removed hosts entry: 127.0.0.1 www.downloadsglobe.com
                Removed hosts entry: 127.0.0.1 downloadsglobe.com
                Removed hosts entry: 127.0.0.1 www.download-trillian.com
                Removed hosts entry: 127.0.0.1 download-trillian.com
                Removed hosts entry: 127.0.0.1 www.downloadv3.com
                Removed hosts entry: 127.0.0.1 downloadv3.com
                Removed hosts entry: 127.0.0.1 www.downloadvax.com
                Removed hosts entry: 127.0.0.1 downloadvax.com
                Removed hosts entry: 127.0.0.1 download-video.12w.net
                Removed hosts entry: 127.0.0.1 www.download-windvd.com
                Removed hosts entry: 127.0.0.1 download-windvd.com
                Removed hosts entry: 127.0.0.1 www.download-winrar.com
                Removed hosts entry: 127.0.0.1 download-winrar.com
                Removed hosts entry: 127.0.0.1 downloadwizard.com
                Removed hosts entry: 127.0.0.1 www.downloadxmoveis.com
                Removed hosts entry: 127.0.0.1 downloadxmoveis.com
                Removed hosts entry: 127.0.0.1 www.downloadxvids.com
                Removed hosts entry: 127.0.0.1 downloadxvids.com
                Removed hosts entry: 127.0.0.1 downloadzcenter.com
                Removed hosts entry: 127.0.0.1 downloadzcentral.com
                Removed hosts entry: 127.0.0.1 www.downloadzfree.com
                Removed hosts entry: 127.0.0.1 downloadzfree.com
                Removed hosts entry: 127.0.0.1 downloadznow.net
                Removed hosts entry: 127.0.0.1 www.download-zone-free.com
                Removed hosts entry: 127.0.0.1 download-zone-free.com
                Removed hosts entry: 127.0.0.1 www.download-zone-free.net
                Removed hosts entry: 127.0.0.1 download-zone-free.net
                Removed hosts entry: 127.0.0.1 www.drepubblica.it
                Removed hosts entry: 127.0.0.1 drepubblica.it
                Removed hosts entry: 127.0.0.1 drocherway.com
                Removed hosts entry: 127.0.0.1 dutch-sex.com
                Removed hosts entry: 127.0.0.1 www.dvd-codec.com
                Removed hosts entry: 127.0.0.1 dvd-codec.com
                Removed hosts entry: 127.0.0.1 www.dvdcodec.net
                Removed hosts entry: 127.0.0.1 dvdcodec.net
                Removed hosts entry: 127.0.0.1 www.dvicodec.com
                Removed hosts entry: 127.0.0.1 dvicodec.com
                Removed hosts entry: 127.0.0.1 eager-sex.com
                Removed hosts entry: 127.0.0.1 easyantispy.com
                Removed hosts entry: 127.0.0.1 www.easypspdownloads.com
                Removed hosts entry: 127.0.0.1 easypspdownloads.com
                Removed hosts entry: 127.0.0.1 easy-search.net
                Removed hosts entry: 127.0.0.1 www.easysearch4you.com
                Removed hosts entry: 127.0.0.1 easysearch4you.com
                Removed hosts entry: 127.0.0.1 easysearchingtips.com
                Removed hosts entry: 127.0.0.1 www.ebay6.it
                Removed hosts entry: 127.0.0.1 ebay6.it
                Removed hosts entry: 127.0.0.1 www.ebay7.it
                Removed hosts entry: 127.0.0.1 ebay7.it
                Removed hosts entry: 127.0.0.1 www.ebayg.it
                Removed hosts entry: 127.0.0.1 ebayg.it
                Removed hosts entry: 127.0.0.1 www.ebayh.it
                Removed hosts entry: 127.0.0.1 ebayh.it
                Removed hosts entry: 127.0.0.1 www.ebayj.it
                Removed hosts entry: 127.0.0.1 ebayj.it
                Removed hosts entry: 127.0.0.1 www.ebayt.it
                Removed hosts entry: 127.0.0.1 ebayt.it
                Removed hosts entry: 127.0.0.1 www.ebayu.it
                Removed hosts entry: 127.0.0.1 ebayu.it
                Removed hosts entry: 127.0.0.1 ebonypornmag.com
                Removed hosts entry: 127.0.0.1 www.ebonypornmag.com
                Removed hosts entry: 127.0.0.1 ebony-pornmag.com
                Removed hosts entry: 127.0.0.1 www.ebony-pornmag.com
                Removed hosts entry: 127.0.0.1 ecstasyporn.net
                Removed hosts entry: 127.0.0.1 www.eebay.it
                Removed hosts entry: 127.0.0.1 eebay.it
                Removed hosts entry: 127.0.0.1 www.eepubblica.it
                Removed hosts entry: 127.0.0.1 eepubblica.it
                Removed hosts entry: 127.0.0.1 www.efcsoftware.com
                Removed hosts entry: 127.0.0.1 efcsoftware.com
                Removed hosts entry: 127.0.0.1 www.elitecodec.com
                Removed hosts entry: 127.0.0.1 elitecodec.com
                Removed hosts entry: 127.0.0.1 www.emcodec.com
                Removed hosts entry: 127.0.0.1 emcodec.com
