Log HJT djolafrite (suite)

Sécurité et insécurité. Virus, Trojans, Spywares, Failles etc. …

Modérateur: Modérateurs et Modératrices

Règles du forum
Assiste.com a suspendu l'assistance à la décontamination après presque 15 ans sur l'ancien forum puis celui-ci. Voir :

Procédure de décontamination 1 - Anti-malware
Décontamination anti-malwares

Procédure de décontamination 2 - Anti-malware et antivirus (La Manip)
La Manip - Procédure standard de décontamination

Entretien périodique d'un PC sous Windows
Entretien périodique d'un PC sous Windows

Protection des navigateurs, de la navigation et de la vie privée
Protéger le navigateur, la navigation et la vie privée

Log HJT djolafrite (suite)

Messagede nickW » 14 Aoû 2005, 08:52

[Suite du fil de discussion Log Hijackthis de djolafrite - Vazkor]

Bonjour,

j'ai un message d'erreur me disant que le fichier nommé clean up n'existe pas et que je me suis sans doute trompée de nom en le recherchant

Quel est le libellé exact du message? (Titre de la fenêtre, texte exact,...)
Si le message concerne VcCleanUp.exe, il s'agit d'un programme de Symantec.
Aurais-tu désinstallé Norton antivirus ou Norton Internet Security?
Voir: http://assiste.com.free.fr/p/comment/de ... ivirus.php

le fichier d'installation de winfixer qui s'était d'autorité invité sur mon bureau, est toujours là, mais l'icône a changé d'apparence.

Faire un clic droit sur l'icône, Propriétés.
Dans l'onglet Général, décocher les attributs Lecture seule et Caché. OK.
Faire un clic droit sur l'icône, Supprimer.

ewido security suite ... m'a trouvé 609 fichiers infectés

Il s'agit en majorité (dans la partie visible du rapport, trop long pour être affiché en totalité) de cookies.
Peut-être devrais-tu ne plus accepter tous les cookies:
Outils--->Options--->Onglet Vie privée--->Cookies
Cocher la case située devant "pour le site Web d'origine seulement"



Pourrais-tu envoyer en réponse

1/ Le rapport de Spybot-S&D
Lancer SpyBot-S&D, faire une Recherche de mises à jour et les appliquer si trouvées.
Lancer un balayage complet ("Vérifier tout"), corriger les problèmes en rouge.
Sur la barre de menus principale, cliquer sur "Mode" et choisir "Mode avancé".
Dans le menu de gauche, choisir "Outils" puis "Voir le rapport".
Vérifier que toutes les options sont cochées sauf "N'incluez pas d'élément désactivé ou connu comme légal.".

Sélectionner (en haut) le bouton "Voir le rapport".
Appuyer sur "Exporter", dans la boîte de dialogue qui apparaît, choisir un emplacement et un nom de sauvegarde pour le fichier (en conservant le Type "Fichiers textes").

2/ Un rapport généré par Startdreck
Télécharger et exécuter Startdreck:
Voir: http://assiste.com.free.fr/p/internet_u ... tdreck.php
Téléchargement: http://www.niksoft.at/download/startdreck.htm
Décompresser l'archive startdreck.zip dans un répertoire qui lui sera réservé (par exemple, c:\startdreck).

Lancer le programme par double clic sur StartDreck.exe

Trouver, en bas, un bouton nommé "Config" et cliquer dessus.
Localiser le bouton "unmark all" et cliquer dessus.

Cocher les cases comme ci-dessous:

Image

La case "refresh on exiting config dialog" doit rester cochée.
Cliquer sur le bouton "OK".

Attendre le nouvel affichage (c'est presque instantané).

Cliquer ensuite sur le bouton "Save".
Donner un nom au fichier de sauvegarde.
L'ouvrir dans un éditeur de texte (Notepad ou Wordpad), Fichier--->Sélectionner tout, Fichier--->Copier, puis le coller dans un message en réponse.



Remarque: Les deux logs étant longs, il serait préférable de les envoyer dans deux réponses séparées.

A suivre,
nickW - Image
30/07/2012: Plus de désinfection de PC jusqu'à nouvel ordre.
Pas de demande d'analyse de log en MP (Message Privé)
Mes configs
Avatar de l’utilisateur
nickW
Modérateur
 
Messages: 21698
Inscription: 20 Mai 2004, 17:41
Localisation: Dordogne/Île de France

Messagede Vazkor » 14 Aoû 2005, 09:21

Bonjour,

Juste une petite remarque en passant
Mon brave UltraEdit compte exactement 572 lignes de ce genre dans le rapport ewido:
:mozilla.22:C:\FOUND.037\FILE0011.CHK -> Spyware.Cookie.Doubleclick : Nettoyer et sauvegarder

Il te faut savoir que les dossiers C:\FOUND.* et les fichiers FILE*.CHK sont créés par Scandisk (chkdsk.exe), pour te permettre éventuellement de recupérer des bouts de fichiers contenus dans des secteurs défectueux. Mais comme le contenu de ces fichiers dans 90% des cas est illisible, cele ne peut servir qu'à récupérer quelques parties de petits fichiers texte simple (.txt, .log). Donc très très peu utile.

Tu peux effacer sans crainte tous ces dossiers et leur contenu, qui ne font que gaspiller de la place sur ton disque dur.

Et à l'avenir quand tu lanceras une vérification d'un disque, dans Options de vérification du disque:
Coche seulement la case "Réparer automatiquement les erreurs de système de fichiers"
Décoche "Rechercher et tenter la récupération des secteurs défectueux".

Si tu effectues chkdsk.exe depuis Invite de commandes, tape chkdsk C: /F pour vérifier le disque C:
N'utilise surtout pas le paramètre /R

Je laisse NickW continuer à s'occuper de tes logs.

@+
Avatar de l’utilisateur
Vazkor
 
Messages: 9810
Inscription: 05 Nov 2002, 23:39
Localisation: Ans, BE

rapport spybot s&d

Messagede djolafrite » 14 Aoû 2005, 13:56

--- Search result list ---
WinRAR: Extraction directory history (12 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\WinRAR\DialogEditHistory\ExtrPath

WinRAR: Last used directory (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\WinRAR\General\LastFolder!=

WinRAR: Recent file list (4 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\WinRAR\ArcHistory

Adobe Acrobat Reader 6: Recent file #5 (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Adobe\Acrobat Reader\6.0\AVGeneral\/
cRecentFiles\c5

Adobe Acrobat Reader 6: Recent file #1 (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Adobe\Acrobat Reader\6.0\AVGeneral\/
cRecentFiles\c1

Adobe Acrobat Reader 6: Recent file #2 (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Adobe\Acrobat Reader\6.0\AVGeneral\/
cRecentFiles\c2

Adobe Acrobat Reader 6: Recent file #3 (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Adobe\Acrobat Reader\6.0\AVGeneral\/
cRecentFiles\c3

Adobe Acrobat Reader 6: Recent file #4 (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Adobe\Acrobat Reader\6.0\AVGeneral\/
cRecentFiles\c4

Ahead Nero Burning Rom: Last ISO directory (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\ahead\Nero - Burning Rom\General\OFDLastISODir!=

Ahead Nero Burning Rom: Browser directory (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Ahead\Nero - Burning Rom\Settings\BrowserDir!=

Ahead Nero Burning Rom: Compilation directory (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Ahead\Nero - Burning Rom\Settings\NeroCompilation!=

Ahead Nero Burning Rom: Compilation directory (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Ahead\Nero - Burning Rom\Settings\NeroCompilation!=

Ahead Nero Burning Rom: Image directory (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Ahead\Nero - Burning Rom\Settings\ImageDir!=

Ahead Nero Burning Rom: Image directory (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Ahead\Nero - Burning Rom\Settings\ImageDir!=

Ahead Nero Burning Rom: Last encoding directory (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Ahead\Nero - Burning Rom\Settings\EncodingLastDir!=

Ahead Nero Burning Rom: Last encoding directory (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\Software\Ahead\Nero - Burning Rom\Settings\EncodingLastDir!=

Ahead Nero Burning Rom: Save tracks directory (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Ahead\Nero - Burning Rom\SaveTrackOptions\Stdflist!=B=

Ahead Nero Burning Rom: Working directory (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Ahead\Nero - Burning Rom\Settings\WorkingDir!=

Gabest Media Player Classic: Recent file list (1 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Gabest\Media Player Classic\Recent File List

Holistyc: Réglages utilisateur (Clé du registre, fixing failed)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Local AppWizard-Generated Applications\holi6713223

Holistyc: Réglages utilisateur (Clé du registre, fixing failed)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Local AppWizard-Generated Applications\holi6708265

Holistyc: Réglages utilisateur (Clé du registre, fixing failed)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Local AppWizard-Generated Applications\holi6698321

Holistyc: Réglages utilisateur (Clé du registre, fixing failed)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Local AppWizard-Generated Applications\holi6693274

Holistyc: Réglages utilisateur (Clé du registre, fixing failed)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Local AppWizard-Generated Applications\holi6684982

Holistyc: Réglages utilisateur (Clé du registre, fixing failed)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Local AppWizard-Generated Applications\holi6673896

Holistyc: Réglages utilisateur (Clé du registre, fixing failed)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Local AppWizard-Generated Applications\holi6114081

Holistyc: Réglages utilisateur (Clé du registre, fixing failed)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Local AppWizard-Generated Applications\holi6061656

Holistyc: Réglages utilisateur (Clé du registre, fixing failed)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Local AppWizard-Generated Applications\holi494831

Internet Explorer: User agent (Modification du registre, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)

Internet Explorer: Download directory (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Internet Explorer\Download Directory!=

Internet Explorer: User agent (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\/
Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)

Internet Explorer: User agent (Modification du registre, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)

Internet Explorer: User agent (Modification du registre, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)

Internet Explorer: User agent (Modification du registre, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent!=Mozilla/4.0 (compatible; MSIE; Win32)

Log: Shutdown: System32\wbem\logs\wmiprov.log (Sauver le fichier, nothing done)
C:\WINDOWS\System32\wbem\logs\wmiprov.log

Log: Activity: imsins.log (Sauver le fichier, nothing done)
C:\WINDOWS\imsins.log

Log: Activity: ntbtlog.txt (Sauver le fichier, nothing done)
C:\WINDOWS\ntbtlog.txt

Log: Activity: OEWABLog.txt (Sauver le fichier, nothing done)
C:\WINDOWS\OEWABLog.txt

Log: Activity: SchedLgU.Txt (Sauver le fichier, nothing done)
C:\WINDOWS\SchedLgU.Txt

Log: Install: comsetup.log (Sauver le fichier, nothing done)
C:\WINDOWS\comsetup.log

Log: Install: DtcInstall.log (Sauver le fichier, nothing done)
C:\WINDOWS\DtcInstall.log

Log: Install: ocgen.log (Sauver le fichier, nothing done)
C:\WINDOWS\ocgen.log

Log: Install: setupact.log (Sauver le fichier, nothing done)
C:\WINDOWS\setupact.log

Log: Install: setupapi.log (Sauver le fichier, nothing done)
C:\WINDOWS\setupapi.log

Log: Install: setuperr.log (Sauver le fichier, nothing done)
C:\WINDOWS\setuperr.log

Log: Install: setuplog.txt (Sauver le fichier, nothing done)
C:\WINDOWS\setuplog.txt

Log: Install: svcpack.log (Sauver le fichier, nothing done)
C:\WINDOWS\svcpack.log

Log: Install: wmsetup.log (Sauver le fichier, nothing done)
C:\WINDOWS\wmsetup.log

Log: Shutdown: System32\wbem\logs\mofcomp.log (Sauver le fichier, nothing done)
C:\WINDOWS\System32\wbem\logs\mofcomp.log

Log: Shutdown: System32\wbem\logs\setup.log (Sauver le fichier, nothing done)
C:\WINDOWS\System32\wbem\logs\setup.log

Log: Shutdown: System32\wbem\logs\wbemcore.log (Sauver le fichier, nothing done)
C:\WINDOWS\System32\wbem\logs\wbemcore.log

Log: Shutdown: System32\wbem\logs\wbemess.lo_ (Sauver le fichier, nothing done)
C:\WINDOWS\System32\wbem\logs\wbemess.lo_

Log: Shutdown: System32\wbem\logs\wbemess.log (Sauver le fichier, nothing done)
C:\WINDOWS\System32\wbem\logs\wbemess.log

Log: Shutdown: System32\wbem\logs\wbemprox.log (Sauver le fichier, nothing done)
C:\WINDOWS\System32\wbem\logs\wbemprox.log

Log: Shutdown: System32\wbem\logs\wbemsnmp.log (Sauver le fichier, nothing done)
C:\WINDOWS\System32\wbem\logs\wbemsnmp.log

Log: Shutdown: System32\wbem\logs\winmgmt.log (Sauver le fichier, nothing done)
C:\WINDOWS\System32\wbem\logs\winmgmt.log

Log: Shutdown: System32\wbem\logs\wmiadap.log (Sauver le fichier, nothing done)
C:\WINDOWS\System32\wbem\logs\wmiadap.log

MS Direct3D: Most recent application (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Direct3D\MostRecentApplication\Name!=

MS DirectDraw: Most recent application (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication\Name!=

MS DirectInput: Most recent application ID (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\DirectInput\MostRecentApplication\Id!=

MS DirectInput: Most recent application (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\DirectInput\MostRecentApplication\Name!=

MS Frontpage: Last opened web (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\/
Settings\LastWebOpen!=

MS Frontpage: Default page (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\FrontPage\DefaultSave!=

MS Frontpage: Recent file list (2 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\/
Recent File List

MS Frontpage: Recent page list (1 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Page List

MS Frontpage: Recent web list (2 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recent Web List

MS Frontpage: Recently created servers (3 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\FrontPage\Explorer\FrontPage Explorer\Recently Created Servers

MS Frontpage: Recently used templates (2 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\FrontPage\Editor\Recent Templates

MS Management Console: Recent command list (4 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Microsoft Management Console\Recent File List

MS Media Player: Anonymous ID (Modification du registre, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\MediaPlayer\Preferences\SendUserGUID!=B=0

MS Media Player: Anonymous ID (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\MediaPlayer\Preferences\SendUserGUID!=B=0

MS Media Player: Anonymous ID (Modification du registre, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\MediaPlayer\Preferences\SendUserGUID!=B=0

MS Media Player: Client ID (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\MediaPlayer\Player\Settings\Client ID!=

MS Media Player: Last CD record path (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\MediaPlayer\Preferences\CDRecordPath!=

MS Media Player: Last opened playlist (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\MediaPlayer\Preferences\LastPlaylist

MS Media Player: Last selected node (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\MediaPlayer\MediaLibraryUI\MLLastSelectedNode!=

MS Media Player: Last selected track index (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\MediaPlayer\Preferences\LastPlaylistIndex

MS Media Player: Search terms history (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\MediaPlayer\AutoComplete\MediaSearch

MS Office 10.0 (Document Scanning): Recent file list #2 (1 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\MSPaper\Persist File Name

MS Office 10.0 (Document Scanning): Recent file list #1 (1 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\MSPaper\Recent File List

MS Office 10.0 (Excel): Recent file list (4 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Office\10.0\Excel\Recent Files

MS Office 10.0 (Word): Templates history (4 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Office\10.0\Word\Recent Templates

MS Office 10.0 (Word): Recently used documents list (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Office\10.0\Word\Data\Settings

MS Office 10.0: Recently used symbol list (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Office\10.0\Common\General\SymbolMRU

MS Office 10.0: Access recent file (1 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Office\10.0\Access\Settings

MS Office 10.0: Internet history (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Office\10.0\Common\Internet\UseRWHlinkNavigation

MS Paint: Recent file list (4 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\Applets\Paint\Recent File List

MS Photo Editor: Recently used file type #4 (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor\LastType4

MS Photo Editor: Last used directory (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Photo Editor\3.0\File Options\Path!=

MS Photo Editor: Recently used file #1 (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor\LastFile1

MS Photo Editor: Recently used file #2 (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor\LastFile2

MS Photo Editor: Recently used file #3 (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor\LastFile3

MS Photo Editor: Recently used file #4 (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor\LastFile4

MS Photo Editor: Recently used file type #1 (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor\LastType1

MS Photo Editor: Recently used file type #2 (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor\LastType2

MS Photo Editor: Recently used file type #3 (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Photo Editor\3.0\Microsoft Photo Editor\LastType3

MS Regedit: Recent open key (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\Applets\Regedit\LastKey!=

MS Search Assistant: Typed search terms history (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Search Assistant\ACMru

Quick Zip: Last new archive path (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Qzip3\Main_sc\MRU-1!=

Quick Zip: Last extract folder (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Qzip3\Extract_sc\ArchiveExtractpath!=

Windows Explorer: Last Copy/MoveTo folder (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\CopyMoveTo\LastFolder

Windows Explorer: Recent wallpaper list (80 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\Wallpaper\MRU

Windows Explorer: Stream history (10 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\StreamMRU

