Problème trojans

Bonjour,

Voila je suis infecté depuis quelques jours de nombreux trojans, qui m'affichent sans cesse lorsque je navigue sur internet le message suivant :
"Processus hote pour les services windows a cessé de fonctionner"

De plus, mon pc se coupe parfois et un ecran bleu apparait...

J'ai réussit a obtenir les noms de certains trojans:
Win32/Wigon.DV
Win32/Vundo.gen!D
Win32/Renos.AW

Mon probleme est que nod32 ne supprime pas ces virus et des logiciels tel que Spybot ou encore Malwarebytes ne se lancent plus, un message apparait a chaque fois que j'ouvre ces logiciels
"Malwaresbytes a cesser de fonctionner"

Je joins ici le rapport Hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:16:18, on 19/11/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16757)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Orange\Systray\SystrayApp.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Users\Gauthier\AppData\Local\Temp\winlogin.exe
C:\Windows\System32\rs32net.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Windows\System32\rs32net.exe
C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\System32\notepad.exe
C:\Windows\system32\conime.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\wermgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\DllHost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\WerFault.exe
C:\Windows\system32\WerFault.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\WerFault.exe
C:\Windows\system32\WerFault.exe
C:\Users\Gauthier\AppData\Local\Temp\csrssc.exe
C:\Users\Gauthier\Downloads\mbam-setup.exe
C:\Windows\system32\WerFault.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Windows\system32\WerFault.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: C:\Windows\system32\jsne87fidgf.dll - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\Windows\system32\jsne87fidgf.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [xsjfn83jkemfofght] C:\Users\Gauthier\AppData\Local\Temp\winlogin.exe
O4 - HKLM\..\Run: [rs32net] C:\Windows\System32\rs32net.exe
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [update 000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000] %AppData%\wunauclt.exe
O4 - HKCU\..\Run: [xsjfn83jkemfofght] C:\Users\Gauthier\AppData\Local\Temp\winlogin.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\Users\Gauthier\AppData\Local\Temp\csrssc.exe
O4 - HKCU\..\Run: [rs32net] C:\Windows\System32\rs32net.exe
O4 - HKCU\..\Run: [12CFG94-z641-2SF-N31P-5M1ER6H6L1] C:\RECYCLER\S-1-5-21-2543280688-2235057422-947018642-0300\winigon.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2009] c:\program files\uniblue\registrybooster\StartRegistryBooster.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.zebulon.fr/outils/antivirus/kavwebscan_unicode.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: mjwjmcu - C:\Windows\SYSTEM32\mjwjmcu32.dll
O22 - SharedTaskScheduler: mcb7uehuj3n8weuhejsw - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\Windows\system32\jsne87fidgf.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: FCI - Unknown owner - C:\Windows\system32\fci.exe.exe:ext.exe
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: ICF - Unknown owner - C:\Windows\system32\icf.exe.exe:ext.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe (file missing)
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 12293 bytes

Merci beaucoup d'avance, en esperant que l'on puisse m'aider...
Configuration: Windows Vista
Firefox 3.0.4

34 réponses

Résumé de la discussion

Des appareils infectés par plusieurs trojans provoquent des messages d’erreur répétés tels que « Processus hôte pour les services Windows a cessé de fonctionner », des écrans bleus et des défaillances d’outils de sécurité. Le contexte inclut des noms de trojans identifiés (Win32/Wigon.DV, Win32/Vundo.gen!D, Win32/Renos.AW) et un rapport HijackThis partagé comme point de départ pour le nettoyage à traiter. Les intervenants recommandent des outils comme ComboFix (déconnecter d'internet, désactiver temporairement les protections, puis exécuter le scan et partager le rapport), SDFix en mode sans échec et MBAM en nettoyage final. D'autres réponses suggèrent un processus combiné incluant MBAM, l’utilisation de rapports, et une vérification des programmes et services suspects avant de remettre le système en ligne.

Bobot (l’IA à votre service)
  1. ========== FILES ==========
    File/Folder C:\Windows\system3­2\uesiuqcr.exe not found.
    ========== COMMANDS ==========
    File delete failed. C:\Users\Gauthier\AppData\Local\Temp\etilqs_crT7WBgdFx5Ks3xHFrE5 scheduled to be deleted on reboot.
    File delete failed. C:\Users\Gauthier\AppData\Local\Temp\~DF1641.tmp scheduled to be deleted on reboot.
    File delete failed. C:\Users\Gauthier\AppData\Local\Temp\~DF3710.tmp scheduled to be deleted on reboot.
    File delete failed. C:\Users\Gauthier\AppData\Local\Temp\~DF3747.tmp scheduled to be deleted on reboot.
    File delete failed. C:\Users\Gauthier\AppData\Local\Temp\~DFC47.tmp scheduled to be deleted on reboot.
    File delete failed. C:\Users\Gauthier\AppData\Local\Temp\~DFED4.tmp scheduled to be deleted on reboot.
    User's Temp folder emptied.
    User's Temporary Internet Files folder emptied.
    User's Internet Explorer cache folder emptied.
    Local Service Temp folder emptied.
    Local Service Temporary Internet Files folder emptied.
    File delete failed. C:\Windows\temp\JET8979.tmp scheduled to be deleted on reboot.
    Windows Temp folder emptied.
    File delete failed. C:\Users\Gauthier\AppData\Local\Mozilla\Firefox\Profiles\vs09ivn6.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
    File delete failed. C:\Users\Gauthier\AppData\Local\Mozilla\Firefox\Profiles\vs09ivn6.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
    File delete failed. C:\Users\Gauthier\AppData\Local\Mozilla\Firefox\Profiles\vs09ivn6.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
    File delete failed. C:\Users\Gauthier\AppData\Local\Mozilla\Firefox\Profiles\vs09ivn6.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
    File delete failed. C:\Users\Gauthier\AppData\Local\Mozilla\Firefox\Profiles\vs09ivn6.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
    File delete failed. C:\Users\Gauthier\AppData\Local\Mozilla\Firefox\Profiles\vs09ivn6.default\XUL.mfl scheduled to be deleted on reboot.
    FireFox cache emptied.
    Temp folders emptied.

    OTMoveIt3 by OldTimer - Version 1.0.7.1 log created on 12042008_164417

    Files moved on Reboot...
    File C:\Users\Gauthier\AppData\Local\Temp\etilqs_crT7WBgdFx5Ks3xHFrE5 not found!
    C:\Users\Gauthier\AppData\Local\Temp\~DF1641.tmp moved successfully.
    File C:\Users\Gauthier\AppData\Local\Temp\~DF3710.tmp not found!
    File C:\Users\Gauthier\AppData\Local\Temp\~DF3747.tmp not found!
    File C:\Users\Gauthier\AppData\Local\Temp\~DFC47.tmp not found!
    File C:\Users\Gauthier\AppData\Local\Temp\~DFED4.tmp not found!
    C:\Windows\temp\JET8979.tmp moved successfully.
    C:\Users\Gauthier\AppData\Local\Mozilla\Firefox\Profiles\vs09ivn6.default\Cache\_CACHE_001_ moved successfully.
    C:\Users\Gauthier\AppData\Local\Mozilla\Firefox\Profiles\vs09ivn6.default\Cache\_CACHE_002_ moved successfully.
    C:\Users\Gauthier\AppData\Local\Mozilla\Firefox\Profiles\vs09ivn6.default\Cache\_CACHE_003_ moved successfully.
    C:\Users\Gauthier\AppData\Local\Mozilla\Firefox\Profiles\vs09ivn6.default\Cache\_CACHE_MAP_ moved successfully.
    C:\Users\Gauthier\AppData\Local\Mozilla\Firefox\Profiles\vs09ivn6.default\urlclassifier3.sqlite moved successfully.
    C:\Users\Gauthier\AppData\Local\Mozilla\Firefox\Profiles\vs09ivn6.default\XUL.mfl moved successfully.
    0
    1. Contributeur sécurité
      • Télécharge OTMoveIt3 de OldTimer
      http://oldtimer.geekstogo.com/OTMoveIt3.exe

      * Enregistre-le sur ton bureau
      * Clique droit sur OTMoveIt3.exe et " executer en tant qu'admin' ...pour le lancer (l'extension peut ne pas apparaître)
      * Copie-colle l'ensemble des lignes en gras ci dessous dans la partie "Paste Instructions for Items to be Moved" (en-dessous de la barre jaune) :

      :files

      C:\Windows\system3­2\uesiuqcr.exe
      :commands
      [emptytemp]
      [Reboot]


      * Clique sur le bouton rouge Moveit! pour lancer le nettoyage
      * Copie-colle dans ta prochaine réponse tout ce qui se trouve dans la fenêtre Results (en vert à droite)

      ==> Un rapport sera généré dans le dossier C:\ _OTMoveIt\MovedFiles avec la date et l'heure du passage de l'outil (mmddyyyy_hhmmss.log)

      * Ferme OTMoveIt3 (en cliquant sur Exit)

      Note : Si un fichier ou un dossier ne sait être supprimé directement, l'outil peut demander un redémarrage pour terminer le processus.
      Clique alors sur "Yes" pour accepter...

      0
      1. Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 16:19:13, on 04/12/2008
        Platform: Windows Vista (WinNT 6.00.1904)
        MSIE: Internet Explorer v7.00 (7.00.6000.16757)
        Boot mode: Normal

        Running processes:
        C:\Windows\system32\uesiuqcr.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\Program Files\Windows Defender\MSASCui.exe
        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
        C:\Program Files\Orange\Systray\SystrayApp.exe
        C:\Windows\system32\taskeng.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
        C:\Windows\System32\rundll32.exe
        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
        C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Program Files\Logitech\SetPoint\SetPoint.exe
        C:\Program Files\Windows Sidebar\sidebar.exe
        C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
        C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
        C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
        C:\Windows\system32\wuauclt.exe
        C:\Program Files\Mozilla Firefox\firefox.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
        R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
        F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\system32\uesiuqcr.exe,
        O1 - Hosts: ::1 localhost
        O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)
        O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
        O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
        O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
        O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
        O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
        O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
        O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
        O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
        O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
        O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)
        O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)
        O13 - Gopher Prefix:
        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
        O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
        O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
        O23 - Service: FCI - Unknown owner - C:\Windows\system32\fci.exe.exe:ext.exe (file missing)
        O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
        O23 - Service: ICF - Unknown owner - C:\Windows\system32\icf.exe.exe:ext.exe (file missing)
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
        O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
        O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
        O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
        O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
        O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe (file missing)
        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
        O23 - Service: SBSD Security Center Service (SBSDWSCService) - Unknown owner - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (file missing)
        O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
        O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
        O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
        0
        1. Contributeur sécurité
          Bon, après concertation :

          Ouvre ton bloc notes ( clic droit sur le bureau ) => nouveau => document texte
          Nomme le windows.reg.

          Copie colle ce texte ( en gras ) ci dessous dans ce document. ( sans les ========)
          ==========================================
          Windows Registry Editor Version 5.00

          [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21A237A4-3A94-4198-911D-647ED2263DD2}]
          [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{21A237A4-3A94-4198-911D-647ED2263DD2}]
          [-HKEY_CLASSES_ROOT\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}]
          [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}]
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
          "{32099AAC-C132-4136-9E9A-4E364A424E17}"=-


          ==========================================

          Ferme ce document, et a sa demande, enregistre les modifications.
          une fois que tu as fait ton script et que tu l'as enregistré avec l'extension reg,
          tu obtiens une icone comme celle ci => http://img216.imageshack.us/img216/6931/regfix1yf1.jpg
          double clique sur l'icône,et ensuite acceptes la fusion.

          reposte moi un nouveau scan HJT ensuite.
          0
          1. Contributeur sécurité
            Arffff Vista....

            C'est pas mon fort, certains outils ne passent pas avec...

            Je demande a mes ""collègues " une manip', et je reviens
            0
            1. Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 21:50:58, on 03/12/2008
              Platform: Windows Vista (WinNT 6.00.1904)
              MSIE: Internet Explorer v7.00 (7.00.6000.16757)
              Boot mode: Normal

              Running processes:
              C:\Windows\system32\uesiuqcr.exe
              C:\Windows\system32\Dwm.exe
              C:\Windows\Explorer.EXE
              C:\Program Files\Windows Defender\MSASCui.exe
              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
              C:\Program Files\Orange\Systray\SystrayApp.exe
              C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
              C:\Windows\System32\rundll32.exe
              C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
              C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
              C:\Windows\system32\taskeng.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
              C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              C:\Program Files\Logitech\SetPoint\SetPoint.exe
              C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
              C:\Program Files\Windows Sidebar\sidebar.exe
              C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
              C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
              C:\Windows\system32\conime.exe
              C:\Windows\system32\wuauclt.exe
              C:\Program Files\Mozilla Firefox\firefox.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
              R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
              F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\system32\uesiuqcr.exe,
              O1 - Hosts: ::1 localhost
              O2 - BHO: getfn32.msiets - {21A237A4-3A94-4198-911D-647ED2263DD2} - C:\Windows\system32\getfn32.dll
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)
              O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
              O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
              O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
              O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
              O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
              O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
              O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
              O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
              O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
              O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
              O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
              O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
              O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
              O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)
              O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (file missing)
              O13 - Gopher Prefix:
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
              O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
              O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
              O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
              O23 - Service: FCI - Unknown owner - C:\Windows\system32\fci.exe.exe:ext.exe (file missing)
              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
              O23 - Service: ICF - Unknown owner - C:\Windows\system32\icf.exe.exe:ext.exe (file missing)
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
              O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
              O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
              O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
              O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
              O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
              O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe (file missing)
              O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
              O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
              O23 - Service: SBSD Security Center Service (SBSDWSCService) - Unknown owner - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (file missing)
              O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
              O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
              O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
              O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
              O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
              0
              1. Contributeur sécurité
                Refais moi un log HJT tout frais stp...

                Ø Relance Hijackthis en double cliquant sur son raccourci sur le Bureau.
                Choisis l'option "Do a system scan and save a log file"
                Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
                Clique sur "Edition" ->> "Sélectionner tout", puis sur "Edition" ->> Copier" pour copier tout le contenu du rapport ici
                0
                1. [b]Files with hidden attributes[/b]:

                  Thu 7 Aug 2008 1,024 A..H. --- "C:\diego\dummy.sys"
                  Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
                  Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
                  Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
                  Tue 18 Nov 2008 72,704 ..SHR --- "C:\RECYCLER\S-1-5-21-2543280688-2235057422-947018642-0300\winigon.exe"
                  Thu 2 Nov 2006 524,288 A.SH. --- "C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
                  Thu 2 Nov 2006 524,288 A.SH. --- "C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
                  Sun 15 Jun 2008 524,288 A.SH. --- "C:\Users\Gauthier\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
                  Mon 25 Feb 2008 524,288 A.SH. --- "C:\Users\Gauthier\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
                  Mon 24 Nov 2008 524,288 A.SH. --- "C:\Users\Gauthier\ntuser.dat{4279ff4f-ba60-11dd-89c3-001b24a350c6}.TMContainer00000000000000000001.regtrans-ms"
                  Mon 24 Nov 2008 524,288 A.SH. --- "C:\Users\Gauthier\ntuser.dat{4279ff4f-ba60-11dd-89c3-001b24a350c6}.TMContainer00000000000000000002.regtrans-ms"
                  Thu 7 Aug 2008 1,024 A..H. --- "C:\$Recycle.Bin\S-1-5-21-916745695-1501797539-4020289792-1002\$R5PQYXW\dummy.sys"
                  Thu 7 Aug 2008 1,024 A..H. --- "C:\$Recycle.Bin\S-1-5-21-916745695-1501797539-4020289792-1002\$RWKVGWB\dummy.sys"
                  Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
                  Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
                  Sat 22 Mar 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{e2022792-f7f4-11dc-b785-00030d000001}.TMContainer00000000000000000001.regtrans-ms"
                  Sat 22 Mar 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{e2022792-f7f4-11dc-b785-00030d000001}.TMContainer00000000000000000002.regtrans-ms"
                  Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
                  Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
                  Sat 22 Mar 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{e202278e-f7f4-11dc-b785-00030d000001}.TMContainer00000000000000000001.regtrans-ms"
                  Sat 22 Mar 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{e202278e-f7f4-11dc-b785-00030d000001}.TMContainer00000000000000000002.regtrans-ms"
                  Sun 23 Nov 2008 5,629,208 A..H. --- "C:\Windows\SoftwareDistribution\Download\59b6efce37fc710d4834d009eab90c77\BIT5437.tmp"
                  Thu 11 Oct 2007 524,288 A.SH. --- "C:\Windows\System32\config\systemprofile\ntuser.dat{8aafc203-7820-11dc-a7d6-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms"
                  Thu 11 Oct 2007 524,288 A.SH. --- "C:\Windows\System32\config\systemprofile\ntuser.dat{8aafc203-7820-11dc-a7d6-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms"
                  Wed 3 Dec 2008 5,242,880 A.SH. --- "C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms"
                  Fri 14 Nov 2008 524,288 A.SH. --- "C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms"
                  Wed 10 Sep 2008 524,288 A.SH. --- "C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms"
                  Thu 11 Sep 2008 5,242,880 A.SH. --- "C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms"
                  Fri 14 Nov 2008 5,242,880 A.SH. --- "C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms"
                  Fri 15 Aug 2008 524,288 A.SH. --- "C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms"
                  Wed 3 Dec 2008 524,288 A.SH. --- "C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms"
                  Wed 26 Nov 2008 524,288 A.SH. --- "C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
                  Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
                  Mon 25 Feb 2008 524,288 A.SH. --- "C:\Users\Gauthier\AppData\Local\Microsoft\Windows\UsrClass.dat{2c53a35a-e3bb-11dc-97fd-00030d000001}.TMContainer00000000000000000001.regtrans-ms"
                  Mon 25 Feb 2008 524,288 A.SH. --- "C:\Users\Gauthier\AppData\Local\Microsoft\Windows\UsrClass.dat{2c53a35a-e3bb-11dc-97fd-00030d000001}.TMContainer00000000000000000002.regtrans-ms"
                  Mon 24 Nov 2008 524,288 A.SH. --- "C:\Users\Gauthier\AppData\Local\Microsoft\Windows\UsrClass.dat{4279ff53-ba60-11dd-89c3-001b24a350c6}.TMContainer00000000000000000001.regtrans-ms"
                  Mon 24 Nov 2008 524,288 A.SH. --- "C:\Users\Gauthier\AppData\Local\Microsoft\Windows\UsrClass.dat{4279ff53-ba60-11dd-89c3-001b24a350c6}.TMContainer00000000000000000002.regtrans-ms"
                  Tue 26 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat{755be32b-e47c-11dc-ac74-00030d000001}.TMContainer00000000000000000001.regtrans-ms"
                  Tue 26 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat{755be32b-e47c-11dc-ac74-00030d000001}.TMContainer00000000000000000002.regtrans-ms"
                  Tue 26 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat{755be331-e47c-11dc-ac74-00030d000001}.TMContainer00000000000000000001.regtrans-ms"
                  Tue 26 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat{755be331-e47c-11dc-ac74-00030d000001}.TMContainer00000000000000000002.regtrans-ms"
                  Tue 26 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat{755be13f-e47c-11dc-ac74-00030d000001}.TMContainer00000000000000000001.regtrans-ms"
                  Tue 26 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat{755be13f-e47c-11dc-ac74-00030d000001}.TMContainer00000000000000000002.regtrans-ms"
                  Tue 26 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat{755be335-e47c-11dc-ac74-00030d000001}.TMContainer00000000000000000001.regtrans-ms"
                  Tue 26 Feb 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat{755be335-e47c-11dc-ac74-00030d000001}.TMContainer00000000000000000002.regtrans-ms"

                  [b]Program Folders[/b]:

                  C:\Program Files\

                  Activation Assistant for the 2007 Microsoft Office suites
                  Activision
                  Adobe
                  Apple Software Update
                  BitDefender
                  CCleaner
                  Cisco
                  Common Files
                  CONEXANT
                  Counter-Strike Source LAN Edition
                  DAEMON Tools Lite
                  DAEMON Tools Toolbar
                  DIFX
                  DivX
                  eMule
                  ESET
                  Fichiers communs
                  FM Modifier 2.2
                  Free Audio Pack
                  Google
                  Guitar Pro 5
                  HDReg
                  HP
                  Infogrames
                  InstallShield Installation Information
                  Intel
                  Internet Explorer
                  IVT Corporation
                  Java
                  Lavalys
                  Lavasoft
                  Logitech
                  ma-config.com
                  Malwarebytes' Anti-Malware
                  Marvell
                  Messenger Plus! Live
                  Microsoft ActiveSync
                  Microsoft Games
                  Microsoft Office
                  Microsoft Works
                  Microsoft.NET
                  Movie Maker
                  Mozilla Firefox
                  MSBuild
                  MSN
                  MSXML 4.0
                  OpenAL
                  OpenOffice.org 3
                  Orange
                  Paint.NET
                  Panda Security
                  QuickTime
                  Reference Assemblies
                  Roxio
                  SafeSoft
                  SAGEM
                  Securitoo
                  Skype
                  SolidWorks
                  Sports Interactive
                  Spybot - Search & Destroy
                  Steam
                  SystemRequirementsLab
                  THQ
                  Trend Micro
                  Uninstall Information
                  UT2004
                  uTorrent
                  VideoLAN
                  Webtarot
                  Winamp
                  Windows Calendar
                  Windows Collaboration
                  Windows Defender
                  Windows Journal
                  Windows Live
                  Windows Mail
                  Windows Media Player
                  Windows NT
                  Windows Photo Gallery
                  Windows Sidebar
                  WinRAR
                  Wolfram Research
                  Yahoo!
                  Zero G Registry

                  C:\Program Files\Common Files\

                  Adobe
                  BitDefender
                  DESIGNER
                  France Telecom
                  HP
                  InstallShield
                  Java
                  Logishrd
                  microsoft shared
                  MSSoap
                  PX Storage Engine
                  Roxio Shared
                  Services
                  Skype
                  Sonic Shared
                  SpeechEngines
                  Steam
                  SureThing Shared
                  Symantec Shared
                  System
                  WindowsLiveInstaller
                  Wise Installation Wizard
                  ??crosoft.NET

                  [b]Add/Remove Programs[/b]:

                  Package de pilotes Windows - ITE Tech.Inc. (itecir) HIDClass (01/05/2007 5.0.0003.2)
                  Package de pilotes Windows - NVIDIA (nvlddmkm) Display (01/20/2008 7.15.11.6762)
                  Activation Assistant for the 2007 Microsoft Office suites
                  Adobe Flash Player ActiveX
                  Adobe Flash Player Plugin
                  CCleaner (remove only)
                  Conexant HD Audio
                  Copy Utility
                  Counter-Strike Source LAN Edition
                  DAEMON Tools Toolbar
                  Editeur FM2008 Fr
                  eMule
                  EPSON Smart Panel
                  EVEREST Home Edition v2.20
                  Football Manager 2008
                  Free Mp3 Wma Converter V 1.8.0
                  Guitar Pro 5.0
                  HijackThis 2.0.2
                  HP Imaging Device Functions 9.0
                  HP Photosmart Essential 2.01
                  HP Solution Center 9.0
                  Microsoft .NET Framework 1.1 Hotfix (KB929729)
                  Malwarebytes' Anti-Malware
                  Messenger Plus! Live
                  Microsoft .NET Framework 1.1
                  Mozilla Firefox (3.0.4)
                  NVIDIA Drivers
                  OpenAL
                  Logiciel Intel(R) PROSet/Wireless
                  Adobe Flash Player 9 ActiveX
                  Counter-Strike: Source
                  Day of Defeat: Source
                  Half-Life 2: Deathmatch
                  Half-Life 2: Lost Coast
                  System Requirements Lab
                  VideoLAN VLC media player 0.8.6f
                  WebTarot 1.26
                  MSXML4 Parser
                  Apple Software Update
                  Steam(TM)
                  CDDRV_Installer
                  HDReg France
                  TrayApp
                  OpenOffice.org 3.0
                  livebox
                  QuickTime
                  AutoUpdate
                  DeviceDiscovery
                  KhalInstallWrapper
                  Java(TM) 6 Update 7
                  Dawn of War - Soulstorm
                  JMB36X Raid Configurer
                  Google Earth
                  HP Smart Web Printing
                  HPSSupply
                  Kit de langue française 3.0
                  UnloadSupport
                  RICOH R5C83x/84x Flash Media Controller Driver Ver.3.50.03
                  Skype™ 3.2
                  Bluesoleil3.2.2.9 Release 070426
                  Activation Assistant for the 2007 Microsoft Office suites
                  eSupportQFolder
                  Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742)
                  Windows Media Player Firefox Plugin
                  CustomerResearchQFolder
                  Microsoft Visual C++ 2005 Redistributable
                  PanoStandAlone
                  DivX Codec
                  VideoToolkit01
                  HP Photosmart Essential2.01
                  MSXML 4.0 SP2 (KB954430)
                  SpeechRedist
                  BitDefender Total Security 2009
                  DivX Player
                  mPfMgr
                  mHelp
                  Microsoft Office Professional Edition 2003
                  Module de compatibilité pour Microsoft Office System 2007
                  Intel® Matrix Storage Manager
                  Counter-Strike: Source
                  mDriver
                  Adobe Shockwave Player
                  mCorev32.ism_new
                  HP Update
                  DeviceManagementQFolder
                  Adobe Reader 8.1.2 - Français
                  FM Modifier 2.22
                  HPProductAssistant
                  DivX Converter
                  Spybot - Search & Destroy
                  dj_sf_software
                  DivX Web Player
                  Roxio Creator 9 LE
                  Windows Live Messenger
                  SolutionCenter
                  MSXML 4.0 SP2 (KB936181)
                  Windows Live Mail
                  MSXML 4.0 SP2 (KB941833)
                  Marvell Miniport Driver
                  Microsoft .NET Framework 1.1
                  Ma-Config.com
                  Ad-Aware
                  BufferChm
                  mMHouse
                  Logitech SetPoint
                  mCPlug
                  PSSWCORE
                  ITECIR Driver
                  Windows Live installer
                  Status
                  Navigateur Orange
                  Orange - Logiciels Internet
                  Kit de langue française 3.0
                  µTorrent

