|
|
|
|
Configuration: Windows XP Firefox 3.0
Salut,
C'est certainement autre chose.... Commence par poster un rapport HijackThis stp, >Télécharge HiJackThis : http://www.commentcamarche.net/telecharger/telecharger-159-hijackthis - Lance le programme, puis sélectionne < do a system scan and save a logfile > - Enregistre le rapport sur ton bureau. Et envoie, par copier/coller, ton log Hijackthis sur le forum, A+ Fire Walk with Me ~~~~~~~~~~> o_Ö Pic et pic et colégramme, bourre et bourre et ratatam !
|
Bonsoir,
Il te faut un antivirus et un pare feu pour être bien protégé. Alors, > Essaye d'installer Antivir : : ouvre ce lien, lis le tuto, télécharge Antivir et installe le - Tu peux aussi télécharger Antivir ICI. - Lance Antivir, fais les mises à jours, branche tous ton matériel de stockage sur le PC, puis lance un scan (si des virus sont découverts, mets les en quarantaine. Si tu ne peux pas alors supprime les). - A la fin du scan clique sur 'report', enregistre ce rapport sur le bureau (fichier => enregistrer sous), puis fait un copier/coller de ce rapport dans ton prochain message. > Relance ton PC Ensuite, Afin d'éviter les trojans... : > Installe un pare feu : - Je te conseille Kerio : http://www.commentcamarche.net/telecharger/telecharger 206 kerio . Si problème, tuto : http://kerio.probb.fr/index.htm - Si tu as des difficultés avec les configuration de Kerio, alors installe Zone Alarme : /telecharger/telecharger-157-zonealarm, en cas de problème : http://forum.telecharger.01net.com/... - Installe le nouveau pare-feu, puis désactive le pare-feu windows. Puis poste un nouveau rapport HiJackT stp. Bon courage. Fire Walk with Me ~~~~~~~~~~> o_Ö Pic et pic et colégramme, bourre et bourre et ratatam ! |
Pour le moment j'ai AVG comme antivirus, spybot et ad aware pour les spyware...
Je désinstalle ça ? |
Avira AntiVir Personal
Report file date: 9 juillet 2008 16:27 Scanning for 1399817 virus strains and unwanted programs. Licensed to: Avira AntiVir PersonalEdition Classic Serial number: 0000149996-ADJIE-0001 Platform: Windows XP Windows version: (Service Pack 2) [5.1.2600] Boot mode: Normally booted Username: SYSTEM Computer name: PIAIRE Version information: BUILD.DAT : 8.1.00.295 16479 Bytes 2008-04-09 16:24:00 AVSCAN.EXE : 8.1.2.12 311553 Bytes 2008-03-18 15:02:56 AVSCAN.DLL : 8.1.1.0 53505 Bytes 2008-02-07 14:43:37 LUKE.DLL : 8.1.2.9 151809 Bytes 2008-02-28 14:41:23 LUKERES.DLL : 8.1.2.1 12033 Bytes 2008-02-21 14:28:40 ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 2007-07-18 16:33:34 ANTIVIR1.VDF : 7.0.5.1 8182784 Bytes 2008-06-24 20:23:48 ANTIVIR2.VDF : 7.0.5.86 547840 Bytes 2008-07-09 20:24:15 ANTIVIR3.VDF : 7.0.5.87 2048 Bytes 2008-07-09 20:24:16 Engineversion : 8.1.0.64 AEVDF.DLL : 8.1.0.5 102772 Bytes 2008-02-25 15:58:21 AESCRIPT.DLL : 8.1.0.46 283002 Bytes 2008-07-09 20:24:56 AESCN.DLL : 8.1.0.22 119157 Bytes 2008-07-09 20:24:50 AERDL.DLL : 8.1.0.20 418165 Bytes 2008-07-09 20:24:47 AEPACK.DLL : 8.1.1.6 364918 Bytes 2008-07-09 20:24:40 AEOFFICE.DLL : 8.1.0.20 192891 Bytes 2008-07-09 20:24:36 AEHEUR.DLL : 8.1.0.35 1298806 Bytes 2008-07-09 20:24:34 AEHELP.DLL : 8.1.0.15 115063 Bytes 2008-07-09 20:24:26 AEGEN.DLL : 8.1.0.29 307573 Bytes 2008-07-09 20:24:24 AEEMU.DLL : 8.1.0.6 430451 Bytes 2008-07-09 20:24:22 AECORE.DLL : 8.1.0.32 168311 Bytes 2008-07-09 20:24:19 AVWINLL.DLL : 1.0.0.7 14593 Bytes 2008-01-23 23:07:53 AVPREF.DLL : 8.0.0.1 25857 Bytes 2008-02-18 16:37:50 AVREP.DLL : 7.0.0.1 155688 Bytes 2007-04-16 19:26:47 AVREG.DLL : 8.0.0.0 30977 Bytes 2008-01-23 23:07:49 AVARKT.DLL : 1.0.0.23 307457 Bytes 2008-02-12 14:29:23 AVEVTLOG.DLL : 8.0.0.11 114945 Bytes 2008-02-28 14:31:31 SQLITE3.DLL : 3.3.17.1 339968 Bytes 2008-01-22 23:28:02 SMTPLIB.DLL : 1.2.0.19 28929 Bytes 2008-01-23 23:08:39 NETNT.DLL : 8.0.0.1 7937 Bytes 2008-01-25 18:05:10 RCIMAGE.DLL : 8.0.0.35 2371841 Bytes 2008-03-10 20:37:25 RCTEXT.DLL : 8.0.32.0 86273 Bytes 2008-03-06 18:02:11 Configuration settings for the scan: Jobname..........................: Complete system scan Configuration file...............: c:\program files\avira\antivir personaledition classic\sysscan.avp Logging..........................: low Primary action...................: interactive Secondary action.................: ignore Scan master boot sector..........: on Scan boot sector.................: on Boot sectors.....................: C:, D:, F:, Scan memory......................: on Process scan.....................: on Scan registry....................: on Search for rootkits..............: off Scan all files...................: Intelligent file selection Scan archives....................: on Recursion depth..................: 20 Smart extensions.................: on Macro heuristic..................: on File heuristic...................: medium Start of the scan: 9 juillet 2008 16:27 The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'wmiprvse.