Aller au contenu
  • Pas encore inscrit ?

    Pourquoi ne pas vous inscrire ? C'est simple, rapide et gratuit.
    Pour en savoir plus, lisez Les avantages de l'inscription... et la Charte de Zébulon.
    De plus, les messages que vous postez en tant qu'invité restent invisibles tant qu'un modérateur ne les a pas validés. Inscrivez-vous, ce sera un gain de temps pour tout le monde, vous, les helpeurs et les modérateurs ! :wink:

analyse hijackthis


Messages recommandés

Bonjour,

mon ordi poLogfile of Trend Micro HijackThis v2.0.2

Scan saved at 13:58:45, on 19/05/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16827)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe

C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Olivetti\ANY_WAY\olMntrService.exe

C:\WINDOWS\system32\IoctlSvc.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe

C:\Program Files\VistaCodecPack\QT\QTSystem\qttask.exe

C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

C:\Program Files\Microsoft ActiveSync\wcescomm.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\PROGRA~1\MI3AA1~1\rapimgr.exe

C:\Program Files\Hercules\Audio\Gamesurround Muse Pocket\MuseCPL.exe

C:\Program Files\NETGEAR\WPN111\wpn111.exe

C:\Program Files\WinZip\WZQKPICK.EXE

C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr/keyword/%s

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/ie

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aliceadsl.fr

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/ie

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.115.25.129:80

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\Program Files\EoRezo\EoAdv\EoRezoBHO.dll

O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb127\Dealio.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb127\SearchSettings.dll

O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\styler\TB\StylerTB.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll

O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe

O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\VistaCodecPack\QT\QTSystem\qttask.exe" -atboottime

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

O4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020

O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot

O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

O4 - Global Startup: Gamesurround Muse Pocket.lnk = C:\Program Files\Hercules\Audio\Gamesurround Muse Pocket\MuseCPL.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\Administrateur\Application Data\Dealio\kb127\res\DealioSearch.html

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000

O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll

O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll

O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: olMntrService - Olivetti - C:\Program Files\Olivetti\ANY_WAY\olMntrService.exe

O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe

 

--

End of file - 9831 bytes

rtable rame. Voici le log hijackthis. Que puis je faire?

Modifié par shogun133x
Lien vers le commentaire
Partager sur d’autres sites

Bonjour,

 

Te revoilà déjà? Ok c'est un autre ordi.

 

Tu devrais désinstaller Spybot S&D car ça fait ramer les pc et ça ne vaut plus rien du tout.

Ne le désinstalle pas n'importe comment, je te dis ça plus loin.

 

Désinstalle SearchSettings par ajouter/supprimer des programmes.

 

Désactive le teatimer de Spybot en passant par les options de Spybot: une fois dans le logiciel, il faut aller dans le menu "Mode" => coche "Mode avancé" => "Outils"(en bas de page)=> "Résident" => et tu décoches cette case: "Résident Teatimer" . Tu ne dois plus voir l'icône du Teatimer dans la barre de tâches!

Ne fais pas l'impasse sur cette étape, car ca peut faire échouer la procédure de désinfection !

 

flechedroitets2.pngOTMOVEIT 3

 

Télécharge systemsr4.pngOTMoveIt3 de OldTimer sur ton Bureau en cliquant sur ce lien:

 

OtMoveIt3

 

  • Double-clique sur OTMoveIt3.exe pour le lancer (l'extension .exe peut ne pas apparaître)
     
    ---> sous VISTA: clic droit: exécuter en temps qu'administrateur.
     
    Vérifie que la case Unregister Dll's and OCX's.exe est bien cochée!
     
  • Copie l'entièreté du code ci-dessous (depuis :Processes)
    :Processes
    
    explorer.exe
    
    :Files
    c:\program files\search settings
    c:\program files\eorezo
    
    
    :Reg
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks]
    "{E312764E-7706-43F1-8DAB-FCDD2B1E416D}"=-
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]


     

  • Colle ce code dans la partie jaune de OtMoveIt3 intitulée:
    "Paste Instructions for Items to be Moved" img-025804xb055.png
     
  • Clique sur le bouton Moveit! pour lancer le nettoyage: img-025919bxiq4.png
     
  • Copie-colle dans ta prochaine réponse tout ce qui se trouve dans la fenêtre Results img-030027q93ue.png
    --> Un rapport sera généré dans le dossier C:\ _OTMoveIt\MovedFiles avec la date et l'heure du passage de l'outil (mmddyyyy_hhmmss.log)
  • Ferme OTMoveIt3 en cliquant sur Exit: img-030110c5gvf.png

Note : Si un fichier ou un dossier ne peut être supprimé directement, l'outil peut demander un redémarrage pour terminer le processus. Clique alors sur "Yes" pour accepter.

 

Le pc doit redémarrer; s'il ne le fait pas tout seul, fais-le toi-même.

 

Après le reboot, poste le rapport OTMoveiT ainsi qu'un nouveau log Hijackthis.

 

@+

 

PS: je te conseille d'installer un Windows complet car cette "version allégée" pourrait te poser des problèmes vu tous les composants manquants. :P

Modifié par Apollo
Lien vers le commentaire
Partager sur d’autres sites

Tu as un problème?

Lien vers le commentaire
Partager sur d’autres sites

Voila:

========== PROCESSES ==========

Process explorer.exe killed successfully.