                  [b]Run Values[/b]:

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
                  "Windows Defender"=hex(2):25,00,50,00,72,00,6f,00,67,00,72,00,61,00,6d,00,46,\
                  00,69,00,6c,00,65,00,73,00,25,00,5c,00,57,00,69,00,6e,00,64,00,6f,00,77,00,\
                  73,00,20,00,44,00,65,00,66,00,65,00,6e,00,64,00,65,00,72,00,5c,00,4d,00,53,\
                  00,41,00,53,00,43,00,75,00,69,00,2e,00,65,00,78,00,65,00,20,00,2d,00,68,00,\
                  69,00,64,00,65,00,00,00
                  "JMB36X IDE Setup"="C:\\Windows\\RaidTool\\xInsIDE.exe"
                  "RoxWatchTray"="\"C:\\Program Files\\Common Files\\Roxio Shared\\9.0\\SharedCOM\\RoxWatchTray9.exe\""
                  "SystrayORAHSS"="\"C:\\Program Files\\Orange\\Systray\\SystrayApp.exe\""
                  "ORAHSSSessionManager"="C:\\Program Files\\Orange\\SessionManager\\SessionManager.exe"
                  "Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE"
                  "IAAnotif"="C:\\Program Files\\Intel\\Intel Matrix Storage Manager\\iaanotif.exe"
                  "NvSvc"="RUNDLL32.EXE C:\\Windows\\system32\\nvsvc.dll,nvsvcStart"
                  "NvCplDaemon"="RUNDLL32.EXE C:\\Windows\\system32\\NvCpl.dll,NvStartup"
                  "NvMediaCenter"="RUNDLL32.EXE C:\\Windows\\system32\\NvMcTray.dll,NvTaskbarInit"
                  "SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.6.0_07\\bin\\jusched.exe\""
                  "BDAgent"="\"C:\\Program Files\\BitDefender\\BitDefender 2009\\bdagent.exe\""
                  "BitDefender Antiphishing Helper"="\"C:\\Program Files\\BitDefender\\BitDefender 2009\\IEShow.exe\""

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]
                  @=""

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
                  "Installed"="1"
                  @=""

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
                  "NoChange"="1"
                  "Installed"="1"
                  @=""

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
                  "Installed"="1"
                  @=""

                  [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
                  "Sidebar"="C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun"
                  "msnmsgr"="\"C:\\Program Files\\Windows Live\\Messenger\\MsnMsgr.Exe\" /background"
                  "SpybotSD TeaTimer"="C:\\Program Files\\Spybot - Search & Destroy\\TeaTimer.exe"

                  [b]Bot Check[/b]:

                  SERVICE_NAME: wscsvc
                  DISPLAY_NAME : Centre de sécurité
                  START_TYPE : 2 AUTO_START

                  SERVICE_NAME: sharedaccess
                  DISPLAY_NAME : Partage de connexion Internet (ICS)
                  START_TYPE : 4 DISABLED

                  SERVICE_NAME: wuauserv
                  DISPLAY_NAME : Windows Update
                  START_TYPE : 2 AUTO_START

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole]
                  "EnableDCOM"="Y"

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                  "DisableTaskMgr"=dword:00000001

                  [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                  "DisableTaskMgr"=dword:00000001

                  [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\System]
                  "DisableTaskMgr"=dword:00000001

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
                  "restrictanonymous"=dword:00000000

                  [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update]
                  "AUOptions"=dword:00000004

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
                  "WaitToKillServiceTimeout"="20000"

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  "Shell"="explorer.exe"
                  "Userinit"="C:\\Windows\\system32\\userinit.exe,C:\\Windows\\system32\\uesiuqcr.exe,"

                  [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shell extensions]

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetBT\Parameters]
                  "TransportBindName"="\\Device\\"

                  [b]ShellExecuteHooks[/b]:

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
                  "{47080957-7903-41FC-B655-CEBA0A65E64A}"=""

                  [b]Environment[/b]:

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager\environment
                  ComSpec REG_EXPAND_SZ %SystemRoot%\system32\cmd.exe
                  OS REG_SZ Windows_NT
                  Path REG_EXPAND_SZ %SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\;C:\Program Files\QuickTime\QTSystem\
                  PATHEXT REG_SZ .COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
                  TEMP REG_EXPAND_SZ %SystemRoot%\TEMP
                  TMP REG_EXPAND_SZ %SystemRoot%\TEMP
                  USERNAME REG_SZ SYSTEM
                  windir REG_EXPAND_SZ %SystemRoot%
                  RoxioCentral REG_SZ C:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
                  CLASSPATH REG_SZ .;C:\Program Files\QuickTime\QTSystem\QTJava.zip
                  QTJAVA REG_SZ C:\Program Files\QuickTime\QTSystem\QTJava.zip

                  [b]SecurityProviders[/b]:

                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders
                  SecurityProviders REG_SZ credssp.dll

                  [b]Authentication Packages[/b]:

                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
                  Authentication Packages REG_MULTI_SZ msv1_0\0C:\Windows\system32\efcywVmn\0\0

                  [b]Subsystem Startup[/b]:

                  [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems]
                  "Windows"="%SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16"

                  [b]Midi Drivers[/b]:

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32]
                  "midi"="wdmaud.drv"

                  [b]Non-Default IFEO Debugger[/b]:

                  [b]Non-Default Installed Components[/b]:

                  [b]Non-Default Safeboot Minimal[/b]:

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice
                  <NO NAME> REG_SZ Service

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\appinfo
                  <NO NAME> REG_SZ Service

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\keyiso
                  <NO NAME> REG_SZ Service

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\ntds
                  <NO NAME> REG_SZ Service

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\profsvc
                  <NO NAME> REG_SZ Service

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sacsvr
                  <NO NAME> REG_SZ Service

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\swprv
                  <NO NAME> REG_SZ Service

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\tabletinputservice
                  <NO NAME> REG_SZ Service

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\tbs
                  <NO NAME> REG_SZ Service

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\trustedinstaller
                  <NO NAME> REG_SZ Service

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\volmgr.sys
                  <NO NAME> REG_SZ Driver

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\volmgrx.sys
                  <NO NAME> REG_SZ Driver

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\windefend
                  <NO NAME> REG_SZ Service

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\{6bdd1fc1-810f-11d0-bec7-08002be2092f}
                  <NO NAME> REG_SZ IEEE 1394 Bus host controllers

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\{d48179be-ec20-11d1-b6b8-00c04fa372a7}
                  <NO NAME> REG_SZ SBP2 IEEE 1394 Devices

                  HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\{d94ee5d8-d189-4994-83d2-f68d7d41b0e6}
                  <NO NAME> REG_SZ SecurityDevices

                  [b]File Associations[/b]:

                  [HKEY_CLASSES_ROOT\batfile\shell\open\command]
                  @="\"%1\" %*"

                  [HKEY_CLASSES_ROOT\cmdfile\shell\open\command]
                  @="\"%1\" %*"

                  [HKEY_CLASSES_ROOT\comfile\shell\open\command]
                  @="\"%1\" %*"

                  [HKEY_CLASSES_ROOT\exefile\shell\open\command]
                  @="\"%1\" %*"
                  "IsolatedCommand"="\"%1\" %*"

                  [HKEY_CLASSES_ROOT\htafile\shell\open\command]
                  @="C:\\Windows\\system32\\mshta.exe \"%1\" %*"

                  [HKEY_CLASSES_ROOT\http\shell\open\command]
                  @="\"C:\\Program Files\\Mozilla Firefox\\firefox.exe\" -requestPending -osint -url \"%1\""

                  [HKEY_CLASSES_ROOT\htmlfile\shell\open\command]

                  [HKEY_CLASSES_ROOT\regedit\shell\open\command]
                  @="regedit.exe \"%1\""

                  [HKEY_CLASSES_ROOT\regfile\shell\open\command]
                  @="regedit.exe \"%1\" %*"

                  [HKEY_CLASSES_ROOT\scrfile\shell\open\command]
                  @="\"%1\" /S"

                  [HKEY_CLASSES_ROOT\txtfile\shell\open\command]
                  @="%SystemRoot%\system32\NOTEPAD.EXE %1"

                  [b]Finished![/b]
                  0
                  1. J'ai pas réussi a le lancer en mode sans echec....
                    Par contre j'ai fait un log en mode normal si sa peut t'aider

                    [b]System Report[/b]
                    *************

                    Run on 03/12/2008 at 21:07

                    Microsoft Windows [version 6.0.6000]

                    Current user is an administrator

                    [b]Running Processes[/b]:

                    \SystemRoot\System32\smss.exe [552]
                    C:\Windows\system32\csrss.exe [624]
                    C:\Windows\system32\wininit.exe [672]
                    C:\Windows\system32\csrss.exe [680]
                    C:\Windows\system32\services.exe [716]
                    C:\Windows\system32\lsass.exe [732]
                    C:\Windows\system32\lsm.exe [740]
                    C:\Windows\system32\svchost.exe [884]
                    C:\Windows\system32\nvvsvc.exe [960]
                    C:\Windows\system32\svchost.exe [984]
                    C:\Windows\System32\svchost.exe [1020]
                    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe [1072]
                    C:\Windows\system32\winlogon.exe [1096]
                    C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe [1132]
                    C:\Windows\System32\svchost.exe [1200]
                    C:\Windows\System32\svchost.exe [1224]
                    C:\Windows\system32\svchost.exe [1248]
                    C:\Windows\system32\SLsvc.exe [1348]
                    C:\Windows\system32\svchost.exe [1504]
                    C:\Windows\system32\svchost.exe [1616]
                    C:\Windows\system32\rundll32.exe [1644]
                    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [1892]
                    C:\Windows\system32\WLANExt.exe [1964]
                    C:\Windows\system32\uesiuqcr.exe [2024]
                    C:\Windows\system32\Dwm.exe [332]
                    C:\Windows\Explorer.EXE [400]
                    C:\Program Files\Windows Defender\MSASCui.exe [784]
                    C:\Windows\System32\spoolsv.exe [2000]
                    C:\Windows\system32\svchost.exe [1864]
                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [616]
                    C:\Program Files\Orange\Systray\SystrayApp.exe [1384]
                    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe [1944]
                    C:\Windows\System32\rundll32.exe [1628]
                    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [1824]
                    C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe [440]
                    C:\Windows\system32\taskeng.exe [2064]
                    C:\Program Files\Windows Sidebar\sidebar.exe [2108]
                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2180]
                    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2208]
                    C:\Program Files\Logitech\SetPoint\SetPoint.exe [2220]
                    C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe [2356]
                    C:\Program Files\Windows Sidebar\sidebar.exe [2504]
                    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE [2768]
                    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [3312]
                    C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe [3416]
                    C:\Windows\system32\svchost.exe [3516]
                    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe [3560]
                    C:\Windows\system32\PnkBstrA.exe [3608]
                    C:\Windows\system32\svchost.exe [3644]
                    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [3700]
                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [3720]
                    C:\Windows\system32\svchost.exe [3796]
                    C:\Windows\System32\svchost.exe [3824]
                    C:\Windows\system32\SearchIndexer.exe [3884]
                    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [3988]
                    C:\Windows\system32\wbem\wmiprvse.exe [2460]
                    C:\Windows\system32\taskeng.exe [1512]
                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [3144]
                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe [4672]
                    C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe [4908]
                    C:\Program Files\Windows Live\Messenger\usnsvc.exe [5340]
                    C:\Windows\servicing\TrustedInstaller.exe [5812]
                    C:\Windows\system32\conime.exe [3688]
                    C:\Windows\system32\wuauclt.exe [4848]
                    C:\Windows\system32\wbem\wmiprvse.exe [2352]
                    C:\diego\apps\procs.exe [5756]

                    [b]Drivers - Running[/b]:

                    ACPI
                    AFD
                    atapi
                    bdfm
                    Bdfndisf
                    bdfsfltr
                    bdftdif
                    BDSelfPr
                    BDVEDISK
                    Beep
                    bowser
                    BT
                    BTHidEnum
                    BTHidMgr
                    cdfs
                    cdrom
                    circlass
                    CLFS
                    CmBatt
                    Compbatt
                    crcdisk
                    DfsC
                    disk
                    DXGKrnl
                    Ecache
                    FileInfo
                    FltMgr
                    GEARAspiWDM
                    HdAudAddService
                    HDAudBus
                    HidIr
                    HidUsb
                    HTTP
                    i8042prt
                    iaStor
                    intelide
                    intelppm
                    iScsiPrt
                    itecir
                    JRAID
                    kbdclass
                    kbdhid
                    KSecDD
                    LHidFilt
                    lltdio
                    LMouFilt
                    luafv
                    Modem
                    monitor
                    mouclass
                    mouhid
                    MountMgr
                    mpsdrv
                    MRxDAV
                    mrxsmb
                    mrxsmb10
                    mrxsmb20
                    Msfs
                    msisadrv
                    mssmbios
                    Mup
                    NativeWifiP
                    NDIS
                    NdisTapi
                    Ndisuio
                    NdisWan
                    NDProxy
                    NetBIOS
                    netbt
                    NETw4v32
                    Npfs
                    nsiproxy
                    Ntfs
                    Null
                    nvlddmkm
                    ohci1394
                    partmgr
                    pci
                    PEAUTH
                    PptpMiniport
                    PSched
                    RasAcd
                    Rasl2tp
                    RasPppoe
                    rdbss
                    RDPCDD
                    RDPENCDD
                    RDPWD
                    rimmptsk
                    rimsptsk
                    ROOTMODEM
                    rspndr
                    sdbus
                    secdrv
                    Serenum
                    Smb
                    spldr
                    sptd
                    srv
                    srv2
                    srvnet
                    swenum
                    Tcpip
                    tcpipreg
                    TDTCP
                    tdx
                    TermDD
                    tssecsrv
                    tunmp
                    tunnel
                    umbus
                    usbccgp
                    usbehci
                    usbhub
                    usbuhci
                    usbvideo
                    VComm
                    VcommMgr
                    VgaSave
                    volmgr
                    volmgrx
                    volsnap
                    Wanarpv6
                    Wdf01000
                    yukonwlh

                    [b]Drivers - Stopped[/b]:

                    adp94xx
                    adpahci
                    adpu160m
                    adpu320
                    agp440
                    aic78xx
                    aliide
                    amdagp
                    amdide
                    AmdK7
                    AmdK8
                    arc
                    arcsas
                    AsyncMac
                    blbdrive
                    BrFiltLo
                    BrFiltUp
                    Brserid
                    BrSerWdm
                    BrUsbMdm
                    BrUsbSer
                    Btcsrusb
                    BTHMODEM
                    cmdide
                    Crusoe
                    driverhardwarev2
                    drmkaud
                    E1G60
                    elxstor
                    EraserUtilRebootDrv
                    fastfat
                    fdc
                    Filetrace
                    flpydisk
                    gagp30kx
                    HidBth
                    HpCISSs
                    i2omp
                    iaStorV
                    iirsp
                    IpFilterDriver
                    IpInIp
                    IPMIDRV
                    IPNAT
                    IRENUM
                    isapnp
                    iteatapi
                    iteraid
                    jatmlano
                    LSI_FC
                    LSI_SAS
                    LSI_SCSI
                    megasas
                    mpio
                    Mraid35x
                    msahci
                    msdsm
                    MSKSSRV
                    MSPCLOCK
                    MSPQM
                    MsRPC
                    MSTEE
                    NETw3v32
                    nfrd960
                    ntrigdigi
                    nvraid
                    nvstor
                    nv_agp
                    NwlnkFlt
                    NwlnkFwd
                    Parport
                    Parvdm
                    PCAMp50
                    PCASp50
                    pciide
                    pcmcia
                    Processor
                    Profos
                    ql2300
                    ql40xx
                    QWAVEdrv
                    rdpdr
                    restore
                    sbp2port
                    Serial
                    sermouse
                    sffdisk
                    sffp_mmc
                    sffp_sd
                    sfloppy
                    sisagp
                    SiSRaid2
                    SiSRaid4
                    Symc8xx
                    Sym_hi
                    Sym_u3
                    Tcpip6
                    TDPIPE
                    Trufos
                    uagp35
                    udfs
                    uliagpkx
                    uliahci
                    UlSata
                    ulsata2
                    usbcir
                    usbohci
                    usbprint
                    USBSTOR
                    vga
                    viaagp
                    ViaC7
                    viaide
                    vsmraid
                    WacomPen
                    Wanarp
                    Wd
                    WmiAcpi
                    WpdUsb
                    ws2ifsl
                    WUDFRd

                    [b]Services - Running[/b]:

                    aawservice
                    AeLookupSvc
                    AudioEndpointBuilder
                    Audiosrv
                    BFE
                    BITS
                    Browser
                    CertPropSvc
                    CryptSvc
                    DcomLaunch
                    Dhcp
                    Dnscache
                    DPS
                    EapHost
                    EMDMgmt
                    Eventlog
                    EventSystem
                    EvtEng
                    fdPHost
                    FDResPub
                    FTRTSVC
                    gpsvc
                    hidserv
                    hpqcxs08
                    hpqddsvc
                    IAANTMON
                    IKEEXT
                    iphlpsvc
                    KeyIso
                    KtmRm
                    LanmanServer
                    LanmanWorkstation
                    LIVESRV
                    lmhosts
                    MMCSS
                    MpsSvc
                    Netman
                    netprofm
                    NlaSvc
                    nsi
                    nvsvc
                    PcaSvc
                    PlugPlay
                    PnkBstrA
                    PolicyAgent
                    ProfSvc
                    RasMan
                    RegSrvc
                    RoxMediaDB9
                    RoxWatch9
                    RpcSs
                    SamSs
                    SBSDWSCService
                    Schedule
                    seclogon
                    SENS
                    SessionEnv
                    ShellHWDetection
                    slsvc
                    Spooler
                    SSDPSRV
                    stisvc
                    SysMain
                    TabletInputService
                    TapiSrv
                    TermService
                    Themes
                    TrkWks
                    TrustedInstaller
                    upnphost
                    usnjsvc
                    UxSms
                    VSSERV
                    W32Time
                    WdiSystemHost
                    WebClient
                    WerSvc
                    WinDefend
                    WinHttpAutoProxySvc
                    Winmgmt
                    Wlansvc
                    WPDBusEnum
                    wscsvc
                    WSearch
                    wuauserv
                    wudfsvc

                    [b]Services - Stopped[/b]:

                    ALG
                    Appinfo
                    Arrakis3
                    clr_optimization_v2.0.50727_32
                    COMSysApp
                    DFSR
                    dot3svc
                    ehRecvr
                    ehSched
                    ehstart
                    FCI
                    FontCache3.0.0.0
                    hkmsvc
                    ICF
                    IDriverT
                    idsvc
                    IPBusEnum
                    LBTServ
                    lltdsvc
                    maconfservice
                    Mcx2Svc
                    MSDTC
                    MSiSCSI
                    msiserver
                    napagent
                    Netlogon
                    NetTcpPortSharing
                    ose
                    p2pimsvc
                    p2psvc
                    pla
                    PNRPAutoReg
                    PNRPsvc
                    ProtectedStorage
                    QWAVE
                    RasAuto
                    RemoteAccess
                    RemoteRegistry
                    RichVideo
                    RpcLocator
                    scan
                    SCardSvr
                    SCPolicySvc
                    SDRSVC
                    SharedAccess
                    SLUINotify
                    SNMPTRAP
                    Start
                    Steam
                    stllssvr
                    swprv
                    Symantec
                    TBS
                    THREADORDER
                    UI0Detect
                    vds
                    VSS
                    wcncsvc
                    WcsPlugInService
                    WdiServiceHost
                    Wecsvc
                    wercplsupport
                    WinRM
                    WLSetupSvc
                    wmiApSrv
                    WMPNetworkSvc
                    WPCSvc

                    [b]Files Created/Modified - 60 Days[/b]:

                    C:\

                    3 Dec 2008 21:00:42 3 211 190 272 A.SH. "C:\hiberfil.sys"
                    3 Dec 2008 21:00:40 3 525 115 904 A.SH. "C:\pagefile.sys"