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'sched.exe' - '1' Module(s) have been scanned Scan process 'avgnt.exe' - '1' Module(s) have been scanned Scan process 'avguard.exe' - '1' Module(s) have been scanned Scan process 'firefox.exe' - '1' Module(s) have been scanned Scan process 'wscntfy.exe' - '1' Module(s) have been scanned Scan process 'distnoted.exe' - '1' Module(s) have been scanned Scan process 'AppleMobileDeviceHelper.exe' - '1' Module(s) have been scanned Scan process 'iTunes.exe' - '1' Module(s) have been scanned Scan process 'usnsvc.exe' - '1' Module(s) have been scanned Scan process 'PSNGive.exe' - '1' Module(s) have been scanned Scan process 'RAMASST.exe' - '1' Module(s) have been scanned Scan process 'PsnLite.exe' - '1' Module(s) have been scanned Scan process 'iPodService.exe' - '1' Module(s) have been scanned Scan process 'TeaTimer.exe' - '1' Module(s) have been scanned Scan process 'msnmsgr.exe' - '1' Module(s) have been scanned Scan process 'msmsgs.exe' - '1' Module(s) have been scanned Scan process 'TOSCDSPD.exe' - '1' Module(s) have been scanned Scan process 'ctfmon.exe' - '1' Module(s) have been scanned Scan process 'iTunesHelper.exe' - '1' Module(s) have been scanned Scan process 'realsched.exe' - '1' Module(s) have been scanned Scan process 'jusched.exe' - '1' Module(s) have been scanned Scan process 'OpWareSE4.exe' - '1' Module(s) have been scanned Scan process 'Dot1XCfg.exe' - '1' Module(s) have been scanned Scan process 'TPSBattM.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'TPSMain.exe' - '1' Module(s) have been scanned Scan process 'igfxpers.exe' - '1' Module(s) have been scanned Scan process 'hkcmd.exe' - '1' Module(s) have been scanned Scan process 'Toshiba.exe' - '1' Module(s) have been scanned Scan process 'iFrmewrk.exe' - '1' Module(s) have been scanned Scan process 'ZCfgSvc.exe' - '1' Module(s) have been scanned Scan process 'SynTPEnh.exe' - '1' Module(s) have been scanned Scan process 'ltmoh.exe' - '1' Module(s) have been scanned Scan process 'TFncKy.exe' - '1' Module(s) have been scanned Scan process 'THotkey.exe' - '1' Module(s) have been scanned Scan process 'TvsTray.exe' - '1' Module(s) have been scanned Scan process 'SmoothView.exe' - '1' Module(s) have been scanned Scan process 'DLACTRLW.EXE' - '1' Module(s) have been scanned Scan process 'NDSTray.exe' - '1' Module(s) have been scanned Scan process 'agrsmmsg.exe' - '1' Module(s) have been scanned Scan process 'dllhost.exe' - '1' Module(s) have been scanned Scan process 'RTHDCPL.exe' - '1' Module(s) have been scanned Scan process 'ehmsas.exe' - '1' Module(s) have been scanned Scan process 'ehtray.exe' - '1' Module(s) have been scanned Scan process 'alg.exe' - '1' Module(s) have been scanned Scan process 'mcrdsvc.exe' - '1' Module(s) have been scanned Scan process 'TAPPSRV.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'RegSrvc.exe' - '1' Module(s) have been scanned Scan process 'MDM.EXE' - '1' Module(s) have been scanned Scan process 'ehSched.exe' - '1' Module(s) have been scanned Scan process 'ehrecvr.exe' - '1' Module(s) have been scanned Scan process 'DVDRAMSV.exe' - '1' Module(s) have been scanned Scan process 'CFSvcs.exe' - '1' Module(s) have been scanned Scan process 'AppleMobileDeviceService.exe' - '1' Module(s) have been scanned Scan process 'spoolsv.exe' - '1' Module(s) have been scanned Scan process 'aawservice.exe' - '1' Module(s) have been scanned Scan process 'explorer.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'S24EvMon.exe' - '1' Module(s) have been scanned Scan process 'EvtEng.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 75 processes with 75 modules were scanned Starting master boot sector scan: Master boot sector HD0 [INFO] No virus was found! Master boot sector HD1 [INFO] No virus was found! Start scanning boot sectors: Boot sector 'C:\' [INFO] No virus was found! Boot sector 'D:\' [INFO] No virus was found! Boot sector 'F:\' [INFO] No virus was found! Starting to scan the registry. The registry was scanned ( '46' files ). Starting the file scan: Begin scan in 'C:\' <S3A4031D002FR> C:\hiberfil.sys [WARNING] The file could not be opened! C:\pagefile.sys [WARNING] The file could not be opened! C:\Documents and Settings\Piaire Blais\Local Settings\Temporary Internet Files\Content.IE5\2ZW9QLGJ\EditMessageLight[1].htm [DETECTION] Contains suspicious code HEUR/HTML.Malware [NOTE] The fund was classified as suspicious. [NOTE] The file was moved to '48de2345.qua'! C:\Documents and Settings\Piaire Blais\Local Settings\Temporary Internet Files\Content.IE5\AT3SDKF2\EditMessageLight[2].htm [DETECTION] Contains suspicious code HEUR/HTML.Malware [NOTE] The fund was classified as suspicious. [NOTE] The file was moved to '48de2446.qua'! C:\Documents and Settings\Piaire Blais\Local Settings\Temporary Internet Files\Content.IE5\WVRR2C5L\EditMessageLight[1].htm [DETECTION] Contains suspicious code HEUR/HTML.Malware [NOTE] The fund was classified as suspicious. [NOTE] The file was moved to '48de24c4.qua'! Begin scan in 'D:\' Begin scan in 'F:\' <New Volume> F:\Musique\05 Track 5.wma [DETECTION] Is the Trojan horse TR/Wimad.A.Gen [NOTE] The file was moved to '48953dec.qua'! End of the scan: 9 juillet 2008 18:46 Used time: 2:18:32 min The scan has been done completely. 