========== FILES ==========

File/Folder c:\program files\search settings not found.

c:\program files\EoRezo\lang moved successfully.

c:\program files\EoRezo\EoAdv moved successfully.

c:\program files\EoRezo moved successfully.

========== REGISTRY ==========

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}\\ deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\\ not found.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}\\ not found.

========== COMMANDS ==========

File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IadHide4.dll scheduled to be deleted on reboot.

File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WCESLog.log scheduled to be deleted on reboot.

User's Temp folder emptied.

User's Internet Explorer cache folder emptied.

File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\V980MMEB\ban_728x90[1].htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\OK4VMDU2\analyse-hijackthis-t163276[1].htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\OK4VMDU2\Generic[1].htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\OK4VMDU2\hp[1].htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\OK4VMDU2\iframe[1].htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\5QX0OPOP\057ACAFV2VNPCAYIA8UECA191BNUCA0YTQFNCA4NSUG7CA4X5YUPCAXKTFSCCAHUM0AVCAKCNEUGC

AOX6I4LCA27QOMNCA9KDUB3CAK8WA42CA0QHZHDCAZ3WQS8CA23W6G8CANHKAA3CA9RUOBY.htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\5QX0OPOP\rectangle_300x250[1].htm scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.

File delete failed. C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.

User's Temporary Internet Files folder emptied.

Local Service Temp folder emptied.

Local Service Temporary Internet Files folder emptied.

Network Service Temp folder emptied.

Network Service Temporary Internet Files folder emptied.

Windows Temp folder emptied.

Temp folders emptied.

Explorer started successfully

 

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 05192009_144233

 

Files moved on Reboot...

DllUnregisterServer procedure not found in C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IadHide4.dll

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IadHide4.dll NOT unregistered.

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\IadHide4.dll moved successfully.

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WCESLog.log moved successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\V980MMEB\ban_728x90[1].htm moved successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\OK4VMDU2\analyse-hijackthis-t163276[1].htm moved successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\OK4VMDU2\Generic[1].htm moved successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\OK4VMDU2\hp[1].htm moved successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\OK4VMDU2\iframe[1].htm moved successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\5QX0OPOP\057ACAFV2VNPCAYIA8UECA191BNUCA0YTQFNCA4NSUG7CA4X5YUPCAXKTFSCCAHUM0AVCAKCNEUGC

AOX6I4LCA27QOMNCA9KDUB3CAK8WA42CA0QHZHDCAZ3WQS8CA23W6G8CANHKAA3CA9RUOBY.htm moved successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5\5QX0OPOP\rectangle_300x250[1].htm moved successfully.

C:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat moved successfully.

 

 

 

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 14:59:30, on 19/05/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16827)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\notepad.exe

C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe

C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Olivetti\ANY_WAY\olMntrService.exe

C:\WINDOWS\system32\IoctlSvc.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe

C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe

C:\Program Files\VistaCodecPack\QT\QTSystem\qttask.exe

C:\Program Files\Microsoft ActiveSync\wcescomm.exe

C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

C:\WINDOWS\system32\ctfmon.exe

C:\PROGRA~1\MI3AA1~1\rapimgr.exe

C:\Program Files\Hercules\Audio\Gamesurround Muse Pocket\MuseCPL.exe

C:\Program Files\NETGEAR\WPN111\wpn111.exe

C:\Program Files\WinZip\WZQKPICK.EXE

C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr/keyword/%s

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/ie

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aliceadsl.fr

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.fr

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/ie

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.115.25.129:80

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb127\Dealio.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\styler\TB\StylerTB.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll

O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe

O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\VistaCodecPack\QT\QTSystem\qttask.exe" -atboottime

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

O4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020

O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot

O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

O4 - Global Startup: Gamesurround Muse Pocket.lnk = C:\Program Files\Hercules\Audio\Gamesurround Muse Pocket\MuseCPL.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\Administrateur\Application Data\Dealio\kb127\res\DealioSearch.html

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000

O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll

O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll

O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: olMntrService - Olivetti - C:\Program Files\Olivetti\ANY_WAY\olMntrService.exe

O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe

 

--

End of file - 9383 bytes

 

Je sais j'ai été long mais l'ordi rame vraiment

Lien vers le commentaire
Partager sur d’autres sites

Désinstalle Spybot S&D mais:

Tu dois retirer les vaccinations faites dans Spybot avant de le désinstaller.

 

supprimevaccinationspybot.jpg

 

===============

Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.

 

  • Lance l'installation du programme en exécutant le fichier téléchargé.
  • Double-clique sur le raccourci de Toolbar-S&D.
  • --> Sous VISTA: clic droit Exécuter en temps qu'administrateur.
  • Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
  • Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
    Poste le rapport généré. (C:\TB.txt)

 

@++

Lien vers le commentaire
Partager sur d’autres sites

-----------\\ ToolBar S&D 1.2.8 XP/Vista

 

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3

X86-based PC ( Uniprocessor Free : AMD Athlon XP Processor 2800+ )

BIOS : Ver 1.00PARTTBL

USER : Administrateur ( Administrator )

BOOT : Normal boot

C:\ (Local Disk) - NTFS - Total:37 Go (Free:21 Go)

D:\ (CD or DVD)

 

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )

Option : [1] ( 19/05/2009|15:17 )

 

-----------\\ Recherche de Fichiers / Dossiers ...

