Trojan-downloader.win32

Bonjour,
Merci de m'aider. Quand j'ouvre une page web, ou un document word, quelques minutes après j'ai une fenetre ressemblant au pare-feu windows et qui dit: trojan-downloader.win32.agent. il me propose de cliquer sur un lien qui me dirige vers une page de telechargement.
Biensur je ne l'ai pas ouvert .
J'ai ccleaner et avast , ad aware et apres les avoir executés ca raconte que je n'ai pas de virus.
SVP. Aider moi ,
Configuration: Windows XP
Internet Explorer 7.0

35 réponses

Résumé de la discussion

Le problème porte sur l’apparition, après l’ouverture d’une page web ou d’un document sous Windows XP et Internet Explorer 7, d’une fenêtre pare-feu affichant Trojan-downloader.win32.agent et incitant à télécharger un fichier suspect. Plusieurs solutions ont été proposées, notamment Malwarebytes qui a détecté et mis en quarantaines des éléments Adware.Minibug et Trojan.FakeAlert.H, puis corrigé des clés et valeurs du Registre liées à ces menaces. D’autres messages recommandent l’emploi d’outils complémentaires comme ComboFix, SmitfraudFix ou HiJackThis, mais impliquent de désactiver provisoirement les protections et de déconnecter l’ordinateur d’Internet, avant d’exécuter les scripts. En cas de suite, les rapports de ces outils (log HijackThis, rapport SDFix ou VACFix) doivent être partagés pour évaluer l’avancement et adapter les actions sans conclure prématurément.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour,

    - Télécharge HiJackThis.zip de Merijn sur ton bureau.
    - Dézippe le dans un dossier prévu à cet effet.
    ** exemple C:\hijackthis < Enregistre le bien dans c : !

    - Double-clique dessus
    - Génère un rapport en suivant ces indications :
    - Exécute le et clique sur "Do a scan and save log file".
    - Le rapport s'ouvre sur le Bloc-Note.
    - Colle le rapport ici, pour cela :
    - Menu Edition / Selectionner Tout
    - Menu Edition / copier
    - Ici dans un nouveau message : clic droit / coller
    - ** ne pas fixer de lignes sans notre avis **
    Aide : N'hésite pas à consulter l'aide HiJackThis de Malekal_morte
    En image
    0
    1. Merci de m'aider, voici le rapport:

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 11:39:49, on 2008-09-09
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16705)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\csrss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\ehome\ehtray.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\DISC\DISCover.exe
      C:\Program Files\DISC\DiscUpdateMgr.exe
      C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
      C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
      C:\Program Files\DISC\DiscGui.exe
      C:\WINDOWS\system32\rundll32.exe
      C:\WINDOWS\system32\WDBtnMgr.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\Program Files\Winamp\Winampa.exe
      C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
      C:\Program Files\Common Files\Real\Update_OB\realsched.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\Documents and Settings\All Users\Application Data\lcxkxqvy\zyfwjazo.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\Program Files\Bonjour\mDNSResponder.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\WINDOWS\eHome\ehRecvr.exe
      C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
      C:\WINDOWS\eHome\ehSched.exe
      C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\video198.cfg.exe
      C:\WINDOWS\system32\ynqpcxef.exe
      C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\c.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
      C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      C:\Program Files\NDAS\System\ndasmgmt.exe
      C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
      C:\Program Files\NDAS\System\ndassvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\ehome\mcrdsvc.exe
      C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
      C:\WINDOWS\system32\ps2.exe
      c:\windows\system\hpsysdrv.exe
      C:\WINDOWS\system32\wbem\wmiprvse.exe
      C:\WINDOWS\system32\dllhost.exe
      C:\WINDOWS\System32\alg.exe
      C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\DISC\DiscStreamHub.exe
      C:\WINDOWS\eHome\ehmsas.exe
      C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
      C:\PROGRA~1\MICROS~4\Office12\OUTLOOK.EXE
      C:\WINDOWS\system32\wscntfy.exe
      C:\Program Files\InvoiceNet40\InvNet40.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\HiJackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: XML module - {500BCA15-57A7-4eaf-8143-8C619470B13D} - C:\WINDOWS\system32\msxml71.dll
      O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
      O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
      O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
      O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
      O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
      O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
      O4 - HKLM\..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
      O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
      O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
      O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
      O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
      O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
      O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
      O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
      O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
      O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05c\BrStDvPt.exe
      O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
      O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
      O4 - HKCU\..\Run: [Somefox] C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\video198.cfg.exe
      O4 - HKCU\..\Run: [comsys] C:\WINDOWS\system32\ynqpcxef.exe
      O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
      O4 - HKCU\..\Policies\Explorer\Run: [6sJ5qDL0y0] C:\Documents and Settings\All Users\Application Data\lcxkxqvy\zyfwjazo.exe
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
      O4 - Global Startup: NDAS Device Management.lnk = C:\Program Files\NDAS\System\ndasmgmt.exe
      O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
      O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O15 - Trusted Zone: http://*.trymedia.com (HKLM)
      O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
      O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
      O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://walmart.pnimedia.com/upload/activex/v2_0_0_9/PCAXSetupv2.0.0.9.cab?
      O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://walmart.pnimedia.com/upload/activex/v2_0_0_10/PCAXSetupv2.0.0.10.cab?
      O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: Service Bonjour (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
      O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
      O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: NDAS Service (ndassvc) - XIMETA, Inc. - C:\Program Files\NDAS\System\ndassvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
      O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
      O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
      O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
      O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
      0
      1. Contributeur sécurité
        bien,
        y a deux,trois infections bien visible

        va falloir utiliser plusieurs fix pour les avoir

        Télécharge SmitFraudfix de S!Ri, balltrap34 et moe31
        http://siri.urz.free.fr/Fix/SmitfraudFix.zip -
        en cas de problème avec le premier lien,
        mirroir: http://72.232.135.12/siri/SmitfraudFix.php

        voila à quoi cela ressemble : http://siri.urz.free.fr/Fix/SmitfraudFix.php

        Désactive les logiciels de protections(antivirus et antispyware)
        -- Fais un clic droit puis Extraire tout sur le fichier SmitfraudFix.zip, cela va tout décompresser dans un nouveau dossier SmitFraudfix
        -- Ouvre le dossier SmitfraudFix double-clique sur SmitfraudFix.cmd (le .cmd peut ne pas être présent)
        -- Choisis l'option 1 et appuie sur Entrée
        -- Réponds o (Oui) aux deux questions suivantes si elles sont posées
        -- Un rapport sera généré; sauvegarde le dans un dossier.
        -- Copie/colle le contenu du rapport ici
        0
        1. Voici le rapport demandé...merci

          SmitFraudFix v2.347

          Scan done at 12:11:33,82, 2008-09-09
          Run from C:\Documents and Settings\HP_Administrator\Desktop\SmitfraudFix
          OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
          The filesystem type is NTFS
          Fix run in normal mode

          »»»»»»»»»»»»»»»»»»»»»»»» Process

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\csrss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\system32\spoolsv.exe
          C:\WINDOWS\ehome\ehtray.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
          C:\WINDOWS\RTHDCPL.EXE
          C:\Program Files\DISC\DISCover.exe
          C:\Program Files\DISC\DiscUpdateMgr.exe
          C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
          C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
          C:\Program Files\DISC\DiscGui.exe
          C:\WINDOWS\system32\rundll32.exe
          C:\WINDOWS\system32\WDBtnMgr.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\Program Files\Winamp\Winampa.exe
          C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
          C:\Program Files\Common Files\Real\Update_OB\realsched.exe
          C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
          C:\Documents and Settings\All Users\Application Data\lcxkxqvy\zyfwjazo.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\WINDOWS\eHome\ehRecvr.exe
          C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
          C:\WINDOWS\eHome\ehSched.exe
          C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\video198.cfg.exe
          C:\WINDOWS\system32\ynqpcxef.exe
          C:\DOCUME~1\HP_ADM~1\LOCALS~1\Temp\c.exe
          C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Program Files\NDAS\System\ndasmgmt.exe
          C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
          C:\Program Files\NDAS\System\ndassvc.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\ehome\mcrdsvc.exe
          C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
          C:\WINDOWS\system32\ps2.exe
          c:\windows\system\hpsysdrv.exe
          C:\WINDOWS\system32\wbem\wmiprvse.exe
          C:\WINDOWS\system32\dllhost.exe
          C:\WINDOWS\System32\alg.exe
          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\Program Files\DISC\DiscStreamHub.exe
          C:\WINDOWS\eHome\ehmsas.exe
          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
          C:\PROGRA~1\MICROS~4\Office12\OUTLOOK.EXE
          C:\WINDOWS\system32\wscntfy.exe
          C:\Program Files\InvoiceNet40\InvNet40.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\WINDOWS\system32\cmd.exe

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          hosts file corrupted !

          127.0.0.1 www.legal-at-spybot.info
          127.0.0.1 legal-at-spybot.info

          »»»»»»»»»»»»»»»»»»»»»»»» C:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Administrator

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\HP_Administrator\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HP_ADM~1\FAVORI~1

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          C:\Program Files\akl\ FOUND !
          C:\Program Files\sav\ FOUND !

          »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

          »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
          "Source"="About:Home"
          "SubscribedURL"="About:Home"
          "FriendlyName"="My Current Home Page"

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
          !!!Attention, following keys are not inevitably infected!!!

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
          !!!Attention, following keys are not inevitably infected!!!

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
          !!!Attention, following keys are not inevitably infected!!!

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
          !!!Attention, following keys are not inevitably infected!!!

          AntiXPVSTFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, following keys are not inevitably infected!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
          !!!Attention, following keys are not inevitably infected!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          Description: Intel(R) PRO/100 VE Network Connection - Packet Scheduler Miniport
          DNS Server Search Order: 192.168.2.1
          DNS Server Search Order: 192.168.2.1

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{A4250EEC-289B-4CC3-A9E0-B0E98B1EE95C}: DhcpNameServer=192.168.2.1 192.168.2.1
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{A4250EEC-289B-4CC3-A9E0-B0E98B1EE95C}: DhcpNameServer=192.168.2.1 192.168.2.1
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{A4250EEC-289B-4CC3-A9E0-B0E98B1EE95C}: DhcpNameServer=192.168.2.1 192.168.2.1
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1 192.168.2.1
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1 192.168.2.1
          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1 192.168.2.1

          »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

          »»»»»»»»»»»»»»»»»»»»»»»» End
          0
          1. Contributeur sécurité
            ok,

            il a trouvé des trucs...pas grand chose mais quand même

            allez hop on nettoie

            Redémarre l'ordinateur en mode sans échec .
            Comment aller en Mode sans échec
            1) Redémarre ton ordi
            2) Tapote la touche F8 immédiatement, (F5 sur certains PC) juste après le "Bip"
            3) Tu verras un écran avec options de démarrage apparaître
            4) Choisis la première option : Sans Échec, et valide avec "Entrée"
            5) Choisis ton compte habituel, et non Administrateur (si besoin ... )
            ( ps : n'oublies pas , en mode sans échec , pas de connexion ! Donc copie ou imprime bien les infos ci-dessous ...)

            *Double click sur SmitfraudFix.exe

            * Sélectionnes 2 et presses "Entrée" dans le menu pour supprimer les fichiers responsables de l'infection.

            * A la question: Voulez-vous nettoyer le registre ? répondre O (oui) et presse Entrée afin de débloquer le fond d'écran et supprimer les clés de registre de l'infection.

            ( Le correctif déterminera si le fichier wininet.dll est infecté.)

            * A la question: "Corriger le fichier infecté ?" répondre O (oui) et presser Entrée
            pour remplacer le fichier corrompu.

            * Un redémarrage sera peut être nécessaire pour terminer la procédure de nettoyage ( sinon fais le manuellement )

            Le rapport se trouve à la racine de C\:
            (dans le fichier "rapport.txt")

            Poste ce dernier rapport accompagné, dans la même réponse, d'un nouveau rapport hijackthis ( fais en mode normal )
            0
            1. Bon comme rien n'est simple, j'ai plein de exe dans le fichier, mais pas rien avec le nom de SmitfraudFix.exe ??
              0
              1. Contributeur sécurité
                tu n'as pas de smitfraudfix sur ton bureau?
                0
                1. j'ai dézipper le tout dans un fichier sur mon bureau et dans ce fichier, j'ai plein de .exe(404fix.exe, antixppvst.exe, dumphive.exe, genericrenosfix.exe, etc) mais le seul SmitfraudFix que j'ai, il est cmd
                  0
                  1. Contributeur sécurité
                    c'est peut-être une erreur dans mes textes

                    clic sur le cmd et prend l'option 2
                    si y a pas c'est pas grave,on ferat autrement
                    0
                    1. Merci de ta patience, c'est long, mais j'y arrive
                      Voici le rapport:

                      SmitFraudFix v2.347

                      Scan done at 13:35:52,46, 2008-09-09
                      Run from C:\Documents and Settings\HP_Administrator\Desktop\SmitfraudFix
                      OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
                      The filesystem type is NTFS
                      Fix run in safe mode

                      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                      !!!Attention, following keys are not inevitably infected!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                      »»»»»»»»»»»»»»»»»»»»»»»» hosts

