Unable to download Acrobat Reader

catpeople12 Posted messages 122 Status Membre -  
 BOB3 -
Hello everyone,

I have Windows XP Pro Version 2002 Service Pack 3. After a Zlob attack that I cleaned up well, my Acrobat Reader 8.1.2 started malfunctioning. As a result, I can no longer read PDF files or watch any videos on YouTube because I can't download Flash Player properly. I've tried several times to download the latest version (Flash Player 9), the site tells me it’s downloaded successfully but the Adobe Flash Player Plugin icon that appears on the list of programs in my Control Panel has a little red X in the corner and no size in MB...

To continue, I consulted forums that suggested uninstalling Acrobat and downloading it again afterward. Like a good soldier, I uninstalled Acrobat from my computer and now I can't download it from anywhere!!! Every time I try to do it, I get a weird error message telling me that my computer is running Windows 2000 (!!??) and that I need to upgrade my computer to Windows 2000 SP 4 (!!??) in order to download Adobe Reader 8.1.2. I don’t understand this story at all and would like to know if anyone could help me...

As a side note, I downloaded Foxit Reader to read PDF files; I was still able to download Adobe Air and Adobe Media Player (which did not resolve my problem with watching videos on YouTube!!). And in case someone thinks to ask me, I have Java properly installed on my computer (even got the latest update!!, yes sir!)

So... HELP!!!!!!!

AND THANK YOU IN ADVANCE!

CP12
Configuration: Windows XP Internet Explorer 7.0

74 réponses

  • 1
  • 2
  • 3
  • 4
rebitus
 
Hi,
A Windows 2000 version (!!??) and that I have to upgrade my computer to Windows 2000 SP 4
SP4 for Windows 2000 is almost mandatory, we can't do anything without it. We just need to find SP4 for Windows 2000. However, I don't know if it's available for direct update since it's old and usually people have stored it directly on their hard drive.
For Acrobat, they are probably in security maintenance. There were issues, and they closed some downloads. They are also working on releasing new online products.
0
catpeople12 Posted messages 122 Status Membre
 
Thank you for your advice, Rebitus!

I'm going to check the Windows Update site to see what I can find about W 2000 SP4, and I'll keep you posted if it allows me to download Acrobat.

(I hope that the inability to download the latest version of this software is due to what you mentioned about their site)

See you!

Catpeople12
0
catpeople12 Posted messages 122 Status Membre
 
Hello Rebitus and everyone who might help me!

I found Windows 2000 SP4 on the Windows Update site thanks to Rebitus's advice, for which I am grateful.

I started downloading it but before the download finished, the following error message appeared:

The installer could not verify the integrity of the Update.inf file. Make sure the Cryptographic Service is running on this computer.

So I went to check in the Control Panel / Administrative Tools / Services / Cryptographic Services and the properties indicate that it is Started as Automatic.

So I have a problem! Right?

But I don’t know what it is or how to fix it!!!.....

HEEEEELP!!!!!
0
catpeople12 Posted messages 122 Status Membre
 
Re-hello everyone,

I've also just realized that I can't even download Adobe Flash Player. The Adobe site keeps telling me that the download was successful, but the software is nowhere to be found on my computer.

The only thing that's there is Java, which works perfectly.

So either the Adobe site has issues, or my computer has a problem that I can't seem to identify! However, the computer's cryptography services are enabled, browsing the Internet and all displays on my computer are working very quickly as usual...

Not being a tech expert, I really need help from someone who knows what they're doing...

Thank you in advance everyone!

Catpeople12
0
catpeople12 Posted messages 122 Status Membre
 
Hello everyone,

I believe I know why I can't download Adobe. It's because my computer apparently no longer has SP4 for Windows 2000. I went looking for it on the Internet and the download started fine. But at the time of installation, I received the following error message:

"The installer could not verify the integrity of the file Update.inf. Please make sure that the Cryptographic Service is running on this computer."

According to the instructions given on this forum to those who have the same problem, I went to Control Panel => Administrative Tools => Services => Cryptographic Services, I looked for the service properties and it is enabled in automatic mode. I even restarted the service and rebooted the computer. But after another attempt to download SP4 for Win 2000, the same message appeared again! I don't understand what's happening...

Can anyone please advise me on how to resolve this issue?

Thank you!

CP12
0
BOB3
 
Hello everyone,
a question for catpeople12,

you say you're equipped with XP Pro SP3, I don't see why you're switching to XP 2000 + SP4 etc..
please confirm which exact version you have on your machine, I will try to find you a solution
see you later
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
Hi BOB3 and thanks for your reply.

I am on Windows XP Pro Version 2002 Service Pack 3. I'm trying to download Win 2000 SP4 just because every time I've tried to download the latest version of Acrobat, I get a message saying something like "the version 2000 you are using does not accept this file. Please update to Windows 2000 sp4 before downloading it".

I thought that Win 2000 SP4 was a necessary component for my system that would allow me to download the latest version of Acrobat. What do you think?

At the same time, I can't even download the latest version of Acrobat Flash Player on my system, which prevents me from watching videos on YouTube.

It would be great if you could find me a solution!

THANK YOU and see you soon!

catpeople12
0
BOB3
 
Re catpeople12,

forget win2000,

restart in safe mode and try to completely uninstall ADOBE--you will reinstall it later.

you will check the integrity of your XP files afterwards
put your installation CD in the main CD drive
click on start, run, and type: sfc /scannow
look at the link
https://www.pcastuces.com/pratique/windows/xp/default.htm
and let it do its thing,
restart,
then you will run Microsoft onecare at this link
https://www.msn.com/fr-fr/
launch the link, accept the activex, and click on full scan.
it will take some time, windows will clean everything and restore your registry.
let it finish, reboot, and keep us updated.
see you later
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
Hi BOB3!

I will follow your instructions and I'll let you know as soon as I'm done.

THANK YOU SO MUCH!!

See you!

catpeople12
0
catpeople12 Posted messages 122 Status Membre
 
Re BOB3,

The first part of your instructions worked like a charm (Thank you!)! I indeed had corrupted .dll files due to a Trojan horse (Zlob) that I caught a week ago (despite my Kaspersky) and I was able to remove it by following recommendations on this Forum. So all the damaged protected files have been repaired or restored with my XP CDROM. I also completely removed Adobe from my computer. I owe you one big time!

However, something strange is happening with the second link to Windows Onecare that you gave me. When I click on Full Scan to start the scanner, a dialog window that shows the status of the scan appears. But shortly after, a small dialog box pops up in the Onecare window telling me that there was a script error on the page with Explorer and if I still want to continue. I click Yes and the W. Onecare window turns into just a frame with only the borders and won’t close; I can only minimize it... To make it disappear I have to restart the computer. I reconnect to Onecare, try again and the same thing happens... I have no indication that something is happening...

Not being very familiar with W. Onecare, could you tell me if this is normal? I think there must be a glitch, but I’m not a tech whiz...

Looking forward to your advice and thanking you again for your help, I send you my best regards.

catpeople12
0
BOB3
 
Good evening catpeople12,

I’m glad you were able to repair your system files,
the script error is related to your IE7 browser, I hope it’s not damaged.
Open Internet Explorer properties,
1--in General, then the 2 settings for searches + tabs, click on settings and set to default.
2--in Security, set everything to default
3--in Privacy, set it to default to automatically accept Microsoft cookies-----I recommend afterwards setting it to High
4--in Advanced, click on Restore advanced settings --- only.