8234 Scanning directories 461951 Files were scanned 1 viruses and/or unwanted programs were found 3 Files were classified as suspicious: 0 files were deleted 0 files were repaired 4 files were moved to quarantine 0 files were renamed 2 Files cannot be scanned 461950 Files not concerned 8771 Archives were scanned 2 Warnings 4 Notes |
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:08:01, on 2008-07-10 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\WINDOWS\system32\DVDRAMSV.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe C:\Program Files\TOSHIBA\Tvs\TvsTray.exe C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe C:\Program Files\ltmoh\Ltmoh.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Synaptics\SynTP\Toshiba.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\TPSMain.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\TPSBattM.exe C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\3M\PSNLite\PsnLite.exe C:\WINDOWS\system32\RAMASST.exe C:\PROGRA~1\3M\PSNLite\PSNGive.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\iTunes\iTunes.exe C:\Program Files\Last.fm\LastFM.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\distnoted.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://shoptoshiba.ca/welcome R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing) O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL O2 - BHO: EWPBrowseObject Class - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Program Files\Canon\Easy-WebPrint\EWPBrowseLoader.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [NDSTray.exe] NDSTray.exe O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe O4 - HKLM\..\Run: [Tvs] C:\Program Files\TOSHIBA\Tvs\TvsTray.exe O4 - HKLM\..\Run: [THotkey] C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe O4 - HKLM\..\Run: [TFncKy] TFncKy.exe O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe" O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [TPSMain] TPSMain.exe O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Fichiers communs\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - S-1-5-18 Startup: IEHOME.LNK = C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat (User 'SYSTEM') O4 - .DEFAULT Startup: IEHOME.LNK = C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat (User 'Default user') O4 - .DEFAULT User Startup: IEHOME.LNK = C:\Documents and Settings\Default User\Local Settings\Temp\iehome.bat (User 'Default user') O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Post-it® Software Notes Lite.lnk = C:\Program Files\3M\PSNLite\PsnLite.exe O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/resources/MSNPUpld.cab O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe O23 - Service: Avira AntiVir Personal – Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: TOSHIBA Application Service (TAPPSRV) - TOSHIBA Corp. - C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe O24 - Desktop Component 0: (no name) - http://i45.photobucket.com/albums/f94/hazeleyegrl1/RonJeremy.jpg End of file - 11388 bytes |
Bonjour,
Désolé pour AVG8, en fait tu avais un antivirus.... Mais je te conseille de garder Antivir qui est plus performant. As-tu volontairement installé cette image ? : http://i45.photobucket.com/albums/f94/hazeleyegrl1/RonJeremy.jpg Sinon je n evois pas grand chose dans le HiJAckT à part que tu n'as pas installé de pare feu. Je te recommande de le faire. Dis moi pour l'image. Sinon on passe à autre chose (un rapport qui en dis plus que HiJAckT). A+ Fire Walk with Me ~~~~~~~~~~> o_Ö Pic et pic et colégramme, bourre et bourre et ratatam ! |
Non je n'ai aps installé ca, et je l'ai vue hier en me demandant ce que c'était... ca peut être un virus ? |
Ok,
alors, >Ouvre ce lien http://siri.urz.free.fr/Fix/SmitfraudFix.php et télécharge SmitfraudFix (de S!RI). - Regarde le tuto - Exécute le programme et choisi l’option 1 (et uniquement). Le programme va générer un rapport, copie/colle le sur le forum. Puis on continue. A+ Fire Walk with Me ~~~~~~~~~~> o_Ö Pic et pic et colégramme, bourre et bourre et ratatam ! |
SmitFraudFix v2.329
