Fenêtre de pub intempestives
Résolu
elkha01
-
elkha01 Messages postés 102 Date d'inscription Statut Membre Dernière intervention -
elkha01 Messages postés 102 Date d'inscription Statut Membre Dernière intervention -
Bonjour,
Depuis quelques jours, de fenêtres de pubs s'ouvrent de manières intempestives. Je navigue avec Firefox, dispose d'un anti popup mais apparemment il ne fait plus son travail.
Voici le rapport HijackThis
Quelqu'un peut il m'aider SVP?
Merci d'avance.
Depuis quelques jours, de fenêtres de pubs s'ouvrent de manières intempestives. Je navigue avec Firefox, dispose d'un anti popup mais apparemment il ne fait plus son travail.
Voici le rapport HijackThis
Quelqu'un peut il m'aider SVP?
Merci d'avance.
A voir également:
- Fenêtre de pub intempestives
- Supprimer pub youtube - Accueil - Streaming
- Stop pub gratuit - Télécharger - Divers Utilitaires
- Fenetre windows - Guide
- Fenêtre hors écran windows 11 - Guide
- Fenetre de navigation privée - Guide
101 réponses
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Voila fait ca ;;
Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.
https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2
* Lance l'installation du programme en exécutant le fichier téléchargé.
* Double-clique maintenant sur le raccourci de Toolbar-S&D.
* Sélectionne la langue souhaitée en tapant la lettre de ton choix puis en validant avec la touche Entrée.
* Choisis maintenant l'option 1 (Recherche). Patiente jusqu'à la fin de la recherche.
* Poste le rapport généré. (C:\TB.txt)
Voici le rapport:
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ )
BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
USER : Abdelhak ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090117-0] 4.8.1296 (Activated)
Firewall : Sygate Personal Firewall 4.6 (Activated)
C:\ (Local Disk) - NTFS - Total:113 Go (Free:81 Go)
D:\ (Local Disk) - FAT32 - Total:113 Go (Free:46 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 18/01/2009|21:25 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resFF
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\temp
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\alerts.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\alerts_over.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\alerts_rec.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\alerts_rec_over.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\chevron-small.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\DealioSearch.html
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\deals-leftcap.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\deal_report.jpg
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\err_mainwindow.html
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\err_toolbar.html
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\global_scripts.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\headerbgthin.jpg
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\highlight-bg.png
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\logo.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\logo_over.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\man_toolbar.css
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\man_toolbar.html
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\man_toolbar.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\man_toolbarl.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\post-this-deal.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\post-this-deal_over.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\scripts.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\scroller.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\search-chevron.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\search-chevron_over.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\search_bg_blink.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\separator.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\settings.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\settings_over.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\yahoo-search.png
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\bottom.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\chevron_down.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\chevron_up.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\close.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\deskbar.css
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\deskbar.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\dispatch_helper.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\ebay_compatible.jpg
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\logo.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\logo_chevron_bkg.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\losing.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\lost.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\man_deskbar.html
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\menu_arrow.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\menu_check.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\no_image.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\prod_img.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\search_chevron.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\spacer.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\textfield_bkg.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\top.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\unknown.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\winning.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\won.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resFF\deal_report.jpg
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resFF\ebay_login.jpg
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\index.76.35
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.10.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.109.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.110.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.12.52
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.13.58
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.130.58
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.135.50
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.153.44
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.155.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.156.49
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.16.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.161.52
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.178.66
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.184.55
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.188.52
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.189.45
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.196.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.198.56
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.199.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.200.53
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.201.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.202.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.203.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.205.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.213.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.214.49
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.215.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.216.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.217.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.218.52
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.219.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.220.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.221.57
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.222.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.223.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.226.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.227.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.228.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.229.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.23.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.239.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.24.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.240.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.241.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.242.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.243.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.244.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.245.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.247.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.248.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.249.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.250.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.251.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.252.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.253.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.254.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.255.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.256.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.257.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.279.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.28.58
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.282.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.283.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.284.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.289.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.290.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.291.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.296.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.297.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.304.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.307.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.308.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.31.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.310.46
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.311.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.315.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.316.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.317.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.318.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.319.49
