Accés impossible au sites antivirus

Fermé
sphinx40000 - 7 avril 2009 à 13:58
 Utilisateur anonyme - 7 avril 2009 à 18:58
Bonjour,
je n'arrive pas à acceder au sites des antivirus ce qui implique une mise à jour impossible ni à au site de microsoft
j'ai lus plusieurs postes à ce sujet et je tiens à remercier tout le monde pour leur aide
ceci dis j'ai deja essayé rhost pour restaurer mon fichier host j'ai aussi essayé smitfraudfix, combofix, Malwarebytes, HijackThis aussi enfin ça ne donne rien tout ça je dois dire que je ne l'ai pas essayé en mode sans echec parceque ça ne marche plus si j'essaye de redemarrer en mode sans echec ça redemarre aussi tot en plein boot du mode donc ...
aidez moi svp
merci
A voir également:

21 réponses

Utilisateur anonyme
7 avril 2009 à 14:05
ok salut peux-tu remettre tous les rapports que tu as eu un par un histoire de voir le travail qui a ete fait ?
0
Merci ben voila le rapport de hijackthis


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:15:59, on 07/04/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Hamachi\hamachi.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Live\Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.dz/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)
O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb127\Dealio.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\NASS\Application Data\Dealio\kb127\res\DealioSearch.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
0
et voila le rapport de Malwarebytes



Malwarebytes' Anti-Malware 1.35
Version de la base de données: 1904
Windows 5.1.2600 Service Pack 2

07/04/2009 13:01:22
mbam-log-2009-04-07 (13-01-22).txt

Type de recherche: Examen rapide
Eléments examinés: 66149
Temps écoulé: 2 minute(s), 33 second(s)

Processus mémoire infecté(s): 0
Module(s) mémoire infecté(s): 0
Clé(s) du Registre infectée(s): 0
Valeur(s) du Registre infectée(s): 0
Elément(s) de données du Registre infecté(s): 0
Dossier(s) infecté(s): 0
Fichier(s) infecté(s): 1

Processus mémoire infecté(s):
(Aucun élément nuisible détecté)

Module(s) mémoire infecté(s):
(Aucun élément nuisible détecté)

Clé(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Valeur(s) du Registre infectée(s):
(Aucun élément nuisible détecté)

Elément(s) de données du Registre infecté(s):
(Aucun élément nuisible détecté)

Dossier(s) infecté(s):
(Aucun élément nuisible détecté)

Fichier(s) infecté(s):
C:\WINDOWS\system32\afmain1.dll (Trojan.Agent) -> Quarantined and deleted successfully.
0
Utilisateur anonyme
7 avril 2009 à 14:14
les autres ont ete passes avant ?
0
ben je ne sais plus dans quel ordre j'ai utilisé ces logiciels désolé :s
0
Utilisateur anonyme
7 avril 2009 à 14:37
ok c est bon j ai vu il manque le rapport de smitfraudfix et Combofix
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
re salut voila le rapport de Combofix


ComboFix 09-04-04.01 - NASS 2009-04-07 13:22:07.3 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.2047.1649 [GMT 2:00]
Lancé depuis: c:\documents and settings\NASS\Bureau\Combofix.exe
AV: BitDefender Antivirus *On-access scanning enabled* (Outdated)
AV: Kaspersky Anti-Virus *On-access scanning disabled* (Outdated)
FW: BitDefender Firewall *enabled*
FW: Kaspersky Anti-Virus *disabled*
.

(((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\windows\IE4 Error Log.txt
F:\autorun.inf . . . . impossible à supprimer
F:\ekffl.cmd . . . . impossible à supprimer
f:\recycler\My Games.exe . . . . impossible à supprimer

.
((((((((((((((((((((((((((((( Fichiers créés du 2009-03-07 au 2009-04-07 ))))))))))))))))))))))))))))))))))))
.