                      127.0.0.1 localhost
                      127.0.0.1 bin.errorprotector.com ## added by CiD
                      127.0.0.1 br.errorsafe.com ## added by CiD
                      127.0.0.1 br.winantivirus.com ## added by CiD
                      127.0.0.1 br.winfixer.com ## added by CiD
                      127.0.0.1 cdn.drivecleaner.com ## added by CiD
                      127.0.0.1 cdn.errorsafe.com ## added by CiD
                      127.0.0.1 cdn.winsoftware.com ## added by CiD
                      127.0.0.1 de.errorsafe.com ## added by CiD
                      127.0.0.1 de.winantivirus.com ## added by CiD
                      127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
                      127.0.0.1 download.cdn.errorsafe.com ## added by CiD
                      127.0.0.1 download.cdn.winsoftware.com ## added by CiD
                      127.0.0.1 download.errorsafe.com ## added by CiD
                      127.0.0.1 download.systemdoctor.com ## added by CiD
                      127.0.0.1 download.winantispyware.com ## added by CiD
                      127.0.0.1 download.windrivecleaner.com ## added by CiD
                      127.0.0.1 download.winfixer.com ## added by CiD
                      127.0.0.1 drivecleaner.com ## added by CiD
                      127.0.0.1 dynamique.drivecleaner.com ## added by CiD
                      127.0.0.1 errorprotector.com ## added by CiD
                      127.0.0.1 errorsafe.com ## added by CiD
                      127.0.0.1 es.winantivirus.com ## added by CiD
                      127.0.0.1 fr.winantivirus.com ## added by CiD
                      127.0.0.1 fr.winfixer.com ## added by CiD
                      127.0.0.1 go.drivecleaner.com ## added by CiD
                      127.0.0.1 go.errorsafe.com ## added by CiD
                      127.0.0.1 go.winantispyware.com ## added by CiD
                      127.0.0.1 go.winantivirus.com ## added by CiD
                      127.0.0.1 hk.winantivirus.com ## added by CiD
                      127.0.0.1 instlog.errorsafe.com ## added by CiD
                      127.0.0.1 instlog.winantivirus.com ## added by CiD
                      127.0.0.1 instlog.winfixer.com ## added by CiD
                      127.0.0.1 jsp.drivecleaner.com ## added by CiD
                      127.0.0.1 kb.errorsafe.com ## added by CiD
                      127.0.0.1 kb.winantivirus.com ## added by CiD
                      127.0.0.1 nl.errorsafe.com ## added by CiD
                      127.0.0.1 se.errorsafe.com ## added by CiD
                      127.0.0.1 secure.drivecleaner.com ## added by CiD
                      127.0.0.1 secure.errorsafe.com ## added by CiD
                      127.0.0.1 secure.winantispam.com ## added by CiD
                      127.0.0.1 secure.winantispy.com ## added by CiD
                      127.0.0.1 secure.winantivirus.com ## added by CiD
                      127.0.0.1 support.winantivirus.com ## added by CiD
                      127.0.0.1 trial.updates.winsoftware.com ## added by CiD
                      127.0.0.1 ulog.winantivirus.com ## added by CiD
                      127.0.0.1 utils.errorsafe.com ## added by CiD
                      127.0.0.1 utils.winantivirus.com ## added by CiD
                      127.0.0.1 utils.winfixer.com ## added by CiD
                      127.0.0.1 winantispyware.com ## added by CiD
                      127.0.0.1 winantivirus.com ## added by CiD
                      127.0.0.1 winfixer.com ## added by CiD
                      127.0.0.1 winfixer2006.com ## added by CiD
                      127.0.0.1 winsoftware.com ## added by CiD
                      127.0.0.1 www.drivecleaner.com ## added by CiD
                      127.0.0.1 www.errorprotector.com ## added by CiD
                      127.0.0.1 www.errorsafe.com ## added by CiD
                      127.0.0.1 www.systemdoctor.com ## added by CiD
                      127.0.0.1 www.utils.winfixer.com ## added by CiD
                      127.0.0.1 www.win-anti-virus-pro.com ## added by CiD
                      127.0.0.1 www.win-virus-pro.com ## added by CiD
                      127.0.0.1 www.winantispam.com ## added by CiD
                      127.0.0.1 www.winantispy.com ## added by CiD
                      127.0.0.1 www.winantispyware.com ## added by CiD
                      127.0.0.1 www.winantivirus.com ## added by CiD
                      127.0.0.1 www.winantiviruspro.com ## added by CiD
                      127.0.0.1 www.windrivecleaner.com ## added by CiD
                      127.0.0.1 www.windrivesafe.com ## added by CiD
                      127.0.0.1 www.winfixer.com ## added by CiD
                      127.0.0.1 www.winfixer2006.com ## added by CiD
                      127.0.0.1 www.winsoftware.com ## added by CiD
                      127.0.0.1 www.007guard.com
                      127.0.0.1 007guard.com
                      127.0.0.1 008i.com
                      127.0.0.1 www.008k.com
                      127.0.0.1 008k.com
                      127.0.0.1 www.00hq.com
                      127.0.0.1 00hq.com
                      127.0.0.1 010402.com
                      127.0.0.1 www.032439.com
                      127.0.0.1 032439.com
                      127.0.0.1 www.1001-search.info
                      127.0.0.1 1001-search.info
                      127.0.0.1 www.100888290cs.com
                      127.0.0.1 100888290cs.com
                      127.0.0.1 www.100sexlinks.com
                      127.0.0.1 100sexlinks.com
                      127.0.0.1 www.10sek.com
                      127.0.0.1 10sek.com
                      127.0.0.1 www.123topsearch.com
                      127.0.0.1 123topsearch.com
                      127.0.0.1 www.132.com
                      127.0.0.1 132.com
                      127.0.0.1 www.136136.net
                      127.0.0.1 136136.net
                      127.0.0.1 www.139mm.com
                      127.0.0.1 139mm.com
                      127.0.0.1 www.163ns.com
                      127.0.0.1 163ns.com
                      127.0.0.1 171203.com
                      127.0.0.1 17-plus.com
                      127.0.0.1 www.1800searchonline.com
                      127.0.0.1 1800searchonline.com
                      127.0.0.1 www.180searchassistant.com
                      127.0.0.1 180searchassistant.com
                      127.0.0.1 www.180solutions.com
                      127.0.0.1 180solutions.com
                      127.0.0.1 www.181.365soft.info
                      127.0.0.1 181.365soft.info
                      127.0.0.1 www.1987324.com
                      127.0.0.1 1987324.com
                      127.0.0.1 www.1-domains-registrations.com
                      127.0.0.1 1-domains-registrations.com
                      127.0.0.1 www.1-extreme.biz
                      127.0.0.1 1-extreme.biz
                      127.0.0.1 www.1sexparty.com
                      127.0.0.1 1sexparty.com
                      127.0.0.1 www.1stantivirus.com
                      127.0.0.1 1stantivirus.com
                      127.0.0.1 www.1stpagehere.com
                      127.0.0.1 1stpagehere.com
                      127.0.0.1 www.1stsearchportal.com
                      127.0.0.1 1stsearchportal.com
                      127.0.0.1 2.82211.net
                      127.0.0.1 www.2006ooo.com
                      127.0.0.1 2006ooo.com
                      127.0.0.1 www.2007-download.com
                      127.0.0.1 2007-download.com
                      127.0.0.1 www.2008-search-destroy.com
                      127.0.0.1 2008-search-destroy.com
                      127.0.0.1 www.2020search.com
                      127.0.0.1 2020search.com
                      127.0.0.1 20x2p.com
                      127.0.0.1 www.24.365soft.info
                      127.0.0.1 24.365soft.info
                      127.0.0.1 www.24-7pharmacy.info
                      127.0.0.1 24-7pharmacy.info
                      127.0.0.1 www.24-7searching-and-more.com
                      127.0.0.1 24-7searching-and-more.com
                      127.0.0.1 www.24teen.com
                      127.0.0.1 24teen.com
                      127.0.0.1 www.2every.net
                      127.0.0.1 2every.net
                      127.0.0.1 2ndpower.com
                      127.0.0.1 www.2search.com
                      127.0.0.1 2search.com
                      127.0.0.1 www.2search.org
                      127.0.0.1 2search.org
                      127.0.0.1 www.2squared.com
                      127.0.0.1 2squared.com
                      127.0.0.1 www.3322.org
                      127.0.0.1 3322.org
                      127.0.0.1 365soft.info
                      127.0.0.1 www.36site.com
                      127.0.0.1 36site.com
                      127.0.0.1 3721.com
                      127.0.0.1 39-93.com
                      127.0.0.1 www.3abetterinternet.com
                      127.0.0.1 3abetterinternet.com
                      127.0.0.1 www.3bay.it
                      127.0.0.1 3bay.it
                      127.0.0.1 www.3ebay.it
                      127.0.0.1 3ebay.it
                      127.0.0.1 www.3xclipsonline.com
                      127.0.0.1 3xclipsonline.com
                      127.0.0.1 www.3xcurves.com
                      127.0.0.1 3xcurves.com
                      127.0.0.1 www.3xfestival.com
                      127.0.0.1 3xfestival.com
                      127.0.0.1 www.3x-festival.com
                      127.0.0.1 3x-festival.com
                      127.0.0.1 www.3x-galls.com
                      127.0.0.1 3x-galls.com
                      127.0.0.1 www.3xmiracle.com
                      127.0.0.1 3xmiracle.com
                      127.0.0.1 www.3xmoviesblog.com
                      127.0.0.1 3xmoviesblog.com
                      127.0.0.1 www.404dns.com
                      127.0.0.1 404dns.com
                      127.0.0.1 www.4199.com
                      127.0.0.1 4199.com
                      127.0.0.1 www.4corn.net
                      127.0.0.1 4corn.net
                      127.0.0.1 www.4ebay.it
                      127.0.0.1 4ebay.it
                      127.0.0.1 4klm.com
                      127.0.0.1 www.4mpg.com
                      127.0.0.1 4mpg.com
                      127.0.0.1 www.4repubblica.it
                      127.0.0.1 4repubblica.it
                      127.0.0.1 www.4softget.com
                      127.0.0.1 4softget.com
                      127.0.0.1 www.59cn.cn
                      127.0.0.1 59cn.cn
                      127.0.0.1 www.5iscali.it
                      127.0.0.1 5iscali.it
                      127.0.0.1 www.5repubblica.it
                      127.0.0.1 5repubblica.it
                      127.0.0.1 www.5starvideos.com
                      127.0.0.1 5starvideos.com
                      127.0.0.1 www.5tiscali.it
                      127.0.0.1 5tiscali.it
                      127.0.0.1 www.5zgmu7o20kt5d8yq.com
                      127.0.0.1 5zgmu7o20kt5d8yq.com
                      127.0.0.1 www.680180.net
                      127.0.0.1 680180.net
                      127.0.0.1 www.6iscali.it
                      127.0.0.1 6iscali.it
                      127.0.0.1 www.6njaga.com
                      127.0.0.1 6njaga.com
                      127.0.0.1 www.6sek.com
                      127.0.0.1 6sek.com
                      127.0.0.1 www.6tiscali.it
                      127.0.0.1 6tiscali.it
                      127.0.0.1 www.70-music.com
                      127.0.0.1 70-music.com
                      127.0.0.1 www.7322.com
                      127.0.0.1 7322.com
                      127.0.0.1 www.745970.com
                      127.0.0.1 745970.com
                      127.0.0.1 75tz.com
                      127.0.0.1 www.777search.com
                      127.0.0.1 777search.com
                      127.0.0.1 www.777top.com
                      127.0.0.1 777top.com
                      127.0.0.1 www.7939.com
                      127.0.0.1 7939.com
                      127.0.0.1 www.7search.com
                      127.0.0.1 7search.com
                      127.0.0.1 80gw6ry3i3x3qbrkwhxhw.032439.com
                      127.0.0.1 www.80-music.com
                      127.0.0.1 80-music.com
                      127.0.0.1 82211.net
                      127.0.0.1 8866.org
                      127.0.0.1 www.88vcd.com
                      127.0.0.1 88vcd.com
                      127.0.0.1 www.8ad.com
                      127.0.0.1 8ad.com
                      127.0.0.1 www.90-music.com
                      127.0.0.1 90-music.com
                      127.0.0.1 www.9505.com
                      127.0.0.1 9505.com
                      127.0.0.1 www.971searchbox.com
                      127.0.0.1 971searchbox.com
                      127.0.0.1 9mmporn.com
                      127.0.0.1 a.bestmanage.org
                      127.0.0.1 www.aaabesthomepage.com
                      127.0.0.1 aaabesthomepage.com
                      127.0.0.1 aaasexypics.com
                      127.0.0.1 www.aaawebfinder.com
                      127.0.0.1 aaawebfinder.com
                      127.0.0.1 www.aaqadarsztriv.com
                      127.0.0.1 aaqadarsztriv.com
                      127.0.0.1 www.aaqada-rsztriv.com
                      127.0.0.1 aaqada-rsztriv.com
                      127.0.0.1 www.aaqadaueorn.com
                      127.0.0.1 aaqadaueorn.com
                      127.0.0.1 www.aaqada-ueorn.com
                      127.0.0.1 aaqada-ueorn.com
                      127.0.0.1 www.aaqada-ygco.com
                      127.0.0.1 aaqada-ygco.com
                      127.0.0.1 www.aaqada-ymct.com
                      127.0.0.1 aaqada-ymct.com
                      127.0.0.1 www.aav2008.com
                      127.0.0.1 aav2008.com
                      127.0.0.1 aavc.com
                      127.0.0.1 www.abccodec.com
                      127.0.0.1 abccodec.com
                      127.0.0.1 www.abcdperformance.com
                      127.0.0.1 abcdperformance.com
                      127.0.0.1 www.abc-find.info
                      127.0.0.1 abc-find.info
                      127.0.0.1 www.abcsearch.com
                      127.0.0.1 abcsearch.com
                      127.0.0.1 www.abcways.com
                      127.0.0.1 abcways.com
                      127.0.0.1 www.abetterinternet.com
                      127.0.0.1 abetterinternet.com
                      127.0.0.1 www.abnetsoft.info
                      127.0.0.1 abnetsoft.info
                      127.0.0.1 www.about-adult.net
                      127.0.0.1 about-adult.net
                      127.0.0.1 www.aboutclicker.com
                      127.0.0.1 aboutclicker.com
                      127.0.0.1 www.abrp.net
                      127.0.0.1 abrp.net
                      127.0.0.1 www.absolutee.com
                      127.0.0.1 absolutee.com
                      127.0.0.1 www.abyssmedia.com
                      127.0.0.1 abyssmedia.com
                      127.0.0.1 www.ac66.cn
                      127.0.0.1 ac66.cn
                      127.0.0.1 access.navinetwork.com
                      127.0.0.1 access.rapid-pass.net
                      127.0.0.1 www.accessactivexvideo.com
                      127.0.0.1 accessactivexvideo.com
                      127.0.0.1 www.accessclips.com
                      127.0.0.1 accessclips.com
                      127.0.0.1 www.access-dvd.com
                      127.0.0.1 access-dvd.com
                      127.0.0.1 www.accesskeygenerator.com
                      127.0.0.1 accesskeygenerator.com
                      127.0.0.1 www.accessthefuture.net
                      127.0.0.1 accessthefuture.net
                      127.0.0.1 www.accessvid.net
                      127.0.0.1 accessvid.net
                      127.0.0.1 www.acemedic.com
                      127.0.0.1 acemedic.com
                      127.0.0.1 www.ace-webmaster.com
                      127.0.0.1 ace-webmaster.com
                      127.0.0.1 acjp.com
                      127.0.0.1 www.acrobat-2007.com
                      127.0.0.1 acrobat-2007.com
                      127.0.0.1 www.acrobat-8.com
                      127.0.0.1 acrobat-8.com
                      127.0.0.1 www.acrobat-center.com
                      127.0.0.1 acrobat-center.com
                      127.0.0.1 www.acrobat-hq.com
                      127.0.0.1 acrobat-hq.com
                      127.0.0.1 www.acrobatreader-8.com
                      127.0.0.1 acrobatreader-8.com
                      127.0.0.1 www.acrobat-reader-8.de
                      127.0.0.1 acrobat-reader-8.de
                      127.0.0.1 www.acrobat-stop.com
                      127.0.0.1 acrobat-stop.com
                      127.0.0.1 www.actionbreastcancer.org
                      127.0.0.1 actionbreastcancer.org
                      127.0.0.1 www.activesearcher.info
                      127.0.0.1 activesearcher.info
                      127.0.0.1 www.activexaccessobject.com
                      127.0.0.1 activexaccessobject.com
                      127.0.0.1 www.activexaccessvideo.com
                      127.0.0.1 activexaccessvideo.com
                      127.0.0.1 www.activexemedia.com
                      127.0.0.1 activexemedia.com
                      127.0.0.1 www.activexmediaobject.com
                      127.0.0.1 activexmediaobject.com
                      127.0.0.1 www.activexmediapro.com
                      127.0.0.1 activexmediapro.com
                      127.0.0.1 www.activexmediasite.com
                      127.0.0.1 activexmediasite.com
                      127.0.0.1 www.activexmediasoftware.com
                      127.0.0.1 activexmediasoftware.com
                      127.0.0.1 www.activexmediasource.com
                      127.0.0.1 activexmediasource.com
                      127.0.0.1 www.activexmediatool.com
                      127.0.0.1 activexmediatool.com
                      127.0.0.1 www.activexmediatour.com
                      127.0.0.1 activexmediatour.com
                      127.0.0.1 www.activexsoftwares.com
                      127.0.0.1 activexsoftwares.com
                      127.0.0.1 www.activexsource.com
                      127.0.0.1 activexsource.com
                      127.0.0.1 www.activexupdate.com
                      127.0.0.1 activexupdate.com
                      127.0.0.1 www.activexvideo.com
                      127.0.0.1 activexvideo.com
                      127.0.0.1 www.activexvideotool.com
                      127.0.0.1 activexvideotool.com
                      127.0.0.1 www.ad.marketingsector.com
                      127.0.0.1 ad.marketingsector.com
                      127.0.0.1 www.ad.mokead.com
                      127.0.0.1 ad.mokead.com
                      127.0.0.1 ad.oinadserver.com
                      127.0.0.1 ad.outerinfoads.com
                      127.0.0.1 www.ad25.com
                      127.0.0.1 ad25.com
                      127.0.0.1 www.ad45.com
                      127.0.0.1 ad45.com
                      127.0.0.1 www.ad77.com
                      127.0.0.1 ad77.com
                      127.0.0.1 www.ad86.com
                      127.0.0.1 ad86.com
                      127.0.0.1 www.adamsupportgroup.org
                      127.0.0.1 adamsupportgroup.org
                      127.0.0.1 www.adarmor.com
                      127.0.0.1 adarmor.com
                      127.0.0.1 www.adasearch.com
                      127.0.0.1 adasearch.com
                      127.0.0.1 adaware.cc
                      127.0.0.1 www.adawarenow.com
                      127.0.0.1 adawarenow.com
                      127.0.0.1 adchannel.contextplus.net
                      127.0.0.1 www.addetect.com
                      127.0.0.1 addetect.com
                      127.0.0.1 www.add-hhh.info
                      127.0.0.1 add-hhh.info
                      127.0.0.1 www.addictivetechnologies.com
                      127.0.0.1 addictivetechnologies.com
                      127.0.0.1 www.addictivetechnologies.net
                      127.0.0.1 addictivetechnologies.net
                      127.0.0.1 www.addioerrori.com
                      127.0.0.1 addioerrori.com
                      127.0.0.1 www.add-manager.com
                      127.0.0.1 add-manager.com
                      127.0.0.1 www.adgate.info
                      127.0.0.1 adgate.info
                      127.0.0.1 www.adintelligence.net
                      127.0.0.1 adintelligence.net
                      127.0.0.1 www.adioserrores.com
                      127.0.0.1 adioserrores.com
                      127.0.0.1 www.adipics.com
                      127.0.0.1 adipics.com
                      127.0.0.1 www.adlogix.com
                      127.0.0.1 adlogix.com
                      127.0.0.1 www.admin2cash.biz
                      127.0.0.1 admin2cash.biz
                      127.0.0.1 adnet-plus.com
                      127.0.0.1 www.adnetserver.com
                      127.0.0.1 adnetserver.com
                      127.0.0.1 adobe-download-now.com
                      127.0.0.1 www.adobe-downloads.com
                      127.0.0.1 adobe-downloads.com
                      127.0.0.1 www.adobe-reader-8.fr
                      127.0.0.1 adobe-reader-8.fr
                      127.0.0.1 www.adprotect.com
                      127.0.0.1 adprotect.com
                      127.0.0.1 ads.centralmedia.ws
                      127.0.0.1 ads.k8l.info
                      127.0.0.1 ads.kmpads.com
                      127.0.0.1 ads.kw.revenue.net
                      127.0.0.1 ads.marketingsector.com
                      127.0.0.1 ads.searchingbooth.com
                      127.0.0.1 ads.z-quest.com
                      127.0.0.1 ads1.revenue.net
                      127.0.0.1 www.ads183.com
                      127.0.0.1 ads183.com
                      127.0.0.1 www.adscontex.com
                      127.0.0.1 adscontex.com
                      127.0.0.1 www.adservices1.enhance.com
                      127.0.0.1 adservices1.enhance.com
                      127.0.0.1 adservs.com
                      127.0.0.1 www.adsextend.net
                      127.0.0.1 adsextend.net
                      127.0.0.1 www.adshttp.com
                      127.0.0.1 adshttp.com
                      127.0.0.1 www.adsniffer.com
                      127.0.0.1 adsniffer.com
                      127.0.0.1 www.adsonwww.com
                      127.0.0.1 adsonwww.com
                      127.0.0.1 www.adspics.com