And try to connect to oncare again.
See you later
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
Hello BOB3,

Thanks again for your great advice!!!

I followed your instructions regarding IE7, and the same thing happened when I tried to download the onecare scanner to start the full analysis... A script error occurred, and then it started spinning with no response. I had to disable the page using the task manager.... However, I added onecare as a trusted site in IE7 and Kaspersky...

Maybe IE7 is damaged as you think, and I don't know how to fix it if that's the case...

Could you help me again, please?

Thanks!

catpeople12
0
BOB3
 
Hello catpeople12,

download IE7 again, install it + update without forgetting to reconfigure as specified in 11

http://www.microsoft.com/downloads/details.aspx?FamilyId=9AE91EBE-3385-447C-8A30-081805B2F90B&displaylang=en

go to onecare again, and do a full scan.
keep me updated.
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
Good evening BOB3,

Alright! Reporting in... I downloaded IE7 again and everything went well. All its settings are also set to default according to your advice. (Anyway, with the download everything comes by default)

However, the problem with Onecare persists nonetheless... Still the same old script error on the page that blocks everything and prevents me from running the full scan... I don't know what to do anymore!... I’m starting to believe that this site doesn't like my computer, even if my computer trusts it...

Do you have another idea up your sleeve?...

Thank you once again for your help, and best regards,

catpeople12
0
BOB3
 
Good evening catpeople,

go to the control panel, click on Java, update it,
still on Java, disable the auto-update, and in Advanced,
then, for Java defaults in browsers, set it to Internet Explorer.
reboot, and in Internet Explorer properties, open Advanced, scroll down,
under Browsing, check both boxes ----disable script debugging
we'll see.
see you+
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
Hello BOB3

I went to Java. I clicked on update now but it tells me that I have the very latest version of Java installed on my computer which is functioning. I disabled automatic updates but Internet Explorer was already checked as the default browser on Java.

Then I rebooted and went to Internet Properties/Advanced/Navigation. The two script debugging boxes were already checked.

I will try again with Onecare and keep you posted.

THANKS again!

catpeople12
0
catpeople12 Posted messages 122 Status Membre
 
Re BOB3!

Well, after following the instructions for Java and IE, it still doesn't work... There is still that damned script error on the page and I have to close it with Task Manager...

It's crazy!!!!! ... ...

Looking forward to your advice, thank you again and best regards,

catpeople12
0
BOB3
 
Hi catpeople,
repost the exact message that the system gives you when you're on one care.
cya
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
Hello BOB3!

Here is the exact message:

!
An error occurred in the script on this page
Line: 26
Character : 1
Error: Object expected
Code: 0
URL: about: blank

Do you want to continue executing scripts on this page?

Yes No


Whether I click Yes or No doesn't change anything; it's just spinning and I have nothing left...

I hope this helps you figure out where it's coming from.

Thanks again and

See you later

catpeople12
0
BOB3
 
Re catpeople,
download Hijackthis from this link, install it in auto mode,
ftp://ftp.commentcamarche.com/download/HJTInstall.exe

click on its icon on the desktop, and do: Do a system scan and save logfile
copy/paste in the post
see you later
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
Hello BOB3,

Here is the scan result:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:58:44, on 07/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\System32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\Ati2evxx.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\windows\Explorer.EXE
C:\WINDOWS\System32\brss01a.exe
C:\windows\system32\spoolsv.exe
C:\windows\SOUNDMAN.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\yodm 3D\Yodm3D.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\MI3AA1~1\wcescomm.exe
C:\windows\system32\ctfmon.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\windows\system32\cisvc.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\system32\LVComS.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\windows\system32\svchost.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\windows\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9989F1F6-70DE-4244-AC9F-6672983681A0} - (no file)
O2 - BHO: (no name) - {A49E097A-D6EF-4B2F-8B0F-1230E998587F} - C:\Program Files\Web Technologies\iebt.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: 238044 helper - {C0F371D7-926D-4700-B65E-63BFF1197205} - C:\WINDOWS\system32\238044\238044.dll (file missing)
O3 - Toolbar: Internet Service - {F99D0C20-F8E1-43B6-AB24-3F16BFAEA77B} - C:\Program Files\Web Technologies\iebr.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [Yodm3D] C:\Program Files\yodm 3D\Yodm3D.exe
O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [I&F Viewer toolbar] "C:\Program Files\Photo Toolkit\ivbar\phototoolkitmem.exe" -start
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: MyTrashCan.lnk = C:\Program Files\Hiro's tool\MyTrashCan\MyTrashCan.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O8 - Extra context menu item: Add to Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
O9 - Extra button: Internet Security Statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create a mobile favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11D2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://www.1001interims.com
O15 - Trusted Zone: https://www.adobe.com/
O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
O15 - Trusted Zone: https://www.ustart.org
O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
O15 - Trusted Zone: https://www.msn.com/fr-fr/
O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
O15 - Trusted Zone: https://fr.yahoo.com/
O15 - Trusted Zone: https://www.youtube.com/
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.serviceshub.microsoft.com/supportforbusiness/create
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-e84a02c34e2ab3f9.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?e=1214407856230&h=460b6a4386982a6d227dd6ec47e07839/&filename=jinstall-6u6-windows-i586-jc.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MicroSoft Media Tools - Unknown owner - C:\WINDOWS\MSmedia.exe (file missing)
O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

--
End of file - 12393 bytes

Hoping this report will help you find the problem and thanking you again for your help,

catpeople12
0
BOB3
 
Hello catpeople12,
A good number of problems to fix

Download Ccleaner, install it without the YAHOO toolbar
in applications check everything
Launch it and perform a complete cleanup: cleaner then registry

1---To start, you will uninstall to fix a disorder in the registry
windows live messenger, you will reinstall it later without the ads sponsors.
windows live onecare
logitech webcam---you will reinstall it later

2--You have a proxy service that needs to be disabled
in internet explorer properties, then connections, network settings, and disable everything

3--Go to start, control panel, regional and language options, languages, details, advanced,
and check to stop advanced text services.

4--Launch msconfig.exe, then startup, and if it exists, disable
ctfmon.exe
LVComS.exe

Restart your computer in safe mode,
launch Hijackthis in Do a system Scan
check the following keys, then click at the bottom left on: Fix Checked
C:\WINDOWS\system32\LVComS.exe

O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: (no name) - {9989F1F6-70DE-4244-AC9F-6672983681A0} - (no file)

O2 - BHO: (no name) - {A49E097A-D6EF-4B2F-8B0F-1230E998587F} - C:\Program Files\Web Technologies\iebt.dll (file missing)
O2 - BHO: 238044 helper - {C0F371D7-926D-4700-B65E-63BFF1197205} - C:\WINDOWS\system32\238044\238044.dll (file missing)
O3 - Toolbar: Internet Service - {F99D0C20-F8E1-43B6-AB24-3F16BFAEA77B} - C:\Program Files\Web Technologies\iebr.dll (file missing)

O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Yodm3D] C:\Program Files\yodm 3D\Yodm3D.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: MyTrashCan.lnk = C:\Program Files\Hiro's tool\MyTrashCan\MyTrashCan.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.serviceshub.microsoft.com/supportforbusiness/create
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPUpld.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-e84a02c34e2ab3f9.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: MicroSoft Media Tools - Unknown owner - C:\WINDOWS\MSmedia.exe (file missing)
O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)

Launch Ccleaner, perform a complete cleanup

Reboot in normal mode, and reinstalls a new Hijackthis log.
See you later
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
Re-BOB3 and THANK you again for your help!