 

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\alerts.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\alerts_over.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\alerts_rec.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\alerts_rec_over.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\chevron-small.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\DealioSearch.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\deals-leftcap.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\deal_report.jpg

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\ebay_login.jpg

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\err_mainwindow.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\err_toolbar.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\global_scripts.js

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\headerbgthin.jpg

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\highlight-bg.png

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\logo.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\logo_over.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\man_toolbar.css

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\man_toolbar.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\man_toolbar.js

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\man_toolbarl.js

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\post-this-deal.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\post-this-deal_over.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\scripts.js

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\scroller.js

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\search-chevron.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\search-chevron_over.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\search_bg_blink.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\separator.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\settings.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\settings_over.gif

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\res\yahoo-search.png

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\index.76.35

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.10.76

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.109.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.110.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.12.52

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.13.58

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.130.58

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.135.50

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.153.44

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.155.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.156.49

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.16.60

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.161.52

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.178.66

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.184.55

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.188.52

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.189.45

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.196.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.198.56

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.199.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.200.53

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.201.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.202.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.203.71

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.205.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.213.71

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.214.49

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.215.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.216.67

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.217.67

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.218.52

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.219.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.220.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.221.57

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.222.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.223.68

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.226.68

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.227.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.228.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.229.76

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.23.63

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.239.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.24.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.240.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.241.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.242.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.243.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.244.63

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.245.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.247.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.248.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.249.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.250.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.251.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.252.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.253.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.254.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.255.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.256.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.257.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.279.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.28.58

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.282.75

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.283.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.284.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.289.67

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.290.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.291.61

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.296.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.297.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.304.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.307.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.308.75

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.31.47

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.310.46

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.311.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.315.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.316.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.317.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.318.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.319.49

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.32.48

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.334.44

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.335.60

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.336.44

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.337.44

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.338.75

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.339.47

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.34.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.340.47

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.341.47

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.349.50

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.35.48

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.350.50

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.351.51

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.352.54

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.353.51

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.354.51

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.357.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.358.52

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.359.52

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.360.53

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.361.54

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.362.68

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.363.58

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.364.54

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.365.53

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.367.56

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.368.58

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.369.55

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.370.56

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.371.56

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.372.57

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.373.55

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.375.56

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.376.57

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.377.55

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.378.65

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.384.58

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.386.71

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.387.59

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.388.59

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.389.59

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.390.60

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.391.60

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.392.60

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.393.60

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.394.60

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.396.61

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.397.61

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.398.60

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.399.60

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.403.61

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.404.63

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.405.61

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.406.61

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.407.76

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.408.63

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.409.61

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.412.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.413.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.414.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.415.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.416.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.417.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.418.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.419.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.420.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.421.62

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.423.63

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.424.63

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.425.63

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.426.63

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.427.63

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.428.65

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.429.63

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.430.63

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.432.65

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.433.64

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.434.65

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.435.64

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.436.76

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.437.64

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.438.71

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.439.71

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.440.75

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.442.73

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.443.73

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.444.73

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.445.68

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.446.69

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.450.67

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.451.67

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.452.68

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.453.68

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.454.69

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.456.69

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.457.75

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.458.70

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.459.70

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.460.69

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.462.74

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.463.69

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.464.70

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.465.68

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.468.70

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.469.70

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.470.70

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.471.73

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.472.70

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.478.74

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.479.73

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.480.68

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.481.71

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.482.74

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.49.67

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.50.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.500.71

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.501.74

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.502.71

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.51.69

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.52.72

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.520.76

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.521.76

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.522.76

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.53.51

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.531.76

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.532.75

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.534.75

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.54.47

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.55.45

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.56.69

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.57.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.58.47

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.593.76

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.595.76

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.63.57

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.66.47

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.70.75

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\rules\rules.1.71.43

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\dealio-14383.log

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\dod_cache.xml

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_1260_484_2.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_160_1236_3.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_160_2232_9.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_1696_2896_5.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_1696_3152_1.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_1696_3152_3.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_3084_3964_1.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_3084_3964_2.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_3112_2596_8.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_3844_1816_6.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_3844_3168_3.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_3884_2304_6.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_3884_3148_3.html

C:\DOCUME~1\ADMINI~1\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_3884_676_9.html