Windows Explorer: User Assistant history files (67 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\/
{75048700-EF1F-11D0-9888-006097DEACF9}\Count

Windows Explorer: User Assistant history IE (4 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\/
{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count

Windows Media SDK: Volume serial number (Valeur du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows Media\WMSDK\General\VolumeSerialNumber

Windows Media SDK: Computer name (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows Media\WMSDK\General\ComputerName!=ComputerName

Windows Media SDK: Unique ID (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows Media\WMSDK\General\UniqueID!=/
{00000000-0000-0000-0000-000000000000}

Windows.OpenWith: Open with list - .CDA extension (6 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\/
.CDA\OpenWithList

Windows.OpenWith: Open with list - .ASF extension (4 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\/
.ASF\OpenWithList

Windows.OpenWith: Open with list - .AVI extension (11 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\/
.AVI\OpenWithList

Windows.OpenWith: Open with list - .BMP extension (6 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\/
.BMP\OpenWithList

Windows.OpenWith: Open with list - .BUP extension (3 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\/
.BUP\OpenWithList

Windows.OpenWith: Open with list - .CAB extension (2 files) (Clé du registre, nothing done)
HKEY_USERS\S-1-5-21-1454471165-764733703-1957994488-1005\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\/
.CAB\OpenWithList

Windows: Drivers installation paths (Modification du registre, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Installation Sources!=


--- Spybot - Search && Destroy version: 1.3 ---
2005-04-26 Includes\Cookies.sbi
2005-07-29 Includes\Dialer.sbi
2005-08-04 Includes\Hijackers.sbi
2005-06-23 Includes\Keyloggers.sbi
2005-08-04 Includes\Malware.sbi
2005-04-27 Includes\Revision.sbi
2005-08-02 Includes\Security.sbi
2005-08-04 Includes\Spybots.sbi
2005-08-04 Includes\Trojans.sbi
2005-02-17 Includes\Tracks.uti
2004-11-29 Includes\LSP.sbi
2005-08-04 Includes\PUPS.sbi


--- System information ---
Windows XP (Build: 2600) Service Pack 2
/ Internet Explorer 6 / SP1: Correctif Windows XP - Article Base de Connaissances 834707
/ Internet Explorer 6 / SP1: Correctif Windows XP - KB890923
/ Windows XP / SP2: Windows XP Service Pack 2
/ Windows XP / SP3: Correctif Windows XP - KB873333
/ Windows XP / SP3: Correctif Windows XP - KB873339
/ Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB883939)
/ Windows XP / SP3: Correctif Windows XP - KB885250
/ Windows XP / SP3: Correctif Windows XP - KB885835
/ Windows XP / SP3: Correctif Windows XP - KB885836
/ Windows XP / SP3: Correctif Windows XP - KB885884
/ Windows XP / SP3: Correctif Windows XP - KB886185
/ Windows XP / SP3: Correctif Windows XP - KB887472
/ Windows XP / SP3: Correctif Windows XP - KB887742
/ Windows XP / SP3: Correctif Windows XP - KB888113
/ Windows XP / SP3: Correctif Windows XP - KB888302
/ Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB890046)
/ Windows XP / SP3: Correctif Windows XP - KB890175
/ Windows XP / SP3: Correctif Windows XP - KB890859
/ Windows XP / SP3: Correctif Windows XP - KB890923
/ Windows XP / SP3: Correctif Windows XP - KB891781
/ Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB893066)
/ Windows XP / SP3: Correctif Windows XP - KB893086
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB896358)
/ Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB896422)
/ Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB896428)
/ Windows XP / SP3: Mise à jour pour Windows XP (KB898461)
/ Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB901214)
/ Windows XP / SP3: Mise à jour de sécurité pour Windows XP (KB903235)


--- Startup entries list ---
Located: HK_LM:Run, AVG7_CC
command: C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
file: C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
size: 352256
MD5: 6e74941e3e14cb67fb1648b45a041f0d

Located: HK_LM:Run, AVG7_EMC
command: C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
file: C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
size: 273920
MD5: 8f0843b553882e9c678b8f83be8a438a

Located: HK_LM:Run, gcasServ
command: "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
file: C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
size: 473928
MD5: 263740ede788a60a6c0a47249fc410bf

Located: HK_LM:Run, KernelFaultCheck
command: %systemroot%\system32\dumprep 0 -k
file: C:\WINDOWS\system32\dumprep.exe
size: 10752
MD5: ba510a646b02cb44137b8296db2783d3

Located: HK_LM:Run, NeroCheck
command: C:\WINDOWS\System32\\NeroCheck.exe
file: C:\WINDOWS\System32\\NeroCheck.exe
size: 155648
MD5: 3e4c03cefad8de135263236b61a49c90

Located: HK_LM:Run, Outpost Firewall
command: C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe /waitservice

Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 98304
MD5: 9b4c1812595c389ab9ccf1ff3b315248

Located: HK_CU:Run, CTFMON.EXE
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 64e41e8fee655b03e3f19ded21ba5118

Located: HK_CU:Run, SpybotSD TeaTimer
command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
size: 1038336
MD5: 58f7e6434d285f4c98ad3621e0bd8c8d

Located: Démarrage (tous utilisateurs), Adobe Gamma Loader.lnk
command: C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
file: C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
size: 110592
MD5: 5cd0cd0ec4dc5df459b3ac016764f5aa

Located: Démarrage (tous utilisateurs), hp psc 1000 series.lnk
command: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
file: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
size: 147456
MD5: f3e93bb3dccf32e62a686210788e8856

Located: Démarrage (tous utilisateurs), hpoddt01.exe.lnk
command: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
file: C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
size: 28672
MD5: ea35dec2bda6310f48ea724b2cdc3ffe

Located: Démarrage (tous utilisateurs), Microsoft Office.lnk
command: C:\Program Files\Microsoft Office\Office10\OSA.EXE
file: C:\Program Files\Microsoft Office\Office10\OSA.EXE
size: 83360
MD5: 5bc65464354a9fd3beaa28e18839734a



--- Browser helper object list ---
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
BHO name:
CLSID name: AcroIEHlprObj Class
description: Adobe Acrobat reader
classification: Legitimate
known filename: AcroIEhelper.ocx<br>AcroIEhelper.dll
info link: http://www.adobe.com/products/acrobat/readstep2.html
info source: TonyKlein
Path: C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\
Long name: AcroIEHelper.dll
Short name: ACROIE~1.DLL
Date (created): 03/11/2003 14:17:44
Date (last access): 14/08/2005
Date (last write): 03/11/2003 14:17:44
Filesize: 54248
Attributes: archive
MD5: FC7850324464E4D19A24A03D882B5CC4
CRC32: 452E8571
Version: 0.6.0.0

{53707962-6F74-2D53-2644-206D7942484F} ()
BHO name:
CLSID name:
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDhelper.dll
info link: http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\PROGRA~1\SPYBOT~1\
Long name: SDHelper.dll
Short name: SDHELPER.DLL
Date (created): 12/05/2004 01:03:00
Date (last access): 14/08/2005
Date (last write): 12/05/2004 01:03:00
Filesize: 744960
Attributes: archive
MD5: ABF5BA518C6A5ED104496FF42D19AD88
CRC32: 5587736E
Version: 0.1.0.3

{AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
BHO name:
CLSID name: Google Toolbar Helper
Path: c:\program files\google\
Long name: GoogleToolbar1.dll
Short name: GOOGLE~1.DLL
Date (created): 23/07/2005 18:13:00
Date (last access): 14/08/2005
Date (last write): 12/07/2005 14:59:56
Filesize: 1157120
Attributes: readonly archive
MD5: 8B5A0B5054E5A604E6FA6C87450C6649
CRC32: F2047595
Version: 0.3.0.0



--- ActiveX list ---
{19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class)
DPF name:
CLSID name: MSSecurityAdvisor Class
Path: C:\WINDOWS\System32\
Long name: mssecadv.dll
Short name:
Date (created): 08/09/2003 11:30:46
Date (last access): 14/08/2005
Date (last write): 08/09/2003 11:30:46
Filesize: 36960
Attributes: archive
MD5: A4282FD762CE1C4FFA665538E335CFF0
CRC32: 51ECFB75
Version: 0.5.0.4

{32564D57-0000-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:

{33564D57-0000-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:

{3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine)
DPF name:
CLSID name: Office Update Installation Engine
Path: C:\WINDOWS\
Long name: opuc.dll
Short name:
Date (created): 27/08/2003 04:10:30
Date (last access): 14/08/2005
Date (last write): 27/08/2003 04:10:30
Filesize: 314368
Attributes: archive
MD5: 1E32EC4A8A17B19926B49EA5F6B79A76
CRC32: E98FC293
Version: 0.11.0.0

{6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class)
DPF name:
CLSID name: WUWebControl Class
Path: C:\WINDOWS\System32\
Long name: wuweb.dll
Short name:
Date (created): 03/08/2004 13:59:06
Date (last access): 14/08/2005
Date (last write): 26/05/2005 04:19:32
Filesize: 173536
Attributes: archive
MD5: C459F2D5E64C942F3F66E1CD7F1C4C00
CRC32: EEF66B50
Version: 0.5.0.8

{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.2)
DPF name: Java Runtime Environment 1.4.2
CLSID name: Java Plug-in 1.4.2
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\j2re1.4.2\bin\
Long name: NPJPI142.dll
Short name:
Date (created): 08/11/2004 23:00:50
Date (last access): 14/08/2005
Date (last write): 08/11/2004 23:00:50
Filesize: 65636
Attributes: archive
MD5: 4ACFBF6AB1BBE79DBD665C186B3B5AFD
CRC32: BE89D675
Version: 0.1.0.4

{8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class)
DPF name:
CLSID name: MessengerStatsClient Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: messengerstatsclient.dll
Short name: MESSEN~1.DLL
Date (created): 29/05/2003 15:00:20
Date (last access): 14/08/2005
Date (last write): 29/05/2003 15:00:20
Filesize: 160864
Attributes: archive
MD5: B069B555A00AA026F657AA4FD13AE154
CRC32: 89BB01E1
Version: 0.7.0.1

{9F1C11AA-197B-4942-BA54-47A8489BB47F} ()
DPF name:
CLSID name:
description: Windows Update
classification: Legitimate
known filename: %WINDIR%\System32\iuctl.dll,iuengine.dll
info link:
info source: Patrick M. Kolla

{CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} (Java Runtime Environment 1.4.2)
DPF name: Java Runtime Environment 1.4.2
CLSID name: Java Plug-in 1.4.2
Path: C:\Program Files\Java\j2re1.4.2\bin\
Long name: NPJPI142.dll
Short name:
Date (created): 08/11/2004 23:00:50
Date (last access): 14/08/2005
Date (last write): 08/11/2004 23:00:50
Filesize: 65636
Attributes: archive
MD5: 4ACFBF6AB1BBE79DBD665C186B3B5AFD
CRC32: BE89D675
Version: 0.1.0.4

{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\System32\macromed\flash\
Long name: Flash.ocx
Short name: FLASH.OCX
Date (created): 09/06/2004 15:59:26
Date (last access): 14/08/2005
Date (last write): 09/06/2004 15:59:26
Filesize: 939224
Attributes: archive
MD5: FC3E17E12C2E31FAC34B416B3DAB829F
CRC32: D1CF3A57
Version: 0.7.0.0

{F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class)
DPF name:
CLSID name: Solitaire Showdown Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: solitaireshowdown.dll
Short name: SOLITA~1.DLL
Date (created): 29/05/2003 15:00:20
Date (last access): 14/08/2005
Date (last write): 29/05/2003 15:00:20
Filesize: 86112
Attributes: archive
MD5: 6E0E81210B17C225AD8DBB86F0C41E32
CRC32: 1C944476
Version: 0.7.0.1



--- Process list ---
Spybot - Search && Destroy process list report, 14/08/2005 14:57:44

PID: 0 ( 0) [System]
PID: 4 ( 0) System
PID: 304 (2012) C:\WINDOWS\system32\Sysocmgr.exe
PID: 320 ( 4) \SystemRoot\System32\smss.exe
PID: 368 ( 320) CSRSS.EXE
PID: 392 ( 320) \??\C:\WINDOWS\system32\winlogon.exe
PID: 436 ( 392) C:\WINDOWS\system32\services.exe
PID: 448 ( 392) C:\WINDOWS\system32\lsass.exe
PID: 496 ( 592) C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
PID: 592 ( 436) C:\WINDOWS\system32\svchost.exe
PID: 652 ( 436) SVCHOST.EXE
PID: 692 ( 436) C:\WINDOWS\System32\svchost.exe
PID: 740 ( 436) SVCHOST.EXE
PID: 800 ( 436) SVCHOST.EXE
PID: 920 ( 436) C:\WINDOWS\system32\spoolsv.exe
PID: 976 ( 436) C:\WINDOWS\System32\HPZipm12.exe
PID: 1016 ( 960) C:\WINDOWS\Explorer.EXE
PID: 1156 (1016) C:\Program Files\QuickTime\qttask.exe
PID: 1208 (1016) C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
PID: 1224 (1016) C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
PID: 1232 (1016) C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
PID: 1256 (1016) C:\WINDOWS\system32\ctfmon.exe
PID: 1264 ( 592) C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
PID: 1272 (1016) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PID: 1404 ( 436) C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
PID: 1416 ( 436) C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
PID: 1476 ( 436) C:\ewido\security suite\ewidoctrl.exe
PID: 1500 ( 436) C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
PID: 1512 ( 436) C:\PROGRA~1\AGNITUM\OUTPOS~1.0\outpost.exe
PID: 1600 ( 436) C:\WINDOWS\system32\spupdsvc.exe
PID: 1716 ( 436) C:\WINDOWS\System32\svchost.exe
PID: 1740 ( 436) WDFMGR.EXE
PID: 1912 (1016) C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
PID: 1964 (1016) C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
PID: 2012 (1600) C:\WINDOWS\system32\spnpinst.exe
PID: 2688 (1016) C:\Program Files\Mozilla Firefox\firefox.exe
PID: 2940 (1016) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe


--- Browser start & search pages list ---
Spybot - Search && Destroy browser pages report, 14/08/2005 14:57:44

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\system32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.google.com
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
http://www.google.com/ie
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.google.fr/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
http://www.google.com/keyword/%s
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.google.com
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
http://www.google.com/ie
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.google.fr/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.google.fr
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://www.google.com/ie
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchUrl\@
http://www.google.com/keyword/%s


--- Winsock Layered Service Provider list ---
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]

Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]

Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]

Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{BF9BD512-39A8-4E3D-9E2D-F518E91B4505}] SEQPACKET 6
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{BF9BD512-39A8-4E3D-9E2D-F518E91B4505}] DATAGRAM 6
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{30B70DA1-3509-41CA-9773-BA5A89F80560}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{30B70DA1-3509-41CA-9773-BA5A89F80560}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{747F0088-5E72-44B0-9926-42539225DCBE}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{747F0088-5E72-44B0-9926-42539225DCBE}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{143B595F-509D-4830-8E08-3D7DA8A10C1B}] SEQPACKET 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{143B595F-509D-4830-8E08-3D7DA8A10C1B}] DATAGRAM 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{87F193F1-880E-477E-8A88-A322FCA1CB9E}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{87F193F1-880E-477E-8A88-A322FCA1CB9E}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{39583B7C-455F-43AA-BAB4-BA2F35ADF417}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{39583B7C-455F-43AA-BAB4-BA2F35ADF417}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 17: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A87EC402-397D-4E84-9A88-E4EBE4946309}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 18: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A87EC402-397D-4E84-9A88-E4EBE4946309}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Namespace Provider 0: TCP/IP
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP

Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS

Namespace Provider 2: Espace de noms NLA (Network Location Awareness)
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace
djolafrite
 
Messages: 13
Inscription: 21 Juil 2005, 00:25

log startdreck

Messagede djolafrite » 14 Aoû 2005, 13:59

StartDreck (build 2.1.7 public stable) - 2005-08-14 @ 15:02:58 (GMT +02:00)
Platform: Windows XP (Win NT 5.1.2600 Service Pack 2)
Internet Explorer: 6.0.2900.2180
Logged in as audrey at TEST