I followed your instructions to the letter. Before I submit the new Hijackthis log, and in case it might be important, I want to inform you that after the System Scan of Hijackthis in Safe Mode, the following keys were missing from the list, which appeared on the one you previously told me to check:

C:\WINDOWS\system32\LVComS.exe
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab

Once the found keys were checked, I clicked Fix Checked and during the process, the following message appeared:

Impossible to repair 010 Winsock LSP entries
Use LSP Fix, which can be downloaded at http://www.cexx.org/lspfix.htm

If the 010 item belongs to WebHancer, New.Net or Common/Name, Spybot S&D can remove it automatically.


I then took the opportunity to run a scan with Spybot and no spyware was found.

I restarted the computer and immediately received a Windows security update (KP950759) for IE7.

And here is the new Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:56:38, on 07/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\System32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\MI3AA1~1\wcescomm.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\windows\system32\cisvc.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\PSIService.exe
C:\windows\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O8 - Extra context menu item: Add to Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menu item: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
O9 - Extra button: Internet Anti-Virus Statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menu item: Create a mobile favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menu item: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://www.1001interims.com
O15 - Trusted Zone: https://www.adobe.com/
O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
O15 - Trusted Zone: https://www.ustart.org
O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
O15 - Trusted Zone: https://www.msn.com/fr-fr/
O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
O15 - Trusted Zone: https://fr.yahoo.com/
O15 - Trusted Zone: https://www.youtube.com/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

--
End of file - 7829 bytes


I am waiting for your news!

Best regards,

catpeople12
0
BOB3
 
Re catpeople12,

we're making progress,
1--a question to confirm,
if I understood correctly, you did delete
--->C:\WINDOWS\system32\LVComS.exe
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab

if not, you can fix them with Hijackthis in normal mode.

download LSP Fix from this link developed by (IUP / Indiana University of Pennsylvania)
http://old.www.iup.edu/house/resnet/WinsockXPFix.exe

BUT DO NOTHING FOR NOW.
waiting for your response, I'm analyzing your log
see you soon
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
Re, BOB3!

I'm really happy that it's moving forward!!

Your help is really valuable to me ( even though 90% of the time I don't quite understand what I'm doing... ) and I will continue to follow your instructions to the letter.

As for the question you wanted to confirm:

I did not delete the keys that I listed for you and that you mentioned in your question.
They simply did not appear on the list of keys that showed up after scanning with Hijackthis in safe mode...

Is it serious?

I'm downloading LSP Fix and I'm awaiting your instructions.

A+

catpeople12
0
BOB3
 
Re catpeople12,

1---to verify, in the log I notice that your Kaspersky antivirus launches 3 times
check the list of services at the beginning
from
Boot mode: Normal ----> until c:\program files\trend micro\hijackthis\hijackthis.exe

2--go to c:\windows\Downloaded Program Files--->and delete all installed activex
right-click, then delete
as you go, you will accept the windows activex again

3---you need to do the same operation with HJT, and perform a Fix checked on the following keys
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

you run Ccleaner, reboot and send a new log.
see you later
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
Re, BOB3!

I just saved LSP Fix on my desktop while waiting for your instructions.

Important question before proceeding:

Should I remove the ActiveX controls in c:\windows\Downloaded Program Files and perform the second operation with HJT and the key repairs in Safe Mode or right away in normal mode?

Over to you, boss!

Best regards,

catpeople12
0
catpeople12 Posted messages 122 Status Membre
 
Re, BOB3,

You're right! Kaspersky launches 3 times according to log 2 of HJT...
Is there any manipulation to do to resolve this if it's abnormal?

I'm waiting for your instructions to delete the ActiveX in C:\Windows\Downloaded Program Files, then to run HJT again and repair the keys you identified, either in safe mode or normal mode.

In which mode should I perform both actions, please?

THANK YOU!

A+

catpeople12
0
BOB3
 
Re catepeople,

1--activex in normal mode
2--for the Fix, you do it in normal mode, if there are remaining traces, in safe mode.

I'm putting other actions for you to do, take your time, and proceed with caution.
see you later
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
Re BOB3,

Report until message 28:

HJT Log 2:


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:56:38, on 07/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\System32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\MI3AA1~1\wcescomm.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\windows\system32\cisvc.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\PSIService.exe
C:\windows\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O8 - Extra context menu item: Add to Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menu item: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
O9 - Extra button: Internet Antivirus Statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menu item: Create a mobile favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menu item: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://www.1001interims.com
O15 - Trusted Zone: https://www.adobe.com/
O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
O15 - Trusted Zone: https://www.ustart.org
O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
O15 - Trusted Zone: https://www.msn.com/fr-fr/
O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
O15 - Trusted Zone: https://fr.yahoo.com/
O15 - Trusted Zone: https://www.youtube.com/
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

--
End of file - 7829 bytes



Missing keys on the HJT list that I had to check:

016 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB

016 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

Once the other keys were checked, I launched the Fix and the same message: HJT cannot repair 010 Winsock LSP entries. You should use LSP Fix for that...

HJT Log 3 before reboot once the manipulations have been accomplished:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:51:15, on 07/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\System32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\windows\system32\spoolsv.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\PROGRA~1\MI3AA1~1\wcescomm.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\PROGRA~1\MI3AA1~1\rapimgr.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\windows\system32\cisvc.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\PSIService.exe
C:\windows\system32\svchost.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\windows\system32\cidaemon.exe
C:\windows\system32\NOTEPAD.EXE
C:\windows\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O8 - Extra context menu item: Add to Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\windows\system32\shdocvw.dll
O9 - Extra 'Tools' menu item: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\windows\system32\shdocvw.dll
O9 - Extra button: Internet Antivirus Statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra 'Tools' menu item: Create a mobile favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menu item: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://www.1001interims.com
O15 - Trusted Zone: https://www.adobe.com/
O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
O15 - Trusted Zone: https://www.ustart.org
O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
O15 - Trusted Zone: https://www.msn.com/fr-fr/
O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
O15 - Trusted Zone: https://fr.yahoo.com/
O15 - Trusted Zone: https://www.youtube.com/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

--
End of file - 7687 bytes

HJT Log 4 after reboot:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:29:10, on 07/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\System32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\brsvc01a.exe
0
BOB3
 
Re catpeople12,

traces of trojans to eradicate

1---Uninstall the Zango program via Add/Remove Programs (if you find it)

2---Download SDFix from AndyManchesta and save it to your Desktop.
http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

Double click on SDFix.exe and choose Install to extract it to a dedicated folder on the Desktop.
Restart your computer in Safe Mode.

Open the SDFix folder that has just been created in the C:\ directory and double click on RunThis.bat to launch the script.
Press Y to start the cleanup process.

It will delete services and Registry entries of certain trojans found and will then ask you to press a key to reboot.
So press a key.

Your system will take longer to reboot than usual because the tool will continue to run and delete files.

After loading the Desktop, the tool will finish its work and display Finished.
Press a key to complete the execution of the script and load your Desktop icons.

Once the Desktop icons are displayed, the SDFix report will open on the screen and will also be saved in the SDFix folder as Report.txt. You will need to paste this report in your next reply.