                Removed hosts entry: 127.0.0.1 www.emediacodec.com
                Removed hosts entry: 127.0.0.1 emediacodec.com
                Removed hosts entry: 127.0.0.1 www.emule.click-new-download.com
                Removed hosts entry: 127.0.0.1 emule.click-new-download.com
                Removed hosts entry: 127.0.0.1 www.emuledownloadhome.com
                Removed hosts entry: 127.0.0.1 emuledownloadhome.com
                Removed hosts entry: 127.0.0.1 www.encodeinstrument.com
                Removed hosts entry: 127.0.0.1 encodeinstrument.com
                Removed hosts entry: 127.0.0.1 www.endcodec.com
                Removed hosts entry: 127.0.0.1 endcodec.com
                Removed hosts entry: 127.0.0.1 www.enterthesearch.com
                Removed hosts entry: 127.0.0.1 enterthesearch.com
                Removed hosts entry: 127.0.0.1 epornsex.com
                Removed hosts entry: 127.0.0.1 www.erepubblica.it
                Removed hosts entry: 127.0.0.1 erepubblica.it
                Removed hosts entry: 127.0.0.1 es.winantivirus.com
                Removed hosts entry: 127.0.0.1 www.esearch2005.com
                Removed hosts entry: 127.0.0.1 esearch2005.com
                Removed hosts entry: 127.0.0.1 www.etomi.all-downloads-now.com
                Removed hosts entry: 127.0.0.1 etomi.all-downloads-now.com
                Removed hosts entry: 127.0.0.1 www.eupdatepage.com
                Removed hosts entry: 127.0.0.1 eupdatepage.com
                Removed hosts entry: 127.0.0.1 www.every-game.com
                Removed hosts entry: 127.0.0.1 every-game.com
                Removed hosts entry: 127.0.0.1 ewebsearch.net
                Removed hosts entry: 127.0.0.1 www.exeupdate.com
                Removed hosts entry: 127.0.0.1 exeupdate.com
                Removed hosts entry: 127.0.0.1 www.eza1netsearch.com
                Removed hosts entry: 127.0.0.1 eza1netsearch.com
                Removed hosts entry: 127.0.0.1 www.ezcybersearch.com
                Removed hosts entry: 127.0.0.1 ezcybersearch.com
                Removed hosts entry: 127.0.0.1 ez-searching.com
                Removed hosts entry: 127.0.0.1 www.ezwebsearching.com
                Removed hosts entry: 127.0.0.1 ezwebsearching.com
                Removed hosts entry: 127.0.0.1 www.fairsearcher.com
                Removed hosts entry: 127.0.0.1 fairsearcher.com
                Removed hosts entry: 127.0.0.1 fastfreedownload.com
                Removed hosts entry: 127.0.0.1 www.fastmetasearch.com
                Removed hosts entry: 127.0.0.1 fastmetasearch.com
                Removed hosts entry: 127.0.0.1 www.fastpspdownloads.com
                Removed hosts entry: 127.0.0.1 fastpspdownloads.com
                Removed hosts entry: 127.0.0.1 www.fastssearch.com
                Removed hosts entry: 127.0.0.1 fastssearch.com
                Removed hosts entry: 127.0.0.1 www.fasttvdownloads.com
                Removed hosts entry: 127.0.0.1 fasttvdownloads.com
                Removed hosts entry: 127.0.0.1 faxporn.com
                Removed hosts entry: 127.0.0.1 www.febay.it
                Removed hosts entry: 127.0.0.1 febay.it
                Removed hosts entry: 127.0.0.1 feed.dedsearch.com
                Removed hosts entry: 127.0.0.1 www.feeds.2search.com
                Removed hosts entry: 127.0.0.1 feeds.2search.com
                Removed hosts entry: 127.0.0.1 www.feeds2.2search.org
                Removed hosts entry: 127.0.0.1 feeds2.2search.org
                Removed hosts entry: 127.0.0.1 www.fgoogle.it
                Removed hosts entry: 127.0.0.1 fgoogle.it
                Removed hosts entry: 127.0.0.1 www.filesharing-downloads.com
                Removed hosts entry: 127.0.0.1 filesharing-downloads.com
                Removed hosts entry: 127.0.0.1 www.filetretporn.com
                Removed hosts entry: 127.0.0.1 filetretporn.com
                Removed hosts entry: 127.0.0.1 fine-search.net
                Removed hosts entry: 127.0.0.1 www.firecodec.com
                Removed hosts entry: 127.0.0.1 firecodec.com
                Removed hosts entry: 127.0.0.1 www.firefoxdownload-now.com
                Removed hosts entry: 127.0.0.1 firefoxdownload-now.com
                Removed hosts entry: 127.0.0.1 www.firstgoodsearch.com
                Removed hosts entry: 127.0.0.1 firstgoodsearch.com
                Removed hosts entry: 127.0.0.1 www.fixerantispy.com
                Removed hosts entry: 127.0.0.1 fixerantispy.com
                Removed hosts entry: 127.0.0.1 www.flwupdate.com
                Removed hosts entry: 127.0.0.1 flwupdate.com
                Removed hosts entry: 127.0.0.1 www.flycodecs.com
                Removed hosts entry: 127.0.0.1 flycodecs.com