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.32.48
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.334.44
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.335.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.336.44
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.337.44
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.338.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.339.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.34.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.340.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.341.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.349.50
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.35.48
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.350.50
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.351.51
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.352.54
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.353.51
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.354.51
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.357.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.358.52
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.359.52
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.360.53
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.361.54
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.362.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.363.58
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.364.54
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.365.53
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.367.56
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.368.58
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.369.55
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.370.56
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.371.56
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.372.57
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.373.55
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.375.56
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.376.57
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.377.55
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.378.65
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.384.58
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.386.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.387.59
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.388.59
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.389.59
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.390.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.391.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.392.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.393.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.394.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.396.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.397.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.398.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.399.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.403.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.404.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.405.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.406.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.407.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.408.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.409.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.412.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.413.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.414.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.415.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.416.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.417.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.418.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.419.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.420.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.421.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.423.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.424.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.425.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.426.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.427.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.428.65
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.429.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.430.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.432.65
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.433.64
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.434.65
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.435.64
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.436.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.437.64
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.438.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.439.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.440.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.442.73
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.443.73
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.444.73
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.445.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.446.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.450.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.451.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.452.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.453.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.454.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.456.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.457.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.458.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.459.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.460.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.462.74
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.463.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.464.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.465.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.468.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.469.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.470.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.471.73
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.472.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.478.74
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.479.73
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.480.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.481.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.482.74
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.49.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.50.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.500.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.501.74
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.502.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.51.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.52.72
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.520.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.521.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.522.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.53.51
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.531.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.532.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.534.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.54.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.55.45
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.56.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.57.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.58.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.593.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.595.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.63.57
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.66.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.70.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.71.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\index.3.67.22
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.109.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.178.66
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.198.56
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.245.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.247.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.279.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.283.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.284.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.289.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.290.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.297.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.315.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.319.49
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.335.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.337.44
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.340.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.360.53
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.386.59
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.388.59
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.391.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.398.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.399.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.403.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.404.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.405.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.406.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.407.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.408.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.409.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.412.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.413.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.414.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.415.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.416.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.417.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.418.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.419.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.420.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.421.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.424.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.427.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.432.65