3-----Press Ctrl + Alt + Delete to open the Task Manager.
Select the Processes tab
In the Image Name column, check if you find
the process zango.exe
Right-click on it and choose End Process
Then look for the process mnew1winc4.exe
Right-click on it and choose End Process

4-----Restart HijackThis and check the following lines if you find them

O2 - BHO: Zango Search Assistant Helper /fleok=1D8A83A5C1E0197791AE75760EA83FA5EF80752B94E2DE7E5A7A47203BCF - {56F1D444-11BF-4879-A12B-79CF0177F038} - c:\program files\zango\zangohook.dll
O4 - HKLM\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe
O4 - HKLM\..\Run: [Memory manager] C:\WINDOWS\System32\himem32.exe
O4 - HKLM\..\Run: [zango] "c:\program files\zango\zango.exe"
O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\System32\rpcc.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
O4 - HKLM\..\RunServices: [Printer] C:\WINDOWS\System32\auditchk.exe
O4 - HKCU\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe
O4 - HKCU\..\Run: [dpr0] C:\WINDOWS\system32\prod.exe
O4 - HKCU\..\Run: [chsr] C:\WINDOWS\system32\lssrvc.exe
O4 - HKCU\..\Run: [mlrnew1c4] C:\WINDOWS\system32\mnew1winc4.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O20 - Winlogon Notify: rpcc - C:\WINDOWS\System32\rpcc.dll (file missing)
O20 - Winlogon Notify: rpccd - C:\WINDOWS\System32\rpccd.dll

Click on Fix Checked and confirm the following message.

5----With Windows Explorer, search for the following files/folders and delete them (if still present):
c:\program files\zango <-- The folder
C:\WINDOWS\System32\auditchk.exe (Be careful with the spelling)
C:\WINDOWS\System32\himem32.exe (Again, be careful with the spelling)
C:\WINDOWS\System32\rpcc.exe
C:\WINDOWS\system32\prod.exe
C:\WINDOWS\system32\lssrvc.exe
C:\WINDOWS\system32\mnew1winc4.exe
C:\WINDOWS\System32\rpcc.dll
C:\WINDOWS\System32\rpccd.dll

6--run Ccleaner, clean up, reboot, and post the log Report.txt from Sdfix.
a+
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
Hello BOB3!

No traces of zango anywhere; no process in the Task Manager, none of the keys you asked me to check or any files searched with Windows Explorer were found... (COOL!)


During the SDFix analysis, the following message appeared:

Note: Protective Host Files such as MVPS/HP hosts or Spybot Immunizers must be applied after SDFix analysis

I have Spybot S&D and it immunizes the system. Should I do it?


Here's the SD Fix report:


[b]SDFix: Version 1.202 [/b]
Run by Carlo on 07/07/2008 at 15:56

Microsoft Windows XP [version 5.1.2600]
Running From: C:\DOCUME~1\Carlo\Desktop\SDFix

[b]Checking Services [/b]:

[b]Name [/b]:
MicroSoft Media Tools

[b]Path [/b]:
"C:\WINDOWS\MSmedia.exe"

MicroSoft Media Tools - Deleted



Restoring Default Security Values
Restoring Default Hosts File

Rebooting


[b]Checking Files [/b]:

Trojan Files Found:

C:\Documents and Settings\Carlo\My Documents.url - Deleted
C:\Documents and Settings\Carlo\My Documents\CARLO\AUDIOVISUEL C & S\Our Music\My Music.url - Deleted
C:\Documents and Settings\Carlo\My Documents\AUDIOVISUEL C & S\Our Videos\My Video.url - Deleted
C:\windows\system32\TFTP1684 - Deleted
C:\windows\system32\TFTP2892 - Deleted
C:\Program Files\Setup.exe - Deleted
C:\tmp.reg - Deleted





Removing Temp Files

[b]ADS Check [/b]:



[b]Final Check [/b]:

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-07 16:04:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


[b]Remaining Services [/b]:




Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"c:\\irpll7l.exe"="C:\\irpll7l.exe:*:Enabled:Server"
"Windows Firewall Monitor"="C:\\dinst.exe:*:enabled:svchost"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\eChanblard\\emule.exe"="C:\\Program Files\\eChanblard\\emule.exe:*:Enabled:eMule"
"C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.6\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.6\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
"C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.5\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.5\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
"C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.4\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.4\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
"C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.3\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.3\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
"C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.2\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.2\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
"C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\Fp2006.exe:*:Disabled:Spy Shooter 2006"
"C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\FlowService.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\FlowService.exe:*:Disabled:Spy Shooter 2006"
"C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\Fp2006.exe:*:Disabled:SpyShooter2006"
"C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\FlowService.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\FlowService.exe:*:Disabled:SpyShooter2006"
"C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\Fp2006.exe:*:Disabled:Spy Shooter 2006"
"C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\FlowService.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\FlowService.exe:*:Disabled:Spy Shooter 2006"
"C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"="C:\\Program Files\\VideoLAN\\VLC\\vlc.exe:*:Enabled:VLC media player"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\messenger\\msmsgs.exe"="C:\\Program Files\\messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"c:\\irpll7l.exe"="C:\\irpll7l.exe:*:Enabled:Server"
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
"C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
"C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

[b]Remaining Files [/b]:


File Backups: - C:\DOCUME~1\Carlo\Desktop\SDFix\backups\backups.zip

[b]Files with Hidden Attributes [/b]:

Sat 21 Jun 2008 212 A.SH. --- "C:\BOOT.BAK"
Fri 13 May 2005 217,073 A.SHR --- "C:\WINDOWS\meta4.exe"
Mon 24 Oct 2005 66,560 A.SHR --- "C:\WINDOWS\MOTA113.exe"
Thu 13 Oct 2005 422,400 A.SHR --- "C:\WINDOWS\x2.64.exe"
Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
Tue 17 Apr 2007 168 ..SHR --- "C:\WINDOWS\system32\0E3DD7342B.sys"
Fri 28 Oct 2005 308,224 A.SH. --- "C:\WINDOWS\system32\avisynth.dll"
Thu 14 Jul 2005 27,648 A.SHR --- "C:\WINDOWS\system32\AVSredirect.dll"
Sun 26 Jun 2005 616,448 A.SHR --- "C:\WINDOWS\system32\cygwin1.dll"
Tue 21 Jun 2005 45,568 A.SHR --- "C:\WINDOWS\system32\cygz.dll"
Sun 25 Jan 2004 70,656 A.SHR --- "C:\WINDOWS\system32\i420vfw.dll"
Tue 17 Apr 2007 2,516 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
Sun 21 Jan 2001 63,488 A..H. --- "C:\WINDOWS\system32\MMRegOCX.exe"
Thu 27 Apr 2006 2,945,024 A.SHR --- "C:\WINDOWS\system32\Smab.dll"
Mon 28 Feb 2005 240,128 A.SHR --- "C:\WINDOWS\system32\x.264.exe"
Sun 25 Jan 2004 70,656 A.SH. --- "C:\WINDOWS\system32\yv12vfw.dll"
Sun 14 May 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sat 24 Nov 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
Fri 18 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4658aca27402c0ea318a0615f08905ca\BIT42.tmp"
Fri 18 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\6092debe4959b217a6aac6c11cc1dd60\BIT48.tmp"
Sun 14 May 2006 4,348 A..H. --- "C:\Documents and Settings\Carlo\My Documents\CARLO\AUDIOVISUEL C & S\Our Music\License Backup\drmv1key.bak"
Fri 16 Jun 2006 20 A..H. --- "C:\Documents and Settings\Carlo\My Documents\CARLO\AUDIOVISUEL C & S\Our Music\License Backup\drmv1lic.bak"
Sun 26 Feb 2006 312 A..H. --- "C:\Documents and Settings\Carlo\My Documents\CARLO\AUDIOVISUEL C & S\Our Music\License Backup\drmv2key.bak"
Fri 16 Jun 2006 1,536 A..H. --- "C:\Documents and Settings\Carlo\My Documents\CARLO\AUDIOVISUEL C & S\Our Music\License Backup\drmv2lic.bak"

[b]Finished![/b]

catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-07-07 16:04:47
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

Otherwise, should I do something with WinsockXPFix that I downloaded?