                Removed hosts entry: 127.0.0.1 fr.winantivirus.com
                Removed hosts entry: 127.0.0.1 frame.crazywinnings.com
                Removed hosts entry: 127.0.0.1 free4porno.net
                Removed hosts entry: 127.0.0.1 www.free-adobe-download-support.com
                Removed hosts entry: 127.0.0.1 free-adobe-download-support.com
                Removed hosts entry: 127.0.0.1 www.free-avg-download.com
                Removed hosts entry: 127.0.0.1 free-avg-download.com
                Removed hosts entry: 127.0.0.1 www.freedownloadhq.com
                Removed hosts entry: 127.0.0.1 freedownloadhq.com
                Removed hosts entry: 127.0.0.1 www.freedownloadpage.com
                Removed hosts entry: 127.0.0.1 freedownloadpage.com
                Removed hosts entry: 127.0.0.1 www.free-download-place.com
                Removed hosts entry: 127.0.0.1 free-download-place.com
                Removed hosts entry: 127.0.0.1 www.free-download-support.com
                Removed hosts entry: 127.0.0.1 free-download-support.com
                Removed hosts entry: 127.0.0.1 www.freedownloadzone.com
                Removed hosts entry: 127.0.0.1 freedownloadzone.com
                Removed hosts entry: 127.0.0.1 www.freeimageheaven.com
                Removed hosts entry: 127.0.0.1 freeimageheaven.com
                Removed hosts entry: 127.0.0.1 free-pics-and-movies.com
                Removed hosts entry: 127.0.0.1 www.free-program-download.com
                Removed hosts entry: 127.0.0.1 free-program-download.com
                Removed hosts entry: 127.0.0.1 free-sex-movie-clips.net
                Removed hosts entry: 127.0.0.1 freeshemalepics.net
                Removed hosts entry: 127.0.0.1 www.free-software-center.com
                Removed hosts entry: 127.0.0.1 free-software-center.com
                Removed hosts entry: 127.0.0.1 www.free-spyware-downloads.com
                Removed hosts entry: 127.0.0.1 free-spyware-downloads.com
                Removed hosts entry: 127.0.0.1 fregat.drocherway.com
                Removed hosts entry: 127.0.0.1 www.frepubblica.it
                Removed hosts entry: 127.0.0.1 frepubblica.it
                Removed hosts entry: 127.0.0.1 www.frostwire.click-new-download.com
                Removed hosts entry: 127.0.0.1 frostwire.click-new-download.com
                Removed hosts entry: 127.0.0.1 www.fullmusicdownload.com
                Removed hosts entry: 127.0.0.1 fullmusicdownload.com
                Removed hosts entry: 127.0.0.1 full-search.net
                Removed hosts entry: 127.0.0.1 www.fullsoftwarecenter.com
                Removed hosts entry: 127.0.0.1 fullsoftwarecenter.com
                Removed hosts entry: 127.0.0.1 www.fullsoftwaredownloadz.com
                Removed hosts entry: 127.0.0.1 fullsoftwaredownloadz.com
                Removed hosts entry: 127.0.0.1 www.fulltvdownloading.com
                Removed hosts entry: 127.0.0.1 fulltvdownloading.com
                Removed hosts entry: 127.0.0.1 www.funcodec.com
                Removed hosts entry: 127.0.0.1 funcodec.com
                Removed hosts entry: 127.0.0.1 www.galleriesforporn.com
                Removed hosts entry: 127.0.0.1 galleriesforporn.com
                Removed hosts entry: 127.0.0.1 www.gallsforporn.com
                Removed hosts entry: 127.0.0.1 gallsforporn.com
                Removed hosts entry: 127.0.0.1 www.game4all.biz
                Removed hosts entry: 127.0.0.1 game4all.biz
                Removed hosts entry: 127.0.0.1 www.gamecodec.com
                Removed hosts entry: 127.0.0.1 gamecodec.com
                Removed hosts entry: 127.0.0.1 www.games.de.ag
                Removed hosts entry: 127.0.0.1 games.de.ag
                Removed hosts entry: 127.0.0.1 games.uzoogle.com
                Removed hosts entry: 127.0.0.1 www.games-desktop.com
                Removed hosts entry: 127.0.0.1 games-desktop.com
                Removed hosts entry: 127.0.0.1 www.games-u-spiele.de
                Removed hosts entry: 127.0.0.1 games-u-spiele.de
                Removed hosts entry: 127.0.0.1 gameterror.net
                Removed hosts entry: 127.0.0.1 www.gayspornmag.com
                Removed hosts entry: 127.0.0.1 gayspornmag.com
                Removed hosts entry: 127.0.0.1 get.hitvirus.com
                Removed hosts entry: 127.0.0.1 www.getanysoftware.com
                Removed hosts entry: 127.0.0.1 getanysoftware.com
                Removed hosts entry: 127.0.0.1 www.getfreepornvideo.com
                Removed hosts entry: 127.0.0.1 getfreepornvideo.com

                Scan started: 08/07/2008 13:05:47

                Scanning running processes and process memory...