Rapport fait à 13:48:39,17, 2008-07-10 Executé à partir de C:\Documents and Settings\Piaire Blais\Bureau\SmitfraudFix OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT Le type du système de fichiers est NTFS Fix executé en mode normal »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe C:\WINDOWS\system32\DVDRAMSV.exe C:\WINDOWS\eHome\ehRecvr.exe C:\WINDOWS\eHome\ehSched.exe C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Toshiba\TOSHIBA Applet\TAPPSRV.exe C:\WINDOWS\ehome\ehtray.exe C:\WINDOWS\eHome\ehmsas.exe C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\dllhost.exe C:\WINDOWS\AGRSMMSG.exe C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe C:\WINDOWS\System32\DLA\DLACTRLW.EXE C:\Program Files\TOSHIBA\Utilitaire de zoom TOSHIBA\SmoothView.exe C:\Program Files\TOSHIBA\Tvs\TvsTray.exe C:\Program Files\Toshiba\Toshiba Applet\thotkey.exe C:\Program Files\TOSHIBA\Commandes TOSHIBA\TFncKy.exe C:\Program Files\ltmoh\Ltmoh.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe C:\Program Files\Synaptics\SynTP\Toshiba.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\WINDOWS\system32\TPSMain.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\TPSBattM.exe C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\3M\PSNLite\PsnLite.exe C:\WINDOWS\system32\RAMASST.exe C:\PROGRA~1\3M\PSNLite\PSNGive.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe C:\Program Files\iTunes\iTunes.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceHelper.exe C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\distnoted.exe C:\Documents and Settings\Piaire Blais\Bureau\SmitfraudFix\Policies.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts Fichier hosts corrompu ! 127.0.0.1 www.legal-at-spybot.info 127.0.0.1 legal-at-spybot.info »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Piaire Blais »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Piaire Blais\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\PIAIRE~1\Favoris »»»»»»»»»»»»»»»»»»»»»»»» Bureau »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="http://i45.photobucket.com/albums/f94/hazeleyegrl1/RonJeremy.jpg" "SubscribedURL"="http://i45.photobucket.com/albums/f94/hazeleyegrl1/RonJeremy.jpg" "FriendlyName"="" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="Ma page d'accueil" »»»»»»»»»»»»»»»»»»»»»»»» IEDFix !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! IEDFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» VACFix !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! VACFix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» 404Fix !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! 404Fix Credits: Malware Analysis & Diagnostic Code: S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" "LoadAppInit_DLLs"=dword:00000001 »»»»»»»»»»»»»»»»»»»»»»»» Winlogon !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "Userinit"="C:\\WINDOWS\\system32\\userinit.exe," "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Intel(R) PRO/Wireless 3945ABG Network Connection - Miniport d'ordonnancement de paquets DNS Server Search Order: 192.168.0.1 HKLM\SYSTEM\CCS\Services\Tcpip\..\{E819BF7A-5644-4812-A0C9-EAFFBADE2B0B}: DhcpNameServer=192.168.0.1 HKLM\SYSTEM\CS1\Services\Tcpip\..\{E819BF7A-5644-4812-A0C9-EAFFBADE2B0B}: DhcpNameServer=192.168.0.1 HKLM\SYSTEM\CS3\Services\Tcpip\..\{E819BF7A-5644-4812-A0C9-EAFFBADE2B0B}: DhcpNameServer=192.168.0.1 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1 HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.0.1 »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll »»»»»»»»»»»»»»»»»»»»»»»» Fin |
Re,
alors, > Démarre en mode sans échec : (image). Si problème : tuto ici - Dans le dossier "SmitfraudFix" ouvre "Smitfraudfix.cmd" puis choisit l 'option 2 et tape "oui" pour toutes les questions. - Enregistre le rapport puis envoie le dans ton prochain poste. Ensuite, > Télécharge Zeb-Restore : http://telechargement.zebulon.fr/zeb-restore.html - Mets le dans un dossier, sur ton bureau par exemple. - Lance Zebrestore et coche la/les case(s) suivante(s) : Sites de confiance et sensibles Préfixes et Protocoles Internet Réinitialiser Fichier Hosts - Ne coche que la/les case(s) indiquée(s). - Clique sur le bouton Restaurer. - Quitte le programme. Après, je te conseille d'activer ton pare feu sinon il ne sert à rien ;-) Comment va la machine ? Sinon on fait un autre nettoyage (de toutes façons il serrait bon de le faire). J'attends ta réponse. A+ Fire Walk with Me ~~~~~~~~~~> o_Ö Pic et pic et colégramme, bourre et bourre et ratatam ! |
SmitFraudFix v2.329