Looking forward to your new instructions, best regards!

catpeople12
0
BOB3
 
Re catpeople12,

thank you for putting your responses in order, it prevents me from going back and forth,

to summarize,
1--you delete all the ActiveX in normal mode
2--you set aside the Kaspersky issue, we will deal with it later
3--if you haven't found the other keys, it's because they have been deleted

the most important
4--you run SDFIX as indicated in 29 and you put its report --- copy and paste

see you soon
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
RESPONSE TO MESSAGE 33 FROM BOB

Re, BOB3

I'm really sorry that you're going back and forth because of me!!...

I thought I had followed the order of your advice messages...

I'll summarize to make your life easier. There are two important messages for you from me:

A - My message N° 31, which responds to your messages 24, 25, and 28, where I posted the Hijackthis logs that you requested.

B - My message N° 32, which responds to your message 29, where you will find the SDFix report that you asked for. As agreed, I deleted the ActiveX and did nothing with Kaspersky or LSP Fix that I was supposed to download (See your message N° 24).

I was just waiting for you to read the SDFix report to know what to do next.

Thanks, sorry again, and see you later!

catpeople12
0
BOB3
 
Re catpeople12,

for verification + modification

1---The following registry keys are added to run processes after reboot:
you open regedit.exe ----- with caution
you search for these keys and delete them

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
• "Printer"="%SYSDIR%\auditchk.exe"

– [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
• "Printer"="%SYSDIR%\auditchk.exe"

– [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
• "Printer"="%SYSDIR%\auditchk.exe"

2--then you search for the following keys and possibly modify them
the keys should be as follows:

– [HKLM\SOFTWARE\Microsoft\Ole]

Name Type Value

• "EnableDCOM"= REG_SZ N

– [HKLM\SYSTEM\CurrentControlSet\Control\Lsa]

• "restrictanonymous"= REG_DWORD 0X00000002 (2)

you close,

3---you note all the files you find
you search your disk for all files located in Temp, and delete them
c:\temp\xxxxxxx.xxxx

c:\documents and settings\administrator\local settings\temp
and you check in the other accounts found in c:\documents and settings\xxxxxxxx\local settings\temp

c:\windows\temp
c:\windows\system32\temp

and you give me the list
a+
BOB3

you reboot,

you run a scan with Spybot,

and you provide a new HijackThis log

a+
BOB3
0
BOB3
 
Re catpeople12,

let's continue from 34 + this post.

forget the hijackthis + spybot reports for now,
the SDFIX report is not great

1---do what is requested in 34

2--I asked you to uninstall windows live messenger in 22, it still appears in the SDFIX report.

1--have you uninstalled microsoft live messenger, if not uninstall it
2--also uninstall microsoft active sync--it is infected----you will reinstall it after cleaning
3--also uninstall microsoft network diagnostic --- it is useless
4--uninstall spybot --- it is infected --- see below

clean up with Ccleaner, delete everything

download spybot again from this link
ftp://ftp.commentcamarche.com/download/spybotsd152.exe

install it, + update + launch the vaccination so that the counters are identical

then configure it as follows.

launch Spybot, then click on Mode at the top, then check Advanced mode
then on tools and check all boxes under tools.
click on System startup, which allows you to remove unwanted or superfluous programs that you can check and delete
click on System interior, run verify, and check them one by one, then click on fix problems
click on Hosts files, to update the list of unwanted sites, and redo this every time Spybot is updated
click on IE adjustment, and check all lock boxes
click on browser pages, and double click on all the links, one by one, and when it opens, delete the content
and click Ok
click on BHOs, and remove everything----> except those from your antivirus+Spybot
click on ActivX, and remove everything----> except those from windows+office+genuine advantage+Shockwave if present
click on Resident, and check both boxes.
and once a day before shutting down your computer,
click on Security Eraser, and click on Templates, then click on the list one by one, and click at the bottom
on Shred to clean everything.

finally run Ccleaner, and do a reboot.

launch Spybot for a complete scan, and give me the results.
a+
BOB3
0
catpeople12 Posted messages 122 Status Membre
 
RESPONSE TO MESSAGES 34 AND 36 FROM BOB3

Hello BOB3!

I'm replying to your messages in order to make it easier for you.

MESSAGE 34

Verification and modification

1 - The registry keys "Printer"="%SYSDIR%\auditchk.exe" were not present in [HKLM\SOFTWARE\Microsoft\Windows\Current Version\Run] nor in [....\RunServices], nor in [HKCU\....\Run]


2 - The following keys were incorrect and I modified them according to your instructions:

[HKLM\SOFTWARE\Microsoft\Ole] had a value Y which I changed to N as indicated.

[HKLM\SYSTEM\CurrentControlSet\Control\Lsa] had a value 0 which I changed to 2 as indicated.


3 - List of files found in Temp to submit to you:

c:\temp
"debug"
folder 38bb9e8aacbb4470e2 containing %temp%dd_msxml_retMSI
deleted

c:\documents and settings\xxxx\local settings\temp
WCESCOMM
ISTMP1.DIR
sv457.tmp
deleted

WCESLog - UNABLE TO DELETE

c:\windows\temp
WGAErrlog
WGANotify.settings
deleted

c:\windows\system32\temp
folder URTTemp containing: fusion.dll; mscoree.dll; mscoree.dll.local; mscorns.dll; mscorwks.dll; msvcr.dll
I DID NOT DARE TO DELETE IT BECAUSE THERE ARE TOO MANY UNKNOWN .dll FILES FOR ME. CAN I DELETE IT?

inetsrv
ASP Compiled Templates (empty folder)
deleted

MESSAGE 36

1 - I did what was requested in 34

2- Uninstallations:
a) I uninstalled the Windows Live components that were still installed
b) I uninstalled Microsoft Active Sync (I don't really need it)
c) Microsoft Network Diagnostic is not in my system
d) I uninstalled the old Spybot S&D

I cleaned up with CCleaner and deleted everything

I downloaded Spybot S&D from the link you gave me and followed your instructions to the letter.

I cleaned again with CCleaner as requested and rebooted

I ran a complete scan with Spybot, which found nothing unusual in the results.

This morning upon starting the computer, Spybot did another complete scan and there are no trackers.


P.S.

I have not yet used LSP Fix, I have not yet downloaded Windows Live nor reinstalled my Labtec webcam while waiting for your instructions.

Best regards,

catpeople12
0
catpeople12 Posted messages 122 Status Membre
 
NEW

Re BOB3,
I took the liberty of running another HJT scan, and I’m sharing the log with you so you can see the current state of the system. I hope I’m not bothering you too much...

Additionally, I can no longer access the internet options in the browser...

The following error message appears when I try to access it:
X This operation has been canceled due to restrictions in effect on this computer. Please contact your System Administrator.