                    C:\Windows\

                    3 Dec 2008 21:00:46 67 584 A.S.. "C:\Windows\bootstat.dat"
                    3 Dec 2008 21:03:08 1 966 A.... "C:\Windows\default.htm"
                    30 Nov 2008 13:18:58 51 200 A.... "C:\Windows\inf\infpub.dat"
                    30 Nov 2008 13:18:58 86 016 A.... "C:\Windows\inf\infstor.dat"
                    30 Nov 2008 13:18:58 86 016 A.... "C:\Windows\inf\infstrng.dat"
                    23 Nov 2008 18:54:52 89 615 A.... "C:\Windows\System32\av.dat"
                    21 Oct 2008 6:16:22 1 645 568 A.... "C:\Windows\System32\connect.dll"
                    10 Oct 2008 4:52:38 2 036 576 A.... "C:\Windows\System32\D3DCompiler_40.dll"
                    10 Oct 2008 4:52:38 4 379 984 A.... "C:\Windows\System32\D3DX9_40.dll"
                    10 Oct 2008 4:52:38 452 440 A.... "C:\Windows\System32\d3dx10_40.dll"
                    21 Nov 2008 20:58:52 0 A.... "C:\Windows\System32\fci.exe.exe"
                    3 Dec 2008 18:57:54 437 296 A.... "C:\Windows\System32\FNTCACHE.DAT"
                    3 Dec 2008 21:00:56 14 848 A.... "C:\Windows\System32\getfn32.dll"
                    21 Nov 2008 20:58:28 0 A.... "C:\Windows\System32\icf.exe.exe"
                    10 Oct 2008 7:58:08 82 944 A.... "C:\Windows\System32\IEDFix.C.exe"
                    21 Nov 2008 21:09:52 0 A.... "C:\Windows\System32\mjwjmcu.dll"
                    3 Nov 2008 16:10:26 17 318 336 A.... "C:\Windows\System32\mrt.exe"
                    16 Oct 2008 5:40:38 425 472 A.... "C:\Windows\System32\netapi32.dll"
                    10 Oct 2008 7:58:08 82 944 A.... "C:\Windows\System32\o4Patch.exe"
                    23 Nov 2008 13:10:24 108 458 A.... "C:\Windows\System32\perfc009.dat"
                    23 Nov 2008 13:10:24 122 898 A.... "C:\Windows\System32\perfc00C.dat"
                    23 Nov 2008 13:10:24 621 374 A.... "C:\Windows\System32\perfh009.dat"
                    23 Nov 2008 13:10:24 702 978 A.... "C:\Windows\System32\perfh00C.dat"
                    23 Nov 2008 18:59:54 63 488 A.... "C:\Windows\System32\smwin32.dll"
                    26 Nov 2008 19:28:12 3 730 A.... "C:\Windows\System32\tmp.reg"
                    23 Nov 2008 16:58:40 192 512 A.... "C:\Windows\System32\txmlutil.dll"
                    23 Nov 2008 18:59:58 89 615 A.... "C:\Windows\System32\uesiuqcr.exe"
                    16 Oct 2008 22:12:20 561 688 A.... "C:\Windows\System32\wuapi.dll"
                    16 Oct 2008 13:56:04 31 232 A.... "C:\Windows\System32\wuapp.exe"
                    16 Oct 2008 22:09:44 51 224 A.... "C:\Windows\System32\wuauclt.exe"
                    16 Oct 2008 22:13:40 1 809 944 A.... "C:\Windows\System32\wuaueng.dll"
                    16 Oct 2008 21:56:30 1 524 736 A.... "C:\Windows\System32\wucltux.dll"
                    16 Oct 2008 21:56:00 83 456 A.... "C:\Windows\System32\wudriver.dll"
                    16 Oct 2008 22:08:58 34 328 A.... "C:\Windows\System32\wups.dll"
                    16 Oct 2008 22:09:44 43 544 A.... "C:\Windows\System32\wups2.dll"
                    16 Oct 2008 14:08:00 162 064 A.... "C:\Windows\System32\wuwebv.dll"
                    27 Oct 2008 10:04:16 23 376 A.... "C:\Windows\System32\X3DAudio1_5.dll"
                    27 Oct 2008 10:04:16 235 856 A.... "C:\Windows\System32\xactengine3_3.dll"
                    27 Oct 2008 10:04:14 70 992 A.... "C:\Windows\System32\XAPOFX1_2.dll"
                    27 Oct 2008 10:04:18 514 384 A.... "C:\Windows\System32\XAudio2_3.dll"
                    3 Dec 2008 21:01:00 6 A..H. "C:\Windows\Tasks\SA.DAT"
                    3 Dec 2008 20:48:54 0 A.... "C:\Windows\Temp\JET8499.tmp"
                    3 Dec 2008 21:01:48 0 A.... "C:\Windows\Temp\JET8564.tmp"
                    3 Dec 2008 18:57:52 0 A.... "C:\Windows\Temp\JET8D8F.tmp"
                    3 Dec 2008 18:54:12 0 A.... "C:\Windows\Temp\JETE6B5.tmp"
                    3 Dec 2008 20:53:18 0 A.... "C:\Windows\Temp\report.dat"
                    3 Dec 2008 20:53:20 0 A.... "C:\Windows\Temp\rtsr.dat"
                    3 Dec 2008 21:03:08 262 144 A.SH. "C:\Windows\ServiceProfiles\LocalService\ntuser.dat"
                    3 Dec 2008 21:03:02 262 144 A.SH. "C:\Windows\ServiceProfiles\NetworkService\ntuser.dat"
                    23 Nov 2008 16:56:52 111 112 A.... "C:\Windows\System32\drivers\bdfm.sys"
                    23 Nov 2008 16:58:38 104 328 A.... "C:\Windows\System32\drivers\bdfndisf.sys"
                    23 Nov 2008 16:56:50 230 920 A.... "C:\Windows\System32\drivers\bdfsfltr.sys"
                    23 Nov 2008 16:58:38 82 440 A.... "C:\Windows\System32\drivers\BDVEDISK.sys"
                    22 Oct 2008 16:10:22 15 504 A.... "C:\Windows\System32\drivers\mbam.sys"
                    22 Oct 2008 16:10:38 38 496 A.... "C:\Windows\System32\drivers\mbamswissarmy.sys"
                    16 Nov 2008 11:41:12 717 296 A.... "C:\Windows\System32\drivers\sptd.sys"
                    16 Nov 2008 11:41:38 1 148 A.... "C:\Windows\System32\WDI\ERCQueuedResolutions.dat"
                    14 Nov 2008 22:50:20 347 136 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.16757_none_95b104b9849fbbb3_dxtmsft.dll_4b67eac6"
                    14 Nov 2008 22:53:32 2 048 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6000.16745_none_8661c59c99cb7ce9_msxml3r.dll_d752d00e"
                    14 Nov 2008 22:50:20 64 512 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16757_none_ffd3a927a4cebb32_wininetplugin.dll_f2ff35f9"
                    14 Nov 2008 22:50:18 180 736 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.16757_none_628d2249b11ab295_ieui.dll_f0fcf806"
                    14 Nov 2008 22:50:18 3 593 216 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16757_none_112dc84625252468_mshtml.dll_fab8f891"
                    14 Nov 2008 22:50:20 124 928 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-advpack_31bf3856ad364e35_6.0.6000.16757_none_a9b61b23f5cc373c_advpack.dll_8c6ea088"
                    14 Nov 2008 22:53:44 2 027 520 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-win32k_31bf3856ad364e35_6.0.6000.16754_none_b6db2e869d852707_win32k.sys_0d7a6fb3"
                    14 Nov 2008 22:50:20 826 368 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16757_none_ffd3a927a4cebb32_wininet.dll_790e2e3a"
                    14 Nov 2008 22:53:32 1 194 496 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-msxml30_31bf3856ad364e35_6.0.6000.16745_none_8661c59c99cb7ce9_msxml3.dll_eaee1698"
                    14 Nov 2008 22:50:20 214 528 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-ie-directxtransforms_31bf3856ad364e35_6.0.6000.16757_none_95b104b9849fbbb3_dxtrans.dll_814d2aee"
                    14 Nov 2008 22:50:18 6 066 176 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.16757_none_628d2249b11ab295_ieframe.dll_c6cbe33f"
                    14 Nov 2008 22:53:20 425 472 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-netapi32_31bf3856ad364e35_6.0.6000.16764_none_8b10fff30496576a_netapi32.dll_8b1e859a"
                    14 Nov 2008 22:50:40 1 341 440 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6000.16747_none_866381d899c9fc7a_msxml6.dll_ebe15265"
                    14 Nov 2008 22:50:40 2 048 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-msxml60_31bf3856ad364e35_6.0.6000.16747_none_866381d899c9fc7a_msxml6r.dll_d8460bdb"
                    14 Nov 2008 22:50:54 3 470 904 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16754_none_6a18166cb7216faf_ntoskrnl.exe_0fb0ab79"
                    14 Nov 2008 22:50:20 27 648 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16757_none_ffd3a927a4cebb32_jsproxy.dll_3cc8d651"
                    14 Nov 2008 22:50:54 3 505 208 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-os-kernel_31bf3856ad364e35_6.0.6000.16754_none_6a18166cb7216faf_ntkrnlpa.exe_165c312a"
                    14 Nov 2008 22:50:20 1 159 680 A.... "C:\Windows\winsxs\Backup\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.16757_none_b2cdcd85d9c5949f_urlmon.dll_95c89473"
                    16 Oct 2008 5:38:28 466 944 A.... "C:\Windows\winsxs\x86_microsoft-windows-netapi32_31bf3856ad364e35_6.0.6001.22288_none_8d6f3cb41ae72563\netapi32.dll"
                    16 Oct 2008 21:56:30 1 524 736 A.... "C:\Windows\winsxs\x86_microsoft-windows-windowsupdateclient-ui_31bf3856ad364e35_7.2.6001.788_none_a8125d5406872725\wucltux.dll"
                    16 Oct 2008 5:47:34 466 944 A.... "C:\Windows\winsxs\x86_microsoft-windows-netapi32_31bf3856ad364e35_6.0.6001.18157_none_8d050f6301b2186f\netapi32.dll"
                    16 Oct 2008 5:22:28 425 984 A.... "C:\Windows\winsxs\x86_microsoft-windows-netapi32_31bf3856ad364e35_6.0.6000.20937_none_8bbe0f461d98ec8d\netapi32.dll"
                    21 Oct 2008 6:25:18 1 645 568 A.... "C:\Windows\winsxs\x86_microsoft-windows-getconnectedwizards_31bf3856ad364e35_6.0.6001.18159_none_64e182cb96dae69e\connect.dll"
                    22 Oct 2008 4:34:56 160 768 A.... "C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6001.22292_none_4b2b163f056ebb45\PortableDeviceTypes.dll"
                    22 Oct 2008 4:34:56 94 720 A.... "C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6001.22292_none_4b2b163f056ebb45\PortableDeviceClassExtension.dll"
                    22 Oct 2008 4:34:56 241 152 A.... "C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6001.22292_none_4b2b163f056ebb45\PortableDeviceApi.dll"
                    22 Oct 2008 4:43:52 160 768 A.... "C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6000.16767_none_48e0ac03ef0db56a\PortableDeviceTypes.dll"
                    22 Oct 2008 4:43:52 95 232 A.... "C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6000.16767_none_48e0ac03ef0db56a\PortableDeviceClassExtension.dll"
                    22 Oct 2008 4:43:52 241 152 A.... "C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6000.16767_none_48e0ac03ef0db56a\PortableDeviceApi.dll"
                    16 Oct 2008 13:56:04 31 232 A.... "C:\Windows\winsxs\x86_microsoft-windows-w..pdateclient-activex_31bf3856ad364e35_7.2.6001.788_none_ba8134361ffa6f73\wuapp.exe"
                    16 Oct 2008 14:08:00 162 064 A.... "C:\Windows\winsxs\x86_microsoft-windows-w..pdateclient-activex_31bf3856ad364e35_7.2.6001.788_none_ba8134361ffa6f73\wuwebv.dll"
                    2 Dec 2008 22:10:22 224 768 A.... "C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91\msvcm90.dll"
                    2 Dec 2008 22:10:22 568 832 A.... "C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91\msvcp90.dll"
                    2 Dec 2008 22:10:22 655 872 A.... "C:\Windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.21022.8_none_bcb86ed6ac711f91\msvcr90.dll"
                    16 Oct 2008 22:12:20 561 688 A.... "C:\Windows\winsxs\x86_microsoft-windows-w..owsupdateclient-aux_31bf3856ad364e35_7.2.6001.788_none_107673f57a433d77\wuapi.dll"
                    16 Oct 2008 21:56:00 83 456 A.... "C:\Windows\winsxs\x86_microsoft-windows-w..owsupdateclient-aux_31bf3856ad364e35_7.2.6001.788_none_107673f57a433d77\wudriver.dll"
                    16 Oct 2008 22:08:58 34 328 A.... "C:\Windows\winsxs\x86_microsoft-windows-w..owsupdateclient-aux_31bf3856ad364e35_7.2.6001.788_none_107673f57a433d77\wups.dll"
                    16 Oct 2008 22:09:44 51 224 A.... "C:\Windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.2.6001.788_none_2a6539a96682e474\wuauclt.exe"
                    16 Oct 2008 22:13:40 1 809 944 A.... "C:\Windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.2.6001.788_none_2a6539a96682e474\wuaueng.dll"
                    16 Oct 2008 22:09:44 43 544 A.... "C:\Windows\winsxs\x86_microsoft-windows-w..wsupdateclient-core_31bf3856ad364e35_7.2.6001.788_none_2a6539a96682e474\wups2.dll"
                    21 Oct 2008 6:16:22 1 645 568 A.... "C:\Windows\winsxs\x86_microsoft-windows-getconnectedwizards_31bf3856ad364e35_6.0.6000.16766_none_62ed735b99bf2599\connect.dll"
                    22 Oct 2008 4:39:44 160 768 A.... "C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6000.20941_none_4979e8d10820826f\PortableDeviceTypes.dll"
                    22 Oct 2008 4:39:44 95 232 A.... "C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6000.20941_none_4979e8d10820826f\PortableDeviceClassExtension.dll"
                    22 Oct 2008 4:39:44 241 152 A.... "C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6000.20941_none_4979e8d10820826f\PortableDeviceApi.dll"
                    22 Oct 2008 4:57:32 241 152 A.... "C:\Windows\winsxs\x86_microsoft-windows-wpd-portabledeviceapi_31bf3856ad364e35_6.0.6001.18160_none_4abfe8a3ec3a94fa\PortableDeviceApi.dll"
                    21 Oct 2008 6:06:54 1 645 568 A.... "C:\Windows\winsxs\x86_microsoft-windows-getconnectedwizards_31bf3856ad364e35_6.0.6000.20940_none_6386b028b2d1f29e\connect.dll"
                    16 Oct 2008 5:40:38 425 472 A.... "C:\Windows\winsxs\x86_microsoft-windows-netapi32_31bf3856ad364e35_6.0.6000.16764_none_8b10fff30496576a\netapi32.dll"
                    14 Nov 2008 22:51:10 1 286 152 A.... "C:\Windows\winsxs\x86_microsoft.msxml2_6bd6b9abf345378f_4.20.9870.0_none_b7e00e6c7b30b69b\msxml4.dll"
                    21 Oct 2008 6:21:44 1 645 568 A.... "C:\Windows\winsxs\x86_microsoft-windows-getconnectedwizards_31bf3856ad364e35_6.0.6001.22291_none_6537dd96b0202b74\connect.dll"
                    14 Nov 2008 22:51:20 105 480 A.... "C:\Windows\winsxs\x86_microsoft.msxml2r_6bd6b9abf345378f_4.1.1.0_none_365945b9da656e4d\msxml4r.dll"
                    3 Dec 2008 21:00:48 2 048 A.SH. "C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat"
                    3 Dec 2008 21:00:48 2 048 A.SH. "C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat"
                    2 Dec 2008 22:51:28 6 291 456 A.... "C:\Windows\System32\SMI\Store\Machine\schema.dat"
                    26 Nov 2008 0:02:36 524 288 A.SH. "C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
                    3 Dec 2008 20:46:44 0 A.... "C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC6057.tmp"
                    3 Dec 2008 20:53:18 0 A.... "C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RAC888F.tmp"
                    3 Dec 2008 20:43:16 0 A.... "C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\RACD0C.tmp"