Rapport fait à 17:55:28,93, 2008-07-10 Executé à partir de C:\Documents and Settings\Piaire Blais\Bureau\SmitfraudFix OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT Le type du système de fichiers est NTFS Fix executé en mode sans echec »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix !!!Attention, les clés qui suivent ne sont pas forcément infectées!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.1001-search.info 127.0.0.1 1001-search.info 127.0.0.1 www.100888290cs.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 www.10sek.com 127.0.0.1 10sek.com 127.0.0.1 www.123topsearch.com 127.0.0.1 123topsearch.com 127.0.0.1 www.132.com 127.0.0.1 132.com 127.0.0.1 www.136136.net 127.0.0.1 136136.net 127.0.0.1 www.139mm.com 127.0.0.1 139mm.com 127.0.0.1 www.163ns.com 127.0.0.1 163ns.com 127.0.0.1 171203.com 127.0.0.1 17-plus.com 127.0.0.1 www.1800searchonline.com 127.0.0.1 1800searchonline.com 127.0.0.1 www.180searchassistant.com 127.0.0.1 180searchassistant.com 127.0.0.1 www.180solutions.com 127.0.0.1 180solutions.com 127.0.0.1 www.181.365soft.info 127.0.0.1 181.365soft.info 127.0.0.1 www.1987324.com 127.0.0.1 1987324.com 127.0.0.1 www.1-domains-registrations.com 127.0.0.1 1-domains-registrations.com 127.0.0.1 www.1-extreme.biz 127.0.0.1 1-extreme.biz 127.0.0.1 www.1sexparty.com 127.0.0.1 1sexparty.com 127.0.0.1 www.1stantivirus.com 127.0.0.1 1stantivirus.com 127.0.0.1 www.1stpagehere.com 127.0.0.1 1stpagehere.com 127.0.0.1 www.1stsearchportal.com 127.0.0.1 1stsearchportal.com 127.0.0.1 2.82211.net 127.0.0.1 www.2006ooo.com 127.0.0.1 www.2007-download.com 127.0.0.1 2007-download.com 127.0.0.1 www.2020search.com 127.0.0.1 2020search.com 127.0.0.1 20x2p.com 127.0.0.1 www.24.365soft.info 127.0.0.1 24.365soft.info 127.0.0.1 www.24-7pharmacy.info 127.0.0.1 24-7pharmacy.info 127.0.0.1 www.24-7searching-and-more.com 127.0.0.1 24-7searching-and-more.com 127.0.0.1 www.24teen.com 127.0.0.1 24teen.com 127.0.0.1 www.2every.net 127.0.0.1 2every.net 127.0.0.1 2ndpower.com 127.0.0.1 www.2search.com 127.0.0.1 2search.com 127.0.0.1 www.2search.org 127.0.0.1 2search.org 127.0.0.1 www.2squared.com 127.0.0.1 2squared.com 127.0.0.1 www.3322.org 127.0.0.1 3322.org 127.0.0.1 365soft.info 127.0.0.1 www.36site.com 127.0.0.1 36site.com 127.0.0.1 3721.com 127.0.0.1 39-93.com 127.0.0.1 www.3abetterinternet.com 127.0.0.1 3abetterinternet.com 127.0.0.1 www.3bay.it 127.0.0.1 3bay.it 127.0.0.1 www.3ebay.it 127.0.0.1 3ebay.it 127.0.0.1 www.3xclipsonline.com 127.0.0.1 3xclipsonline.com 127.0.0.1 www.3xcurves.com 127.0.0.1 3xcurves.com 127.0.0.1 www.3xfestival.com 127.0.0.1 3xfestival.com 127.0.0.1 www.3x-festival.com 127.0.0.1 3x-festival.com 127.0.0.1 www.3x-galls.com 127.0.0.1 3x-galls.com 127.0.0.1 www.3xmiracle.com 127.0.0.1 3xmiracle.com 127.0.0.1 www.3xmoviesblog.com 127.0.0.1 3xmoviesblog.com 127.0.0.1 www.404dns.com 127.0.0.1 404dns.com 127.0.0.1 www.4199.com 127.0.0.1 4199.com 127.0.0.1 www.4corn.net 127.0.0.1 4corn.net 127.0.0.1 www.4ebay.it 127.0.0.1 4ebay.it 127.0.0.1 4klm.com 127.0.0.1 www.4mpg.com 127.0.0.1 4mpg.com 127.0.0.1 www.4repubblica.it 127.0.0.1 4repubblica.it 127.0.0.1 www.4softget.com 127.0.0.1 4softget.com 127.0.0.1 www.5iscali.it 127.0.0.1 5iscali.it 127.0.0.1 www.5repubblica.it 127.0.0.1 5repubblica.it 127.0.0.1 www.5starvideos.com 127.0.0.1 5starvideos.com 127.0.0.1 www.5tiscali.it 127.0.0.1 5tiscali.it 127.0.0.1 www.5zgmu7o20kt5d8yq.com 127.0.0.1 5zgmu7o20kt5d8yq.com 127.0.0.1 www.680180.net 127.0.0.1 680180.net 127.0.0.1 www.6iscali.it 127.0.0.1 6iscali.it 127.0.0.1 www.6njaga.com 127.0.0.1 6njaga.com 127.0.0.1 www.6sek.com 127.0.0.1 6sek.com 127.0.0.1 www.6tiscali.it 127.0.0.1 6tiscali.it 127.0.0.1 www.70-music.com 127.0.0.1 70-music.com 127.0.0.1 www.7322.com 127.0.0.1 7322.com 127.0.0.1 75tz.com 127.0.0.1 www.777search.com 127.0.0.1 777search.com 127.0.0.1 www.777top.com 127.0.0.1 777top.com 127.0.0.1 www.7939.com 127.0.0.1 7939.com 127.0.0.1 www.7search.com 127.0.0.1 7search.com 127.0.0.1 80gw6ry3i3x3qbrkwhxhw.032439.com 127.0.0.1 www.80-music.com 127.0.0.1 80-music.com 127.0.0.1 82211.net 127.0.0.1 8866.org 127.0.0.1 www.8ad.com 127.0.0.1 8ad.com 127.0.0.1 www.90-music.com 127.0.0.1 90-music.com 127.0.0.1 www.9505.com 127.0.0.1 9505.com 127.0.0.1 www.971searchbox.com 127.0.0.1 971searchbox.com 127.0.0.1 a.bestmanage.org 127.0.0.1 www.aaabesthomepage.com 127.0.0.1 aaabesthomepage.com 127.0.0.1 aaasexypics.com 127.0.0.1 www.aaawebfinder.com 127.0.0.1 aaawebfinder.com 127.0.0.1 www.aaqadarsztriv.com 127.0.0.1 aaqadarsztriv.com 127.0.0.1 www.aaqada-rsztriv.com 127.0.0.1 aaqada-rsztriv.com 127.0.0.1 www.aaqadaueorn.com 127.0.0.1 aaqadaueorn.com 127.0.0.1 www.aaqada-ueorn.com 127.0.0.1 aaqada-ueorn.com 127.0.0.1 www.aaqada-ygco.com 127.0.0.1 aaqada-ygco.com 127.0.0.1 www.aaqada-ymct.com 127.0.0.1 aaqada-ymct.com 127.0.0.1 aavc.com 127.0.0.1 www.abcdperformance.com 127.0.0.1 abcdperformance.com 127.0.0.1 www.abc-find.info 127.0.0.1 abc-find.info 127.0.0.1 www.abcsearch.com 127.0.0.1 abcsearch.com 127.0.0.1 www.abetterinternet.com 127.0.0.1 abetterinternet.com 127.0.0.1 www.abnetsoft.info 127.0.0.1 abnetsoft.info 127.0.0.1 www.aboutclicker.com 127.0.0.1 aboutclicker.com 127.0.0.1 www.abrp.net 127.0.0.1 abrp.net 127.0.0.1 www.absolutee.com 127.0.0.1 absolutee.com 127.0.0.1 www.abyssmedia.com 127.0.0.1 abyssmedia.com 127.0.0.1 www.ac66.cn 