C:\Program Files\Dealio

C:\Program Files\Dealio\DealioAU.exe

C:\Program Files\Dealio\kb127

C:\Program Files\Dealio\SearchSettingsKit.exe

C:\Program Files\Dealio\kb127\Dealio Deskbar.exe

C:\Program Files\Dealio\kb127\Dealio.dll

C:\Program Files\Dealio\kb127\DealioRes409.dll

C:\Program Files\Dealio\kb127\res

C:\Program Files\Dealio\kb127\resDN

C:\Program Files\Dealio\kb127\rules

C:\Program Files\Dealio\kb127\temp

C:\Program Files\Dealio\kb127\res\alerts.gif

C:\Program Files\Dealio\kb127\res\alerts_over.gif

C:\Program Files\Dealio\kb127\res\alerts_rec.gif

C:\Program Files\Dealio\kb127\res\alerts_rec_over.gif

C:\Program Files\Dealio\kb127\res\chevron-small.gif

C:\Program Files\Dealio\kb127\res\DealioSearch.html

C:\Program Files\Dealio\kb127\res\deals-leftcap.gif

C:\Program Files\Dealio\kb127\res\deal_report.jpg

C:\Program Files\Dealio\kb127\res\ebay_login.jpg

C:\Program Files\Dealio\kb127\res\err_mainwindow.html

C:\Program Files\Dealio\kb127\res\err_toolbar.html

C:\Program Files\Dealio\kb127\res\global_scripts.js

C:\Program Files\Dealio\kb127\res\headerbgthin.jpg

C:\Program Files\Dealio\kb127\res\highlight-bg.png

C:\Program Files\Dealio\kb127\res\logo.gif

C:\Program Files\Dealio\kb127\res\logo_over.gif

C:\Program Files\Dealio\kb127\res\man_toolbar.css

C:\Program Files\Dealio\kb127\res\man_toolbar.html

C:\Program Files\Dealio\kb127\res\man_toolbar.js

C:\Program Files\Dealio\kb127\res\man_toolbarl.js

C:\Program Files\Dealio\kb127\res\post-this-deal.gif

C:\Program Files\Dealio\kb127\res\post-this-deal_over.gif

C:\Program Files\Dealio\kb127\res\scripts.js

C:\Program Files\Dealio\kb127\res\scroller.js

C:\Program Files\Dealio\kb127\res\search-chevron.gif

C:\Program Files\Dealio\kb127\res\search-chevron_over.gif

C:\Program Files\Dealio\kb127\res\search_bg_blink.gif

C:\Program Files\Dealio\kb127\res\separator.gif

C:\Program Files\Dealio\kb127\res\settings.gif

C:\Program Files\Dealio\kb127\res\settings_over.gif

C:\Program Files\Dealio\kb127\res\yahoo-search.png

C:\Program Files\Dealio\kb127\resDN\bottom.gif

C:\Program Files\Dealio\kb127\resDN\chevron_down.gif

C:\Program Files\Dealio\kb127\resDN\chevron_up.gif

C:\Program Files\Dealio\kb127\resDN\close.gif

C:\Program Files\Dealio\kb127\resDN\deskbar.css

C:\Program Files\Dealio\kb127\resDN\deskbar.js

C:\Program Files\Dealio\kb127\resDN\dispatch_helper.js

C:\Program Files\Dealio\kb127\resDN\ebay_compatible.jpg

C:\Program Files\Dealio\kb127\resDN\logo.gif

C:\Program Files\Dealio\kb127\resDN\logo_chevron_bkg.gif

C:\Program Files\Dealio\kb127\resDN\losing.gif

C:\Program Files\Dealio\kb127\resDN\lost.gif

C:\Program Files\Dealio\kb127\resDN\man_deskbar.html

C:\Program Files\Dealio\kb127\resDN\menu_arrow.gif

C:\Program Files\Dealio\kb127\resDN\menu_check.gif

C:\Program Files\Dealio\kb127\resDN\no_image.gif

C:\Program Files\Dealio\kb127\resDN\prod_img.gif

C:\Program Files\Dealio\kb127\resDN\search_chevron.gif

C:\Program Files\Dealio\kb127\resDN\spacer.gif

C:\Program Files\Dealio\kb127\resDN\textfield_bkg.gif

C:\Program Files\Dealio\kb127\resDN\top.gif

C:\Program Files\Dealio\kb127\resDN\unknown.gif

C:\Program Files\Dealio\kb127\resDN\winning.gif

C:\Program Files\Dealio\kb127\resDN\won.gif

C:\Program Files\Dealio\kb127\rules\index.76.35

C:\Program Files\Dealio\kb127\rules\rules.1.10.76

C:\Program Files\Dealio\kb127\rules\rules.1.109.43

C:\Program Files\Dealio\kb127\rules\rules.1.110.43

C:\Program Files\Dealio\kb127\rules\rules.1.12.52

C:\Program Files\Dealio\kb127\rules\rules.1.13.58

C:\Program Files\Dealio\kb127\rules\rules.1.130.58

C:\Program Files\Dealio\kb127\rules\rules.1.135.50

C:\Program Files\Dealio\kb127\rules\rules.1.153.44

C:\Program Files\Dealio\kb127\rules\rules.1.155.43

C:\Program Files\Dealio\kb127\rules\rules.1.156.49

C:\Program Files\Dealio\kb127\rules\rules.1.16.60

C:\Program Files\Dealio\kb127\rules\rules.1.161.52

C:\Program Files\Dealio\kb127\rules\rules.1.178.66

C:\Program Files\Dealio\kb127\rules\rules.1.184.55

C:\Program Files\Dealio\kb127\rules\rules.1.188.52

C:\Program Files\Dealio\kb127\rules\rules.1.189.45