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.49.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.51.46
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.52.57
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.53.51
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.54.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.57.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.58.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\temp\dealio-14158.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\temp\dealio-14159.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\temp\dealio-14160.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\temp\dealio-14161.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\temp\dod_cache.xml
C:\WINDOWS\Prefetch\SEARCHSETTINGS.EXE-30EFBC20.pf
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127\res
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127\temp
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127\temp\ws-14259.log
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127\temp\ws-14260.log
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127\temp\ws-14261.log
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127\temp\ws-14262.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127\res
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127\temp
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127\temp\ws-14259.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127\temp\ws-14260.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127\temp\ws-14261.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127\temp\ws-14262.log
C:\Program Files\Search Settings
C:\Program Files\Search Settings\kb127
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\Search Settings\kb127\res
C:\Program Files\Search Settings\kb127\SearchSettings.dll
C:\Program Files\Search Settings\kb127\SearchSettingsRes409.dll
C:\Program Files\Search Settings\kb127\temp
C:\WINDOWS\iun6002.exe
-----------\\ Extensions
(Abdelhak) - {0200c2a9-70da-4f6d-b527-f5f7d7877228} => fireuploader
(Abdelhak) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Abdelhak) - {5A170DD3-63CA-4c58-93B7-DE9FF536C2FF} => walnut
(Abdelhak) - {a7c6cf7f-112c-4500-a7ea-39801a327e5f} => fireftp
(Abdelhak) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper
(Abdelhak) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus
(Abdelhak) - {e1170235-2845-420c-acc3-42261a29dd46} => clipmarks
(Abdelhak) - {EF522540-89F5-46b9-B6FE-1829E2B572C6} => googlepreview
(Abdelhak) - {3b4e7bc6-3b45-11dc-8314-0800200c9a66} => aquabird_black-1.0.5-tb
(Abdelhak) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(Abdelhak) - {4e797306-9ff7-11dc-8314-0800200c9a66} => aero_thunderbird-1.0.3-tb
(Abdelhak) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Abdelhak) - {F3A60010-0E28-4503-B4AA-0E5F90275F77} => walnut_tb
(Abdelhak) - {03B08592-E5B4-45ff-A0BE-C1D975458688} => tbutton
(Abdelhak) - {3b4e7bc6-3b45-11dc-8314-0800200c9a66} => aquabird_black-1.0.5-tb
(Abdelhak) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(Abdelhak) - {42b649d0-62e0-11da-8cd6-0800200c9a66} => pitchdark_for_tb-2.0.2-tb
(Abdelhak) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Abdelhak) - {F3A60010-0E28-4503-B4AA-0E5F90275F77} => walnut_tb
(All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(ghizlan) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(ghizlan) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(ghizlan) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Ghizlane) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Ghizlane) - {799eea9e-84ae-491b-8d7b-5d803e2e6ff6} => nacho_green
(Ghizlane) - {FDE3FEE9-893E-4cc7-A814-60E0DE7B2E01} => chrome
(Ghizlane) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(Ghizlane) - {4e797306-9ff7-11dc-8314-0800200c9a66} => aero_thunderbird-1.0.3-tb
(Ghizlane) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Ghizlane) - {F3A60010-0E28-4503-B4AA-0E5F90275F77} => walnut_tb
(NetworkService) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Start Page"="https://www.orange.fr/portail"
"Search Bar"="https://www.orange.fr/portail?kw="
"Url"="http://www.microsoft.com/athome/community/rss.xml"
"Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
"Url"="http://www.microsoft.com/atwork/community/rss.xml"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.google.com/?gws_rd=ssl"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.search.yahoo.com/"
"Start Page"="https://fr.yahoo.com/"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At3.job
1 - "C:\ToolBar SD\TB_1.txt" - 18/01/2009|21:26 - Option : [1]
-----------\\ Fin du rapport a 21:26:57,40
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ )
BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
USER : Abdelhak ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090117-0] 4.8.1296 (Activated)
Firewall : Sygate Personal Firewall 4.6 (Activated)
C:\ (Local Disk) - NTFS - Total:113 Go (Free:81 Go)
D:\ (Local Disk) - FAT32 - Total:113 Go (Free:46 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 18/01/2009|21:25 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resFF
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\temp
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\alerts.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\alerts_over.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\alerts_rec.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\alerts_rec_over.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\chevron-small.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\DealioSearch.html
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\deals-leftcap.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\deal_report.jpg
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\err_mainwindow.html
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\err_toolbar.html
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\global_scripts.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\headerbgthin.jpg
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\highlight-bg.png
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\logo.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\logo_over.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\man_toolbar.css
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\man_toolbar.html
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\man_toolbar.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\man_toolbarl.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\post-this-deal.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\post-this-deal_over.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\scripts.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\scroller.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\search-chevron.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\search-chevron_over.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\search_bg_blink.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\separator.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\settings.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\settings_over.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\res\yahoo-search.png
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\bottom.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\chevron_down.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\chevron_up.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\close.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\deskbar.css
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\deskbar.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\dispatch_helper.js
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\ebay_compatible.jpg
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\logo.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\logo_chevron_bkg.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\losing.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\lost.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\man_deskbar.html
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\menu_arrow.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\menu_check.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\no_image.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\prod_img.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\search_chevron.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\spacer.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\textfield_bkg.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\top.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\unknown.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\winning.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resDN\won.gif
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resFF\deal_report.jpg
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\resFF\ebay_login.jpg
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\index.76.35
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.10.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.109.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.110.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.12.52
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.13.58
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.130.58
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.135.50
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.153.44
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.155.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.156.49
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.16.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.161.52
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.178.66
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.184.55
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.188.52
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.189.45
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.196.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.198.56
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.199.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.200.53