                Number of processes/threads found: 1692
                Number of processes/threads scanned: 1692
                Number of processes/threads not scanned: 0
                Number of infected processes/threads terminated: 0
                Total scanning time: 29s

                Scanning file system...

                Scanning: C:\*.*

                C:\Program Files\WebMediaPlayer\WebMediaPlayer.exe (Infected with W32/Smalltroj.CDIP)
                Deleted file

                C:\System Volume Information\_RESTO~1\RP371\A0103062.exe (Infected with Renos.XS)
                Deleted file

                C:\System Volume Information\_RESTO~1\RP379\A0103828.exe (Infected with W32/Zlob.BWLZ)
                Deleted file

                C:\System Volume Information\_RESTO~1\RP406\A0115214.exe (Infected with W32/Smalltroj.CDIP)
                Deleted file

                Scanning: c:\System Volume Information\*.*

                Running post-scan cleanup routine:
                Removed hosts entry: 127.0.0.1 getpicshere.com
                Removed hosts entry: 127.0.0.1 www.getpornmag.com
                Removed hosts entry: 127.0.0.1 getpornmag.com
                Removed hosts entry: 127.0.0.1 www.getpornvideoz.com
                Removed hosts entry: 127.0.0.1 getpornvideoz.com
                Removed hosts entry: 127.0.0.1 www.gigacodec.net
                Removed hosts entry: 127.0.0.1 gigacodec.net
                Removed hosts entry: 127.0.0.1 girls-porn-life.com
                Removed hosts entry: 127.0.0.1 www.givemepornvids.com
                Removed hosts entry: 127.0.0.1 givemepornvids.com
                Removed hosts entry: 127.0.0.1 www.globalfreesearch.com
                Removed hosts entry: 127.0.0.1 globalfreesearch.com
                Removed hosts entry: 127.0.0.1 www.globalsoftwareagreement.com
                Removed hosts entry: 127.0.0.1 globalsoftwareagreement.com
                Removed hosts entry: 127.0.0.1 globalwebsearch.com
                Removed hosts entry: 127.0.0.1 www.globesearch.com
                Removed hosts entry: 127.0.0.1 globesearch.com
                Removed hosts entry: 127.0.0.1 go.winantispyware.com
                Removed hosts entry: 127.0.0.1 go.winantivirus.com
                Removed hosts entry: 127.0.0.1 www.go2realsearch.com
                Removed hosts entry: 127.0.0.1 go2realsearch.com
                Removed hosts entry: 127.0.0.1 go2-search.com
                Removed hosts entry: 127.0.0.1 www.gocodec.com
                Removed hosts entry: 127.0.0.1 gocodec.com
                Removed hosts entry: 127.0.0.1 www.gocybersearch.com
                Removed hosts entry: 127.0.0.1 gocybersearch.com
                Removed hosts entry: 127.0.0.1 www.goldcodec.com
                Removed hosts entry: 127.0.0.1 goldcodec.com
                Removed hosts entry: 127.0.0.1 www.goldenantispy.com
                Removed hosts entry: 127.0.0.1 goldenantispy.com
                Removed hosts entry: 127.0.0.1 goodsexs.com
                Removed hosts entry: 127.0.0.1 google.panet.org
                Removed hosts entry: 127.0.0.1 google123.web1000.com
                Removed hosts entry: 127.0.0.1 googlebar.jps.ru
                Removed hosts entry: 127.0.0.1 www.googlebawt.com
                Removed hosts entry: 127.0.0.1 googlebawt.com
                Removed hosts entry: 127.0.0.1 gratis-porn-movie.com
                Removed hosts entry: 127.0.0.1 gratis-pornopics.com
                Removed hosts entry: 127.0.0.1 www.greatcodec.com
                Removed hosts entry: 127.0.0.1 greatcodec.com
                Removed hosts entry: 127.0.0.1 greg-search.com
                Removed hosts entry: 127.0.0.1 greg-tut.com
                Removed hosts entry: 127.0.0.1 www.grepubblica.it
                Removed hosts entry: 127.0.0.1 grepubblica.it
                Removed hosts entry: 127.0.0.1 www.hacker.com.cn
                Removed hosts entry: 127.0.0.1 hacker.com.cn
                Removed hosts entry: 127.0.0.1 www.hardcorepornmag.com
                Removed hosts entry: 127.0.0.1 hardcorepornmag.com
                Removed hosts entry: 127.0.0.1 hardpornmpg.com
                Removed hosts entry: 127.0.0.1 www.hastalavista.com
                Removed hosts entry: 127.0.0.1 hastalavista.com
                Removed hosts entry: 127.0.0.1 www.helpcodec.com
                Removed hosts entry: 127.0.0.1 helpcodec.com
                Removed hosts entry: 127.0.0.1 helpyoursearch.com
                Removed hosts entry: 127.0.0.1 www.here4search.biz
                Removed hosts entry: 127.0.0.1 here4search.biz
                Removed hosts entry: 127.0.0.1 www.here4search.com