                    C:\Program Files\

                    30 Nov 2008 19:10:52 24 637 A.... "C:\Program Files\Free Audio Pack\unins000.dat"
                    30 Nov 2008 19:10:00 694 800 A.... "C:\Program Files\Free Audio Pack\unins000.exe"
                    22 Oct 2008 16:10:20 378 344 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbam-dor.exe"
                    22 Oct 2008 16:10:18 65 168 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbam.dll"
                    22 Oct 2008 16:10:20 1 261 200 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe"
                    22 Oct 2008 16:10:22 73 360 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll"
                    22 Oct 2008 16:10:24 399 504 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe"
                    22 Oct 2008 16:10:24 170 640 A.... "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe"
                    22 Oct 2008 16:10:26 44 688 A.... "C:\Program Files\Malwarebytes' Anti-Malware\ssubtmr6.dll"
                    30 Nov 2008 12:23:16 8 192 A.... "C:\Program Files\Malwarebytes' Anti-Malware\unins000.dat"
                    30 Nov 2008 12:23:02 688 784 A.... "C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
                    22 Oct 2008 16:10:36 77 968 A.... "C:\Program Files\Malwarebytes' Anti-Malware\zlib.dll"
                    16 Nov 2008 11:32:00 17 408 A.... "C:\Program Files\Mozilla Firefox\AccessibleMarshal.dll"
                    16 Nov 2008 11:32:00 185 856 A.... "C:\Program Files\Mozilla Firefox\crashreporter.exe"
                    16 Nov 2008 11:32:02 307 712 A.... "C:\Program Files\Mozilla Firefox\firefox.exe"
                    16 Nov 2008 11:32:02 233 472 A.... "C:\Program Files\Mozilla Firefox\freebl3.dll"
                    16 Nov 2008 11:32:02 697 344 A.... "C:\Program Files\Mozilla Firefox\js3250.dll"
                    16 Nov 2008 11:32:02 710 144 A.... "C:\Program Files\Mozilla Firefox\mozcrt19.dll"
                    16 Nov 2008 11:32:02 198 144 A.... "C:\Program Files\Mozilla Firefox\nspr4.dll"
                    16 Nov 2008 11:32:02 697 856 A.... "C:\Program Files\Mozilla Firefox\nss3.dll"
                    16 Nov 2008 11:32:02 304 640 A.... "C:\Program Files\Mozilla Firefox\nssckbi.dll"
                    16 Nov 2008 11:32:02 103 936 A.... "C:\Program Files\Mozilla Firefox\nssdbm3.dll"
                    16 Nov 2008 11:32:02 87 552 A.... "C:\Program Files\Mozilla Firefox\nssutil3.dll"
                    16 Nov 2008 11:32:02 20 480 A.... "C:\Program Files\Mozilla Firefox\plc4.dll"
                    16 Nov 2008 11:32:02 17 408 A.... "C:\Program Files\Mozilla Firefox\plds4.dll"
                    16 Nov 2008 11:32:02 103 936 A.... "C:\Program Files\Mozilla Firefox\smime3.dll"
                    16 Nov 2008 11:32:02 151 552 A.... "C:\Program Files\Mozilla Firefox\softokn3.dll"
                    16 Nov 2008 11:32:02 395 776 A.... "C:\Program Files\Mozilla Firefox\sqlite3.dll"
                    16 Nov 2008 11:32:02 136 704 A.... "C:\Program Files\Mozilla Firefox\ssl3.dll"
                    16 Nov 2008 11:32:02 242 176 A.... "C:\Program Files\Mozilla Firefox\updater.exe"
                    16 Nov 2008 11:32:02 17 920 A.... "C:\Program Files\Mozilla Firefox\xpcom.dll"
                    16 Nov 2008 11:32:02 9 729 536 A.... "C:\Program Files\Mozilla Firefox\xul.dll"
                    30 Nov 2008 13:36:18 21 590 A.... "C:\Program Files\Spybot - Search & Destroy\unins000.dat"
                    30 Nov 2008 13:35:18 692 104 A.... "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
                    18 Nov 2008 18:17:10 122 864 A.... "C:\Program Files\Steam\CSERHelper.dll"
                    18 Nov 2008 18:17:08 1 039 192 A.... "C:\Program Files\Steam\dbghelp.dll"
                    18 Nov 2008 18:17:10 238 840 A.... "C:\Program Files\Steam\GameOverlayRenderer.dll"
                    18 Nov 2008 18:17:10 1 008 888 A.... "C:\Program Files\Steam\GameOverlayUI.exe"
                    18 Nov 2008 18:17:10 551 408 A.... "C:\Program Files\Steam\mss32_s.dll"
                    18 Nov 2008 18:17:08 3 069 176 A.... "C:\Program Files\Steam\Steam.dll"
                    18 Nov 2008 18:16:14 1 410 296 A.... "C:\Program Files\Steam\steam.exe"
                    18 Nov 2008 18:17:10 2 647 008 A.... "C:\Program Files\Steam\steamclient.dll"
                    18 Nov 2008 18:17:08 2 942 200 A.... "C:\Program Files\Steam\SteamUI.dll"
                    18 Nov 2008 18:17:10 238 840 A.... "C:\Program Files\Steam\tier0_s.dll"
                    18 Nov 2008 18:17:10 365 816 A.... "C:\Program Files\Steam\vstdlib_s.dll"
                    18 Nov 2008 18:17:08 256 496 A.... "C:\Program Files\Steam\WriteMiniDump.exe"
                    23 Nov 2008 16:56:54 245 760 A.... "C:\Program Files\BitDefender\BitDefender 2009\About.exe"
                    23 Nov 2008 16:56:50 45 056 A.... "C:\Program Files\BitDefender\BitDefender 2009\actxcont.dll"
                    23 Nov 2008 16:56:50 106 496 A.... "C:\Program Files\BitDefender\BitDefender 2009\advanced.dll"
                    23 Nov 2008 16:57:40 163 840 A.... "C:\Program Files\BitDefender\BitDefender 2009\agentreg.dll"
                    23 Nov 2008 16:57:40 139 264 A.... "C:\Program Files\BitDefender\BitDefender 2009\antispam.dll"
                    23 Nov 2008 16:57:00 37 376 A.... "C:\Program Files\BitDefender\BitDefender 2009\antispy.dll"
                    23 Nov 2008 16:56:50 34 304 A.... "C:\Program Files\BitDefender\BitDefender 2009\antivirus.dll"
                    23 Nov 2008 16:57:54 9 728 A.... "C:\Program Files\BitDefender\BitDefender 2009\asfn.dll"
                    23 Nov 2008 16:57:56 114 688 A.... "C:\Program Files\BitDefender\BitDefender 2009\ashield.dll"
                    23 Nov 2008 16:57:56 258 048 A.... "C:\Program Files\BitDefender\BitDefender 2009\backup.dll"
                    23 Nov 2008 16:57:58 741 376 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
                    23 Nov 2008 16:56:36 61 440 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdapupck.dll"
                    23 Nov 2008 16:57:04 24 576 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdch.dll"
                    23 Nov 2008 16:57:08 139 264 A.... "C:\Program Files\BitDefender\BitDefender 2009\BDChartActiveX.dll"
                    23 Nov 2008 16:56:58 155 648 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdelev.dll"
                    23 Nov 2008 16:56:36 98 304 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdfdrvi.dll"
                    23 Nov 2008 16:56:52 111 112 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdfm.sys"
                    23 Nov 2008 16:56:48 230 920 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdfsfltr.sys"
                    23 Nov 2008 16:56:38 266 240 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdfvcl.exe"
                    23 Nov 2008 16:56:48 335 360 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdfvconp.dll"
                    23 Nov 2008 16:57:04 134 656 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdfvsctx.dll"
                    23 Nov 2008 16:56:48 29 184 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdfvsecp.dll"
                    23 Nov 2008 16:56:56 716 800 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdfvwiz.exe"
                    23 Nov 2008 16:56:42 909 312 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdGUICtl.dll"
                    23 Nov 2008 16:57:08 69 632 A.... "C:\Program Files\BitDefender\BitDefender 2009\BDInProcPatch.exe"
                    23 Nov 2008 16:58:00 126 976 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdmcon.dll"
                    23 Nov 2008 16:57:08 8 192 A.... "C:\Program Files\BitDefender\BitDefender 2009\BDMsnScan.exe"
                    23 Nov 2008 16:56:44 348 160 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdo.dll"
                    23 Nov 2008 16:57:04 131 072 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdoe.dll"
                    23 Nov 2008 16:56:48 25 600 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdplugin.dll"
                    23 Nov 2008 16:58:00 86 016 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdpop3p.dll"
                    23 Nov 2008 16:56:44 26 112 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdpredir.dll"
                    23 Nov 2008 16:57:00 40 960 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdreinit.exe"
                    23 Nov 2008 16:56:48 151 552 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdshelxt.dll"
                    23 Nov 2008 16:58:00 86 016 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdsmtpp.dll"
                    23 Nov 2008 16:56:42 192 512 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdsubmit.dll"
                    23 Nov 2008 16:58:02 929 792 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdsubwiz.exe"
                    23 Nov 2008 16:58:04 332 288 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdthunderbird.exe"
                    23 Nov 2008 16:58:06 161 280 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdtkexec.exe"
                    23 Nov 2008 16:58:06 30 208 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdusers.dll"
                    23 Nov 2008 16:57:08 98 304 A.... "C:\Program Files\BitDefender\BitDefender 2009\BDUtils.dll"
                    23 Nov 2008 16:57:08 57 856 A.... "C:\Program Files\BitDefender\BitDefender 2009\BDVEDAPI.dll"
                    23 Nov 2008 16:57:10 82 440 A.... "C:\Program Files\BitDefender\BitDefender 2009\BDVEDISK.sys"
                    23 Nov 2008 16:57:10 57 344 A.... "C:\Program Files\BitDefender\BitDefender 2009\BDWizard.dll"
                    23 Nov 2008 16:58:10 847 872 A.... "C:\Program Files\BitDefender\BitDefender 2009\bdwizreg.exe"
                    23 Nov 2008 16:58:10 204 800 A.... "C:\Program Files\BitDefender\BitDefender 2009\bkpconp.dll"
                    23 Nov 2008 16:57:10 303 104 A.... "C:\Program Files\BitDefender\BitDefender 2009\BTCommon.dll"
                    23 Nov 2008 16:57:10 14 336 A.... "C:\Program Files\BitDefender\BitDefender 2009\BTCProxy.dll"
                    23 Nov 2008 16:58:10 236 A.... "C:\Program Files\BitDefender\BitDefender 2009\build.reg"
                    23 Nov 2008 16:58:12 241 664 A.... "C:\Program Files\BitDefender\BitDefender 2009\bwlist.dll"
                    23 Nov 2008 16:58:12 81 920 A.... "C:\Program Files\BitDefender\BitDefender 2009\bwlisttb.dll"
                    23 Nov 2008 16:58:12 24 064 A.... "C:\Program Files\BitDefender\BitDefender 2009\cleanIELow.exe"
                    23 Nov 2008 16:57:12 7 680 A.... "C:\Program Files\BitDefender\BitDefender 2009\CleanupMidas.exe"
                    23 Nov 2008 16:57:04 122 880 A.... "C:\Program Files\BitDefender\BitDefender 2009\Cookie.dll"
                    23 Nov 2008 16:56:54 208 896 A.... "C:\Program Files\BitDefender\BitDefender 2009\Dashboard.dll"
                    23 Nov 2008 16:58:16 73 728 A.... "C:\Program Files\BitDefender\BitDefender 2009\dbokf.dll"
                    23 Nov 2008 16:58:16 49 152 A.... "C:\Program Files\BitDefender\BitDefender 2009\dbokfui.dll"
                    23 Nov 2008 16:56:36 25 088 A.... "C:\Program Files\BitDefender\BitDefender 2009\encryption.dll"
                    23 Nov 2008 16:56:40 278 528 A.... "C:\Program Files\BitDefender\BitDefender 2009\Exclude.dll"
                    23 Nov 2008 16:56:54 167 936 A.... "C:\Program Files\BitDefender\BitDefender 2009\ExcMgr.dll"
                    23 Nov 2008 16:57:12 39 424 A.... "C:\Program Files\BitDefender\BitDefender 2009\FFComm.dll"
                    23 Nov 2008 16:56:52 58 880 A.... "C:\Program Files\BitDefender\BitDefender 2009\fshredctx.dll"
                    23 Nov 2008 16:58:18 376 832 A.... "C:\Program Files\BitDefender\BitDefender 2009\fwgui.dll"
                    23 Nov 2008 16:56:36 25 600 A.... "C:\Program Files\BitDefender\BitDefender 2009\general.dll"
                    23 Nov 2008 16:57:32 389 120 A.... "C:\Program Files\BitDefender\BitDefender 2009\History.exe"
                    23 Nov 2008 16:56:48 122 880 A.... "C:\Program Files\BitDefender\BitDefender 2009\hmcore.dll"
                    23 Nov 2008 16:57:30 765 952 A.... "C:\Program Files\BitDefender\BitDefender 2009\HMPlugin.dll"
                    23 Nov 2008 16:56:50 77 824 A.... "C:\Program Files\BitDefender\BitDefender 2009\htmlpack.dll"
                    23 Nov 2008 16:56:42 86 016 A.... "C:\Program Files\BitDefender\BitDefender 2009\httproxy.dll"
                    23 Nov 2008 16:57:32 69 632 A.... "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
                    23 Nov 2008 16:57:34 90 112 A.... "C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll"
                    23 Nov 2008 16:57:34 61 440 A.... "C:\Program Files\BitDefender\BitDefender 2009\IMEncUI.dll"
                    23 Nov 2008 16:56:56 143 360 A.... "C:\Program Files\BitDefender\BitDefender 2009\imguimsn.dll"
                    23 Nov 2008 16:56:46 143 360 A.... "C:\Program Files\BitDefender\BitDefender 2009\imguiym.dll"
                    23 Nov 2008 16:58:18 262 144 A.... "C:\Program Files\BitDefender\BitDefender 2009\issues.dll"
                    23 Nov 2008 16:56:38 11 776 A.... "C:\Program Files\BitDefender\BitDefender 2009\JsRcGen.exe"
                    23 Nov 2008 16:58:20 188 416 A.... "C:\Program Files\BitDefender\BitDefender 2009\live.dll"
                    23 Nov 2008 16:56:46 122 880 A.... "C:\Program Files\BitDefender\BitDefender 2009\midascomm.dll"
                    23 Nov 2008 16:56:44 86 016 A.... "C:\Program Files\BitDefender\BitDefender 2009\MsnDll.dll"
                    23 Nov 2008 16:57:06 53 248 A.... "C:\Program Files\BitDefender\BitDefender 2009\nag.dll"
                    23 Nov 2008 16:56:40 40 960 A.... "C:\Program Files\BitDefender\BitDefender 2009\npcomm.dll"
                    23 Nov 2008 16:56:50 376 832 A.... "C:\Program Files\BitDefender\BitDefender 2009\ODSW.exe"
                    23 Nov 2008 16:56:52 18 944 A.... "C:\Program Files\BitDefender\BitDefender 2009\OnlineSupport.dll"
                    23 Nov 2008 16:58:22 397 312 A.... "C:\Program Files\BitDefender\BitDefender 2009\pcontrol.dll"
                    23 Nov 2008 16:58:22 1 004 A.... "C:\Program Files\BitDefender\BitDefender 2009\phishingrsp.htm"
                    23 Nov 2008 16:58:22 274 432 A.... "C:\Program Files\BitDefender\BitDefender 2009\popup.dll"
                    23 Nov 2008 16:56:42 278 528 A.... "C:\Program Files\BitDefender\BitDefender 2009\privintf.dll"
                    23 Nov 2008 16:56:58 192 512 A.... "C:\Program Files\BitDefender\BitDefender 2009\privscan.dll"
                    23 Nov 2008 16:57:36 249 856 A.... "C:\Program Files\BitDefender\BitDefender 2009\ProductTweaksPlugin.dll"
                    23 Nov 2008 16:57:34 34 304 A.... "C:\Program Files\BitDefender\BitDefender 2009\ProductInfo.dll"
                    23 Nov 2008 16:56:46 53 760 A.... "C:\Program Files\BitDefender\BitDefender 2009\proxymgr.dll"
                    23 Nov 2008 16:56:44 73 728 A.... "C:\Program Files\BitDefender\BitDefender 2009\proxymgrui.dll"
                    23 Nov 2008 16:57:00 86 016 A.... "C:\Program Files\BitDefender\BitDefender 2009\quarcore.dll"
                    23 Nov 2008 16:57:04 86 016 A.... "C:\Program Files\BitDefender\BitDefender 2009\quarmgr.dll"
                    23 Nov 2008 16:56:54 122 880 A.... "C:\Program Files\BitDefender\BitDefender 2009\quarui.dll"
                    23 Nov 2008 16:56:50 49 152 A.... "C:\Program Files\BitDefender\BitDefender 2009\reginfo.dll"
                    23 Nov 2008 16:57:36 106 496 A.... "C:\Program Files\BitDefender\BitDefender 2009\Registry.dll"
                    23 Nov 2008 16:56:36 25 600 A.... "C:\Program Files\BitDefender\BitDefender 2009\reg_sup.dll"
                    23 Nov 2008 16:56:52 98 304 A.... "C:\Program Files\BitDefender\BitDefender 2009\sch_serv.dll"
                    23 Nov 2008 16:57:36 118 784 A.... "C:\Program Files\BitDefender\BitDefender 2009\Script.dll"
                    23 Nov 2008 16:58:26 413 696 A.... "C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe"
                    23 Nov 2008 16:56:58 65 536 A.... "C:\Program Files\BitDefender\BitDefender 2009\security.dll"
                    23 Nov 2008 16:58:26 8 192 A.... "C:\Program Files\BitDefender\BitDefender 2009\signcheck.exe"
                    23 Nov 2008 16:58:26 382 A.... "C:\Program Files\BitDefender\BitDefender 2009\support.reg"
                    23 Nov 2008 16:56:36 225 280 A.... "C:\Program Files\BitDefender\BitDefender 2009\sysinfo.dll"
                    23 Nov 2008 16:56:42 65 536 A.... "C:\Program Files\BitDefender\BitDefender 2009\taskWizard.dll"
                    23 Nov 2008 16:58:32 1 171 456 A.... "C:\Program Files\BitDefender\BitDefender 2009\tuneup.dll"
                    23 Nov 2008 16:58:32 65 536 A.... "C:\Program Files\BitDefender\BitDefender 2009\tuneupconp.dll"
                    23 Nov 2008 16:58:32 86 016 A.... "C:\Program Files\BitDefender\BitDefender 2009\txmlx.dll"
                    23 Nov 2008 16:58:34 618 496 A.... "C:\Program Files\BitDefender\BitDefender 2009\uiscan.exe"
                    23 Nov 2008 16:58:34 393 216 A.... "C:\Program Files\BitDefender\BitDefender 2009\vscan.dll"
                    23 Nov 2008 16:57:06 278 528 A.... "C:\Program Files\BitDefender\BitDefender 2009\vshield.dll"
                    23 Nov 2008 16:58:36 14 848 A.... "C:\Program Files\BitDefender\BitDefender 2009\vshieldpatch.exe"
                    23 Nov 2008 16:58:38 1 572 864 A.... "C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe"
                    23 Nov 2008 16:56:44 651 264 A.... "C:\Program Files\BitDefender\BitDefender 2009\vswizard.dll"
                    23 Nov 2008 16:57:00 77 824 A.... "C:\Program Files\BitDefender\BitDefender 2009\Vulnerability.dll"
                    23 Nov 2008 16:56:58 577 536 A.... "C:\Program Files\BitDefender\BitDefender 2009\wizards.dll"
                    23 Nov 2008 16:56:36 35 328 A.... "C:\Program Files\BitDefender\BitDefender 2009\wsc.dll"
                    23 Nov 2008 16:56:46 7 680 A.... "C:\Program Files\BitDefender\BitDefender 2009\wscfxas.exe"
                    23 Nov 2008 16:56:52 7 680 A.... "C:\Program Files\BitDefender\BitDefender 2009\wscfxav.exe"
                    23 Nov 2008 16:57:02 7 680 A.... "C:\Program Files\BitDefender\BitDefender 2009\wscfxfw.exe"
                    23 Nov 2008 16:56:40 65 536 A.... "C:\Program Files\BitDefender\BitDefender 2009\WSID.dll"
                    23 Nov 2008 16:56:40 634 880 A.... "C:\Program Files\BitDefender\BitDefender 2009\WSLib.dll"
                    23 Nov 2008 16:57:02 94 208 A.... "C:\Program Files\BitDefender\BitDefender 2009\WSPack.dll"
                    23 Nov 2008 16:57:38 98 304 A.... "C:\Program Files\BitDefender\BitDefender 2009\YCryptp.dll"
                    18 Nov 2008 18:17:08 104 944 A.... "C:\Program Files\Common Files\Steam\SteamService.exe"
                    18 Nov 2008 18:17:08 104 944 A.... "C:\Program Files\Common Files\Steam\SteamServiceTmp.exe"
                    20 Nov 2008 18:21:42 352 032 A.... "C:\Program Files\Free Audio Pack\Easy Audio Cutter\AudioCutter.exe"
                    23 Oct 2008 23:12:58 2 818 048 A.... "C:\Program Files\Free Audio Pack\Free CD Ripper\FreeCDRipper.exe"
                    20 Nov 2008 18:12:20 719 104 A.... "C:\Program Files\Free Audio Pack\FreeConverter\FreeConverter.exe"
                    6 Oct 2008 9:52:34 3 610 424 A.... "C:\Program Files\Microsoft Office\OFFICE11\OUTLFLTR.DAT"
                    16 Nov 2008 11:32:00 23 040 A.... "C:\Program Files\Mozilla Firefox\components\browserdirprovider.dll"
                    16 Nov 2008 11:32:00 134 656 A.... "C:\Program Files\Mozilla Firefox\components\brwsrcmp.dll"
                    28 Nov 2008 18:49:56 144 759 A.... "C:\Program Files\Mozilla Firefox\components\compreg.dat"
                    23 Nov 2008 16:57:12 39 424 A.... "C:\Program Files\Mozilla Firefox\components\FFComm.dll"
                    28 Nov 2008 18:49:54 98 222 A.... "C:\Program Files\Mozilla Firefox\components\xpti.dat"
                    16 Nov 2008 11:32:02 65 536 A.... "C:\Program Files\Mozilla Firefox\plugins\npnul32.dll"
                    16 Nov 2008 11:32:02 510 600 A.... "C:\Program Files\Mozilla Firefox\uninstall\helper.exe"
                    19 Nov 2008 20:38:58 68 723 A.... "C:\Program Files\SafeSoft\Chaos Shredder\uninst.exe"
                    18 Nov 2008 18:17:08 206 072 A.... "C:\Program Files\Steam\bin\FileSystem_Steam.dll"
                    18 Nov 2008 18:17:08 1 271 032 A.... "C:\Program Files\Steam\bin\friendsUI.dll"
                    18 Nov 2008 18:17:08 161 016 A.... "C:\Program Files\Steam\bin\installscript.dll"
                    18 Nov 2008 18:17:08 546 040 A.... "C:\Program Files\Steam\bin\mss32_s.dll"
                    18 Nov 2008 18:17:08 831 208 A.... "C:\Program Files\Steam\bin\nattypeprobe.dll"
                    18 Nov 2008 18:17:08 5 288 928 A.... "C:\Program Files\Steam\bin\p2pcore.dll"
                    18 Nov 2008 18:17:08 1 185 016 A.... "C:\Program Files\Steam\bin\p2pvoice.dll"
                    18 Nov 2008 18:17:08 931 064 A.... "C:\Program Files\Steam\bin\ServerBrowser.dll"
                    18 Nov 2008 18:17:08 653 808 A.... "C:\Program Files\Steam\bin\SteamService.dll"
                    18 Nov 2008 18:17:08 104 944 A.... "C:\Program Files\Steam\bin\SteamService.exe"
                    18 Nov 2008 18:17:08 197 880 A.... "C:\Program Files\Steam\bin\vaudio_speex.dll"
                    18 Nov 2008 18:17:08 464 120 A.... "C:\Program Files\Steam\bin\vgui2.dll"
                    18 Nov 2008 18:17:08 1 670 A.... "C:\Program Files\Steam\Public\Account.html"
                    18 Nov 2008 18:17:08 36 596 A.... "C:\Program Files\Steam\Public\ssa_english.htm"
                    18 Nov 2008 18:17:08 41 518 A.... "C:\Program Files\Steam\Public\ssa_french.htm"
                    18 Nov 2008 18:17:08 43 448 A.... "C:\Program Files\Steam\Public\ssa_german.htm"
                    18 Nov 2008 18:17:08 42 536 A.... "C:\Program Files\Steam\Public\ssa_italian.htm"
                    18 Nov 2008 18:17:08 68 253 A.... "C:\Program Files\Steam\Public\ssa_russian.htm"
                    18 Nov 2008 18:17:08 41 413 A.... "C:\Program Files\Steam\Public\ssa_spanish.htm"
                    23 Nov 2008 16:57:02 151 552 A.... "C:\Program Files\BitDefender\BitDefender 2009\as2core\as2core.dll"
                    23 Nov 2008 16:57:54 217 088 A.... "C:\Program Files\BitDefender\BitDefender 2009\as2core\asregex.dll"
                    23 Nov 2008 16:57:04 147 456 A.... "C:\Program Files\BitDefender\BitDefender 2009\as2core\mimepack.dll"
                    27 Nov 2008 23:18:04 82 808 A.... "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdaterInstallMgr.exe"
                    27 Nov 2008 23:18:14 2 356 088 A.... "C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
                    23 Nov 2008 16:56:22 94 208 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\bdardrv.dll"
                    23 Nov 2008 16:56:22 192 512 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\bdsubmit.dll"
                    23 Nov 2008 16:56:22 6 656 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.dll"
                    23 Nov 2008 16:56:22 13 056 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.sys"
                    23 Nov 2008 16:56:24 200 704 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\scan.dll"
                    23 Nov 2008 16:56:34 2 197 936 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\smartscn.dat"
                    23 Nov 2008 16:56:34 65 536 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\smartscn.dll"
                    23 Nov 2008 16:56:34 12 800 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\trufos.dll"
                    23 Nov 2008 16:58:44 24 576 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Update Service\bdch.dll"
                    23 Nov 2008 16:58:42 909 312 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Update Service\bdGUICtl.dll"
                    23 Nov 2008 16:58:42 192 512 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Update Service\bdsubmit.dll"
                    23 Nov 2008 16:58:46 929 792 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Update Service\bdsubwiz.exe"
                    23 Nov 2008 16:58:42 98 304 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Update Service\BDUtils.dll"
                    23 Nov 2008 16:58:44 401 408 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe"
                    23 Nov 2008 16:58:40 40 960 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Update Service\npcomm.dll"
                    23 Nov 2008 16:58:44 192 512 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Update Service\txmlutil.dll"
                    23 Nov 2008 16:58:44 139 264 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Update Service\upgrepl.exe"
                    23 Nov 2008 16:58:40 634 880 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Update Service\WSLib.dll"
                    23 Nov 2008 16:58:44 94 208 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Update Service\WSPack.dll"
                    23 Nov 2008 16:56:34 135 944 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Firewall\bdftdif.sys"
                    15 Nov 2008 14:29:34 121 152 ..... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\Uninstall_Football Manager 2009 Demo\Uninstall Football Manager 2009 Demo.exe"
                    23 Nov 2008 16:57:06 4 608 A.... "C:\Program Files\BitDefender\BitDefender 2009\Account\Trial\trial.html"
                    22 Nov 2008 17:17:36 0 A.... "C:\Program Files\BitDefender\BitDefender 2009\as2core\antispam_sig_16056\pcdic.dat"
                    22 Nov 2008 17:17:36 0 A.... "C:\Program Files\BitDefender\BitDefender 2009\as2core\antispam_sig_16057\pcdic.dat"
                    23 Nov 2008 16:56:06 143 360 A.... "C:\Program Files\BitDefender\BitDefender 2009\BitDefender InnerFire\midas32-v1_7\midas32.dll"
                    23 Nov 2008 16:56:06 57 344 A.... "C:\Program Files\BitDefender\BitDefender 2009\BitDefender InnerFire\midas32-v1_7\neurons.dll"
                    23 Nov 2008 16:55:46 53 248 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_8895\avxdisk.dll"
                    23 Nov 2008 16:55:48 102 400 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_8895\bdcore.dll"
                    3 Dec 2008 21:01:52 3 618 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_8895\plugins.htm"
                    23 Nov 2008 16:55:46 53 248 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_8894\avxdisk.dll"
                    23 Nov 2008 16:55:48 102 400 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_8894\bdcore.dll"
                    23 Nov 2008 18:55:00 3 618 A.... "C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\av32bit_8894\plugins.htm"
                    2 Dec 2008 22:13:46 1 A.... "C:\Program Files\OpenOffice.org 3\share\uno_packages\cache\stamp.sys"
                    15 Nov 2008 14:29:08 1 331 301 ..... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\jre\bin\awt.dll"
                    15 Nov 2008 14:29:14 143 462 ..... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\jre\bin\dcpr.dll"
                    15 Nov 2008 14:29:14 249 974 ..... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\jre\bin\fontmanager.dll"
                    15 Nov 2008 14:29:14 32 878 ..... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\jre\bin\hpi.dll"
                    15 Nov 2008 14:29:14 118 890 ..... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\jre\bin\java.dll"
                    15 Nov 2008 14:29:14 49 250 ..... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\jre\bin\javaw.exe"
                    15 Nov 2008 14:29:16 77 926 ..... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\jre\bin\net.dll"
                    15 Nov 2008 14:29:16 36 967 ..... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\jre\bin\nio.dll"
                    15 Nov 2008 14:29:18 49 252 ..... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\jre\bin\verify.dll"
                    15 Nov 2008 14:29:18 61 547 ..... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\jre\bin\zip.dll"
                    15 Nov 2008 14:29:34 71 168 ..... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\Uninstall_Football Manager 2009 Demo\resource\iawin32.dll"
                    15 Nov 2008 14:29:34 109 056 A.... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\Uninstall_Football Manager 2009 Demo\resource\remove.exe"
                    2 Dec 2008 22:10:28 0 A.... "C:\Program Files\OpenOffice.org 3\share\uno_packages\cache\uno_packages\C246.tmp"
                    2 Dec 2008 22:10:36 0 A.... "C:\Program Files\OpenOffice.org 3\share\uno_packages\cache\uno_packages\E263.tmp"
                    2 Dec 2008 22:10:36 0 A.... "C:\Program Files\OpenOffice.org 3\share\uno_packages\cache\uno_packages\E5FB.tmp"
                    15 Nov 2008 14:29:12 1 523 833 ..... "C:\Program Files\Sports Interactive\Football Manager 2009 Demo\jre\bin\client\jvm.dll"
                    2 Dec 2008 22:10:28 18 597 793 A.... "C:\Program Files\OpenOffice.org 3\share\uno_packages\cache\uno_packages\C246.tmp_\dict-en.oxt\th_en_US_v2.dat"
                    2 Dec 2008 22:10:36 4 506 346 A.... "C:\Program Files\OpenOffice.org 3\share\uno_packages\cache\uno_packages\E5FB.tmp_\dict-fr.oxt\th_fr_FR_v2.dat"

                    [b]Files with hidden attributes[/b]:

                    Thu 7 Aug 2008 1,024 A..H. --- "C:\diego\dummy.sys"
                    Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
                    Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
                    Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
                    Tue 18 Nov 2008 72,704 ..SHR --- "C:\RECYCLER\S-1-5-21-2543280688-2235057422-947018642-0300\winigon.exe"
                    Thu 2 Nov 2006 524,288 A.SH. --- "C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
                    Thu 2 Nov 2006 524,288 A.SH. --- "C:\Users\Default\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
                    Sun 15 Jun 2008 524,288 A.SH. --- "C:\Users\Gauthier\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
                    Mon 25 Feb 2008 524,288 A.SH. --- "C:\Users\Gauthier\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
                    Mon 24 Nov 2008 524,288 A.SH. --- "C:\Users\Gauthier\ntuser.dat{4279ff4f-ba60-11dd-89c3-001b24a350c6}.TMContainer00000000000000000001.regtrans-ms"
                    Mon 24 Nov 2008 524,288 A.SH. --- "C:\Users\Gauthier\ntuser.dat{4279ff4f-ba60-11dd-89c3-001b24a350c6}.TMContainer00000000000000000002.regtrans-ms"
                    Thu 7 Aug 2008 1,024 A..H. --- "C:\$Recycle.Bin\S-1-5-21-916745695-1501797539-4020289792-1002\$R5PQYXW\dummy.sys"
                    Thu 7 Aug 2008 1,024 A..H. --- "C:\$Recycle.Bin\S-1-5-21-916745695-1501797539-4020289792-1002\$RWKVGWB\dummy.sys"
                    Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
                    Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{3a539869-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
                    Sat 22 Mar 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{e2022792-f7f4-11dc-b785-00030d000001}.TMContainer00000000000000000001.regtrans-ms"
                    Sat 22 Mar 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{e2022792-f7f4-11dc-b785-00030d000001}.TMContainer00000000000000000002.regtrans-ms"
                    Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
                    Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{3a539865-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
                    Sat 22 Mar 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{e202278e-f7f4-11dc-b785-00030d000001}.TMContainer00000000000000000001.regtrans-ms"
                    Sat 22 Mar 2008 524,288 A.SH. --- "C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT{e202278e-f7f4-11dc-b785-00030d000001}.TMContainer00000000000000000002.regtrans-ms"
                    Sun 23 Nov 2008 5,629,208 A..H. --- "C:\Windows\SoftwareDistribution\Download\59b6efce37fc710d4834d009eab90c77\BIT5437.tmp"
                    Thu 11 Oct 2007 524,288 A.SH. --- "C:\Windows\System32\config\systemprofile\ntuser.dat{8aafc203-7820-11dc-a7d6-806e6f6e6963}.TMContainer00000000000000000001.regtrans-ms"
                    Thu 11 Oct 2007 524,288 A.SH. --- "C:\Windows\System32\config\systemprofile\ntuser.dat{8aafc203-7820-11dc-a7d6-806e6f6e6963}.TMContainer00000000000000000002.regtrans-ms"
                    Wed 3 Dec 2008 5,242,880 A.SH. --- "C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.2.regtrans-ms"
                    Fri 14 Nov 2008 524,288 A.SH. --- "C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000001.regtrans-ms"
                    Wed 10 Sep 2008 524,288 A.SH. --- "C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000002.regtrans-ms"
                    Thu 11 Sep 2008 5,242,880 A.SH. --- "C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.0.regtrans-ms"
                    Fri 14 Nov 2008 5,242,880 A.SH. --- "C:\Windows\System32\config\TxR\{250834b7-750c-494d-bdc3-da86b6e2101a}.TxR.1.regtrans-ms"
                    Fri 15 Aug 2008 524,288 A.SH. --- "C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000004.regtrans-ms"
                    Wed 3 Dec 2008 524,288 A.SH. --- "C:\Windows\System32\config\TxR\{250834B7-750C-494d-BDC3-DA86B6E2101B}.TMContainer00000000000000000003.regtrans-ms"
                    Wed 26 Nov 2008 524,288 A.SH. --- "C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms"
                    Thu 2 Nov 2006 524,288 A.SH. --- "C:\Windows\System32\SMI\Store\Machine\SCHEMA.DAT{3a53986d-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000002.regtrans-ms"
                    Mon 25 Feb 2008 524,288 A.SH. --- "C:\Users\Gauthier\AppData\Local\Microsoft\Windows\UsrClass.dat{2c53a35a-e3bb-11dc-97fd-00030d000001}.TMContainer00000000000000
                    0
                    1. Contributeur sécurité
                      Fais un clic droit sur SDFix => renommer
                      Nomme le comme tu veux ( diego par exemple ), démarre en MSE et essaye de le lancer
                      0
                      1. N'ayant pas reçu de réponse, j'ai essayer de me débrouiller par moi même, mais sans résultat....

                        Je sais que je suis infecté par Generic.Malwares, mais bitdefender ne parvient pas a le supprimer. Je suis également infecté par windows protection center, et les sites expliquant comment s'en débarrasser ne m'aident pas.

                        Je n'ai également plus accès au gestionnaire des taches.

                        Merci de bien vouloir m'aider :)
                        0
                        1. Comme pour SDFix ou Malwarebytes, je ne parviens pas a l'executer. Dois-je essayer en mode sans echec?
                          0
                          1. Contributeur sécurité
                            Télécharge combofix.exe (par sUBs) et sauvegarde le sur ton bureau.
                            http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                            * Déconnecte toi d'internet et ferme toutes tes applications.

                            * Désactive tes protections (antivirus, parefeu,antispyware) provisoirement et seulement le temps de l'utilisation de ComboFix,

                            * Double-clic sur combofix.exe, il est possible que ton parefeu te demande si tu acceptes ou non l'accès de nircmd.cfexe à la zone sûre: accepte.

                            * /!\ Ne touche à rien tant que le scan n'est pas terminé.Attention, n'utilise pas ta souris ni ton clavier (ni un autre système de pointage) pendant que le programme tourne /!\

                            * Attends que Combofix ait terminé, un rapport sera créé.