C:\Program Files\Dealio\kb127\rules\rules.1.196.43

C:\Program Files\Dealio\kb127\rules\rules.1.198.56

C:\Program Files\Dealio\kb127\rules\rules.1.199.43

C:\Program Files\Dealio\kb127\rules\rules.1.200.53

C:\Program Files\Dealio\kb127\rules\rules.1.201.43

C:\Program Files\Dealio\kb127\rules\rules.1.202.43

C:\Program Files\Dealio\kb127\rules\rules.1.203.71

C:\Program Files\Dealio\kb127\rules\rules.1.205.62

C:\Program Files\Dealio\kb127\rules\rules.1.213.71

C:\Program Files\Dealio\kb127\rules\rules.1.214.49

C:\Program Files\Dealio\kb127\rules\rules.1.215.43

C:\Program Files\Dealio\kb127\rules\rules.1.216.67

C:\Program Files\Dealio\kb127\rules\rules.1.217.67

C:\Program Files\Dealio\kb127\rules\rules.1.218.52

C:\Program Files\Dealio\kb127\rules\rules.1.219.43

C:\Program Files\Dealio\kb127\rules\rules.1.220.43

C:\Program Files\Dealio\kb127\rules\rules.1.221.57

C:\Program Files\Dealio\kb127\rules\rules.1.222.43

C:\Program Files\Dealio\kb127\rules\rules.1.223.68

C:\Program Files\Dealio\kb127\rules\rules.1.226.68

C:\Program Files\Dealio\kb127\rules\rules.1.227.43

C:\Program Files\Dealio\kb127\rules\rules.1.228.62

C:\Program Files\Dealio\kb127\rules\rules.1.229.76

C:\Program Files\Dealio\kb127\rules\rules.1.23.63

C:\Program Files\Dealio\kb127\rules\rules.1.239.43

C:\Program Files\Dealio\kb127\rules\rules.1.24.43

C:\Program Files\Dealio\kb127\rules\rules.1.240.43

C:\Program Files\Dealio\kb127\rules\rules.1.241.43

C:\Program Files\Dealio\kb127\rules\rules.1.242.43

C:\Program Files\Dealio\kb127\rules\rules.1.243.43

C:\Program Files\Dealio\kb127\rules\rules.1.244.63

C:\Program Files\Dealio\kb127\rules\rules.1.245.43

C:\Program Files\Dealio\kb127\rules\rules.1.247.43

C:\Program Files\Dealio\kb127\rules\rules.1.248.43

C:\Program Files\Dealio\kb127\rules\rules.1.249.43

C:\Program Files\Dealio\kb127\rules\rules.1.250.43

C:\Program Files\Dealio\kb127\rules\rules.1.251.43

C:\Program Files\Dealio\kb127\rules\rules.1.252.43

C:\Program Files\Dealio\kb127\rules\rules.1.253.43

C:\Program Files\Dealio\kb127\rules\rules.1.254.43

C:\Program Files\Dealio\kb127\rules\rules.1.255.43

C:\Program Files\Dealio\kb127\rules\rules.1.256.43

C:\Program Files\Dealio\kb127\rules\rules.1.257.43

C:\Program Files\Dealio\kb127\rules\rules.1.279.43

C:\Program Files\Dealio\kb127\rules\rules.1.28.58

C:\Program Files\Dealio\kb127\rules\rules.1.282.75

C:\Program Files\Dealio\kb127\rules\rules.1.283.43

C:\Program Files\Dealio\kb127\rules\rules.1.284.43

C:\Program Files\Dealio\kb127\rules\rules.1.289.67

C:\Program Files\Dealio\kb127\rules\rules.1.290.62

C:\Program Files\Dealio\kb127\rules\rules.1.291.61

C:\Program Files\Dealio\kb127\rules\rules.1.296.43

C:\Program Files\Dealio\kb127\rules\rules.1.297.43

C:\Program Files\Dealio\kb127\rules\rules.1.304.43

C:\Program Files\Dealio\kb127\rules\rules.1.307.43

C:\Program Files\Dealio\kb127\rules\rules.1.308.75

C:\Program Files\Dealio\kb127\rules\rules.1.31.47

C:\Program Files\Dealio\kb127\rules\rules.1.310.46

C:\Program Files\Dealio\kb127\rules\rules.1.311.43

C:\Program Files\Dealio\kb127\rules\rules.1.315.43

C:\Program Files\Dealio\kb127\rules\rules.1.316.43

C:\Program Files\Dealio\kb127\rules\rules.1.317.43

C:\Program Files\Dealio\kb127\rules\rules.1.318.43

C:\Program Files\Dealio\kb127\rules\rules.1.319.49

C:\Program Files\Dealio\kb127\rules\rules.1.32.48

C:\Program Files\Dealio\kb127\rules\rules.1.334.44

C:\Program Files\Dealio\kb127\rules\rules.1.335.60

C:\Program Files\Dealio\kb127\rules\rules.1.336.44

C:\Program Files\Dealio\kb127\rules\rules.1.337.44

C:\Program Files\Dealio\kb127\rules\rules.1.338.75

C:\Program Files\Dealio\kb127\rules\rules.1.339.47

C:\Program Files\Dealio\kb127\rules\rules.1.34.43

C:\Program Files\Dealio\kb127\rules\rules.1.340.47

C:\Program Files\Dealio\kb127\rules\rules.1.341.47

C:\Program Files\Dealio\kb127\rules\rules.1.349.50

C:\Program Files\Dealio\kb127\rules\rules.1.35.48

C:\Program Files\Dealio\kb127\rules\rules.1.350.50

C:\Program Files\Dealio\kb127\rules\rules.1.351.51

C:\Program Files\Dealio\kb127\rules\rules.1.352.54

C:\Program Files\Dealio\kb127\rules\rules.1.353.51