                      127.0.0.1 adspics.com
                      127.0.0.1 www.adsrevenue.net
                      127.0.0.1 adsrevenue.net
                      127.0.0.1 www.adtrak.net
                      127.0.0.1 adtrak.net
                      127.0.0.1 adtrgt.com
                      127.0.0.1 www.adult18codec.com
                      127.0.0.1 adult18codec.com
                      127.0.0.1 www.adult777search.info
                      127.0.0.1 adult777search.info
                      127.0.0.1 www.adultan.com
                      127.0.0.1 adultan.com
                      127.0.0.1 www.adultcodec-2008.com
                      127.0.0.1 adultcodec-2008.com
                      127.0.0.1 www.adultcodecstars.com
                      127.0.0.1 adultcodecstars.com
                      127.0.0.1 www.adult-engine-search.com
                      127.0.0.1 adult-engine-search.com
                      127.0.0.1 www.adult-erotic-guide.net
                      127.0.0.1 adult-erotic-guide.net
                      127.0.0.1 www.adultfilmsite.com
                      127.0.0.1 adultfilmsite.com
                      127.0.0.1 www.adult-friends-finder.net
                      127.0.0.1 adult-friends-finder.net
                      127.0.0.1 adultgambling.org
                      127.0.0.1 adult-host.org
                      127.0.0.1 www.adulthyperlinks.com
                      127.0.0.1 adulthyperlinks.com
                      127.0.0.1 www.adultmovieplus.com
                      127.0.0.1 adultmovieplus.com
                      127.0.0.1 www.adult-mpg.net
                      127.0.0.1 adult-mpg.net
                      127.0.0.1 adult-personal.us
                      127.0.0.1 adultsgames.net
                      127.0.0.1 www.adultsonlyvids.com
                      127.0.0.1 adultsonlyvids.com
                      127.0.0.1 www.adultsper.com
                      127.0.0.1 adultsper.com
                      127.0.0.1 www.adulttds.com
                      127.0.0.1 adulttds.com
                      127.0.0.1 www.adultzoneworld.com
                      127.0.0.1 adultzoneworld.com
                      127.0.0.1 www.advancedcleaner.com
                      127.0.0.1 advancedcleaner.com
                      127.0.0.1 www.advcash.biz
                      127.0.0.1 advcash.biz
                      127.0.0.1 advert.exaccess.ru
                      127.0.0.1 www.advertisemoney.info
                      127.0.0.1 advertisemoney.info
                      127.0.0.1 advertising.paltalk.com
                      127.0.0.1 www.advertising-money.info
                      127.0.0.1 advertising-money.info
                      127.0.0.1 ad-ware.cc
                      127.0.0.1 www.ad-w-a-r-e.com
                      127.0.0.1 ad-w-a-r-e.com
                      127.0.0.1 www.a-d-w-a-r-e.com
                      127.0.0.1 a-d-w-a-r-e.com
                      127.0.0.1 www.adware.pro
                      127.0.0.1 adware.pro
                      127.0.0.1 www.adwarealert.com
                      127.0.0.1 adwarealert.com
                      127.0.0.1 www.ad-warealert.com
                      127.0.0.1 ad-warealert.com
                      127.0.0.1 www.adwarearrest.com
                      127.0.0.1 adwarearrest.com
                      127.0.0.1 www.adwarebazooka.com
                      127.0.0.1 adwarebazooka.com
                      127.0.0.1 www.adwarecommander.com
                      127.0.0.1 adwarecommander.com
                      127.0.0.1 www.adwarefinder.com
                      127.0.0.1 adwarefinder.com
                      127.0.0.1 www.adwaregold.com
                      127.0.0.1 adwaregold.com
                      127.0.0.1 www.adwarepatrol.com
                      127.0.0.1 adwarepatrol.com
                      127.0.0.1 www.adwareplatinum.com
                      127.0.0.1 adwareplatinum.com
                      127.0.0.1 www.adwareprotectionsite.com
                      127.0.0.1 adwareprotectionsite.com
                      127.0.0.1 www.adwarepunisher.com
                      127.0.0.1 adwarepunisher.com
                      127.0.0.1 www.adwareremover.ws
                      127.0.0.1 adwareremover.ws
                      127.0.0.1 www.adwaresafety.com
                      127.0.0.1 adwaresafety.com
                      127.0.0.1 www.adwarexp.com
                      127.0.0.1 adwarexp.com
                      127.0.0.1 affiliate.idownload.com
                      127.0.0.1 www.aflgate.com
                      127.0.0.1 aflgate.com
                      127.0.0.1 africaspromise.org
                      127.0.0.1 agava.com
                      127.0.0.1 agava.ru
                      127.0.0.1 agentstudio.com
                      127.0.0.1 www.ageofconans.net
                      127.0.0.1 ageofconans.net
                      127.0.0.1 www.aginegialle.it
                      127.0.0.1 aginegialle.it
                      127.0.0.1 www.ahnenforschung.de
                      127.0.0.1 ahnenforschung.de
                      127.0.0.1 www.aifind.info
                      127.0.0.1 aifind.info
                      127.0.0.1 www.airtleworld.com
                      127.0.0.1 airtleworld.com
                      127.0.0.1 www.aitalia.it
                      127.0.0.1 aitalia.it
                      127.0.0.1 akamai.downloadv3.com
                      127.0.0.1 www.aklitalia.it
                      127.0.0.1 aklitalia.it
                      127.0.0.1 akril.com
                      127.0.0.1 alcatel.ws
                      127.0.0.1 www.alertspy.com
                      127.0.0.1 alertspy.com
                      127.0.0.1 www.alfacleaner.com
                      127.0.0.1 alfacleaner.com
                      127.0.0.1 alfa-search.com
                      127.0.0.1 www.alialia.it
                      127.0.0.1 alialia.it
                      127.0.0.1 www.aliotalia.it
                      127.0.0.1 aliotalia.it
                      127.0.0.1 www.alirtalia.it
                      127.0.0.1 alirtalia.it
                      127.0.0.1 www.alitaia.it
                      127.0.0.1 alitaia.it
                      127.0.0.1 www.alitaklia.it
                      127.0.0.1 alitaklia.it
                      127.0.0.1 www.alitala.it
                      127.0.0.1 alitala.it
                      127.0.0.1 www.alitali.it
                      127.0.0.1 alitali.it
                      127.0.0.1 www.alitaliaq.it
                      127.0.0.1 alitaliaq.it
                      127.0.0.1 www.alitalias.it
                      127.0.0.1 alitalias.it
                      127.0.0.1 www.alitaliaz.it
                      127.0.0.1 alitaliaz.it
                      127.0.0.1 www.alitalioa.it
                      127.0.0.1 alitalioa.it
                      127.0.0.1 www.alitalisa.it
                      127.0.0.1 alitalisa.it
                      127.0.0.1 www.alitaliua.it
                      127.0.0.1 alitaliua.it
                      127.0.0.1 www.alitalkia.it
                      127.0.0.1 alitalkia.it
                      127.0.0.1 www.alitaloia.it
                      127.0.0.1 alitaloia.it
                      127.0.0.1 www.alitaluia.it
                      127.0.0.1 alitaluia.it
                      127.0.0.1 www.alitaslia.it
                      127.0.0.1 alitaslia.it
                      127.0.0.1 www.alitlia.it
                      127.0.0.1 alitlia.it
                      127.0.0.1 www.alitralia.it
                      127.0.0.1 alitralia.it
                      127.0.0.1 www.alitsalia.it
                      127.0.0.1 alitsalia.it
                      127.0.0.1 www.aliutalia.it
                      127.0.0.1 aliutalia.it
                      127.0.0.1 www.all1count.net
                      127.0.0.1 all1count.net
                      127.0.0.1 www.all4internet.com
                      127.0.0.1 all4internet.com
                      127.0.0.1 allabtcars.com
                      127.0.0.1 allabtjeeps.com
                      127.0.0.1 www.all-bittorrent.com
                      127.0.0.1 all-bittorrent.com
                      127.0.0.1 www.allcollisions.com
                      127.0.0.1 allcollisions.com
                      127.0.0.1 www.allcybersearch.com
                      127.0.0.1 allcybersearch.com
                      127.0.0.1 www.alldnserrors.com
                      127.0.0.1 alldnserrors.com
                      127.0.0.1 www.all-downloads-now.com
                      127.0.0.1 all-downloads-now.com
                      127.0.0.1 www.all-edonkey.com
                      127.0.0.1 all-edonkey.com
                      127.0.0.1 www.allertaminacce.com
                      127.0.0.1 allertaminacce.com
                      127.0.0.1 allforadult.com
                      127.0.0.1 allhyperlinks.com
                      127.0.0.1 www.alliesecurity.com
                      127.0.0.1 alliesecurity.com
                      127.0.0.1 all-inet.com
                      127.0.0.1 allinternetbusiness.com
                      127.0.0.1 www.all-limewire.com
                      127.0.0.1 all-limewire.com
                      127.0.0.1 www.allmegabucks.com
                      127.0.0.1 allmegabucks.com
                      127.0.0.1 www.allprotections.com
                      127.0.0.1 allprotections.com
                      127.0.0.1 www.allresultz.net
                      127.0.0.1 allresultz.net
                      127.0.0.1 www.allsearch.us
                      127.0.0.1 allsearch.us
                      127.0.0.1 www.allsecuritynotes.com
                      127.0.0.1 allsecuritynotes.com
                      127.0.0.1 www.allsecuritysite.com
                      127.0.0.1 allsecuritysite.com
                      127.0.0.1 www.allstarsvideos.net
                      127.0.0.1 allstarsvideos.net
                      127.0.0.1 www.alltiettantivirus.com
                      127.0.0.1 alltiettantivirus.com
                      127.0.0.1 www.alltruesoftware.com
                      127.0.0.1 alltruesoftware.com
                      127.0.0.1 www.allvideoactivex.com
                      127.0.0.1 allvideoactivex.com
                      127.0.0.1 www.almanah.biz
                      127.0.0.1 almanah.biz
                      127.0.0.1 almarvideos.com
                      127.0.0.1 www.aloitalia.it
                      127.0.0.1 aloitalia.it
                      127.0.0.1 www.aluitalia.it
                      127.0.0.1 aluitalia.it
                      127.0.0.1 www.amaena.com
                      127.0.0.1 amaena.com
                      127.0.0.1 amandamountains.com
                      127.0.0.1 www.amateurliveshow.com
                      127.0.0.1 amateurliveshow.com
                      127.0.0.1 www.amediasoftware.com
                      127.0.0.1 amediasoftware.com
                      127.0.0.1 www.amediasource.com
                      127.0.0.1 amediasource.com
                      127.0.0.1 www.americanautobargains.com
                      127.0.0.1 americanautobargains.com
                      127.0.0.1 www.americancarbargains.com
                      127.0.0.1 americancarbargains.com
                      127.0.0.1 american-teens.net
                      127.0.0.1 amigeek.com
                      127.0.0.1 www.amigobore.com
                      127.0.0.1 amigobore.com
                      127.0.0.1 amisbusiness.com
                      127.0.0.1 www.ampmsearch.com
                      127.0.0.1 ampmsearch.com
                      127.0.0.1 www.analcord.com
                      127.0.0.1 analcord.com
                      127.0.0.1 analmovi.com
                      127.0.0.1 www.anarchylolita.com
                      127.0.0.1 anarchylolita.com
                      127.0.0.1 anarchyporn.com
                      127.0.0.1 www.andromedical.com
                      127.0.0.1 andromedical.com
                      127.0.0.1 www.animepornmag.com
                      127.0.0.1 animepornmag.com
                      127.0.0.1 anin.org
                      127.0.0.1 www.anjpn-avxiz.biz
                      127.0.0.1 anjpn-avxiz.biz
                      127.0.0.1 www.anjpnzqav.biz
                      127.0.0.1 anjpnzqav.biz
                      127.0.0.1 www.anjpn-zqav.biz
                      127.0.0.1 anjpn-zqav.biz
                      127.0.0.1 annaromeo.com
                      127.0.0.1 www.antiddos.us
                      127.0.0.1 antiddos.us
                      127.0.0.1 www.antiespiadorado.com
                      127.0.0.1 antiespiadorado.com
                      127.0.0.1 www.antiespionspack.com
                      127.0.0.1 antiespionspack.com
                      127.0.0.1 www.antigusanos2008.com
                      127.0.0.1 antigusanos2008.com
                      127.0.0.1 www.antispamassistant.com
                      127.0.0.1 antispamassistant.com
                      127.0.0.1 www.antispamdeluxe.com
                      127.0.0.1 antispamdeluxe.com
                      127.0.0.1 www.antispionage.com
                      127.0.0.1 antispionage.com
                      127.0.0.1 www.antispionagepro.com
                      127.0.0.1 antispionagepro.com
                      127.0.0.1 www.antispyadvanced.com
                      127.0.0.1 antispyadvanced.com
                      127.0.0.1 www.antispycheck.com
                      127.0.0.1 antispycheck.com
                      127.0.0.1 www.antispydns.biz
                      127.0.0.1 antispydns.biz
                      127.0.0.1 www.antispykit.com
                      127.0.0.1 antispykit.com
                      127.0.0.1 www.antispylab.com
                      127.0.0.1 antispylab.com
                      127.0.0.1 www.antispyshield.com
                      127.0.0.1 antispyshield.com
                      127.0.0.1 www.antispysolutions.com
                      127.0.0.1 antispysolutions.com
                      127.0.0.1 www.antispyware.com
                      127.0.0.1 antispyware.com
                      127.0.0.1 www.antispyware-2008.info
                      127.0.0.1 antispyware-2008.info
                      127.0.0.1 www.antispyware2008.name
                      127.0.0.1 antispyware2008.name
                      127.0.0.1 www.antispyware-2008.name
                      127.0.0.1 antispyware-2008.name
                      127.0.0.1 www.antispyware2008.org
                      127.0.0.1 antispyware2008.org
                      127.0.0.1 www.antispyware-2008.org
                      127.0.0.1 antispyware-2008.org
                      127.0.0.1 www.antispyware2008-download.com
                      127.0.0.1 antispyware2008-download.com
                      127.0.0.1 www.antispyware-2008-download.com
                      127.0.0.1 antispyware-2008-download.com
                      127.0.0.1 www.antispyware2008-download.name
                      127.0.0.1 antispyware2008-download.name
                      127.0.0.1 www.antispyware2008-download.org
                      127.0.0.1 antispyware2008-download.org
                      127.0.0.1 www.antispyware-2008-download.org
                      127.0.0.1 antispyware-2008-download.org
                      127.0.0.1 www.antispywareboot.com
                      127.0.0.1 antispywareboot.com
                      127.0.0.1 www.antispywarebot.com
                      127.0.0.1 antispywarebot.com
                      127.0.0.1 www.antispywarebox.com
                      127.0.0.1 antispywarebox.com
                      127.0.0.1 www.antispywaredownloads.com
                      127.0.0.1 antispywaredownloads.com
                      127.0.0.1 www.antispywaresuite.com
                      127.0.0.1 antispywaresuite.com
                      127.0.0.1 www.antispywareupdates.net
                      127.0.0.1 antispywareupdates.net
                      127.0.0.1 www.antispywarexp.com
                      127.0.0.1 antispywarexp.com
                      127.0.0.1 www.antispyweb.net
                      127.0.0.1 antispyweb.net
                      127.0.0.1 www.antiver2008.com
                      127.0.0.1 antiver2008.com
                      127.0.0.1 www.antivermins.com
                      127.0.0.1 antivermins.com
                      127.0.0.1 www.anti-vermins.com
                      127.0.0.1 anti-vermins.com
                      127.0.0.1 www.antivir2007.com
                      127.0.0.1 antivir2007.com
                      127.0.0.1 www.antivirgear.com
                      127.0.0.1 antivirgear.com
                      127.0.0.1 www.antivirprotect.com
                      127.0.0.1 antivirprotect.com
                      127.0.0.1 www.antivirus.fastfreedownload.com
                      127.0.0.1 antivirus.fastfreedownload.com
                      127.0.0.1 www.antivirus2008pro.com
                      127.0.0.1 antivirus2008pro.com
                      127.0.0.1 www.antivirus-2008pro.com
                      127.0.0.1 antivirus-2008pro.com
                      127.0.0.1 www.antivirus-2008-pro.com
                      127.0.0.1 antivirus-2008-pro.com
                      127.0.0.1 www.antivirus2008pro.info
                      127.0.0.1 antivirus2008pro.info
                      127.0.0.1 www.antivirus-2008pro.info
                      127.0.0.1 antivirus-2008pro.info
                      127.0.0.1 www.antivirus-2008-pro.info
                      127.0.0.1 antivirus-2008-pro.info
                      127.0.0.1 www.antivirus2008pro.net
                      127.0.0.1 antivirus2008pro.net
                      127.0.0.1 www.antivirus-2008pro.net
                      127.0.0.1 antivirus-2008pro.net
                      127.0.0.1 www.antivirus-2008-pro.net
                      127.0.0.1 antivirus-2008-pro.net
                      127.0.0.1 www.antivirus2008pro.org
                      127.0.0.1 antivirus2008pro.org
                      127.0.0.1 www.antivirus-2008pro.org
                      127.0.0.1 antivirus-2008pro.org
                      127.0.0.1 www.antivirus-2008-pro.org
                      127.0.0.1 antivirus-2008-pro.org
                      127.0.0.1 www.antivirus2008scanner.com
                      127.0.0.1 antivirus2008scanner.com
                      127.0.0.1 www.antivirus2008x.com
                      127.0.0.1 antivirus2008x.com
                      127.0.0.1 www.antivirus2009-freescan.com
                      127.0.0.1 antivirus2009-freescan.com
                      127.0.0.1 www.antivirusadvance.com
                      127.0.0.1 antivirusadvance.com
                      127.0.0.1 www.antivirusaskeladd.com
                      127.0.0.1 antivirusaskeladd.com
                      127.0.0.1 www.antivirus-database.com
                      127.0.0.1 antivirus-database.com
                      127.0.0.1 www.antivirusgereedschap.com
                      127.0.0.1 antivirusgereedschap.com
                      127.0.0.1 www.antivirusgolden.com
                      127.0.0.1 antivirusgolden.com
                      127.0.0.1 www.antivirus-hq.net
                      127.0.0.1 antivirus-hq.net
                      127.0.0.1 www.antiviruspcsuite.com
                      127.0.0.1 antiviruspcsuite.com
                      127.0.0.1 www.antiviruspremium.com
                      127.0.0.1 antiviruspremium.com
                      127.0.0.1 www.anti-virus-pro.com
                      127.0.0.1 anti-virus-pro.com
                      127.0.0.1 www.antivirusprotector.com
                      127.0.0.1 antivirusprotector.com
                      127.0.0.1 www.antivirus-scanner.com
                      127.0.0.1 antivirus-scanner.com
                      127.0.0.1 www.antivirusscherm.com
                      127.0.0.1 antivirusscherm.com
                      127.0.0.1 www.antivirussecuritypro.com
                      127.0.0.1 antivirussecuritypro.com
                      127.0.0.1 www.antivirus-server.com
                      127.0.0.1 antivirus-server.com
                      127.0.0.1 www.antivirus-stop.com
                      127.0.0.1 antivirus-stop.com
                      127.0.0.1 www.antivirussuite.com
                      127.0.0.1 antivirussuite.com
                      127.0.0.1 www.antiworm2008.com
                      127.0.0.1 antiworm2008.com
                      127.0.0.1 www.antiwurm2008.com
                      127.0.0.1 antiwurm2008.com
                      127.0.0.1 antrocity.com
                      127.0.0.1 www.anyofus.com
                      127.0.0.1 anyofus.com
                      127.0.0.1 www.anysafereviews.com
                      127.0.0.1 anysafereviews.com
                      127.0.0.1 www.anysn.seproger.com
                      127.0.0.1 anysn.seproger.com
                      127.0.0.1 anything4health.com
                      127.0.0.1 www.apicpreview.com
                      127.0.0.1 apicpreview.com
                      127.0.0.1 www.appealcircuit.com
                      127.0.0.1 appealcircuit.com
                      127.0.0.1 www.approvedlinks.com
                      127.0.0.1 approvedlinks.com
                      127.0.0.1 apps.deskwizz.com
                      127.0.0.1 apps.webservicehost.com
                      127.0.0.1 www.aprotectedpage.com
                      127.0.0.1 aprotectedpage.com
                      127.0.0.1 apsua.com
                      127.0.0.1 www.archivioadulti.com
                      127.0.0.1 archivioadulti.com
                      127.0.0.1 www.archiviosex.net
                      127.0.0.1 archiviosex.net
                      127.0.0.1 aregay.com
                      127.0.0.1 www.ares.click-new-download.com
                      127.0.0.1 ares.click-new-download.com
                      127.0.0.1 www.ares-freebie.com
                      127.0.0.1 ares-freebie.com
                      127.0.0.1 www.arespro2007.com
                      127.0.0.1 arespro2007.com
                      127.0.0.1 www.aresultra.com
                      127.0.0.1 aresultra.com
                      127.0.0.1 www.ares-usa.com
                      127.0.0.1 ares-usa.com
                      127.0.0.1 arheo.com
                      127.0.0.1 arizonaweb.org
                      127.0.0.1 armitageinn.com
                      127.0.0.1 www.arquivojpgs.smtp.ru
                      127.0.0.1 arquivojpgs.smtp.ru
                      127.0.0.1 artachnid.com
                      127.0.0.1 art-func.com
                      127.0.0.1 art-xxx.com
                      127.0.0.1 www.asafebrowser.com
                      127.0.0.1 asafebrowser.com
                      127.0.0.1 www.asafetyalways.com
                      127.0.0.1 asafetyalways.com
                      127.0.0.1 www.asafetynote.com
                      127.0.0.1 asafetynote.com
