Unable to download Acrobat Reader

Hello everyone,

I have Windows XP Pro Version 2002 Service Pack 3. After a Zlob attack that I cleaned up well, my Acrobat Reader 8.1.2 started malfunctioning. As a result, I can no longer read PDF files or watch any videos on YouTube because I can't download Flash Player properly. I've tried several times to download the latest version (Flash Player 9), the site tells me it’s downloaded successfully but the Adobe Flash Player Plugin icon that appears on the list of programs in my Control Panel has a little red X in the corner and no size in MB...

To continue, I consulted forums that suggested uninstalling Acrobat and downloading it again afterward. Like a good soldier, I uninstalled Acrobat from my computer and now I can't download it from anywhere!!! Every time I try to do it, I get a weird error message telling me that my computer is running Windows 2000 (!!??) and that I need to upgrade my computer to Windows 2000 SP 4 (!!??) in order to download Adobe Reader 8.1.2. I don’t understand this story at all and would like to know if anyone could help me...

As a side note, I downloaded Foxit Reader to read PDF files; I was still able to download Adobe Air and Adobe Media Player (which did not resolve my problem with watching videos on YouTube!!). And in case someone thinks to ask me, I have Java properly installed on my computer (even got the latest update!!, yes sir!)

So... HELP!!!!!!!

AND THANK YOU IN ADVANCE!

CP12
Configuration: Windows XP Internet Explorer 7.0

74 answers

  1. Hi,
    A Windows 2000 version (!!??) and that I have to upgrade my computer to Windows 2000 SP 4
    SP4 for Windows 2000 is almost mandatory, we can't do anything without it. We just need to find SP4 for Windows 2000. However, I don't know if it's available for direct update since it's old and usually people have stored it directly on their hard drive.
    For Acrobat, they are probably in security maintenance. There were issues, and they closed some downloads. They are also working on releasing new online products.
    0
    1. Thank you for your advice, Rebitus!

      I'm going to check the Windows Update site to see what I can find about W 2000 SP4, and I'll keep you posted if it allows me to download Acrobat.

      (I hope that the inability to download the latest version of this software is due to what you mentioned about their site)

      See you!

      Catpeople12
      0
    2. Hello Rebitus and everyone who might help me!

      I found Windows 2000 SP4 on the Windows Update site thanks to Rebitus's advice, for which I am grateful.

      I started downloading it but before the download finished, the following error message appeared:

      The installer could not verify the integrity of the Update.inf file. Make sure the Cryptographic Service is running on this computer.

      So I went to check in the Control Panel / Administrative Tools / Services / Cryptographic Services and the properties indicate that it is Started as Automatic.

      So I have a problem! Right?

      But I don’t know what it is or how to fix it!!!.....

      HEEEEELP!!!!!
      0
  2. Re-hello everyone,

    I've also just realized that I can't even download Adobe Flash Player. The Adobe site keeps telling me that the download was successful, but the software is nowhere to be found on my computer.

    The only thing that's there is Java, which works perfectly.

    So either the Adobe site has issues, or my computer has a problem that I can't seem to identify! However, the computer's cryptography services are enabled, browsing the Internet and all displays on my computer are working very quickly as usual...

    Not being a tech expert, I really need help from someone who knows what they're doing...

    Thank you in advance everyone!

    Catpeople12
    0
    1. Hello everyone,

      I believe I know why I can't download Adobe. It's because my computer apparently no longer has SP4 for Windows 2000. I went looking for it on the Internet and the download started fine. But at the time of installation, I received the following error message:

      "The installer could not verify the integrity of the file Update.inf. Please make sure that the Cryptographic Service is running on this computer."

      According to the instructions given on this forum to those who have the same problem, I went to Control Panel => Administrative Tools => Services => Cryptographic Services, I looked for the service properties and it is enabled in automatic mode. I even restarted the service and rebooted the computer. But after another attempt to download SP4 for Win 2000, the same message appeared again! I don't understand what's happening...

      Can anyone please advise me on how to resolve this issue?

      Thank you!

      CP12
      0
      1. Hello everyone,
        a question for catpeople12,

        you say you're equipped with XP Pro SP3, I don't see why you're switching to XP 2000 + SP4 etc..
        please confirm which exact version you have on your machine, I will try to find you a solution
        see you later
        BOB3
        0
        1. Hi BOB3 and thanks for your reply.

          I am on Windows XP Pro Version 2002 Service Pack 3. I'm trying to download Win 2000 SP4 just because every time I've tried to download the latest version of Acrobat, I get a message saying something like "the version 2000 you are using does not accept this file. Please update to Windows 2000 sp4 before downloading it".

          I thought that Win 2000 SP4 was a necessary component for my system that would allow me to download the latest version of Acrobat. What do you think?

          At the same time, I can't even download the latest version of Acrobat Flash Player on my system, which prevents me from watching videos on YouTube.

          It would be great if you could find me a solution!

          THANK YOU and see you soon!

          catpeople12
          0
          1. Re catpeople12,

            forget win2000,

            restart in safe mode and try to completely uninstall ADOBE--you will reinstall it later.

            you will check the integrity of your XP files afterwards
            put your installation CD in the main CD drive
            click on start, run, and type: sfc /scannow
            look at the link
            https://www.pcastuces.com/pratique/windows/xp/default.htm
            and let it do its thing,
            restart,
            then you will run Microsoft onecare at this link
            https://www.msn.com/fr-fr/
            launch the link, accept the activex, and click on full scan.
            it will take some time, windows will clean everything and restore your registry.
            let it finish, reboot, and keep us updated.
            see you later
            BOB3
            0
            1. Hi BOB3!

              I will follow your instructions and I'll let you know as soon as I'm done.

              THANK YOU SO MUCH!!

              See you!

              catpeople12
              0
            2. Re BOB3,

              The first part of your instructions worked like a charm (Thank you!)! I indeed had corrupted .dll files due to a Trojan horse (Zlob) that I caught a week ago (despite my Kaspersky) and I was able to remove it by following recommendations on this Forum. So all the damaged protected files have been repaired or restored with my XP CDROM. I also completely removed Adobe from my computer. I owe you one big time!

              However, something strange is happening with the second link to Windows Onecare that you gave me. When I click on Full Scan to start the scanner, a dialog window that shows the status of the scan appears. But shortly after, a small dialog box pops up in the Onecare window telling me that there was a script error on the page with Explorer and if I still want to continue. I click Yes and the W. Onecare window turns into just a frame with only the borders and won’t close; I can only minimize it... To make it disappear I have to restart the computer. I reconnect to Onecare, try again and the same thing happens... I have no indication that something is happening...

              Not being very familiar with W. Onecare, could you tell me if this is normal? I think there must be a glitch, but I’m not a tech whiz...

              Looking forward to your advice and thanking you again for your help, I send you my best regards.

              catpeople12
              0
          2. Good evening catpeople12,

            I’m glad you were able to repair your system files,
            the script error is related to your IE7 browser, I hope it’s not damaged.
            Open Internet Explorer properties,
            1--in General, then the 2 settings for searches + tabs, click on settings and set to default.
            2--in Security, set everything to default
            3--in Privacy, set it to default to automatically accept Microsoft cookies-----I recommend afterwards setting it to High
            4--in Advanced, click on Restore advanced settings --- only.

            And try to connect to oncare again.
            See you later
            BOB3
            0
            1. Hello BOB3,

              Thanks again for your great advice!!!

              I followed your instructions regarding IE7, and the same thing happened when I tried to download the onecare scanner to start the full analysis... A script error occurred, and then it started spinning with no response. I had to disable the page using the task manager.... However, I added onecare as a trusted site in IE7 and Kaspersky...

              Maybe IE7 is damaged as you think, and I don't know how to fix it if that's the case...

              Could you help me again, please?

              Thanks!

              catpeople12
              0
          3. Hello catpeople12,

            download IE7 again, install it + update without forgetting to reconfigure as specified in 11

            http://www.microsoft.com/downloads/details.aspx?FamilyId=9AE91EBE-3385-447C-8A30-081805B2F90B&displaylang=en

            go to onecare again, and do a full scan.
            keep me updated.
            BOB3
            0
            1. Good evening BOB3,

              Alright! Reporting in... I downloaded IE7 again and everything went well. All its settings are also set to default according to your advice. (Anyway, with the download everything comes by default)

              However, the problem with Onecare persists nonetheless... Still the same old script error on the page that blocks everything and prevents me from running the full scan... I don't know what to do anymore!... I’m starting to believe that this site doesn't like my computer, even if my computer trusts it...

              Do you have another idea up your sleeve?...

              Thank you once again for your help, and best regards,

              catpeople12
              0
          4. Good evening catpeople,

            go to the control panel, click on Java, update it,
            still on Java, disable the auto-update, and in Advanced,
            then, for Java defaults in browsers, set it to Internet Explorer.
            reboot, and in Internet Explorer properties, open Advanced, scroll down,
            under Browsing, check both boxes ----disable script debugging
            we'll see.
            see you+
            BOB3
            0
            1. Hello BOB3

              I went to Java. I clicked on update now but it tells me that I have the very latest version of Java installed on my computer which is functioning. I disabled automatic updates but Internet Explorer was already checked as the default browser on Java.