                            * réactive ton parefeu, ton antivirus, la garde de ton antispyware

                            * copie/colle le rapport, le rapport se trouve dans : C:Combofix.txt

                            * Réactive tes protections en temps réel, Antivirus, Antispywares, avant de te reconnecter à internet.
                            0
                            1. Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 20:11:16, on 26/11/2008
                              Platform: Windows Vista (WinNT 6.00.1904)
                              MSIE: Internet Explorer v7.00 (7.00.6000.16757)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\uesiuqcr.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              C:\Windows\system32\taskeng.exe
                              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                              C:\Program Files\Orange\Systray\SystrayApp.exe
                              C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                              C:\Windows\System32\rundll32.exe
                              C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                              C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\Logitech\SetPoint\SetPoint.exe
                              C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                              C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
                              C:\Program Files\Windows Sidebar\sidebar.exe
                              C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                              C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Windows\system32\wuauclt.exe
                              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
                              R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                              F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\system32\uesiuqcr.exe,
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: getfn32.msiets - {21A237A4-3A94-4198-911D-647ED2263DD2} - C:\Windows\system32\getfn32.dll
                              O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
                              O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
                              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                              O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
                              O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                              O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
                              O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
                              O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                              O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                              O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                              O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
                              O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
                              O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                              O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                              O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                              O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
                              O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
                              O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                              O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                              O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                              O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe (file missing)
                              O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                              O13 - Gopher Prefix:
                              O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                              O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                              O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                              O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
                              O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                              O23 - Service: FCI - Unknown owner - C:\Windows\system32\fci.exe.exe:ext.exe (file missing)
                              O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                              O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                              O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                              O23 - Service: ICF - Unknown owner - C:\Windows\system32\icf.exe.exe:ext.exe (file missing)
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                              O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
                              O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                              O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                              O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                              O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                              O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe (file missing)
                              O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                              O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                              O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                              O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
                              O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                              O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                              O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                              O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                              0
                              1. SmitFraudFix v2.378

                                Scan done at 19:26:50,20, 26/11/2008
                                Run from C:\SmitfraudFix
                                OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                                The filesystem type is
                                Fix run in safe mode

                                »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                                !!!Attention, following keys are not inevitably infected!!!

                                SrchSTS.exe by S!Ri
                                Search SharedTaskScheduler's .dll