And here is the very latest HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:43:15, on 08/07/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\System32\Ati2evxx.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\Ati2evxx.exe
C:\windows\Explorer.EXE
C:\WINDOWS\System32\brsvc01a.exe
C:\WINDOWS\System32\brss01a.exe
C:\windows\system32\spoolsv.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
C:\windows\system32\cisvc.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\windows\system32\svchost.exe
C:\windows\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Add to Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Internet Anti-Virus Statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: http://www.1001interims.com
O15 - Trusted Zone: https://www.adobe.com/
O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
O15 - Trusted Zone: https://www.ustart.org
O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
O15 - Trusted Zone: https://www.msn.com/fr-fr/
O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
O15 - Trusted Zone: https://fr.yahoo.com/
O15 - Trusted Zone: https://www.youtube.com/
O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)

--
End of file - 5453 bytes



Thanks and A+ for your patience!

catpeople12
0
BOB3
 
Hello catpeople12,

WCESLog - CANNOT BE REMOVED
remove it in safe mode,

leave LSP Fix aside for now, I’m waiting for a response if it is compatible with XP in French.

you are going to download Norman Malware Cleaner
for this, go to the folder c:\SDFix
1---in normal mode with internet connection required.
launch RunThis.bat, it opens a DOS menu,
type 2, to download Norman_Malware_Cleaner
it will install itself in the same folder, its size=22268ko
normally it launches automatically after the download, otherwise open the SDFix folder, and launch
Norman_Malware_Cleaner.exe

let it scan all your drives, it may take some time, it finishes and puts a log on your desktop,
paste it in a new post so I can take a look.
see you+
BOB3

P.S.I WILL BE ABSENT ---->4:00 PM
0
catpeople12 Posted messages 122 Status Membre
 
Hello again BOB3 and thank you for your response!

I followed your instructions and I’m letting you check the log from Norman Malware Cleaner (4 infected files removed) below.
(By the way, what does this IP address 127.0.0.1 correspond to?.... There are a lot of weird sites in it that I didn't know existed but that appeared in the log... ).

Otherwise, will I be able to download Windows Live and reinstall the Labtec webcam soon?

I’m waiting for your instructions after 4:00 PM.

Best regards,

catpeople12


LOG FROM 07/08/2008

Norman Malware Cleaner
Copyright © 1990 - 2008, Norman ASA. Built 2008/06/30 19:19:50

Norman Scanner Engine Version: 5.92.08
Nvcbin.def Version: 5.92.00, Date: 2008/06/30 19:19:50, Variants: 1812814

Running pre-scan cleanup routine:
Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 3
Logged on user: CARLO\Carlo

Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLS = "C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll" -> ""
Removed hosts entry: 127.0.0.1 www.100sexlinks.com
Removed hosts entry: 127.0.0.1 100sexlinks.com
Removed hosts entry: 127.0.0.1 www.123topsearch.com
Removed hosts entry: 127.0.0.1 123topsearch.com
Removed hosts entry: 127.0.0.1 www.1800searchonline.com
Removed hosts entry: 127.0.0.1 1800searchonline.com
Removed hosts entry: 127.0.0.1 www.180searchassistant.com
Removed hosts entry: 127.0.0.1 180searchassistant.com
Removed hosts entry: 127.0.0.1 www.1stantivirus.com
Removed hosts entry: 127.0.0.1 1stantivirus.com
Removed hosts entry: 127.0.0.1 www.1stsearchportal.com
Removed hosts entry: 127.0.0.1 1stsearchportal.com
Removed hosts entry: 127.0.0.1 www.2007-download.com
Removed hosts entry: 127.0.0.1 2007-download.com
Removed hosts entry: 127.0.0.1 www.2020search.com
Removed hosts entry: 127.0.0.1 2020search.com
Removed hosts entry: 127.0.0.1 www.24-7searching-and-more.com
Removed hosts entry: 127.0.0.1 24-7searching-and-more.com
Removed hosts entry: 127.0.0.1 www.2search.com
Removed hosts entry: 127.0.0.1 2search.com
Removed hosts entry: 127.0.0.1 www.2search.org
Removed hosts entry: 127.0.0.1 2search.org
Removed hosts entry: 127.0.0.1 www.3ebay.it
Removed hosts entry: 127.0.0.1 3ebay.it
Removed hosts entry: 127.0.0.1 www.4ebay.it
Removed hosts entry: 127.0.0.1 4ebay.it
Removed hosts entry: 127.0.0.1 www.4repubblica.it
Removed hosts entry: 127.0.0.1 4repubblica.it
Removed hosts entry: 127.0.0.1 www.5repubblica.it
Removed hosts entry: 127.0.0.1 5repubblica.it
Removed hosts entry: 127.0.0.1 www.777search.com
Removed hosts entry: 127.0.0.1 777search.com
Removed hosts entry: 127.0.0.1 www.7search.com
Removed hosts entry: 127.0.0.1 7search.com
Removed hosts entry: 127.0.0.1 www.971searchbox.com
Removed hosts entry: 127.0.0.1 971searchbox.com
Removed hosts entry: 127.0.0.1 www.abccodec.com
Removed hosts entry: 127.0.0.1 abccodec.com
Removed hosts entry: 127.0.0.1 www.abcsearch.com
Removed hosts entry: 127.0.0.1 abcsearch.com
Removed hosts entry: 127.0.0.1 www.activexmediasoftware.com
Removed hosts entry: 127.0.0.1 activexmediasoftware.com
Removed hosts entry: 127.0.0.1 www.activexsoftwares.com
Removed hosts entry: 127.0.0.1 activexsoftwares.com
Removed hosts entry: 127.0.0.1 www.activexupdate.com
Removed hosts entry: 127.0.0.1 activexupdate.com
Removed hosts entry: 127.0.0.1 www.adasearch.com
Removed hosts entry: 127.0.0.1 adasearch.com
Removed hosts entry: 127.0.0.1 www.adipics.com
Removed hosts entry: 127.0.0.1 adipics.com
Removed hosts entry: 127.0.0.1 adobe-download-now.com
Removed hosts entry: 127.0.0.1 www.adobe-downloads.com
Removed hosts entry: 127.0.0.1 adobe-downloads.com
Removed hosts entry: 127.0.0.1 ads.searchingbooth.com
Removed hosts entry: 127.0.0.1 www.adsextend.net
Removed hosts entry: 127.0.0.1 adsextend.net
Removed hosts entry: 127.0.0.1 www.adspics.com
Removed hosts entry: 127.0.0.1 adspics.com
Removed hosts entry: 127.0.0.1 www.adult18codec.com
Removed hosts entry: 127.0.0.1 adult18codec.com
Removed hosts entry: 127.0.0.1 www.adultcodec-2008.com
Removed hosts entry: 127.0.0.1 adultcodec-2008.com
Removed hosts entry: 127.0.0.1 www.adultcodecstars.com
Removed hosts entry: 127.0.0.1 adultcodecstars.com
Removed hosts entry: 127.0.0.1 www.adult-engine-search.com
Removed hosts entry: 127.0.0.1 adult-engine-search.com
Removed hosts entry: 127.0.0.1 affiliate.idownload.com
Removed hosts entry: 127.0.0.1 www.airtleworld.com
Removed hosts entry: 127.0.0.1 airtleworld.com
Removed hosts entry: 127.0.0.1 akamai.downloadv3.com
Removed hosts entry: 127.0.0.1 alfa-search.com
Removed hosts entry: 127.0.0.1 www.allcybersearch.com
Removed hosts entry: 127.0.0.1 allcybersearch.com
Removed hosts entry: 127.0.0.1 www.all-downloads-now.com
Removed hosts entry: 127.0.0.1 all-downloads-now.com
Removed hosts entry: 127.0.0.1 allforadult.com
Removed hosts entry: 127.0.0.1 www.alltiettantivirus.com
Removed hosts entry: 127.0.0.1 alltiettantivirus.com
Removed hosts entry: 127.0.0.1 www.alltruesoftware.com
Removed hosts entry: 127.0.0.1 alltruesoftware.com
Removed hosts entry: 127.0.0.1 www.amediasoftware.com
Removed hosts entry: 127.0.0.1 amediasoftware.com
Removed hosts entry: 127.0.0.1 www.americanautobargains.com
Removed hosts entry: 127.0.0.1 americanautobargains.com
Removed hosts entry: 127.0.0.1 www.ampmsearch.com
Removed hosts entry: 127.0.0.1 ampmsearch.com
Removed hosts entry: 127.0.0.1 anarchyporn.com
Removed hosts entry: 127.0.0.1 www.animepornmag.com
Removed hosts entry: 127.0.0.1 animepornmag.com
Removed hosts entry: 127.0.0.1 www.antiespiadorado.com
Removed hosts entry: 127.0.0.1 antiespiadorado.com
Removed hosts entry: 127.0.0.1 www.antiespionspack.com
Removed hosts entry: 127.0.0.1 antiespionspack.com
Removed hosts entry: 127.0.0.1 www.antigusanos2008.com
Removed hosts entry: 127.0.0.1 antigusanos2008.com
Removed hosts entry: 127.0.0.1 www.antispamassistant.com
Removed hosts entry: 127.0.0.1 antispamassistant.com
Removed hosts entry: 127.0.0.1 www.antispamdeluxe.com
Removed hosts entry: 127.0.0.1 antispamdeluxe.com
Removed hosts entry: 127.0.0.1 www.antispionage.com
Removed hosts entry: 127.0.0.1 antispionage.com
Removed hosts entry: 127.0.0.1 www.antispionagepro.com
Removed hosts entry: 127.0.0.1 antispionagepro.com
Removed hosts entry: 127.0.0.1 www.antispyadvanced.com
Removed hosts entry: 127.0.0.1 antispyadvanced.com
Removed hosts entry: 127.0.0.1 www.antispycheck.com
Removed hosts entry: 127.0.0.1 antispycheck.com
Removed hosts entry: 127.0.0.1 www.antispydns.biz
Removed hosts entry: 127.0.0.1 antispydns.biz
Removed hosts entry: 127.0.0.1 www.antispykit.com
Removed hosts entry: 127.0.0.1 antispykit.com
Removed hosts entry: 127.0.0.1 www.antispylab.com
Removed hosts entry: 127.0.0.1 antispylab.com
Removed hosts entry: 127.0.0.1 www.antispyshield.com
Removed hosts entry: 127.0.0.1 antispyshield.com
Removed hosts entry: 127.0.0.1 www.antispysolutions.com
Removed hosts entry: 127.0.0.1 antispysolutions.com
Removed hosts entry: 127.0.0.1 www.antispyware.com
Removed hosts entry: 127.0.0.1 antispyware.com
Removed hosts entry: 127.0.0.1 www.antispywareboot.com
Removed hosts entry: 127.0.0.1 antispywareboot.com
Removed hosts entry: 127.0.0.1 www.antispywarebot.com
Removed hosts entry: 127.0.0.1 antispywarebot.com
Removed hosts entry: 127.0.0.1 www.antispywarebox.com
Removed hosts entry: 127.0.0.1 antispywarebox.com
Removed hosts entry: 127.0.0.1 www.antispywaredownloads.com
Removed hosts entry: 127.0.0.1 antispywaredownloads.com
Removed hosts entry: 127.0.0.1 www.antispywaresuite.com
Removed hosts entry: 127.0.0.1 antispywaresuite.com
Removed hosts entry: 127.0.0.1 www.antispywareupdates.net
Removed hosts entry: 127.0.0.1 antispywareupdates.net
Removed hosts entry: 127.0.0.1 www.antispywarexp.com
Removed hosts entry: 127.0.0.1 antispywarexp.com
Removed hosts entry: 127.0.0.1 www.antispyweb.net
Removed hosts entry: 127.0.0.1 antispyweb.net
Removed hosts entry: 127.0.0.1 www.antiver2008.com
Removed hosts entry: 127.0.0.1 antiver2008.com
Removed hosts entry: 127.0.0.1 www.antivermins.com
Removed hosts entry: 127.0.0.1 antivermins.com
Removed hosts entry: 127.0.0.1 www.anti-vermins.com
Removed hosts entry: 127.0.0.1 anti-vermins.com
Removed hosts entry: 127.0.0.1 www.antivir2007.com
Removed hosts entry: 127.0.0.1 antivir2007.com
Removed hosts entry: 127.0.0.1 www.antivirgear.com
Removed hosts entry: 127.0.0.1 antivirgear.com