                      127.0.0.1 www.asafetynotice.com
                      127.0.0.1 asafetynotice.com
                      127.0.0.1 www.asafetypage.com
                      127.0.0.1 asafetypage.com
                      127.0.0.1 www.asdbiz.biz
                      127.0.0.1 asdbiz.biz
                      127.0.0.1 www.asdeykuddq.com
                      127.0.0.1 asdeykuddq.com
                      127.0.0.1 www.asecurebar.com
                      127.0.0.1 asecurebar.com
                      127.0.0.1 www.asecureboard.com
                      127.0.0.1 asecureboard.com
                      127.0.0.1 www.asecurevalue.com
                      127.0.0.1 asecurevalue.com
                      127.0.0.1 www.asecurityissue.com
                      127.0.0.1 asecurityissue.com
                      127.0.0.1 www.asecuritynotice.com
                      127.0.0.1 asecuritynotice.com
                      127.0.0.1 www.asecuritypaper.com
                      127.0.0.1 asecuritypaper.com
                      127.0.0.1 www.asecuritystuff.com
                      127.0.0.1 asecuritystuff.com
                      127.0.0.1 www.asfadaptation.com
                      127.0.0.1 asfadaptation.com
                      127.0.0.1 asiankingkong.com
                      127.0.0.1 www.asianpornmag.com
                      127.0.0.1 asianpornmag.com
                      127.0.0.1 www.asiantoolbar.com
                      127.0.0.1 asiantoolbar.com
                      127.0.0.1 www.asidseiupc.com
                      127.0.0.1 asidseiupc.com
                      127.0.0.1 www.aslitalia.it
                      127.0.0.1 aslitalia.it
                      127.0.0.1 ass-gals.com
                      127.0.0.1 www.assureprotection.com
                      127.0.0.1 assureprotection.com
                      127.0.0.1 asta-killer.com
                      127.0.0.1 www.astrologie-server.com
                      127.0.0.1 astrologie-server.com
                      127.0.0.1 www.asupereva.it
                      127.0.0.1 asupereva.it
                      127.0.0.1 www.ataprogram.com
                      127.0.0.1 ataprogram.com
                      127.0.0.1 athenrye.com
                      127.0.0.1 www.atotalsafety.com
                      127.0.0.1 atotalsafety.com
                      127.0.0.1 www.atrueprotection.com
                      127.0.0.1 atrueprotection.com
                      127.0.0.1 www.atruesecurity.com
                      127.0.0.1 atruesecurity.com
                      127.0.0.1 www.attackware.com
                      127.0.0.1 attackware.com
                      127.0.0.1 www.attrezzi.biz
                      127.0.0.1 attrezzi.biz
                      127.0.0.1 www.aucunsvirus.com
                      127.0.0.1 aucunsvirus.com
                      127.0.0.1 www.aulde.net
                      127.0.0.1 aulde.net
                      127.0.0.1 www.aupereva.it
                      127.0.0.1 aupereva.it
                      127.0.0.1 www.autobargains.org
                      127.0.0.1 autobargains.org
                      127.0.0.1 www.autobargainsnetwork.com
                      127.0.0.1 autobargainsnetwork.com
                      127.0.0.1 www.autocontext.begun.ru
                      127.0.0.1 autocontext.begun.ru
                      127.0.0.1 autoescrowpay.com
                      127.0.0.1 www.autotuningportal.com
                      127.0.0.1 autotuningportal.com
                      127.0.0.1 www.avadvance.com
                      127.0.0.1 avadvance.com
                      127.0.0.1 www.avast.free-software-center.com
                      127.0.0.1 avast.free-software-center.com
                      127.0.0.1 www.avast-2007.com
                      127.0.0.1 avast-2007.com
                      127.0.0.1 www.avast-downloads.com
                      127.0.0.1 avast-downloads.com
                      127.0.0.1 www.avast-hq.com
                      127.0.0.1 avast-hq.com
                      127.0.0.1 www.avforce.com
                      127.0.0.1 avforce.com
                      127.0.0.1 www.avg.grab-it-today.net
                      127.0.0.1 avg.grab-it-today.net
                      127.0.0.1 www.avg.softwarecenterz.com
                      127.0.0.1 avg.softwarecenterz.com
                      127.0.0.1 www.avg-secure.com
                      127.0.0.1 avg-secure.com
                      127.0.0.1 www.aviadaptation.com
                      127.0.0.1 aviadaptation.com
                      127.0.0.1 avian-ads.com
                      127.0.0.1 www.avicoupler.com
                      127.0.0.1 avicoupler.com
                      127.0.0.1 www.avideoaxaccess.com
                      127.0.0.1 avideoaxaccess.com
                      127.0.0.1 www.avideosurfer.com
                      127.0.0.1 avideosurfer.com
                      127.0.0.1 www.avidirection.com
                      127.0.0.1 avidirection.com
                      127.0.0.1 www.aviewersoft.com
                      127.0.0.1 aviewersoft.com
                      127.0.0.1 www.aviexecution.com
                      127.0.0.1 aviexecution.com
                      127.0.0.1 www.avihelper.com
                      127.0.0.1 avihelper.com
                      127.0.0.1 www.aviinstrument.com
                      127.0.0.1 aviinstrument.com
                      127.0.0.1 www.avitool.com
                      127.0.0.1 avitool.com
                      127.0.0.1 www.aviutility.com
                      127.0.0.1 aviutility.com
                      127.0.0.1 www.avpcheckupdate.com
                      127.0.0.1 avpcheckupdate.com
                      127.0.0.1 www.avsmanufacture.com
                      127.0.0.1 avsmanufacture.com
                      127.0.0.1 www.avsystemcare.com
                      127.0.0.1 avsystemcare.com
                      127.0.0.1 www.avxizaaqada.biz
                      127.0.0.1 avxizaaqada.biz
                      127.0.0.1 www.avxiz-anjpn.biz
                      127.0.0.1 avxiz-anjpn.biz
                      127.0.0.1 www.avxizueorn.biz
                      127.0.0.1 avxizueorn.biz
                      127.0.0.1 www.avxiz-ueorn.biz
                      127.0.0.1 avxiz-ueorn.biz
                      127.0.0.1 www.avxiz-vtvcp.biz
                      127.0.0.1 avxiz-vtvcp.biz
                      127.0.0.1 www.avxiz-ygco.biz
                      127.0.0.1 avxiz-ygco.biz
                      127.0.0.1 www.avxiz-zqav.biz
                      127.0.0.1 avxiz-zqav.biz
                      127.0.0.1 www.awarenesstech.com
                      127.0.0.1 awarenesstech.com
                      127.0.0.1 www.awarninglist.com
                      127.0.0.1 awarninglist.com
                      127.0.0.1 awbeta.net-nucleus.com
                      127.0.0.1 www.awesomehomepage.com
                      127.0.0.1 awesomehomepage.com
                      127.0.0.1 awmcash.biz
                      127.0.0.1 awmdabest.com
                      127.0.0.1 www.axemediasoftware.com
                      127.0.0.1 axemediasoftware.com
                      127.0.0.1 www.aximageobject.com
                      127.0.0.1 aximageobject.com
                      127.0.0.1 www.axmediaproject.com
                      127.0.0.1 axmediaproject.com
                      127.0.0.1 www.axmediasoftware.com
                      127.0.0.1 axmediasoftware.com
                      127.0.0.1 www.axmediasolutions.com
                      127.0.0.1 axmediasolutions.com
                      127.0.0.1 www.axobjectpage.com
                      127.0.0.1 axobjectpage.com
                      127.0.0.1 www.axobjectsource.com
                      127.0.0.1 axobjectsource.com
                      127.0.0.1 www.axsoftwaretool.com
                      127.0.0.1 axsoftwaretool.com
                      127.0.0.1 www.axvideoproject.com
                      127.0.0.1 axvideoproject.com
                      127.0.0.1 www.axvideosetup.com
                      127.0.0.1 axvideosetup.com
                      127.0.0.1 ayakawamura.com
                      127.0.0.1 ayb.dns-look-up.com
                      127.0.0.1 ayb.netbios-wait.com
                      127.0.0.1 ayumitaniguchi.com
                      127.0.0.1 azebar.com
                      127.0.0.1 www.azureusclub.com
                      127.0.0.1 azureusclub.com
                      127.0.0.1 www.azureus-freebie.com
                      127.0.0.1 azureus-freebie.com
                      127.0.0.1 www.azzetta.it
                      127.0.0.1 azzetta.it
                      127.0.0.1 b.casalemedia.com
                      127.0.0.1 b122.mcboo.com
                      127.0.0.1 www.babe.k-lined.com
                      127.0.0.1 babe.k-lined.com
                      127.0.0.1 www.babe.the-killer.bz
                      127.0.0.1 babe.the-killer.bz
                      127.0.0.1 www.babenet.com
                      127.0.0.1 babenet.com
                      127.0.0.1 www.babespornmag.com
                      127.0.0.1 babespornmag.com
                      127.0.0.1 www.babeweb.de
                      127.0.0.1 babeweb.de
                      127.0.0.1 www.baccarat-other.info
                      127.0.0.1 baccarat-other.info
                      127.0.0.1 www.backstripgirls.com
                      127.0.0.1 backstripgirls.com
                      127.0.0.1 backup.mabou.org
                      127.0.0.1 www.baiduqqsina.cn
                      127.0.0.1 baiduqqsina.cn
                      127.0.0.1 www.balotierra.com
                      127.0.0.1 balotierra.com
                      127.0.0.1 bannedhost.net
                      127.0.0.1 barbudafarms.com
                      127.0.0.1 www.bardownload.com
                      127.0.0.1 bardownload.com
                      127.0.0.1 barnandfence.com
                      127.0.0.1 www.basteln-und-heimwerken.com
                      127.0.0.1 basteln-und-heimwerken.com
                      127.0.0.1 batsearch.com
                      127.0.0.1 baygraphicsllc.com
                      127.0.0.1 bb.wudiliuliang.com
                      127.0.0.1 bbbsearch.com
                      127.0.0.1 bb-search.com
                      127.0.0.1 www.bcnproduction.com
                      127.0.0.1 bcnproduction.com
                      127.0.0.1 bdsmlibrary.net
                      127.0.0.1 www.bdsmpornmag.com
                      127.0.0.1 bdsmpornmag.com
                      127.0.0.1 www.bealent.com
                      127.0.0.1 bealent.com
                      127.0.0.1 www.bearshare.click-new-download.com
                      127.0.0.1 bearshare.click-new-download.com
                      127.0.0.1 www.bearshare.download-me.info
                      127.0.0.1 bearshare.download-me.info
                      127.0.0.1 www.bearshare.mp3-muzic.com
                      127.0.0.1 bearshare.mp3-muzic.com
                      127.0.0.1 www.bearshare-download.org
                      127.0.0.1 bearshare-download.org
                      127.0.0.1 www.bearshare-downloads.net
                      127.0.0.1 bearshare-downloads.net
                      127.0.0.1 www.bearsharelive.co.uk
                      127.0.0.1 bearsharelive.co.uk
                      127.0.0.1 www.bearshare-music-downloads.com
                      127.0.0.1 bearshare-music-downloads.com
                      127.0.0.1 www.bearsharepro2007.com
                      127.0.0.1 bearsharepro2007.com
                      127.0.0.1 www.bearshare-usa.com
                      127.0.0.1 bearshare-usa.com
                      127.0.0.1 bedhome.com
                      127.0.0.1 bediadance.com
                      127.0.0.1 www.beebappyy.biz
                      127.0.0.1 beebappyy.biz
                      127.0.0.1 www.begin2search.com
                      127.0.0.1 begin2search.com
                      127.0.0.1 bellabasketsfl.com
                      127.0.0.1 bernaolatwin.com
                      127.0.0.1 www.berufe-jobs.de
                      127.0.0.1 berufe-jobs.de
                      127.0.0.1 www.berufe-server.de
                      127.0.0.1 berufe-server.de
                      127.0.0.1 www.berufe-welt.de
                      127.0.0.1 berufe-welt.de
                      127.0.0.1 www.berufs-wahl.de
                      127.0.0.1 berufs-wahl.de
                      127.0.0.1 www.beruijindegunhadesun.com
                      127.0.0.1 beruijindegunhadesun.com
                      127.0.0.1 www.best3xclips.com
                      127.0.0.1 best3xclips.com
                      127.0.0.1 www.bestadults.com
                      127.0.0.1 bestadults.com
                      127.0.0.1 www.best-codec.com
                      127.0.0.1 best-codec.com
                      127.0.0.1 best-counter.com
                      127.0.0.1 bestcrawler.com
                      127.0.0.1 www.bestdailyvids.com
                      127.0.0.1 bestdailyvids.com
                      127.0.0.1 bestfor.ru
                      127.0.0.1 www.bestfuckvids.com
                      127.0.0.1 bestfuckvids.com
                      127.0.0.1 best-hardpics.com
                      127.0.0.1 www.bestmanage.org
                      127.0.0.1 bestmanage.org
                      127.0.0.1 www.bestmanage0.org
                      127.0.0.1 bestmanage0.org
                      127.0.0.1 www.bestmanage1.org
                      127.0.0.1 bestmanage1.org
                      127.0.0.1 www.bestmanage2.org
                      127.0.0.1 bestmanage2.org
                      127.0.0.1 www.bestmanage3.org
                      127.0.0.1 bestmanage3.org
                      127.0.0.1 www.bestmanage4.org
                      127.0.0.1 bestmanage4.org
                      127.0.0.1 www.bestmanage5.org
                      127.0.0.1 bestmanage5.org
                      127.0.0.1 www.bestmanage6.org
                      127.0.0.1 bestmanage6.org
                      127.0.0.1 www.bestmanage7.org
                      127.0.0.1 bestmanage7.org
                      127.0.0.1 www.bestmanage8.org
                      127.0.0.1 bestmanage8.org
                      127.0.0.1 www.bestmanage9.org
                      127.0.0.1 bestmanage9.org
                      127.0.0.1 www.bestmovszone.com
                      127.0.0.1 bestmovszone.com
                      127.0.0.1 www.bestoffersnetworks.com
                      127.0.0.1 bestoffersnetworks.com
                      127.0.0.1 www.best-porncollection.com
                      127.0.0.1 best-porncollection.com
                      127.0.0.1 bestporngate.com
                      127.0.0.1 www.bestsafetyguide.net
                      127.0.0.1 bestsafetyguide.net
                      127.0.0.1 www.bestsearch.cc
                      127.0.0.1 bestsearch.cc
                      127.0.0.1 www.bestsearchworld.info
                      127.0.0.1 bestsearchworld.info
                      127.0.0.1 www.best-spyware.info
                      127.0.0.1 best-spyware.info
                      127.0.0.1 www.best-targeted-traffic.com
                      127.0.0.1 best-targeted-traffic.com
                      127.0.0.1 www.best-voyeur.info
                      127.0.0.1 best-voyeur.info
                      127.0.0.1 bestweblinks.com
                      127.0.0.1 best-winning-casino.com
                      127.0.0.1 www.bestworldgirls-for-u.net
                      127.0.0.1 bestworldgirls-for-u.net
                      127.0.0.1 www.bestxclips.com
                      127.0.0.1 bestxclips.com
                      127.0.0.1 bestxporno.com
                      127.0.0.1 www.bestxxxmpegs.com
                      127.0.0.1 bestxxxmpegs.com
                      127.0.0.1 www.bettersearch.biz
                      127.0.0.1 bettersearch.biz
                      127.0.0.1 www.bewerbungsexperte.com
                      127.0.0.1 bewerbungsexperte.com
                      127.0.0.1 www.bgazzetta.it
                      127.0.0.1 bgazzetta.it
                      127.0.0.1 www.bgoogle.it
                      127.0.0.1 bgoogle.it
                      127.0.0.1 www.bigcodecadult.com
                      127.0.0.1 bigcodecadult.com
                      127.0.0.1 www.bigcodecadult2008.com
                      127.0.0.1 bigcodecadult2008.com
                      127.0.0.1 www.bigcodecadult2008-17.com
                      127.0.0.1 bigcodecadult2008-17.com
                      127.0.0.1 www.bighot18adult2008.com
                      127.0.0.1 bighot18adult2008.com
                      127.0.0.1 www.bighot18-adult2008.com
                      127.0.0.1 bighot18-adult2008.com
                      127.0.0.1 www.bighot18codec2008.com
                      127.0.0.1 bighot18codec2008.com
                      127.0.0.1 www.bighot18-codec2008.com
                      127.0.0.1 bighot18-codec2008.com
                      127.0.0.1 www.bigtrafficnetwork.com
                      127.0.0.1 bigtrafficnetwork.com
                      127.0.0.1 www.bigwww.com
                      127.0.0.1 bigwww.com
                      127.0.0.1 www.bill.de
                      127.0.0.1 bill.de
                      127.0.0.1 bins.media-motor.net
                      127.0.0.1 bins2.media-motor.net
                      127.0.0.1 bis.180solutions.com
                      127.0.0.1 bitchesonline.net
                      127.0.0.1 www.bitcomet-freebie.com
                      127.0.0.1 bitcomet-freebie.com
                      127.0.0.1 www.bittorrent.click-new-download.com
                      127.0.0.1 bittorrent.click-new-download.com
                      127.0.0.1 biz.biz
                      127.0.0.1 www.bkvcompany.com
                      127.0.0.1 bkvcompany.com
                      127.0.0.1 www.blackblues00.com
                      127.0.0.1 blackblues00.com
                      127.0.0.1 www.blackcodec.com
                      127.0.0.1 blackcodec.com
                      127.0.0.1 www.black-codec.com
                      127.0.0.1 black-codec.com
                      127.0.0.1 www.blackcodec.net
                      127.0.0.1 blackcodec.net
                      127.0.0.1 www.blackhats.tc
                      127.0.0.1 blackhats.tc
                      127.0.0.1 www.blackhawksoftware.com
                      127.0.0.1 blackhawksoftware.com
                      127.0.0.1 blackjack-free.net
                      127.0.0.1 www.blacklegion.info
                      127.0.0.1 blacklegion.info
                      127.0.0.1 blazefind.com
                      127.0.0.1 blender.xu.pl
                      127.0.0.1 www.blockcheckercontrol.com
                      127.0.0.1 blockcheckercontrol.com
                      127.0.0.1 blondetgp.com
                      127.0.0.1 www.blue-elefant.com
                      127.0.0.1 blue-elefant.com
                      127.0.0.1 www.bm.theaimonline.com
                      127.0.0.1 bm.theaimonline.com
                      127.0.0.1 www.bnmgate.com
                      127.0.0.1 bnmgate.com
                      127.0.0.1 bodaciousbabette.com
                      127.0.0.1 www.bonzi.com
                      127.0.0.1 bonzi.com
                      127.0.0.1 boobdoll.com
                      127.0.0.1 boobsandtits.com
                      127.0.0.1 boobsclub.com
                      127.0.0.1 www.bookedspace.com
                      127.0.0.1 bookedspace.com
                      127.0.0.1 www.boom.com.vn
                      127.0.0.1 boom.com.vn
                      127.0.0.1 www.boomgirltv.com
                      127.0.0.1 boomgirltv.com
                      127.0.0.1 boredlife.com
                      127.0.0.1 bowlofogumbo.com
                      127.0.0.1 www.bpfq02.com
                      127.0.0.1 bpfq02.com
                      127.0.0.1 www.bqgate.com
                      127.0.0.1 bqgate.com
                      127.0.0.1 bradcoem.org
                      127.0.0.1 www.braincodec.com
                      127.0.0.1 braincodec.com
                      127.0.0.1 www.brakecodec.com
                      127.0.0.1 brakecodec.com
                      127.0.0.1 www.brakecodec.net
                      127.0.0.1 brakecodec.net
                      127.0.0.1 brandiyoung.com
                      127.0.0.1 www.bravesentry.com
                      127.0.0.1 bravesentry.com
                      127.0.0.1 www.breenten.biz
                      127.0.0.1 breenten.biz
                      127.0.0.1 www.brodbfm.net
                      127.0.0.1 brodbfm.net
                      127.0.0.1 brookeburn.com
                      127.0.0.1 www.browserwise.com
                      127.0.0.1 browserwise.com
                      127.0.0.1 bsa.safetydownload.com
                      127.0.0.1 www.bsplaycodec.com
                      127.0.0.1 bsplaycodec.com
                      127.0.0.1 bucps.com
                      127.0.0.1 buhartes.info
                      127.0.0.1 buldog-stats.com
                      127.0.0.1 www.bullseye-network.com
                      127.0.0.1 bullseye-network.com
                      127.0.0.1 burgerkingbigscreen.com
                      127.0.0.1 www.burningsite.com
                      127.0.0.1 burningsite.com
                      127.0.0.1 www.burnsrecyclinginc.com
                      127.0.0.1 burnsrecyclinginc.com
                      127.0.0.1 buscards.net
                      127.0.0.1 bustyrussell.com
                      127.0.0.1 www.busysearch.net
                      127.0.0.1 busysearch.net
                      127.0.0.1 buttejazz.org
                      127.0.0.1 www.buy-find.info
                      127.0.0.1 buy-find.info
                      127.0.0.1 buyselldomain.net
                      127.0.0.1 www.buytraff.biz
                      127.0.0.1 buytraff.biz
                      127.0.0.1 buz.ru
                      127.0.0.1 www.bvdtechinque.com
                      127.0.0.1 bvdtechinque.com
                      127.0.0.1 www.bvirgilio.it
                      127.0.0.1 bvirgilio.it
                      127.0.0.1 www.bye-spyware.com
                      127.0.0.1 bye-spyware.com
                      127.0.0.1 c.centralmedia.ws
                      127.0.0.1 www.c.enhance.com
                      127.0.0.1 c.enhance.com
                      127.0.0.1 c.goclick.com
                      127.0.0.1 www.c4tdownload.com
                      127.0.0.1 c4tdownload.com
                      127.0.0.1 www.c5.www4free.info
                      127.0.0.1 c5.www4free.info
                      127.0.0.1 www.cache.surfaccuracy.com
                      127.0.0.1 cache.surfaccuracy.com
                      127.0.0.1 cache.ysbweb.com
                      127.0.0.1 www.cadesfinjeriokas.com