              Then I rebooted and went to Internet Properties/Advanced/Navigation. The two script debugging boxes were already checked.

              I will try again with Onecare and keep you posted.

              THANKS again!

              catpeople12
              0
            2. Re BOB3!

              Well, after following the instructions for Java and IE, it still doesn't work... There is still that damned script error on the page and I have to close it with Task Manager...

              It's crazy!!!!! ... ...

              Looking forward to your advice, thank you again and best regards,

              catpeople12
              0
          5. Hi catpeople,
            repost the exact message that the system gives you when you're on one care.
            cya
            BOB3
            0
            1. Hello BOB3!

              Here is the exact message:

              !
              An error occurred in the script on this page
              Line: 26
              Character : 1
              Error: Object expected
              Code: 0
              URL: about: blank

              Do you want to continue executing scripts on this page?

              Yes No


              Whether I click Yes or No doesn't change anything; it's just spinning and I have nothing left...

              I hope this helps you figure out where it's coming from.

              Thanks again and

              See you later

              catpeople12
              0
          6. Re catpeople,
            download Hijackthis from this link, install it in auto mode,
            ftp://ftp.commentcamarche.com/download/HJTInstall.exe

            click on its icon on the desktop, and do: Do a system scan and save logfile
            copy/paste in the post
            see you later
            BOB3
            0
            1. Hello BOB3,

              Here is the scan result:

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 08:58:44, on 07/07/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16674)
              Boot mode: Normal

              Running processes:
              C:\windows\System32\smss.exe
              C:\windows\system32\winlogon.exe
              C:\windows\system32\services.exe
              C:\windows\system32\lsass.exe
              C:\windows\System32\Ati2evxx.exe
              C:\windows\system32\svchost.exe
              C:\windows\System32\svchost.exe
              C:\windows\system32\Ati2evxx.exe
              C:\WINDOWS\System32\brsvc01a.exe
              C:\windows\Explorer.EXE
              C:\WINDOWS\System32\brss01a.exe
              C:\windows\system32\spoolsv.exe
              C:\windows\SOUNDMAN.EXE
              C:\Program Files\VIA\RAID\raid_tool.exe
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\Program Files\QuickTime\qttask.exe
              C:\Program Files\Logitech\Video\LogiTray.exe
              C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
              C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
              C:\Program Files\Windows Media Player\WMPNSCFG.exe
              C:\Program Files\yodm 3D\Yodm3D.exe
              C:\Program Files\Messenger\msmsgs.exe
              C:\PROGRA~1\MI3AA1~1\wcescomm.exe
              C:\windows\system32\ctfmon.exe
              C:\PROGRA~1\MI3AA1~1\rapimgr.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\windows\system32\cisvc.exe
              C:\windows\System32\svchost.exe
              C:\WINDOWS\system32\LVComS.exe
              C:\WINDOWS\system32\inetsrv\inetinfo.exe
              C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
              C:\WINDOWS\system32\PSIService.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
              C:\windows\system32\svchost.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
              C:\Program Files\Windows Live\Messenger\usnsvc.exe
              C:\windows\system32\cidaemon.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: (no name) - {9989F1F6-70DE-4244-AC9F-6672983681A0} - (no file)
              O2 - BHO: (no name) - {A49E097A-D6EF-4B2F-8B0F-1230E998587F} - C:\Program Files\Web Technologies\iebt.dll (file missing)
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O2 - BHO: 238044 helper - {C0F371D7-926D-4700-B65E-63BFF1197205} - C:\WINDOWS\system32\238044\238044.dll (file missing)
              O3 - Toolbar: Internet Service - {F99D0C20-F8E1-43B6-AB24-3F16BFAEA77B} - C:\Program Files\Web Technologies\iebr.dll (file missing)
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
              O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
              O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [Yodm3D] C:\Program Files\yodm 3D\Yodm3D.exe
              O4 - HKCU\..\Run: [Free Download Manager] C:\Program Files\Free Download Manager\fdm.exe -autorun
              O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
              O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
              O4 - HKCU\..\Run: [I&F Viewer toolbar] "C:\Program Files\Photo Toolkit\ivbar\phototoolkitmem.exe" -start
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
              O4 - Startup: MyTrashCan.lnk = C:\Program Files\Hiro's tool\MyTrashCan\MyTrashCan.exe
              O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
              O8 - Extra context menu item: Add to Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O9 - Extra 'Tools' menuitem: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll
              O9 - Extra button: Internet Security Statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra 'Tools' menuitem: Create a mobile favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
              O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11D2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
              O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
              O15 - Trusted Zone: http://www.1001interims.com
              O15 - Trusted Zone: https://www.adobe.com/
              O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
              O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
              O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
              O15 - Trusted Zone: https://www.ustart.org
              O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
              O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
              O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
              O15 - Trusted Zone: https://www.msn.com/fr-fr/
              O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
              O15 - Trusted Zone: https://fr.yahoo.com/
              O15 - Trusted Zone: https://www.youtube.com/
              O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
              O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
              O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
              O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.serviceshub.microsoft.com/supportforbusiness/create
              O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
              O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPUpld.cab
              O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
              O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-e84a02c34e2ab3f9.spaces.live.com/PhotoUpload/MsnPUpld.cab
              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
              O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD42/JSCDL/jre/6u6-b90/jinstall-6u6-windows-i586-jc.cab?e=1214407856230&h=460b6a4386982a6d227dd6ec47e07839/&filename=jinstall-6u6-windows-i586-jc.cab
              O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
              O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
              O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
              O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: MicroSoft Media Tools - Unknown owner - C:\WINDOWS\MSmedia.exe (file missing)
              O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
              O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

              --
              End of file - 12393 bytes

              Hoping this report will help you find the problem and thanking you again for your help,

              catpeople12
              0
          7. Hello catpeople12,
            A good number of problems to fix

            Download Ccleaner, install it without the YAHOO toolbar
            in applications check everything
            Launch it and perform a complete cleanup: cleaner then registry

            1---To start, you will uninstall to fix a disorder in the registry
            windows live messenger, you will reinstall it later without the ads sponsors.
            windows live onecare
            logitech webcam---you will reinstall it later

            2--You have a proxy service that needs to be disabled
            in internet explorer properties, then connections, network settings, and disable everything

            3--Go to start, control panel, regional and language options, languages, details, advanced,
            and check to stop advanced text services.

            4--Launch msconfig.exe, then startup, and if it exists, disable
            ctfmon.exe
            LVComS.exe

            Restart your computer in safe mode,
            launch Hijackthis in Do a system Scan
            check the following keys, then click at the bottom left on: Fix Checked
            C:\WINDOWS\system32\LVComS.exe

            O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\eoRezo\EoAdv\EOREZO~1.DLL (file missing)
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

            O2 - BHO: (no name) - {9989F1F6-70DE-4244-AC9F-6672983681A0} - (no file)

            O2 - BHO: (no name) - {A49E097A-D6EF-4B2F-8B0F-1230E998587F} - C:\Program Files\Web Technologies\iebt.dll (file missing)
            O2 - BHO: 238044 helper - {C0F371D7-926D-4700-B65E-63BFF1197205} - C:\WINDOWS\system32\238044\238044.dll (file missing)
            O3 - Toolbar: Internet Service - {F99D0C20-F8E1-43B6-AB24-3F16BFAEA77B} - C:\Program Files\Web Technologies\iebr.dll (file missing)

            O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE

            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe

            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

            O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [Yodm3D] C:\Program Files\yodm 3D\Yodm3D.exe
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\windows\system32\ctfmon.exe
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
            O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
            O4 - Startup: MyTrashCan.lnk = C:\Program Files\Hiro's tool\MyTrashCan\MyTrashCan.exe
            O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
            O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll

            O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
            O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.serviceshub.microsoft.com/supportforbusiness/create
            O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
            O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.serviceshub.microsoft.com/supportforbusiness/create
            O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - https://www.linkedin.com/cab/LinkedInContactFinderControl.cab
            O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107w.bay107.mail.live.com/mail/resources/MsnPUpld.cab
            O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab
            O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/default.aspx
            O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://cid-e84a02c34e2ab3f9.spaces.live.com/PhotoUpload/MsnPUpld.cab
            O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/
            O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
            O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
            O23 - Service: MicroSoft Media Tools - Unknown owner - C:\WINDOWS\MSmedia.exe (file missing)
            O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)

            Launch Ccleaner, perform a complete cleanup

            Reboot in normal mode, and reinstalls a new Hijackthis log.
            See you later
            BOB3
            0
            1. Re-BOB3 and THANK you again for your help!

              I followed your instructions to the letter. Before I submit the new Hijackthis log, and in case it might be important, I want to inform you that after the System Scan of Hijackthis in Safe Mode, the following keys were missing from the list, which appeared on the one you previously told me to check:

              C:\WINDOWS\system32\LVComS.exe
              O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
              O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab

              Once the found keys were checked, I clicked Fix Checked and during the process, the following message appeared:

              Impossible to repair 010 Winsock LSP entries
              Use LSP Fix, which can be downloaded at http://www.cexx.org/lspfix.htm

              If the 010 item belongs to WebHancer, New.Net or Common/Name, Spybot S&D can remove it automatically.