                                »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                                »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                127.0.0.1 localhost
                                ::1 localhost
                                127.0.0.1 www.007guard.com
                                127.0.0.1 007guard.com
                                127.0.0.1 008i.com
                                127.0.0.1 www.008k.com
                                127.0.0.1 008k.com
                                127.0.0.1 www.00hq.com
                                127.0.0.1 00hq.com
                                127.0.0.1 010402.com
                                127.0.0.1 www.032439.com
                                127.0.0.1 032439.com
                                127.0.0.1 www.1001-search.info
                                127.0.0.1 1001-search.info
                                127.0.0.1 www.100888290cs.com
                                127.0.0.1 100888290cs.com
                                127.0.0.1 www.100sexlinks.com
                                127.0.0.1 100sexlinks.com
                                127.0.0.1 www.10sek.com
                                127.0.0.1 10sek.com
                                127.0.0.1 www.123topsearch.com
                                127.0.0.1 123topsearch.com
                                127.0.0.1 www.132.com
                                127.0.0.1 132.com
                                127.0.0.1 www.136136.net
                                127.0.0.1 136136.net
                                127.0.0.1 www.139mm.com
                                127.0.0.1 139mm.com
                                127.0.0.1 www.163ns.com
                                127.0.0.1 163ns.com
                                127.0.0.1 171203.com
                                127.0.0.1 17-plus.com
                                127.0.0.1 www.1800searchonline.com
                                127.0.0.1 1800searchonline.com
                                127.0.0.1 www.180searchassistant.com
                                127.0.0.1 180searchassistant.com
                                127.0.0.1 www.180solutions.com
                                127.0.0.1 180solutions.com
                                127.0.0.1 www.181.365soft.info
                                127.0.0.1 181.365soft.info
                                127.0.0.1 www.1987324.com
                                127.0.0.1 1987324.com
                                127.0.0.1 www.1-domains-registrations.com
                                127.0.0.1 1-domains-registrations.com
                                127.0.0.1 www.1-extreme.biz
                                127.0.0.1 1-extreme.biz
                                127.0.0.1 www.1sexparty.com
                                127.0.0.1 1sexparty.com
                                127.0.0.1 www.1stantivirus.com
                                127.0.0.1 1stantivirus.com
                                127.0.0.1 www.1stpagehere.com
                                127.0.0.1 1stpagehere.com
                                127.0.0.1 www.1stsearchportal.com
                                127.0.0.1 1stsearchportal.com
                                127.0.0.1 2.82211.net
                                127.0.0.1 www.2006ooo.com
                                127.0.0.1 2006ooo.com
                                127.0.0.1 www.2007-download.com
                                127.0.0.1 2007-download.com
                                127.0.0.1 www.2020search.com
                                127.0.0.1 2020search.com
                                127.0.0.1 20x2p.com
                                127.0.0.1 www.24.365soft.info
                                127.0.0.1 24.365soft.info
                                127.0.0.1 www.24-7pharmacy.info
                                127.0.0.1 24-7pharmacy.info
                                127.0.0.1 www.24-7searching-and-more.com
                                127.0.0.1 24-7searching-and-more.com
                                127.0.0.1 www.24teen.com
                                127.0.0.1 24teen.com
                                127.0.0.1 www.2every.net
                                127.0.0.1 2every.net
                                127.0.0.1 2ndpower.com
                                127.0.0.1 www.2search.com
                                127.0.0.1 2search.com
                                127.0.0.1 www.2search.org
                                127.0.0.1 2search.org
                                127.0.0.1 www.2squared.com
                                127.0.0.1 2squared.com
                                127.0.0.1 www.3322.org
                                127.0.0.1 3322.org
                                127.0.0.1 365soft.info
                                127.0.0.1 www.36site.com
                                127.0.0.1 36site.com
                                127.0.0.1 3721.com
                                127.0.0.1 39-93.com
                                127.0.0.1 www.3abetterinternet.com
                                127.0.0.1 3abetterinternet.com
                                127.0.0.1 www.3bay.it
                                127.0.0.1 3bay.it
                                127.0.0.1 www.3ebay.it
                                127.0.0.1 3ebay.it
                                127.0.0.1 www.3xclipsonline.com
                                127.0.0.1 3xclipsonline.com
                                127.0.0.1 www.3xcurves.com
                                127.0.0.1 3xcurves.com
                                127.0.0.1 www.3xfestival.com
                                127.0.0.1 3xfestival.com
                                127.0.0.1 www.3x-festival.com
                                127.0.0.1 3x-festival.com
                                127.0.0.1 www.3x-galls.com
                                127.0.0.1 3x-galls.com
                                127.0.0.1 www.3xmiracle.com
                                127.0.0.1 3xmiracle.com
                                127.0.0.1 www.3xmoviesblog.com
                                127.0.0.1 3xmoviesblog.com
                                127.0.0.1 www.404dns.com
                                127.0.0.1 404dns.com
                                127.0.0.1 www.4199.com
                                127.0.0.1 4199.com
                                127.0.0.1 www.4corn.net
                                127.0.0.1 4corn.net
                                127.0.0.1 www.4ebay.it
                                127.0.0.1 4ebay.it
                                127.0.0.1 4klm.com
                                127.0.0.1 www.4mpg.com
                                127.0.0.1 4mpg.com
                                127.0.0.1 www.4repubblica.it
                                127.0.0.1 4repubblica.it
                                127.0.0.1 www.4softget.com
                                127.0.0.1 4softget.com
                                127.0.0.1 www.5iscali.it
                                127.0.0.1 5iscali.it
                                127.0.0.1 www.5repubblica.it
                                127.0.0.1 5repubblica.it
                                127.0.0.1 www.5starvideos.com
                                127.0.0.1 5starvideos.com
                                127.0.0.1 www.5tiscali.it
                                127.0.0.1 5tiscali.it
                                127.0.0.1 www.5zgmu7o20kt5d8yq.com
                                127.0.0.1 5zgmu7o20kt5d8yq.com
                                127.0.0.1 www.680180.net
                                127.0.0.1 680180.net
                                127.0.0.1 www.6iscali.it
                                127.0.0.1 6iscali.it
                                127.0.0.1 www.6njaga.com
                                127.0.0.1 6njaga.com
                                127.0.0.1 www.6sek.com
                                127.0.0.1 6sek.com
                                127.0.0.1 www.6tiscali.it
                                127.0.0.1 6tiscali.it
                                127.0.0.1 www.70-music.com
                                127.0.0.1 70-music.com
                                127.0.0.1 www.7322.com
                                127.0.0.1 7322.com
                                127.0.0.1 75tz.com
                                127.0.0.1 www.777search.com
                                127.0.0.1 777search.com
                                127.0.0.1 www.777top.com
                                127.0.0.1 777top.com
                                127.0.0.1 www.7939.com
                                127.0.0.1 7939.com
                                127.0.0.1 www.7search.com
                                127.0.0.1 7search.com
                                127.0.0.1 80gw6ry3i3x3qbrkwhxhw.032439.com
                                127.0.0.1 www.80-music.com
                                127.0.0.1 80-music.com
                                127.0.0.1 82211.net
                                127.0.0.1 8866.org
                                127.0.0.1 www.88vcd.com
                                127.0.0.1 88vcd.com
                                127.0.0.1 www.8ad.com
                                127.0.0.1 8ad.com
                                127.0.0.1 www.90-music.com
                                127.0.0.1 90-music.com
                                127.0.0.1 www.9505.com
                                127.0.0.1 9505.com
                                127.0.0.1 www.971searchbox.com
                                127.0.0.1 971searchbox.com
                                127.0.0.1 9mmporn.com
                                127.0.0.1 a.bestmanage.org
                                127.0.0.1 www.aaabesthomepage.com
                                127.0.0.1 aaabesthomepage.com
                                127.0.0.1 aaasexypics.com
                                127.0.0.1 www.aaawebfinder.com
                                127.0.0.1 aaawebfinder.com
                                127.0.0.1 www.aaqadarsztriv.com
                                127.0.0.1 aaqadarsztriv.com
                                127.0.0.1 www.aaqada-rsztriv.com
                                127.0.0.1 aaqada-rsztriv.com
                                127.0.0.1 www.aaqadaueorn.com
                                127.0.0.1 aaqadaueorn.com
                                127.0.0.1 www.aaqada-ueorn.com
                                127.0.0.1 aaqada-ueorn.com
                                127.0.0.1 www.aaqada-ygco.com
                                127.0.0.1 aaqada-ygco.com
                                127.0.0.1 www.aaqada-ymct.com
                                127.0.0.1 aaqada-ymct.com
                                127.0.0.1 aavc.com
                                127.0.0.1 www.abccodec.com
                                127.0.0.1 abccodec.com
                                127.0.0.1 www.abcdperformance.com
                                127.0.0.1 abcdperformance.com
                                127.0.0.1 www.abc-find.info
                                127.0.0.1 abc-find.info
                                127.0.0.1 www.abcsearch.com
                                127.0.0.1 abcsearch.com
                                127.0.0.1 www.abetterinternet.com
                                127.0.0.1 abetterinternet.com
                                127.0.0.1 www.abnetsoft.info
                                127.0.0.1 abnetsoft.info
                                127.0.0.1 www.aboutclicker.com
                                127.0.0.1 aboutclicker.com
                                127.0.0.1 www.abrp.net
                                127.0.0.1 abrp.net
                                127.0.0.1 www.absolutee.com
                                127.0.0.1 absolutee.com
                                127.0.0.1 www.abyssmedia.com
                                127.0.0.1 abyssmedia.com
                                127.0.0.1 www.ac66.cn
                                127.0.0.1 ac66.cn
                                127.0.0.1 access.navinetwork.com
                                127.0.0.1 access.rapid-pass.net
                                127.0.0.1 www.accessactivexvideo.com
                                127.0.0.1 accessactivexvideo.com
                                127.0.0.1 www.accessclips.com
                                127.0.0.1 accessclips.com
                                127.0.0.1 www.access-dvd.com
                                127.0.0.1 access-dvd.com
                                127.0.0.1 www.accesskeygenerator.com
                                127.0.0.1 accesskeygenerator.com
                                127.0.0.1 www.accessthefuture.net
                                127.0.0.1 accessthefuture.net
                                127.0.0.1 www.accessvid.net
                                127.0.0.1 accessvid.net
                                127.0.0.1 www.acemedic.com
                                127.0.0.1 acemedic.com
                                127.0.0.1 www.ace-webmaster.com
                                127.0.0.1 ace-webmaster.com
                                127.0.0.1 acjp.com
                                127.0.0.1 www.acrobat-2007.com
                                127.0.0.1 acrobat-2007.com
                                127.0.0.1 www.acrobat-8.com
                                127.0.0.1 acrobat-8.com
                                127.0.0.1 www.acrobat-center.com
                                127.0.0.1 acrobat-center.com
                                127.0.0.1 www.acrobat-hq.com
                                127.0.0.1 acrobat-hq.com
                                127.0.0.1 www.acrobatreader-8.com
                                127.0.0.1 acrobatreader-8.com
                                127.0.0.1 www.acrobat-reader-8.de
                                127.0.0.1 acrobat-reader-8.de
                                127.0.0.1 www.acrobat-stop.com
                                127.0.0.1 acrobat-stop.com
                                127.0.0.1 www.actionbreastcancer.org
                                127.0.0.1 actionbreastcancer.org
                                127.0.0.1 www.activesearcher.info
                                127.0.0.1 activesearcher.info
                                127.0.0.1 www.activexaccessobject.com
                                127.0.0.1 activexaccessobject.com
                                127.0.0.1 www.activexaccessvideo.com
                                127.0.0.1 activexaccessvideo.com
                                127.0.0.1 www.activexemedia.com
                                127.0.0.1 activexemedia.com
                                127.0.0.1 www.activexmediaobject.com
                                127.0.0.1 activexmediaobject.com
                                127.0.0.1 www.activexmediapro.com
                                127.0.0.1 activexmediapro.com
                                127.0.0.1 www.activexmediasite.com
                                127.0.0.1 activexmediasite.com
                                127.0.0.1 www.activexmediasoftware.com
                                127.0.0.1 activexmediasoftware.com
                                127.0.0.1 www.activexmediasource.com
                                127.0.0.1 activexmediasource.com
                                127.0.0.1 www.activexmediatool.com
                                127.0.0.1 activexmediatool.com
                                127.0.0.1 www.activexmediatour.com
                                127.0.0.1 activexmediatour.com
                                127.0.0.1 www.activexsoftwares.com
                                127.0.0.1 activexsoftwares.com
                                127.0.0.1 www.activexsource.com
                                127.0.0.1 activexsource.com
                                127.0.0.1 www.activexupdate.com
                                127.0.0.1 activexupdate.com
                                127.0.0.1 www.activexvideo.com
                                127.0.0.1 activexvideo.com
                                127.0.0.1 www.activexvideotool.com
                                127.0.0.1 activexvideotool.com
                                127.0.0.1 www.ad.marketingsector.com
                                127.0.0.1 ad.marketingsector.com
                                127.0.0.1 www.ad.mokead.com
                                127.0.0.1 ad.mokead.com
                                127.0.0.1 ad.oinadserver.com
                                127.0.0.1 ad.outerinfoads.com
                                127.0.0.1 www.ad25.com
                                127.0.0.1 ad25.com
                                127.0.0.1 www.ad45.com
                                127.0.0.1 ad45.com
                                127.0.0.1 www.ad77.com
                                127.0.0.1 ad77.com
                                127.0.0.1 www.ad86.com
                                127.0.0.1 ad86.com
                                127.0.0.1 www.adamsupportgroup.org
                                127.0.0.1 adamsupportgroup.org
                                127.0.0.1 www.adarmor.com
                                127.0.0.1 adarmor.com
                                127.0.0.1 www.adasearch.com
                                127.0.0.1 adasearch.com
                                127.0.0.1 adaware.cc
                                127.0.0.1 www.adawarenow.com
                                127.0.0.1 adawarenow.com
                                127.0.0.1 adchannel.contextplus.net
                                127.0.0.1 www.addetect.com
                                127.0.0.1 addetect.com
                                127.0.0.1 www.add-hhh.info
                                127.0.0.1 add-hhh.info
                                127.0.0.1 www.addictivetechnologies.com
                                127.0.0.1 addictivetechnologies.com
                                127.0.0.1 www.addictivetechnologies.net
                                127.0.0.1 addictivetechnologies.net
                                127.0.0.1 www.addioerrori.com
                                127.0.0.1 addioerrori.com
                                127.0.0.1 www.add-manager.com
                                127.0.0.1 add-manager.com
                                127.0.0.1 www.adgate.info
                                127.0.0.1 adgate.info
                                127.0.0.1 www.adintelligence.net
                                127.0.0.1 adintelligence.net
                                127.0.0.1 www.adioserrores.com
                                127.0.0.1 adioserrores.com
                                127.0.0.1 www.adipics.com
                                127.0.0.1 adipics.com
                                127.0.0.1 www.adlogix.com
                                127.0.0.1 adlogix.com
                                127.0.0.1 www.admin2cash.biz
                                127.0.0.1 admin2cash.biz
                                127.0.0.1 adnet-plus.com
                                127.0.0.1 www.adnetserver.com
                                127.0.0.1 adnetserver.com
                                127.0.0.1 adobe-download-now.com
                                127.0.0.1 www.adobe-downloads.com
                                127.0.0.1 adobe-downloads.com
                                127.0.0.1 www.adobe-reader-8.fr
                                127.0.0.1 adobe-reader-8.fr
                                127.0.0.1 www.adprotect.com
                                127.0.0.1 adprotect.com
                                127.0.0.1 ads.centralmedia.ws
                                127.0.0.1 ads.k8l.info
                                127.0.0.1 ads.kmpads.com
                                127.0.0.1 ads.kw.revenue.net
                                127.0.0.1 ads.marketingsector.com
                                127.0.0.1 ads.searchingbooth.com
                                127.0.0.1 ads.z-quest.com
                                127.0.0.1 ads1.revenue.net
                                127.0.0.1 www.ads183.com
                                127.0.0.1 ads183.com
                                127.0.0.1 www.adscontex.com
                                127.0.0.1 adscontex.com
                                127.0.0.1 www.adservices1.enhance.com
                                127.0.0.1 adservices1.enhance.com
                                127.0.0.1 adservs.com
                                127.0.0.1 www.adsextend.net
                                127.0.0.1 adsextend.net
                                127.0.0.1 www.adshttp.com
                                127.0.0.1 adshttp.com
                                127.0.0.1 www.adsniffer.com
                                127.0.0.1 adsniffer.com
                                127.0.0.1 www.adsonwww.com
                                127.0.0.1 adsonwww.com
                                127.0.0.1 www.adspics.com
                                127.0.0.1 adspics.com
                                127.0.0.1 www.adsrevenue.net
                                127.0.0.1 adsrevenue.net
                                127.0.0.1 www.adtrak.net
                                127.0.0.1 adtrak.net
                                127.0.0.1 adtrgt.com
                                127.0.0.1 www.adult18codec.com
                                127.0.0.1 adult18codec.com
                                127.0.0.1 www.adult777search.info
                                127.0.0.1 adult777search.info
                                127.0.0.1 www.adultan.com
                                127.0.0.1 adultan.com
                                127.0.0.1 www.adultcodec-2008.com
                                127.0.0.1 adultcodec-2008.com
                                127.0.0.1 www.adultcodecstars.com
                                127.0.0.1 adultcodecstars.com
                                127.0.0.1 www.adult-engine-search.com
                                127.0.0.1 adult-engine-search.com
                                127.0.0.1 www.adult-erotic-guide.net
                                127.0.0.1 adult-erotic-guide.net
                                127.0.0.1 www.adultfilmsite.com
                                127.0.0.1 adultfilmsite.com
                                127.0.0.1 www.adult-friends-finder.net
                                127.0.0.1 adult-friends-finder.net
                                127.0.0.1 adultgambling.org
                                127.0.0.1 adult-host.org
                                127.0.0.1 www.adulthyperlinks.com
                                127.0.0.1 adulthyperlinks.com
                                127.0.0.1 www.adultmovieplus.com
                                127.0.0.1 adultmovieplus.com
                                127.0.0.1 www.adult-mpg.net
                                127.0.0.1 adult-mpg.net
                                127.0.0.1 adult-personal.us
                                127.0.0.1 adultsgames.net
                                127.0.0.1 www.adultsonlyvids.com
                                127.0.0.1 adultsonlyvids.com
                                127.0.0.1 www.adultsper.com
                                127.0.0.1 adultsper.com
                                127.0.0.1 www.adulttds.com
                                127.0.0.1 adulttds.com
                                127.0.0.1 www.adultzoneworld.com
                                127.0.0.1 adultzoneworld.com
                                127.0.0.1 www.advancedcleaner.com
                                127.0.0.1 advancedcleaner.com
                                127.0.0.1 www.advcash.biz
                                127.0.0.1 advcash.biz
                                127.0.0.1 advert.exaccess.ru
                                127.0.0.1 www.advertisemoney.info
                                127.0.0.1 advertisemoney.info
                                127.0.0.1 advertising.paltalk.com
                                127.0.0.1 www.advertising-money.info
                                127.0.0.1 advertising-money.info
                                127.0.0.1 ad-ware.cc
                                127.0.0.1 www.ad-w-a-r-e.com
                                127.0.0.1 ad-w-a-r-e.com
                                127.0.0.1 www.a-d-w-a-r-e.com
                                127.0.0.1 a-d-w-a-r-e.com
                                127.0.0.1 www.adware.pro
                                127.0.0.1 adware.pro
                                127.0.0.1 www.adwarealert.com
                                127.0.0.1 adwarealert.com
                                127.0.0.1 www.ad-warealert.com
                                127.0.0.1 ad-warealert.com
                                127.0.0.1 www.adwarearrest.com
                                127.0.0.1 adwarearrest.com
                                127.0.0.1 www.adwarebazooka.com
                                127.0.0.1 adwarebazooka.com
                                127.0.0.1 www.adwarecommander.com
                                127.0.0.1 adwarecommander.com
                                127.0.0.1 www.adwarefinder.com
                                127.0.0.1 adwarefinder.com
                                127.0.0.1 www.adwaregold.com
                                127.0.0.1 adwaregold.com
                                127.0.0.1 www.adwarepatrol.com
                                127.0.0.1 adwarepatrol.com
                                127.0.0.1 www.adwareplatinum.com
                                127.0.0.1 adwareplatinum.com
                                127.0.0.1 www.adwareprotectionsite.com
                                127.0.0.1 adwareprotectionsite.com
                                127.0.0.1 www.adwarepunisher.com
                                127.0.0.1 adwarepunisher.com
                                127.0.0.1 www.adwareremover.ws
                                127.0.0.1 adwareremover.ws
                                127.0.0.1 www.adwaresafety.com
                                127.0.0.1 adwaresafety.com
                                127.0.0.1 www.adwarexp.com
                                127.0.0.1 adwarexp.com
                                127.0.0.1 affiliate.idownload.com
                                127.0.0.1 www.aflgate.com
                                127.0.0.1 aflgate.com
                                127.0.0.1 africaspromise.org
                                127.0.0.1 agava.com
                                127.0.0.1 agava.ru
                                127.0.0.1 agentstudio.com
                                127.0.0.1 www.aginegialle.it
                                127.0.0.1 aginegialle.it
                                127.0.0.1 www.ahnenforschung.de
                                127.0.0.1 ahnenforschung.de
                                127.0.0.1 www.aifind.info
                                127.0.0.1 aifind.info
                                127.0.0.1 www.airtleworld.com
                                127.0.0.1 airtleworld.com
                                127.0.0.1 www.aitalia.it
                                127.0.0.1 aitalia.it
                                127.0.0.1 akamai.downloadv3.com
                                127.0.0.1 www.aklitalia.it
                                127.0.0.1 aklitalia.it
                                127.0.0.1 akril.com
                                127.0.0.1 alcatel.ws
                                127.0.0.1 www.alertspy.com
                                127.0.0.1 alertspy.com
                                127.0.0.1 www.alfacleaner.com
                                127.0.0.1 alfacleaner.com
                                127.0.0.1 alfa-search.com
                                127.0.0.1 www.alialia.it
                                127.0.0.1 alialia.it
                                127.0.0.1 www.aliotalia.it
                                127.0.0.1 aliotalia.it
                                127.0.0.1 www.alirtalia.it
                                127.0.0.1 alirtalia.it
                                127.0.0.1 www.alitaia.it
                                127.0.0.1 alitaia.it
                                127.0.0.1 www.alitaklia.it
                                127.0.0.1 alitaklia.it
                                127.0.0.1 www.alitala.it
                                127.0.0.1 alitala.it
                                127.0.0.1 www.alitali.it
                                127.0.0.1 alitali.it
                                127.0.0.1 www.alitaliaq.it
                                127.0.0.1 alitaliaq.it
                                127.0.0.1 www.alitalias.it
                                127.0.0.1 alitalias.it
                                127.0.0.1 www.alitaliaz.it
                                127.0.0.1 alitaliaz.it
                                127.0.0.1 www.alitalioa.it
                                127.0.0.1 alitalioa.it
                                127.0.0.1 www.alitalisa.it
                                127.0.0.1 alitalisa.it
                                127.0.0.1 www.alitaliua.it
                                127.0.0.1 alitaliua.it
                                127.0.0.1 www.alitalkia.it
                                127.0.0.1 alitalkia.it
                                127.0.0.1 www.alitaloia.it
                                127.0.0.1 alitaloia.it
                                127.0.0.1 www.alitaluia.it
                                127.0.0.1 alitaluia.it
                                127.0.0.1 www.alitaslia.it
                                127.0.0.1 alitaslia.it
                                127.0.0.1 www.alitlia.it
                                127.0.0.1 alitlia.it
                                127.0.0.1 www.alitralia.it
                                127.0.0.1 alitralia.it
                                127.0.0.1 www.alitsalia.it
                                127.0.0.1 alitsalia.it
                                127.0.0.1 www.aliutalia.it
                                127.0.0.1 aliutalia.it
                                127.0.0.1 www.all1count.net
                                127.0.0.1 all1count.net
                                127.0.0.1 www.all4internet.com
                                127.0.0.1 all4internet.com
                                127.0.0.1 allabtcars.com
                                127.0.0.1 allabtjeeps.com
                                127.0.0.1 www.all-bittorrent.com
                                127.0.0.1 all-bittorrent.com
                                127.0.0.1 www.allcollisions.com
                                127.0.0.1 allcollisions.com
                                127.0.0.1 www.allcybersearch.com
                                127.0.0.1 allcybersearch.com
                                127.0.0.1 www.alldnserrors.com
                                127.0.0.1 alldnserrors.com
                                127.0.0.1 www.all-downloads-now.com
                                127.0.0.1 all-downloads-now.com
                                127.0.0.1 www.all-edonkey.com
                                127.0.0.1 all-edonkey.com
                                127.0.0.1 www.allertaminacce.com
                                127.0.0.1 allertaminacce.com
                                127.0.0.1 allforadult.com
                                127.0.0.1 allhyperlinks.com
                                127.0.0.1 www.alliesecurity.com
                                127.0.0.1 alliesecurity.com
                                127.0.0.1 all-inet.com
                                127.0.0.1 allinternetbusiness.com
                                127.0.0.1 www.all-limewire.com
                                127.0.0.1 all-limewire.com
                                127.0.0.1 www.allmegabucks.com
                                127.0.0.1 allmegabucks.com
                                127.0.0.1 www.allprotections.com
                                127.0.0.1 allprotections.com
                                127.0.0.1 www.allresultz.net
                                127.0.0.1 allresultz.net
                                127.0.0.1 www.allsearch.us
                                127.0.0.1 allsearch.us
                                127.0.0.1 www.allsecuritynotes.com
                                127.0.0.1 allsecuritynotes.com
                                127.0.0.1 www.allsecuritysite.com
                                127.0.0.1 allsecuritysite.com
                                127.0.0.1 www.allstarsvideos.net
                                127.0.0.1 allstarsvideos.net
                                127.0.0.1 www.alltiettantivirus.com
                                127.0.0.1 alltiettantivirus.com
                                127.0.0.1 www.alltruesoftware.com
                                127.0.0.1 alltruesoftware.com
                                127.0.0.1 www.allvideoactivex.com
                                127.0.0.1 allvideoactivex.com
                                127.0.0.1 www.almanah.biz
                                127.0.0.1 almanah.biz
                                127.0.0.1 almarvideos.com
                                127.0.0.1 www.aloitalia.it
                                127.0.0.1 aloitalia.it
                                127.0.0.1 www.aluitalia.it
                                127.0.0.1 aluitalia.it
                                127.0.0.1 www.amaena.com
                                127.0.0.1 amaena.com
                                127.0.0.1 amandamountains.com
                                127.0.0.1 www.amateurliveshow.com
                                127.0.0.1 amateurliveshow.com
                                127.0.0.1 www.amediasoftware.com
                                127.0.0.1 amediasoftware.com
                                127.0.0.1 www.amediasource.com
                                127.0.0.1 amediasource.com
                                127.0.0.1 www.americanautobargains.com
                                127.0.0.1 americanautobargains.com
                                127.0.0.1 www.americancarbargains.com
                                127.0.0.1 americancarbargains.com
                                127.0.0.1 american-teens.net
                                127.0.0.1 amigeek.com
                                127.0.0.1 www.amigobore.com
                                127.0.0.1 amigobore.com
                                127.0.0.1 amisbusiness.com
                                127.0.0.1 www.ampmsearch.com
                                127.0.0.1 ampmsearch.com
                                127.0.0.1 www.analcord.com
                                127.0.0.1 analcord.com
                                127.0.0.1 analmovi.com
                                127.0.0.1 www.anarchylolita.com
                                127.0.0.1 anarchylolita.com
                                127.0.0.1 anarchyporn.com
                                127.0.0.1 www.andromedical.com
                                127.0.0.1 andromedical.com
                                127.0.0.1 www.animepornmag.com
                                127.0.0.1 animepornmag.com
                                127.0.0.1 anin.org
                                127.0.0.1 www.anjpn-avxiz.biz
                                127.0.0.1 anjpn-avxiz.biz
                                127.0.0.1 www.anjpnzqav.biz
                                127.0.0.1 anjpnzqav.biz
                                127.0.0.1 www.anjpn-zqav.biz
                                127.0.0.1 anjpn-zqav.biz
                                127.0.0.1 annaromeo.com
                                127.0.0.1 www.antiddos.us
                                127.0.0.1 antiddos.us
                                127.0.0.1 www.antiespiadorado.com
                                127.0.0.1 antiespiadorado.com
                                127.0.0.1 www.antiespionspack.com
                                127.0.0.1 antiespionspack.com
                                127.0.0.1 www.antigusanos2008.com
                                127.0.0.1 antigusanos2008.com
                                127.0.0.1 www.antispamassistant.com
                                127.0.0.1 antispamassistant.com
                                127.0.0.1 www.antispamdeluxe.com
                                127.0.0.1 antispamdeluxe.com
                                127.0.0.1 www.antispionage.com
                                127.0.0.1 antispionage.com
                                127.0.0.1 www.antispionagepro.com
                                127.0.0.1 antispionagepro.com
                                127.0.0.1 www.antispyadvanced.com
                                127.0.0.1 antispyadvanced.com
                                127.0.0.1 www.antispydns.biz
                                127.0.0.1 antispydns.biz
                                127.0.0.1 www.antispykit.com
                                127.0.0.1 antispykit.com
                                127.0.0.1 www.antispylab.com
                                127.0.0.1 antispylab.com
                                127.0.0.1 www.antispyshield.com
                                127.0.0.1 antispyshield.com
                                127.0.0.1 www.antispysolutions.com
                                127.0.0.1 antispysolutions.com
                                127.0.0.1 www.antispyware.com
                                127.0.0.1 antispyware.com
                                127.0.0.1 www.antispywareboot.com
                                127.0.0.1 antispywareboot.com
                                127.0.0.1 www.antispywarebot.com
                                127.0.0.1 antispywarebot.com
                                127.0.0.1 www.antispywarebox.com
                                127.0.0.1 antispywarebox.com
                                127.0.0.1 www.antispywaredownloads.com
                                127.0.0.1 antispywaredownloads.com
                                127.0.0.1 www.antispywaresuite.com
                                127.0.0.1 antispywaresuite.com
                                127.0.0.1 www.antispywareupdates.net
                                127.0.0.1 antispywareupdates.net
                                127.0.0.1 www.antispywarexp.com
                                127.0.0.1 antispywarexp.com
                                127.0.0.1 www.antispyweb.net
                                127.0.0.1 antispyweb.net
                                127.0.0.1 www.antiver2008.com
                                127.0.0.1 antiver2008.com
                                127.0.0.1 www.antivermins.com
                                127.0.0.1 antivermins.com
                                127.0.0.1 www.anti-vermins.com
                                127.0.0.1 anti-vermins.com
                                127.0.0.1 www.antivir2007.com
                                127.0.0.1 antivir2007.com
                                127.0.0.1 www.antivirgear.com
                                127.0.0.1 antivirgear.com
                                127.0.0.1 www.antivirus.fastfreedownload.com
                                127.0.0.1 antivirus.fastfreedownload.com
                                127.0.0.1 www.antivirus2008x.com
                                127.0.0.1 antivirus2008x.com
                                127.0.0.1 www.antivirusadvance.com
                                127.0.0.1 antivirusadvance.com
                                127.0.0.1 www.antivirusaskeladd.com
                                127.0.0.1 antivirusaskeladd.com
                                127.0.0.1 www.antivirusgereedschap.com
                                127.0.0.1 antivirusgereedschap.com
                                127.0.0.1 www.antivirusgolden.com
                                127.0.0.1 antivirusgolden.com
                                127.0.0.1 www.antivirus-hq.net
                                127.0.0.1 antivirus-hq.net
                                127.0.0.1 www.antiviruspcsuite.com
                                127.0.0.1 antiviruspcsuite.com
                                127.0.0.1 www.antiviruspremium.com
                                127.0.0.1 antiviruspremium.com
                                127.0.0.1 www.anti-virus-pro.com
                                127.0.0.1 anti-virus-pro.com
                                127.0.0.1 www.antivirusprotector.com
                                127.0.0.1 antivirusprotector.com
                                127.0.0.1 www.antivirus-scanner.com
                                127.0.0.1 antivirus-scanner.com
                                127.0.0.1 www.antivirusscherm.com
                                127.0.0.1 antivirusscherm.com
                                127.0.0.1 www.antivirussecuritypro.com
                                127.0.0.1 antivirussecuritypro.com
                                127.0.0.1 www.antivirus-stop.com
                                127.0.0.1 antivirus-stop.com
                                127.0.0.1 www.antivirussuite.com
                                127.0.0.1 antivirussuite.com
                                127.0.0.1 www.antiworm2008.com
                                127.0.0.1 antiworm2008.com
                                127.0.0.1 www.antiwurm2008.com
                                127.0.0.1 antiwurm2008.com
                                127.0.0.1 antrocity.com
                                127.0.0.1 www.anyofus.com
                                127.0.0.1 anyofus.com
                                127.0.0.1 www.anysn.seproger.com
                                127.0.0.1 anysn.seproger.com
                                127.0.0.1 anything4health.com
                                127.0.0.1 www.apicpreview.com
                                127.0.0.1 apicpreview.com
                                127.0.0.1 www.appealcircuit.com
                                127.0.0.1 appealcircuit.com
                                127.0.0.1 www.approvedlinks.com
                                127.0.0.1 approvedlinks.com
                                127.0.0.1 apps.deskwizz.com
                                127.0.0.1 apps.webservicehost.com
                                127.0.0.1 www.aprotectedpage.com
                                127.0.0.1 aprotectedpage.com
                                127.0.0.1 apsua.com
                                127.0.0.1 www.archivioadulti.com
                                127.0.0.1 archivioadulti.com
                                127.0.0.1 www.archiviosex.net
                                127.0.0.1 archiviosex.net
                                127.0.0.1 aregay.com
                                127.0.0.1 www.ares.click-new-download.com
                                127.0.0.1 ares.click-new-download.com
                                127.0.0.1 www.ares-freebie.com
                                127.0.0.1 ares-freebie.com
                                127.0.0.1 www.arespro2007.com
                                127.0.0.1 arespro2007.com
                                127.0.0.1 www.aresultra.com
                                127.0.0.1 aresultra.com
                                127.0.0.1 www.ares-usa.com
                                127.0.0.1 ares-usa.com
                                127.0.0.1 arheo.com
                                127.0.0.1 arizonaweb.org
                                127.0.0.1 armitageinn.com
                                127.0.0.1 www.arquivojpgs.smtp.ru
                                127.0.0.1 arquivojpgs.smtp.ru
                                127.0.0.1 artachnid.com
                                127.0.0.1 art-func.com
                                127.0.0.1 art-xxx.com
                                127.0.0.1 www.asafebrowser.com
                                127.0.0.1 asafebrowser.com
                                127.0.0.1 www.asafetyalways.com
                                127.0.0.1 asafetyalways.com
                                127.0.0.1 www.asafetynotice.com
                                127.0.0.1 asafetynotice.com
                                127.0.0.1 www.asafetypage.com
                                127.0.0.1 asafetypage.com
                                127.0.0.1 www.asdbiz.biz
                                127.0.0.1 asdbiz.biz
                                127.0.0.1 www.asdeykuddq.com
                                127.0.0.1 asdeykuddq.com
                                127.0.0.1 www.asecurebar.com
                                127.0.0.1 asecurebar.com
                                127.0.0.1 www.asecureboard.com
                                127.0.0.1 asecureboard.com
                                127.0.0.1 www.asecurevalue.com
                                127.0.0.1 asecurevalue.com
                                127.0.0.1 www.asecurityissue.com
                                127.0.0.1 asecurityissue.com
                                127.0.0.1 www.asecuritynotice.com
                                127.0.0.1 asecuritynotice.com
                                127.0.0.1 www.asecuritypaper.com
                                127.0.0.1 asecuritypaper.com
                                127.0.0.1 www.asecuritystuff.com
                                127.0.0.1 asecuritystuff.com
                                127.0.0.1 www.asfadaptation.com
                                127.0.0.1 asfadaptation.com
                                127.0.0.1 asiankingkong.com
                                127.0.0.1 www.asianpornmag.com
                                127.0.0.1 asianpornmag.com
                                127.0.0.1 www.asiantoolbar.com
                                127.0.0.1 asiantoolbar.com
                                127.0.0.1 www.asidseiupc.com
                                127.0.0.1 asidseiupc.com
                                127.0.0.1 www.aslitalia.it
                                127.0.0.1 aslitalia.it
                                127.0.0.1 ass-gals.com
                                127.0.0.1 www.assureprotection.com
                                127.0.0.1 assureprotection.com
                                127.0.0.1 asta-killer.com
                                127.0.0.1 www.astrologie-server.com
                                127.0.0.1 astrologie-server.com
                                127.0.0.1 www.asupereva.it
                                127.0.0.1 asupereva.it
                                127.0.0.1 www.ataprogram.com
                                127.0.0.1 ataprogram.com
                                127.0.0.1 athenrye.com
                                127.0.0.1 www.atotalsafety.com
                                127.0.0.1 atotalsafety.com
                                127.0.0.1 www.atrueprotection.com
                                127.0.0.1 atrueprotection.com
                                127.0.0.1 www.atruesecurity.com
                                127.0.0.1 atruesecurity.com
                                127.0.0.1 www.attackware.com
                                127.0.0.1 attackware.com
                                127.0.0.1 www.attrezzi.biz
                                127.0.0.1 attrezzi.biz
                                127.0.0.1 www.aucunsvirus.com
                                127.0.0.1 aucunsvirus.com
                                127.0.0.1 www.aulde.net
                                127.0.0.1 aulde.net
                                127.0.0.1 www.aupereva.it
                                127.0.0.1 aupereva.it
                                127.0.0.1 www.autobargains.org
                                127.0.0.1 autobargains.org
                                127.0.0.1 www.autobargainsnetwork.com
                                127.0.0.1 autobargainsnetwork.com
                                127.0.0.1 www.autocontext.begun.ru
                                127.0.0.1 autocontext.begun.ru
                                127.0.0.1 autoescrowpay.com
                                127.0.0.1 www.avadvance.com
                                127.0.0.1 avadvance.com
                                127.0.0.1 www.avast.free-software-center.com
                                127.0.0.1 avast.free-software-center.com
                                127.0.0.1 www.avast-2007.com
                                127.0.0.1 avast-2007.com
                                127.0.0.1 www.avast-downloads.com
                                127.0.0.1 avast-downloads.com
                                127.0.0.1 www.avast-hq.com
                                127.0.0.1 avast-hq.com
                                127.0.0.1 www.avforce.com
                                127.0.0.1 avforce.com
                                127.0.0.1 www.avg.grab-it-today.net
                                127.0.0.1 avg.grab-it-today.net
                                127.0.0.1 www.avg.softwarecenterz.com
                                127.0.0.1 avg.softwarecenterz.com
                                127.0.0.1 www.avg-secure.com
                                127.0.0.1 avg-secure.com
                                127.0.0.1 www.aviadaptation.com
                                127.0.0.1 aviadaptation.com
                                127.0.0.1 avian-ads.com
                                127.0.0.1 www.avicoupler.com
                                127.0.0.1 avicoupler.com
                                127.0.0.1 www.avideoaxaccess.com
                                127.0.0.1 avideoaxaccess.com
                                127.0.0.1 www.avideosurfer.com
                                127.0.0.1 avideosurfer.com
                                127.0.0.1 www.avidirection.com
                                127.0.0.1 avidirection.com
                                127.0.0.1 www.aviewersoft.com
                                127.0.0.1 aviewersoft.com
                                127.0.0.1 www.avihelper.com
                                127.0.0.1 avihelper.com
                                127.0.0.1 www.avitool.com
                                127.0.0.1 avitool.com
                                127.0.0.1 www.avpcheckupdate.com
                                127.0.0.1 avpcheckupdate.com
                                127.0.0.1 www.avsmanufacture.com
                                127.0.0.1 avsmanufacture.com
                                127.0.0.1 www.avsystemcare.com
                                127.0.0.1 avsystemcare.com
                                127.0.0.1 www.avxizaaqada.biz
                                127.0.0.1 avxizaaqada.biz
                                127.0.0.1 www.avxiz-anjpn.biz
                                127.0.0.1 avxiz-anjpn.biz
                                127.0.0.1 www.avxizueorn.biz
                                127.0.0.1 avxizueorn.biz
                                127.0.0.1 www.avxiz-ueorn.biz
                                127.0.0.1 avxiz-ueorn.biz
                                127.0.0.1 www.avxiz-vtvcp.biz
                                127.0.0.1 avxiz-vtvcp.biz
                                127.0.0.1 www.avxiz-ygco.biz
                                127.0.0.1 avxiz-ygco.biz
                                127.0.0.1 www.avxiz-zqav.biz
                                127.0.0.1 avxiz-zqav.biz
                                127.0.0.1 www.awarenesstech.com
                                127.0.0.1 awarenesstech.com
                                127.0.0.1 www.awarninglist.com
                                127.0.0.1 awarninglist.com
                                127.0.0.1 awbeta.net-nucleus.com
                                127.0.0.1 www.awesomehomepage.com
                                127.0.0.1 awesomehomepage.com
                                127.0.0.1 awmcash.biz
                                127.0.0.1 awmdabest.com
                                127.0.0.1 www.axemediasoftware.com
                                127.0.0.1 axemediasoftware.com
                                127.0.0.1 www.aximageobject.com
                                127.0.0.1 aximageobject.com
                                127.0.0.1 www.axmediaproject.com
                                127.0.0.1 axmediaproject.com
                                127.0.0.1 www.axmediasoftware.com
                                127.0.0.1 axmediasoftware.com
                                127.0.0.1 www.axmediasolutions.com
                                127.0.0.1 axmediasolutions.com
                                127.0.0.1 www.axobjectpage.com
                                127.0.0.1 axobjectpage.com
                                127.0.0.1 www.axobjectsource.com
                                127.0.0.1 axobjectsource.com
                                127.0.0.1 www.axsoftwaretool.com
                                127.0.0.1 axsoftwaretool.com
                                127.0.0.1 www.axvideoproject.com
                                127.0.0.1 axvideoproject.com
                                127.0.0.1 www.axvideosetup.com
                                127.0.0.1 axvideosetup.com
                                127.0.0.1 ayakawamura.com
                                127.0.0.1 ayb.dns-look-up.com
                                127.0.0.1 ayb.netbios-wait.com
                                127.0.0.1 ayumitaniguchi.com
                                127.0.0.1 azebar.com
                                127.0.0.1 www.azureusclub.com
                                127.0.0.1 azureusclub.com
                                127.0.0.1 www.azureus-freebie.com
                                127.0.0.1 azureus-freebie.com
                                127.0.0.1 www.azzetta.it
                                127.0.0.1 azzetta.it
                                127.0.0.1 b.casalemedia.com
                                127.0.0.1 b122.mcboo.com
                                127.0.0.1 www.babe.k-lined.com
                                127.0.0.1 babe.k-lined.com
                                127.0.0.1 www.babe.the-killer.bz
                                127.0.0.1 babe.the-killer.bz
                                127.0.0.1 www.babenet.com
                                127.0.0.1 babenet.com
                                127.0.0.1 www.babespornmag.com
                                127.0.0.1 babespornmag.com
                                127.0.0.1 www.babeweb.de
                                127.0.0.1 babeweb.de
                                127.0.0.1 www.baccarat-other.info
                                127.0.0.1 baccarat-other.info
                                127.0.0.1 www.backstripgirls.com
                                127.0.0.1 backstripgirls.com
                                127.0.0.1 backup.mabou.org