C:\Program Files\Dealio\kb127\rules\rules.1.354.51

C:\Program Files\Dealio\kb127\rules\rules.1.357.62

C:\Program Files\Dealio\kb127\rules\rules.1.358.52

C:\Program Files\Dealio\kb127\rules\rules.1.359.52

C:\Program Files\Dealio\kb127\rules\rules.1.360.53

C:\Program Files\Dealio\kb127\rules\rules.1.361.54

C:\Program Files\Dealio\kb127\rules\rules.1.362.68

C:\Program Files\Dealio\kb127\rules\rules.1.363.58

C:\Program Files\Dealio\kb127\rules\rules.1.364.54

C:\Program Files\Dealio\kb127\rules\rules.1.365.53

C:\Program Files\Dealio\kb127\rules\rules.1.367.56

C:\Program Files\Dealio\kb127\rules\rules.1.368.58

C:\Program Files\Dealio\kb127\rules\rules.1.369.55

C:\Program Files\Dealio\kb127\rules\rules.1.370.56

C:\Program Files\Dealio\kb127\rules\rules.1.371.56

C:\Program Files\Dealio\kb127\rules\rules.1.372.57

C:\Program Files\Dealio\kb127\rules\rules.1.373.55

C:\Program Files\Dealio\kb127\rules\rules.1.375.56

C:\Program Files\Dealio\kb127\rules\rules.1.376.57

C:\Program Files\Dealio\kb127\rules\rules.1.377.55

C:\Program Files\Dealio\kb127\rules\rules.1.378.65

C:\Program Files\Dealio\kb127\rules\rules.1.384.58

C:\Program Files\Dealio\kb127\rules\rules.1.386.71

C:\Program Files\Dealio\kb127\rules\rules.1.387.59

C:\Program Files\Dealio\kb127\rules\rules.1.388.59

C:\Program Files\Dealio\kb127\rules\rules.1.389.59

C:\Program Files\Dealio\kb127\rules\rules.1.390.60

C:\Program Files\Dealio\kb127\rules\rules.1.391.60

C:\Program Files\Dealio\kb127\rules\rules.1.392.60

C:\Program Files\Dealio\kb127\rules\rules.1.393.60

C:\Program Files\Dealio\kb127\rules\rules.1.394.60

C:\Program Files\Dealio\kb127\rules\rules.1.396.61

C:\Program Files\Dealio\kb127\rules\rules.1.397.61

C:\Program Files\Dealio\kb127\rules\rules.1.398.60

C:\Program Files\Dealio\kb127\rules\rules.1.399.60

C:\Program Files\Dealio\kb127\rules\rules.1.403.61

C:\Program Files\Dealio\kb127\rules\rules.1.404.63

C:\Program Files\Dealio\kb127\rules\rules.1.405.61

C:\Program Files\Dealio\kb127\rules\rules.1.406.61

C:\Program Files\Dealio\kb127\rules\rules.1.407.76

C:\Program Files\Dealio\kb127\rules\rules.1.408.63

C:\Program Files\Dealio\kb127\rules\rules.1.409.61

C:\Program Files\Dealio\kb127\rules\rules.1.412.62

C:\Program Files\Dealio\kb127\rules\rules.1.413.62

C:\Program Files\Dealio\kb127\rules\rules.1.414.62

C:\Program Files\Dealio\kb127\rules\rules.1.415.62

C:\Program Files\Dealio\kb127\rules\rules.1.416.62

C:\Program Files\Dealio\kb127\rules\rules.1.417.62

C:\Program Files\Dealio\kb127\rules\rules.1.418.62

C:\Program Files\Dealio\kb127\rules\rules.1.419.62

C:\Program Files\Dealio\kb127\rules\rules.1.420.62

C:\Program Files\Dealio\kb127\rules\rules.1.421.62

C:\Program Files\Dealio\kb127\rules\rules.1.423.63

C:\Program Files\Dealio\kb127\rules\rules.1.424.63

C:\Program Files\Dealio\kb127\rules\rules.1.425.63

C:\Program Files\Dealio\kb127\rules\rules.1.426.63

C:\Program Files\Dealio\kb127\rules\rules.1.427.63

C:\Program Files\Dealio\kb127\rules\rules.1.428.65

C:\Program Files\Dealio\kb127\rules\rules.1.429.63

C:\Program Files\Dealio\kb127\rules\rules.1.430.63

C:\Program Files\Dealio\kb127\rules\rules.1.432.65

C:\Program Files\Dealio\kb127\rules\rules.1.433.64

C:\Program Files\Dealio\kb127\rules\rules.1.434.65

C:\Program Files\Dealio\kb127\rules\rules.1.435.64

C:\Program Files\Dealio\kb127\rules\rules.1.436.76

C:\Program Files\Dealio\kb127\rules\rules.1.437.64

C:\Program Files\Dealio\kb127\rules\rules.1.438.71

C:\Program Files\Dealio\kb127\rules\rules.1.439.71

C:\Program Files\Dealio\kb127\rules\rules.1.440.75

C:\Program Files\Dealio\kb127\rules\rules.1.442.73

C:\Program Files\Dealio\kb127\rules\rules.1.443.73

C:\Program Files\Dealio\kb127\rules\rules.1.444.73

C:\Program Files\Dealio\kb127\rules\rules.1.445.68

C:\Program Files\Dealio\kb127\rules\rules.1.446.69

C:\Program Files\Dealio\kb127\rules\rules.1.450.67

C:\Program Files\Dealio\kb127\rules\rules.1.451.67

C:\Program Files\Dealio\kb127\rules\rules.1.452.68

C:\Program Files\Dealio\kb127\rules\rules.1.453.68

C:\Program Files\Dealio\kb127\rules\rules.1.454.69