              I then took the opportunity to run a scan with Spybot and no spyware was found.

              I restarted the computer and immediately received a Windows security update (KP950759) for IE7.

              And here is the new Hijackthis log:

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 12:56:38, on 07/07/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16674)
              Boot mode: Normal

              Running processes:
              C:\windows\System32\smss.exe
              C:\windows\system32\winlogon.exe
              C:\windows\system32\services.exe
              C:\windows\system32\lsass.exe
              C:\windows\System32\Ati2evxx.exe
              C:\windows\system32\svchost.exe
              C:\windows\System32\svchost.exe
              C:\WINDOWS\System32\brsvc01a.exe
              C:\WINDOWS\System32\brss01a.exe
              C:\windows\system32\spoolsv.exe
              C:\windows\system32\Ati2evxx.exe
              C:\windows\Explorer.EXE
              C:\Program Files\VIA\RAID\raid_tool.exe
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
              C:\Program Files\Windows Media Player\WMPNSCFG.exe
              C:\PROGRA~1\MI3AA1~1\wcescomm.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
              C:\PROGRA~1\MI3AA1~1\rapimgr.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\windows\system32\cisvc.exe
              C:\windows\System32\svchost.exe
              C:\WINDOWS\system32\inetsrv\inetinfo.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              C:\WINDOWS\system32\msiexec.exe
              C:\WINDOWS\system32\PSIService.exe
              C:\windows\system32\svchost.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\windows\system32\wuauclt.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
              O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
              O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
              O8 - Extra context menu item: Add to Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
              O9 - Extra 'Tools' menu item: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
              O9 - Extra button: Internet Anti-Virus Statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra 'Tools' menu item: Create a mobile favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menu item: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
              O15 - Trusted Zone: http://www.1001interims.com
              O15 - Trusted Zone: https://www.adobe.com/
              O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
              O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
              O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
              O15 - Trusted Zone: https://www.ustart.org
              O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
              O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
              O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
              O15 - Trusted Zone: https://www.msn.com/fr-fr/
              O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
              O15 - Trusted Zone: https://fr.yahoo.com/
              O15 - Trusted Zone: https://www.youtube.com/
              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
              O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
              O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
              O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

              --
              End of file - 7829 bytes

              I am waiting for your news!

              Best regards,

              catpeople12
              0
          8. Re catpeople12,

            we're making progress,
            1--a question to confirm,
            if I understood correctly, you did delete
            --->C:\WINDOWS\system32\LVComS.exe
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5036.cab

            if not, you can fix them with Hijackthis in normal mode.

            download LSP Fix from this link developed by (IUP / Indiana University of Pennsylvania)
            http://old.www.iup.edu/house/resnet/WinsockXPFix.exe

            BUT DO NOTHING FOR NOW.
            waiting for your response, I'm analyzing your log
            see you soon
            BOB3
            0
            1. Re, BOB3!

              I'm really happy that it's moving forward!!

              Your help is really valuable to me ( even though 90% of the time I don't quite understand what I'm doing... ) and I will continue to follow your instructions to the letter.

              As for the question you wanted to confirm:

              I did not delete the keys that I listed for you and that you mentioned in your question.
              They simply did not appear on the list of keys that showed up after scanning with Hijackthis in safe mode...

              Is it serious?

              I'm downloading LSP Fix and I'm awaiting your instructions.

              A+

              catpeople12
              0
          9. Re catpeople12,

            1---to verify, in the log I notice that your Kaspersky antivirus launches 3 times
            check the list of services at the beginning
            from
            Boot mode: Normal ----> until c:\program files\trend micro\hijackthis\hijackthis.exe

            2--go to c:\windows\Downloaded Program Files--->and delete all installed activex
            right-click, then delete
            as you go, you will accept the windows activex again

            3---you need to do the same operation with HJT, and perform a Fix checked on the following keys
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
            R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
            R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
            O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
            O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
            O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
            O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
            O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
            O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
            O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
            O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
            O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
            O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
            O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

            you run Ccleaner, reboot and send a new log.
            see you later
            BOB3
            0
            1. Re, BOB3!

              I just saved LSP Fix on my desktop while waiting for your instructions.

              Important question before proceeding:

              Should I remove the ActiveX controls in c:\windows\Downloaded Program Files and perform the second operation with HJT and the key repairs in Safe Mode or right away in normal mode?

              Over to you, boss!

              Best regards,

              catpeople12
              0
            2. Re, BOB3,

              You're right! Kaspersky launches 3 times according to log 2 of HJT...
              Is there any manipulation to do to resolve this if it's abnormal?

              I'm waiting for your instructions to delete the ActiveX in C:\Windows\Downloaded Program Files, then to run HJT again and repair the keys you identified, either in safe mode or normal mode.

              In which mode should I perform both actions, please?

              THANK YOU!

              A+

              catpeople12
              0
          10. Re catepeople,

            1--activex in normal mode
            2--for the Fix, you do it in normal mode, if there are remaining traces, in safe mode.

            I'm putting other actions for you to do, take your time, and proceed with caution.
            see you later
            BOB3
            0
            1. Re BOB3,

              Report until message 28:

              HJT Log 2:


              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 12:56:38, on 07/07/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16674)
              Boot mode: Normal

              Running processes:
              C:\windows\System32\smss.exe
              C:\windows\system32\winlogon.exe
              C:\windows\system32\services.exe
              C:\windows\system32\lsass.exe
              C:\windows\System32\Ati2evxx.exe
              C:\windows\system32\svchost.exe
              C:\windows\System32\svchost.exe
              C:\WINDOWS\System32\brsvc01a.exe
              C:\WINDOWS\System32\brss01a.exe
              C:\windows\system32\spoolsv.exe
              C:\windows\system32\Ati2evxx.exe
              C:\windows\Explorer.EXE
              C:\Program Files\VIA\RAID\raid_tool.exe
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
              C:\Program Files\Windows Media Player\WMPNSCFG.exe
              C:\PROGRA~1\MI3AA1~1\wcescomm.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
              C:\PROGRA~1\MI3AA1~1\rapimgr.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\windows\system32\cisvc.exe
              C:\windows\System32\svchost.exe
              C:\WINDOWS\system32\inetsrv\inetinfo.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              C:\WINDOWS\system32\msiexec.exe
              C:\WINDOWS\system32\PSIService.exe
              C:\windows\system32\svchost.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\windows\system32\wuauclt.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
              O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
              O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
              O8 - Extra context menu item: Add to Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
              O9 - Extra 'Tools' menu item: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll (file missing)
              O9 - Extra button: Internet Antivirus Statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra 'Tools' menu item: Create a mobile favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menu item: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
              O15 - Trusted Zone: http://www.1001interims.com
              O15 - Trusted Zone: https://www.adobe.com/
              O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
              O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
              O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
              O15 - Trusted Zone: https://www.ustart.org
              O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
              O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
              O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
              O15 - Trusted Zone: https://www.msn.com/fr-fr/
              O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
              O15 - Trusted Zone: https://fr.yahoo.com/
              O15 - Trusted Zone: https://www.youtube.com/
              O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - https://www.kaspersky.fr/?domain=webscanner.kaspersky.fr
              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://drivers1.free.fr/hardwaredetection.cab
              O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
              O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
              O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
              O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

              --
              End of file - 7829 bytes

              Missing keys on the HJT list that I had to check:

              016 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://rtc3.webresponse.one.microsoft.com/media/xp/TLIEFlash.CAB

              016 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

              Once the other keys were checked, I launched the Fix and the same message: HJT cannot repair 010 Winsock LSP entries. You should use LSP Fix for that...

              HJT Log 3 before reboot once the manipulations have been accomplished:

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 14:51:15, on 07/07/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16674)
              Boot mode: Normal

              Running processes:
              C:\windows\System32\smss.exe
              C:\windows\system32\winlogon.exe
              C:\windows\system32\services.exe
              C:\windows\system32\lsass.exe
              C:\windows\System32\Ati2evxx.exe
              C:\windows\system32\svchost.exe
              C:\windows\System32\svchost.exe
              C:\WINDOWS\System32\brsvc01a.exe
              C:\WINDOWS\System32\brss01a.exe
              C:\windows\system32\spoolsv.exe
              C:\windows\system32\Ati2evxx.exe
              C:\windows\Explorer.EXE
              C:\Program Files\VIA\RAID\raid_tool.exe
              C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe
              C:\Program Files\Windows Media Player\WMPNSCFG.exe
              C:\PROGRA~1\MI3AA1~1\wcescomm.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
              C:\PROGRA~1\MI3AA1~1\rapimgr.exe
              C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\windows\system32\cisvc.exe
              C:\windows\System32\svchost.exe
              C:\WINDOWS\system32\inetsrv\inetinfo.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
              C:\WINDOWS\system32\PSIService.exe
              C:\windows\system32\svchost.exe
              C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              C:\Program Files\Internet Explorer\iexplore.exe
              C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
              C:\windows\system32\cidaemon.exe
              C:\windows\system32\NOTEPAD.EXE
              C:\windows\system32\wuauclt.exe
              C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:4578
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
              O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O2 - BHO: (no name) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - (no file)
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
              O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
              O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
              O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
              O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"
              O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
              O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MI3AA1~1\wcescomm.exe"
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
              O4 - HKUS\S-1-5-18\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe (User 'Default user')
              O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
              O8 - Extra context menu item: Add to Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
              O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
              O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\windows\system32\shdocvw.dll
              O9 - Extra 'Tools' menu item: Java Console (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\windows\system32\shdocvw.dll
              O9 - Extra button: Internet Antivirus Statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
              O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra 'Tools' menu item: Create a mobile favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll
              O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O9 - Extra 'Tools' menu item: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
              O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
              O15 - Trusted Zone: http://www.1001interims.com
              O15 - Trusted Zone: https://www.adobe.com/
              O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
              O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
              O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
              O15 - Trusted Zone: https://www.ustart.org
              O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
              O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
              O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
              O15 - Trusted Zone: https://www.msn.com/fr-fr/
              O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
              O15 - Trusted Zone: https://fr.yahoo.com/
              O15 - Trusted Zone: https://www.youtube.com/
              O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
              O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
              O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
              O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
              O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
              O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
              O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
              O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
              O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
              O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)
              O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe

              --
              End of file - 7687 bytes

              HJT Log 4 after reboot:

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 15:29:10, on 07/07/2008
              Platform: Windows XP SP3 (WinNT 5.01.2600)
              MSIE: Internet Explorer v7.00 (7.00.6000.16674)
              Boot mode: Normal

              Running processes:
              C:\windows\System32\smss.exe
              C:\windows\system32\winlogon.exe
              C:\windows\system32\services.exe
              C:\windows\system32\lsass.exe
              C:\windows\System32\Ati2evxx.exe
              C:\windows\system32\svchost.exe
              C:\windows\System32\svchost.exe
              C:\WINDOWS\System32\brsvc01a.exe
              0
          11. Re catpeople12,

            traces of trojans to eradicate

            1---Uninstall the Zango program via Add/Remove Programs (if you find it)

            2---Download SDFix from AndyManchesta and save it to your Desktop.
            http://downloads.andymanchesta.com/RemovalTools/SDFix.exe

            Double click on SDFix.exe and choose Install to extract it to a dedicated folder on the Desktop.
            Restart your computer in Safe Mode.

            Open the SDFix folder that has just been created in the C:\ directory and double click on RunThis.bat to launch the script.
            Press Y to start the cleanup process.

            It will delete services and Registry entries of certain trojans found and will then ask you to press a key to reboot.
            So press a key.

            Your system will take longer to reboot than usual because the tool will continue to run and delete files.

            After loading the Desktop, the tool will finish its work and display Finished.
            Press a key to complete the execution of the script and load your Desktop icons.

            Once the Desktop icons are displayed, the SDFix report will open on the screen and will also be saved in the SDFix folder as Report.txt. You will need to paste this report in your next reply.

            3-----Press Ctrl + Alt + Delete to open the Task Manager.
            Select the Processes tab
            In the Image Name column, check if you find
            the process zango.exe
            Right-click on it and choose End Process
            Then look for the process mnew1winc4.exe
            Right-click on it and choose End Process

            4-----Restart HijackThis and check the following lines if you find them

            O2 - BHO: Zango Search Assistant Helper /fleok=1D8A83A5C1E0197791AE75760EA83FA5EF80752B94E2DE7E5A7A47203BCF - {56F1D444-11BF-4879-A12B-79CF0177F038} - c:\program files\zango\zangohook.dll
            O4 - HKLM\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe
            O4 - HKLM\..\Run: [Memory manager] C:\WINDOWS\System32\himem32.exe
            O4 - HKLM\..\Run: [zango] "c:\program files\zango\zango.exe"
            O4 - HKLM\..\Run: [WindowsHive] C:\WINDOWS\System32\rpcc.exe
            O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
            O4 - HKLM\..\Run: [PD0620 STISvc] RunDLL32.exe P0620Pin.dll,RunDLL32EP 513
            O4 - HKLM\..\RunServices: [Printer] C:\WINDOWS\System32\auditchk.exe
            O4 - HKCU\..\Run: [Printer] C:\WINDOWS\System32\auditchk.exe
            O4 - HKCU\..\Run: [dpr0] C:\WINDOWS\system32\prod.exe
            O4 - HKCU\..\Run: [chsr] C:\WINDOWS\system32\lssrvc.exe
            O4 - HKCU\..\Run: [mlrnew1c4] C:\WINDOWS\system32\mnew1winc4.exe
            O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
            O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
            O20 - Winlogon Notify: rpcc - C:\WINDOWS\System32\rpcc.dll (file missing)
            O20 - Winlogon Notify: rpccd - C:\WINDOWS\System32\rpccd.dll

            Click on Fix Checked and confirm the following message.

            5----With Windows Explorer, search for the following files/folders and delete them (if still present):
            c:\program files\zango <-- The folder
            C:\WINDOWS\System32\auditchk.exe (Be careful with the spelling)
            C:\WINDOWS\System32\himem32.exe (Again, be careful with the spelling)
            C:\WINDOWS\System32\rpcc.exe
            C:\WINDOWS\system32\prod.exe
            C:\WINDOWS\system32\lssrvc.exe
            C:\WINDOWS\system32\mnew1winc4.exe
            C:\WINDOWS\System32\rpcc.dll
            C:\WINDOWS\System32\rpccd.dll

            6--run Ccleaner, clean up, reboot, and post the log Report.txt from Sdfix.
            a+
            BOB3
            0
            1. Hello BOB3!

              No traces of zango anywhere; no process in the Task Manager, none of the keys you asked me to check or any files searched with Windows Explorer were found... (COOL!)

              During the SDFix analysis, the following message appeared:

              Note: Protective Host Files such as MVPS/HP hosts or Spybot Immunizers must be applied after SDFix analysis

              I have Spybot S&D and it immunizes the system. Should I do it?

              Here's the SD Fix report:

              [b]SDFix: Version 1.202 [/b]
              Run by Carlo on 07/07/2008 at 15:56

              Microsoft Windows XP [version 5.1.2600]
              Running From: C:\DOCUME~1\Carlo\Desktop\SDFix

              [b]Checking Services [/b]:

              [b]Name [/b]:
              MicroSoft Media Tools

              [b]Path [/b]:
              "C:\WINDOWS\MSmedia.exe"

              MicroSoft Media Tools - Deleted

              Restoring Default Security Values
              Restoring Default Hosts File

              Rebooting

              [b]Checking Files [/b]:

              Trojan Files Found:

              C:\Documents and Settings\Carlo\My Documents.url - Deleted
              C:\Documents and Settings\Carlo\My Documents\CARLO\AUDIOVISUEL C & S\Our Music\My Music.url - Deleted
              C:\Documents and Settings\Carlo\My Documents\AUDIOVISUEL C & S\Our Videos\My Video.url - Deleted
              C:\windows\system32\TFTP1684 - Deleted
              C:\windows\system32\TFTP2892 - Deleted
              C:\Program Files\Setup.exe - Deleted
              C:\tmp.reg - Deleted

              Removing Temp Files

              [b]ADS Check [/b]:

              [b]Final Check [/b]:

              catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2008-07-07 16:04:47
              Windows 5.1.2600 Service Pack 3 NTFS

              scanning hidden processes ...

              scanning hidden services & system hive ...

              scanning hidden registry entries ...

              scanning hidden files ...

              scan completed successfully
              hidden processes: 0
              hidden services: 0
              hidden files: 0

              [b]Remaining Services [/b]:

              Authorized Application Key Export:

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
              "c:\\irpll7l.exe"="C:\\irpll7l.exe:*:Enabled:Server"
              "Windows Firewall Monitor"="C:\\dinst.exe:*:enabled:svchost"
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
              "C:\\Program Files\\eChanblard\\emule.exe"="C:\\Program Files\\eChanblard\\emule.exe:*:Enabled:eMule"
              "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.6\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.6\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
              "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.5\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.5\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
              "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.4\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.4\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
              "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.3\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.3\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
              "C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.2\\ProxyAuth.exe"="C:\\Program Files\\CheckFlow\\SurfInvisible\\2.0.0.2\\ProxyAuth.exe:*:Disabled:Proxy CheckFlow"
              "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\Fp2006.exe:*:Disabled:Spy Shooter 2006"
              "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\FlowService.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.4\\FlowService.exe:*:Disabled:Spy Shooter 2006"
              "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\Fp2006.exe:*:Disabled:SpyShooter2006"
              "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\FlowService.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.6\\FlowService.exe:*:Disabled:SpyShooter2006"
              "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\Fp2006.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\Fp2006.exe:*:Disabled:Spy Shooter 2006"
              "C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\FlowService.exe"="C:\\Program Files\\CheckFlow\\SpyShooter\\5.0.0.2\\FlowService.exe:*:Disabled:Spy Shooter 2006"
              "C:\\Program Files\\VideoLAN\\VLC\\vlc.exe"="C:\\Program Files\\VideoLAN\\VLC\\vlc.exe:*:Enabled:VLC media player"
              "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
              "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
              "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
              "C:\\Program Files\\messenger\\msmsgs.exe"="C:\\Program Files\\messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
              "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
              "C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Enabled:@xpsp2res.dll,-22019"