127.0.0.1 ac66.cn 127.0.0.1 access.Navinetwork.com 127.0.0.1 access.rapid-pass.net 127.0.0.1 www.accessactivexvideo.com 127.0.0.1 accessactivexvideo.com 127.0.0.1 www.accessclips.com 127.0.0.1 accessclips.com 127.0.0.1 www.access-dvd.com 127.0.0.1 access-dvd.com 127.0.0.1 www.accesskeygenerator.com 127.0.0.1 accesskeygenerator.com 127.0.0.1 www.accessorygeeks.com 127.0.0.1 accessorygeeks.com 127.0.0.1 www.accessthefuture.net 127.0.0.1 accessthefuture.net 127.0.0.1 www.accessvid.net 127.0.0.1 accessvid.net 127.0.0.1 www.acemedic.com 127.0.0.1 acemedic.com 127.0.0.1 www.ace-webmaster.com 127.0.0.1 ace-webmaster.com 127.0.0.1 acjp.com 127.0.0.1 www.acrobat-2007.com 127.0.0.1 acrobat-2007.com 127.0.0.1 www.acrobat-8.com 127.0.0.1 acrobat-8.com 127.0.0.1 www.acrobat-center.com 127.0.0.1 acrobat-center.com 127.0.0.1 www.acrobat-hq.com 127.0.0.1 acrobat-hq.com 127.0.0.1 www.acrobatreader-8.com 127.0.0.1 acrobatreader-8.com 127.0.0.1 www.acrobat-reader-8.de 127.0.0.1 acrobat-reader-8.de 127.0.0.1 www.acrobat-stop.com 127.0.0.1 acrobat-stop.com 127.0.0.1 www.actionbreastcancer.org 127.0.0.1 actionbreastcancer.org 127.0.0.1 www.activesearcher.info 127.0.0.1 activesearcher.info 127.0.0.1 www.activexaccessobject.com 127.0.0.1 activexaccessobject.com 127.0.0.1 www.activexaccessvideo.com 127.0.0.1 activexaccessvideo.com 127.0.0.1 www.activexemedia.com 127.0.0.1 activexemedia.com 127.0.0.1 www.activexmediaobject.com 127.0.0.1 activexmediaobject.com 127.0.0.1 www.activexmediapro.com 127.0.0.1 activexmediapro.com 127.0.0.1 www.activexmediasite.com 127.0.0.1 activexmediasite.com 127.0.0.1 www.activexmediasoftware.com 127.0.0.1 activexmediasoftware.com 127.0.0.1 www.activexmediasource.com 127.0.0.1 activexmediasource.com 127.0.0.1 www.activexmediatool.com 127.0.0.1 activexmediatool.com 127.0.0.1 www.activexmediatour.com 127.0.0.1 activexmediatour.com 127.0.0.1 www.activexsoftwares.com 127.0.0.1 activexsoftwares.com 127.0.0.1 www.activexsource.com 127.0.0.1 activexsource.com 127.0.0.1 www.activexupdate.com 127.0.0.1 activexupdate.com 127.0.0.1 www.activexvideo.com 127.0.0.1 activexvideo.com 127.0.0.1 www.activexvideotool.com 127.0.0.1 activexvideotool.com 127.0.0.1 www.ad.marketingsector.com 127.0.0.1 ad.marketingsector.com 127.0.0.1 www.ad.mokead.com 127.0.0.1 ad.mokead.com 127.0.0.1 ad.oinadserver.com 127.0.0.1 ad.outerinfoads.com 127.0.0.1 www.ad25.com 127.0.0.1 ad25.com 127.0.0.1 www.ad45.com 127.0.0.1 ad45.com 127.0.0.1 www.ad77.com 127.0.0.1 ad77.com 127.0.0.1 www.ad86.com 127.0.0.1 ad86.com 127.0.0.1 www.adamsupportgroup.org 127.0.0.1 adamsupportgroup.org 127.0.0.1 www.adarmor.com 127.0.0.1 adarmor.com 127.0.0.1 www.adasearch.com 127.0.0.1 adasearch.com 127.0.0.1 adaware.cc 127.0.0.1 www.adawarenow.com 127.0.0.1 adawarenow.com 127.0.0.1 adchannel.contextplus.net 127.0.0.1 www.addetect.com 127.0.0.1 addetect.com 127.0.0.1 www.add-hhh.info 127.0.0.1 add-hhh.info 127.0.0.1 www.addictivetechnologies.com 127.0.0.1 addictivetechnologies.com 127.0.0.1 www.addictivetechnologies.net 127.0.0.1 addictivetechnologies.net 127.0.0.1 www.addioerrori.com 127.0.0.1 addioerrori.com 127.0.0.1 www.add-manager.com 127.0.0.1 add-manager.com 127.0.0.1 www.adgate.info 127.0.0.1 adgate.info 127.0.0.1 www.adintelligence.net 127.0.0.1 adintelligence.net 127.0.0.1 www.adioserrores.com 127.0.0.1 adioserrores.com 127.0.0.1 www.adipics.com 127.0.0.1 adipics.com 127.0.0.1 www.adlogix.com 127.0.0.1 adlogix.com 127.0.0.1 www.admin2cash.biz 127.0.0.1 admin2cash.biz 127.0.0.1 adnet-plus.com 127.0.0.1 www.adnetserver.com 127.0.0.1 adnetserver.com 127.0.0.1 adobe-download-now.com 127.0.0.1 www.adobe-downloads.com 127.0.0.1 adobe-downloads.com 127.0.0.1 www.adobe-reader-8.fr 127.0.0.1 adobe-reader-8.fr 127.0.0.1 www.adprotect.com 127.0.0.1 adprotect.com 127.0.0.1 ads.centralmedia.ws 127.0.0.1 ads.k8l.info 127.0.0.1 ads.kmpads.com 127.0.0.1 ads.kw.revenue.net 127.0.0.1 ads.marketingsector.com 127.0.0.1 ads.searchingbooth.com 127.0.0.1 ads.z-quest.com 127.0.0.1 ads1.revenue.net 127.0.0.1 www.ads183.com 127.0.0.1 ads183.com 127.0.0.1 www.adscontex.com 127.0.0.1 adscontex.com 127.0.0.1 www.adservices1.enhance.com 127.0.0.1 adservices1.enhance.com 127.0.0.1 adservs.com 127.0.0.1 www.adsextend.net 127.0.0.1 adsextend.net 127.0.0.1 www.adshttp.com 127.0.0.1 adshttp.com 127.0.0.1 www.adsniffer.com 127.0.0.1 adsniffer.com 127.0.0.1 www.adsonwww.com 127.0.0.1 adsonwww.com 127.0.0.1 www.adspics.com 127.0.0.1 adspics.com 127.0.0.1 www.adsrevenue.net 127.0.0.1 adsrevenue.net 127.0.0.1 www.adtrak.net 127.0.0.1 adtrak.net 127.0.0.1 adtrgt.com 127.0.0.1 www.adult777search.info 127.0.0.1 adult777search.info 127.0.0.1 www.adultan.com 127.0.0.1 adultan.com 127.0.0.1 www.adult-engine-search.com 127.0.0.1 adult-engine-search.com 127.0.0.1 www.adult-erotic-guide.net 127.0.0.1 adult-erotic-guide.net 127.0.0.1 www.adultfilmsite.com 