                                127.0.0.1 www.balotierra.com
                                127.0.0.1 balotierra.com
                                127.0.0.1 bannedhost.net
                                127.0.0.1 barbudafarms.com
                                127.0.0.1 www.bardownload.com
                                127.0.0.1 bardownload.com
                                127.0.0.1 barnandfence.com
                                127.0.0.1 batsearch.com
                                127.0.0.1 baygraphicsllc.com
                                127.0.0.1 bbbsearch.com
                                127.0.0.1 bb-search.com
                                127.0.0.1 www.bcnproduction.com
                                127.0.0.1 bcnproduction.com
                                127.0.0.1 bdsmlibrary.net
                                127.0.0.1 www.bdsmpornmag.com
                                127.0.0.1 bdsmpornmag.com
                                127.0.0.1 www.bearshare.click-new-download.com
                                127.0.0.1 bearshare.click-new-download.com
                                127.0.0.1 www.bearshare.download-me.info
                                127.0.0.1 bearshare.download-me.info
                                127.0.0.1 www.bearshare.mp3-muzic.com
                                127.0.0.1 bearshare.mp3-muzic.com
                                127.0.0.1 www.bearshare-download.org
                                127.0.0.1 bearshare-download.org
                                127.0.0.1 www.bearshare-downloads.net
                                127.0.0.1 bearshare-downloads.net
                                127.0.0.1 www.bearsharelive.co.uk
                                127.0.0.1 bearsharelive.co.uk
                                127.0.0.1 www.bearshare-music-downloads.com
                                127.0.0.1 bearshare-music-downloads.com
                                127.0.0.1 www.bearsharepro2007.com
                                127.0.0.1 bearsharepro2007.com
                                127.0.0.1 www.bearshare-usa.com
                                127.0.0.1 bearshare-usa.com
                                127.0.0.1 bedhome.com
                                127.0.0.1 bediadance.com
                                127.0.0.1 www.beebappyy.biz
                                127.0.0.1 beebappyy.biz
                                127.0.0.1 www.begin2search.com
                                127.0.0.1 begin2search.com
                                127.0.0.1 bellabasketsfl.com
                                127.0.0.1 bernaolatwin.com
                                127.0.0.1 www.berufe-jobs.de
                                127.0.0.1 berufe-jobs.de
                                127.0.0.1 www.berufe-server.de
                                127.0.0.1 berufe-server.de
                                127.0.0.1 www.berufe-welt.de
                                127.0.0.1 berufe-welt.de
                                127.0.0.1 www.berufs-wahl.de
                                127.0.0.1 berufs-wahl.de
                                127.0.0.1 www.beruijindegunhadesun.com
                                127.0.0.1 beruijindegunhadesun.com
                                127.0.0.1 www.best3xclips.com
                                127.0.0.1 best3xclips.com
                                127.0.0.1 www.bestadults.com
                                127.0.0.1 bestadults.com
                                127.0.0.1 best-counter.com
                                127.0.0.1 bestcrawler.com
                                127.0.0.1 www.bestdailyvids.com
                                127.0.0.1 bestdailyvids.com
                                127.0.0.1 bestfor.ru
                                127.0.0.1 www.bestfuckvids.com
                                127.0.0.1 bestfuckvids.com
                                127.0.0.1 best-hardpics.com
                                127.0.0.1 www.bestmanage.org
                                127.0.0.1 bestmanage.org
                                127.0.0.1 www.bestmanage0.org
                                127.0.0.1 bestmanage0.org
                                127.0.0.1 www.bestmanage1.org
                                127.0.0.1 bestmanage1.org
                                127.0.0.1 www.bestmanage2.org
                                127.0.0.1 bestmanage2.org
                                127.0.0.1 www.bestmanage3.org
                                127.0.0.1 bestmanage3.org
                                127.0.0.1 www.bestmanage4.org
                                127.0.0.1 bestmanage4.org
                                127.0.0.1 www.bestmanage5.org
                                127.0.0.1 bestmanage5.org
                                127.0.0.1 www.bestmanage6.org
                                127.0.0.1 bestmanage6.org
                                127.0.0.1 www.bestmanage7.org
                                127.0.0.1 bestmanage7.org
                                127.0.0.1 www.bestmanage8.org
                                127.0.0.1 bestmanage8.org
                                127.0.0.1 www.bestmanage9.org
                                127.0.0.1 bestmanage9.org
                                127.0.0.1 www.bestmovszone.com
                                127.0.0.1 bestmovszone.com
                                127.0.0.1 www.bestoffersnetworks.com
                                127.0.0.1 bestoffersnetworks.com
                                127.0.0.1 bestporngate.com
                                127.0.0.1 www.bestsafetyguide.net
                                127.0.0.1 bestsafetyguide.net
                                127.0.0.1 www.bestsearch.cc
                                127.0.0.1 bestsearch.cc
                                127.0.0.1 www.bestsearchworld.info
                                127.0.0.1 bestsearchworld.info
                                127.0.0.1 www.best-spyware.info
                                127.0.0.1 best-spyware.info
                                127.0.0.1 www.best-targeted-traffic.com
                                127.0.0.1 best-targeted-traffic.com
                                127.0.0.1 www.best-voyeur.info
                                127.0.0.1 best-voyeur.info
                                127.0.0.1 bestweblinks.com
                                127.0.0.1 best-winning-casino.com
                                127.0.0.1 www.bestworldgirls-for-u.net
                                127.0.0.1 bestworldgirls-for-u.net
                                127.0.0.1 www.bestxclips.com
                                127.0.0.1 bestxclips.com
                                127.0.0.1 bestxporno.com
                                127.0.0.1 www.bestxxxmpegs.com
                                127.0.0.1 bestxxxmpegs.com
                                127.0.0.1 www.bettersearch.biz
                                127.0.0.1 bettersearch.biz
                                127.0.0.1 www.bgazzetta.it
                                127.0.0.1 bgazzetta.it
                                127.0.0.1 www.bgoogle.it
                                127.0.0.1 bgoogle.it
                                127.0.0.1 www.bigcodecadult.com
                                127.0.0.1 bigcodecadult.com
                                127.0.0.1 www.bigcodecadult2008.com
                                127.0.0.1 bigcodecadult2008.com
                                127.0.0.1 www.bigcodecadult2008-17.com
                                127.0.0.1 bigcodecadult2008-17.com
                                127.0.0.1 www.bighot18adult2008.com
                                127.0.0.1 bighot18adult2008.com
                                127.0.0.1 www.bighot18-adult2008.com
                                127.0.0.1 bighot18-adult2008.com
                                127.0.0.1 www.bighot18codec2008.com
                                127.0.0.1 bighot18codec2008.com
                                127.0.0.1 www.bighot18-codec2008.com
                                127.0.0.1 bighot18-codec2008.com
                                127.0.0.1 www.bigtrafficnetwork.com
                                127.0.0.1 bigtrafficnetwork.com
                                127.0.0.1 www.bigwww.com
                                127.0.0.1 bigwww.com
                                127.0.0.1 www.bill.de
                                127.0.0.1 bill.de
                                127.0.0.1 bin.errorprotector.com
                                127.0.0.1 bins.media-motor.net
                                127.0.0.1 bins2.media-motor.net
                                127.0.0.1 bis.180solutions.com
                                127.0.0.1 bitchesonline.net
                                127.0.0.1 www.bitcomet-freebie.com
                                127.0.0.1 bitcomet-freebie.com
                                127.0.0.1 www.bittorrent.click-new-download.com
                                127.0.0.1 bittorrent.click-new-download.com
                                127.0.0.1 biz.biz
                                127.0.0.1 www.bkvcompany.com
                                127.0.0.1 bkvcompany.com
                                127.0.0.1 www.blackblues00.com
                                127.0.0.1 blackblues00.com
                                127.0.0.1 www.blackcodec.com
                                127.0.0.1 blackcodec.com
                                127.0.0.1 www.blackcodec.net
                                127.0.0.1 blackcodec.net
                                127.0.0.1 www.blackhats.tc
                                127.0.0.1 blackhats.tc
                                127.0.0.1 www.blackhawksoftware.com
                                127.0.0.1 blackhawksoftware.com
                                127.0.0.1 blackjack-free.net
                                127.0.0.1 www.blacklegion.info
                                127.0.0.1 blacklegion.info
                                127.0.0.1 blazefind.com
                                127.0.0.1 blender.xu.pl
                                127.0.0.1 www.blockcheckercontrol.com
                                127.0.0.1 blockcheckercontrol.com
                                127.0.0.1 blondetgp.com
                                127.0.0.1 www.blue-elefant.com
                                127.0.0.1 blue-elefant.com
                                127.0.0.1 www.bm.theaimonline.com
                                127.0.0.1 bm.theaimonline.com
                                127.0.0.1 www.bnmgate.com
                                127.0.0.1 bnmgate.com
                                127.0.0.1 bodaciousbabette.com
                                127.0.0.1 www.bonzi.com
                                127.0.0.1 bonzi.com
                                127.0.0.1 boobdoll.com
                                127.0.0.1 boobsandtits.com
                                127.0.0.1 boobsclub.com
                                127.0.0.1 www.bookedspace.com
                                127.0.0.1 bookedspace.com
                                127.0.0.1 www.boom.com.vn
                                127.0.0.1 boom.com.vn
                                127.0.0.1 www.boomgirltv.com
                                127.0.0.1 boomgirltv.com
                                127.0.0.1 boredlife.com
                                127.0.0.1 bowlofogumbo.com
                                127.0.0.1 www.bpfq02.com
                                127.0.0.1 bpfq02.com
                                127.0.0.1 www.bqgate.com
                                127.0.0.1 bqgate.com
                                127.0.0.1 br.errorsafe.com
                                127.0.0.1 br.winantivirus.com
                                127.0.0.1 br.winfixer.com
                                127.0.0.1 bradcoem.org
                                127.0.0.1 www.braincodec.com
                                127.0.0.1 braincodec.com
                                127.0.0.1 brandiyoung.com
                                127.0.0.1 www.bravesentry.com
                                127.0.0.1 bravesentry.com
                                127.0.0.1 www.breenten.biz
                                127.0.0.1 breenten.biz
                                127.0.0.1 www.brodbfm.net
                                127.0.0.1 brodbfm.net
                                127.0.0.1 brookeburn.com
                                127.0.0.1 www.browserwise.com
                                127.0.0.1 browserwise.com
                                127.0.0.1 bsa.safetydownload.com
                                127.0.0.1 www.bsplaycodec.com
                                127.0.0.1 bsplaycodec.com
                                127.0.0.1 bucps.com
                                127.0.0.1 buhartes.info
                                127.0.0.1 buldog-stats.com
                                127.0.0.1 www.bullseye-network.com
                                127.0.0.1 bullseye-network.com
                                127.0.0.1 burgerkingbigscreen.com
                                127.0.0.1 www.burningsite.com
                                127.0.0.1 burningsite.com
                                127.0.0.1 www.burnsrecyclinginc.com
                                127.0.0.1 burnsrecyclinginc.com
                                127.0.0.1 buscards.net
                                127.0.0.1 bustyrussell.com
                                127.0.0.1 www.busysearch.net
                                127.0.0.1 busysearch.net
                                127.0.0.1 buttejazz.org
                                127.0.0.1 www.buy-find.info
                                127.0.0.1 buy-find.info
                                127.0.0.1 buyselldomain.net
                                127.0.0.1 www.buytraff.biz
                                127.0.0.1 buytraff.biz
                                127.0.0.1 buz.ru
                                127.0.0.1 www.bvdtechinque.com
                                127.0.0.1 bvdtechinque.com
                                127.0.0.1 www.bvirgilio.it
                                127.0.0.1 bvirgilio.it
                                127.0.0.1 c.centralmedia.ws
                                127.0.0.1 www.c.enhance.com
                                127.0.0.1 c.enhance.com
                                127.0.0.1 c.goclick.com
                                127.0.0.1 www.c4tdownload.com
                                127.0.0.1 c4tdownload.com
                                127.0.0.1 www.c5.www4free.info
                                127.0.0.1 c5.www4free.info
                                127.0.0.1 www.cache.surfaccuracy.com
                                127.0.0.1 cache.surfaccuracy.com
                                127.0.0.1 cache.ysbweb.com
                                127.0.0.1 www.cadesfinjeriokas.com
                                127.0.0.1 cadesfinjeriokas.com
                                127.0.0.1 calcioturris.com
                                127.0.0.1 www.calendaralerts.net
                                127.0.0.1 calendaralerts.net
                                127.0.0.1 www.callinghome.biz
                                127.0.0.1 callinghome.biz
                                127.0.0.1 www.cameouk.co.uk
                                127.0.0.1 cameouk.co.uk
                                127.0.0.1 cameup.com
                                127.0.0.1 www.camouflageclothingonline.net
                                127.0.0.1 camouflageclothingonline.net
                                127.0.0.1 campaigns.outerinfo.net
                                127.0.0.1 camup.net
                                127.0.0.1 canberracricketcoaching.com
                                127.0.0.1 candycantaloupes.com
                                127.0.0.1 www.canidetect.org
                                127.0.0.1 canidetect.org
                                127.0.0.1 www.cantfind.com
                                127.0.0.1 cantfind.com
                                127.0.0.1 careers.dulcineasystems.net
                                127.0.0.1 carsands.com
                                127.0.0.1 carsrentals.net
                                127.0.0.1 cartoes.uol.com.br
                                127.0.0.1 www.casalemedia.com
                                127.0.0.1 casalemedia.com
                                127.0.0.1 www.cashdeluxe.net
                                127.0.0.1 cashdeluxe.net
                                127.0.0.1 www.cashengines.com
                                127.0.0.1 cashengines.com
                                127.0.0.1 cashsearch.biz
                                127.0.0.1 www.cashsurfers.com
                                127.0.0.1 cashsurfers.com
                                127.0.0.1 www.cashunlim.com
                                127.0.0.1 cashunlim.com
                                127.0.0.1 casino.com.free.game.pogo.gratisdownloads.nl
                                127.0.0.1 casino2win.net
                                127.0.0.1 casino-gambling-1.net
                                127.0.0.1 casino-gambling-2.net
                                127.0.0.1 casinomidas.net
                                127.0.0.1 casinonline.net
                                127.0.0.1 casino-onlines.net
                                127.0.0.1 www.castingsamateur.com
                                127.0.0.1 castingsamateur.com
                                127.0.0.1 catallogue.com
                                127.0.0.1 www.catch-dc.info
                                127.0.0.1 catch-dc.info
                                127.0.0.1 categories.mygeek.com
                                127.0.0.1 catsss.da.ru
                                127.0.0.1 caxa.ru
                                127.0.0.1 cazygirls-world.com
                                127.0.0.1 cc.panet.org
                                127.0.0.1 www.ccecaedbebfcaf.com
                                127.0.0.1 ccecaedbebfcaf.com
                                127.0.0.1 cclebali.org
                                127.0.0.1 www.ccorriere.it
                                127.0.0.1 ccorriere.it
                                127.0.0.1 www.cdcopysite.com
                                127.0.0.1 cdcopysite.com
                                127.0.0.1 www.cdegate.com
                                127.0.0.1 cdegate.com
                                127.0.0.1 cdn.drivecleaner.com
                                127.0.0.1 cdn.errorsafe.com
                                127.0.0.1 cdn.movies-etc.com
                                127.0.0.1 cdn.winsoftware.com
                                127.0.0.1 cdn2.movies-etc.com
                                127.0.0.1 www.cdorriere.it
                                127.0.0.1 cdorriere.it
                                127.0.0.1 ceewawires.org
                                127.0.0.1 centralmedia.ws
                                127.0.0.1 certumgroup.com
                                127.0.0.1 www.cforriere.it
                                127.0.0.1 cforriere.it
                                127.0.0.1 www.check.jupitersatellites.biz
                                127.0.0.1 check.jupitersatellites.biz
                                127.0.0.1 www.checkin100.com
                                127.0.0.1 checkin100.com
                                127.0.0.1 www.checkssecurity.com
                                127.0.0.1 checkssecurity.com
                                127.0.0.1 chelancatering.com
                                127.0.0.1 www.chenshijituan.com
                                127.0.0.1 chenshijituan.com
                                127.0.0.1 childrenvilla.com
                                127.0.0.1 www.chilly3xvids.com
                                127.0.0.1 chilly3xvids.com
                                127.0.0.1 www.chillymovs.com
                                127.0.0.1 chillymovs.com
                                127.0.0.1 chips-4-free.com
                                127.0.0.1 chrisswasey.com
                                127.0.0.1 chriswallace.net
                                127.0.0.1 www.cia-trjn.myvnc.com
                                127.0.0.1 cia-trjn.myvnc.com
                                127.0.0.1 www.cinemadownload.com
                                127.0.0.1 cinemadownload.com
                                127.0.0.1 www.ciorriere.it
                                127.0.0.1 ciorriere.it
                                127.0.0.1 www.cirriere.it
                                127.0.0.1 cirriere.it
                                127.0.0.1 www.citycodec.com
                                127.0.0.1 citycodec.com
                                127.0.0.1 ckick4thumbs.com
                                127.0.0.1 cl55.biz
                                127.0.0.1 clackamasliteraryreview.com
                                127.0.0.1 www.clckm.com
                                127.0.0.1 clckm.com
                                127.0.0.1 www.cleancodec.com
                                127.0.0.1 cleancodec.com
                                127.0.0.1 www.cleansoftwares.com
                                127.0.0.1 cleansoftwares.com
                                127.0.0.1 clearsearch.cc
                                127.0.0.1 clearsearch.net
                                127.0.0.1 clickaire.com
                                127.0.0.1 www.click-codec.com
                                127.0.0.1 click-codec.com
                                127.0.0.1 www.clickhere4search.com
                                127.0.0.1 clickhere4search.com
                                127.0.0.1 www.click-new-download.com
                                127.0.0.1 click-new-download.com
                                127.0.0.1 click-now.net
                                127.0.0.1 www.clickspring.net
                                127.0.0.1 clickspring.net
                                127.0.0.1 www.click-to-download.com
                                127.0.0.1 click-to-download.com
                                127.0.0.1 www.clicktomakeasearch.com
                                127.0.0.1 clicktomakeasearch.com
                                127.0.0.1 clickyestoenter.net
                                127.0.0.1 client.exeupdate.com
                                127.0.0.1 client.myadultexplorer.com
                                127.0.0.1 www.cliks.org
                                127.0.0.1 cliks.org
                                127.0.0.1 www.clipsfestival.com
                                127.0.0.1 clipsfestival.com
                                127.0.0.1 www.clipsreality.com
                                127.0.0.1 clipsreality.com
                                127.0.0.1 www.clorriere.it
                                127.0.0.1 clorriere.it
                                127.0.0.1 clrsch.com
                                127.0.0.1 www.clubxxxvideo.com
                                127.0.0.1 clubxxxvideo.com
                                127.0.0.1 clusif.free.fr
                                127.0.0.1 cmtapestry.com
                                127.0.0.1 www.cnetadd.com
                                127.0.0.1 cnetadd.com
                                127.0.0.1 www.cnomy.com
                                127.0.0.1 cnomy.com
                                127.0.0.1 www.cnzz.com
                                127.0.0.1 cnzz.com
                                127.0.0.1 www.cocktails-ideen.de
                                127.0.0.1 cocktails-ideen.de
                                127.0.0.1 code.ignphrases.com
                                127.0.0.1 codec.ninoa.com
                                127.0.0.1 www.codecadult18.com
                                127.0.0.1 codecadult18.com
                                127.0.0.1 www.codecbest.com
                                127.0.0.1 codecbest.com
                                127.0.0.1 www.codecbsplay.com
                                127.0.0.1 codecbsplay.com
                                127.0.0.1 www.codecdemo.com
                                127.0.0.1 codecdemo.com
                                127.0.0.1 www.codecdvd.net
                                127.0.0.1 codecdvd.net
                                127.0.0.1 www.codecdvi.com
                                127.0.0.1 codecdvi.com
                                127.0.0.1 www.codec-fun.com
                                127.0.0.1 codec-fun.com
                                127.0.0.1 www.codechard.com
                                127.0.0.1 codechard.com
                                127.0.0.1 www.codechot.net
                                127.0.0.1 codechot.net
                                127.0.0.1 www.codechq.net
                                127.0.0.1 codechq.net
                                127.0.0.1 www.codecmeg.net
                                127.0.0.1 codecmeg.net
                                127.0.0.1 www.codecmega.com
                                127.0.0.1 codecmega.com
                                127.0.0.1 www.codecmega.net
                                127.0.0.1 codecmega.net
                                127.0.0.1 www.codecmoon.com
                                127.0.0.1 codecmoon.com
                                127.0.0.1 www.codecmpg.com
                                127.0.0.1 codecmpg.com
                                127.0.0.1 www.codecnice.net
                                127.0.0.1 codecnice.net
                                127.0.0.1 www.codecnitro.com
                                127.0.0.1 codecnitro.com
                                127.0.0.1 www.codecops.net
                                127.0.0.1 codecops.net
                                127.0.0.1 www.codecplay.com
                                127.0.0.1 codecplay.com
                                127.0.0.1 www.codecpretty.net
                                127.0.0.1 codecpretty.net
                                127.0.0.1 www.codecpro.net
                                127.0.0.1 codecpro.net
                                127.0.0.1 www.codecred.net
                                127.0.0.1 codecred.net
                                127.0.0.1 www.codecsoft.net
                                127.0.0.1 codecsoft.net
                                127.0.0.1 www.codecthe.com
                                127.0.0.1 codecthe.com
                                127.0.0.1 www.codectime.com
                                127.0.0.1 codectime.com
                                127.0.0.1 www.codecultra.net
                                127.0.0.1 codecultra.net
                                127.0.0.1 www.codecvids.com
                                127.0.0.1 codecvids.com
                                127.0.0.1 www.codecvip.com
                                127.0.0.1 codecvip.com
                                127.0.0.1 www.codecviva.com
                                127.0.0.1 codecviva.com
                                127.0.0.1 www.codeczang.net
                                127.0.0.1 codeczang.net
                                127.0.0.1 www.codrriere.it
                                127.0.0.1 codrriere.it
                                127.0.0.1 www.coeriere.it
                                127.0.0.1 coeriere.it
                                127.0.0.1 www.coerriere.it
                                127.0.0.1 coerriere.it
                                127.0.0.1 www.cofrriere.it
                                127.0.0.1 cofrriere.it
                                127.0.0.1 www.cogrriere.it
                                127.0.0.1 cogrriere.it
                                127.0.0.1 www.coirriere.it
                                127.0.0.1 coirriere.it
                                127.0.0.1 command.adservs.com
                                127.0.0.1 www.commonname.com
                                127.0.0.1 commonname.com
                                127.0.0.1 www.computerpcgames.net
                                127.0.0.1 computerpcgames.net
                                127.0.0.1 www.computerrecover.com
                                127.0.0.1 computerrecover.com
                                127.0.0.1 config.180solutions.com
                                127.0.0.1 www.content.dollarrevenue.com
                                127.0.0.1 content.dollarrevenue.com
                                127.0.0.1 www.content.ireit.com
                                127.0.0.1 content.ireit.com
                                127.0.0.1 content.onerateld.com
                                127.0.0.1 www.contentmatch.net
                                127.0.0.1 contentmatch.net
                                127.0.0.1 www.contextplus.net
                                127.0.0.1 contextplus.net
                                127.0.0.1 www.contra-virus.com
                                127.0.0.1 contra-virus.com
                                127.0.0.1 www.controlmeh.com
                                127.0.0.1 controlmeh.com
                                127.0.0.1 www.convenient-search.com
                                127.0.0.1 convenient-search.com
                                127.0.0.1 www.cookingluck.com
                                127.0.0.1 cookingluck.com
                                127.0.0.1 www.cooldeskalert.com
                                127.0.0.1 cooldeskalert.com
                                127.0.0.1 coolfetishsite.com
                                127.0.0.1 coolfreehost.com
                                127.0.0.1 coolfreepage.com
                                127.0.0.1 coolfreepages.com
                                127.0.0.1 cool-homepage.co
                                127.0.0.1 cool-homepage.com
                                127.0.0.1 coolmoneysearch.com
                                127.0.0.1 www.coolonlinebusiness.com
                                127.0.0.1 coolonlinebusiness.com
                                127.0.0.1 coolpornsearch.com
                                127.0.0.1 cool-search.net
                                127.0.0.1 cool-search.netfartpost.com
                                127.0.0.1 coolsearcher.info
                                127.0.0.1 www.coolservecorp.net
                                127.0.0.1 coolservecorp.net
                                127.0.0.1 www.coolwebsearch.com
                                127.0.0.1 coolwebsearch.com
                                127.0.0.1 cool-web-search.com
                                127.0.0.1 coolwebsearsh.com
                                127.0.0.1 www.coolwwwsearch.com
                                127.0.0.1 coolwwwsearch.com
                                127.0.0.1 cool-xxx.net
                                127.0.0.1 www.coorriere.it
                                127.0.0.1 coorriere.it
                                127.0.0.1 copmtraine.com
                                127.0.0.1 www.coprriere.it
                                127.0.0.1 coprriere.it
                                127.0.0.1 www.core.psyche-evolution.com
                                127.0.0.1 core.psyche-evolution.com
                                127.0.0.1 www.coreiere.it
                                127.0.0.1 coreiere.it
                                127.0.0.1 www.coreriere.it
                                127.0.0.1 coreriere.it
                                127.0.0.1 www.corrdiere.it
                                127.0.0.1 corrdiere.it
                                127.0.0.1 www.correiere.it
                                127.0.0.1 correiere.it
                                127.0.0.1 www.corrfiere.it
                                127.0.0.1 corrfiere.it
                                127.0.0.1 www.corrgiere.it
                                127.0.0.1 corrgiere.it
                                127.0.0.1 www.corridere.it
                                127.0.0.1 corridere.it
                                127.0.0.1 www.corriedre.it
                                127.0.0.1 corriedre.it
                                127.0.0.1 www.corriee.it
                                127.0.0.1 corriee.it
                                127.0.0.1 www.corrieere.it
                                127.0.0.1 corrieere.it
                                127.0.0.1 www.corriefre.it
                                127.0.0.1 corriefre.it
                                127.0.0.1 www.corriegre.it
                                127.0.0.1 corriegre.it
                                127.0.0.1 www.corrierde.it
                                127.0.0.1 corrierde.it
                                127.0.0.1 www.corriered.it
                                127.0.0.1 corriered.it
                                127.0.0.1 www.corrieree.it
                                127.0.0.1 corrieree.it
                                127.0.0.1 www.corrieref.it
                                127.0.0.1 corrieref.it
                                127.0.0.1 www.corrierer.it
                                127.0.0.1 corrierer.it
                                127.0.0.1 www.corrieres.it
                                127.0.0.1 corrieres.it
                                127.0.0.1 www.corrierew.it
                                127.0.0.1 corrierew.it
                                127.0.0.1 www.corrierfe.it
                                127.0.0.1 corrierfe.it
                                127.0.0.1 www.corrierge.it
                                127.0.0.1 corrierge.it
                                127.0.0.1 www.corrierr.it
                                127.0.0.1 corrierr.it
                                127.0.0.1 www.corrierre.it
                                127.0.0.1 corrierre.it
                                127.0.0.1 www.corrierse.it
                                127.0.0.1 corrierse.it
                                127.0.0.1 www.corrierte.it
                                127.0.0.1 corrierte.it
                                127.0.0.1 www.corrierw.it
                                127.0.0.1 corrierw.it
                                127.0.0.1 www.corrierwe.it
                                127.0.0.1 corrierwe.it
                                127.0.0.1 www.corriesre.it
                                127.0.0.1 corriesre.it
                                127.0.0.1 www.corriete.it
                                127.0.0.1 corriete.it
                                127.0.0.1 www.corrietre.it
                                127.0.0.1 corrietre.it
                                127.0.0.1 www.corriewre.it
                                127.0.0.1 corriewre.it
                                127.0.0.1 www.corrifere.it
                                127.0.0.1 corrifere.it
                                127.0.0.1 www.corriiere.it
                                127.0.0.1 corriiere.it
                                127.0.0.1 www.corrilere.it
                                127.0.0.1 corrilere.it
                                127.0.0.1 www.corrioere.it
                                127.0.0.1 corrioere.it
                                127.0.0.1 www.corrire.it
                                127.0.0.1 corrire.it
                                127.0.0.1 www.corrirere.it
                                127.0.0.1 corrirere.it
                                127.0.0.1 www.corrirre.it
                                127.0.0.1 corrirre.it
                                127.0.0.1 www.corrisere.it
                                127.0.0.1 corrisere.it
                                127.0.0.1 www.corriuere.it
                                127.0.0.1 corriuere.it
                                127.0.0.1 www.corriwere.it
                                127.0.0.1 corriwere.it
                                127.0.0.1 www.corriwre.it
                                127.0.0.1 corriwre.it
                                127.0.0.1 www.corrliere.it
                                127.0.0.1 corrliere.it
                                127.0.0.1 www.corroere.it
                                127.0.0.1 corroere.it
                                127.0.0.1 www.corroiere.it
                                127.0.0.1 corroiere.it
                                127.0.0.1 www.corrriere.it
                                127.0.0.1 corrriere.it
                                127.0.0.1 www.corrtiere.it
                                127.0.0.1 corrtiere.it
                                127.0.0.1 www.corruere.it
                                127.0.0.1 corruere.it
                                127.0.0.1 www.corruiere.it
                                127.0.0.1 corruiere.it
                                127.0.0.1 www.cortiere.it
                                127.0.0.1 cortiere.it
                                127.0.0.1 www.cortriere.it
                                127.0.0.1 cortriere.it
                                127.0.0.1 www.costrike.com
                                127.0.0.1 costrike.com
                                127.0.0.1 www.cotriere.it
                                127.0.0.1 cotriere.it
                                127.0.0.1 www.cotrriere.it
                                127.0.0.1 cotrriere.it
                                127.0.0.1 couldnotfind.com
                                127.0.0.1 count.cc
                                127.0.0.1 count.hitscount.net
                                127.0.0.1 count-all.com
                                127.0.0.1 www.countdutycall.info
                                127.0.0.1 countdutycall.info
                                127.0.0.1 counter.sexmaniack.com
                                127.0.0.1 www.courtrecordslookup.com
                                127.0.0.1 courtrecordslookup.com
                                127.0.0.1 www.cporriere.it
                                127.0.0.1 cporriere.it
                                127.0.0.1 www.cprriere.it
                                127.0.0.1 cprriere.it
                                127.0.0.1 cpvfeed.com
                                127.0.0.1 cracks.me.uk
                                127.0.0.1 www.cracks4all.com
                                127.0.0.1 cracks4all.com
                                127.0.0.1 www.crapsgold.info
                                127.0.0.1 crapsgold.info
                                127.0.0.1 www.crazygirls-world.com
                                127.0.0.1 crazygirls-world.com
                                127.0.0.1 www.crazywinnings.com
                                127.0.0.1 crazywinnings.com
                                127.0.0.1 creamedcutties.com
                                127.0.0.1 www.createaccesskey.com
                                127.0.0.1 createaccesskey.com
                                127.0.0.1 www.creatonsoft.com
                                127.0.0.1 creatonsoft.com
                                127.0.0.1 creditsearchonline.com
                                127.0.0.1 crestring.com
                                127.0.0.1 crooder.com
                                127.0.0.1 www.crriere.it
                                127.0.0.1 crriere.it
                                127.0.0.1 www.cryptdrive.com
                                127.0.0.1 cryptdrive.com
                                127.0.0.1 www.crystalysmedia.com
                                127.0.0.1 crystalysmedia.com
                                127.0.0.1 www.csx.adservs.com
                                127.0.0.1 csx.adservs.com
                                127.0.0.1 cts.180solutions.com
                                127.0.0.1 www.cuisinartoven.com
                                127.0.0.1 cuisinartoven.com
                                127.0.0.1 www.curedc.info
                                127.0.0.1 curedc.info
                                127.0.0.1 www.curepcsolutions.com
                                127.0.0.1 curepcsolutions.com
                                127.0.0.1 curvedspaces.com
                                127.0.0.1 www.cutadult.com
                                127.0.0.1 cutadult.com
                                127.0.0.1 www.cvirgilio.it
                                127.0.0.1 cvirgilio.it
                                127.0.0.1 www.cvorriere.it
                                127.0.0.1 cvorriere.it
                                127.0.0.1 cvs.jps.ru
                                127.0.0.1 cvsymphony.com
                                127.0.0.1 www.cxorriere.it
                                127.0.0.1 cxorriere.it
                                127.0.0.1 www.cyberrape.com
                                127.0.0.1 cyberrape.com
                                127.0.0.1 cydom.com
                                127.0.0.1 www.cydoor.com
                                127.0.0.1 cydoor.com
                                127.0.0.1 www.daily3xlinks.com
                                127.0.0.1 daily3xlinks.com
                                127.0.0.1 www.dailybestclips.com
                                127.0.0.1 dailybestclips.com
                                127.0.0.1 daily-gals.com
                                127.0.0.1 www.dailyhugemovs.com
                                127.0.0.1 dailyhugemovs.com
                                127.0.0.1 www.dailykeys.com
                                127.0.0.1 dailykeys.com
                                127.0.0.1 www.dailypornmag.com
                                127.0.0.1 dailypornmag.com
                                127.0.0.1 dailyteenspic.com
                                127.0.0.1 www.dailytoolbar.com
                                127.0.0.1 dailytoolbar.com
                                127.0.0.1 www.dailyxvids.com
                                127.0.0.1 dailyxvids.com
                                127.0.0.1 dancingbabycd.com
                                127.0.0.1 www.dapsol.com
                                127.0.0.1 dapsol.com
                                127.0.0.1 www.dapsolution.com
                                127.0.0.1 dapsolution.com
                                127.0.0.1 www.data-hoster.com
                                127.0.0.1 data-hoster.com
                                127.0.0.1 datanotary.com
                                127.0.0.1 datareco.com
                                127.0.0.1 www.dateanybabe.com
                                127.0.0.1 dateanybabe.com
                                127.0.0.1 www.dateanychick.com
                                127.0.0.1 dateanychick.com
                                127.0.0.1 www.datingdoctorsite.com
                                127.0.0.1 datingdoctorsite.com
                                127.0.0.1 www.dating-galaxy.info
                                127.0.0.1 dating-galaxy.info
                                127.0.0.1 dating-search.net
                                127.0.0.1 davemarshall.org
                                127.0.0.1 db105.com
                                127.0.0.1 www.dbdecicated.com
                                127.0.0.1 dbdecicated.com
                                127.0.0.1 www.dbxcompany.com
                                127.0.0.1 dbxcompany.com
                                127.0.0.1 dcdl.dmcast.com
                                127.0.0.1 dcfitusa.com
                                127.0.0.1 www.dcorriere.it
                                127.0.0.1 dcorriere.it
                                127.0.0.1 www.dcurtis.com
                                127.0.0.1 dcurtis.com
                                127.0.0.1 dcww.dmcast.com
                                127.0.0.1 de.ag
                                127.0.0.1 de.drivecleaner.com
                                127.0.0.1 de.errorsafe.com
                                127.0.0.1 de.winantivirus.com
                                127.0.0.1 de98.remsys.org
                                127.0.0.1 www.debay.it
                                127.0.0.1 debay.it
                                127.0.0.1 www.decknews.com
                                127.0.0.1 decknews.com
                                127.0.0.1 dedmazay.3322.org
                                127.0.0.1 www.dedsearch.com
                                127.0.0.1 dedsearch.com
                                127.0.0.1 defaultsearch.net
                                127.0.0.1 www.defensaantimalware.com
                                127.0.0.1 defensaantimalware.com
                                127.0.0.1 www.deja-rue.com
                                127.0.0.1 deja-rue.com
                                127.0.0.1 www.delficodec.com
                                127.0.0.1 delficodec.com
                                127.0.0.1 www.democodec.com
                                127.0.0.1 democodec.com
                                127.0.0.1 www.derklaif.biz
                                127.0.0.1 derklaif.biz
                                127.0.0.1 www.derrari.it
                                127.0.0.1 derrari.it
                                127.0.0.1 desarrollocreativo.com
                                127.0.0.1 www.deskbar.worldtostart.com
                                127.0.0.1 deskbar.worldtostart.com
                                127.0.0.1 www.deskwizz.com
                                127.0.0.1 deskwizz.com
                                127.0.0.1 www.destroy-spyware.net
                                127.0.0.1 destroy-spyware.net
                                127.0.0.1 www.destruktor.to.pl
                                127.0.0.1 destruktor.to.pl
                                127.0.0.1 www.detectivehound.com
                                127.0.0.1 detectivehound.com
                                127.0.0.1 www.detectivesearches.com
                                127.0.0.1 detectivesearches.com
                                127.0.0.1 dev.ntcor.com
                                127.0.0.1 develip.com
                                127.0.0.1 dewis.spb.ru
                                127.0.0.1 dewis.us
                                127.0.0.1 df809jow4wj2304lfd0sf9fsd0a2t4ldf809jow4wj2304lfd0sf9fsd0a2t4ld.biz
                                127.0.0.1 www.dgbusiness.com
                                127.0.0.1 dgbusiness.com
                                127.0.0.1 dialer2004.com
                                127.0.0.1 www.dialerclub.com
                                127.0.0.1 dialerclub.com
                                127.0.0.1 www.dialer-shop.com
                                127.0.0.1 dialer-shop.com
                                127.0.0.1 www.dialoff.com
                                127.0.0.1 dialoff.com
                                127.0.0.1 www.did.i-used.cc
                                127.0.0.1 did.i-used.cc
                                127.0.0.1 dietpills4free.com
                                127.0.0.1 dietpussy.com
                                127.0.0.1 www.digikeygen.com
                                127.0.0.1 digikeygen.com
                                127.0.0.1 digistreamsa.com
                                127.0.0.1 www.digitalcoders.net
                                127.0.0.1 digitalcoders.net
                                127.0.0.1 www.digitalfan.com
                                127.0.0.1 digitalfan.com
                                127.0.0.1 digital-pornography.com
                                127.0.0.1 dionforvalleycouncil.org
                                127.0.0.1 www.directdvdpro.com
                                127.0.0.1 directdvdpro.com
                                127.0.0.1 www.directnameservice.com
                                127.0.0.1 directnameservice.com
                                127.0.0.1 www.directporta.info
                                127.0.0.1 directporta.info
                                127.0.0.1 www.directsearchzone.com
                                127.0.0.1 directsearchzone.com
                                127.0.0.1 www.diskretter.com
                                127.0.0.1 diskretter.com
                                127.0.0.1 dist.checkin100.com
                                127.0.0.1 dl.ad-ware.cc
                                127.0.0.1 dl.malwarewipe.com
                                127.0.0.1 dl.mcboo.com
                                127.0.0.1 www.dl.targetsaver.com
                                127.0.0.1 dl.targetsaver.com
                                127.0.0.1 dl.web-nexus.net
                                127.0.0.1 dl1.antivermins.com
                                127.0.0.1 dl1.antivirgear.com
                                127.0.0.1 dl1.spydawn.com
                                127.0.0.1 dl1.virusprotectpro.com
                                127.0.0.1 dl10.spyfalcon.com
                                127.0.0.1 dl16.spyfalcon.com
                                127.0.0.1 dl2.spyfalcon.com
                                127.0.0.1 dl2.spyheal.com
                                127.0.0.1 dl2.spywarestrike.com
                                127.0.0.1 dl3.spyfalcon.com
                                127.0.0.1 dl3.spyheal.com
                                127.0.0.1 dl3.spywarestrike.com
                                127.0.0.1 dl4.spyfalcon.com
                                127.0.0.1 dl4.spywarestrike.com
                                127.0.0.1 dl5.spyfalcon.com
                                127.0.0.1 dl5.spywarestrike.com
                                127.0.0.1 dl6.spywarestrike.com
                                127.0.0.1 dl7.spywarestrike.com
                                127.0.0.1 dl8.spyheal.com
                                127.0.0.1 dl8.spywarestrike.com
                                127.0.0.1 dl9.spyfalcon.com
                                127.0.0.1 dload.contextplus.net
                                127.0.0.1 www.dltsolution.com
                                127.0.0.1 dltsolution.com
                                127.0.0.1 www.dmcast.com
                                127.0.0.1 dmcast.com
                                127.0.0.1 www.dmqfirm.com
                                127.0.0.1 dmqfirm.com
                                127.0.0.1 www.dnaads.com
                                127.0.0.1 dnaads.com
                                127.0.0.1 dnl.mabou.org
                                127.0.0.1 www.dns-look-up.com
                                127.0.0.1 dns-look-up.com
                                127.0.0.1 doctorwaldron.com
                                127.0.0.1 document-not-found.pornpic.org
                                127.0.0.1 doggyaction.com
                                127.0.0.1 www.dogproblemswebsite.com
                                127.0.0.1 dogproblemswebsite.com
                                127.0.0.1 doktorxxx.com
                                127.0.0.1 dollarrevenue.com
                                127.0.0.1 www.domaincar.com
                                127.0.0.1 domaincar.com
                                127.0.0.1 domains2003.net
                                127.0.0.1 domains-for-you-online.com
                                127.0.0.1 domain-your-registration.com
                                127.0.0.1 domkrat.com
                                127.0.0.1 www.doofo.com
                                127.0.0.1 doofo.com
                                127.0.0.1 www.dotcomtoolbar.com
                                127.0.0.1 dotcomtoolbar.com
                                127.0.0.1 down.136136.net
                                127.0.0.1 download.abetterinternet.com
                                127.0.0.1 download.adintelligence.net
                                127.0.0.1 www.download.antispywarebot.com
                                127.0.0.1 download.antispywarebot.com
                                127.0.0.1 www.download.bardownload.com
                                127.0.0.1 download.bardownload.com
                                127.0.0.1 www.download.bravesentry.com
                                127.0.0.1 download.bravesentry.com
                                127.0.0.1 download.cdn.drivecleaner.com
                                127.0.0.1 download.cdn.errorsafe.com
                                127.0.0.1 download.cdn.winsoftware.com
                                127.0.0.1 download.contextplus.net
                                127.0.0.1 download.errorsafe.com
                                127.0.0.1 www.download.jupitersatellites.biz
                                127.0.0.1 download.jupitersatellites.biz
                                127.0.0.1 download.malwarealarm.com
                                127.0.0.1 download.searchtabs.net
                                127.0.0.1 www.download.secureyournet.biz
                                127.0.0.1 download.secureyournet.biz
                                127.0.0.1 download.spyonthis.net
                                127.0.0.1 download.spy-shredder.com
                                127.0.0.1 download.systemdoctor.com
                                127.0.0.1 download.winantispyware.com
                                127.0.0.1 download.winantivirus.com
                                127.0.0.1 download.windrivecleaner.com
                                127.0.0.1 download.winfixer.com
                                127.0.0.1 download10.spywarequake.com
                                127.0.0.1 download11.spywarequake.com
                                127.0.0.1 download12.spywarequake.com
                                127.0.0.1 download13.spywarequake.com
                                127.0.0.1 download15.spywarequake.com
                                127.0.0.1 download2.spywarequake.com
                                127.0.0.1 www.download-2007.com
                                127.0.0.1 download-2007.com
                                127.0.0.1 download3.spyaxe.com
                                127.0.0.1 download3.spywarequake.com
                                127.0.0.1 www.download3xpics.com
                                127.0.0.1 download3xpics.com
                                127.0.0.1 download4.spyaxe.com
                                127.0.0.1 download4.spywarequake.com
                                127.0.0.1 download5.spyaxe.com
                                127.0.0.1 download5.spywarequake.com
                                127.0.0.1 download6.spyaxe.com
                                127.0.0.1 download7.spywarequake.com
                                127.0.0.1 download8.spywarequake.com
                                127.0.0.1 download9.spywarequake.com
                                127.0.0.1 www.downloadaccele
                                0
                                1. Contributeur sécurité
                                  Option 2