»Registry
»Run Keys
»Current User
»Run
*CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
*SpybotSD TeaTimer=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
»RunOnce
»Default User
»Run
*CTFMON.EXE=C:\WINDOWS\System32\CTFMON.EXE
*System driver=Messenger.exe
*wvsvc=wvsvc.exe
*AVG7_Run=C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE
»RunOnce
*System driver=Messenger.exe
»Local Machine
»Run
*NeroCheck=C:\WINDOWS\System32\\NeroCheck.exe
*QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
*KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
*gcasServ="C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
*Outpost Firewall=C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe /waitservice
*AVG7_CC=C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
*AVG7_EMC=C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
+OptionalComponents
+MSFS
*Installed=1
+MAPI
*Installed=1
*NoChange=1
+MAPI
*Installed=1
*NoChange=1
»RunOnce
»RunServices
»RunServicesOnce
»RunOnceEx
»RunServicesOnceEx
»File Associations (CR)
+.bat
*batfile="%1" %*
+.com
*comfile="%1" %*
+.disabled
*SpybotSD.DisabledFile="C:\Program Files\Spybot - Search & Destroy\blindman.exe" "%1"
+.exe
*exefile="%1" %*
+.hta
`= [key or value does not exist]
+.htm
*FirefoxHTML=C:\PROGRA~1\MOZILL~1\FIREFOX.EXE -url "%1"
+.html
*FirefoxHTML=C:\PROGRA~1\MOZILL~1\FIREFOX.EXE -url "%1"
+.js
*JSFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.jse
*JSEFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.pif
*piffile="%1" %*
+.reg
*regfile=regedit.exe "%1"
+.scr
*scrfile="%1" /S
+.txt
*txtfile=%SystemRoot%\system32\NOTEPAD.EXE %1
+.vbs
*VBSFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.vbe
*VBEFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.wsh
*WSHFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.wsf
*WSFFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.lnk
`lnkfile= [key or value does not exist]
»Active Setup (LM)
+Internet Explorer/>{26923b43-4d38-484f-9b9e-de460746276c}
*StubPath=%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
+Outlook Express/>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
*StubPath=%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
+Themes Setup/{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
*StubPath=%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
+Microsoft Outlook Express 6/{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
*StubPath="%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
+NetMeeting 3.01/{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
*StubPath=rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
+Windows Messenger 4.7/{5945c046-1e7d-11d1-bc44-00c04fd912be}
*StubPath=rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
+Microsoft Windows Media Player/{6BF52A52-394A-11d3-B153-00C04F79FAA6}
*StubPath=rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub
+Carnet d'adresses 6/{7790769C-0471-11d2-AF11-00C04FA35D02}
*StubPath="%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
+Mise à jour du Bureau Windows/{89820200-ECBD-11cf-8B85-00AA005B4340}
*StubPath=regsvr32.exe /s /n /i:U shell32.dll
+Internet Explorer 6/{89820200-ECBD-11cf-8B85-00AA005B4383}
*StubPath=%SystemRoot%\system32\ie4uinit.exe
»Browser Helper Objects (LM)
*AcroIEHelper.AcroIEHlprObj.1/{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
`InprocServer32=C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
*{53707962-6F74-2D53-2644-206D7942484F}
`InprocServer32=C:\PROGRA~1\SPYBOT~1\SDHelper.dll
*Google Toolbar Helper/{AA58ED58-01DD-4d91-8333-CF10577473F7}
`InprocServer32=c:\program files\google\googletoolbar1.dll
»ShellServiceObjectDelayLoad (LM)
*PostBootReminder={7849596a-48ea-486e-8937-a2a3009f31a9}
`InprocServer32=%SystemRoot%\system32\SHELL32.dll
*CDBurn={fbeb8a05-beee-4442-804e-409d6c4515e9}
`InprocServer32=%SystemRoot%\system32\SHELL32.dll
*WebCheck={E6FB5E20-DE35-11CF-9C87-00AA005127ED}
`InprocServer32=%SystemRoot%\System32\webcheck.dll
*SysTray={35CEC8A3-2BE6-11D2-8773-92E220524153}
`InprocServer32=C:\WINDOWS\System32\stobject.dll
»Special NT Values
»Current User
*Load=
*Run=
*Programs=com exe bat pif cmd
*SHELL=
»Default User
*Load=
*Run=
*Programs=com exe bat pif cmd
*SHELL=
»Local Machine
*AppInit_DLLs=
*SHELL=Explorer.exe
*Userinit=C:\WINDOWS\system32\userinit.exe,
»Files
»Autostart Folders
»Current User
*C:\Documents and Settings\audrey\Menu Démarrer\Programmes\Démarrage\desktop.ini
»Default User
*C:\WINDOWS\system32\config\systemprofile\Menu Démarrer\Programmes\Démarrage\desktop.ini
»Local Machine
*C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\desktop.ini
*C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
*C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\hpoddt01.exe.lnk
*C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\hp psc 1000 series.lnk
*C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk
»INI-Files
»WIN.INI\[windows]
*LOAD=
*RUN=
»SYSTEM.INI\[boot]
*SHELL=Explorer.exe
»Text Files
*C:\boot.ini
`[boot loader]
`timeout=30
`default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
`[operating systems]
`multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn
*C:\msdos.sys
*C:\config.sys
*C:\WINDOWS\system32\config.nt
`dos=high, umb
`device=%SystemRoot%\system32\himem.sys
`files=40
*C:\WINDOWS\system32\drivers\etc\hosts
`127.0.0.1 localhostor.com
`127.0.0.1 1ad2srvr-cpt-v1.com
`127.0.0.1 www.1ad2srvr-cpt-v1.com
`127.0.0.1 207-182-237-233.visionaire-us.com
`127.0.0.1 www.207-182-237-233.visionaire-us.com
`127.0.0.1 3721.com
`127.0.0.1 www.3721.com
`127.0.0.1 680180.net
`127.0.0.1 www.680180.net
`127.0.0.1 7search.com
`127.0.0.1 www.7search.com
`127.0.0.1 Ad.doubleclick.net
`127.0.0.1 www.Ad.doubleclick.net
`127.0.0.1 Adserv.internetfuel.com
`127.0.0.1 www.Adserv.internetfuel.com
`127.0.0.1 Akapp.whenu.com
`127.0.0.1 www.Akapp.whenu.com
`127.0.0.1 App.whenu.com
`127.0.0.1 www.App.whenu.com
`127.0.0.1 Banserv.internetfuel.com
`127.0.0.1 www.Banserv.internetfuel.com
`127.0.0.1 Bidtxt.whenu.com
`127.0.0.1 www.Bidtxt.whenu.com
`127.0.0.1 Corr.conscorr.com
`127.0.0.1 www.Corr.conscorr.com
`127.0.0.1 Dclcorp.rpts.net
`127.0.0.1 www.Dclcorp.rpts.net
`127.0.0.1 Drk.localnrd.com
`127.0.0.1 www.Drk.localnrd.com
`127.0.0.1 Homecgocable.net
`127.0.0.1 www.Homecgocable.net
`127.0.0.1 Netbroadcast.com
`127.0.0.1 www.Netbroadcast.com
`127.0.0.1 Smartpops.com
`127.0.0.1 www.Smartpops.com
`127.0.0.1 Spapp.whenu.com
`127.0.0.1 www.Spapp.whenu.com
`127.0.0.1 Xxxtoolbar.com
`127.0.0.1 www.Xxxtoolbar.com
`127.0.0.1 abetterinternet.com
`127.0.0.1 www.abetterinternet.com
`127.0.0.1 active-alert-server.com
`127.0.0.1 www.active-alert-server.com
`127.0.0.1 active-max.com
`127.0.0.1 www.active-max.com
`127.0.0.1 addictivetechnologies.net
`127.0.0.1 www.addictivetechnologies.net
`127.0.0.1 address.3721.com
`127.0.0.1 www.address.3721.com
`127.0.0.1 adopt.hotbar.com
`127.0.0.1 www.adopt.hotbar.com
`127.0.0.1 adpopper.outblaze.com
`127.0.0.1 www.adpopper.outblaze.com
`127.0.0.1 adroar.com
`127.0.0.1 www.adroar.com
`127.0.0.1 ads.adroar.com
`127.0.0.1 www.ads.adroar.com
`127.0.0.1 ads.adtomi.com
`127.0.0.1 www.ads.adtomi.com
`127.0.0.1 ads.centralmedia.ws
`127.0.0.1 www.ads.centralmedia.ws
`127.0.0.1 ads.hotbar.com
`127.0.0.1 www.ads.hotbar.com
`127.0.0.1 ads.internet-optimizer.com
`127.0.0.1 www.ads.internet-optimizer.com
`127.0.0.1 ads.offeroptimizer.com
`127.0.0.1 www.ads.offeroptimizer.com
`127.0.0.1 ads.vx2.cc
`127.0.0.1 www.ads.vx2.cc
`127.0.0.1 ads3.virtumundo.com
`127.0.0.1 www.ads3.virtumundo.com
`127.0.0.1 ads4.virtumundo.com
`127.0.0.1 www.ads4.virtumundo.com
`127.0.0.1 adserv1.ebates.com
`127.0.0.1 www.adserv1.ebates.com
`127.0.0.1 adtactics.com
`127.0.0.1 www.adtactics.com
`127.0.0.1 adtracker.411web.com
`127.0.0.1 www.adtracker.411web.com
`127.0.0.1 advertisingagent.com
`127.0.0.1 www.advertisingagent.com
`127.0.0.1 agent.3721.com
`127.0.0.1 www.agent.3721.com
`127.0.0.1 ajokeaday.com
`127.0.0.1 www.ajokeaday.com
`127.0.0.1 ak.imgfarm.com
`127.0.0.1 www.ak.imgfarm.com
`127.0.0.1 akapp.whenu.com
`127.0.0.1 www.akapp.whenu.com
`127.0.0.1 akweb.whenu.com
`127.0.0.1 www.akweb.whenu.com
`127.0.0.1 allaboutsearching.com
`127.0.0.1 www.allaboutsearching.com
`127.0.0.1 almightysearch.com
`127.0.0.1 www.almightysearch.com
`127.0.0.1 alpha.searchassistant.net
`127.0.0.1 www.alpha.searchassistant.net
`127.0.0.1 altnet.com
`127.0.0.1 www.altnet.com
`127.0.0.1 amazingautossearch.com
`127.0.0.1 www.amazingautossearch.com
`127.0.0.1 amnv.net
`127.0.0.1 www.amnv.net
`127.0.0.1 ao.lop.com
`127.0.0.1 www.ao.lop.com
`127.0.0.1 app.desktop.ak-networks.com
`127.0.0.1 www.app.desktop.ak-networks.com
`127.0.0.1 app.ezula.com
`127.0.0.1 www.app.ezula.com
`127.0.0.1 app.whenu.com
`127.0.0.1 www.app.whenu.com
`127.0.0.1 app.whenu.speedera.net
`127.0.0.1 www.app.whenu.speedera.net
`127.0.0.1 assistant.3721.com
`127.0.0.1 www.assistant.3721.com
`127.0.0.1 avenuemedia.com
`127.0.0.1 www.avenuemedia.com
`127.0.0.1 ayb.lop.com
`127.0.0.1 www.ayb.lop.com
`127.0.0.1 b3d.com
`127.0.0.1 www.b3d.com
`127.0.0.1 badsol.bianas.com
`127.0.0.1 www.badsol.bianas.com
`127.0.0.1 badurl.grandstreetinteractive.com
`127.0.0.1 www.badurl.grandstreetinteractive.com
`127.0.0.1 badurl.ieplugin.com
`127.0.0.1 www.badurl.ieplugin.com
`127.0.0.1 bannerserver.gator.com
`127.0.0.1 www.bannerserver.gator.com
`127.0.0.1 bannersxchange.com
`127.0.0.1 www.bannersxchange.com
`127.0.0.1 bannerx.adtactics.com
`127.0.0.1 www.bannerx.adtactics.com
`127.0.0.1 bar.mywebsearch.com
`127.0.0.1 www.bar.mywebsearch.com
`127.0.0.1 bc2.gator.com
`127.0.0.1 www.bc2.gator.com
`127.0.0.1 bde3d.com
`127.0.0.1 www.bde3d.com
`127.0.0.1 belt.abetterinternet.com
`127.0.0.1 www.belt.abetterinternet.com
`127.0.0.1 beta.searchassistant.net
`127.0.0.1 www.beta.searchassistant.net
`127.0.0.1 bg.gator.com
`127.0.0.1 www.bg.gator.com
`127.0.0.1 bg2.gator.com
`127.0.0.1 www.bg2.gator.com
`127.0.0.1 bi.gator.com
`127.0.0.1 www.bi.gator.com
`127.0.0.1 bidtxt.whenu.com
`127.0.0.1 www.bidtxt.whenu.com
`127.0.0.1 bigbrother.gigatechsoftware.com
`127.0.0.1 www.bigbrother.gigatechsoftware.com
`127.0.0.1 bins.lop.com
`127.0.0.1 www.bins.lop.com
`127.0.0.1 bis.180solutions.com
`127.0.0.1 www.bis.180solutions.com
`127.0.0.1 bluehavenmedia.com
`127.0.0.1 www.bluehavenmedia.com
`127.0.0.1 brilliantdigital.com
`127.0.0.1 www.brilliantdigital.com
`127.0.0.1 browserwise.com
`127.0.0.1 www.browserwise.com
`127.0.0.1 bundleware.com
`127.0.0.1 www.bundleware.com
`127.0.0.1 c.abetterinternet.com
`127.0.0.1 www.c.abetterinternet.com
`127.0.0.1 c.centralmedia.ws
`127.0.0.1 www.c.centralmedia.ws
`127.0.0.1 c.pornograph.com
`127.0.0.1 www.c.pornograph.com
`127.0.0.1 c4.iwon.com
`127.0.0.1 www.c4.iwon.com
`127.0.0.1 c4.maxserving.com
`127.0.0.1 www.c4.maxserving.com
`127.0.0.1 c4.mysearch.com
`127.0.0.1 www.c4.mysearch.com
`127.0.0.1 cadsol.bianas.com
`127.0.0.1 www.cadsol.bianas.com
`127.0.0.1 casinobuilder.i-lookup.com
`127.0.0.1 www.casinobuilder.i-lookup.com
`127.0.0.1 cassandra.searchassistant.net
`127.0.0.1 www.cassandra.searchassistant.net
`127.0.0.1 cc.iwon.com
`127.0.0.1 www.cc.iwon.com
`127.0.0.1 cdn.climaxbucks.com
`127.0.0.1 www.cdn.climaxbucks.com
`127.0.0.1 cdn.movies-etc.com
`127.0.0.1 www.cdn.movies-etc.com
`127.0.0.1 centralmedia.ws
`127.0.0.1 www.centralmedia.ws
`127.0.0.1 cfg.mysearch.com
`127.0.0.1 www.cfg.mysearch.com
`127.0.0.1 cfg.mywebsearch.com
`127.0.0.1 www.cfg.mywebsearch.com
`127.0.0.1 checkin.clickalchemy.com
`127.0.0.1 www.checkin.clickalchemy.com
`127.0.0.1 chromium.whenu.com
`127.0.0.1 www.chromium.whenu.com
`127.0.0.1 cjt1.net
`127.0.0.1 www.cjt1.net
`127.0.0.1 cleangetaway.biz
`127.0.0.1 www.cleangetaway.biz
`127.0.0.1 click2findnow.com
`127.0.0.1 www.click2findnow.com
`127.0.0.1 clickalchemy.com
`127.0.0.1 www.clickalchemy.com
`127.0.0.1 climaxbucks.com
`127.0.0.1 www.climaxbucks.com
`127.0.0.1 cns.3721.com
`127.0.0.1 www.cns.3721.com
`127.0.0.1 cnsmin.3721.com
`127.0.0.1 www.cnsmin.3721.com
`127.0.0.1 cocktailcash.com
`127.0.0.1 www.cocktailcash.com
`127.0.0.1 code.ignphrases.com
`127.0.0.1 www.code.ignphrases.com
`127.0.0.1 config.grandstreetinteractive.com
`127.0.0.1 www.config.grandstreetinteractive.com
`127.0.0.1 content.dashbar.com
`127.0.0.1 www.content.dashbar.com
`127.0.0.1 contexualsearch.com
`127.0.0.1 www.contexualsearch.com

`127.0.0.1 corp.3721.com
`127.0.0.1 www.corp.3721.com
`127.0.0.1 coupons.gator.com
`127.0.0.1 www.coupons.gator.com
`127.0.0.1 cr.stop-popup-ads-now.com
`127.0.0.1 www.cr.stop-popup-ads-now.com
`127.0.0.1 crap2.com
`127.0.0.1 www.crap2.com
`127.0.0.1 crossroad.trekdata.com
`127.0.0.1 www.crossroad.trekdata.com
`127.0.0.1 cs.hotbar.com
`127.0.0.1 www.cs.hotbar.com
`127.0.0.1 ct.cydoor.com
`127.0.0.1 www.ct.cydoor.com
`127.0.0.1 ctl.twain-tech.com
`127.0.0.1 www.ctl.twain-tech.com
`127.0.0.1 cust.bezeqint.net
`127.0.0.1 www.cust.bezeqint.net
`127.0.0.1 daptest.speedbit.com
`127.0.0.1 www.daptest.speedbit.com
`127.0.0.1 datastorm.biz
`127.0.0.1 www.datastorm.biz