                      127.0.0.1 cadesfinjeriokas.com
                      127.0.0.1 calcioturris.com
                      127.0.0.1 www.calendaralerts.net
                      127.0.0.1 calendaralerts.net
                      127.0.0.1 www.callinghome.biz
                      127.0.0.1 callinghome.biz
                      127.0.0.1 www.cameouk.co.uk
                      127.0.0.1 cameouk.co.uk
                      127.0.0.1 cameup.com
                      127.0.0.1 www.camouflageclothingonline.net
                      127.0.0.1 camouflageclothingonline.net
                      127.0.0.1 campaigns.outerinfo.net
                      127.0.0.1 www.camping-community.com
                      127.0.0.1 camping-community.com
                      127.0.0.1 camup.net
                      127.0.0.1 canberracricketcoaching.com
                      127.0.0.1 candycantaloupes.com
                      127.0.0.1 www.canidetect.org
                      127.0.0.1 canidetect.org
                      127.0.0.1 www.cantfind.com
                      127.0.0.1 cantfind.com
                      127.0.0.1 careers.dulcineasystems.net
                      127.0.0.1 carsands.com
                      127.0.0.1 carsrentals.net
                      127.0.0.1 cartoes.uol.com.br
                      127.0.0.1 www.casalemedia.com
                      127.0.0.1 casalemedia.com
                      127.0.0.1 www.cashdeluxe.net
                      127.0.0.1 cashdeluxe.net
                      127.0.0.1 www.cashengines.com
                      127.0.0.1 cashengines.com
                      127.0.0.1 cashsearch.biz
                      127.0.0.1 www.cashsurfers.com
                      127.0.0.1 cashsurfers.com
                      127.0.0.1 www.cashunlim.com
                      127.0.0.1 cashunlim.com
                      127.0.0.1 casino.com.free.game.pogo.gratisdownloads.nl
                      127.0.0.1 casino2win.net
                      127.0.0.1 casino-gambling-1.net
                      127.0.0.1 casino-gambling-2.net
                      127.0.0.1 casinomidas.net
                      127.0.0.1 casinonline.net
                      127.0.0.1 casino-onlines.net
                      127.0.0.1 www.castingsamateur.com
                      127.0.0.1 castingsamateur.com
                      127.0.0.1 catallogue.com
                      127.0.0.1 www.catch-dc.info
                      127.0.0.1 catch-dc.info
                      127.0.0.1 categories.mygeek.com
                      127.0.0.1 catsss.da.ru
                      127.0.0.1 caxa.ru
                      127.0.0.1 cazygirls-world.com
                      127.0.0.1 cc.panet.org
                      127.0.0.1 www.ccecaedbebfcaf.com
                      127.0.0.1 ccecaedbebfcaf.com
                      127.0.0.1 cclebali.org
                      127.0.0.1 www.ccorriere.it
                      127.0.0.1 ccorriere.it
                      127.0.0.1 www.cdcopysite.com
                      127.0.0.1 cdcopysite.com
                      127.0.0.1 www.cdegate.com
                      127.0.0.1 cdegate.com
                      127.0.0.1 cdn.movies-etc.com
                      127.0.0.1 cdn2.movies-etc.com
                      127.0.0.1 www.cdorriere.it
                      127.0.0.1 cdorriere.it
                      127.0.0.1 ceewawires.org
                      127.0.0.1 centralmedia.ws
                      127.0.0.1 certumgroup.com
                      127.0.0.1 www.cforriere.it
                      127.0.0.1 cforriere.it
                      127.0.0.1 www.check.jupitersatellites.biz
                      127.0.0.1 check.jupitersatellites.biz
                      127.0.0.1 www.checkin100.com
                      127.0.0.1 checkin100.com
                      127.0.0.1 www.checkssecurity.com
                      127.0.0.1 checkssecurity.com
                      127.0.0.1 chelancatering.com
                      127.0.0.1 www.chenshijituan.com
                      127.0.0.1 chenshijituan.com
                      127.0.0.1 childrenvilla.com
                      127.0.0.1 www.chilly3xvids.com
                      127.0.0.1 chilly3xvids.com
                      127.0.0.1 www.chillymovs.com
                      127.0.0.1 chillymovs.com
                      127.0.0.1 chips-4-free.com
                      127.0.0.1 chrisswasey.com
                      127.0.0.1 chriswallace.net
                      127.0.0.1 www.cia-trjn.myvnc.com
                      127.0.0.1 cia-trjn.myvnc.com
                      127.0.0.1 www.cinemadownload.com
                      127.0.0.1 cinemadownload.com
                      127.0.0.1 www.ciorriere.it
                      127.0.0.1 ciorriere.it
                      127.0.0.1 www.cirriere.it
                      127.0.0.1 cirriere.it
                      127.0.0.1 www.citycodec.com
                      127.0.0.1 citycodec.com
                      127.0.0.1 ckick4thumbs.com
                      127.0.0.1 cl55.biz
                      127.0.0.1 clackamasliteraryreview.com
                      127.0.0.1 www.clckm.com
                      127.0.0.1 clckm.com
                      127.0.0.1 www.cleancodec.com
                      127.0.0.1 cleancodec.com
                      127.0.0.1 www.cleancodec.net
                      127.0.0.1 cleancodec.net
                      127.0.0.1 www.cleansoftwares.com
                      127.0.0.1 cleansoftwares.com
                      127.0.0.1 clearsearch.cc
                      127.0.0.1 clearsearch.net
                      127.0.0.1 clickaire.com
                      127.0.0.1 www.click-codec.com
                      127.0.0.1 click-codec.com
                      127.0.0.1 www.clickhere4search.com
                      127.0.0.1 clickhere4search.com
                      127.0.0.1 www.click-new-download.com
                      127.0.0.1 click-new-download.com
                      127.0.0.1 click-now.net
                      127.0.0.1 www.clickspring.net
                      127.0.0.1 clickspring.net
                      127.0.0.1 www.click-to-download.com
                      127.0.0.1 click-to-download.com
                      127.0.0.1 www.clicktomakeasearch.com
                      127.0.0.1 clicktomakeasearch.com
                      127.0.0.1 clickyestoenter.net
                      127.0.0.1 client.exeupdate.com
                      127.0.0.1 client.myadultexplorer.com
                      127.0.0.1 www.cliks.org
                      127.0.0.1 cliks.org
                      127.0.0.1 www.cliparts4free.com
                      127.0.0.1 cliparts4free.com
                      127.0.0.1 www.clipsfestival.com
                      127.0.0.1 clipsfestival.com
                      127.0.0.1 www.clipsreality.com
                      127.0.0.1 clipsreality.com
                      127.0.0.1 www.clorriere.it
                      127.0.0.1 clorriere.it
                      127.0.0.1 clrsch.com
                      127.0.0.1 www.clubxxxvideo.com
                      127.0.0.1 clubxxxvideo.com
                      127.0.0.1 clusif.free.fr
                      127.0.0.1 cmtapestry.com
                      127.0.0.1 www.cnetadd.com
                      127.0.0.1 cnetadd.com
                      127.0.0.1 www.cnomy.com
                      127.0.0.1 cnomy.com
                      127.0.0.1 www.cnzz.com
                      127.0.0.1 cnzz.com
                      127.0.0.1 www.cocktails-ideen.de
                      127.0.0.1 cocktails-ideen.de
                      127.0.0.1 code.ignphrases.com
                      127.0.0.1 codec.ninoa.com
                      127.0.0.1 www.codecadult18.com
                      127.0.0.1 codecadult18.com
                      127.0.0.1 www.codecbest.com
                      127.0.0.1 codecbest.com
                      127.0.0.1 www.codecbsplay.com
                      127.0.0.1 codecbsplay.com
                      127.0.0.1 www.codecdemo.com
                      127.0.0.1 codecdemo.com
                      127.0.0.1 www.codecdvd.net
                      127.0.0.1 codecdvd.net
                      127.0.0.1 www.codecdvi.com
                      127.0.0.1 codecdvi.com
                      127.0.0.1 www.codec-fun.com
                      127.0.0.1 codec-fun.com
                      127.0.0.1 www.codechard.com
                      127.0.0.1 codechard.com
                      127.0.0.1 www.codechot.net
                      127.0.0.1 codechot.net
                      127.0.0.1 www.codechq.net
                      127.0.0.1 codechq.net
                      127.0.0.1 www.codecmeg.net
                      127.0.0.1 codecmeg.net
                      127.0.0.1 www.codecmega.com
                      127.0.0.1 codecmega.com
                      127.0.0.1 www.codecmega.net
                      127.0.0.1 codecmega.net
                      127.0.0.1 www.codecmoon.com
                      127.0.0.1 codecmoon.com
                      127.0.0.1 www.codecmpg.com
                      127.0.0.1 codecmpg.com
                      127.0.0.1 www.codecnice.net
                      127.0.0.1 codecnice.net
                      127.0.0.1 www.codecnitro.com
                      127.0.0.1 codecnitro.com
                      127.0.0.1 www.codecops.net
                      127.0.0.1 codecops.net
                      127.0.0.1 www.codecplay.com
                      127.0.0.1 codecplay.com
                      127.0.0.1 www.codecpretty.net
                      127.0.0.1 codecpretty.net
                      127.0.0.1 www.codecpro.net
                      127.0.0.1 codecpro.net
                      127.0.0.1 www.codecred.net
                      127.0.0.1 codecred.net
                      127.0.0.1 www.codecsoft.net
                      127.0.0.1 codecsoft.net
                      127.0.0.1 www.codecthe.com
                      127.0.0.1 codecthe.com
                      127.0.0.1 www.codectime.com
                      127.0.0.1 codectime.com
                      127.0.0.1 www.codecultra.net
                      127.0.0.1 codecultra.net
                      127.0.0.1 www.codecvids.com
                      127.0.0.1 codecvids.com
                      127.0.0.1 www.codecvip.com
                      127.0.0.1 codecvip.com
                      127.0.0.1 www.codecviva.com
                      127.0.0.1 codecviva.com
                      127.0.0.1 www.codeczang.net
                      127.0.0.1 codeczang.net
                      127.0.0.1 www.codrriere.it
                      127.0.0.1 codrriere.it
                      127.0.0.1 www.coeriere.it
                      127.0.0.1 coeriere.it
                      127.0.0.1 www.coerriere.it
                      127.0.0.1 coerriere.it
                      127.0.0.1 www.cofrriere.it
                      127.0.0.1 cofrriere.it
                      127.0.0.1 www.cogrriere.it
                      127.0.0.1 cogrriere.it
                      127.0.0.1 www.coirriere.it
                      127.0.0.1 coirriere.it
                      127.0.0.1 command.adservs.com
                      127.0.0.1 www.commonname.com
                      127.0.0.1 commonname.com
                      127.0.0.1 www.computerpcgames.net
                      127.0.0.1 computerpcgames.net
                      127.0.0.1 www.computerrecover.com
                      127.0.0.1 computerrecover.com
                      127.0.0.1 config.180solutions.com
                      127.0.0.1 www.congtouzailai.net
                      127.0.0.1 congtouzailai.net
                      127.0.0.1 www.content.dollarrevenue.com
                      127.0.0.1 content.dollarrevenue.com
                      127.0.0.1 www.content.ireit.com
                      127.0.0.1 content.ireit.com
                      127.0.0.1 content.onerateld.com
                      127.0.0.1 www.contentmatch.net
                      127.0.0.1 contentmatch.net
                      127.0.0.1 www.contextplus.net
                      127.0.0.1 contextplus.net
                      127.0.0.1 www.contra-virus.com
                      127.0.0.1 contra-virus.com
                      127.0.0.1 www.controlmeh.com
                      127.0.0.1 controlmeh.com
                      127.0.0.1 www.convenient-search.com
                      127.0.0.1 convenient-search.com
                      127.0.0.1 www.cookingluck.com
                      127.0.0.1 cookingluck.com
                      127.0.0.1 www.cooldeskalert.com
                      127.0.0.1 cooldeskalert.com
                      127.0.0.1 coolfetishsite.com
                      127.0.0.1 coolfreehost.com
                      127.0.0.1 coolfreepage.com
                      127.0.0.1 coolfreepages.com
                      127.0.0.1 cool-homepage.co
                      127.0.0.1 cool-homepage.com
                      127.0.0.1 coolmoneysearch.com
                      127.0.0.1 www.coolonlinebusiness.com
                      127.0.0.1 coolonlinebusiness.com
                      127.0.0.1 coolpornsearch.com
                      127.0.0.1 cool-search.net
                      127.0.0.1 cool-search.netfartpost.com
                      127.0.0.1 coolsearcher.info
                      127.0.0.1 www.coolservecorp.net
                      127.0.0.1 coolservecorp.net
                      127.0.0.1 www.coolwebsearch.com
                      127.0.0.1 coolwebsearch.com
                      127.0.0.1 cool-web-search.com
                      127.0.0.1 coolwebsearsh.com
                      127.0.0.1 www.coolwwwsearch.com
                      127.0.0.1 coolwwwsearch.com
                      127.0.0.1 cool-xxx.net
                      127.0.0.1 www.coorriere.it
                      127.0.0.1 coorriere.it
                      127.0.0.1 copmtraine.com
                      127.0.0.1 www.coprriere.it
                      127.0.0.1 coprriere.it
                      127.0.0.1 www.core.psyche-evolution.com
                      127.0.0.1 core.psyche-evolution.com
                      127.0.0.1 www.coreiere.it
                      127.0.0.1 coreiere.it
                      127.0.0.1 www.coreriere.it
                      127.0.0.1 coreriere.it
                      127.0.0.1 www.corrdiere.it
                      127.0.0.1 corrdiere.it
                      127.0.0.1 www.correiere.it
                      127.0.0.1 correiere.it
                      127.0.0.1 www.corrfiere.it
                      127.0.0.1 corrfiere.it
                      127.0.0.1 www.corrgiere.it
                      127.0.0.1 corrgiere.it
                      127.0.0.1 www.corridere.it
                      127.0.0.1 corridere.it
                      127.0.0.1 www.corriedre.it
                      127.0.0.1 corriedre.it
                      127.0.0.1 www.corriee.it
                      127.0.0.1 corriee.it
                      127.0.0.1 www.corrieere.it
                      127.0.0.1 corrieere.it
                      127.0.0.1 www.corriefre.it
                      127.0.0.1 corriefre.it
                      127.0.0.1 www.corriegre.it
                      127.0.0.1 corriegre.it
                      127.0.0.1 www.corrierde.it
                      127.0.0.1 corrierde.it
                      127.0.0.1 www.corriered.it
                      127.0.0.1 corriered.it
                      127.0.0.1 www.corrieree.it
                      127.0.0.1 corrieree.it
                      127.0.0.1 www.corrieref.it
                      127.0.0.1 corrieref.it
                      127.0.0.1 www.corrierer.it
                      127.0.0.1 corrierer.it
                      127.0.0.1 www.corrieres.it
                      127.0.0.1 corrieres.it
                      127.0.0.1 www.corrierew.it
                      127.0.0.1 corrierew.it
                      127.0.0.1 www.corrierfe.it
                      127.0.0.1 corrierfe.it
                      127.0.0.1 www.corrierge.it
                      127.0.0.1 corrierge.it
                      127.0.0.1 www.corrierr.it
                      127.0.0.1 corrierr.it
                      127.0.0.1 www.corrierre.it
                      127.0.0.1 corrierre.it
                      127.0.0.1 www.corrierse.it
                      127.0.0.1 corrierse.it
                      127.0.0.1 www.corrierte.it
                      127.0.0.1 corrierte.it
                      127.0.0.1 www.corrierw.it
                      127.0.0.1 corrierw.it
                      127.0.0.1 www.corrierwe.it
                      127.0.0.1 corrierwe.it
                      127.0.0.1 www.corriesre.it
                      127.0.0.1 corriesre.it
                      127.0.0.1 www.corriete.it
                      127.0.0.1 corriete.it
                      127.0.0.1 www.corrietre.it
                      127.0.0.1 corrietre.it
                      127.0.0.1 www.corriewre.it
                      127.0.0.1 corriewre.it
                      127.0.0.1 www.corrifere.it
                      127.0.0.1 corrifere.it
                      127.0.0.1 www.corriiere.it
                      127.0.0.1 corriiere.it
                      127.0.0.1 www.corrilere.it
                      127.0.0.1 corrilere.it
                      127.0.0.1 www.corrioere.it
                      127.0.0.1 corrioere.it
                      127.0.0.1 www.corrire.it
                      127.0.0.1 corrire.it
                      127.0.0.1 www.corrirere.it
                      127.0.0.1 corrirere.it
                      127.0.0.1 www.corrirre.it
                      127.0.0.1 corrirre.it
                      127.0.0.1 www.corrisere.it
                      127.0.0.1 corrisere.it
                      127.0.0.1 www.corriuere.it
                      127.0.0.1 corriuere.it
                      127.0.0.1 www.corriwere.it
                      127.0.0.1 corriwere.it
                      127.0.0.1 www.corriwre.it
                      127.0.0.1 corriwre.it
                      127.0.0.1 www.corrliere.it
                      127.0.0.1 corrliere.it
                      127.0.0.1 www.corroere.it
                      127.0.0.1 corroere.it
                      127.0.0.1 www.corroiere.it
                      127.0.0.1 corroiere.it
                      127.0.0.1 www.corrriere.it
                      127.0.0.1 corrriere.it
                      127.0.0.1 www.corrtiere.it
                      127.0.0.1 corrtiere.it
                      127.0.0.1 www.corruere.it
                      127.0.0.1 corruere.it
                      127.0.0.1 www.corruiere.it
                      127.0.0.1 corruiere.it
                      127.0.0.1 www.cortiere.it
                      127.0.0.1 cortiere.it
                      127.0.0.1 www.cortriere.it
                      127.0.0.1 cortriere.it
                      127.0.0.1 www.costrike.com
                      127.0.0.1 costrike.com
                      127.0.0.1 www.cotriere.it
                      127.0.0.1 cotriere.it
                      127.0.0.1 www.cotrriere.it
                      127.0.0.1 cotrriere.it
                      127.0.0.1 couldnotfind.com
                      127.0.0.1 count.cc
                      127.0.0.1 count.hitscount.net
                      127.0.0.1 count-all.com
                      127.0.0.1 www.countdutycall.info
                      127.0.0.1 countdutycall.info
                      127.0.0.1 counter.sexmaniack.com
                      127.0.0.1 www.courtrecordslookup.com
                      127.0.0.1 courtrecordslookup.com
                      127.0.0.1 www.cporriere.it
                      127.0.0.1 cporriere.it
                      127.0.0.1 www.cprriere.it
                      127.0.0.1 cprriere.it
                      127.0.0.1 cpvfeed.com
                      127.0.0.1 cracks.me.uk
                      127.0.0.1 www.cracks4all.com
                      127.0.0.1 cracks4all.com
                      127.0.0.1 www.crapsgold.info
                      127.0.0.1 crapsgold.info
                      127.0.0.1 www.crazygirls-world.com
                      127.0.0.1 crazygirls-world.com
                      127.0.0.1 www.crazywinnings.com
                      127.0.0.1 crazywinnings.com
                      127.0.0.1 creamedcutties.com
                      127.0.0.1 www.createaccesskey.com
                      127.0.0.1 createaccesskey.com
                      127.0.0.1 www.creatonsoft.com
                      127.0.0.1 creatonsoft.com
                      127.0.0.1 creditsearchonline.com
                      127.0.0.1 crestring.com
                      127.0.0.1 crooder.com
                      127.0.0.1 www.crriere.it
                      127.0.0.1 crriere.it
                      127.0.0.1 www.cryptdrive.com
                      127.0.0.1 cryptdrive.com
                      127.0.0.1 www.crystalysmedia.com
                      127.0.0.1 crystalysmedia.com
                      127.0.0.1 www.csx.adservs.com
                      127.0.0.1 csx.adservs.com
                      127.0.0.1 cts.180solutions.com
                      127.0.0.1 www.cuisinartoven.com
                      127.0.0.1 cuisinartoven.com
                      127.0.0.1 www.curedc.info
                      127.0.0.1 curedc.info
                      127.0.0.1 www.curepcsolutions.com
                      127.0.0.1 curepcsolutions.com
                      127.0.0.1 curvedspaces.com
                      127.0.0.1 www.cutadult.com
                      127.0.0.1 cutadult.com
                      127.0.0.1 www.cutoffspyware.com
                      127.0.0.1 cutoffspyware.com
                      127.0.0.1 www.cvirgilio.it
                      127.0.0.1 cvirgilio.it
                      127.0.0.1 www.cvorriere.it
                      127.0.0.1 cvorriere.it
                      127.0.0.1 cvs.jps.ru
                      127.0.0.1 cvsymphony.com
                      127.0.0.1 www.cxorriere.it
                      127.0.0.1 cxorriere.it
                      127.0.0.1 www.cyberrape.com
                      127.0.0.1 cyberrape.com
                      127.0.0.1 cydom.com
                      127.0.0.1 www.cydoor.com
                      127.0.0.1 cydoor.com
                      127.0.0.1 d34s.qfdfqawd.cn
                      127.0.0.1 www.daily3xlinks.com
                      127.0.0.1 daily3xlinks.com
                      127.0.0.1 www.dailybestclips.com
                      127.0.0.1 dailybestclips.com
                      127.0.0.1 daily-gals.com
                      127.0.0.1 www.dailyhugemovs.com
                      127.0.0.1 dailyhugemovs.com
                      0
                      1. Contributeur sécurité
                        en fait,
                        il manque la fin du rapport
                        peux tu me mettre juste la fin
                        derrière la liste des 127.0.0.1