127.0.0.1 adultfilmsite.com 127.0.0.1 www.adult-friends-finder.net 127.0.0.1 adult-friends-finder.net 127.0.0.1 adultgambling.org 127.0.0.1 adult-host.org 127.0.0.1 www.adulthyperlinks.com 127.0.0.1 adulthyperlinks.com 127.0.0.1 www.adultmovieplus.com 127.0.0.1 adultmovieplus.com 127.0.0.1 www.adult-mpg.net 127.0.0.1 adult-mpg.net 127.0.0.1 adult-personal.us 127.0.0.1 adultsgames.net 127.0.0.1 www.adultsonlyvids.com 127.0.0.1 adultsonlyvids.com 127.0.0.1 www.adultsper.com 127.0.0.1 adultsper.com 127.0.0.1 www.adulttds.com 127.0.0.1 adulttds.com 127.0.0.1 www.adultzoneworld.com 127.0.0.1 adultzoneworld.com 127.0.0.1 www.advcash.biz 127.0.0.1 advcash.biz 127.0.0.1 advert.exaccess.ru 127.0.0.1 www.advertisemoney.info 127.0.0.1 advertisemoney.info 127.0.0.1 advertising.paltalk.com 127.0.0.1 www.advertising-money.info 127.0.0.1 advertising-money.info 127.0.0.1 ad-ware.cc 127.0.0.1 www.ad-w-a-r-e.com 127.0.0.1 ad-w-a-r-e.com 127.0.0.1 www.a-d-w-a-r-e.com 127.0.0.1 a-d-w-a-r-e.com 127.0.0.1 www.adware.pro 127.0.0.1 adware.pro 127.0.0.1 www.adwarealert.com 127.0.0.1 adwarealert.com 127.0.0.1 www.ad-warealert.com 127.0.0.1 ad-warealert.com 127.0.0.1 www.adwarearrest.com 127.0.0.1 adwarearrest.com 127.0.0.1 www.adwarebazooka.com 127.0.0.1 adwarebazooka.com 127.0.0.1 www.adwarecommander.com 127.0.0.1 adwarecommander.com 127.0.0.1 www.adwarefinder.com 127.0.0.1 adwarefinder.com 127.0.0.1 www.adwaregold.com 127.0.0.1 adwaregold.com 127.0.0.1 www.adwarepatrol.com 127.0.0.1 adwarepatrol.com 127.0.0.1 www.adwareplatinum.com 127.0.0.1 adwareplatinum.com 127.0.0.1 www.adwareprotectionsite.com 127.0.0.1 adwareprotectionsite.com 127.0.0.1 www.adwarepunisher.com 127.0.0.1 adwarepunisher.com 127.0.0.1 www.adwareremover.ws 127.0.0.1 adwareremover.ws 127.0.0.1 www.adwaresafety.com 127.0.0.1 adwaresafety.com 127.0.0.1 www.adwarexp.com 127.0.0.1 adwarexp.com 127.0.0.1 affiliate.idownload.com 127.0.0.1 www.aflgate.com 127.0.0.1 aflgate.com 127.0.0.1 africaspromise.org 127.0.0.1 agava.com 127.0.0.1 agava.ru 127.0.0.1 agentstudio.com 127.0.0.1 www.aginegialle.it 127.0.0.1 aginegialle.it 127.0.0.1 aifind.info 127.0.0.1 www.aifind.info 127.0.0.1 www.airtleworld.com 127.0.0.1 airtleworld.com 127.0.0.1 www.aitalia.it 127.0.0.1 aitalia.it 127.0.0.1 akamai.downloadv3.com 127.0.0.1 www.aklitalia.it 127.0.0.1 aklitalia.it 127.0.0.1 akril.com 127.0.0.1 alcatel.ws 127.0.0.1 www.alertspy.com 127.0.0.1 alertspy.com 127.0.0.1 www.alfacleaner.com 127.0.0.1 alfacleaner.com 127.0.0.1 alfa-search.com 127.0.0.1 www.alialia.it 127.0.0.1 alialia.it 127.0.0.1 www.aliotalia.it 127.0.0.1 aliotalia.it 127.0.0.1 www.alirtalia.it 127.0.0.1 alirtalia.it 127.0.0.1 www.alitaia.it 127.0.0.1 alitaia.it 127.0.0.1 www.alitaklia.it 127.0.0.1 alitaklia.it 127.0.0.1 www.alitala.it 127.0.0.1 alitala.it 127.0.0.1 www.alitali.it 127.0.0.1 alitali.it 127.0.0.1 www.alitaliaq.it 127.0.0.1 alitaliaq.it 127.0.0.1 www.alitalias.it 127.0.0.1 alitalias.it 127.0.0.1 www.alitaliaz.it 127.0.0.1 alitaliaz.it 127.0.0.1 www.alitalioa.it 127.0.0.1 alitalioa.it 127.0.0.1 www.alitalisa.it 127.0.0.1 alitalisa.it 127.0.0.1 www.alitaliua.it 127.0.0.1 alitaliua.it 127.0.0.1 www.alitalkia.it 127.0.0.1 alitalkia.it 127.0.0.1 www.alitaloia.it 127.0.0.1 alitaloia.it 127.0.0.1 www.alitaluia.it 127.0.0.1 alitaluia.it 127.0.0.1 www.alitaslia.it 127.0.0.1 alitaslia.it 127.0.0.1 www.alitlia.it 127.0.0.1 alitlia.it 127.0.0.1 www.alitralia.it 127.0.0.1 alitralia.it 127.0.0.1 www.alitsalia.it 127.0.0.1 alitsalia.it 127.0.0.1 www.aliutalia.it 127.0.0.1 aliutalia.it 127.0.0.1 www.ALL1COUNT.NET 127.0.0.1 ALL1COUNT.NET 127.0.0.1 www.all4internet.com 127.0.0.1 all4internet.com 127.0.0.1 allabtcars.com 127.0.0.1 allabtjeeps.com 127.0.0.1 www.all-bittorrent.com 127.0.0.1 all-bittorrent.com 127.0.0.1 www.allcollisions.com 127.0.0.1 allcollisions.com 127.0.0.1 allcybersearch.com 127.0.0.1 www.allcybersearch.com 127.0.0.1 www.alldnserrors.com 127.0.0.1 alldnserrors.com 127.0.0.1 www.all-downloads-now.com 127.0.0.1 all-downloads-now.com 127.0.0.1 www.all-edonkey.com 127.0.0.1 all-edonkey.com 127.0.0.1 www.allertaminacce.com 127.0.0.1 allertaminacce.com 127.0.0.1 allforadult.com 127.0.0.1 allhyperlinks.com 127.0.0.1 www.alliesecurity.com 127.0.0.1 alliesecurity.com 127.0.0.1 all-inet.com 127.0.0.1 allinternetbusiness.com 127.0.0.1 www.all-limewire.com 127.0.0.1 all-limewire.com 127.0.0.1 www.allmegabucks.com 127.0.0.1 allmegabucks.com 127.0.0.1 www.allprotections.com 127.0.0.1 allprotections.com 127.0.0.1 www.allresultz.net 127.0.0.1 allresultz.net 127.0.0.1 www.allsearch.us 127.0.0.1 allsearch.us 127.0.0.1 www.allsecuritynotes.com 127.0.0.1 allsecuritynotes.com 127.0.0.1 www.allsecuritysite.com 127.0.0.1 allsecuritysite.com 127.0.0.1 www.allstarsvideos.net 127.0.0.1 allstarsvideos.net 127.0.0.1 www.alltiettantivirus.com 127.0.0.1 alltiettantivirus.com 