`127.0.0.1 delta.adroar.com
`127.0.0.1 www.delta.adroar.com
`127.0.0.1 dir.3721.com
`127.0.0.1 www.dir.3721.com
`127.0.0.1 direct.simpletraffic.com
`127.0.0.1 www.direct.simpletraffic.com
`127.0.0.1 docs1.iwon.com
`127.0.0.1 www.docs1.iwon.com
`127.0.0.1 domain.i-lookup.com
`127.0.0.1 www.domain.i-lookup.com
`127.0.0.1 download.3721.com
`127.0.0.1 www.download.3721.com
`127.0.0.1 download.abetterinternet.com
`127.0.0.1 www.download.abetterinternet.com
`127.0.0.1 download.bonzi.com
`127.0.0.1 www.download.bonzi.com
`127.0.0.1 download.bulletproofsoft.com
`127.0.0.1 www.download.bulletproofsoft.com
`127.0.0.1 download.feiyang.com
`127.0.0.1 www.download.feiyang.com
`127.0.0.1 download.gigatechsoftware.com
`127.0.0.1 www.download.gigatechsoftware.com
`127.0.0.1 download.ipinsight.net
`127.0.0.1 www.download.ipinsight.net
`127.0.0.1 download.vx2.cc
`127.0.0.1 www.download.vx2.cc
`127.0.0.1 download.whenu.com
`127.0.0.1 www.download.whenu.com
`127.0.0.1 download2.abetterinternet.com
`127.0.0.1 www.download2.abetterinternet.com
`127.0.0.1 dyn.virtumundo.com
`127.0.0.1 www.dyn.virtumundo.com
`127.0.0.1 dynamic.hotbar.com
`127.0.0.1 www.dynamic.hotbar.com
`127.0.0.1 dynmenu.hotbar.com
`127.0.0.1 www.dynmenu.hotbar.com
`127.0.0.1 ecpm.com
`127.0.0.1 www.ecpm.com
`127.0.0.1 efc.iwon.com
`127.0.0.1 www.efc.iwon.com
`127.0.0.1 epsilon.searchassistant.net
`127.0.0.1 www.epsilon.searchassistant.net
`127.0.0.1 express.3721.com
`127.0.0.1 www.express.3721.com
`127.0.0.1 ez-searching.com
`127.0.0.1 www.ez-searching.com
`127.0.0.1 ezula.com
`127.0.0.1 www.ezula.com
`127.0.0.1 find-quick.com
`127.0.0.1 www.find-quick.com
`127.0.0.1 findology.mail.everyone.net
`127.0.0.1 www.findology.mail.everyone.net
`127.0.0.1 fstrack.7search.com
`127.0.0.1 www.fstrack.7search.com
`127.0.0.1 ftp.clicktracking.info
`127.0.0.1 www.ftp.clicktracking.info
`127.0.0.1 gator29.gator.com
`127.0.0.1 www.gator29.gator.com
`127.0.0.1 gatorcme.gator.com
`127.0.0.1 www.gatorcme.gator.com
`127.0.0.1 gbs.gator.com
`127.0.0.1 www.gbs.gator.com
`127.0.0.1 getweathercast.com
`127.0.0.1 www.getweathercast.com
`127.0.0.1 gi.gator.com
`127.0.0.1 www.gi.gator.com
`127.0.0.1 globaltoolbar.com
`127.0.0.1 www.globaltoolbar.com
`127.0.0.1 globalwebsearch.com
`127.0.0.1 www.globalwebsearch.com
`127.0.0.1 grandstreetinteractive.com
`127.0.0.1 www.grandstreetinteractive.com
`127.0.0.1 gs.gator.com
`127.0.0.1 www.gs.gator.com
`127.0.0.1 gt.gator.com
`127.0.0.1 www.gt.gator.com
`127.0.0.1 help.mysearch.com
`127.0.0.1 www.help.mysearch.com
`127.0.0.1 hits.411web.com
`127.0.0.1 www.hits.411web.com
`127.0.0.1 home.iwon.com
`127.0.0.1 www.home.iwon.com
`127.0.0.1 hotbar.com
`127.0.0.1 www.hotbar.com
`127.0.0.1 i-lookup.com
`127.0.0.1 www.i-lookup.com
`127.0.0.1 i1img.com
`127.0.0.1 www.i1img.com
`127.0.0.1 iads.adroar.com
`127.0.0.1 www.iads.adroar.com
`127.0.0.1 ieplugin.com
`127.0.0.1 www.ieplugin.com
`127.0.0.1 igetnet.com
`127.0.0.1 www.igetnet.com
`127.0.0.1 image.i1img.com
`127.0.0.1 www.image.i1img.com
`127.0.0.1 image.imgfarm.com
`127.0.0.1 www.image.imgfarm.com
`127.0.0.1 images.bonzi.com
`127.0.0.1 www.images.bonzi.com
`127.0.0.1 images.gator.com
`127.0.0.1 www.images.gator.com
`127.0.0.1 img.3721.com
`127.0.0.1 www.img.3721.com
`127.0.0.1 img.7meta.com
`127.0.0.1 www.img.7meta.com
`127.0.0.1 img.bannersxchange.com
`127.0.0.1 www.img.bannersxchange.com
`127.0.0.1 img.lop.com
`127.0.0.1 www.img.lop.com
`127.0.0.1 imgfarm.com
`127.0.0.1 www.imgfarm.com
`127.0.0.1 impression.7search.com
`127.0.0.1 www.impression.7search.com
`127.0.0.1 install.browsertoolbar.com
`127.0.0.1 www.install.browsertoolbar.com
`127.0.0.1 installdollars.com
`127.0.0.1 www.installdollars.com
`127.0.0.1 installs.hotbar.com
`127.0.0.1 www.installs.hotbar.com
`127.0.0.1 internal.vx2.cc
`127.0.0.1 www.internal.vx2.cc
`127.0.0.1 internet-optimizer.com
`127.0.0.1 www.internet-optimizer.com
`127.0.0.1 ipend.datastorm.biz
`127.0.0.1 www.ipend.datastorm.biz
`127.0.0.1 ipinsight.com
`127.0.0.1 www.ipinsight.com
`127.0.0.1 iron.whenu.com
`127.0.0.1 www.iron.whenu.com
`127.0.0.1 javatar.cjt1.net
`127.0.0.1 www.javatar.cjt1.net
`127.0.0.1 jbns2.cydoor.com
`127.0.0.1 www.jbns2.cydoor.com
`127.0.0.1 jcde-nms4.joltid.net
`127.0.0.1 www.jcde-nms4.joltid.net
`127.0.0.1 jcde-nms5.joltid.net
`127.0.0.1 www.jcde-nms5.joltid.net
`127.0.0.1 jcde-nms6.joltid.net
`127.0.0.1 www.jcde-nms6.joltid.net
`127.0.0.1 jcms.cydoor.com
`127.0.0.1 www.jcms.cydoor.com
`127.0.0.1 jcontent.bns1.net
`127.0.0.1 www.jcontent.bns1.net
`127.0.0.1 jdownloadacc.cjt1.net
`127.0.0.1 www.jdownloadacc.cjt1.net
`127.0.0.1 jedonkey.cjt1.net
`127.0.0.1 www.jedonkey.cjt1.net
`127.0.0.1 jicq.cjt1.net
`127.0.0.1 www.jicq.cjt1.net
`127.0.0.1 jmindset.cjt1.net
`127.0.0.1 www.jmindset.cjt1.net
`127.0.0.1 jpedownload.joltid.com
`127.0.0.1 www.jpedownload.joltid.com
`127.0.0.1 jpiolet.cjt1.net
`127.0.0.1 www.jpiolet.cjt1.net
`127.0.0.1 jwildmedia.cjt1.net
`127.0.0.1 www.jwildmedia.cjt1.net
`127.0.0.1 k17177.bins.lop.com
`127.0.0.1 www.k17177.bins.lop.com
`127.0.0.1 kazanon.com
`127.0.0.1 www.kazanon.com
`127.0.0.1 lead.whenu.com
`127.0.0.1 www.lead.whenu.com
`127.0.0.1 license.hotbar.com
`127.0.0.1 www.license.hotbar.com
`127.0.0.1 lists.adroar.com
`127.0.0.1 www.lists.adroar.com
`127.0.0.1 look-today.com
`127.0.0.1 www.look-today.com
`127.0.0.1 look2me.com
`127.0.0.1 www.look2me.com
`127.0.0.1 lop.com
`127.0.0.1 www.lop.com
`127.0.0.1 magic.3721.com
`127.0.0.1 www.magic.3721.com
`127.0.0.1 mail.vx2.cc
`127.0.0.1 www.mail.vx2.cc
`127.0.0.1 map.gator.com
`127.0.0.1 www.map.gator.com
`127.0.0.1 mark.3721.com
`127.0.0.1 www.mark.3721.com
`127.0.0.1 master.mx-targeting.com
`127.0.0.1 www.master.mx-targeting.com
`127.0.0.1 maxexp.com
`127.0.0.1 www.maxexp.com
`127.0.0.1 media.altnet.com
`127.0.0.1 www.media.altnet.com
`127.0.0.1 mediabuy-nic.cjt1.net
`127.0.0.1 www.mediabuy-nic.cjt1.net
`127.0.0.1 memorymeter.com
`127.0.0.1 www.memorymeter.com
`127.0.0.1 mercury.whenu.com
`127.0.0.1 www.mercury.whenu.com
`127.0.0.1 messagebroadcaster.net
`127.0.0.1 www.messagebroadcaster.net
`127.0.0.1 meta.3721.com
`127.0.0.1 www.meta.3721.com
`127.0.0.1 mindseti.com
`127.0.0.1 www.mindseti.com
`127.0.0.1 movies-etc.com
`127.0.0.1 www.movies-etc.com
`127.0.0.1 msearch.3721.com
`127.0.0.1 www.msearch.3721.com
`127.0.0.1 msview.cc
`127.0.0.1 www.msview.cc
`127.0.0.1 mt1.climaxbucks.com
`127.0.0.1 www.mt1.climaxbucks.com
`127.0.0.1 mt23.climaxbucks.com
`127.0.0.1 www.mt23.climaxbucks.com
`127.0.0.1 my.iwon.com
`127.0.0.1 www.my.iwon.com
`127.0.0.1 mypanicbutton.com
`127.0.0.1 www.mypanicbutton.com
`127.0.0.1 mysearchnow.com
`127.0.0.1 www.mysearchnow.com
`127.0.0.1 mywebsearch.com
`127.0.0.1 www.mywebsearch.com
`127.0.0.1 netpalnow.com
`127.0.0.1 www.netpalnow.com
`127.0.0.1 netpaloffers.net
`127.0.0.1 www.netpaloffers.net
`127.0.0.1 netsearchsoft.com
`127.0.0.1 www.netsearchsoft.com
`127.0.0.1 new.net
`127.0.0.1 www.new.net
`127.0.0.1 nictechnetworks.com
`127.0.0.1 www.nictechnetworks.com
`127.0.0.1 nopop.net
`127.0.0.1 www.nopop.net
`127.0.0.1 ns1.exportusa.com
`127.0.0.1 www.ns1.exportusa.com
`127.0.0.1 ns1.vx2.cc
`127.0.0.1 www.ns1.vx2.cc
`127.0.0.1 ns2.vx2.cc
`127.0.0.1 www.ns2.vx2.cc
`127.0.0.1 odysseusmarketing.com
`127.0.0.1 www.odysseusmarketing.com
`127.0.0.1 offeroptimizer.com
`127.0.0.1 www.offeroptimizer.com
`127.0.0.1 omegasearch.com
`127.0.0.1 www.omegasearch.com
`127.0.0.1 omi-update.net
`127.0.0.1 www.omi-update.net
`127.0.0.1 orbitexplorer.com
`127.0.0.1 www.orbitexplorer.com
`127.0.0.1 partners.hotbar.com
`127.0.0.1 www.partners.hotbar.com
`127.0.0.1 paypertext.com
`127.0.0.1 www.paypertext.com
`127.0.0.1 pchi-vtrk.virtumundo.com
`127.0.0.1 www.pchi-vtrk.virtumundo.com
`127.0.0.1 plugusin4cash.com
`127.0.0.1 www.plugusin4cash.com
`127.0.0.1 plus.iwon.com
`127.0.0.1 www.plus.iwon.com
`127.0.0.1 pm.altnet.com
`127.0.0.1 www.pm.altnet.com
`127.0.0.1 predictivesearch.com
`127.0.0.1 www.predictivesearch.com
`127.0.0.1 pricebandit.com
`127.0.0.1 www.pricebandit.com
`127.0.0.1 privacy.virtumundo.com
`127.0.0.1 www.privacy.virtumundo.com
`127.0.0.1 prizemachine.games.iwon.com
`127.0.0.1 www.prizemachine.games.iwon.com
`127.0.0.1 promos.hotbar.com
`127.0.0.1 www.promos.hotbar.com
`127.0.0.1 prosearching.com
`127.0.0.1 www.prosearching.com
`127.0.0.1 puv.hotbar.com
`127.0.0.1 www.puv.hotbar.com
`127.0.0.1 query.i-lookup.com
`127.0.0.1 www.query.i-lookup.com
`127.0.0.1 regserver.gator.com
`127.0.0.1 www.regserver.gator.com
`127.0.0.1 reports.hotbar.com
`127.0.0.1 www.reports.hotbar.com
`127.0.0.1 reports.offeroptimizer.com
`127.0.0.1 www.reports.offeroptimizer.com
`127.0.0.1 results.dashbar.com
`127.0.0.1 www.results.dashbar.com
`127.0.0.1 results.searchscout.com
`127.0.0.1 www.results.searchscout.com
`127.0.0.1 resultsmaster.com
`127.0.0.1 www.resultsmaster.com
`127.0.0.1 rs.gator.com
`127.0.0.1 www.rs.gator.com
`127.0.0.1 rspsearch.com
`127.0.0.1 www.rspsearch.com
`127.0.0.1 s.abetterinternet.com
`127.0.0.1 www.s.abetterinternet.com
`127.0.0.1 savenow-pop-ads.com
`127.0.0.1 www.savenow-pop-ads.com
`127.0.0.1 savenow-popup-ads.com
`127.0.0.1 www.savenow-popup-ads.com
`127.0.0.1 sbox.3721.com
`127.0.0.1 www.sbox.3721.com
`127.0.0.1 sbvr.com
`127.0.0.1 www.sbvr.com
`127.0.0.1 scriptserver.gator.com
`127.0.0.1 www.scriptserver.gator.com
`127.0.0.1 search.active-max.com
`127.0.0.1 www.search.active-max.com
`127.0.0.1 search.gator.com
`127.0.0.1 www.search.gator.com
`127.0.0.1 search.ieplugin.com
`127.0.0.1 www.search.ieplugin.com
`127.0.0.1 search.iwon.com
`127.0.0.1 www.search.iwon.com
`127.0.0.1 search.mysearchnow.com
`127.0.0.1 www.search.mysearchnow.com
`127.0.0.1 search.xrenoder.com
`127.0.0.1 www.search.xrenoder.com
`127.0.0.1 search2.i-lookup.com
`127.0.0.1 www.search2.i-lookup.com
`127.0.0.1 search200.com
`127.0.0.1 www.search200.com
`127.0.0.1 searchassistant.iwon.com
`127.0.0.1 www.searchassistant.iwon.com
`127.0.0.1 searchassistant.net
`127.0.0.1 www.searchassistant.net
`127.0.0.1 searchbus.com
`127.0.0.1 www.searchbus.com
`127.0.0.1 searchdisp.hotbar.com
`127.0.0.1 www.searchdisp.hotbar.com
`127.0.0.1 searchexe.com
`127.0.0.1 www.searchexe.com
`127.0.0.1 searchweb2.com
`127.0.0.1 www.searchweb2.com
`127.0.0.1 sentrymon.ipinsight.net
`127.0.0.1 www.sentrymon.ipinsight.net
`127.0.0.1 server.ipinsight.net
`127.0.0.1 www.server.ipinsight.net
`127.0.0.1 shanghai.3721.com
`127.0.0.1 www.shanghai.3721.com
`127.0.0.1 similarsingles.com
`127.0.0.1 www.similarsingles.com
`127.0.0.1 sina.3721.com
`127.0.0.1 www.sina.3721.com
`127.0.0.1 skins.hotbar.com
`127.0.0.1 www.skins.hotbar.com
`127.0.0.1 soap.alexa.com
`127.0.0.1 www.soap.alexa.com
`127.0.0.1 spapp.whenu.com
`127.0.0.1 www.spapp.whenu.com
`127.0.0.1 spawnet.com
`127.0.0.1 www.spawnet.com
`127.0.0.1 speedbar.myway.com
`127.0.0.1 www.speedbar.myway.com
`127.0.0.1 sputnik.vx2.cc
`127.0.0.1 www.sputnik.vx2.cc
`127.0.0.1 spweather.whenu.com
`127.0.0.1 www.spweather.whenu.com
`127.0.0.1 spweb.whenu.com
`127.0.0.1 www.spweb.whenu.com
`127.0.0.1 spywarehelp.net
`127.0.0.1 www.spywarehelp.net
`127.0.0.1 sqwire.com
`127.0.0.1 www.sqwire.com
`127.0.0.1 sqwire.i-lookup.com
`127.0.0.1 www.sqwire.i-lookup.com
`127.0.0.1 srch.lop.com
`127.0.0.1 www.srch.lop.com
`127.0.0.1 ss.gator.com
`127.0.0.1 www.ss.gator.com
`127.0.0.1 ssbackup.gator.com
`127.0.0.1 www.ssbackup.gator.com
`127.0.0.1 st.brilliantdigital.com
`127.0.0.1 www.st.brilliantdigital.com
`127.0.0.1 static.411web.com
`127.0.0.1 www.static.411web.com
`127.0.0.1 stop-popup-ads-now.com
`127.0.0.1 www.stop-popup-ads-now.com
`127.0.0.1 stubmon.ipinsight.net
`127.0.0.1 www.stubmon.ipinsight.net
`127.0.0.1 sue.lop.com
`127.0.0.1 www.sue.lop.com
`127.0.0.1 superwebsearch.com
`127.0.0.1 www.superwebsearch.com
`127.0.0.1 sysupdate.grandstreetinteractive.com
`127.0.0.1 www.sysupdate.grandstreetinteractive.com
`127.0.0.1 sysupdate.ieplugin.com
`127.0.0.1 www.sysupdate.ieplugin.com
`127.0.0.1 tdko.com
`127.0.0.1 www.tdko.com
`127.0.0.1 tdmy.com
`127.0.0.1 www.tdmy.com
`127.0.0.1 tefs.com
`127.0.0.1 www.tefs.com
`127.0.0.1 tfil.com
`127.0.0.1 www.tfil.com
`127.0.0.1 thinkingmedia.net
`127.0.0.1 www.thinkingmedia.net
`127.0.0.1 thinstall.abetterinternet.com
`127.0.0.1 www.thinstall.abetterinternet.com
`127.0.0.1 tin.whenu.com
`127.0.0.1 www.tin.whenu.com
`127.0.0.1 titanium.whenu.com
`127.0.0.1 www.titanium.whenu.com
`127.0.0.1 toolbar.i-lookup.com
`127.0.0.1 www.toolbar.i-lookup.com
`127.0.0.1 toolbar2.i-lookup.com
`127.0.0.1 www.toolbar2.i-lookup.com
`127.0.0.1 tooltips.hotbar.com
`127.0.0.1 www.tooltips.hotbar.com
`127.0.0.1 topicks.com
`127.0.0.1 www.topicks.com
`127.0.0.1 totalvelocity.com
`127.0.0.1 www.totalvelocity.com
`127.0.0.1 tpcms.topicks.com
`127.0.0.1 www.tpcms.topicks.com
`127.0.0.1 tpdownload.topicks.com
`127.0.0.1 www.tpdownload.topicks.com
`127.0.0.1 tpreport.topicks.com
`127.0.0.1 www.tpreport.topicks.com
`127.0.0.1 track.dlsearchbar.com
`127.0.0.1 www.track.dlsearchbar.com
`127.0.0.1 track.simpletraffic.com
`127.0.0.1 www.track.simpletraffic.com
`127.0.0.1 tracking.roispy.com
`127.0.0.1 www.tracking.roispy.com
`127.0.0.1 tracking.spiderbait.com
`127.0.0.1 www.tracking.spiderbait.com
`127.0.0.1 tracking.thunderdownloads.com
`127.0.0.1 www.tracking.thunderdownloads.com
`127.0.0.1 traffichog.com
`127.0.0.1 www.traffichog.com
`127.0.0.1 transctl-dev.vx2.cc
`127.0.0.1 www.transctl-dev.vx2.cc
`127.0.0.1 transctl.vx2.cc
`127.0.0.1 www.transctl.vx2.cc
`127.0.0.1 trickle.gator.com
`127.0.0.1 www.trickle.gator.com
`127.0.0.1 ts.altnet.com
`127.0.0.1 www.ts.altnet.com
`127.0.0.1 ts.gator.com
`127.0.0.1 www.ts.gator.com
`127.0.0.1 tss.altnet.com
`127.0.0.1 www.tss.altnet.com
`127.0.0.1 tv.180solutions.com
`127.0.0.1 www.tv.180solutions.com
`127.0.0.1 update.speedbit.com
`127.0.0.1 www.update.speedbit.com
`127.0.0.1 update.stop-popup-ads-now.com
`127.0.0.1 www.update.stop-popup-ads-now.com
`127.0.0.1 update.thunderdownloads.com
`127.0.0.1 www.update.thunderdownloads.com
`127.0.0.1 updates.desktop.ak-networks.com
`127.0.0.1 www.updates.desktop.ak-networks.com
`127.0.0.1 updates.desktop.virtumundo.com
`127.0.0.1 www.updates.desktop.virtumundo.com
`127.0.0.1 updates.hotbar.com
`127.0.0.1 www.updates.hotbar.com
`127.0.0.1 updateserver.gator.com
`127.0.0.1 www.updateserver.gator.com
`127.0.0.1 upgrades.hotbar.com
`127.0.0.1 www.upgrades.hotbar.com
`127.0.0.1 user.3721.com
`127.0.0.1 www.user.3721.com
`127.0.0.1 view.atdmt.com
`127.0.0.1 www.view.atdmt.com
`127.0.0.1 vip-farm1.hotbar.com
`127.0.0.1 www.vip-farm1.hotbar.com
`127.0.0.1 vip-farm1v.hotbar.com
`127.0.0.1 www.vip-farm1v.hotbar.com
`127.0.0.1 vip-farm2.hotbar.com
`127.0.0.1 www.vip-farm2.hotbar.com
`127.0.0.1 vip-farm2v.hotbar.com
`127.0.0.1 www.vip-farm2v.hotbar.com
`127.0.0.1 vip-farm31v.hotbar.com
`127.0.0.1 www.vip-farm31v.hotbar.com
`127.0.0.1 vip-farm5v.hotbar.com
`127.0.0.1 www.vip-farm5v.hotbar.com
`127.0.0.1 virtumundo.com
`127.0.0.1 www.virtumundo.com
`127.0.0.1 vlogic.ak-networks.com
`127.0.0.1 www.vlogic.ak-networks.com
`127.0.0.1 vmadmin.com
`127.0.0.1 www.vmadmin.com
`127.0.0.1 vrape.hardloved.com
`127.0.0.1 www.vrape.hardloved.com
`127.0.0.1 vtrack.virtumundo.com
`127.0.0.1 www.vtrack.virtumundo.com
`127.0.0.1 wap.3721.com
`127.0.0.1 www.wap.3721.com
`127.0.0.1 wb.gator.com
`127.0.0.1 www.wb.gator.com
`127.0.0.1 weather.gator.com
`127.0.0.1 www.weather.gator.com
`127.0.0.1 weather.whenu.com
`127.0.0.1 www.weather.whenu.com
`127.0.0.1 weather.whenu.speedera.net
`127.0.0.1 www.weather.whenu.speedera.net
`127.0.0.1 web.balance.gator.com
`127.0.0.1 www.web.balance.gator.com
`127.0.0.1 web.whenu.com
`127.0.0.1 www.web.whenu.com
`127.0.0.1 web.whenu.speedera.net
`127.0.0.1 www.web.whenu.speedera.net
`127.0.0.1 webpdp.gator.com
`127.0.0.1 www.webpdp.gator.com
`127.0.0.1 wfix.com