                        ensuite

                        Télécharge SDfix (créé par AndyManchesta) et sauvegarde le sur ton Bureau. Tu peux suivre le tutorial SDFix de Malekal pour t'aider :

                        Double clique sur SDFix.exe et choisis Install pour l'extraire dans un dossier dédié sur le Bureau. Redémarre ton ordinateur en mode sans échec en suivant la procédure que voici :
                        [*]Redémarre ton ordinateur
                        [*]Après avoir entendu l'ordinateur biper lors du démarrage, mais avant que l'icône Windows apparaisse, tapote la touche F8 (une pression par seconde).
                        [*]A la place du chargement normal de Windows, un menu avec différentes options devrait apparaître.
                        [*]Choisis la première option, pour exécuter Windows en mode sans échec, puis appuie sur "Entrée".
                        [*]Choisis ton compte.
                        Déroule la liste des instructions ci-dessous :
                        [*]Ouvre le dossier SDFix qui vient d'être créé dans le répertoire C:\ et double clique sur RunThis.bat pour lancer le script.
                        [*]Appuie sur Y pour commencer le processus de nettoyage.
                        [*]Il va supprimer les services et les entrées du Registre de certains trojans trouvés puis te demandera d'appuyer sur une touche pour redémarrer.
                        [*]Appuie sur une touche pour redémarrer le PC.
                        [*]Ton système sera plus long pour redémarrer qu'à l'accoutumée car l'outil va continuer à s'exécuter et supprimer des fichiers.
                        [*]Après le chargement du Bureau, l'outil terminera son travail et affichera Finished.
                        [*]Appuie sur une touche pour finir l'exécution du script et charger les icônes de ton Bureau.
                        [*]Les icônes du Bureau affichées, le rapport SDFix s'ouvrira à l'écran et s'enregistrera aussi dans le dossier SDFix sous le nom Report.txt.
                        [*]Enfin, copie/colle le contenu du fichier Report.txt dans ta prochaine réponse sur le forum, avec un nouveau log Hijackthis !
                        0
                        1. Voici la fin du rapport

                          VACFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                          S!Ri's WS2Fix: LSP not Found.

                          »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                          GenericRenosFix by S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                          C:\Program Files\akl\ Deleted
                          C:\Program Files\sav\ Deleted

                          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                          IEDFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

                          404Fix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

                          AntiXPVSTFix
                          Credits: Malware Analysis & Diagnostic
                          Code: S!Ri

                          »»»»»»»»»»»»»»»»»»»»»»»» RK

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{A4250EEC-289B-4CC3-A9E0-B0E98B1EE95C}: DhcpNameServer=192.168.2.1 192.168.2.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{A4250EEC-289B-4CC3-A9E0-B0E98B1EE95C}: DhcpNameServer=192.168.2.1 192.168.2.1
                          HKLM\SYSTEM\CS2\Services\Tcpip\..\{A4250EEC-289B-4CC3-A9E0-B0E98B1EE95C}: DhcpNameServer=192.168.2.1 192.168.2.1
                          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1 192.168.2.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1 192.168.2.1
                          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1 192.168.2.1

                          »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                          !!!Attention, following keys are not inevitably infected!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                          "System"=""

                          »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                          Registry Cleaning done.

                          »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                          !!!Attention, following keys are not inevitably infected!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» End
                          0
                          1. Voici le rapport SDFix

                            [b]SDFix: Version 1.223 [/b]
                            Run by HP_Administrator on 2008-09-09 at 15:01

                            Microsoft Windows XP [Version 5.1.2600]
                            Running From: C:\SDFix

                            [b]Checking Services [/b]:

                            Restoring Default Security Values
                            Restoring Default Hosts File

                            Rebooting

                            [b]Checking Files [/b]:

                            Trojan Files Found:

                            C:\WINDOWS\mslagent\2_mslagent.dll - Deleted
                            C:\WINDOWS\mslagent\mslagent.exe - Deleted
                            C:\WINDOWS\mslagent\uninstall.exe - Deleted
                            C:\Program Files\Inet Delivery\inetdl.exe - Deleted
                            C:\Program Files\Inet Delivery\intdel.exe - Deleted
                            C:\WINDOWS\a.bat - Deleted
                            C:\WINDOWS\zip1.tmp - Deleted
                            C:\WINDOWS\zip2.tmp - Deleted
                            C:\WINDOWS\zip3.tmp - Deleted
                            C:\WINDOWS\zipped.tmp - Deleted
                            C:\WINDOWS\a.bat - Deleted
                            C:\WINDOWS\base64.tmp - Deleted
                            C:\WINDOWS\bdn.com - Deleted
                            C:\WINDOWS\FVProtect.exe - Deleted
                            C:\WINDOWS\iTunesMusic.exe - Deleted
                            C:\WINDOWS\mssecu.exe - Deleted
                            C:\WINDOWS\system32\akttzn.exe - Deleted
                            C:\WINDOWS\system32\anticipator.dll - Deleted
                            C:\WINDOWS\system32\awtoolb.dll - Deleted
                            C:\WINDOWS\system32\bdn.com - Deleted
                            C:\WINDOWS\system32\bsva-egihsg52.exe - Deleted
                            C:\WINDOWS\system32\dpcproxy.exe - Deleted
                            C:\WINDOWS\system32\emesx.dll - Deleted
                            C:\WINDOWS\system32\h@tkeysh@@k.dll - Deleted
                            C:\WINDOWS\system32\hoproxy.dll - Deleted
                            C:\WINDOWS\system32\hxiwlgpm.dat - Deleted
                            C:\WINDOWS\system32\hxiwlgpm.exe - Deleted
                            C:\WINDOWS\system32\medup012.dll - Deleted
                            C:\WINDOWS\system32\medup020.dll - Deleted
                            C:\WINDOWS\system32\msgp.exe - Deleted
                            C:\WINDOWS\system32\msnbho.dll - Deleted
                            C:\WINDOWS\system32\mssecu.exe - Deleted
                            C:\WINDOWS\system32\msvchost.exe - Deleted
                            C:\WINDOWS\system32\mtr2.exe - Deleted
                            C:\WINDOWS\system32\mwin32.exe - Deleted
                            C:\WINDOWS\system32\netode.exe - Deleted
                            C:\WINDOWS\system32\newsd32.exe - Deleted
                            C:\WINDOWS\system32\ps1.exe - Deleted
                            C:\WINDOWS\system32\psof1.exe - Deleted
                            C:\WINDOWS\system32\psoft1.exe - Deleted
                            C:\WINDOWS\system32\regc64.dll - Deleted
                            C:\WINDOWS\system32\regm64.dll - Deleted
                            C:\WINDOWS\system32\Rundl1.exe - Deleted
                            C:\WINDOWS\system32\smp\msrc.exe - Deleted
                            C:\WINDOWS\system32\sncntr.exe - Deleted
                            C:\WINDOWS\system32\ssurf022.dll - Deleted
                            C:\WINDOWS\system32\ssvchost.com - Deleted
                            C:\WINDOWS\system32\ssvchost.exe - Deleted
                            C:\WINDOWS\system32\sysreq.exe - Deleted
                            C:\WINDOWS\system32\taack.dat - Deleted
                            C:\WINDOWS\system32\taack.exe - Deleted
                            C:\WINDOWS\system32\temp#01.exe - Deleted
                            C:\WINDOWS\system32\thun.dll - Deleted
                            C:\WINDOWS\system32\thun32.dll - Deleted
                            C:\WINDOWS\system32\VBIEWER.OCX - Deleted
                            C:\WINDOWS\system32\vbsys2.dll - Deleted
                            C:\WINDOWS\system32\vcatchpi.dll - Deleted
                            C:\WINDOWS\system32\winlogonpc.exe - Deleted
                            C:\WINDOWS\system32\winsystem.exe - Deleted
                            C:\WINDOWS\system32\WINWGPX.EXE - Deleted
                            C:\WINDOWS\userconfig9x.dll - Deleted
                            C:\WINDOWS\winsystem.exe - Deleted

                            Folder C:\Program Files\Inet Delivery - Removed
                            Folder C:\WINDOWS\mslagent - Removed
                            Folder C:\WINDOWS\system32\smp - Removed

                            Removing Temp Files

                            [b]ADS Check [/b]:

                            [b]Final Check [/b]:

                            catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                            Rootkit scan 2008-09-09 15:10:27
                            Windows 5.1.2600 Service Pack 2 NTFS

                            scanning hidden processes ...

                            scanning hidden services & system hive ...

                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\E100B]
                            "EventMessageFile"=str(2):"%SystemRoot%\System32\netevent.dll;%SystemRoot%\system32\drivers\e100b325.sys"
                            "TypesSupported"=dword:00000007
                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\NtServicePack]
                            "EventMessageFile"=str(2):"%SystemRoot%\System32\spmsg.dll"
                            "TypesSupported"=dword:00000007
                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\nv]
                            "EventMessageFile"=str(2):"%SystemRoot%\System32\IoLogMsg.dll;%SystemRoot%\System32\drivers\nv4_mini.sys"
                            "TypesSupported"=dword:00000007
                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\PS2]
                            "EventMessageFile"=str(2):"%SystemRoot%\System32\IoLogMsg.dll;%SystemRoot%\System32\drivers\PS2.sys"
                            "TypesSupported"=dword:00000007
                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\Windows Installer 3.1]
                            "EventMessageFile"=str(2):"%SystemRoot%\System32\spmsg.dll"
                            "TypesSupported"=dword:00000007
                            [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Eventlog\System\WindowsMedia]
                            "EventMessageFile"=str(2):"%SystemRoot%\System32\spmsg.dll"
                            "TypesSupported"=dword:00000007
                            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\E100B]
                            "EventMessageFile"=str(2):"%SystemRoot%\System32\netevent.dll;%SystemRoot%\system32\drivers\e100b325.sys"
                            "TypesSupported"=dword:00000007
                            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\NtServicePack]
                            "EventMessageFile"=str(2):"%SystemRoot%\System32\spmsg.dll"
                            "TypesSupported"=dword:00000007
                            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\nv]
                            "EventMessageFile"=str(2):"%SystemRoot%\System32\IoLogMsg.dll;%SystemRoot%\System32\drivers\nv4_mini.sys"
                            "TypesSupported"=dword:00000007
                            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\PS2]
                            "EventMessageFile"=str(2):"%SystemRoot%\System32\IoLogMsg.dll;%SystemRoot%\System32\drivers\PS2.sys"
                            "TypesSupported"=dword:00000007
                            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\Windows Installer 3.1]
                            "EventMessageFile"=str(2):"%SystemRoot%\System32\spmsg.dll"
                            "TypesSupported"=dword:00000007
                            [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Eventlog\System\WindowsMedia]
                            "EventMessageFile"=str(2):"%SystemRoot%\System32\spmsg.dll"
                            "TypesSupported"=dword:00000007

                            scanning hidden registry entries ...