                Removed hosts entry: 127.0.0.1 here4search.com
                Removed hosts entry: 127.0.0.1 www.herocodec.com
                Removed hosts entry: 127.0.0.1 herocodec.com
                Removed hosts entry: 127.0.0.1 www.hgoogle.it
                Removed hosts entry: 127.0.0.1 hgoogle.it
                Removed hosts entry: 127.0.0.1 hi-search.com
                Removed hosts entry: 127.0.0.1 www.hitvirus.com
                Removed hosts entry: 127.0.0.1 hitvirus.com
                Removed hosts entry: 127.0.0.1 hk.winantivirus.com
                Removed hosts entry: 127.0.0.1 www.hobbypesca.com.br
                Removed hosts entry: 127.0.0.1 hobbypesca.com.br
                Removed hosts entry: 127.0.0.1 holidayautostr.com
                Removed hosts entry: 127.0.0.1 www.host-codec.com
                Removed hosts entry: 127.0.0.1 host-codec.com
                Removed hosts entry: 127.0.0.1 www.hot18-codec2008.com
                Removed hosts entry: 127.0.0.1 hot18-codec2008.com
                Removed hosts entry: 127.0.0.1 www.hot200818codec.com
                Removed hosts entry: 127.0.0.1 hot200818codec.com
                Removed hosts entry: 127.0.0.1 www.hot2008-18codec.com
                Removed hosts entry: 127.0.0.1 hot2008-18codec.com
                Removed hosts entry: 127.0.0.1 www.hot2008codec.com
                Removed hosts entry: 127.0.0.1 hot2008codec.com
                Removed hosts entry: 127.0.0.1 hot-cartoon-sex.anime.american-teens.net
                Removed hosts entry: 127.0.0.1 www.hotcodec.net
                Removed hosts entry: 127.0.0.1 hotcodec.net
                Removed hosts entry: 127.0.0.1 www.hot-codec18.com
                Removed hosts entry: 127.0.0.1 hot-codec18.com
                Removed hosts entry: 127.0.0.1 www.hotcodecstars.com
                Removed hosts entry: 127.0.0.1 hotcodecstars.com
                Removed hosts entry: 127.0.0.1 www.hotecodec18.com
                Removed hosts entry: 127.0.0.1 hotecodec18.com
                Removed hosts entry: 127.0.0.1 www.hotelcodec.com
                Removed hosts entry: 127.0.0.1 hotelcodec.com
                Removed hosts entry: 127.0.0.1 www.hotmp3download.com
                Removed hosts entry: 127.0.0.1 hotmp3download.com
                Removed hosts entry: 127.0.0.1 hotsearchbox.com
                Removed hosts entry: 127.0.0.1 hotsex-series.com
                Removed hosts entry: 127.0.0.1 www.hotwinupdates.com
                Removed hosts entry: 127.0.0.1 hotwinupdates.com
                Removed hosts entry: 127.0.0.1 www.hqcodectime.net
                Removed hosts entry: 127.0.0.1 hqcodectime.net
                Removed hosts entry: 127.0.0.1 www.hqcodecvip.com
                Removed hosts entry: 127.0.0.1 hqcodecvip.com
                Removed hosts entry: 127.0.0.1 www.hq-downloads.com
                Removed hosts entry: 127.0.0.1 hq-downloads.com
                Removed hosts entry: 127.0.0.1 hqsex.biz
                Removed hosts entry: 127.0.0.1 hugeporn4u.net
                Removed hosts entry: 127.0.0.1 www.iaxobjectdownload.com
                Removed hosts entry: 127.0.0.1 iaxobjectdownload.com
                Removed hosts entry: 127.0.0.1 icansearch.net
                Removed hosts entry: 127.0.0.1 idgsearch.com
                Removed hosts entry: 127.0.0.1 www.idownload.com
                Removed hosts entry: 127.0.0.1 idownload.com
                Removed hosts entry: 127.0.0.1 ie-search.com
                Removed hosts entry: 127.0.0.1 iframe.biz
                Removed hosts entry: 127.0.0.1 www.iframebiz.com
                Removed hosts entry: 127.0.0.1 iframebiz.com
                Removed hosts entry: 127.0.0.1 www.imcodec.com
                Removed hosts entry: 127.0.0.1 imcodec.com
                Removed hosts entry: 127.0.0.1 www.imediacodec.com
                Removed hosts entry: 127.0.0.1 imediacodec.com
                Removed hosts entry: 127.0.0.1 www.imesh.click-new-download.com
                Removed hosts entry: 127.0.0.1 imesh.click-new-download.com
                Removed hosts entry: 127.0.0.1 www.imp3download.com
                Removed hosts entry: 127.0.0.1 imp3download.com
                Removed hosts entry: 127.0.0.1 imrworldwide.com
                Removed hosts entry: 127.0.0.1 www.inc-codec.com
                Removed hosts entry: 127.0.0.1 inc-codec.com
                Removed hosts entry: 127.0.0.1 incestporngate.com
                Removed hosts entry: 127.0.0.1 www.incredimail-download-now.com
                Removed hosts entry: 127.0.0.1 incredimail-download-now.com