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.201.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.202.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.203.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.205.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.213.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.214.49
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.215.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.216.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.217.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.218.52
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.219.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.220.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.221.57
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.222.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.223.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.226.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.227.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.228.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.229.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.23.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.239.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.24.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.240.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.241.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.242.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.243.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.244.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.245.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.247.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.248.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.249.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.250.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.251.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.252.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.253.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.254.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.255.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.256.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.257.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.279.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.28.58
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.282.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.283.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.284.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.289.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.290.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.291.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.296.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.297.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.304.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.307.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.308.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.31.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.310.46
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.311.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.315.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.316.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.317.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.318.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.319.49
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.32.48
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.334.44
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.335.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.336.44
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.337.44
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.338.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.339.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.34.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.340.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.341.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.349.50
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.35.48
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.350.50
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.351.51
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.352.54
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.353.51
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.354.51
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.357.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.358.52
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.359.52
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.360.53
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.361.54
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.362.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.363.58
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.364.54
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.365.53
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.367.56
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.368.58
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.369.55
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.370.56
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.371.56
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.372.57
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.373.55
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.375.56
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.376.57
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.377.55
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.378.65
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.384.58
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.386.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.387.59
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.388.59
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.389.59
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.390.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.391.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.392.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.393.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.394.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.396.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.397.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.398.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.399.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.403.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.404.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.405.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.406.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.407.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.408.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.409.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.412.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.413.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.414.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.415.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.416.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.417.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.418.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.419.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.420.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.421.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.423.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.424.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.425.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.426.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.427.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.428.65
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.429.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.430.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.432.65
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.433.64
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.434.65
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.435.64
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.436.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.437.64
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.438.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.439.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.440.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.442.73
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.443.73
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.444.73
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.445.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.446.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.450.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.451.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.452.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.453.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.454.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.456.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.457.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.458.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.459.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.460.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.462.74
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.463.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.464.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.465.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.468.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.469.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.470.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.471.73
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.472.70
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.478.74
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.479.73
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.480.68
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.481.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.482.74
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.49.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.50.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.500.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.501.74
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.502.71