127.0.0.1 www.alltruesoftware.com 127.0.0.1 alltruesoftware.com 127.0.0.1 www.allvideoactivex.com 127.0.0.1 allvideoactivex.com 127.0.0.1 www.almanah.biz 127.0.0.1 almanah.biz 127.0.0.1 almarvideos.com 127.0.0.1 www.aloitalia.it 127.0.0.1 aloitalia.it 127.0.0.1 www.aluitalia.it 127.0.0.1 aluitalia.it 127.0.0.1 www.amaena.com 127.0.0.1 amaena.com 127.0.0.1 amandamountains.com 127.0.0.1 www.amateurliveshow.com 127.0.0.1 amateurliveshow.com 127.0.0.1 www.amediasoftware.com 127.0.0.1 amediasoftware.com 127.0.0.1 www.amediasource.com 127.0.0.1 amediasource.com 127.0.0.1 www.americanautobargains.com 127.0.0.1 americanautobargains.com 127.0.0.1 www.americancarbargains.com 127.0.0.1 americancarbargains.com 127.0.0.1 american-teens.net 127.0.0.1 amigeek.com 127.0.0.1 www.amigobore.com 127.0.0.1 amigobore.com 127.0.0.1 amisbusiness.com 127.0.0.1 www.ampmsearch.com 127.0.0.1 ampmsearch.com 127.0.0.1 www.analcord.com 127.0.0.1 analcord.com 127.0.0.1 analmovi.com 127.0.0.1 www.anarchylolita.com 127.0.0.1 anarchylolita.com 127.0.0.1 anarchyporn.com 127.0.0.1 www.andromedical.com 127.0.0.1 andromedical.com 127.0.0.1 www.animepornmag.com 127.0.0.1 animepornmag.com 127.0.0.1 anin.org 127.0.0.1 www.anjpn-avxiz.biz 127.0.0.1 anjpn-avxiz.biz 127.0.0.1 www.anjpnzqav.biz 127.0.0.1 anjpnzqav.biz 127.0.0.1 www.anjpn-zqav.biz 127.0.0.1 anjpn-zqav.biz 127.0.0.1 annaromeo.com 127.0.0.1 www.antiddos.us 127.0.0.1 antiddos.us 127.0.0.1 www.Antiespiadorado.com 127.0.0.1 Antiespiadorado.com 127.0.0.1 www.Antiespionspack.com 127.0.0.1 Antiespionspack.com 127.0.0.1 www.Antigusanos2008.com 127.0.0.1 Antigusanos2008.com 127.0.0.1 www.antispamassistant.com 127.0.0.1 antispamassistant.com 127.0.0.1 www.antispamdeluxe.com 127.0.0.1 antispamdeluxe.com 127.0.0.1 www.Antispionage.com 127.0.0.1 Antispionage.com 127.0.0.1 www.Antispionagepro.com 127.0.0.1 Antispionagepro.com 127.0.0.1 www.antispyadvanced.com 127.0.0.1 antispyadvanced.com 127.0.0.1 www.antispydns.biz 127.0.0.1 antispydns.biz 127.0.0.1 www.antispylab.com 127.0.0.1 antispylab.com 127.0.0.1 www.antispysolutions.com 127.0.0.1 antispysolutions.com 127.0.0.1 www.antispyware.com 127.0.0.1 antispyware.com 127.0.0.1 www.antispywareboot.com 127.0.0.1 antispywareboot.com 127.0.0.1 www.antispywarebot.com 127.0.0.1 antispywarebot.com 127.0.0.1 www.antispywarebox.com 127.0.0.1 antispywarebox.com 127.0.0.1 www.antispywaredownloads.com 127.0.0.1 antispywaredownloads.com 127.0.0.1 antispywaresuite.com 127.0.0.1 www.antispywaresuite.com 127.0.0.1 Antispywaresuite.com 127.0.0.1 www.Antispywaresuite.com 127.0.0.1 www.antispywareupdates.net 127.0.0.1 antispywareupdates.net 127.0.0.1 www.antispywarexp.com 127.0.0.1 antispywarexp.com 127.0.0.1 www.Antispyweb.net 127.0.0.1 Antispyweb.net 127.0.0.1 www.Antiver2008.com 127.0.0.1 Antiver2008.com 127.0.0.1 www.antivermins.com 127.0.0.1 antivermins.com 127.0.0.1 www.anti-vermins.com 127.0.0.1 anti-vermins.com 127.0.0.1 www.antivir2007.com 127.0.0.1 antivir2007.com 127.0.0.1 www.antivirgear.com 127.0.0.1 antivirgear.com 127.0.0.1 www.antivirus.fastfreedownload.com 127.0.0.1 antivirus.fastfreedownload.com 127.0.0.1 www.antivirusadvance.com 127.0.0.1 antivirusadvance.com 127.0.0.1 www.antivirusaskeladd.com 127.0.0.1 antivirusaskeladd.com 127.0.0.1 www.antivirusgereedschap.com 127.0.0.1 antivirusgereedschap.com 127.0.0.1 www.antivirusgolden.com 127.0.0.1 antivirusgolden.com 127.0.0.1 www.antivirus-hq.net 127.0.0.1 antivirus-hq.net 127.0.0.1 www.antiviruspcsuite.com 127.0.0.1 antiviruspcsuite.com 127.0.0.1 www.antiviruspremium.com 127.0.0.1 antiviruspremium.com 127.0.0.1 www.anti-virus-pro.com 127.0.0.1 anti-virus-pro.com 127.0.0.1 www.antivirusprotector.com 127.0.0.1 antivirusprotector.com 127.0.0.1 www.antivirusscherm.com 127.0.0.1 antivirusscherm.com 127.0.0.1 www.antivirussecuritypro.com 127.0.0.1 antivirussecuritypro.com 127.0.0.1 www.antivirus-stop.com 127.0.0.1 antivirus-stop.com 127.0.0.1 antiworm2008.com 127.0.0.1 www.antiworm2008.com 127.0.0.1 Antiworm2008.com 127.0.0.1 www.Antiworm2008.com 127.0.0.1 www.Antiwurm2008.com 127.0.0.1 Antiwurm2008.com 127.0.0.1 antrocity.com 127.0.0.1 www.anyofus.com 127.0.0.1 anyofus.com 127.0.0.1 www.anysn.seproger.com 127.0.0.1 anysn.seproger.com 127.0.0.1 anything4health.com 127.0.0.1 www.apicpreview.com 127.0.0.1 apicpreview.com 127.0.0.1 www.appealcircuit.com 127.0.0.1 appealcircuit.com 127.0.0.1 www.approvedlinks.com 127.0.0.1 approvedlinks.com 127.0.0.1 apps.deskwizz.com 127.0.0.1 apps.webservicehost.com 127.0.0.1 www.aprotectedpage.com 127.0.0.1 aprotectedpage.com 127.0.0.1 apsua.com 127.0.0.1 www.archivioadulti.com 127.0.0.1 archivioadulti.com 127.0.0.1 www.archiviosex.net 127.0.0.1 archiviosex.net 127.0.0.1 aregay.com 127.0.0.1 www.ares.click-new-download.com 127.0.0.1 ares.click-new-download.com 127.0.0.1 www.ares-freebie.com 127.0.0.1 ares-freebie.com 127.0.0.1 w |