`127.0.0.1 www.wfix.com
`127.0.0.1 whenu-advertising-info.com
`127.0.0.1 www.whenu-advertising-info.com
`127.0.0.1 whenu-advertising.com
`127.0.0.1 www.whenu-advertising.com
`127.0.0.1 whenu-popup-ads.com
`127.0.0.1 www.whenu-popup-ads.com
`127.0.0.1 whenu.com
`127.0.0.1 www.whenu.com
`127.0.0.1 whenusearch.com
`127.0.0.1 www.whenusearch.com
`127.0.0.1 whenushop-advertising-central.com
`127.0.0.1 www.whenushop-advertising-central.com
`127.0.0.1 whenushop-pop-ads.com
`127.0.0.1 www.whenushop-pop-ads.com
`127.0.0.1 whenushop-space.com
`127.0.0.1 www.whenushop-space.com
`127.0.0.1 whenushop.whenu.com
`127.0.0.1 www.whenushop.whenu.com
`127.0.0.1 ww2.ieplugin.com
`127.0.0.1 www.ww2.ieplugin.com
`127.0.0.1 ww3.ieplugin.com
`127.0.0.1 www.ww3.ieplugin.com
`127.0.0.1 wwa.ieplugin.com
`127.0.0.1 www.wwa.ieplugin.com
`127.0.0.1 wwd.ieplugin.com
`127.0.0.1 www.wwd.ieplugin.com
`127.0.0.1 www.2004cms.com
`127.0.0.1 2004cms.com
`127.0.0.1 www.3721.com
`127.0.0.1 3721.com
`127.0.0.1 www.680180.net
`127.0.0.1 680180.net
`127.0.0.1 www.7metasearch.com
`127.0.0.1 7metasearch.com
`127.0.0.1 www.7search.com
`127.0.0.1 7search.com
`127.0.0.1 www.aadcom.com
`127.0.0.1 aadcom.com
`127.0.0.1 www.abetterinternet.com
`127.0.0.1 abetterinternet.com
`127.0.0.1 www.active-alert-server.com
`127.0.0.1 active-alert-server.com
`127.0.0.1 www.active-max.com
`127.0.0.1 active-max.com
`127.0.0.1 www.acustat.com
`127.0.0.1 acustat.com
`127.0.0.1 www.addictivetechnologies.net
`127.0.0.1 addictivetechnologies.net
`127.0.0.1 www.adroar.com
`127.0.0.1 adroar.com
`127.0.0.1 www.adtactics.com
`127.0.0.1 adtactics.com
`127.0.0.1 www.adtomi.com
`127.0.0.1 adtomi.com
`127.0.0.1 www.aimdolls.com
`127.0.0.1 aimdolls.com
`127.0.0.1 www.aimphuck.com
`127.0.0.1 aimphuck.com
`127.0.0.1 www.alexa.com
`127.0.0.1 alexa.com
`127.0.0.1 www.allaboutsearching.com
`127.0.0.1 allaboutsearching.com
`127.0.0.1 www.allhyperlinks.com
`127.0.0.1 allhyperlinks.com
`127.0.0.1 www.almightysearch.com
`127.0.0.1 almightysearch.com
`127.0.0.1 www.altnet.com
`127.0.0.1 altnet.com
`127.0.0.1 www.altnetp2p.com
`127.0.0.1 altnetp2p.com
`127.0.0.1 www.amazingautossearch.com
`127.0.0.1 amazingautossearch.com
`127.0.0.1 www.amnv.net
`127.0.0.1 amnv.net
`127.0.0.1 www.at-games.com
`127.0.0.1 at-games.com
`127.0.0.1 www.avenuemedia.com
`127.0.0.1 avenuemedia.com
`127.0.0.1 www.b3d.com
`127.0.0.1 b3d.com
`127.0.0.1 www.bc777.com
`127.0.0.1 bc777.com
`127.0.0.1 www.bluehavenmedia.com
`127.0.0.1 bluehavenmedia.com
`127.0.0.1 www.bns1.net
`127.0.0.1 bns1.net
`127.0.0.1 www.bns2.net
`127.0.0.1 bns2.net
`127.0.0.1 www.bonzi.com
`127.0.0.1 bonzi.com
`127.0.0.1 www.bonzibuddy.com
`127.0.0.1 bonzibuddy.com
`127.0.0.1 www.brilliantdigital.com
`127.0.0.1 brilliantdigital.com
`127.0.0.1 www.browsertoolbar.com
`127.0.0.1 browsertoolbar.com
`127.0.0.1 www.browserwise.com
`127.0.0.1 browserwise.com
`127.0.0.1 www.bulletproofsoft.com
`127.0.0.1 bulletproofsoft.com
`127.0.0.1 www.bundleware.com
`127.0.0.1 bundleware.com
`127.0.0.1 www.centralmedia.ws
`127.0.0.1 centralmedia.ws
`127.0.0.1 www.cleangetaway.biz
`127.0.0.1 cleangetaway.biz
`127.0.0.1 www.click2findnow.com
`127.0.0.1 click2findnow.com
`127.0.0.1 www.clickalchemy.com
`127.0.0.1 clickalchemy.com
`127.0.0.1 www.clicktracking.info
`127.0.0.1 clicktracking.info
`127.0.0.1 www.climaxbucks.com
`127.0.0.1 climaxbucks.com
`127.0.0.1 www.clock-sync.com
`127.0.0.1 clock-sync.com
`127.0.0.1 www.cms1.net
`127.0.0.1 cms1.net
`127.0.0.1 www.cms2.net
`127.0.0.1 cms2.net
`127.0.0.1 www.cocktailcash.com
`127.0.0.1 cocktailcash.com
`127.0.0.1 www.contexualsearch.com
`127.0.0.1 contexualsearch.com
`127.0.0.1 www.crap2.com
`127.0.0.1 crap2.com
`127.0.0.1 www.cydoor.com
`127.0.0.1 cydoor.com
`127.0.0.1 www.dashbar.com
`127.0.0.1 dashbar.com
`127.0.0.1 www.datastorm.biz
`127.0.0.1 datastorm.biz
`127.0.0.1 www.date-manager.com
`127.0.0.1 date-manager.com
`127.0.0.1 www.dialup2.com
`127.0.0.1 dialup2.com
`127.0.0.1 www.domain.i-lookup.com
`127.0.0.1 domain.i-lookup.com
`127.0.0.1 www.ebates.com
`127.0.0.1 ebates.com
`127.0.0.1 www.ecpm.com
`127.0.0.1 ecpm.com
`127.0.0.1 www.ez-searching.com
`127.0.0.1 ez-searching.com
`127.0.0.1 www.find-quick.com
`127.0.0.1 find-quick.com
`127.0.0.1 www.findology.com
`127.0.0.1 findology.com
`127.0.0.1 www.funwebproducts.com
`127.0.0.1 funwebproducts.com
`127.0.0.1 www.gator.com
`127.0.0.1 gator.com
`127.0.0.1 www.gatoradvertisinginformationnetwork.com
`127.0.0.1 gatoradvertisinginformationnetwork.com
`127.0.0.1 www.gatorcorporation.com
`127.0.0.1 gatorcorporation.com
`127.0.0.1 www.getweathercast.com
`127.0.0.1 getweathercast.com
`127.0.0.1 www.gigatechsoftware.com
`127.0.0.1 gigatechsoftware.com
`127.0.0.1 www.gonnasearch.com
`127.0.0.1 gonnasearch.com
`127.0.0.1 www.grandstreetinteractive.com
`127.0.0.1 grandstreetinteractive.com
`127.0.0.1 www.greasycow.com
`127.0.0.1 greasycow.com
`127.0.0.1 www.hotbar.com
`127.0.0.1 hotbar.com
`127.0.0.1 www.i-lookup.com
`127.0.0.1 i-lookup.com
`127.0.0.1 www.ieplugin.com
`127.0.0.1 ieplugin.com
`127.0.0.1 www.igetnet.com
`127.0.0.1 igetnet.com
`127.0.0.1 www.ignkeywords.com
`127.0.0.1 ignkeywords.com
`127.0.0.1 www.ignphrases.com
`127.0.0.1 ignphrases.com
`127.0.0.1 www.imbum.com
`127.0.0.1 imbum.com
`127.0.0.1 www.internet-optimizer.com
`127.0.0.1 internet-optimizer.com
`127.0.0.1 www.ipinsight.com
`127.0.0.1 ipinsight.com
`127.0.0.1 www.ipinsight.net
`127.0.0.1 ipinsight.net
`127.0.0.1 www.iwon.com
`127.0.0.1 iwon.com
`127.0.0.1 www.kazanon.com
`127.0.0.1 kazanon.com
`127.0.0.1 www.linkstoyou.com
`127.0.0.1 linkstoyou.com
`127.0.0.1 www.look-today.com
`127.0.0.1 look-today.com
`127.0.0.1 www.look2me.com
`127.0.0.1 look2me.com
`127.0.0.1 www.look2me1.com
`127.0.0.1 look2me1.com
`127.0.0.1 www.look2me2.com
`127.0.0.1 look2me2.com
`127.0.0.1 www.look2me4.com
`127.0.0.1 look2me4.com
`127.0.0.1 www.lop.com
`127.0.0.1 lop.com
`127.0.0.1 www.lop2.com
`127.0.0.1 lop2.com
`127.0.0.1 www.lovetraffic.com
`127.0.0.1 lovetraffic.com
`127.0.0.1 www.lunasearch.com
`127.0.0.1 lunasearch.com
`127.0.0.1 www.memorymeter.com
`127.0.0.1 memorymeter.com
`127.0.0.1 www.messagebroadcaster.net
`127.0.0.1 messagebroadcaster.net
`127.0.0.1 www.mindseti.com
`127.0.0.1 mindseti.com
`127.0.0.1 www.mindsetinteractive.com
`127.0.0.1 mindsetinteractive.com
`127.0.0.1 www.movies-etc.com
`127.0.0.1 movies-etc.com
`127.0.0.1 www.mp3search.com
`127.0.0.1 mp3search.com
`127.0.0.1 www.msview.cc
`127.0.0.1 msview.cc
`127.0.0.1 www.mx-targeting.com
`127.0.0.1 mx-targeting.com
`127.0.0.1 www.mypanicbutton.com
`127.0.0.1 mypanicbutton.com
`127.0.0.1 www.mypctuneup.com
`127.0.0.1 mypctuneup.com
`127.0.0.1 www.mysearch.com
`127.0.0.1 mysearch.com
`127.0.0.1 www.mysearchnow.com
`127.0.0.1 mysearchnow.com
`127.0.0.1 www.mywebsearch.com
`127.0.0.1 mywebsearch.com
`127.0.0.1 www.netpalnow.com
`127.0.0.1 netpalnow.com
`127.0.0.1 www.netpaloffers.net
`127.0.0.1 netpaloffers.net
`127.0.0.1 www.netsearchsoft.com
`127.0.0.1 netsearchsoft.com
`127.0.0.1 www.newtonknows.com
`127.0.0.1 newtonknows.com
`127.0.0.1 www.nictechnetworks.com
`127.0.0.1 nictechnetworks.com
`127.0.0.1 www.no-pops.com
`127.0.0.1 no-pops.com
`127.0.0.1 www.nopop.net
`127.0.0.1 nopop.net
`127.0.0.1 www.nuker.com
`127.0.0.1 nuker.com
`127.0.0.1 www.odysseusmarketing.com
`127.0.0.1 odysseusmarketing.com
`127.0.0.1 www.offercompanion.com
`127.0.0.1 offercompanion.com
`127.0.0.1 www.offeroptimizer.com
`127.0.0.1 offeroptimizer.com
`127.0.0.1 www.omegasearch.com
`127.0.0.1 omegasearch.com
`127.0.0.1 www.omi-update.net
`127.0.0.1 omi-update.net
`127.0.0.1 www.pay-per-search.com
`127.0.0.1 pay-per-search.com
`127.0.0.1 www.payperranking.com
`127.0.0.1 payperranking.com
`127.0.0.1 www.plugusin4cash.com
`127.0.0.1 plugusin4cash.com
`127.0.0.1 www.precision-time.com
`127.0.0.1 precision-time.com
`127.0.0.1 www.pricebandit.com
`127.0.0.1 pricebandit.com
`127.0.0.1 www.prosearching.com
`127.0.0.1 prosearching.com
`127.0.0.1 www.qcksearch.com
`127.0.0.1 qcksearch.com
`127.0.0.1 www.resultsmaster.com
`127.0.0.1 resultsmaster.com
`127.0.0.1 www.rgs1.net
`127.0.0.1 rgs1.net
`127.0.0.1 www.rgs2.net
`127.0.0.1 rgs2.net
`127.0.0.1 www.roispy.com
`127.0.0.1 roispy.com
`127.0.0.1 www.rspsearch.com
`127.0.0.1 rspsearch.com
`127.0.0.1 www.rub.to
`127.0.0.1 rub.to
`127.0.0.1 www.sbvr.com
`127.0.0.1 sbvr.com
`127.0.0.1 www.search200.com
`127.0.0.1 search200.com
`127.0.0.1 www.searchassistant.net
`127.0.0.1 searchassistant.net
`127.0.0.1 www.searchexe.com
`127.0.0.1 searchexe.com
`127.0.0.1 www.searchscout.com
`127.0.0.1 searchscout.com
`127.0.0.1 www.searchweb2.com
`127.0.0.1 searchweb2.com
`127.0.0.1 www.similarsingles.com
`127.0.0.1 similarsingles.com
`127.0.0.1 www.spawnet.com
`127.0.0.1 spawnet.com
`127.0.0.1 www.spiderbait.com
`127.0.0.1 spiderbait.com
`127.0.0.1 www.spywarehelp.net
`127.0.0.1 spywarehelp.net
`127.0.0.1 www.spywarenuker.com
`127.0.0.1 spywarenuker.com
`127.0.0.1 www.srv2cpt.com
`127.0.0.1 srv2cpt.com
`127.0.0.1 www.stop-popup-ads-now.com
`127.0.0.1 stop-popup-ads-now.com
`127.0.0.1 www.tdko.com
`127.0.0.1 tdko.com
`127.0.0.1 www.tfil.com
`127.0.0.1 tfil.com
`127.0.0.1 www.tgcsearch.com
`127.0.0.1 tgcsearch.com
`127.0.0.1 www.thinkingmedia.net
`127.0.0.1 thinkingmedia.net
`127.0.0.1 www.topicks.com
`127.0.0.1 topicks.com
`127.0.0.1 www.totalvelocity.com
`127.0.0.1 totalvelocity.com
`127.0.0.1 www.tps108.org
`127.0.0.1 tps108.org
`127.0.0.1 www.trekblue.com
`127.0.0.1 trekblue.com
`127.0.0.1 www.twain-tech.com
`127.0.0.1 twain-tech.com
`127.0.0.1 www.unitedvending.net
`127.0.0.1 unitedvending.net
`127.0.0.1 www.virtumundo.com
`127.0.0.1 virtumundo.com
`127.0.0.1 www.vx2.cc
`127.0.0.1 vx2.cc
`127.0.0.1 www.weatherscope.com
`127.0.0.1 weatherscope.com
`127.0.0.1 www.websecurealert.com
`127.0.0.1 websecurealert.com
`127.0.0.1 www.whenu.com
`127.0.0.1 whenu.com
`127.0.0.1 www.whenu.com.edgesuite.net
`127.0.0.1 whenu.com.edgesuite.net
`127.0.0.1 www.whenusearch.com
`127.0.0.1 whenusearch.com
`127.0.0.1 www.whenushop.com
`127.0.0.1 whenushop.com
`127.0.0.1 www.world-portal.com
`127.0.0.1 world-portal.com
`127.0.0.1 www.yoogee.com
`127.0.0.1 yoogee.com
`127.0.0.1 www.zestyfind.com
`127.0.0.1 zestyfind.com
`127.0.0.1 www.zsearchtoolbar.com
`127.0.0.1 zsearchtoolbar.com
`127.0.0.1 www1.iwon.com
`127.0.0.1 www.www1.iwon.com
`127.0.0.1 www1.lop.com
`127.0.0.1 www.www1.lop.com
`127.0.0.1 www2.browsertoolbar.com
`127.0.0.1 www.www2.browsertoolbar.com
`127.0.0.1 www2.i-lookup.com
`127.0.0.1 www.www2.i-lookup.com
`127.0.0.1 xads.offeroptimizer.com
`127.0.0.1 www.xads.offeroptimizer.com
`127.0.0.1 xadso.offeroptimizer.com
`127.0.0.1 www.xadso.offeroptimizer.com
`127.0.0.1 xadsq.offeroptimizer.com
`127.0.0.1 www.xadsq.offeroptimizer.com
`127.0.0.1 xadx.offeroptimizer.com
`127.0.0.1 www.xadx.offeroptimizer.com
`127.0.0.1 xbs.climaxbucks.com
`127.0.0.1 www.xbs.climaxbucks.com
`127.0.0.1 xbs.cocktailcash.com
`127.0.0.1 www.xbs.cocktailcash.com
`127.0.0.1 ximages.offeroptimizer.com
`127.0.0.1 www.ximages.offeroptimizer.com
`127.0.0.1 xjupiter.com
`127.0.0.1 www.xjupiter.com
`127.0.0.1 xlime.offeroptimizer.com
`127.0.0.1 www.xlime.offeroptimizer.com
`127.0.0.1 xml.411web.com
`127.0.0.1 www.xml.411web.com
`127.0.0.1 xmlsearch.balance.gator.com
`127.0.0.1 www.xmlsearch.balance.gator.com
`127.0.0.1 xmlsearch.gator.com
`127.0.0.1 www.xmlsearch.gator.com
`127.0.0.1 yahoo.3721.com
`127.0.0.1 www.yahoo.3721.com
`127.0.0.1 yoogee.com
`127.0.0.1 www.yoogee.com
`127.0.0.1 z1.vx2.cc
`127.0.0.1 www.z1.vx2.cc
`127.0.0.1 zestyfind.com
`127.0.0.1 www.zestyfind.com
`127.0.0.1 zinc.whenu.com
`127.0.0.1 www.zinc.whenu.com
`127.0.0.1 zsearchtoolbar.com
`127.0.0.1 www.zsearchtoolbar.com
`127.0.0.1 babe.the-killer.bz
`127.0.0.1 babe.k-lined.com
`127.0.0.1 did.i-used.cc
`127.0.0.1 coolwwwsearch.com
`127.0.0.1 coolwebsearch.com
`127.0.0.1 hi.studioaperto.net
`127.0.0.1 www.webbrowser.tv
`127.0.0.1 www.wazzupnet.com
`127.0.0.1 gueb.com
`127.0.0.1 kabex.com
`127.0.0.1 www.hityou.com
`127.0.0.1 miosearch.com
`127.0.0.1 wazzupnet.com
`127.0.0.1 213.131.225.2
`127.0.0.1 www.blue-elefant.com
`127.0.0.1 babeweb.de
`127.0.0.1 start-seite.com
`127.0.0.1 sexolymp.com
`127.0.0.1 toriii.cc
`127.0.0.1 www.xtipp.de
`127.0.0.1 urawa.cool.ne.jp
`127.0.0.1 777search.com
`127.0.0.1 ace-webmaster.com
`127.0.0.1 aifind.info
`127.0.0.1 amateurliveshow.com
`127.0.0.1 anarchylolita.com
`127.0.0.1 anarchyporn.com
`127.0.0.1 approvedlinks.com
`127.0.0.1 cantfind.com
`127.0.0.1 castingsamateur.com
`127.0.0.1 cyberrape.com
`127.0.0.1 dialerclub.com
`127.0.0.1 exit.megago.com
`127.0.0.1 fastmetasearch.com
`127.0.0.1 findwhatevernow.com
`127.0.0.1 globesearch.com
`127.0.0.1 hotfreebies.com
`127.0.0.1 krankin.com
`127.0.0.1 begin2search.com
`127.0.0.1 mainstreamdollars.com
`127.0.0.1 live.sex-explorer.com
`127.0.0.1 loveadot.com
`127.0.0.1 megaseek.net
`127.0.0.1 mixsearch.com
`127.0.0.1 munky.com
`127.0.0.1 newtopsites.com
`127.0.0.1 noblindlinks.com
`127.0.0.1 r.babenet.com
`127.0.0.1 searchresult.net
`127.0.0.1 sexarena.org
`127.0.0.1 skeech.com
`127.0.0.1 superwp.by.ru
`127.0.0.1 sureseeker.com
`127.0.0.1 wethere.com
`127.0.0.1 wowsearch.org
`127.0.0.1 www.xxx.com
`127.0.0.1 www.websearch.com
`127.0.0.1 partner23.firehunt.com
`127.0.0.1 screensaver.it
`127.0.0.1 xads.cliks.org
`127.0.0.1 xwebsearch.biz
`127.0.0.1 znext.com
`127.0.0.1 rawtocash.net
`127.0.0.1 dev.ntcor.com
`127.0.0.1 193.125.201.50
`127.0.0.1 www.allcybersearch.com
`127.0.0.1 www.tinybar.com
`127.0.0.1 topsite.us
`127.0.0.1 topsites.us
`127.0.0.1 topsitez.us
`127.0.0.1 out.true-counter.com
`127.0.0.1 www.cnetadd.com
`127.0.0.1 okmmm.com
`127.0.0.1 www.139mm.com
`127.0.0.1 008k.com
`127.0.0.1 00hq.com
`127.0.0.1 1-domains-registrations.com
`127.0.0.1 100sexlinks.com
`127.0.0.1 157.238.62.14
`127.0.0.1 1sexparty.com
`127.0.0.1 1stpagehere.com
`127.0.0.1 2020search.com
`127.0.0.1 209.66.114.130
`127.0.0.1 24teen.com
`127.0.0.1 36site.com
`127.0.0.1 4corn.net
`127.0.0.1 66.117.14.138
`127.0.0.1 66.197.100.83
`127.0.0.1 66.250.107.99
`127.0.0.1 66.250.107.100
`127.0.0.1 66.250.107.101
`127.0.0.1 66.250.130.194
`127.0.0.1 66.250.170.107
`127.0.0.1 66.250.57.26
`127.0.0.1 66.250.57.27
`127.0.0.1 66.250.57.28
`127.0.0.1 66.250.74.150
`127.0.0.1 777top.com
`127.0.0.1 8ad.com
`127.0.0.1 aboutclicker.com
`127.0.0.1 abrp.net
`127.0.0.1 accessthefuture.net
`127.0.0.1 acemedic.com
`127.0.0.1 actionbreastcancer.org
`127.0.0.1 activexupdate.com
`127.0.0.1 adamsupportgroup.org
`127.0.0.1 adasearch.com
`127.0.0.1 adipics.com
`127.0.0.1 adspics.com
`127.0.0.1 adult-engine-search.com
`127.0.0.1 adult-erotic-guide.net
`127.0.0.1 adult-friends-finder.net
`127.0.0.1 adulthyperlinks.com
`127.0.0.1 adulttds.com
`127.0.0.1 advert.exaccess.ru
`127.0.0.1 agentstudio.com
`127.0.0.1 africaspromise.org
`127.0.0.1 akril.com
`127.0.0.1 alcatel.ws
`127.0.0.1 alfa-search.com
`127.0.0.1 all-inet.com
`127.0.0.1 allabtcars.com
`127.0.0.1 allabtjeeps.com
`127.0.0.1 allcybersearch.com
`127.0.0.1 allinternetbusiness.com
`127.0.0.1 almarvideos.com
`127.0.0.1 amandamountains.com
`127.0.0.1 amigeek.com
`127.0.0.1 amisbusiness.com
`127.0.0.1 analmovi.com
`127.0.0.1 anin.org
`127.0.0.1 annaromeo.com
`127.0.0.1 antrocity.com
`127.0.0.1 anything4health.com
`127.0.0.1 apsua.com
`127.0.0.1 aregay.com
`127.0.0.1 arheo.com
`127.0.0.1 arizonaweb.org
`127.0.0.1 armitageinn.com
`127.0.0.1 art-func.com
`127.0.0.1 art-xxx.com
`127.0.0.1 artachnid.com
`127.0.0.1 asiankingkong.com
`127.0.0.1 ass-gals.com
`127.0.0.1 athenrye.com
`127.0.0.1 avian-ads.com
`127.0.0.1 ayakawamura.com
`127.0.0.1 ayumitaniguchi.com
`127.0.0.1 bannedhost.net
`127.0.0.1 barbudafarms.com
`127.0.0.1 barnandfence.com
`127.0.0.1 batsearch.com
`127.0.0.1 baygraphicsllc.com
`127.0.0.1 bb-search.com
`127.0.0.1 bbbsearch.com
`127.0.0.1 bedhome.com