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.51.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.52.72
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.520.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.521.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.522.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.53.51
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.531.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.532.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.534.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.54.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.55.45
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.56.69
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.57.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.58.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.593.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.595.76
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.63.57
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.66.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.70.75
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rules\rules.1.71.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\index.3.67.22
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.109.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.178.66
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.198.56
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.245.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.247.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.279.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.283.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.284.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.289.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.290.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.297.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.315.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.319.49
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.335.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.337.44
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.340.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.360.53
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.386.59
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.388.59
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.391.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.398.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.399.60
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.403.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.404.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.405.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.406.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.407.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.408.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.409.61
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.412.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.413.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.414.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.415.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.416.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.417.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.418.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.419.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.420.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.421.62
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.424.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.427.63
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.432.65
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.49.67
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.51.46
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.52.57
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.53.51
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.54.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.57.43
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\rulesFF\rules.3.58.47
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\temp\dealio-14158.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\temp\dealio-14159.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\temp\dealio-14160.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\temp\dealio-14161.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127\temp\dod_cache.xml
C:\WINDOWS\Prefetch\SEARCHSETTINGS.EXE-30EFBC20.pf
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127\res
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127\temp
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127\temp\ws-14259.log
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127\temp\ws-14260.log
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127\temp\ws-14261.log
C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127\temp\ws-14262.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127\res
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127\temp
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127\temp\ws-14259.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127\temp\ws-14260.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127\temp\ws-14261.log
C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127\temp\ws-14262.log
C:\Program Files\Search Settings
C:\Program Files\Search Settings\kb127
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\Search Settings\kb127\res
C:\Program Files\Search Settings\kb127\SearchSettings.dll
C:\Program Files\Search Settings\kb127\SearchSettingsRes409.dll
C:\Program Files\Search Settings\kb127\temp
C:\WINDOWS\iun6002.exe
-----------\\ Extensions
(Abdelhak) - {0200c2a9-70da-4f6d-b527-f5f7d7877228} => fireuploader
(Abdelhak) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Abdelhak) - {5A170DD3-63CA-4c58-93B7-DE9FF536C2FF} => walnut
(Abdelhak) - {a7c6cf7f-112c-4500-a7ea-39801a327e5f} => fireftp
(Abdelhak) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper
(Abdelhak) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus
(Abdelhak) - {e1170235-2845-420c-acc3-42261a29dd46} => clipmarks
(Abdelhak) - {EF522540-89F5-46b9-B6FE-1829E2B572C6} => googlepreview
(Abdelhak) - {3b4e7bc6-3b45-11dc-8314-0800200c9a66} => aquabird_black-1.0.5-tb
(Abdelhak) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(Abdelhak) - {4e797306-9ff7-11dc-8314-0800200c9a66} => aero_thunderbird-1.0.3-tb
(Abdelhak) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Abdelhak) - {F3A60010-0E28-4503-B4AA-0E5F90275F77} => walnut_tb
(Abdelhak) - {03B08592-E5B4-45ff-A0BE-C1D975458688} => tbutton
(Abdelhak) - {3b4e7bc6-3b45-11dc-8314-0800200c9a66} => aquabird_black-1.0.5-tb
(Abdelhak) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(Abdelhak) - {42b649d0-62e0-11da-8cd6-0800200c9a66} => pitchdark_for_tb-2.0.2-tb
(Abdelhak) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Abdelhak) - {F3A60010-0E28-4503-B4AA-0E5F90275F77} => walnut_tb
(All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(ghizlan) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(ghizlan) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(ghizlan) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Ghizlane) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Ghizlane) - {799eea9e-84ae-491b-8d7b-5d803e2e6ff6} => nacho_green
(Ghizlane) - {FDE3FEE9-893E-4cc7-A814-60E0DE7B2E01} => chrome
(Ghizlane) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(Ghizlane) - {4e797306-9ff7-11dc-8314-0800200c9a66} => aero_thunderbird-1.0.3-tb
(Ghizlane) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Ghizlane) - {F3A60010-0E28-4503-B4AA-0E5F90275F77} => walnut_tb
(NetworkService) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Start Page"="https://www.orange.fr/portail"
"Search Bar"="https://www.orange.fr/portail?kw="
"Url"="http://www.microsoft.com/athome/community/rss.xml"
"Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
"Url"="http://www.microsoft.com/atwork/community/rss.xml"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.google.com/?gws_rd=ssl"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.search.yahoo.com/"
"Start Page"="https://fr.yahoo.com/"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At3.job
1 - "C:\ToolBar SD\TB_1.txt" - 18/01/2009|21:26 - Option : [1]
-----------\\ Fin du rapport a 21:26:57,40
J_O_J_O,
Je pense que cela va être un jeu d'enfant pour toi de m'aider =)
Je suis novice en informatique et tout appris sur le tard...
Je pense que cela va être un jeu d'enfant pour toi de m'aider =)
Je suis novice en informatique et tout appris sur le tard...
^^ Merci . Passe l'option 2 de Toolbar S&D ;) puis poste son nouveau rapport ici . Ensuite il ne restera plus grand chose à faire si ce n'est que du nettoyage donc sa pourra attendre demain car je doit bouger .. Mais si tu est pressé,demande l'aide à un autre helper .
Ccleaner :::
*Télécharge et installe CCleaner https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html ( à l'installation, pense à DÉCOCHER l'installation de Yahoo toolbar !!!).
*Lance CCleaner
Option --> avancé --> décoche « effacer uniquement les fichiers plus vieux que 48h »
Puis nettoyeur --> Analyse > Lancer le nettoyage, puis sur OK dans la fenêtre qui s' affiche.
Relance le nettoyage une deuxième fois.(pense à cocher toutes les cases décochées !!!!)
*Enfin, registre --> corrige toutes les erreurs, et recommence jusqu'à ce qu'il ne trouve plus d'erreurs.
*(garde ce logiciel et utilise le régulièrement il te servira à nettoyer ton pc et à l'optimiser ;) ).
Refait un hijackthis et poste --> son rapport encore une fois :P . Bonne soirée à d'main .
Ccleaner :::
*Télécharge et installe CCleaner https://www.01net.com/telecharger/windows/Utilitaire/nettoyeurs_et_installeurs/fiches/32599.html ( à l'installation, pense à DÉCOCHER l'installation de Yahoo toolbar !!!).
*Lance CCleaner
Option --> avancé --> décoche « effacer uniquement les fichiers plus vieux que 48h »
Puis nettoyeur --> Analyse > Lancer le nettoyage, puis sur OK dans la fenêtre qui s' affiche.
Relance le nettoyage une deuxième fois.(pense à cocher toutes les cases décochées !!!!)
*Enfin, registre --> corrige toutes les erreurs, et recommence jusqu'à ce qu'il ne trouve plus d'erreurs.
*(garde ce logiciel et utilise le régulièrement il te servira à nettoyer ton pc et à l'optimiser ;) ).
Refait un hijackthis et poste --> son rapport encore une fois :P . Bonne soirée à d'main .
Merci et bonne soirée à toi aussi.