                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\AppLogLevels]
                            "MasterInstaller"=dword:00000000
                            "IEngine"=dword:00000000
                            "SetupEngine"=dword:00000000
                            "SetupMSI"=dword:00000000
                            "cmLock"=dword:00000000
                            "cmlib"=dword:00000000
                            "Tester"=dword:00000000
                            "REGISTRATION"=dword:00000000
                            "REGISTER_DLL"=dword:00000000
                            "SetupError"=dword:00000000
                            "ccsstop"=dword:00000000
                            "vistaact"=dword:00000000
                            "wirelessguid"=dword:00000000
                            "ptswia"=dword:00000000
                            "OTTBPVER"=dword:00000000
                            "opt_act"=dword:00000000
                            "unin_act"=dword:00000000
                            "CheckReboot"=dword:00000000
                            "KodakShx"=dword:00000000
                            "inst_act"=dword:00000000
                            "KodakDCCameraManager"=dword:00000000
                            "ksustop"=dword:00000000
                            "esbwclntext"=dword:00000000
                            "checkpdockreboot"=dword:00000000
                            "pdockact"=dword:00000000
                            "cr_stop"=dword:00000000
                            "Atlas"=dword:00000000
                            "AlbumCat"=dword:00000000
                            "AtlasManager"=dword:00000000
                            "bragbook"=dword:00000000
                            "DevicePrefsCat"=dword:00000000
                            "IAtlasAlbum"=dword:00000000
                            "ccsreg"=dword:00000000
                            "EasyShareExe"=dword:00000000
                            "pjObj"=dword:00000000
                            "AppCore"=dword:00000000
                            "CVistaImage"=dword:00000000
                            "VistaCollection"=dword:00000000
                            "CVistaDirector"=dword:00000000
                            "acqmod"=dword:00000000
                            "hydrahelper"=dword:00000000
                            "RemoveableMedia"=dword:00000000
                            "SyncEngine"=dword:00000000
                            "ICameraColectionAlbum"=dword:00000000
                            "DiscoverBBCollections"=dword:00000000
                            "CameraCollection"=dword:00000000
                            "IESAddPicturesWO"=dword:00000000
                            "IESTransferAX"=dword:00000000
                            "wireless"=dword:00000000
                            "PtpCore"=dword:00000000
                            "WIA"=dword:00000000
                            "dpofinfo"=dword:00000000
                            "PtpBragbook"=dword:00000000
                            "CamAddrBook"=dword:00000000
                            "PtpBaseAdapter"=dword:00000000
                            "bragbookhowfile"=dword:00000000
                            "HydraAdapter"=dword:00000000
                            "VpolHelper"=dword:00000000
                            "VPrintOnlineLocale"=dword:00000000
                            "PCD"=dword:00000000
                            "EstablishPCDMutex"=dword:00000000
                            "PCDFirstTimeMessage"=dword:00000000
                            "PCDIRetailer"=dword:00000000
                            "PCDRemoveShortcut"=dword:00000000
                            "PCDRunTransfer"=dword:00000000
                            "PCDSUPP"=dword:00000000
                            "CameraCollectionTreeAction"=dword:00000000
                            "KEmail"=dword:00000000
                            ""VistaEmail""=dword:00000000
                            "ofotoXMI"=dword:00000000
                            "VistaPrint"=dword:00000000
                            "VPOLView"=dword:00000000
                            "OFOTOSUPP"=dword:00000000
                            "PtpTransportIntf"=dword:00000000
                            "dccamCoinstall"=dword:00000000
                            "KSU_NOTIFIER"=dword:00000000
                            "NOTIFIER_KSU_DATA"=dword:00000000
                            "tcConfigFileData"=dword:00000000
                            "NOTIFIER_ARBITER"=dword:00000000
                            "NOTIFIER_UTILITY"=dword:00000000
                            "USBSCAN"=dword:00000000
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{077ACEC7-979C-40AB-9835-435BA1511E0D}]
                            "FriendlyName"="Windows Media Files"
                            "ComponentGUID"="{077ACEC7-979C-40AB-9835-435BA1511E0D}"
                            "Version"=dword:000a0000
                            "Sub-Version"=dword:000010ec
                            "ExceptionInfName"=str(2):"C:\WINDOWS\RegisteredPackages\{077ACEC7-979C-40AB-9835-435BA1511E0D}\MPPRE10.inf"
                            "ExceptionCatalogName"=str(2):"C:\WINDOWS\RegisteredPackages\{077ACEC7-979C-40AB-9835-435BA1511E0D}\mppre10.cat"
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{30C7234B-6482-4A55-A11D-ECD9030313F2}]
                            "FriendlyName"="Windows Media Files"
                            "ComponentGUID"="{30C7234B-6482-4A55-A11D-ECD9030313F2}"
                            "Version"=dword:000a0000
                            "Sub-Version"=dword:000010ec
                            "ExceptionInfName"=str(2):"C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\WMDM10.inf"
                            "ExceptionCatalogName"=str(2):"C:\WINDOWS\RegisteredPackages\{30C7234B-6482-4A55-A11D-ECD9030313F2}\wmdm10.cat"
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{981FB688-E76B-4246-987B-92083185B90A}]
                            "FriendlyName"="Windows Media Files"
                            "ComponentGUID"="{981FB688-E76B-4246-987B-92083185B90A}"
                            "Version"=dword:000a0000
                            "Sub-Version"=dword:000010ec
                            "ExceptionInfName"=str(2):"C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\WPD10.inf"
                            "ExceptionCatalogName"=str(2):"C:\WINDOWS\RegisteredPackages\{981FB688-E76B-4246-987B-92083185B90A}\wpd10.cat"
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{A47B3654-48EE-48A5-B629-97D70175E58F}]
                            "FriendlyName"="Windows Media Files"
                            "ComponentGUID"="{A47B3654-48EE-48A5-B629-97D70175E58F}"
                            "Version"=dword:000a0000
                            "Sub-Version"=dword:000010ec
                            "ExceptionInfName"=str(2):"C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\codecs10.inf"
                            "ExceptionCatalogName"=str(2):"C:\WINDOWS\RegisteredPackages\{A47B3654-48EE-48A5-B629-97D70175E58F}\codecs10.cat"
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}]
                            "FriendlyName"="Windows Media Files"
                            "ComponentGUID"="{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}"
                            "Version"=dword:000a0000
                            "Sub-Version"=dword:000010ec
                            "ExceptionInfName"=str(2):"C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\WMFSDK10.inf"
                            "ExceptionCatalogName"=str(2):"C:\WINDOWS\RegisteredPackages\{AAC1D942-0B38-4E37-9E4E-5B96A9DD2170}\wmfsdk10.cat"
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\ExceptionComponents\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}]
                            "FriendlyName"="Windows Media Files"
                            "ComponentGUID"="{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}"
                            "Version"=dword:000a0000
                            "Sub-Version"=dword:000010ec
                            "ExceptionInfName"=str(2):"C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\DRM10.inf"
                            "ExceptionCatalogName"=str(2):"C:\WINDOWS\RegisteredPackages\{C5B8FBE9-645E-4484-A7AA-E8DA9A70DD77}\drm10.cat"
                            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\OptionalComponents\SwFlash]
                            "Installed"="1"
                            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpga\OpenWithProgids]
                            "RealPlayer.MPGA.6"=hex(0):
                            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.obd\OpenWithProgids]
                            "Office.Binder.9"=hex(0):
                            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.obt\OpenWithProgids]
                            "Office.Binder.Template.9"=hex(0):
                            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rpl\OpenWithProgids]
                            "Rhapsody Playlist"=hex(0):
                            [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ssm\OpenWithProgids]
                            "SSM"=hex(0):

                            scanning hidden files ...

                            scan completed successfully
                            hidden processes: 0
                            hidden services: 0
                            hidden files: 0

                            [b]Remaining Services [/b]:

                            Authorized Application Key Export:

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
                            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe:*:Enabled:hpqtra08.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe:*:Enabled:hpqste08.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe:*:Enabled:hpofxm08.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe:*:Enabled:hposfx08.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe:*:Enabled:hposid01.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe:*:Enabled:hpqscnvw.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe:*:Enabled:hpqkygrp.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe:*:Enabled:hpqcopy.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe:*:Enabled:hpfccopy.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe:*:Enabled:hpzwiz01.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe:*:Enabled:hpqphunl.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"="C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe:*:Enabled:hpqdia.exe"
                            "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"="C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe:*:Enabled:hpoews01.exe"
                            "C:\\Program Files\\DISC\\DISCover.exe"="C:\\Program Files\\DISC\\DISCover.exe:*:Enabled:DISCover Drop & Play System"
                            "C:\\Program Files\\DISC\\DiscStreamHub.exe"="C:\\Program Files\\DISC\\DiscStreamHub.exe:*:Enabled:DISCover Stream Hub"
                            "C:\\Program Files\\DISC\\myFTP.exe"="C:\\Program Files\\DISC\\myFTP.exe:*:Enabled:DISCover FTP"
                            "C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
                            "C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"
                            "C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
                            "C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"="C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe:*:Disabled:Kodak Software Updater"
                            "C:\\mirc\\mirc32.exe"="C:\\mirc\\mirc32.exe:*:Enabled:Internet Relay Chat Client"
                            "C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:æTorrent"
                            "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
                            "C:\\Documents and Settings\\HP_Administrator\\Local Settings\\Temp\\Rar$EX04.750\\mcoview.exe"="C:\\Documents and Settings\\HP_Administrator\\Local Settings\\Temp\\Rar$EX04.750\\mcoview.exe:*:Enabled:mcoview"
                            "C:\\Documents and Settings\\HP_Administrator\\Local Settings\\Temp\\Rar$EX00.687\\mcoview.exe"="C:\\Documents and Settings\\HP_Administrator\\Local Settings\\Temp\\Rar$EX00.687\\mcoview.exe:*:Enabled:mcoview"
                            "C:\\Documents and Settings\\HP_Administrator\\Local Settings\\Temp\\Rar$EX37.547\\mcoview.exe"="C:\\Documents and Settings\\HP_Administrator\\Local Settings\\Temp\\Rar$EX37.547\\mcoview.exe:*:Enabled:mcoview"
                            "C:\\Documents and Settings\\HP_Administrator\\Local Settings\\Temp\\Rar$EX00.672\\mcoview.exe"="C:\\Documents and Settings\\HP_Administrator\\Local Settings\\Temp\\Rar$EX00.672\\mcoview.exe:*:Enabled:mcoview"
                            "C:\\Documents and Settings\\HP_Administrator\\Local Settings\\Temp\\Rar$EX79.344\\mcoview.exe"="C:\\Documents and Settings\\HP_Administrator\\Local Settings\\Temp\\Rar$EX79.344\\mcoview.exe:*:Enabled:mcoview"
                            "C:\\WINDOWS\\system32\\fxsclnt.exe"="C:\\WINDOWS\\system32\\fxsclnt.exe:*:Enabled:Microsoft Fax Console"
                            "C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUpnpService9.exe"="C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUpnpService9.exe:*:Enabled:RoxioUpnpService9"
                            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                            "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
                            "C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Disabled:LimeWire"

                            [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
                            "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
                            "C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"="C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe:*:Enabled:Updates from HP"
                            "C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUpnpService9.exe"="C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUpnpService9.exe:*:Enabled:RoxioUpnpService9"
                            "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
                            "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

                            [b]Remaining Files [/b]:

                            File Backups: - C:\SDFix\backups\backups.zip

                            [b]Files with Hidden Attributes [/b]:

                            Sun 26 Nov 2006 211 A.SHR --- "C:\BOOT.BAK"
                            Wed 30 Jul 2008 1,429,840 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
                            Wed 30 Jul 2008 4,891,984 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
                            Wed 30 Jul 2008 1,829,712 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
                            Tue 15 Nov 2005 78,104 ..SHR --- "C:\Program Files\Autodesk\Autodesk DWF Viewer\Setup.exe"
                            Tue 15 Nov 2005 12,912 A.SHR --- "C:\Program Files\Autodesk\Autodesk DWF Viewer\_Setupx.dll"
                            Thu 22 Feb 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"

                            [b]Finished![/b]
                            0
                            1. Voici le nouveau log Hijackthis
                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 15:21:42, on 2008-09-09
                              Platform: Windows XP SP2 (WinNT 5.01.2600)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                              Boot mode: Normal

                              Running processes:
                              C:\WINDOWS\System32\smss.exe
                              C:\WINDOWS\system32\winlogon.exe
                              C:\WINDOWS\system32\services.exe
                              C:\WINDOWS\system32\lsass.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                              C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              C:\WINDOWS\Explorer.EXE
                              C:\WINDOWS\system32\spoolsv.exe
                              C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              C:\Program Files\Bonjour\mDNSResponder.exe
                              C:\WINDOWS\eHome\ehRecvr.exe
                              C:\WINDOWS\eHome\ehSched.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                              C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                              C:\Program Files\NDAS\System\ndassvc.exe
                              C:\WINDOWS\system32\nvsvc32.exe
                              C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
                              C:\WINDOWS\system32\svchost.exe
                              C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
                              C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              C:\WINDOWS\system32\dllhost.exe
                              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                              C:\WINDOWS\system32\wuauclt.exe
                              C:\WINDOWS\ehome\ehtray.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
                              C:\WINDOWS\RTHDCPL.EXE
                              C:\WINDOWS\system32\rundll32.exe
                              C:\Program Files\DISC\DISCover.exe
                              C:\Program Files\DISC\DiscUpdateMgr.exe
                              C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
                              C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe
                              C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                              C:\WINDOWS\eHome\ehmsas.exe
                              C:\WINDOWS\system32\WDBtnMgr.exe
                              C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              C:\Program Files\DISC\DiscGui.exe
                              C:\Program Files\Winamp\Winampa.exe
                              C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                              C:\WINDOWS\System32\svchost.exe
                              C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                              C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                              C:\Program Files\QuickTime\qttask.exe
                              C:\WINDOWS\system32\ctfmon.exe
                              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                              C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
                              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                              C:\WINDOWS\system32\ynqpcxef.exe
                              C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              C:\Program Files\NDAS\System\ndasmgmt.exe
                              C:\PROGRA~1\MICROS~4\Office12\OUTLOOK.EXE
                              C:\Program Files\DISC\DiscStreamHub.exe
                              C:\Program Files\Internet Explorer\IEXPLORE.EXE
                              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                              C:\WINDOWS\system32\ps2.exe
                              c:\windows\system\hpsysdrv.exe
                              C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
                              C:\HiJackThis\HijackThis.exe

                              O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                              O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
                              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                              O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                              O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
                              O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                              O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                              O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
                              O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
                              O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
                              O4 - HKLM\..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
                              O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                              O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                              O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                              O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
                              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                              O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                              O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
                              O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05c\BrStDvPt.exe
                              O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
                              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                              O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                              O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                              O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                              O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
                              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                              O4 - HKCU\..\Run: [comsys] C:\WINDOWS\system32\ynqpcxef.exe
                              O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
                              O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                              O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                              O4 - Global Startup: NDAS Device Management.lnk = C:\Program Files\NDAS\System\ndasmgmt.exe
                              O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O15 - Trusted Zone: http://*.trymedia.com (HKLM)
                              O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
                              O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                              O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                              O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
                              O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://walmart.pnimedia.com/upload/activex/v2_0_0_9/PCAXSetupv2.0.0.9.cab?
                              O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://walmart.pnimedia.com/upload/activex/v2_0_0_10/PCAXSetupv2.0.0.10.cab?
                              O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                              O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                              O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
                              O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                              O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                              O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                              O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
                              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                              O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              O23 - Service: NDAS Service (ndassvc) - XIMETA, Inc. - C:\Program Files\NDAS\System\ndassvc.exe
                              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                              O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
                              O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
                              O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
                              O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                              O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                              0
                              1. Contributeur sécurité
                                ça avance bien,
                                t'as remarqué qu'il avait vachement bien travailler!!!!

                                reste l'un ou l'autre truc bizarre

                                Télécharge Combofix sUBs : http://download.bleepingcomputer.com/sUBs/ComboFix.exe
                                et sauvegarde le sur ton bureau et pas ailleurs!

                                **Désactive les logiciels de protection** (Antivirus, Antispywares) puis :
                                deconnecte toi d'internet,ferme tout les programmes

                                Double-clique sur combofix, Il va te poser une question, réponds par la touche 1 et entrée pour valider.
                                ne touche plus à rien, même pas ta souris!!
                                Attends que combofix ait terminé, un rapport sera créé. Poste le rapport.

                                Copie/colle un nouveau rapport HiJackThis avec.
                                0
                                1. Ça travail bien t'es p'tit prog. Moi j'en ai des chaleurs ouf !!!
                                  ComboFix 08-09-05.12 - HP_Administrator 2008-09-09 15:44:53.1 - NTFSx86
                                  Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1448 [GMT -4:00]
                                  Running from: C:\Documents and Settings\HP_Administrator\Desktop\ComboFix.exe
                                  * Created a new restore point
                                  .

                                  ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
                                  .

                                  C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Windows Media\10.0\WMSDKNSD.XML
                                  D:\Autorun.inf

                                  .
                                  ((((((((((((((((((((((((( Files Created from 2008-08-09 to 2008-09-09 )))))))))))))))))))))))))))))))
                                  .

                                  2008-09-09 14:57 . 2008-09-09 14:57 <DIR> d-------- C:\WINDOWS\ERUNT
                                  2008-09-09 14:53 . 2008-09-09 15:15 <DIR> d-------- C:\SDFix
                                  2008-09-09 12:11 . 2008-09-09 13:36 7,050 --a------ C:\WINDOWS\system32\tmp.reg
                                  2008-09-09 12:10 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
                                  2008-09-09 12:10 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
                                  2008-09-09 12:10 . 2008-09-08 23:38 88,576 --a------ C:\WINDOWS\system32\AntiXPVSTFix.exe
                                  2008-09-09 12:10 . 2008-09-02 16:51 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
                                  2008-09-09 12:10 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe
                                  2008-09-09 12:10 . 2008-08-28 22:36 82,432 --a------ C:\WINDOWS\system32\IEDFix.C.exe
                                  2008-09-09 12:10 . 2008-08-18 12:19 82,432 --a------ C:\WINDOWS\system32\404Fix.exe
                                  2008-09-09 12:10 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe
                                  2008-09-09 12:10 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
                                  2008-09-09 12:10 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
                                  2008-09-09 11:36 . 2008-09-09 15:21 <DIR> d-------- C:\HiJackThis
                                  2008-09-09 08:11 . 2008-09-09 14:50 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\lcxkxqvy
                                  2008-09-09 08:11 . 2008-09-09 08:11 90,112 --a------ C:\WINDOWS\system32\ynqpcxef.exe
                                  2008-09-02 13:19 . 2008-09-02 13:19 <DIR> d-------- C:\Program Files\FlexiSIGN-PRO 8.1v1
                                  2008-09-02 12:42 . 2008-09-02 12:42 <DIR> d-------- C:\Program Files\MagicISO
                                  2008-08-20 21:10 . 2008-08-20 21:28 <DIR> d-------- C:\WINDOWS\system32\CatRoot_bak
                                  2008-08-15 18:16 . 2008-08-15 18:16 <DIR> d-------- C:\WINDOWS\report
                                  2008-08-15 18:16 . 2008-08-15 18:14 25,732,881 --a------ C:\WINDOWS\LPT$VPN.479
                                  2008-08-15 18:14 . 2008-08-15 18:14 <DIR> d-------- C:\WINDOWS\AU_Backup
                                  2008-08-15 18:14 . 2008-08-15 18:14 25,732,881 --a------ C:\WINDOWS\VPTNFILE.479
                                  2008-08-15 18:14 . 2008-08-15 18:14 1,964,523 --a------ C:\WINDOWS\tsc.ptn
                                  2008-08-15 18:14 . 2008-08-15 18:14 1,213,784 --a------ C:\WINDOWS\vsapi32.dll
                                  2008-08-15 18:14 . 2008-08-15 18:14 333,576 --a------ C:\WINDOWS\TSC.exe
                                  2008-08-15 18:14 . 2008-08-15 18:14 91,744 --a------ C:\WINDOWS\BPMNT.dll
                                  2008-08-15 18:14 . 2008-08-15 18:14 71,749 --a------ C:\WINDOWS\hcextoutput.dll
                                  2008-08-15 18:14 . 2008-08-15 22:11 823 --a------ C:\WINDOWS\tsc.ini
                                  2008-08-15 18:13 . 2008-08-15 18:14 <DIR> d-------- C:\WINDOWS\AU_Temp
                                  2008-08-15 18:13 . 2008-08-15 18:13 <DIR> d-------- C:\WINDOWS\AU_Log
                                  2008-08-15 18:13 . 2008-08-15 18:13 507,904 --a------ C:\WINDOWS\TMUPDATE.DLL
                                  2008-08-15 18:13 . 2008-08-15 18:13 286,720 --a------ C:\WINDOWS\PATCH.EXE
                                  2008-08-15 18:13 . 2008-08-15 18:13 69,689 --a------ C:\WINDOWS\UNZIP.DLL
                                  2008-08-15 18:13 . 2008-08-15 18:13 170 --a------ C:\WINDOWS\GetServer.ini
                                  2008-08-14 03:01 . 2008-08-14 03:03 1,374 --a------ C:\WINDOWS\imsins.BAK
                                  2008-08-10 13:35 . 2008-08-10 13:35 <DIR> d-------- C:\Program Files\Enigma Software Group