                                  Redémarre en mode sans échec :
                                  Pour cela, tapotes la touche F8 (Si F8 ne marche pas utilise la touche F5).

                                  dès le début de l’allumage du pc sans t’arrêter.
                                  Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                                  Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !

                                  TUTO Mode sans Echec
                                  -------------------------------------------------------------------------------
                                  clic droit sur smitfraudfix.cmd > <gras>executer en tant qu' Admnin'

                                  Cette fois choisit l’option 2,
                                  répond oui (o) à tout

                                  Une fois le nettoyage terminé, SmitFraudfix ouvre le rapport de nettoyage sur le bloc-note.
                                  Redémarre l'ordinateur en mode normal (comme d'habitude),
                                  Sur le bureau doit se trouver le rapport enregistré (sinon il est sur le Poste de Travail / Disque C / rapport.txt)
                                  Refais un log Hitjackthis et poste les rapports s'il te plait !
                                  0
                                  1. SmitFraudFix v2.378

                                    Scan done at 22:50:36,43, 25/11/2008
                                    Run from C:\SmitfraudFix
                                    OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                                    The filesystem type is
                                    Fix run in normal mode

                                    »»»»»»»»»»»»»»»»»»»»»»»» Process

                                    C:\Windows\system32\csrss.exe
                                    C:\Windows\system32\wininit.exe
                                    C:\Windows\system32\csrss.exe
                                    C:\Windows\system32\winlogon.exe
                                    C:\Windows\system32\services.exe
                                    C:\Windows\system32\lsass.exe
                                    C:\Windows\system32\lsm.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\nvvsvc.exe
                                    C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                                    C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\system32\SLsvc.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\system32\rundll32.exe
                                    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                    C:\Windows\system32\WLANExt.exe
                                    C:\Windows\system32\uesiuqcr.exe
                                    C:\Windows\system32\Dwm.exe
                                    C:\Windows\Explorer.EXE
                                    C:\Windows\System32\spoolsv.exe
                                    C:\Windows\system32\taskeng.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                                    C:\Program Files\Orange\Systray\SystrayApp.exe
                                    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                    C:\Windows\System32\rundll32.exe
                                    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                                    C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
                                    C:\Program Files\Windows Sidebar\sidebar.exe
                                    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                    C:\Users\Gauthier\AppData\Local\Temp\csrssc.exe
                                    C:\Program Files\Logitech\SetPoint\SetPoint.exe
                                    C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                                    C:\Program Files\Windows Sidebar\sidebar.exe
                                    C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
                                    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                    C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                    C:\Windows\system32\PnkBstrA.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                    C:\Windows\system32\svchost.exe
                                    C:\Windows\System32\svchost.exe
                                    C:\Windows\system32\SearchIndexer.exe
                                    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                    C:\Windows\system32\taskeng.exe
                                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                    C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                                    C:\Program Files\Windows Live\Messenger\usnsvc.exe
                                    C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
                                    C:\Windows\system32\wuauclt.exe
                                    C:\Program Files\Mozilla Firefox\firefox.exe
                                    C:\Windows\System32\cmd.exe
                                    C:\Windows\system32\conime.exe
                                    C:\Windows\system32\wbem\wmiprvse.exe

                                    »»»»»»»»»»»»»»»»»»»»»»»» hosts

                                    hosts file corrupted !

                                    127.0.0.1 www.legal-at-spybot.info
                                    127.0.0.1 legal-at-spybot.info

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                                    C:\Windows\default.htm FOUND !
                                    C:\Windows\Tasks\At?.job FOUND !
                                    C:\Windows\Tasks\At??.job FOUND !

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Gauthier

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Gauthier\AppData\Local\Temp

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Gauthier\Application Data

                                    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\Gauthier\FAVORI~1

                                    »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                                    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                                    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                                    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                                    »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                                    !!!Attention, following keys are not inevitably infected!!!

                                    o4Patch
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                                    !!!Attention, following keys are not inevitably infected!!!

                                    »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                                    !!!Attention, following keys are not inevitably infected!!!

                                    VACFix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                                    !!!Attention, following keys are not inevitably infected!!!

                                    404Fix
                                    Credits: Malware Analysis & Diagnostic
                                    Code: S!Ri

                                    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                                    !!!Attention, following keys are not inevitably infected!!!

                                    SrchSTS.exe by S!Ri
                                    Search SharedTaskScheduler's .dll

                                    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                                    !!!Attention, following keys are not inevitably infected!!!

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                                    "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~3\\GOEC62~1.DLL"
                                    "LoadAppInit_DLLs"=dword:00000001

                                    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                                    !!!Attention, following keys are not inevitably infected!!!

                                    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                                    "Userinit"="C:\\Windows\\system32\\userinit.exe,C:\\Windows\\system32\\uesiuqcr.exe,"

                                    »»»»»»»»»»»»»»»»»»»»»»»» RK

                                    »»»»»»»»»»»»»»»»»»»»»»»» DNS

                                    Description: Intel(R) PRO/Wireless 3945ABG Network Connection
                                    DNS Server Search Order: 192.168.1.1

                                    HKLM\SYSTEM\CCS\Services\Tcpip\..\{CF0C3717-B005-4771-A1C1-08011CA25074}: DhcpNameServer=192.168.1.1

                                    »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                                    »»»»»»»»»»»»»»»»»»»»»»»» End
                                    0
                                    1. Contributeur sécurité
                                      Veille à ce que le contrôle des comptes utilisateurs (UAC) soit désactivé.
                                      Démarrer > Panneau de configuration > Choisis l'affichage classique sur la gauche et double-clique sur Comptes d'utilisateurs.
                                      Clique ensuite sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
                                      L'UAC demandera une confirmation (la dernière !), clique sur le bouton Continuer.
                                      Dans la nouvelle fenêtre venant de s'ouvrir, décoche la case "Utiliser le contrôle des comptes d'utilisateurs"
                                      clique sur OK.
                                      Afin que les changements soient effectifs, il te sera demandé de redémarrer l'ordinateur.

                                      Télécharge SmitfraudFix
                                      Utilitaire de S!Ri: Moe et balltrap34

                                      Installe le à la racine de C : Tuto d'utilisation
                                      Clique droit sur l'exe ( executer en tant qu'administrateur ) pour le décompresser et lancer le fix.
                                      Utilisation option 1 Recherche :
                                      Clique droit sur smitfraudfix.cmd
                                      Sélectionne 1 pour créer un rapport des fichiers responsables de l'infection.

                                      Ne fais rien d'autre sans notre avis

                                      Copie/colle le RAPPORT sur ta prochaine réponse sur ce post stp.

                                      Process.exe est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
                                      Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
                                      Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.
                                      0
                                      1. Logfile of Trend Micro HijackThis v2.0.2
                                        Scan saved at 21:09:10, on 25/11/2008
                                        Platform: Windows Vista (WinNT 6.00.1904)
                                        MSIE: Internet Explorer v7.00 (7.00.6000.16757)
                                        Boot mode: Normal

                                        Running processes:
                                        C:\Windows\system32\uesiuqcr.exe
                                        C:\Windows\system32\Dwm.exe
                                        C:\Windows\Explorer.EXE
                                        C:\Windows\system32\taskeng.exe
                                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
                                        C:\Program Files\Orange\Systray\SystrayApp.exe
                                        C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
                                        C:\Windows\System32\rundll32.exe
                                        C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                                        C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
                                        C:\Program Files\Windows Sidebar\sidebar.exe
                                        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                                        C:\Users\Gauthier\AppData\Local\Temp\csrssc.exe
                                        C:\Program Files\Logitech\SetPoint\SetPoint.exe
                                        C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
                                        C:\Program Files\Windows Sidebar\sidebar.exe
                                        C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
                                        C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
                                        C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
                                        C:\Windows\system32\wuauclt.exe
                                        C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                                        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                                        R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                                        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                                        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange\SearchURLHook\SearchPageURL.dll
                                        R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
                                        F2 - REG:system.ini: UserInit=C:\Windows\system32\userinit.exe,C:\Windows\system32\uesiuqcr.exe,
                                        O1 - Hosts: ::1 localhost
                                        O2 - BHO: getfn32.msiets - {21A237A4-3A94-4198-911D-647ED2263DD2} - C:\Windows\system32\getfn32.dll
                                        O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
                                        O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
                                        O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                                        O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
                                        O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
                                        O4 - HKLM\..\Run: [SystrayORAHSS] "C:\Program Files\Orange\Systray\SystrayApp.exe"
                                        O4 - HKLM\..\Run: [ORAHSSSessionManager] C:\Program Files\Orange\SessionManager\SessionManager.exe
                                        O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
                                        O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                                        O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
                                        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                                        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                                        O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                                        O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
                                        O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
                                        O4 - HKLM\..\Run: [MSConfig] "C:\Windows\System32\msconfig.exe" /auto
                                        O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
                                        O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                                        O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\Users\Gauthier\AppData\Local\Temp\csrssc.exe
                                        O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                                        O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                                        O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
                                        O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
                                        O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                                        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
                                        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
                                        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~2.0_0\bin\ssv.dll
                                        O9 - Extra button: Livre de reliures HP - {58ECB495-38F0-49cb-A538-10282ABF65E7} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                                        O9 - Extra button: Sélection intelligente HP - {700259D7-1666-479a-93B1-3250410481E8} - C:\Program Files\HP\Smart Web Printing\hpswp_extensions.dll
                                        O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                        O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
                                        O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                                        O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                                        O13 - Gopher Prefix:
                                        O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.zebulon.fr/outils/antivirus/kavwebscan_unicode.cab
                                        O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://www.pandasecurity.com/activescan/cabs/as2stubie.cab
                                        O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.zebulon.fr/scan8/oscan8.cab
                                        O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
                                        O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) - https://www.f-secure.com/en/home/support
                                        O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
                                        O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
                                        O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
                                        O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
                                        O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
                                        O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
                                        O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                                        O23 - Service: FCI - Unknown owner - C:\Windows\system32\fci.exe.exe:ext.exe (file missing)
                                        O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom SA - C:\PROGRA~1\COMMON~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
                                        O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
                                        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
                                        O23 - Service: ICF - Unknown owner - C:\Windows\system32\icf.exe.exe:ext.exe (file missing)
                                        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                                        O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
                                        O23 - Service: BitDefender Desktop Update Service (LIVESRV) - BitDefender SRL - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe
                                        O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                                        O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                                        O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
                                        O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                                        O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe (file missing)
                                        O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                        O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                        O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
                                        O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
                                        O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
                                        O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                                        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                                        O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
                                        0
                                        1. Contributeur sécurité
                                          C'est ça que tu as ?

                                          http://img.bleepingcomputer.com/swr-guides/p/pc-protection-center-2008/pc-protection-center-2008.jpg

                                          Essaye de me poster un rapport HJT

                                          Ø Relance Hijackthis en double cliquant sur son raccourci sur le Bureau.
                                          Choisis l'option "Do a system scan and save a log file"
                                          Clique sur "Save log" pour enregistrer le rapport qui s'ouvrira avec le bloc-note
                                          Clique sur "Edition" ->> "Sélectionner tout", puis sur "Edition" ->> Copier" pour copier tout le contenu du rapport ici
                                          0
                                          • 1
                                          • 2