              [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
              "c:\\irpll7l.exe"="C:\\irpll7l.exe:*:Enabled:Server"
              "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
              "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
              "C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager"
              "C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe"="C:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager"
              "C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe"="C:\\Program Files\\Microsoft ActiveSync\\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application"
              "C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"="C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger"
              "C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"="C:\\Program Files\\Windows Live\\Messenger\\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"

              [b]Remaining Files [/b]:

              File Backups: - C:\DOCUME~1\Carlo\Desktop\SDFix\backups\backups.zip

              [b]Files with Hidden Attributes [/b]:

              Sat 21 Jun 2008 212 A.SH. --- "C:\BOOT.BAK"
              Fri 13 May 2005 217,073 A.SHR --- "C:\WINDOWS\meta4.exe"
              Mon 24 Oct 2005 66,560 A.SHR --- "C:\WINDOWS\MOTA113.exe"
              Thu 13 Oct 2005 422,400 A.SHR --- "C:\WINDOWS\x2.64.exe"
              Mon 28 Jan 2008 1,404,240 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SDUpdate.exe"
              Mon 28 Jan 2008 5,146,448 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
              Mon 28 Jan 2008 2,097,488 A.SHR --- "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
              Tue 17 Apr 2007 168 ..SHR --- "C:\WINDOWS\system32\0E3DD7342B.sys"
              Fri 28 Oct 2005 308,224 A.SH. --- "C:\WINDOWS\system32\avisynth.dll"
              Thu 14 Jul 2005 27,648 A.SHR --- "C:\WINDOWS\system32\AVSredirect.dll"
              Sun 26 Jun 2005 616,448 A.SHR --- "C:\WINDOWS\system32\cygwin1.dll"
              Tue 21 Jun 2005 45,568 A.SHR --- "C:\WINDOWS\system32\cygz.dll"
              Sun 25 Jan 2004 70,656 A.SHR --- "C:\WINDOWS\system32\i420vfw.dll"
              Tue 17 Apr 2007 2,516 A.SH. --- "C:\WINDOWS\system32\KGyGaAvL.sys"
              Sun 21 Jan 2001 63,488 A..H. --- "C:\WINDOWS\system32\MMRegOCX.exe"
              Thu 27 Apr 2006 2,945,024 A.SHR --- "C:\WINDOWS\system32\Smab.dll"
              Mon 28 Feb 2005 240,128 A.SHR --- "C:\WINDOWS\system32\x.264.exe"
              Sun 25 Jan 2004 70,656 A.SH. --- "C:\WINDOWS\system32\yv12vfw.dll"
              Sun 14 May 2006 4,348 ..SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
              Sat 24 Nov 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv02.tmp"
              Fri 18 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\4658aca27402c0ea318a0615f08905ca\BIT42.tmp"
              Fri 18 Apr 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\6092debe4959b217a6aac6c11cc1dd60\BIT48.tmp"
              Sun 14 May 2006 4,348 A..H. --- "C:\Documents and Settings\Carlo\My Documents\CARLO\AUDIOVISUEL C & S\Our Music\License Backup\drmv1key.bak"
              Fri 16 Jun 2006 20 A..H. --- "C:\Documents and Settings\Carlo\My Documents\CARLO\AUDIOVISUEL C & S\Our Music\License Backup\drmv1lic.bak"
              Sun 26 Feb 2006 312 A..H. --- "C:\Documents and Settings\Carlo\My Documents\CARLO\AUDIOVISUEL C & S\Our Music\License Backup\drmv2key.bak"
              Fri 16 Jun 2006 1,536 A..H. --- "C:\Documents and Settings\Carlo\My Documents\CARLO\AUDIOVISUEL C & S\Our Music\License Backup\drmv2lic.bak"

              [b]Finished![/b]

              catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
              Rootkit scan 2008-07-07 16:04:47
              Windows 5.1.2600 Service Pack 3 NTFS

              scanning hidden processes ...

              scanning hidden services & system hive ...

              scanning hidden registry entries ...

              scanning hidden files ...

              scan completed successfully
              hidden processes: 0
              hidden services: 0
              hidden files: 0

              Otherwise, should I do something with WinsockXPFix that I downloaded?

              Looking forward to your new instructions, best regards!

              catpeople12
              0
          12. Re catpeople12,

            thank you for putting your responses in order, it prevents me from going back and forth,

            to summarize,
            1--you delete all the ActiveX in normal mode
            2--you set aside the Kaspersky issue, we will deal with it later
            3--if you haven't found the other keys, it's because they have been deleted

            the most important
            4--you run SDFIX as indicated in 29 and you put its report --- copy and paste

            see you soon
            BOB3
            0
            1. RESPONSE TO MESSAGE 33 FROM BOB

              Re, BOB3

              I'm really sorry that you're going back and forth because of me!!...

              I thought I had followed the order of your advice messages...

              I'll summarize to make your life easier. There are two important messages for you from me:

              A - My message N° 31, which responds to your messages 24, 25, and 28, where I posted the Hijackthis logs that you requested.

              B - My message N° 32, which responds to your message 29, where you will find the SDFix report that you asked for. As agreed, I deleted the ActiveX and did nothing with Kaspersky or LSP Fix that I was supposed to download (See your message N° 24).

              I was just waiting for you to read the SDFix report to know what to do next.

              Thanks, sorry again, and see you later!

              catpeople12
              0
          13. Re catpeople12,

            for verification + modification

            1---The following registry keys are added to run processes after reboot:
            you open regedit.exe ----- with caution
            you search for these keys and delete them

            – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
            • "Printer"="%SYSDIR%\auditchk.exe"

            – [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
            • "Printer"="%SYSDIR%\auditchk.exe"

            – [HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
            • "Printer"="%SYSDIR%\auditchk.exe"

            2--then you search for the following keys and possibly modify them
            the keys should be as follows:

            – [HKLM\SOFTWARE\Microsoft\Ole]

            Name Type Value

            • "EnableDCOM"= REG_SZ N

            – [HKLM\SYSTEM\CurrentControlSet\Control\Lsa]

            • "restrictanonymous"= REG_DWORD 0X00000002 (2)

            you close,

            3---you note all the files you find
            you search your disk for all files located in Temp, and delete them
            c:\temp\xxxxxxx.xxxx

            c:\documents and settings\administrator\local settings\temp
            and you check in the other accounts found in c:\documents and settings\xxxxxxxx\local settings\temp

            c:\windows\temp
            c:\windows\system32\temp

            and you give me the list
            a+
            BOB3

            you reboot,

            you run a scan with Spybot,

            and you provide a new HijackThis log

            a+
            BOB3
            0
            1. Re catpeople12,

              let's continue from 34 + this post.

              forget the hijackthis + spybot reports for now,
              the SDFIX report is not great

              1---do what is requested in 34

              2--I asked you to uninstall windows live messenger in 22, it still appears in the SDFIX report.

              1--have you uninstalled microsoft live messenger, if not uninstall it
              2--also uninstall microsoft active sync--it is infected----you will reinstall it after cleaning
              3--also uninstall microsoft network diagnostic --- it is useless
              4--uninstall spybot --- it is infected --- see below

              clean up with Ccleaner, delete everything

              download spybot again from this link
              ftp://ftp.commentcamarche.com/download/spybotsd152.exe

              install it, + update + launch the vaccination so that the counters are identical

              then configure it as follows.

              launch Spybot, then click on Mode at the top, then check Advanced mode
              then on tools and check all boxes under tools.
              click on System startup, which allows you to remove unwanted or superfluous programs that you can check and delete
              click on System interior, run verify, and check them one by one, then click on fix problems
              click on Hosts files, to update the list of unwanted sites, and redo this every time Spybot is updated
              click on IE adjustment, and check all lock boxes
              click on browser pages, and double click on all the links, one by one, and when it opens, delete the content
              and click Ok
              click on BHOs, and remove everything----> except those from your antivirus+Spybot
              click on ActivX, and remove everything----> except those from windows+office+genuine advantage+Shockwave if present
              click on Resident, and check both boxes.
              and once a day before shutting down your computer,
              click on Security Eraser, and click on Templates, then click on the list one by one, and click at the bottom
              on Shred to clean everything.

              finally run Ccleaner, and do a reboot.

              launch Spybot for a complete scan, and give me the results.
              a+
              BOB3
              0
              1. RESPONSE TO MESSAGES 34 AND 36 FROM BOB3

                Hello BOB3!

                I'm replying to your messages in order to make it easier for you.

                MESSAGE 34

                Verification and modification

                1 - The registry keys "Printer"="%SYSDIR%\auditchk.exe" were not present in [HKLM\SOFTWARE\Microsoft\Windows\Current Version\Run] nor in [....\RunServices], nor in [HKCU\....\Run]

                2 - The following keys were incorrect and I modified them according to your instructions:

                [HKLM\SOFTWARE\Microsoft\Ole] had a value Y which I changed to N as indicated.

                [HKLM\SYSTEM\CurrentControlSet\Control\Lsa] had a value 0 which I changed to 2 as indicated.