`127.0.0.1 bediadance.com
`127.0.0.1 bellabasketsfl.com
`127.0.0.1 bernaolatwin.com
`127.0.0.1 best-counter.com
`127.0.0.1 best-hardpics.com
`127.0.0.1 best-winning-casino.com
`127.0.0.1 bestcrawler.com
`127.0.0.1 bestfor.ru
`127.0.0.1 bestporngate.com
`127.0.0.1 bestxporno.com
`127.0.0.1 blackjack-free.net
`127.0.0.1 blender.xu.pl
`127.0.0.1 bodaciousbabette.com
`127.0.0.1 boobdoll.com
`127.0.0.1 boobsandtits.com
`127.0.0.1 boobsclub.com
`127.0.0.1 boredlife.com
`127.0.0.1 bowlofogumbo.com
`127.0.0.1 bradcoem.org
`127.0.0.1 brandiyoung.com
`127.0.0.1 brookeburn.com
`127.0.0.1 bucps.com
`127.0.0.1 burgerkingbigscreen.com
`127.0.0.1 buscards.net
`127.0.0.1 bustyrussell.com
`127.0.0.1 buttejazz.org
`127.0.0.1 buyselldomain.net
`127.0.0.1 calcioturris.com
`127.0.0.1 canberracricketcoaching.com
`127.0.0.1 candycantaloupes.com
`127.0.0.1 careers.dulcineasystems.net
`127.0.0.1 carsands.com
`127.0.0.1 carsrentals.net
`127.0.0.1 casino-gambling-1.net
`127.0.0.1 casino-gambling-2.net
`127.0.0.1 casino-onlines.net
`127.0.0.1 casino.com.free.game.pogo.gratisdownloads.nl
`127.0.0.1 casino2win.net
`127.0.0.1 casinomidas.net
`127.0.0.1 casinonline.net
`127.0.0.1 catallogue.com
`127.0.0.1 catsss.da.ru
`127.0.0.1 caxa.ru
`127.0.0.1 cclebali.org
`127.0.0.1 ceewawires.org
`127.0.0.1 certumgroup.com
`127.0.0.1 chelancatering.com
`127.0.0.1 childrenvilla.com
`127.0.0.1 chips-4-free.com
`127.0.0.1 chrisswasey.com
`127.0.0.1 chriswallace.net
`127.0.0.1 ckick4thumbs.com
`127.0.0.1 clackamasliteraryreview.com
`127.0.0.1 clearsearch.cc
`127.0.0.1 clearsearch.net
`127.0.0.1 clickaire.com
`127.0.0.1 clickyestoenter.net
`127.0.0.1 clrsch.com
`127.0.0.1 cmtapestry.com
`127.0.0.1 cool-homepage.co
`127.0.0.1 cool-homepage.com
`127.0.0.1 cool-search.net
`127.0.0.1 cool-search.netfartpost.com
`127.0.0.1 cool-web-search.com
`127.0.0.1 coolfetishsite.com
`127.0.0.1 coolfreehost.com
`127.0.0.1 coolfreepage.com
`127.0.0.1 coolfreepages.com
`127.0.0.1 coolmoneysearch.com
`127.0.0.1 coolpornsearch.com
`127.0.0.1 coolsearcher.info
`127.0.0.1 coolwebsearch.
`127.0.0.1 coolwebsearsh.com
`127.0.0.1 coolwwwsearch.
`127.0.0.1 copmtraine.com
`127.0.0.1 couldnotfind.com
`127.0.0.1 count-all.com
`127.0.0.1 cracks.me.uk
`127.0.0.1 creamedcutties.com
`127.0.0.1 creditsearchonline.com
`127.0.0.1 crestring.com
`127.0.0.1 crooder.com
`127.0.0.1 curvedspaces.com
`127.0.0.1 cvs.jps.ru
`127.0.0.1 cvsymphony.com
`127.0.0.1 cydom.com
`127.0.0.1 daily-gals.com
`127.0.0.1 dancingbabycd.com
`127.0.0.1 datanotary.com
`127.0.0.1 datareco.com
`127.0.0.1 davemarshall.org
`127.0.0.1 dcfitusa.com
`127.0.0.1 defaultsearch.net
`127.0.0.1 desarrollocreativo.com
`127.0.0.1 develip.com
`127.0.0.1 dewis.spb.ru
`127.0.0.1 dewis.us
`127.0.0.1 df809jow4wj2304lfd0sf9fsd0a2t4ldf809jow4wj2304lfd0sf9fsd0a2t4ld.biz
`127.0.0.1 dietpills4free.com
`127.0.0.1 dietpussy.com
`127.0.0.1 digistreamsa.com
`127.0.0.1 dionforvalleycouncil.org
`127.0.0.1 doctorwaldron.com
`127.0.0.1 document-not-found.pornpic.org
`127.0.0.1 doggyaction.com
`127.0.0.1 domain-your-registration.com
`127.0.0.1 domains-for-you-online.com
`127.0.0.1 domains2003.net
`127.0.0.1 domkrat.com
`127.0.0.1 dp-host.com
`127.0.0.1 dragqueen.gay-clan.com
`127.0.0.1 drug-sources-exposed.com
`127.0.0.1 drvvv.com
`127.0.0.1 dutch-sex.com
`127.0.0.1 dvdbank.org
`127.0.0.1 e-localad.com
`127.0.0.1 e-plus.cc
`127.0.0.1 e-websitesolutions.com
`127.0.0.1 eases.net
`127.0.0.1 easy-search.net
`127.0.0.1 easycategories.com
`127.0.0.1 ecosrioplatenses.org
`127.0.0.1 ecstasyporn.net
`127.0.0.1 eikokoike.com
`127.0.0.1 epornsex.com
`127.0.0.1 euuu.com
`127.0.0.1 evidence-detector.biz
`127.0.0.1 evilspidercomics.com
`127.0.0.1 ewebsearch.net
`127.0.0.1 findloss.com
`127.0.0.1 excellentsckin.com
`127.0.0.1 extremeseek.net
`127.0.0.1 f*ckdenniss.com
`127.0.0.1 f*cknicepics.com
`127.0.0.1 faithstevens.com
`127.0.0.1 fantasiewelten.com
`127.0.0.1 farmsteadbandb.com
`127.0.0.1 fartpost.com
`127.0.0.1 fastwebfinder.com
`127.0.0.1 faxporn.com
`127.0.0.1 fickenisgeil.de
`127.0.0.1 finance-loans.com
`127.0.0.1 find-itnow.com
`127.0.0.1 find-uk-health.co.uk
`127.0.0.1 find4u.net
`127.0.0.1 findit-now.com
`127.0.0.1 findthesite.com
`127.0.0.1 findthewebsiteyouneed.com
`127.0.0.1 fionasteel.com
`127.0.0.1 firstbookmark.net
`127.0.0.1 fitness-free.com
`127.0.0.1 foodvacations.net
`127.0.0.1 forex.jps.ru
`127.0.0.1 forexcredit.com
`127.0.0.1 forexcredit.ru
`127.0.0.1 formingfusions.com
`127.0.0.1 forsythfire.net
`127.0.0.1 forthline.com
`127.0.0.1 free-chipes.com
`127.0.0.1 free-f*cking-video.com
`127.0.0.1 free-hit.com
`127.0.0.1 free-pics-and-movies.com
`127.0.0.1 free-sex-movie-clips.net
`127.0.0.1 free4porno.net
`127.0.0.1 free64all.com
`127.0.0.1 freebookmark.net
`127.0.0.1 freebookmarks.net
`127.0.0.1 freecategories.com
`127.0.0.1 freecoolhost.com
`127.0.0.1 freerbhost.com
`127.0.0.1 freeshemalepics.net
`127.0.0.1 freeyaho.com
`127.0.0.1 freshseek.com
`127.0.0.1 freshteensite.com
`127.0.0.1 gabrielscott.com
`127.0.0.1 galpostgirls.com
`127.0.0.1 gals-for-free.com
`127.0.0.1 gambling-online4you.com
`127.0.0.1 gameterror.net
`127.0.0.1 gay50.com
`127.0.0.1 generalsmeltingofcanada.com
`127.0.0.1 geteens.com
`127.0.0.1 getpicshere.com
`127.0.0.1 gimmezamore.com
`127.0.0.1 gimnasiaer.com
`127.0.0.1 girls-porn-life.com
`127.0.0.1 glbdf.org
`127.0.0.1 global-finder.com
`127.0.0.1 globe-finder.cc
`127.0.0.1 globe-finder.com
`127.0.0.1 gocybersearch.com
`127.0.0.1 golftennis.net
`127.0.0.1 good-mortgages-calculator.com
`127.0.0.1 good-mortgages.net
`127.0.0.1 goodsexs.com
`127.0.0.1 googlebar.jps.ru
`127.0.0.1 googlf.com
`127.0.0.1 gradforum.org
`127.0.0.1 gratis-porn-movie.com
`127.0.0.1 gratis-pornopics.com
`127.0.0.1 guzzycats.com
`127.0.0.1 gzphoenix.com
`127.0.0.1 hallnetaccolade.com
`127.0.0.1 hand-book.com
`127.0.0.1 happyanal.com
`127.0.0.1 hard-gals.com
`127.0.0.1 hardbodytgp.com
`127.0.0.1 hardcoreover.com
`127.0.0.1 hardloved.com
`127.0.0.1 hardwareseek.net
`127.0.0.1 harukaigawa.com
`127.0.0.1 hccsolanonapa.org
`127.0.0.1 health-protein.com
`127.0.0.1 hentai4u.net
`127.0.0.1 here4search.com
`127.0.0.1 heyrichy.com
`127.0.0.1 hi-search.com
`127.0.0.1 hiddenguides.com
`127.0.0.1 hitlistlyrics.com
`127.0.0.1 holidayautostr.com
`127.0.0.1 homemortage.ws
`127.0.0.1 hostssp.com
`127.0.0.1 hot-cartoon-sex.anime.american-teens.net
`127.0.0.1 hotbookmark.com
`127.0.0.1 hotels-list.net
`127.0.0.1 hotelxxxcams.com
`127.0.0.1 hotpopup.com
`127.0.0.1 hotsearchbox.com
`127.0.0.1 hotsex-series.com
`127.0.0.1 hotstartpage.com