                                  .
                                  (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
                                  .
                                  2008-09-09 16:32 --------- d-----w C:\Program Files\InvoiceNet40
                                  2008-08-21 07:07 --------- d-----w C:\Documents and Settings\All Users\Application Data\Microsoft Help
                                  2008-08-12 02:21 --------- d-----w C:\Program Files\Hijackthis Version Française
                                  2008-08-10 15:38 --------- d-----w C:\Documents and Settings\HP_Administrator\Application Data\OpenOffice.org2
                                  2008-08-09 20:31 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
                                  2008-08-09 20:27 --------- d-----w C:\Program Files\Spybot - Search & Destroy
                                  2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll
                                  2008-07-19 02:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
                                  2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
                                  2008-07-19 02:10 53,448 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe
                                  2008-07-19 02:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
                                  2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
                                  2008-07-19 02:10 36,552 ----a-w C:\WINDOWS\system32\dllcache\wups.dll
                                  2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
                                  2008-07-19 02:09 563,912 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll
                                  2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
                                  2008-07-19 02:09 325,832 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll
                                  2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
                                  2008-07-19 02:09 205,000 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll
                                  2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
                                  2008-07-19 02:09 1,811,656 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll
                                  2008-07-19 02:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
                                  2008-07-19 02:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
                                  2008-07-13 16:53 --------- d-----w C:\Program Files\Lavasoft
                                  2008-07-13 16:52 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
                                  2008-07-13 16:52 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
                                  2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\es.dll
                                  2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\system32\dllcache\es.dll
                                  2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\mscms.dll
                                  2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\system32\dllcache\mscms.dll
                                  2008-06-24 14:57 3,592,192 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll
                                  2008-06-23 09:20 70,656 ----a-w C:\WINDOWS\system32\dllcache\ie4uinit.exe
                                  2008-06-23 09:20 625,664 ----a-w C:\WINDOWS\system32\dllcache\iexplore.exe
                                  2008-06-23 09:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe
                                  2008-06-21 05:23 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll
                                  2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\mswsock.dll
                                  2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\system32\dllcache\mswsock.dll
                                  2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\system32\dllcache\dnsapi.dll
                                  2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\system32\dllcache\tcpip.sys
                                  2008-06-20 10:44 138,368 ----a-w C:\WINDOWS\system32\dllcache\afd.sys
                                  2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\system32\dllcache\tcpip6.sys
                                  2008-06-13 13:10 272,128 ------w C:\WINDOWS\system32\dllcache\bthport.sys
                                  2001-03-28 17:02 122,880 -c--a-w C:\WINDOWS\inf\Agfa\message.exe
                                  1999-12-21 01:57 3,072 ----a-w C:\Program Files\InvoiceNet40toolbar.dat
                                  .

                                  ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
                                  .
                                  .
                                  *Note* empty entries & legit default entries are not shown
                                  REGEDIT4

                                  [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 15360]
                                  "MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
                                  "swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-07-26 68856]
                                  "ISUSPM"="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
                                  "SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-30 1829712]
                                  "comsys"="C:\WINDOWS\system32\ynqpcxef.exe" [2008-09-09 90112]
                                  "AdobeUpdater"="C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe" [2007-03-01 2321600]

                                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
                                  "ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 64512]
                                  "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-02-21 143360]
                                  "HPHUPD08"="c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe" [2005-06-02 49152]
                                  "DISCover"="C:\Program Files\DISC\DISCover.exe" [2005-11-11 1064960]
                                  "DiscUpdateManager"="C:\Program Files\DISC\DiscUpdateMgr.exe" [2005-11-11 61440]
                                  "DMAScheduler"="c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe" [2005-11-01 90112]
                                  "Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2005-07-22 237568]
                                  "HPBootOp"="C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2005-11-09 249856]
                                  "HP Software Update"="C:\Program Files\HP\HP Software Update\HPwuSchd2.exe" [2005-05-12 49152]
                                  "ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-09-11 218032]
                                  "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2008-05-15 79224]
                                  "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2005-12-14 7323648]
                                  "WinampAgent"="C:\Program Files\Winamp\Winampa.exe" [2002-04-26 12288]
                                  "SSBkgdUpdate"="C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2003-10-14 155648]
                                  "PaperPort PTD"="C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe" [2005-03-17 57393]
                                  "IndexSearch"="C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe" [2005-03-17 40960]
                                  "SetDefPrt"="C:\Program Files\Brother\Brmfl05c\BrStDvPt.exe" [2005-01-26 49152]
                                  "ControlCenter2.0"="C:\Program Files\Brother\ControlCenter2\brctrcen.exe" [2005-11-11 995328]
                                  "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-05-11 40048]
                                  "RoxWatchTray"="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe" [2007-08-16 236016]
                                  "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-01-19 185896]
                                  "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 132496]
                                  "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-09-01 282624]
                                  "nwiz"="nwiz.exe" [2005-12-14 C:\WINDOWS\system32\nwiz.exe]
                                  "RTHDCPL"="RTHDCPL.EXE" [2006-01-11 C:\WINDOWS\RTHDCPL.EXE]
                                  "WD Button Manager"="WDBtnMgr.exe" [2006-12-01 C:\WINDOWS\system32\WDBtnMgr.exe]

                                  C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
                                  Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2006-12-01 110592]
                                  HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2005-05-12 282624]
                                  NDAS Device Management.lnk - C:\Program Files\NDAS\System\ndasmgmt.exe [2007-06-29 236520]

                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
                                  "InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
                                  "InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

                                  [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
                                  "msacm.l3acm"= l3codecp.acm

                                  [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
                                  "DisableMonitoring"=dword:00000001

                                  [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
                                  "%windir%\\system32\\sessmgr.exe"=
                                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
                                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
                                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
                                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
                                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
                                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
                                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
                                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
                                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
                                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
                                  "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
                                  "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
                                  "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
                                  "C:\\Program Files\\DISC\\DISCover.exe"=
                                  "C:\\Program Files\\DISC\\DiscStreamHub.exe"=
                                  "C:\\Program Files\\DISC\\myFTP.exe"=
                                  "C:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
                                  "C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
                                  "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
                                  "C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
                                  "C:\\mirc\\mirc32.exe"=
                                  "C:\\Program Files\\uTorrent\\utorrent.exe"=
                                  "C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
                                  "C:\\WINDOWS\\system32\\fxsclnt.exe"=
                                  "C:\\Program Files\\Roxio\\Digital Home 9\\RoxioUpnpService9.exe"=
                                  "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
                                  "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
                                  "C:\\Program Files\\LimeWire\\LimeWire.exe"=

                                  R0 lfsfilt;Lean File Sharing;C:\WINDOWS\system32\DRIVERS\lfsfilt.sys [2007-06-29 254440]
                                  R0 lpx;LPX Protocol;C:\WINDOWS\system32\DRIVERS\lpx.sys [2007-06-29 62056]
                                  R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [2008-05-15 78416]
                                  R1 ndasfat;NDAS FAT;C:\WINDOWS\system32\DRIVERS\ndasfat.sys [2007-06-29 372584]
                                  R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-05-15 20560]
                                  R3 BrSerIf;Brother MFC Serial Port Interface WDM Driver;C:\WINDOWS\system32\Drivers\BrSerIf.sys [2004-09-29 51712]
                                  R3 BrUsbSer;Brother MFC USB Serial WDM Driver;C:\WINDOWS\system32\Drivers\BrUsbSer.sys [2004-01-10 11648]
                                  R3 ndasbus;NDAS Bus Driver;C:\WINDOWS\system32\DRIVERS\ndasbus.sys [2007-06-29 75880]

                                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
                                  \Shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe protect.ed 480 480

                                  *Newly Created Service* - PROCEXP90
                                  .
                                  - - - - ORPHANS REMOVED - - - -

                                  HKLM-Run-SpyHunter Security Suite - C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
                                  HKLM-Run-PCDrProfiler - (no file)

                                  .
                                  ------- Supplementary Scan -------
                                  .
                                  O8 -: Convertir les liens sélectionnés en fichier Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                                  O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                                  O8 -: E&xporter vers Microsoft Excel - C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
                                  .

                                  **************************************************************************

                                  catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
                                  Rootkit scan 2008-09-09 15:46:09
                                  Windows 5.1.2600 Service Pack 2 NTFS

                                  scanning hidden processes ...

                                  scanning hidden autostart entries ...

                                  scanning hidden files ...

                                  scan completed successfully
                                  hidden files: 0

                                  **************************************************************************
                                  .
                                  Completion time: 2008-09-09 15:47:52
                                  ComboFix-quarantined-files.txt 2008-09-09 19:47:42

                                  Pre-Run: 150,348,357,632 bytes free
                                  Post-Run: 150,360,346,624 bytes free

                                  215 --- E O F --- 2008-08-21 07:07:16
                                  0
                                  1. et voici encore le nouveau rapport Hijackthis:
                                    Logfile of Trend Micro HijackThis v2.0.2
                                    Scan saved at 16:00:06, on 2008-09-09
                                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                                    MSIE: Internet Explorer v7.00 (7.00.6000.16705)
                                    Boot mode: Normal

                                    Running processes:
                                    C:\WINDOWS\System32\smss.exe
                                    C:\WINDOWS\system32\winlogon.exe
                                    C:\WINDOWS\system32\services.exe
                                    C:\WINDOWS\system32\lsass.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                    C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    C:\WINDOWS\system32\spoolsv.exe
                                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    C:\Program Files\Bonjour\mDNSResponder.exe
                                    C:\WINDOWS\eHome\ehRecvr.exe
                                    C:\WINDOWS\eHome\ehSched.exe
                                    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
                                    C:\Program Files\NDAS\System\ndassvc.exe
                                    C:\WINDOWS\system32\nvsvc32.exe
                                    C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
                                    C:\WINDOWS\system32\svchost.exe
                                    C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
                                    C:\WINDOWS\system32\dllhost.exe
                                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                    C:\WINDOWS\ehome\ehtray.exe
                                    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
                                    C:\WINDOWS\RTHDCPL.EXE
                                    C:\Program Files\DISC\DiscUpdateMgr.exe
                                    C:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
                                    C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                                    C:\WINDOWS\eHome\ehmsas.exe
                                    C:\WINDOWS\system32\WDBtnMgr.exe
                                    C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                                    C:\WINDOWS\System32\svchost.exe
                                    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
                                    C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                    C:\WINDOWS\system32\ctfmon.exe
                                    C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
                                    C:\WINDOWS\system32\ynqpcxef.exe
                                    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    C:\WINDOWS\system32\ps2.exe
                                    c:\windows\system\hpsysdrv.exe
                                    C:\Program Files\Java\jre1.6.0_03\bin\jucheck.exe
                                    C:\WINDOWS\system32\wscntfy.exe
                                    C:\WINDOWS\system32\wuauclt.exe
                                    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                    C:\WINDOWS\explorer.exe
                                    C:\PROGRA~1\MICROS~4\Office12\OUTLOOK.EXE
                                    C:\Program Files\Internet Explorer\IEXPLORE.EXE
                                    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                                    C:\HiJackThis\HijackThis.exe

                                    O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
                                    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                                    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                                    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                                    O2 - BHO: HpWebHelper - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dll
                                    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll
                                    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                                    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                                    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
                                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
                                    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                                    O4 - HKLM\..\Run: [HPHUPD08] c:\Program Files\HP\Digital Imaging\{33D6CC28-9F75-4d1b-A11D-98895B3A3729}\hphupd08.exe
                                    O4 - HKLM\..\Run: [DISCover] C:\Program Files\DISC\DISCover.exe
                                    O4 - HKLM\..\Run: [DiscUpdateManager] C:\Program Files\DISC\DiscUpdateMgr.exe
                                    O4 - HKLM\..\Run: [DMAScheduler] c:\Program Files\Sonic\DigitalMedia Plus\DigitalMedia Archive\DMAScheduler.exe
                                    O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
                                    O4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /run
                                    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPwuSchd2.exe
                                    O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
                                    O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
                                    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                                    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
                                    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                                    O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
                                    O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
                                    O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05c\BrStDvPt.exe
                                    O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
                                    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
                                    O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                                    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
                                    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                                    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                                    O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe
                                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                                    O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler
                                    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                                    O4 - HKCU\..\Run: [comsys] C:\WINDOWS\system32\ynqpcxef.exe
                                    O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
                                    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
                                    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
                                    O4 - Global Startup: NDAS Device Management.lnk = C:\Program Files\NDAS\System\ndasmgmt.exe
                                    O8 - Extra context menu item: Convertir les liens sélectionnés en fichier Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
                                    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
                                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
                                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
                                    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                    O15 - Trusted Zone: http://*.trymedia.com (HKLM)
                                    O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
                                    O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
                                    O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
                                    O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
                                    O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://walmart.pnimedia.com/upload/activex/v2_0_0_9/PCAXSetupv2.0.0.9.cab?
                                    O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://walmart.pnimedia.com/upload/activex/v2_0_0_10/PCAXSetupv2.0.0.10.cab?
                                    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                    O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                                    O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
                                    O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                                    O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                                    O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                                    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                                    O23 - Service: Service Bonjour (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                                    O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
                                    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                    O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
                                    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                    O23 - Service: NDAS Service (ndassvc) - XIMETA, Inc. - C:\Program Files\NDAS\System\ndassvc.exe
                                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                                    O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
                                    O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
                                    O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
                                    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                    O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                    0
                                    1. Contributeur sécurité
                                      bien,
                                      il reste encore un ou deux p'tit truc que normalement MBAM va enlever

                                      ceci dit, le scan est très long...donc je reprendrai demain

                                      Télécharge Malwarebytes' Anti-Malware et enregistre le sur ton Bureau.
                                      https://www.malwarebytes.com/
                                      A la fin du téléchargement, ferme toutes les fenêtres et programmes, y compris celui-ci.
                                      Double-clique sur l'icône "Download_mbam-setup.exe" sur ton bureau pour démarrer le programme d'installation.
                                      Pendant l'installation, suis les indications n'apporte aucune modification aux réglages par défaut et, en fin d'installation, vérifie que les options Update Malwarebytes' Anti-Malware et Launch Malwarebytes' Anti-Malware sont cochées.
                                      MBAM démarrera automatiquement et enverra un message demandant à mettre à jour le programme avant de lancer une analyse. Comme MBAM se met automatiquement à jour en fin d'installation, clique sur OK pour fermer la boîte de dialogue.
                                      Ferme MBAM
                                      Redémarre en mode sans échec, pour cela, redémarre l'ordinateur, avant le logo Windows, tapote sur la touche F8, un menu va apparaître, choisis Mode sans échec et appuye sur la touche entrée du clavier.

                                      Relance MBAM
                                      La fenêtre principale de MBAM s'affiche :
                                      Dans l'onglet analyse, vérifie que "Exécuter un examen complet" est coché et clique sur le bouton Rechercher pour démarrer l'analyse.
                                      MBAM analyse ton ordinateur. L'analyse peut prendre un certain temps. Il suffit de vérifier de temps en temps son avancement.

                                      A la fin de l'analyse, un message s'affiche indiquant la fin de l'analyse. Clique sur OK pour poursuivre.
                                      Si des malwares ont été détectés, leur liste s'affiche.
                                      ***EN CLIQUANT SUR SUPPRESSION(?)FAIT LE***, MBAM va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.

                                      MBAM va ouvrir le Bloc-notes et y copier le rapport d'analyse. Ferme le Bloc-notes. (Le rapport peut être retrouvé sous l'onglet Rapports/logs)
                                      Ferme MBAM en cliquant sur Quitter.
                                      Poste le rapport dans ta réponse
                                      0
                                      1. Voici le dernier rapport:

                                        Malwarebytes' Anti-Malware 1.27
                                        Version de la base de données: 1133
                                        Windows 5.1.2600 Service Pack 2

                                        2008-09-09 17:20:09
                                        mbam-log-2008-09-09 (17-20-09).txt

                                        Type de recherche: Examen complet (C:\|D:\|)
                                        Eléments examinés: 193043
                                        Temps écoulé: 36 minute(s), 6 second(s)

                                        Processus mémoire infecté(s): 0
                                        Module(s) mémoire infecté(s): 0
                                        Clé(s) du Registre infectée(s): 4
                                        Valeur(s) du Registre infectée(s): 1
                                        Elément(s) de données du Registre infecté(s): 0
                                        Dossier(s) infecté(s): 0
                                        Fichier(s) infecté(s): 2

                                        Processus mémoire infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Module(s) mémoire infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Clé(s) du Registre infectée(s):
                                        HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
                                        HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
                                        HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
                                        HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.

                                        Valeur(s) du Registre infectée(s):
                                        HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\comsys (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.

                                        Elément(s) de données du Registre infecté(s):
                                        (Aucun élément nuisible détecté)

                                        Dossier(s) infecté(s):
                                        (Aucun élément nuisible détecté)
                                        0
                                        1. Contributeur sécurité
                                          Télécharge OTMoveIt2( de Old Timer )
                                          http://download.bleepingcomputer.com/oldtimer/OTMoveIt2.exe
                                          Une fois téléchargé double-clique sur OTMoveIt2.exe pour le lancer.
                                          Assure toi que la case "Unregister Dll's and Ocx's" est cochée
                                          Copie les lignes en gras qui se trouvent en dessous :

                                          C:\WINDOWS\LPT$VPN.479
                                          C:\Documents and Settings\All Users\Application Data\lcxkxqvy
                                          C:\WINDOWS\system32\ynqpcxef.exe
                                          C:\WINDOWS\VPTNFILE.479
                                          C:\WINDOWS\tsc.ptn
                                          C:\WINDOWS\TSC.exe
                                          C:\WINDOWS\tsc.ini


                                          et colle-les dans le cadre de gauche de OTMoveIt : "Paste List Of Files/Folders to Move."
                                          Clique sur "MoveIt!" pour lancer la suppression.
                                          Le résultat apparaitra dans le cadre "Results".
                                          Clique sur Exit pour fermer.
                                          Poste le rapport situé dans C:\_OTMoveIt\MovedFiles.
                                          -Il te sera peut-être demander de redémarrer le pc pour achever la suppression -> Accepte ( si il ne fait pas automatiquement , fait-le toi même )

                                          /!\ Note : Au démarrage ton bureau RISQUE de ne plus apparaître, dans ce cas fait --> CTRL+ALT+SUPP pour ouvrir le Gestionnaire des tâches.
                                          Puis rends toi sur l'onglet "Processus". Clique en haut à gauche sur "Fichiers" et choisis "Exécuter"
                                          Tape "explorer.exe"(sans les guillemèts) et valide. Cela fera réapparaître le Bureau.

                                          je regarde demain car fatigué
                                          0
                                          • 1
                                          • 2