                Removed hosts entry: 127.0.0.1 install.searchtab.net
                Removed hosts entry: 127.0.0.1 instlog.winantivirus.com
                Removed hosts entry: 127.0.0.1 www.intcodec.com
                Removed hosts entry: 127.0.0.1 intcodec.com
                Removed hosts entry: 127.0.0.1 www.internetgamebox.com
                Removed hosts entry: 127.0.0.1 internetgamebox.com
                Removed hosts entry: 127.0.0.1 www.internet-media-download.com
                Removed hosts entry: 127.0.0.1 internet-media-download.com
                Removed hosts entry: 127.0.0.1 internetsearch.ru
                Removed hosts entry: 127.0.0.1 www.internetsearchservice.com
                Removed hosts entry: 127.0.0.1 internetsearchservice.com
                Removed hosts entry: 127.0.0.1 www.ipoddownloadingpro.com
                Removed hosts entry: 127.0.0.1 ipoddownloadingpro.com
                Removed hosts entry: 127.0.0.1 www.ipod-itunes-download-now.com
                Removed hosts entry: 127.0.0.1 ipod-itunes-download-now.com
                Removed hosts entry: 127.0.0.1 www.ipod-tunes-download.com
                Removed hosts entry: 127.0.0.1 ipod-tunes-download.com
                Removed hosts entry: 127.0.0.1 ipsex.net
                Removed hosts entry: 127.0.0.1 www.ipspdownload.com
                Removed hosts entry: 127.0.0.1 ipspdownload.com
                Removed hosts entry: 127.0.0.1 iqsearch.net
                Removed hosts entry: 127.0.0.1 www.irfanview-download-now.com
                Removed hosts entry: 127.0.0.1 irfanview-download-now.com
                Removed hosts entry: 127.0.0.1 www.itvdownload.com
                Removed hosts entry: 127.0.0.1 itvdownload.com
                Removed hosts entry: 127.0.0.1 www.ivideocodec.com
                Removed hosts entry: 127.0.0.1 ivideocodec.com
                Removed hosts entry: 127.0.0.1 www.iwantsearch.net
                Removed hosts entry: 127.0.0.1 iwantsearch.net
                Removed hosts entry: 127.0.0.1 www.ixcodec.com
                Removed hosts entry: 127.0.0.1 ixcodec.com
                Removed hosts entry: 127.0.0.1 www.ixcodec.net
                Removed hosts entry: 127.0.0.1 ixcodec.net
                Removed hosts entry: 127.0.0.1 www.jetcodec.com
                Removed hosts entry: 127.0.0.1 jetcodec.com
                Removed hosts entry: 127.0.0.1 www.jmsn.it
                Removed hosts entry: 127.0.0.1 jmsn.it
                Removed hosts entry: 127.0.0.1 junkysex.com
                Removed hosts entry: 127.0.0.1 www.katasearch.com
                Removed hosts entry: 127.0.0.1 katasearch.com
                Removed hosts entry: 127.0.0.1 kb.winantivirus.com
                Removed hosts entry: 127.0.0.1 www.keycodec.com
                Removed hosts entry: 127.0.0.1 keycodec.com
                Removed hosts entry: 127.0.0.1 www.key-codec.com
                Removed hosts entry: 127.0.0.1 key-codec.com
                Removed hosts entry: 127.0.0.1 killerpornstars.com
                Removed hosts entry: 127.0.0.1 kilosex.com
                Removed hosts entry: 127.0.0.1 www.kimsoftware.com
                Removed hosts entry: 127.0.0.1 kimsoftware.com
                Removed hosts entry: 127.0.0.1 kliksearch.com
                Removed hosts entry: 127.0.0.1 www.kliksoftware.com
                Removed hosts entry: 127.0.0.1 kliksoftware.com
                Removed hosts entry: 127.0.0.1 www.kmsn.it
                Removed hosts entry: 127.0.0.1 kmsn.it
                Removed hosts entry: 127.0.0.1 l.mezzicodec.net
                Removed hosts entry: 127.0.0.1 www.lastsoftwares.com
                Removed hosts entry: 127.0.0.1 lastsoftwares.com
                Removed hosts entry: 127.0.0.1 www.lavasoftupdate.com
                Removed hosts entry: 127.0.0.1 lavasoftupdate.com
                Removed hosts entry: 127.0.0.1 www.lesbianpornmag.com
                Removed hosts entry: 127.0.0.1 lesbianpornmag.com
                Removed hosts entry: 127.0.0.1 www.lesbianspornmag.com
                Removed hosts entry: 127.0.0.1 lesbianspornmag.com
                Removed hosts entry: 127.0.0.1 www.lightcodec.com
                Removed hosts entry: 127.0.0.1 lightcodec.com
                Removed hosts entry: 127.0.0.1 www.light-codec.com
                Removed hosts entry: 127.0.0.1 light-codec.com
                Removed hosts entry: 127.0.0.1 www.lightcodec.net
                Removed hosts entry: 127.0.0.1 lightcodec.net
                Removed hosts entry: 127.0.0.1 www.lightspeedsearch.net
                Removed hosts entry: 127.0.0.1 lightspeedsearch.net
                Removed hosts entry: 127.0.0.1 www.limewire.click-new-download.com