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ )
BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
USER : Abdelhak ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090117-0] 4.8.1296 (Activated)
Firewall : Sygate Personal Firewall 4.6 (Activated)
C:\ (Local Disk) - NTFS - Total:113 Go (Free:81 Go)
D:\ (Local Disk) - FAT32 - Total:113 Go (Free:46 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 18/01/2009|21:35 )
-----------\\ SUPPRESSION
Supprime! - C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127
Supprime! - C:\WINDOWS\Prefetch\SEARCHSETTINGS.EXE-30EFBC20.pf
Supprime! - C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127
Supprime! - C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127
Supprime! - C:\Program Files\Search Settings\kb127
Supprime! - C:\Program Files\Search Settings\SearchSettings.exe
Supprime! - C:\WINDOWS\iun6002.exe
Supprime! - C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio
Supprime! - C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings
Supprime! - C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings
Supprime! - C:\Program Files\Search Settings
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ Extensions
(Abdelhak) - {0200c2a9-70da-4f6d-b527-f5f7d7877228} => fireuploader
(Abdelhak) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Abdelhak) - {5A170DD3-63CA-4c58-93B7-DE9FF536C2FF} => walnut
(Abdelhak) - {a7c6cf7f-112c-4500-a7ea-39801a327e5f} => fireftp
(Abdelhak) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper
(Abdelhak) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus
(Abdelhak) - {e1170235-2845-420c-acc3-42261a29dd46} => clipmarks
(Abdelhak) - {EF522540-89F5-46b9-B6FE-1829E2B572C6} => googlepreview
(Abdelhak) - {3b4e7bc6-3b45-11dc-8314-0800200c9a66} => aquabird_black-1.0.5-tb
(Abdelhak) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(Abdelhak) - {4e797306-9ff7-11dc-8314-0800200c9a66} => aero_thunderbird-1.0.3-tb
(Abdelhak) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Abdelhak) - {F3A60010-0E28-4503-B4AA-0E5F90275F77} => walnut_tb
(Abdelhak) - {03B08592-E5B4-45ff-A0BE-C1D975458688} => tbutton
(Abdelhak) - {3b4e7bc6-3b45-11dc-8314-0800200c9a66} => aquabird_black-1.0.5-tb
(Abdelhak) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(Abdelhak) - {42b649d0-62e0-11da-8cd6-0800200c9a66} => pitchdark_for_tb-2.0.2-tb
(Abdelhak) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Abdelhak) - {F3A60010-0E28-4503-B4AA-0E5F90275F77} => walnut_tb
(All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(ghizlan) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(ghizlan) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(ghizlan) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Ghizlane) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Ghizlane) - {799eea9e-84ae-491b-8d7b-5d803e2e6ff6} => nacho_green
(Ghizlane) - {FDE3FEE9-893E-4cc7-A814-60E0DE7B2E01} => chrome
(Ghizlane) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(Ghizlane) - {4e797306-9ff7-11dc-8314-0800200c9a66} => aero_thunderbird-1.0.3-tb
(Ghizlane) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Ghizlane) - {F3A60010-0E28-4503-B4AA-0E5F90275F77} => walnut_tb
(NetworkService) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Start Page"="https://www.orange.fr/portail"
"Search Bar"="https://www.orange.fr/portail?kw="
"Url"="http://www.microsoft.com/athome/community/rss.xml"
"Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
"Url"="http://www.microsoft.com/atwork/community/rss.xml"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.google.com/?gws_rd=ssl"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.search.yahoo.com/"
"Start Page"="https://www.msn.com/fr-fr/"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At3.job
1 - "C:\ToolBar SD\TB_1.txt" - 18/01/2009|21:26 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 18/01/2009|21:37 - Option : [2]
-----------\\ Fin du rapport a 21:37:06,98
-----------\\ ToolBar S&D 1.2.8 XP/Vista
Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 4200+ )
BIOS : )Phoenix - Award WorkstationBIOS v6.00PG
USER : Abdelhak ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1296 [VPS 090117-0] 4.8.1296 (Activated)
Firewall : Sygate Personal Firewall 4.6 (Activated)
C:\ (Local Disk) - NTFS - Total:113 Go (Free:81 Go)
D:\ (Local Disk) - FAT32 - Total:113 Go (Free:46 Go)
E:\ (CD or DVD)
F:\ (USB)
G:\ (USB)
H:\ (USB)
I:\ (USB)
"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 18/01/2009|21:35 )
-----------\\ SUPPRESSION
Supprime! - C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio\kb127
Supprime! - C:\WINDOWS\Prefetch\SEARCHSETTINGS.EXE-30EFBC20.pf
Supprime! - C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings\kb127
Supprime! - C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings\kb127
Supprime! - C:\Program Files\Search Settings\kb127
Supprime! - C:\Program Files\Search Settings\SearchSettings.exe
Supprime! - C:\WINDOWS\iun6002.exe
Supprime! - C:\DOCUME~1\Ghizlane\APPLIC~1\Dealio
Supprime! - C:\DOCUME~1\Abdelhak\APPLIC~1\Search Settings
Supprime! - C:\DOCUME~1\Ghizlane\APPLIC~1\Search Settings
Supprime! - C:\Program Files\Search Settings
-----------\\ Recherche de Fichiers / Dossiers ...