Removed hosts entry: 127.0.0.1 www.antivirprotect.com
Removed hosts entry: 127.0.0.1 antivirprotect.com
Removed hosts entry: 127.0.0.1 www.antivirus.fastfreedownload.com
Removed hosts entry: 127.0.0.1 antivirus.fastfreedownload.com
Removed hosts entry: 127.0.0.1 www.antivirus2008pro.com
Removed hosts entry: 127.0.0.1 antivirus2008pro.com
Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.com
Removed hosts entry: 127.0.0.1 antivirus-2008pro.com
Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.com
Removed hosts entry: 127.0.0.1 antivirus-2008-pro.com
Removed hosts entry: 127.0.0.1 www.antivirus2008pro.info
Removed hosts entry: 127.0.0.1 antivirus2008pro.info
Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.info
Removed hosts entry: 127.0.0.1 antivirus-2008pro.info
Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.info
Removed hosts entry: 127.0.0.1 antivirus-2008-pro.info
Removed hosts entry: 127.0.0.1 www.antivirus2008pro.net
Removed hosts entry: 127.0.0.1 antivirus2008pro.net
Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.net
Removed hosts entry: 127.0.0.1 antivirus-2008pro.net
Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.net
Removed hosts entry: 127.0.0.1 antivirus-2008-pro.net
Removed hosts entry: 127.0.0.1 www.antivirus2008pro.org
Removed hosts entry: 127.0.0.1 antivirus2008pro.org
Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.org
Removed hosts entry: 127.0.0.1 antivirus-2008pro.org
Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.org
Removed hosts entry: 127.0.0.1 antivirus-2008-pro.org
Removed hosts entry: 127.0.0.1 www.antivirus2008x.com
Removed hosts entry: 127.0.0.1 antivirus2008x.com
Removed hosts entry: 127.0.0.1 www.antivirusadvance.com
Removed hosts entry: 127.0.0.1 antivirusadvance.com
Removed hosts entry: 127.0.0.1 www.antivirusaskeladd.com
Removed hosts entry: 127.0.0.1 antivirusaskeladd.com
Removed hosts entry: 127.0.0.1 www.antivirusgereedschap.com
Removed hosts entry: 127.0.0.1 antivirusgereedschap.com
Removed hosts entry: 127.0.0.1 www.antivirusgolden.com
Removed hosts entry: 127.0.0.1 antivirusgolden.com
Removed hosts entry: 127.0.0.1 www.antivirus-hq.net
Removed hosts entry: 127.0.0.1 antivirus-hq.net
Removed hosts entry: 127.0.0.1 www.antiviruspcsuite.com
Removed hosts entry: 127.0.0.1 antiviruspcsuite.com
Removed hosts entry: 127.0.0.1 www.antiviruspremium.com
Removed hosts entry: 127.0.0.1 antiviruspremium.com
Removed hosts entry: 127.0.0.1 www.anti-virus-pro.com
Removed hosts entry: 127.0.0.1 anti-virus-pro.com
Removed hosts entry: 127.0.0.1 www.antivirusprotector.com
Removed hosts entry: 127.0.0.1 antivirusprotector.com
Removed hosts entry: 127.0.0.1 www.antivirus-scanner.com
Removed hosts entry: 127.0.0.1 antivirus-scanner.com
Removed hosts entry: 127.0.0.1 www.antivirusscherm.com
Removed hosts entry: 127.0.0.1 antivirusscherm.com
Removed hosts entry: 127.0.0.1 www.antivirussecuritypro.com
Removed hosts entry: 127.0.0.1 antivirussecuritypro.com
Removed hosts entry: 127.0.0.1 www.antivirus-stop.com
Removed hosts entry: 127.0.0.1 antivirus-stop.com
Removed hosts entry: 127.0.0.1 www.antivirussuite.com
Removed hosts entry: 127.0.0.1 antivirussuite.com
Removed hosts entry: 127.0.0.1 www.antiworm2008.com
Removed hosts entry: 127.0.0.1 antiworm2008.com
Removed hosts entry: 127.0.0.1 www.antiwurm2008.com
Removed hosts entry: 127.0.0.1 antiwurm2008.com
Removed hosts entry: 127.0.0.1 www.archiviosex.net
Removed hosts entry: 127.0.0.1 archiviosex.net
Removed hosts entry: 127.0.0.1 www.ares.click-new-download.com
Removed hosts entry: 127.0.0.1 ares.click-new-download.com
Removed hosts entry: 127.0.0.1 www.asianpornmag.com
Removed hosts entry: 127.0.0.1 asianpornmag.com
Removed hosts entry: 127.0.0.1 www.aucunsvirus.com
Removed hosts entry: 127.0.0.1 aucunsvirus.com
Removed hosts entry: 127.0.0.1 www.autobargains.org
Removed hosts entry: 127.0.0.1 autobargains.org
Removed hosts entry: 127.0.0.1 www.autobargainsnetwork.com
Removed hosts entry: 127.0.0.1 autobargainsnetwork.com
Removed hosts entry: 127.0.0.1 www.autocontext.begun.ru
Removed hosts entry: 127.0.0.1 autocontext.begun.ru
Removed hosts entry: 127.0.0.1 autoescrowpay.com
Removed hosts entry: 127.0.0.1 www.avast.free-software-center.com
Removed hosts entry: 127.0.0.1 avast.free-software-center.com
Removed hosts entry: 127.0.0.1 www.avast-downloads.com
Removed hosts entry: 127.0.0.1 avast-downloads.com
Removed hosts entry: 127.0.0.1 www.avg.softwarecenterz.com
Removed hosts entry: 127.0.0.1 avg.softwarecenterz.com
Removed hosts entry: 127.0.0.1 www.avpcheckupdate.com
Removed hosts entry: 127.0.0.1 avpcheckupdate.com
Removed hosts entry: 127.0.0.1 awmcash.biz
Removed hosts entry: 127.0.0.1 awmdabest.com
Removed hosts entry: 127.0.0.1 www.axemediasoftware.com
Removed hosts entry: 127.0.0.1 axemediasoftware.com
Removed hosts entry: 127.0.0.1 www.axmediasoftware.com
Removed hosts entry: 127.0.0.1 axmediasoftware.com
Removed hosts entry: 127.0.0.1 www.axsoftwaretool.com
Removed hosts entry: 127.0.0.1 axsoftwaretool.com
Removed hosts entry: 127.0.0.1 www.babespornmag.com
Removed hosts entry: 127.0.0.1 babespornmag.com
Removed hosts entry: 127.0.0.1 www.bardownload.com
Removed hosts entry: 127.0.0.1 bardownload.com
Removed hosts entry: 127.0.0.1 batsearch.com
Removed hosts entry: 127.0.0.1 bbbsearch.com
Removed hosts entry: 127.0.0.1 bb-search.com
Removed hosts entry: 127.0.0.1 www.bdsmpornmag.com
Removed hosts entry: 127.0.0.1 bdsmpornmag.com
Removed hosts entry: 127.0.0.1 www.bearshare.click-new-download.com
Removed hosts entry: 127.0.0.1 bearshare.click-new-download.com
Removed hosts entry: 127.0.0.1 www.bearshare-download.org
Removed hosts entry: 127.0.0.1 bearshare-download.org
Removed hosts entry: 127.0.0.1 www.bearshare-downloads.net
Removed hosts entry: 127.0.0.1 bearshare-downloads.net
Removed hosts entry: 127.0.0.1 www.bearshare-music-downloads.com
Removed hosts entry: 127.0.0.1 bearshare-music-downloads.com
Removed hosts entry: 127.0.0.1 www.begin2search.com
Removed hosts entry: 127.0.0.1 begin2search.com
Removed hosts entry: 127.0.0.1 best-hardpics.com
Removed hosts entry: 127.0.0.1 www.best-porncollection.com
Removed hosts entry: 127.0.0.1 best-porncollection.com
Removed hosts entry: 127.0.0.1 bestporngate.com
Removed hosts entry: 127.0.0.1 www.bestsearchworld.info
Removed hosts entry: 127.0.0.1 bestsearchworld.info
Removed hosts entry: 127.0.0.1 www.bestworldgirls-for-u.net
Removed hosts entry: 127.0.0.1 bestworldgirls-for-u.net
Removed hosts entry: 127.0.0.1 bestxporno.com
Removed hosts entry: 127.0.0.1 www.bettersearch.biz
Removed hosts entry: 127.0.0.1 bettersearch.biz
Removed hosts entry: 127.0.0.1 www.bgoogle.it
Removed hosts entry: 127.0.0.1 bgoogle.it
Removed hosts entry: 127.0.0.1 www.bigcodecadult.com
Removed hosts entry: 127.0.0.1 bigcodecadult.com
Removed hosts entry: 127.0.0.1 www.bigcodecadult2008.com
Removed hosts entry: 127.0.0.1 bigcodecadult2008.com
Removed hosts entry: 127.0.0.1 www.bigcodecadult2008-17.com
Removed hosts entry: 127.0.0.1 bigcodecadult2008-17.com
Removed hosts entry: 127.0.0.1 www.bighot18codec2008.com
Removed hosts entry: 127.0.0.1 bighot18codec2008.com
Removed hosts entry: 127.0.0.1 www.bighot18-codec2008.com
Removed hosts entry: 127.0.0.1 bighot18-codec2008.com
Removed hosts entry: 127.0.0.1 www.bittorrent.click-new-download.com
Removed hosts entry: 127.0.0.1 bittorrent.click-new-download.com
Removed hosts entry: 127.0.0.1 www.blackcodec.com
Removed hosts entry: 127.0.0.1 blackcodec.com
0
  • 1
  • 2
  • 3
  • 4