                3 - List of files found in Temp to submit to you:

                c:\temp
                "debug"
                folder 38bb9e8aacbb4470e2 containing %temp%dd_msxml_retMSI
                deleted

                c:\documents and settings\xxxx\local settings\temp
                WCESCOMM
                ISTMP1.DIR
                sv457.tmp
                deleted

                WCESLog - UNABLE TO DELETE

                c:\windows\temp
                WGAErrlog
                WGANotify.settings
                deleted

                c:\windows\system32\temp
                folder URTTemp containing: fusion.dll; mscoree.dll; mscoree.dll.local; mscorns.dll; mscorwks.dll; msvcr.dll
                I DID NOT DARE TO DELETE IT BECAUSE THERE ARE TOO MANY UNKNOWN .dll FILES FOR ME. CAN I DELETE IT?

                inetsrv
                ASP Compiled Templates (empty folder)
                deleted

                MESSAGE 36

                1 - I did what was requested in 34

                2- Uninstallations:
                a) I uninstalled the Windows Live components that were still installed
                b) I uninstalled Microsoft Active Sync (I don't really need it)
                c) Microsoft Network Diagnostic is not in my system
                d) I uninstalled the old Spybot S&D

                I cleaned up with CCleaner and deleted everything

                I downloaded Spybot S&D from the link you gave me and followed your instructions to the letter.

                I cleaned again with CCleaner as requested and rebooted

                I ran a complete scan with Spybot, which found nothing unusual in the results.

                This morning upon starting the computer, Spybot did another complete scan and there are no trackers.

                P.S.

                I have not yet used LSP Fix, I have not yet downloaded Windows Live nor reinstalled my Labtec webcam while waiting for your instructions.

                Best regards,

                catpeople12
                0
              2. NEW

                Re BOB3,
                I took the liberty of running another HJT scan, and I’m sharing the log with you so you can see the current state of the system. I hope I’m not bothering you too much...

                Additionally, I can no longer access the internet options in the browser...

                The following error message appears when I try to access it:
                X This operation has been canceled due to restrictions in effect on this computer. Please contact your System Administrator.

                And here is the very latest HJT log:

                Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 11:43:15, on 08/07/2008
                Platform: Windows XP SP3 (WinNT 5.01.2600)
                MSIE: Internet Explorer v7.00 (7.00.6000.16674)
                Boot mode: Normal

                Running processes:
                C:\windows\System32\smss.exe
                C:\windows\system32\winlogon.exe
                C:\windows\system32\services.exe
                C:\windows\system32\lsass.exe
                C:\windows\System32\Ati2evxx.exe
                C:\windows\system32\svchost.exe
                C:\windows\System32\svchost.exe
                C:\windows\system32\Ati2evxx.exe
                C:\windows\Explorer.EXE
                C:\WINDOWS\System32\brsvc01a.exe
                C:\WINDOWS\System32\brss01a.exe
                C:\windows\system32\spoolsv.exe
                C:\Program Files\VIA\RAID\raid_tool.exe
                C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                C:\Program Files\Windows Media Player\WMPNSCFG.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
                C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
                C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                C:\windows\system32\cisvc.exe
                C:\windows\System32\svchost.exe
                C:\WINDOWS\system32\inetsrv\inetinfo.exe
                C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
                C:\windows\system32\svchost.exe
                C:\windows\system32\cidaemon.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
                R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Links
                O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll (file missing)
                O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe
                O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
                O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
                O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
                O4 - HKLM\..\Run: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe"
                O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
                O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
                O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
                O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
                O8 - Extra context menu item: Add to Kaspersky Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
                O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
                O9 - Extra button: Internet Anti-Virus Statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
                O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
                O15 - Trusted Zone: http://www.1001interims.com
                O15 - Trusted Zone: https://www.adobe.com/
                O15 - Trusted Zone: https://www.blogger.com/about/?r=1-null_user
                O15 - Trusted Zone: http://contracreciendoengracia.blogspot.com
                O15 - Trusted Zone: http://mirandadesvelado.blogspot.com
                O15 - Trusted Zone: https://www.ustart.org
                O15 - Trusted Zone: https://www.emule-project.net/home/perl/general.cgi?l=1
                O15 - Trusted Zone: https://www.google.fr/?gws_rd=ssl
                O15 - Trusted Zone: https://www.bing.com/search?q=onecare%20live&form=MSDTR1&toHttps=1&redig=1C92C1A5A5B14363B76B4872209A5D58
                O15 - Trusted Zone: https://www.msn.com/fr-fr/
                O15 - Trusted Zone: https://jesucristohombre.wordpress.com/
                O15 - Trusted Zone: https://fr.yahoo.com/
                O15 - Trusted Zone: https://www.youtube.com/
                O17 - HKLM\System\CCS\Services\Tcpip\..\{2ED85A46-280F-4EA4-AB66-A909F6275AE1}: NameServer = 212.27.32.176,212.27.37.177
                O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll
                O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\windows\System32\Ati2evxx.exe
                O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
                O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
                O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: Microsoft Network Service (Network) - Unknown owner - C:\WINDOWS\msnet32.exe (file missing)

                --
                End of file - 5453 bytes


                Thanks and A+ for your patience!

                catpeople12
                0
            2. Hello catpeople12,

              WCESLog - CANNOT BE REMOVED
              remove it in safe mode,

              leave LSP Fix aside for now, I’m waiting for a response if it is compatible with XP in French.

              you are going to download Norman Malware Cleaner
              for this, go to the folder c:\SDFix
              1---in normal mode with internet connection required.
              launch RunThis.bat, it opens a DOS menu,
              type 2, to download Norman_Malware_Cleaner
              it will install itself in the same folder, its size=22268ko
              normally it launches automatically after the download, otherwise open the SDFix folder, and launch
              Norman_Malware_Cleaner.exe

              let it scan all your drives, it may take some time, it finishes and puts a log on your desktop,
              paste it in a new post so I can take a look.
              see you+
              BOB3

              P.S.I WILL BE ABSENT ---->4:00 PM
              0
              1. Hello again BOB3 and thank you for your response!

                I followed your instructions and I’m letting you check the log from Norman Malware Cleaner (4 infected files removed) below.
                (By the way, what does this IP address 127.0.0.1 correspond to?.... There are a lot of weird sites in it that I didn't know existed but that appeared in the log... ).

                Otherwise, will I be able to download Windows Live and reinstall the Labtec webcam soon?

                I’m waiting for your instructions after 4:00 PM.

                Best regards,

                catpeople12

                LOG FROM 07/08/2008

                Norman Malware Cleaner
                Copyright © 1990 - 2008, Norman ASA. Built 2008/06/30 19:19:50

                Norman Scanner Engine Version: 5.92.08
                Nvcbin.def Version: 5.92.00, Date: 2008/06/30 19:19:50, Variants: 1812814

                Running pre-scan cleanup routine:
                Operating System: Microsoft Windows XP Professional 5.1.2600 Service Pack 3
                Logged on user: CARLO\Carlo