-----------\\ Extensions
(Abdelhak) - {0200c2a9-70da-4f6d-b527-f5f7d7877228} => fireuploader
(Abdelhak) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Abdelhak) - {5A170DD3-63CA-4c58-93B7-DE9FF536C2FF} => walnut
(Abdelhak) - {a7c6cf7f-112c-4500-a7ea-39801a327e5f} => fireftp
(Abdelhak) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper
(Abdelhak) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus
(Abdelhak) - {e1170235-2845-420c-acc3-42261a29dd46} => clipmarks
(Abdelhak) - {EF522540-89F5-46b9-B6FE-1829E2B572C6} => googlepreview
(Abdelhak) - {3b4e7bc6-3b45-11dc-8314-0800200c9a66} => aquabird_black-1.0.5-tb
(Abdelhak) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(Abdelhak) - {4e797306-9ff7-11dc-8314-0800200c9a66} => aero_thunderbird-1.0.3-tb
(Abdelhak) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Abdelhak) - {F3A60010-0E28-4503-B4AA-0E5F90275F77} => walnut_tb
(Abdelhak) - {03B08592-E5B4-45ff-A0BE-C1D975458688} => tbutton
(Abdelhak) - {3b4e7bc6-3b45-11dc-8314-0800200c9a66} => aquabird_black-1.0.5-tb
(Abdelhak) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(Abdelhak) - {42b649d0-62e0-11da-8cd6-0800200c9a66} => pitchdark_for_tb-2.0.2-tb
(Abdelhak) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Abdelhak) - {F3A60010-0E28-4503-B4AA-0E5F90275F77} => walnut_tb
(All Users) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(ghizlan) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(ghizlan) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(ghizlan) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Ghizlane) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Ghizlane) - {799eea9e-84ae-491b-8d7b-5d803e2e6ff6} => nacho_green
(Ghizlane) - {FDE3FEE9-893E-4cc7-A814-60E0DE7B2E01} => chrome
(Ghizlane) - {3c8e8390-2cf6-11d9-9669-0800200c9a66} => web-mail
(Ghizlane) - {4e797306-9ff7-11dc-8314-0800200c9a66} => aero_thunderbird-1.0.3-tb
(Ghizlane) - {a6a33690-2c6a-11d9-9669-0800200c9a66} => hotmail
(Ghizlane) - {F3A60010-0E28-4503-B4AA-0E5F90275F77} => walnut_tb
(NetworkService) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\WINDOWS\\system32\\blank.htm"
"Search Page"="https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC"
"SearchMigratedDefaultURL"="https://search.yahoo.com/web{searchTerms}&ei=utf-8&fr=b1ie7"
"Start Page"="https://www.orange.fr/portail"
"Search Bar"="https://www.orange.fr/portail?kw="
"Url"="http://www.microsoft.com/athome/community/rss.xml"
"Url"="http://rss.msn.com/en-us/?feedoutput=rss&ocid=iehrs&unsub=true"
"Url"="http://www.microsoft.com/atwork/community/rss.xml"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.google.com/?gws_rd=ssl"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.search.yahoo.com/"
"Start Page"="https://www.msn.com/fr-fr/"
--------------------\\ Recherche d'autres infections
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\Tasks\At2.job
C:\WINDOWS\Tasks\At3.job
1 - "C:\ToolBar SD\TB_1.txt" - 18/01/2009|21:26 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 18/01/2009|21:37 - Option : [2]
-----------\\ Fin du rapport a 21:37:06,98
Voilà le rapport
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:43:04, on 18/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\MSI\MSI.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
C:\Program Files\Thunderbird-Tray\TBTray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Thunderbird2\thunderbird.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail?kw=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Hitware Popup Killer Lite - {604B283A-4E26-4504-98E7-72859F949547} - C:\PROGRA~1\HITWAR~1\sypcms.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSI] "C:\Program Files\MSI\MSI.exe" -nogui
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 1
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
O4 - Global Startup: TB-Tray.lnk = C:\Program Files\Thunderbird-Tray\TBTray.exe
O8 - Extra context menu item: Download with &Shareaza - res://D:\Shareaza\Plugins\RazaWebHook.dll/3000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O15 - Trusted Zone: https://www.orange.fr/portail