`127.0.0.1 hqsex.biz
`127.0.0.1 hugeporn4u.net
`127.0.0.1 hunacsa.com
`127.0.0.1 hupacasath.com
`127.0.0.1 hzsx.com
`127.0.0.1 icansearch.net
`127.0.0.1 idgsearch.com
`127.0.0.1 ie-search.com
`127.0.0.1 incestporngate.com
`127.0.0.1 infodigger.net
`127.0.0.1 infoglobus.com
`127.0.0.1 inherhole.com
`127.0.0.1 insertthiscock.com
`127.0.0.1 insurance-flood.net
`127.0.0.1 insuranceall.net
`127.0.0.1 internetsearch.ru
`127.0.0.1 ionichost.com
`127.0.0.1 ionomist.com
`127.0.0.1 ipsex.net
`127.0.0.1 itsanal.com
`127.0.0.1 itseasy.us
`127.0.0.1 iweb-commerce.com
`127.0.0.1 iwebland.com
`127.0.0.1 jeannineoldfield.com
`127.0.0.1 jethomepage.com
`127.0.0.1 jetseeker.com
`127.0.0.1 jmhgallery.org
`127.0.0.1 joannelatham.com
`127.0.0.1 judin.ru
`127.0.0.1 junkysex.com
`127.0.0.1 karleyt.narod.ru
`127.0.0.1 kathisomers.com
`127.0.0.1 kazaa-lite.ws
`127.0.0.1 keithgreenpro.com
`127.0.0.1 kenmccaul.com
`127.0.0.1 kilosex.com
`127.0.0.1 kimhines.com
`127.0.0.1 kinoru.com
`127.0.0.1 ksdspups.org
`127.0.0.1 landrape.com
`127.0.0.1 lauraroebuck.com
`127.0.0.1 leannalovelace.com
`127.0.0.1 lesobank.ru
`127.0.0.1 libertyonlinehosting.com
`127.0.0.1 lingerie-mania.com
`127.0.0.1 lisamatthew.com
`127.0.0.1 liveholio.com
`127.0.0.1 livenewspaper.com
`127.0.0.1 louiseleeds.com
`127.0.0.1 love-pix.com
`127.0.0.1 lovelas.com
`127.0.0.1 lovelysearch.com
`127.0.0.1 low-taxes.com
`127.0.0.1 luckysearch.net
`127.0.0.1 lunitaweb.net
`127.0.0.1 lustful-porno.com
`127.0.0.1 mackinnonsbrook.org
`127.0.0.1 madfinder.com
`127.0.0.1 madisonmoons.com
`127.0.0.1 madisonoilco.com
`127.0.0.1 madonalive.com
`127.0.0.1 majuozawa.com
`127.0.0.1 makin-do.com
`127.0.0.1 male4free.com
`127.0.0.1 map-quest.org
`127.0.0.1 marilynchamber.com
`127.0.0.1 martfinder.com
`127.0.0.1 massearch.com
`127.0.0.1 matetrava.com
`127.0.0.1 mature50.com
`127.0.0.1 matureporngate.com
`127.0.0.1 maxdzines.com
`127.0.0.1 mcgeeforlabor.com
`127.0.0.1 mdstunisie.org
`127.0.0.1 medicare-insurance.net
`127.0.0.1 medicare-supplemental.com
`127.0.0.1 mega-dating-tips.com
`127.0.0.1 megumikanzaki.com
`127.0.0.1 meshalynn.com
`127.0.0.1 meta-adult.com
`127.0.0.1 meta-casino.com
`127.0.0.1 meta-mobile.com
`127.0.0.1 meta-porn.com
`127.0.0.1 metafora.ru
`127.0.0.1 metapoisk.ru
`127.0.0.1 michiyonakajima.com
`127.0.0.1 miconsultamedica.com
`127.0.0.1 mikasakamoto.com
`127.0.0.1 mikoni.com
`127.0.0.1 militarygods.porn4porn.net
`127.0.0.1 millennialpeople.org
`127.0.0.1 mipham.org
`127.0.0.1 missingcommand.com
`127.0.0.1 mommykiss.com
`127.0.0.1 moneyhunters.com
`127.0.0.1 montgomeryhospitalanesthesia.com
`127.0.0.1 morflot.com
`127.0.0.1 mortgage-debt.net
`127.0.0.1 mortismaximus.com
`127.0.0.1 moscowwhores.com
`127.0.0.1 moviecategories.com
`127.0.0.1 mp3-pix.com
`127.0.0.1 mrtg.jps.ru
`127.0.0.1 msn-info.net
`127.0.0.1 multipussy.com
`127.0.0.1 mundopolar.com
`127.0.0.1 mustv.com
`127.0.0.1 mywebsearch.net
`127.0.0.1 nativehardcore.com
`127.0.0.1 naturalspy.com
`127.0.0.1 nbasportsbook.net
`127.0.0.1 needf*cknow.com
`127.0.0.1 nellyslyrics.com
`127.0.0.1 nepgyan.com
`127.0.0.1 nesrecords.com
`127.0.0.1 netshastra.net
`127.0.0.1 nettime.ru
`127.0.0.1 nettracker.jps.ru
`127.0.0.1 netyellowpages.info
`127.0.0.1 new-incest.com
`127.0.0.1 newcategories.com
`127.0.0.1 newcracks.com
`127.0.0.1 newcracks.net
`127.0.0.1 newlife-lajolla.com
`127.0.0.1 newsexgate.com
`127.0.0.1 newtonsracks.com
`127.0.0.1 newxpics.com
`127.0.0.1 nhlsportsbook.net
`127.0.0.1 niagaracapital.com
`127.0.0.1 niche-tv.com
`127.0.0.1 nmrba.com
`127.0.0.1 nocalories.net
`127.0.0.1 nocensor.com
`127.0.0.1 ormandcompany.com
`127.0.0.1 nsbabes.com
`127.0.0.1 nuclearwitness.org
`127.0.0.1 nursemania.com
`127.0.0.1 nvntour.com
`127.0.0.1 nvphall.org
`127.0.0.1 oborot.com
`127.0.0.1 ocalalivestockmarket.com
`127.0.0.1 ocsff.com
`127.0.0.1 oeatlanta.com
`127.0.0.1 oharrowsearch.com
`127.0.0.1 ok-search.com
`127.0.0.1 okulta.com
`127.0.0.1 omegabrains.net
`127.0.0.1 online-casino-1.net
`127.0.0.1 online-casino-bonus.info
`127.0.0.1 online-casinos-x.com
`127.0.0.1 online-winning.net
`127.0.0.1 onlineserverz.com
`127.0.0.1 onlinetradings.net
`127.0.0.1 onlycunt.com
`127.0.0.1 onlyinsured.com
`127.0.0.1 operanabuco.com
`127.0.0.1 opsex.com
`127.0.0.1 oregoncharters.org
`127.0.0.1 otrlives.com
`127.0.0.1 ozawamadoka.com
`127.0.0.1 paigesummer.com
`127.0.0.1 pamelacollections.com
`127.0.0.1 panamcup.com
`127.0.0.1 pantygirls4u.com
`127.0.0.1 pantyhoserealm.com
`127.0.0.1 pantyplace.com
`127.0.0.1 pastubes.com
`127.0.0.1 paulapage.com
`127.0.0.1 paulhoover.com
`127.0.0.1 payfortraffic.net
`127.0.0.1 pedo.ws
`127.0.0.1 people.1gb.ru
`127.0.0.1 pervertbot.com
`127.0.0.1 pharma-diet-pills.com
`127.0.0.1 pharmacy2003.com
`127.0.0.1 pharmalocator.com
`127.0.0.1 phendimetrazine-tenuate-adipex.com
`127.0.0.1 pics-videos.com
`127.0.0.1 picsdir.com
`127.0.0.1 picsforbucks.com
`127.0.0.1 picsofseductiveladies.com
`127.0.0.1 pills-birth-control.com
`127.0.0.1 pillsmall.com
`127.0.0.1 pilotronix.com
`127.0.0.1 pixpox.com
`127.0.0.1 planemusic.com
`127.0.0.1 poiska.net
`127.0.0.1 poker-casino-free.com
`127.0.0.1 poker-games-free.net
`127.0.0.1 polradiologia.com
`127.0.0.1 pooi.net
`127.0.0.1 porn-teacher.com
`127.0.0.1 porncamz.com
`127.0.0.1 pornfree.info
`127.0.0.1 pornnightdreams.com
`127.0.0.1 pornokopec.com
`127.0.0.1 porntetris.com
`127.0.0.1 porntwist.com
`127.0.0.1 powerwebsearch.com
`127.0.0.1 prblitz.com
`127.0.0.1 pretypics.com
`127.0.0.1 pribalt.com
`127.0.0.1 privacy-support.biz
`127.0.0.1 privateporn.net
`127.0.0.1 prostactive.com
`127.0.0.1 prostol.com
`127.0.0.1 protect-yourself.biz
`127.0.0.1 prsainlandempire.org
`127.0.0.1 put-your-link-here.com
`127.0.0.1 pyrocorp.com
`127.0.0.1 quick-search.ws
`127.0.0.1 quiksearchgenealogy.com
`127.0.0.1 radfrall.org
`127.0.0.1 ramgo.com
`127.0.0.1 ranafrog.ne
`127.0.0.1 rapegate.com
`127.0.0.1 redbudbmx.com
`127.0.0.1 refinance-help.com
`127.0.0.1 removeearthkeepers.org
`127.0.0.1 rightfinder.net
`127.0.0.1 robbsproshop.com
`127.0.0.1 robertferencz.com
`127.0.0.1 rotocasters.com
`127.0.0.1 royalsearch.net
`127.0.0.1 runsearch.com
`127.0.0.1 russiansponsor.com
`127.0.0.1 russogay.com
`127.0.0.1 s2.exocrew.com
`127.0.0.1 sacitylife.com
`127.0.0.1 samplegals.com
`127.0.0.1 satisf*cktion.net
`127.0.0.1 sbssurvivor.com
`127.0.0.1 scarypix.com
`127.0.0.1 sccdnet.com
`127.0.0.1 schoolforest.com
`127.0.0.1 search-1.net
`127.0.0.1 search-2003.com
`127.0.0.1 search-about.net
`127.0.0.1 search-hawk.com
`127.0.0.1 search-log.com
`127.0.0.1 search-meta.com
`127.0.0.1 search-safe.com
`127.0.0.1 search.psn.cn
`127.0.0.1 searchadult
djolafrite
 