                Set registry value: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLS = "C:\PROGRA~1\KASPER~1\KASPER~2.0\adialhk.dll" -> ""
                Removed hosts entry: 127.0.0.1 www.100sexlinks.com
                Removed hosts entry: 127.0.0.1 100sexlinks.com
                Removed hosts entry: 127.0.0.1 www.123topsearch.com
                Removed hosts entry: 127.0.0.1 123topsearch.com
                Removed hosts entry: 127.0.0.1 www.1800searchonline.com
                Removed hosts entry: 127.0.0.1 1800searchonline.com
                Removed hosts entry: 127.0.0.1 www.180searchassistant.com
                Removed hosts entry: 127.0.0.1 180searchassistant.com
                Removed hosts entry: 127.0.0.1 www.1stantivirus.com
                Removed hosts entry: 127.0.0.1 1stantivirus.com
                Removed hosts entry: 127.0.0.1 www.1stsearchportal.com
                Removed hosts entry: 127.0.0.1 1stsearchportal.com
                Removed hosts entry: 127.0.0.1 www.2007-download.com
                Removed hosts entry: 127.0.0.1 2007-download.com
                Removed hosts entry: 127.0.0.1 www.2020search.com
                Removed hosts entry: 127.0.0.1 2020search.com
                Removed hosts entry: 127.0.0.1 www.24-7searching-and-more.com
                Removed hosts entry: 127.0.0.1 24-7searching-and-more.com
                Removed hosts entry: 127.0.0.1 www.2search.com
                Removed hosts entry: 127.0.0.1 2search.com
                Removed hosts entry: 127.0.0.1 www.2search.org
                Removed hosts entry: 127.0.0.1 2search.org
                Removed hosts entry: 127.0.0.1 www.3ebay.it
                Removed hosts entry: 127.0.0.1 3ebay.it
                Removed hosts entry: 127.0.0.1 www.4ebay.it
                Removed hosts entry: 127.0.0.1 4ebay.it
                Removed hosts entry: 127.0.0.1 www.4repubblica.it
                Removed hosts entry: 127.0.0.1 4repubblica.it
                Removed hosts entry: 127.0.0.1 www.5repubblica.it
                Removed hosts entry: 127.0.0.1 5repubblica.it
                Removed hosts entry: 127.0.0.1 www.777search.com
                Removed hosts entry: 127.0.0.1 777search.com
                Removed hosts entry: 127.0.0.1 www.7search.com
                Removed hosts entry: 127.0.0.1 7search.com
                Removed hosts entry: 127.0.0.1 www.971searchbox.com
                Removed hosts entry: 127.0.0.1 971searchbox.com
                Removed hosts entry: 127.0.0.1 www.abccodec.com
                Removed hosts entry: 127.0.0.1 abccodec.com
                Removed hosts entry: 127.0.0.1 www.abcsearch.com
                Removed hosts entry: 127.0.0.1 abcsearch.com
                Removed hosts entry: 127.0.0.1 www.activexmediasoftware.com
                Removed hosts entry: 127.0.0.1 activexmediasoftware.com
                Removed hosts entry: 127.0.0.1 www.activexsoftwares.com
                Removed hosts entry: 127.0.0.1 activexsoftwares.com
                Removed hosts entry: 127.0.0.1 www.activexupdate.com
                Removed hosts entry: 127.0.0.1 activexupdate.com
                Removed hosts entry: 127.0.0.1 www.adasearch.com
                Removed hosts entry: 127.0.0.1 adasearch.com
                Removed hosts entry: 127.0.0.1 www.adipics.com
                Removed hosts entry: 127.0.0.1 adipics.com
                Removed hosts entry: 127.0.0.1 adobe-download-now.com
                Removed hosts entry: 127.0.0.1 www.adobe-downloads.com
                Removed hosts entry: 127.0.0.1 adobe-downloads.com
                Removed hosts entry: 127.0.0.1 ads.searchingbooth.com
                Removed hosts entry: 127.0.0.1 www.adsextend.net
                Removed hosts entry: 127.0.0.1 adsextend.net
                Removed hosts entry: 127.0.0.1 www.adspics.com
                Removed hosts entry: 127.0.0.1 adspics.com
                Removed hosts entry: 127.0.0.1 www.adult18codec.com
                Removed hosts entry: 127.0.0.1 adult18codec.com
                Removed hosts entry: 127.0.0.1 www.adultcodec-2008.com
                Removed hosts entry: 127.0.0.1 adultcodec-2008.com
                Removed hosts entry: 127.0.0.1 www.adultcodecstars.com
                Removed hosts entry: 127.0.0.1 adultcodecstars.com
                Removed hosts entry: 127.0.0.1 www.adult-engine-search.com
                Removed hosts entry: 127.0.0.1 adult-engine-search.com
                Removed hosts entry: 127.0.0.1 affiliate.idownload.com
                Removed hosts entry: 127.0.0.1 www.airtleworld.com
                Removed hosts entry: 127.0.0.1 airtleworld.com
                Removed hosts entry: 127.0.0.1 akamai.downloadv3.com
                Removed hosts entry: 127.0.0.1 alfa-search.com
                Removed hosts entry: 127.0.0.1 www.allcybersearch.com
                Removed hosts entry: 127.0.0.1 allcybersearch.com
                Removed hosts entry: 127.0.0.1 www.all-downloads-now.com
                Removed hosts entry: 127.0.0.1 all-downloads-now.com
                Removed hosts entry: 127.0.0.1 allforadult.com
                Removed hosts entry: 127.0.0.1 www.alltiettantivirus.com
                Removed hosts entry: 127.0.0.1 alltiettantivirus.com
                Removed hosts entry: 127.0.0.1 www.alltruesoftware.com
                Removed hosts entry: 127.0.0.1 alltruesoftware.com
                Removed hosts entry: 127.0.0.1 www.amediasoftware.com
                Removed hosts entry: 127.0.0.1 amediasoftware.com
                Removed hosts entry: 127.0.0.1 www.americanautobargains.com
                Removed hosts entry: 127.0.0.1 americanautobargains.com
                Removed hosts entry: 127.0.0.1 www.ampmsearch.com
                Removed hosts entry: 127.0.0.1 ampmsearch.com
                Removed hosts entry: 127.0.0.1 anarchyporn.com
                Removed hosts entry: 127.0.0.1 www.animepornmag.com
                Removed hosts entry: 127.0.0.1 animepornmag.com
                Removed hosts entry: 127.0.0.1 www.antiespiadorado.com
                Removed hosts entry: 127.0.0.1 antiespiadorado.com
                Removed hosts entry: 127.0.0.1 www.antiespionspack.com
                Removed hosts entry: 127.0.0.1 antiespionspack.com
                Removed hosts entry: 127.0.0.1 www.antigusanos2008.com
                Removed hosts entry: 127.0.0.1 antigusanos2008.com
                Removed hosts entry: 127.0.0.1 www.antispamassistant.com
                Removed hosts entry: 127.0.0.1 antispamassistant.com
                Removed hosts entry: 127.0.0.1 www.antispamdeluxe.com
                Removed hosts entry: 127.0.0.1 antispamdeluxe.com
                Removed hosts entry: 127.0.0.1 www.antispionage.com
                Removed hosts entry: 127.0.0.1 antispionage.com
                Removed hosts entry: 127.0.0.1 www.antispionagepro.com
                Removed hosts entry: 127.0.0.1 antispionagepro.com
                Removed hosts entry: 127.0.0.1 www.antispyadvanced.com
                Removed hosts entry: 127.0.0.1 antispyadvanced.com
                Removed hosts entry: 127.0.0.1 www.antispycheck.com
                Removed hosts entry: 127.0.0.1 antispycheck.com
                Removed hosts entry: 127.0.0.1 www.antispydns.biz
                Removed hosts entry: 127.0.0.1 antispydns.biz
                Removed hosts entry: 127.0.0.1 www.antispykit.com
                Removed hosts entry: 127.0.0.1 antispykit.com
                Removed hosts entry: 127.0.0.1 www.antispylab.com
                Removed hosts entry: 127.0.0.1 antispylab.com
                Removed hosts entry: 127.0.0.1 www.antispyshield.com
                Removed hosts entry: 127.0.0.1 antispyshield.com
                Removed hosts entry: 127.0.0.1 www.antispysolutions.com
                Removed hosts entry: 127.0.0.1 antispysolutions.com
                Removed hosts entry: 127.0.0.1 www.antispyware.com
                Removed hosts entry: 127.0.0.1 antispyware.com
                Removed hosts entry: 127.0.0.1 www.antispywareboot.com
                Removed hosts entry: 127.0.0.1 antispywareboot.com
                Removed hosts entry: 127.0.0.1 www.antispywarebot.com
                Removed hosts entry: 127.0.0.1 antispywarebot.com
                Removed hosts entry: 127.0.0.1 www.antispywarebox.com
                Removed hosts entry: 127.0.0.1 antispywarebox.com
                Removed hosts entry: 127.0.0.1 www.antispywaredownloads.com
                Removed hosts entry: 127.0.0.1 antispywaredownloads.com
                Removed hosts entry: 127.0.0.1 www.antispywaresuite.com
                Removed hosts entry: 127.0.0.1 antispywaresuite.com
                Removed hosts entry: 127.0.0.1 www.antispywareupdates.net
                Removed hosts entry: 127.0.0.1 antispywareupdates.net
                Removed hosts entry: 127.0.0.1 www.antispywarexp.com
                Removed hosts entry: 127.0.0.1 antispywarexp.com
                Removed hosts entry: 127.0.0.1 www.antispyweb.net
                Removed hosts entry: 127.0.0.1 antispyweb.net
                Removed hosts entry: 127.0.0.1 www.antiver2008.com
                Removed hosts entry: 127.0.0.1 antiver2008.com
                Removed hosts entry: 127.0.0.1 www.antivermins.com
                Removed hosts entry: 127.0.0.1 antivermins.com
                Removed hosts entry: 127.0.0.1 www.anti-vermins.com
                Removed hosts entry: 127.0.0.1 anti-vermins.com
                Removed hosts entry: 127.0.0.1 www.antivir2007.com
                Removed hosts entry: 127.0.0.1 antivir2007.com
                Removed hosts entry: 127.0.0.1 www.antivirgear.com
                Removed hosts entry: 127.0.0.1 antivirgear.com