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://free-spirit1978.spaces.live.com/PhotoUpload/MsnPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E0A3361E-806E-4F30-990A-FC175544593C}: NameServer = 192.168.1.1
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: MSI Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:43:04, on 18/01/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sygate\SPF\smc.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\MSI\MSI.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Program Files\RocketDock\RocketDock.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Acer\Empowering Technology\Acer.Empowering.Framework.Launcher.exe
C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
C:\Program Files\Thunderbird-Tray\TBTray.exe
C:\Program Files\Microsoft IntelliType Pro\type32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Thunderbird2\thunderbird.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail?kw=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?FORM=TOOLBR&cc=fr&toHttps=1&redig=4527FFF1C12746FC9EDB535C75E80ECC
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://fr.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*https://fr.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://fr.rd.yahoo.com/customize/ie/defaults/su/msgr8/*https://fr.search.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://actus.sfr.fr
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer avec Club-Internet
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: (no name) - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
O2 - BHO: (no name) - {0EEDB912-C5FA-486F-8334-57288578C627} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Hitware Popup Killer Lite - {604B283A-4E26-4504-98E7-72859F949547} - C:\PROGRA~1\HITWAR~1\sypcms.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32\eDStoolbar.dll
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [MSI] "C:\Program Files\MSI\MSI.exe" -nogui
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe 1
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: RocketDock.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\RocketDock\RocketDock.exe
O4 - Startup: TransBar.lnk = C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: Acer WLAN 11g USB Dongle.lnk = C:\Program Files\Acer WLAN 11g USB Dongle\ZDWlan.exe
O4 - Global Startup: TB-Tray.lnk = C:\Program Files\Thunderbird-Tray\TBTray.exe
O8 - Extra context menu item: Download with &Shareaza - res://D:\Shareaza\Plugins\RazaWebHook.dll/3000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: (no name) - cmdmapping - (no file) (HKCU)
O15 - Trusted Zone: https://www.orange.fr/portail
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) - http://free-spirit1978.spaces.live.com/PhotoUpload/MsnPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E0A3361E-806E-4F30-990A-FC175544593C}: NameServer = 192.168.1.1
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: MSI Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe
Merci . Tu est sain par contre je te conseil d'abandonné Avast pour Avira antivir .
Pk :::: http://forum.telecharger.01net.com/forum/high-tech/SECURITE/Securite/avast-protege-sujet_44722_1.htm
Avira antivir :::: https://www.01net.com/telecharger/windows/Securite/antivirus-antitrojan/fiches/13198.html
Tutoriel d'installation :::: https://www.malekal.com/tutorial-sur-lantivirus-antivir/
Si tu veux le changer à la place d'avast désinstalle bien Avast avec Ccleaner et nettoie bien ;)
Pk :::: http://forum.telecharger.01net.com/forum/high-tech/SECURITE/Securite/avast-protege-sujet_44722_1.htm
Avira antivir :::: https://www.01net.com/telecharger/windows/Securite/antivirus-antitrojan/fiches/13198.html
Tutoriel d'installation :::: https://www.malekal.com/tutorial-sur-lantivirus-antivir/
Si tu veux le changer à la place d'avast désinstalle bien Avast avec Ccleaner et nettoie bien ;)
Non J'ai oublier que t'avais du zlob .. comme infection Crapoulou va t'aidé à le viré . Moi je doit partir . Bonne soirée .
ma femme vient de me rosser...alors qu'elle a grandement participé à l'infection...lol xD
ma femme vient de me rosser...alors qu'elle a grandement participé à l'infection...lol xD