C:\Program Files\Dealio\kb127\rules\rules.1.456.69

C:\Program Files\Dealio\kb127\rules\rules.1.457.75

C:\Program Files\Dealio\kb127\rules\rules.1.458.70

C:\Program Files\Dealio\kb127\rules\rules.1.459.70

C:\Program Files\Dealio\kb127\rules\rules.1.460.69

C:\Program Files\Dealio\kb127\rules\rules.1.462.74

C:\Program Files\Dealio\kb127\rules\rules.1.463.69

C:\Program Files\Dealio\kb127\rules\rules.1.464.70

C:\Program Files\Dealio\kb127\rules\rules.1.465.68

C:\Program Files\Dealio\kb127\rules\rules.1.468.70

C:\Program Files\Dealio\kb127\rules\rules.1.469.70

C:\Program Files\Dealio\kb127\rules\rules.1.470.70

C:\Program Files\Dealio\kb127\rules\rules.1.471.73

C:\Program Files\Dealio\kb127\rules\rules.1.472.70

C:\Program Files\Dealio\kb127\rules\rules.1.478.74

C:\Program Files\Dealio\kb127\rules\rules.1.479.73

C:\Program Files\Dealio\kb127\rules\rules.1.480.68

C:\Program Files\Dealio\kb127\rules\rules.1.481.71

C:\Program Files\Dealio\kb127\rules\rules.1.482.74

C:\Program Files\Dealio\kb127\rules\rules.1.49.67

C:\Program Files\Dealio\kb127\rules\rules.1.50.43

C:\Program Files\Dealio\kb127\rules\rules.1.500.71

C:\Program Files\Dealio\kb127\rules\rules.1.501.74

C:\Program Files\Dealio\kb127\rules\rules.1.502.71

C:\Program Files\Dealio\kb127\rules\rules.1.51.69

C:\Program Files\Dealio\kb127\rules\rules.1.52.72

C:\Program Files\Dealio\kb127\rules\rules.1.520.76

C:\Program Files\Dealio\kb127\rules\rules.1.521.76

C:\Program Files\Dealio\kb127\rules\rules.1.522.76

C:\Program Files\Dealio\kb127\rules\rules.1.53.51

C:\Program Files\Dealio\kb127\rules\rules.1.531.76

C:\Program Files\Dealio\kb127\rules\rules.1.532.75

C:\Program Files\Dealio\kb127\rules\rules.1.534.75

C:\Program Files\Dealio\kb127\rules\rules.1.54.47

C:\Program Files\Dealio\kb127\rules\rules.1.55.45

C:\Program Files\Dealio\kb127\rules\rules.1.56.69

C:\Program Files\Dealio\kb127\rules\rules.1.57.43

C:\Program Files\Dealio\kb127\rules\rules.1.58.47

C:\Program Files\Dealio\kb127\rules\rules.1.593.76

C:\Program Files\Dealio\kb127\rules\rules.1.595.76

C:\Program Files\Dealio\kb127\rules\rules.1.63.57

C:\Program Files\Dealio\kb127\rules\rules.1.66.47

C:\Program Files\Dealio\kb127\rules\rules.1.70.75

C:\Program Files\Dealio\kb127\rules\rules.1.71.43

C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Dealio

 

-----------\\ Extensions

 

(Administrateur) - {c4dc572a-3295-40eb-b30f-b54aa4cdc4b7} => wmlbrowser

 

 

-----------\\ [..\Internet Explorer\Main]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Search Page"="http://www.google.fr"'>http://www.google.fr"'>http://www.google.fr"'>http://www.google.fr"'>http://www.google.fr"

"Search Bar"="http://www.google.fr/ie"

"Start Page"="http://www.aliceadsl.fr"

"Default_Search_URL"="http://www.google.fr/keyword/%s"

"Local Page"="C:\\WINDOWS\\system32\\blank.htm"

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]

"Default_Page_URL"="http://www.google.fr"

"Default_Search_URL"="http://www.google.fr"

"Search Page"="http://www.google.fr"

"Start Page"="http://www.google.fr"

 

 

--------------------\\ Recherche d'autres infections

 

--------------------\\ Cracks & Keygens ..

 

C:\DOCUME~1\ADMINI~1\Mes documents\Keygen WinZip 11.1 International.exe

 

 

 

1 - "C:\ToolBar SD\TB_1.txt" - 19/05/2009|15:18 - Option : [1]

 

-----------\\ Fin du rapport a 15:18:52,31

Lien vers le commentaire
Partager sur d’autres sites

Vire ça puis vide la corbeille:

 

Tu veux choper Virut? Eloigne-toi des cracks, c'est dangereux; tu as l'équivalent en gratuit avec 7Zip:

 

C:\DOCUME~1\ADMINI~1\Mes documents\Keygen WinZip 11.1 International.exe

 

http://www.7-zip.org/

 

*

Relance Toolbar-S&D en double-cliquant sur le raccourci. Tape sur "2" puis valide en appuyant sur "Entrée".

 

--> Sous VISTA: clic droit Exécuter en temps qu'administrateur.

Ne ferme pas la fenêtre lors de la suppression !

Un rapport sera généré, poste son contenu dans ta réponse.

 

NB: Si ton Bureau ne réapparaissait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.

Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."

Tape explorer puis valide.