                Removed hosts entry: 127.0.0.1 www.antivirprotect.com
                Removed hosts entry: 127.0.0.1 antivirprotect.com
                Removed hosts entry: 127.0.0.1 www.antivirus.fastfreedownload.com
                Removed hosts entry: 127.0.0.1 antivirus.fastfreedownload.com
                Removed hosts entry: 127.0.0.1 www.antivirus2008pro.com
                Removed hosts entry: 127.0.0.1 antivirus2008pro.com
                Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.com
                Removed hosts entry: 127.0.0.1 antivirus-2008pro.com
                Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.com
                Removed hosts entry: 127.0.0.1 antivirus-2008-pro.com
                Removed hosts entry: 127.0.0.1 www.antivirus2008pro.info
                Removed hosts entry: 127.0.0.1 antivirus2008pro.info
                Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.info
                Removed hosts entry: 127.0.0.1 antivirus-2008pro.info
                Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.info
                Removed hosts entry: 127.0.0.1 antivirus-2008-pro.info
                Removed hosts entry: 127.0.0.1 www.antivirus2008pro.net
                Removed hosts entry: 127.0.0.1 antivirus2008pro.net
                Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.net
                Removed hosts entry: 127.0.0.1 antivirus-2008pro.net
                Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.net
                Removed hosts entry: 127.0.0.1 antivirus-2008-pro.net
                Removed hosts entry: 127.0.0.1 www.antivirus2008pro.org
                Removed hosts entry: 127.0.0.1 antivirus2008pro.org
                Removed hosts entry: 127.0.0.1 www.antivirus-2008pro.org
                Removed hosts entry: 127.0.0.1 antivirus-2008pro.org
                Removed hosts entry: 127.0.0.1 www.antivirus-2008-pro.org
                Removed hosts entry: 127.0.0.1 antivirus-2008-pro.org
                Removed hosts entry: 127.0.0.1 www.antivirus2008x.com
                Removed hosts entry: 127.0.0.1 antivirus2008x.com
                Removed hosts entry: 127.0.0.1 www.antivirusadvance.com
                Removed hosts entry: 127.0.0.1 antivirusadvance.com
                Removed hosts entry: 127.0.0.1 www.antivirusaskeladd.com
                Removed hosts entry: 127.0.0.1 antivirusaskeladd.com
                Removed hosts entry: 127.0.0.1 www.antivirusgereedschap.com
                Removed hosts entry: 127.0.0.1 antivirusgereedschap.com
                Removed hosts entry: 127.0.0.1 www.antivirusgolden.com
                Removed hosts entry: 127.0.0.1 antivirusgolden.com
                Removed hosts entry: 127.0.0.1 www.antivirus-hq.net
                Removed hosts entry: 127.0.0.1 antivirus-hq.net
                Removed hosts entry: 127.0.0.1 www.antiviruspcsuite.com
                Removed hosts entry: 127.0.0.1 antiviruspcsuite.com
                Removed hosts entry: 127.0.0.1 www.antiviruspremium.com
                Removed hosts entry: 127.0.0.1 antiviruspremium.com
                Removed hosts entry: 127.0.0.1 www.anti-virus-pro.com
                Removed hosts entry: 127.0.0.1 anti-virus-pro.com
                Removed hosts entry: 127.0.0.1 www.antivirusprotector.com
                Removed hosts entry: 127.0.0.1 antivirusprotector.com
                Removed hosts entry: 127.0.0.1 www.antivirus-scanner.com
                Removed hosts entry: 127.0.0.1 antivirus-scanner.com
                Removed hosts entry: 127.0.0.1 www.antivirusscherm.com
                Removed hosts entry: 127.0.0.1 antivirusscherm.com
                Removed hosts entry: 127.0.0.1 www.antivirussecuritypro.com
                Removed hosts entry: 127.0.0.1 antivirussecuritypro.com
                Removed hosts entry: 127.0.0.1 www.antivirus-stop.com
                Removed hosts entry: 127.0.0.1 antivirus-stop.com
                Removed hosts entry: 127.0.0.1 www.antivirussuite.com
                Removed hosts entry: 127.0.0.1 antivirussuite.com
                Removed hosts entry: 127.0.0.1 www.antiworm2008.com
                Removed hosts entry: 127.0.0.1 antiworm2008.com
                Removed hosts entry: 127.0.0.1 www.antiwurm2008.com
                Removed hosts entry: 127.0.0.1 antiwurm2008.com
                Removed hosts entry: 127.0.0.1 www.archiviosex.net
                Removed hosts entry: 127.0.0.1 archiviosex.net
                Removed hosts entry: 127.0.0.1 www.ares.click-new-download.com
                Removed hosts entry: 127.0.0.1 ares.click-new-download.com
                Removed hosts entry: 127.0.0.1 www.asianpornmag.com
                Removed hosts entry: 127.0.0.1 asianpornmag.com
                Removed hosts entry: 127.0.0.1 www.aucunsvirus.com
                Removed hosts entry: 127.0.0.1 aucunsvirus.com
                Removed hosts entry: 127.0.0.1 www.autobargains.org
                Removed hosts entry: 127.0.0.1 autobargains.org
                Removed hosts entry: 127.0.0.1 www.autobargainsnetwork.com
                Removed hosts entry: 127.0.0.1 autobargainsnetwork.com
                Removed hosts entry: 127.0.0.1 www.autocontext.begun.ru
                Removed hosts entry: 127.0.0.1 autocontext.begun.ru
                Removed hosts entry: 127.0.0.1 autoescrowpay.com
                Removed hosts entry: 127.0.0.1 www.avast.free-software-center.com
                Removed hosts entry: 127.0.0.1 avast.free-software-center.com
                Removed hosts entry: 127.0.0.1 www.avast-downloads.com
                Removed hosts entry: 127.0.0.1 avast-downloads.com
                Removed hosts entry: 127.0.0.1 www.avg.softwarecenterz.com
                Removed hosts entry: 127.0.0.1 avg.softwarecenterz.com
                Removed hosts entry: 127.0.0.1 www.avpcheckupdate.com
                Removed hosts entry: 127.0.0.1 avpcheckupdate.com
                Removed hosts entry: 127.0.0.1 awmcash.biz
                Removed hosts entry: 127.0.0.1 awmdabest.com
                Removed hosts entry: 127.0.0.1 www.axemediasoftware.com
                Removed hosts entry: 127.0.0.1 axemediasoftware.com
                Removed hosts entry: 127.0.0.1 www.axmediasoftware.com
                Removed hosts entry: 127.0.0.1 axmediasoftware.com
                Removed hosts entry: 127.0.0.1 www.axsoftwaretool.com
                Removed hosts entry: 127.0.0.1 axsoftwaretool.com
                Removed hosts entry: 127.0.0.1 www.babespornmag.com
                Removed hosts entry: 127.0.0.1 babespornmag.com
                Removed hosts entry: 127.0.0.1 www.bardownload.com
                Removed hosts entry: 127.0.0.1 bardownload.com
                Removed hosts entry: 127.0.0.1 batsearch.com
                Removed hosts entry: 127.0.0.1 bbbsearch.com
                Removed hosts entry: 127.0.0.1 bb-search.com
                Removed hosts entry: 127.0.0.1 www.bdsmpornmag.com
                Removed hosts entry: 127.0.0.1 bdsmpornmag.com
                Removed hosts entry: 127.0.0.1 www.bearshare.click-new-download.com
                Removed hosts entry: 127.0.0.1 bearshare.click-new-download.com
                Removed hosts entry: 127.0.0.1 www.bearshare-download.org
                Removed hosts entry: 127.0.0.1 bearshare-download.org
                Removed hosts entry: 127.0.0.1 www.bearshare-downloads.net
                Removed hosts entry: 127.0.0.1 bearshare-downloads.net
                Removed hosts entry: 127.0.0.1 www.bearshare-music-downloads.com
                Removed hosts entry: 127.0.0.1 bearshare-music-downloads.com
                Removed hosts entry: 127.0.0.1 www.begin2search.com
                Removed hosts entry: 127.0.0.1 begin2search.com
                Removed hosts entry: 127.0.0.1 best-hardpics.com
                Removed hosts entry: 127.0.0.1 www.best-porncollection.com
                Removed hosts entry: 127.0.0.1 best-porncollection.com
                Removed hosts entry: 127.0.0.1 bestporngate.com
                Removed hosts entry: 127.0.0.1 www.bestsearchworld.info
                Removed hosts entry: 127.0.0.1 bestsearchworld.info
                Removed hosts entry: 127.0.0.1 www.bestworldgirls-for-u.net
                Removed hosts entry: 127.0.0.1 bestworldgirls-for-u.net
                Removed hosts entry: 127.0.0.1 bestxporno.com
                Removed hosts entry: 127.0.0.1 www.bettersearch.biz
                Removed hosts entry: 127.0.0.1 bettersearch.biz
                Removed hosts entry: 127.0.0.1 www.bgoogle.it
                Removed hosts entry: 127.0.0.1 bgoogle.it
                Removed hosts entry: 127.0.0.1 www.bigcodecadult.com
                Removed hosts entry: 127.0.0.1 bigcodecadult.com
                Removed hosts entry: 127.0.0.1 www.bigcodecadult2008.com
                Removed hosts entry: 127.0.0.1 bigcodecadult2008.com
                Removed hosts entry: 127.0.0.1 www.bigcodecadult2008-17.com
                Removed hosts entry: 127.0.0.1 bigcodecadult2008-17.com
                Removed hosts entry: 127.0.0.1 www.bighot18codec2008.com
                Removed hosts entry: 127.0.0.1 bighot18codec2008.com
                Removed hosts entry: 127.0.0.1 www.bighot18-codec2008.com
                Removed hosts entry: 127.0.0.1 bighot18-codec2008.com
                Removed hosts entry: 127.0.0.1 www.bittorrent.click-new-download.com
                Removed hosts entry: 127.0.0.1 bittorrent.click-new-download.com
                Removed hosts entry: 127.0.0.1 www.blackcodec.com
                Removed hosts entry: 127.0.0.1 blackcodec.com
                0
            • 1
            • 2
            • 3
            • 4