Messages: 13
Inscription: 21 Juil 2005, 00:25

Messagede nickW » 14 Aoû 2005, 16:33

Bonjour,

Le même log, stp, en ayant supprimé les lignes commençant par 127.0.0.1 (contenu du fichier hosts).

Merci,
nickW - Image
30/07/2012: Plus de désinfection de PC jusqu'à nouvel ordre.
Pas de demande d'analyse de log en MP (Message Privé)
Mes configs
Avatar de l’utilisateur
nickW
Modérateur
 
Messages: 21698
Inscription: 20 Mai 2004, 17:41
Localisation: Dordogne/Île de France

Messagede djolafrite » 14 Aoû 2005, 17:31

StartDreck (build 2.1.7 public stable) - 2005-08-14 @ 15:02:58 (GMT +02:00)
Platform: Windows XP (Win NT 5.1.2600 Service Pack 2)
Internet Explorer: 6.0.2900.2180
Logged in as audrey at TEST

»Registry
»Run Keys
»Current User
»Run
*CTFMON.EXE=C:\WINDOWS\system32\ctfmon.exe
*SpybotSD TeaTimer=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
»RunOnce
»Default User
»Run
*CTFMON.EXE=C:\WINDOWS\System32\CTFMON.EXE
*System driver=Messenger.exe
*wvsvc=wvsvc.exe
*AVG7_Run=C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE
»RunOnce
*System driver=Messenger.exe
»Local Machine
»Run
*NeroCheck=C:\WINDOWS\System32\\NeroCheck.exe
*QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
*KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
*gcasServ="C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
*Outpost Firewall=C:\Program Files\Agnitum\Outpost Firewall 1.0\outpost.exe /waitservice
*AVG7_CC=C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
*AVG7_EMC=C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
+OptionalComponents
+MSFS
*Installed=1
+MAPI
*Installed=1
*NoChange=1
+MAPI
*Installed=1
*NoChange=1
»RunOnce
»RunServices
»RunServicesOnce
»RunOnceEx
»RunServicesOnceEx
»File Associations (CR)
+.bat
*batfile="%1" %*
+.com
*comfile="%1" %*
+.disabled
*SpybotSD.DisabledFile="C:\Program Files\Spybot - Search & Destroy\blindman.exe" "%1"
+.exe
*exefile="%1" %*
+.hta
`= [key or value does not exist]
+.htm
*FirefoxHTML=C:\PROGRA~1\MOZILL~1\FIREFOX.EXE -url "%1"
+.html
*FirefoxHTML=C:\PROGRA~1\MOZILL~1\FIREFOX.EXE -url "%1"
+.js
*JSFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.jse
*JSEFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.pif
*piffile="%1" %*
+.reg
*regfile=regedit.exe "%1"
+.scr
*scrfile="%1" /S
+.txt
*txtfile=%SystemRoot%\system32\NOTEPAD.EXE %1
+.vbs
*VBSFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.vbe
*VBEFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.wsh
*WSHFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.wsf
*WSFFile=%SystemRoot%\System32\WScript.exe "%1" %*
+.lnk
`lnkfile= [key or value does not exist]
»Active Setup (LM)
+Internet Explorer/>{26923b43-4d38-484f-9b9e-de460746276c}
*StubPath=%systemroot%\system32\shmgrate.exe OCInstallUserConfigIE
+Outlook Express/>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}
*StubPath=%systemroot%\system32\shmgrate.exe OCInstallUserConfigOE
+Themes Setup/{2C7339CF-2B09-4501-B3F3-F3508C9228ED}
*StubPath=%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll
+Microsoft Outlook Express 6/{44BBA840-CC51-11CF-AAFA-00AA00B6015C}
*StubPath="%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install
+NetMeeting 3.01/{44BBA842-CC51-11CF-AAFA-00AA00B6015B}
*StubPath=rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT
+Windows Messenger 4.7/{5945c046-1e7d-11d1-bc44-00c04fd912be}
*StubPath=rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser
+Microsoft Windows Media Player/{6BF52A52-394A-11d3-B153-00C04F79FAA6}
*StubPath=rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp.inf,PerUserStub
+Carnet d'adresses 6/{7790769C-0471-11d2-AF11-00C04FA35D02}
*StubPath="%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install
+Mise à jour du Bureau Windows/{89820200-ECBD-11cf-8B85-00AA005B4340}
*StubPath=regsvr32.exe /s /n /i:U shell32.dll
+Internet Explorer 6/{89820200-ECBD-11cf-8B85-00AA005B4383}
*StubPath=%SystemRoot%\system32\ie4uinit.exe
»Browser Helper Objects (LM)
*AcroIEHelper.AcroIEHlprObj.1/{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
`InprocServer32=C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
*{53707962-6F74-2D53-2644-206D7942484F}
`InprocServer32=C:\PROGRA~1\SPYBOT~1\SDHelper.dll
*Google Toolbar Helper/{AA58ED58-01DD-4d91-8333-CF10577473F7}
`InprocServer32=c:\program files\google\googletoolbar1.dll
»ShellServiceObjectDelayLoad (LM)
*PostBootReminder={7849596a-48ea-486e-8937-a2a3009f31a9}
`InprocServer32=%SystemRoot%\system32\SHELL32.dll
*CDBurn={fbeb8a05-beee-4442-804e-409d6c4515e9}
`InprocServer32=%SystemRoot%\system32\SHELL32.dll
*WebCheck={E6FB5E20-DE35-11CF-9C87-00AA005127ED}
`InprocServer32=%SystemRoot%\System32\webcheck.dll
*SysTray={35CEC8A3-2BE6-11D2-8773-92E220524153}
`InprocServer32=C:\WINDOWS\System32\stobject.dll
»Special NT Values
»Current User
*Load=
*Run=
*Programs=com exe bat pif cmd
*SHELL=
»Default User
*Load=
*Run=
*Programs=com exe bat pif cmd
*SHELL=
»Local Machine
*AppInit_DLLs=
*SHELL=Explorer.exe
*Userinit=C:\WINDOWS\system32\userinit.exe,
»Files
»Autostart Folders
»Current User
*C:\Documents and Settings\audrey\Menu Démarrer\Programmes\Démarrage\desktop.ini
»Default User
*C:\WINDOWS\system32\config\systemprofile\Menu Démarrer\Programmes\Démarrage\desktop.ini
»Local Machine
*C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\desktop.ini
*C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
*C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\hpoddt01.exe.lnk
*C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\hp psc 1000 series.lnk
*C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk
»INI-Files
»WIN.INI\[windows]
*LOAD=
*RUN=
»SYSTEM.INI\[boot]
*SHELL=Explorer.exe
»Text Files
*C:\boot.ini
`[boot loader]
`timeout=30
`default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
`[operating systems]
`multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn
*C:\msdos.sys
*C:\config.sys
*C:\WINDOWS\system32\config.nt
`dos=high, umb
`device=%SystemRoot%\system32\himem.sys
`files=40
*C:\WINDOWS\system32\drivers\etc\hosts
»Program Files
*C:\ntldr
*C:\ntdetect.com
*C:\io.sys
*C:\WINDOWS\system32\win.com
*C:\WINDOWS\explorer.exe
»System/Drivers
»Running Processes
+0=<idle>
+4=<system>
+320=\SystemRoot\System32\smss.exe
+368=\??\C:\WINDOWS\system32\csrss.exe
+392=\??\C:\WINDOWS\system32\winlogon.exe
+436=C:\WINDOWS\system32\services.exe
+448=C:\WINDOWS\system32\lsass.exe
+592=C:\WINDOWS\system32\svchost.exe
+652=C:\WINDOWS\system32\svchost.exe
+692=C:\WINDOWS\System32\svchost.exe
+740=C:\WINDOWS\System32\svchost.exe
+800=C:\WINDOWS\System32\svchost.exe
+920=C:\WINDOWS\system32\spoolsv.exe
+1016=C:\WINDOWS\Explorer.EXE
+1156=C:\Program Files\QuickTime\qttask.exe
+1208=C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
+1224=C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
+1232=C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
+1256=C:\WINDOWS\system32\ctfmon.exe
+1264=C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
+1272=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
+1404=C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
+1416=C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
+1476=C:\ewido\security suite\ewidoctrl.exe
+1500=C:\Program Files\Fichiers communs\Microsoft Shared\VS7Debug\mdm.exe
+1512=C:\PROGRA~1\AGNITUM\OUTPOS~1.0\outpost.exe
+1600=C:\WINDOWS\system32\spupdsvc.exe
+1716=C:\WINDOWS\System32\svchost.exe
+1740=C:\WINDOWS\System32\wdfmgr.exe
+1912=C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
+1964=C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
+2012=C:\WINDOWS\system32\spnpinst.exe
+304=C:\WINDOWS\system32\Sysocmgr.exe
+496=C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
+976=C:\WINDOWS\System32\HPZipm12.exe
+3248=C:\startdreck\StartDreck.exe
»NT Services
*Avertissement Alerter - disabled
*Service de la passerelle de la couche Applicati ALG - on demand
`on
*Gestion d'applications AppMgmt - on demand
*Audio Windows AudioSrv running auto
*AVG7 Alert Manager Server Avg7Alrt running auto
*AVG7 Update Service Avg7UpdSvc running auto
*Service de transfert intelligent en arrière-pla BITS - on demand
`n
*Explorateur d'ordinateur Browser - auto
*Service d'indexation CiSvc - on demand
*Gestionnaire de l'Album ClipSrv - disabled
*Application système COM+ COMSysApp - on demand
*Services de cryptographie CryptSvc running auto
*Lanceur de processus serveur DCOM DcomLaunch running auto
*Client DHCP Dhcp running auto
*Service d'administration du Gestionnaire de dis dmadmin - on demand
`que logique
*Gestionnaire de disque logique dmserver running auto
*Client DNS Dnscache running auto
*Service de rapport d'erreurs ERSvc - disabled
*Journal des événements Eventlog running auto
*Système d'événements de COM+ EventSystem running on demand
*ewido security suite control ewido security suite running auto
*Compatibilité avec le Changement rapide d'utili FastUserSwitchingCom - on demand
`sateur
*Aide et support helpsvc running auto
*Accès du périphérique d'interface utilisateur HidServ - disabled
*HTTP SSL HTTPFilter - on demand
*Service COM de gravure de CD IMAPI ImapiService - disabled
*Serveur lanmanserver running auto
*Station de travail lanmanworkstation running auto
*Assistance TCP/IP NetBIOS LmHosts running auto
*Machine Debug Manager MDM running auto
*Affichage des messages Messenger - disabled
*Partage de Bureau à distance NetMeeting mnmsrvc - on demand
*Distributed Transaction Coordinator MSDTC - on demand
*Windows Installer MSIServer - on demand
*DDE réseau NetDDE - disabled
*DSDM DDE réseau NetDDEdsdm - disabled
*Ouverture de session réseau Netlogon - on demand
*Connexions réseau Netman running on demand
*NLA (Network Location Awareness) Nla running on demand
*Fournisseur de la prise en charge de sécurité L NtLmSsp - on demand
`M NT
*Stockage amovible NtmsSvc - on demand
*Outpost Firewall Service OutpostFirewall running auto
*Plug-and-Play PlugPlay running auto
*Pml Driver HPZ12 Pml Driver HPZ12 running on demand
*Services IPSEC PolicyAgent running auto
*Emplacement protégé ProtectedStorage running auto
*Gestionnaire de connexion automatique d'accès d RasAuto - on demand
`istant
*Gestionnaire de connexions d'accès distant RasMan running on demand
*Gestionnaire de session d'aide sur le Bureau à RDSessMgr - disabled
`distance
*Routage et accès distant RemoteAccess - disabled
*Accès à distance au Registre RemoteRegistry - disabled
*Localisateur d'appels de procédure distante (RP RpcLocator - disabled
`C)
*Appel de procédure distante (RPC) RpcSs running auto
*QoS RSVP RSVP - on demand
*Gestionnaire de comptes de sécurité SamSs running auto
*Carte à puce SCardSvr - on demand
*Planificateur de tâches Schedule - disabled
*Connexion secondaire seclogon running auto
*Notification d'événement système SENS running auto
*Pare-feu Windows / Partage de connexion Interne SharedAccess - disabled
`t
*Détection matériel noyau ShellHWDetection running auto
*Spouleur d'impression Spooler running auto
*Windows Service Pack Installer update service spupdsvc running auto
*Service de restauration système srservice running auto
*Service de découvertes SSDP SSDPSRV - disabled
*Acquisition d'image Windows (WIA) stisvc running auto
*MS Software Shadow Copy Provider SwPrv - on demand
*Journaux et alertes de performance SysmonLog - on demand
*Téléphonie TapiSrv running on demand
*Services Terminal Server TermService running on demand
*Thèmes Themes running auto
*Telnet TlntSvr - disabled
*Client de suivi de lien distribué TrkWks running auto
*Windows User Mode Driver Framework UMWdf running auto
*Onduleur UPS - on demand
*Cliché instantané de volume VSS - on demand
*Horloge Windows W32Time - disabled
*WebClient WebClient running auto
*Infrastructure de gestion Windows winmgmt running auto
*Service de numéro de série du lecteur multimédi WmdmPmSN - on demand
`a portable
*Extensions du pilote WMI Wmi - on demand
*Carte de performance WMI WmiApSrv - on demand
*Centre de sécurité wscsvc - disabled
*Mises à jour automatiques wuauserv - disabled
*Configuration automatique sans fil WZCSVC - disabled
*Service d'approvisionnement réseau xmlprov - on demand
»Application specific
djolafrite
 
Messages: 13
Inscription: 21 Juil 2005, 00:25

Messagede Vazkor » 14 Aoû 2005, 17:37

Bonjour,

[HS]
Méchant problème d'affichage sur le post précédent (avant division), pour les derniers messages.
La colonne de gauche avec le pseudo est anormalement large et le texte du message est massacré sur la droite.
Et ce avec Firefox et Opera 8.02, donc ce n'est pas le navigateur qui est en cause.

Capture de la moitié droite de mon écran:
Image

Constatez-vous la même chose?

@+
Avatar de l’utilisateur
Vazkor
 
Messages: 9810
Inscription: 05 Nov 2002, 23:39
Localisation: Ans, BE

Messagede djolafrite » 14 Aoû 2005, 18:13

oui...
chez moi le problème d'affichage commence à la réponse de nickW à mes logs hijackthis et ewido
je me demandais si je ne devais pas créer un autre topic traitant de mon problème, pour remédier à ce problème d'affichage, mais je sais combien il est énervant pour vous de traiter des doublons, donc je ne veux pas faire de bétises...

si l'administateur ou un modo pouvait clore le topic, nous pourrions créer un topic jumeau avec un affichage correct.
djolafrite
 
Messages: 13
Inscription: 21 Juil 2005, 00:25

Messagede Vazkor » 14 Aoû 2005, 18:46

Bonsoir,

Cela va mieux maintenant que j'ai divisé le fil de discussion et que j'ai désactivé le BBCode dans le message avec le contenu du fichier Hosts.

@+
Avatar de l’utilisateur
Vazkor
 
Messages: 9810
Inscription: 05 Nov 2002, 23:39
Localisation: Ans, BE

Messagede Vazkor » 14 Aoû 2005, 18:48

Bonsoir,

Nous pouvons la récupérer mais pas à deux en même temps.

@+
Avatar de l’utilisateur
Vazkor
 
Messages: 9810
Inscription: 05 Nov 2002, 23:39
Localisation: Ans, BE

Suivante

Retourner vers Sécurité (Contamination - Décontamination)

Qui est en ligne

Utilisateurs parcourant ce forum: Aucun utilisateur enregistré et 17 invités