                Removed hosts entry: 127.0.0.1 limewire.click-new-download.com
                Removed hosts entry: 127.0.0.1 www.limewire-download-pro.com
                Removed hosts entry: 127.0.0.1 limewire-download-pro.com
                Removed hosts entry: 127.0.0.1 www.limewire-pro-downloads.com
                Removed hosts entry: 127.0.0.1 limewire-pro-downloads.com
                Removed hosts entry: 127.0.0.1 www.linkautomatici.com
                Removed hosts entry: 127.0.0.1 linkautomatici.com
                Removed hosts entry: 127.0.0.1 www.little-download.net
                Removed hosts entry: 127.0.0.1 little-download.net
                Removed hosts entry: 127.0.0.1 www.live.sex-explorer.com
                Removed hosts entry: 127.0.0.1 live.sex-explorer.com
                Removed hosts entry: 127.0.0.1 lovelysearch.com
                Removed hosts entry: 127.0.0.1 luckysearch.net
                Removed hosts entry: 127.0.0.1 lustful-porno.com
                Removed hosts entry: 127.0.0.1 www.macrovirus.com
                Removed hosts entry: 127.0.0.1 macrovirus.com
                Removed hosts entry: 127.0.0.1 www.madsexxx.com
                Removed hosts entry: 127.0.0.1 madsexxx.com
                Removed hosts entry: 127.0.0.1 mafiapics.com
                Removed hosts entry: 127.0.0.1 www.malwarewipeupdate.com
                Removed hosts entry: 127.0.0.1 malwarewipeupdate.com
                Removed hosts entry: 127.0.0.1 massearch.com
                Removed hosts entry: 127.0.0.1 matureporngate.com
                Removed hosts entry: 127.0.0.1 www.maturepornmag.com
                Removed hosts entry: 127.0.0.1 maturepornmag.com
                Removed hosts entry: 127.0.0.1 www.maturespornmag.com
                Removed hosts entry: 127.0.0.1 maturespornmag.com
                Removed hosts entry: 127.0.0.1 www.mcafee-antivirus-2007.com
                Removed hosts entry: 127.0.0.1 mcafee-antivirus-2007.com
                Removed hosts entry: 127.0.0.1 www.medcodec.com
                Removed hosts entry: 127.0.0.1 medcodec.com
                Removed hosts entry: 127.0.0.1 www.media-codec.com
                Removed hosts entry: 127.0.0.1 media-codec.com
                Removed hosts entry: 127.0.0.1 www.mediacodec.net
                Removed hosts entry: 127.0.0.1 mediacodec.net
                Removed hosts entry: 127.0.0.1 www.media-codec.net
                Removed hosts entry: 127.0.0.1 media-codec.net
                Removed hosts entry: 127.0.0.1 www.mediacodec2007.com
                Removed hosts entry: 127.0.0.1 mediacodec2007.com
                Removed hosts entry: 127.0.0.1 www.mediaplayer-download.org
                Removed hosts entry: 127.0.0.1 mediaplayer-download.org
                Removed hosts entry: 127.0.0.1 www.mediaplayer-download-now.com
                Removed hosts entry: 127.0.0.1 mediaplayer-download-now.com
                Removed hosts entry: 127.0.0.1 www.mega-codec.com
                Removed hosts entry: 127.0.0.1 mega-codec.com
                Removed hosts entry: 127.0.0.1 www.mega-codec.net
                Removed hosts entry: 127.0.0.1 mega-codec.net
                Removed hosts entry: 127.0.0.1 www.mega-downloads.net
                Removed hosts entry: 127.0.0.1 mega-downloads.net
                Removed hosts entry: 127.0.0.1 megapornix.com
                Removed hosts entry: 127.0.0.1 www.megasearchbar.com
                Removed hosts entry: 127.0.0.1 megasearchbar.com
                Removed hosts entry: 127.0.0.1 www.megaviruskit.com
                Removed hosts entry: 127.0.0.1 megaviruskit.com
                Removed hosts entry: 127.0.0.1 www.megcodec.com
                Removed hosts entry: 127.0.0.1 megcodec.com
                Removed hosts entry: 127.0.0.1 meta-porn.com
                Removed hosts entry: 127.0.0.1 www.mezzicodec.net
                Removed hosts entry: 127.0.0.1 mezzicodec.net
                Removed hosts entry: 127.0.0.1 miconsultamedica.com
                Removed hosts entry: 127.0.0.1 www.microantivirus.com
                Removed hosts entry: 127.0.0.1 microantivirus.com
                Removed hosts entry: 127.0.0.1 www.microantivirusxp.com
                Removed hosts entry: 127.0.0.1 microantivirusxp.com
                Removed hosts entry: 127.0.0.1 www.micro-codec.com
                Removed hosts entry: 127.0.0.1 micro-codec.com
                Removed hosts entry: 127.0.0.1 www.microsoftantispyware.net
                Removed hosts entry: 127.0.0.1 microsoftantispyware.net
                Removed hosts entry: 127.0.0.1 militarygods.porn4porn.net