 

** Poste également un nouveau log Hijackthis après stp :P

 

@++

Lien vers le commentaire
Partager sur d’autres sites

-----------\\ ToolBar S&D 1.2.8 XP/Vista

 

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 3

X86-based PC ( Uniprocessor Free : AMD Athlon XP Processor 2800+ )

BIOS : Ver 1.00PARTTBL

USER : Administrateur ( Administrator )

BOOT : Normal boot

Antivirus : AntiVir Desktop 9.0.1.26 (Activated)

C:\ (Local Disk) - NTFS - Total:37 Go (Free:21 Go)

D:\ (CD or DVD)

 

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )

Option : [2] ( 19/05/2009|15:56 )

 

-----------\\ Recherche de Fichiers / Dossiers ...

 

 

-----------\\ Extensions

 

(Administrateur) - {c4dc572a-3295-40eb-b30f-b54aa4cdc4b7} => wmlbrowser

 

 

-----------\\ [..\Internet Explorer\Main]

 

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]

"Search Page"="http://www.google.fr"'>http://www.google.fr"'>http://www.google.fr"'>http://www.google.fr"

"Search Bar"="http://www.google.fr/ie"

"Start Page"="http://www.aliceadsl.fr"

"Default_Search_URL"="http://www.google.fr/keyword/%s"

"Local Page"="C:\\WINDOWS\\system32\\blank.htm"

 

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]

"Default_Page_URL"="http://www.google.fr"

"Default_Search_URL"="http://www.google.fr"

"Search Page"="http://www.google.fr"

"Start Page"="http://www.msn.com/"

 

 

--------------------\\ Recherche d'autres infections

 

 

Aucune autre infection trouvée !

 

 

1 - "C:\ToolBar SD\TB_1.txt" - 19/05/2009|15:18 - Option : [1]

2 - "C:\ToolBar SD\TB_2.txt" - 19/05/2009|15:44 - Option : [2]

3 - "C:\ToolBar SD\TB_3.txt" - 19/05/2009|15:59 - Option : [2]

 

-----------\\ Fin du rapport a 15:59:31,98

 

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 16:05:45, on 19/05/2009

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16827)

Boot mode: Normal

 

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Windows Defender\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\mdm.exe

C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

C:\WINDOWS\system32\nvsvc32.exe

C:\Program Files\Olivetti\ANY_WAY\olMntrService.exe

C:\WINDOWS\system32\IoctlSvc.exe

C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe

C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe

C:\Program Files\VistaCodecPack\QT\QTSystem\qttask.exe

C:\Program Files\Microsoft ActiveSync\wcescomm.exe

C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

C:\WINDOWS\system32\ctfmon.exe

C:\PROGRA~1\MI3AA1~1\rapimgr.exe

C:\Program Files\Hercules\Audio\Gamesurround Muse Pocket\MuseCPL.exe

C:\Program Files\NETGEAR\WPN111\wpn111.exe

C:\Program Files\WinZip\WZQKPICK.EXE

C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe

C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\Program Files\Avira\AntiVir Desktop\sched.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe

c:\program files\avira\antivir desktop\avscan.exe

C:\WINDOWS\system32\notepad.exe

C:\WINDOWS\system32\LVComsX.exe

C:\WINDOWS\system32\wuauclt.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

 

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr/keyword/%s

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/ie

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aliceadsl.fr

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.fr

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.fr

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.fr

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.fr/ie

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Alice ADSL

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 195.115.25.129:80

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

R3 - Default URLSearchHook is missing

O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\styler\TB\StylerTB.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O4 - HKLM\..\Run: [AliceSAV] C:\Program Files\TechCity Solutions\AliceSAV\AliceAgent.exe

O4 - HKLM\..\Run: [MobileConnect] %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\VistaCodecPack\QT\QTSystem\qttask.exe" -atboottime

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

O4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020

O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot

O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')

O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE RÉSEAU')

O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

O4 - Global Startup: Gamesurround Muse Pocket.lnk = C:\Program Files\Hercules\Audio\Gamesurround Muse Pocket\MuseCPL.exe

O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe

O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ?

O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE

O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000

O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra 'Tools' menuitem: Créer un Favori de l'appareil mobile... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab

O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Fichiers communs\Nero\Lib\NMIndexingService.exe

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: olMntrService - Olivetti - C:\Program Files\Olivetti\ANY_WAY\olMntrService.exe

O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe

O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe

 

--

End of file - 9344 bytes

Lien vers le commentaire
Partager sur d’autres sites

Rejoindre la conversation

Vous pouvez publier maintenant et vous inscrire plus tard. Si vous avez un compte, connectez-vous maintenant pour publier avec votre compte.
Remarque : votre message nécessitera l’approbation d’un modérateur avant de pouvoir être visible.

Invité
Répondre à ce sujet…

×   Collé en tant que texte enrichi.   Coller en tant que texte brut à la place

  Seulement 75 émoticônes maximum sont autorisées.

×   Votre lien a été automatiquement intégré.   Afficher plutôt comme un lien

×   Votre contenu précédent a été rétabli.   Vider l’éditeur

×   Vous ne pouvez pas directement coller des images. Envoyez-les depuis votre ordinateur ou insérez-les depuis une URL.

  • En ligne récemment   0 membre est en ligne

    • Aucun utilisateur enregistré regarde cette page.
×
×
  • Créer...