                Removed hosts entry: 127.0.0.1 www.miosearch.com
                Removed hosts entry: 127.0.0.1 miosearch.com
                Removed hosts entry: 127.0.0.1 www.mirarsearch.com
                Removed hosts entry: 127.0.0.1 mirarsearch.com
                Removed hosts entry: 127.0.0.1 www.mircosoftantispy.com
                Removed hosts entry: 127.0.0.1 mircosoftantispy.com
                Removed hosts entry: 127.0.0.1 www.mixsearch.com
                Removed hosts entry: 127.0.0.1 mixsearch.com
                Removed hosts entry: 127.0.0.1 www.mmcodec.com
                Removed hosts entry: 127.0.0.1 mmcodec.com
                Removed hosts entry: 127.0.0.1 www.mmcodecs.com
                Removed hosts entry: 127.0.0.1 mmcodecs.com
                Removed hosts entry: 127.0.0.1 moneyhunters.com
                Removed hosts entry: 127.0.0.1 www.mooncodec.com
                Removed hosts entry: 127.0.0.1 mooncodec.com
                Removed hosts entry: 127.0.0.1 www.mooncodec.net
                Removed hosts entry: 127.0.0.1 mooncodec.net
                Removed hosts entry: 127.0.0.1 www.morpheus.click-new-download.com
                Removed hosts entry: 127.0.0.1 morpheus.click-new-download.com
                Removed hosts entry: 127.0.0.1 www.motioncodecs.com
                Removed hosts entry: 127.0.0.1 motioncodecs.com
                Removed hosts entry: 127.0.0.1 www.moviecodec.net
                Removed hosts entry: 127.0.0.1 moviecodec.net
                Removed hosts entry: 127.0.0.1 www.moviecodecs.net
                Removed hosts entry: 127.0.0.1 moviecodecs.net
                Removed hosts entry: 127.0.0.1 www.moviedownloadreview.biz
                Removed hosts entry: 127.0.0.1 moviedownloadreview.biz
                Removed hosts entry: 127.0.0.1 www.movies-codecs.com
                Removed hosts entry: 127.0.0.1 movies-codecs.com
                Removed hosts entry: 127.0.0.1 www.movscodec.com
                Removed hosts entry: 127.0.0.1 movscodec.com
                Removed hosts entry: 127.0.0.1 www.movupdate.com
                Removed hosts entry: 127.0.0.1 movupdate.com
                Removed hosts entry: 127.0.0.1 www.mp3downloadin.net
                Removed hosts entry: 127.0.0.1 mp3downloadin.net
                Removed hosts entry: 127.0.0.1 www.mp3downloadpro.com
                Removed hosts entry: 127.0.0.1 mp3downloadpro.com
                Removed hosts entry: 127.0.0.1 www.mp3downloadsnow.com
                Removed hosts entry: 127.0.0.1 mp3downloadsnow.com
                Removed hosts entry: 127.0.0.1 www.mpegcodec.net
                Removed hosts entry: 127.0.0.1 mpegcodec.net
                Removed hosts entry: 127.0.0.1 www.mpegupdate.com
                Removed hosts entry: 127.0.0.1 mpegupdate.com
                Removed hosts entry: 127.0.0.1 www.mpgcodec.net
                Removed hosts entry: 127.0.0.1 mpgcodec.net
                Removed hosts entry: 127.0.0.1 www.mrantispy.com
                Removed hosts entry: 127.0.0.1 mrantispy.com
                Removed hosts entry: 127.0.0.1 www.msantispy.com
                Removed hosts entry: 127.0.0.1 msantispy.com
                Removed hosts entry: 127.0.0.1 www.msupdate.net
                Removed hosts entry: 127.0.0.1 msupdate.net
                Removed hosts entry: 127.0.0.1 www.msupdater.net
                Removed hosts entry: 127.0.0.1 msupdater.net
                Removed hosts entry: 127.0.0.1 www.mt-download.com
                Removed hosts entry: 127.0.0.1 mt-download.com
                Removed hosts entry: 127.0.0.1 www.musicmatch.free-software-center.com
                Removed hosts entry: 127.0.0.1 musicmatch.free-software-center.com
                Removed hosts entry: 127.0.0.1 www.mybestsearch2007.com
                Removed hosts entry: 127.0.0.1 mybestsearch2007.com
                Removed hosts entry: 127.0.0.1 www.myeasymp3downloadsnow.com
                Removed hosts entry: 127.0.0.1 myeasymp3downloadsnow.com
                Removed hosts entry: 127.0.0.1 www.mymysticporn.com
                Removed hosts entry: 127.0.0.1 mymysticporn.com
                Removed hosts entry: 127.0.0.1 www.mypornmagpass.com
                Removed hosts entry: 127.0.0.1 mypornmagpass.com
                Removed hosts entry: 127.0.0.1 www.mypspdownloading.com
                Removed hosts entry: 127.0.0.1 mypspdownloading.com
                Removed hosts entry: 127.0.0.1 www.mysoftwareprovider.com
                Removed hosts entry: 127.0.0.1 mysoftwareprovider.com
                Removed hosts entry: 127.0.0.1 www.my-software-
                0
            • 1
            • 2
            • 3
            • 4