2009-11-25 13:45 . 2009-11-25 13:45 <REP> d-------- c:\program files\Fichiers communs\Vbox
2009-11-25 13:44 . 2009-11-25 13:44 <REP> d-------- C:\Adobe Illustrator 10
2009-04-07 12:58 . 2009-04-07 12:58 <REP> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-04-07 12:58 . 2009-04-07 12:58 <REP> d-------- c:\documents and settings\NASS\Application Data\Malwarebytes
2009-04-07 12:58 . 2009-04-07 12:58 <REP> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-07 12:58 . 2009-03-26 16:49 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-07 12:58 . 2009-03-26 16:49 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-04-07 12:47 . 2009-04-07 12:47 <REP> d-------- c:\program files\Lavasoft
2009-04-07 12:47 . 2009-04-07 12:48 <REP> d-------- c:\documents and settings\All Users\Application Data\Lavasoft
2009-04-07 12:46 . 2009-04-07 12:46 <REP> d-------- c:\program files\Fichiers communs\Wise Installation Wizard
2009-04-07 12:23 . 2009-04-07 12:32 <REP> d-------- C:\SDFix
2009-04-01 13:41 . 2009-04-01 13:43 <REP> d-------- c:\program files\UltraVNC
2009-04-01 13:41 . 2005-06-10 22:02 12,800 --a------ c:\windows\system32\vncdrv.dll
2009-04-01 13:41 . 2004-06-26 13:22 6,016 --a------ c:\windows\system32\drivers\vnccom.SYS
2009-04-01 13:41 . 2004-06-26 13:21 5,760 --a------ c:\windows\system32\vnchelp.dll
2009-04-01 13:41 . 2004-06-26 13:22 4,736 --a------ c:\windows\system32\drivers\vncdrv.sys
2009-04-01 13:41 . 2009-04-01 13:41 17 --a------ c:\windows\system32\'
2009-04-01 13:37 . 2009-04-01 13:37 <REP> d-------- c:\program files\Hamachi
2009-04-01 13:37 . 2009-04-06 11:39 <REP> d-------- c:\documents and settings\NASS\Application Data\Hamachi
2009-04-01 13:37 . 2009-04-01 13:37 25,280 --a------ c:\windows\system32\drivers\hamachi.sys
2009-04-01 09:04 . 2009-04-01 09:04 268 --ah----- C:\sqmdata19.sqm
2009-04-01 09:04 . 2009-04-01 09:04 244 --ah----- C:\sqmnoopt19.sqm
2009-03-31 08:56 . 2009-03-31 08:56 268 --ah----- C:\sqmdata18.sqm
2009-03-31 08:56 . 2009-03-31 08:56 244 --ah----- C:\sqmnoopt18.sqm
2009-03-30 21:35 . 2009-03-30 21:35 268 --ah----- C:\sqmdata17.sqm
2009-03-30 21:35 . 2009-03-30 21:35 244 --ah----- C:\sqmnoopt17.sqm
2009-03-30 20:17 . 2009-03-30 20:17 172 --ah----- C:\sqmnoopt16.sqm
2009-03-30 20:17 . 2009-03-30 20:17 172 --ah----- C:\sqmdata16.sqm
2009-03-30 13:15 . 2009-04-07 13:26 268 --ah----- C:\sqmdata15.sqm
2009-03-30 13:15 . 2009-04-07 13:26 244 --ah----- C:\sqmnoopt15.sqm
2009-03-28 19:14 . 2009-04-07 13:03 268 --ah----- C:\sqmdata14.sqm
2009-03-28 19:14 . 2009-04-07 13:03 244 --ah----- C:\sqmnoopt14.sqm
2009-03-25 11:27 . 2009-03-25 11:27 <REP> d-------- c:\documents and settings\NASS\Application Data\Search Settings
2009-03-25 10:36 . 2009-03-25 10:36 <REP> d-------- c:\program files\Search Settings
2009-03-25 10:35 . 2009-03-25 10:35 <REP> d-------- c:\program files\Dealio
2009-03-25 10:35 . 2009-03-25 10:35 <REP> d-------- c:\documents and settings\NASS\Application Data\Dealio
2009-03-25 10:33 . 2009-03-25 10:33 <REP> d-------- c:\program files\Free Audio Pack
2009-03-22 16:57 . 2009-04-07 13:01 208 --ah----- C:\sqmdata13.sqm
2009-03-22 16:57 . 2009-04-07 13:01 172 --ah----- C:\sqmnoopt13.sqm
2009-03-22 16:55 . 2009-04-07 12:35 268 --ah----- C:\sqmdata12.sqm
2009-03-22 16:55 . 2009-04-07 12:35 244 --ah----- C:\sqmnoopt12.sqm
2009-03-21 11:36 . 2009-04-07 12:33 208 --ah----- C:\sqmdata11.sqm
2009-03-21 11:36 . 2009-04-07 12:33 172 --ah----- C:\sqmnoopt11.sqm
2009-03-19 13:20 . 2009-04-07 12:31 268 --ah----- C:\sqmdata10.sqm
2009-03-19 13:20 . 2009-04-07 12:31 244 --ah----- C:\sqmnoopt10.sqm
2009-03-19 13:18 . 2009-04-07 09:03 268 --ah----- C:\sqmdata09.sqm
2009-03-19 13:18 . 2009-04-07 09:03 244 --ah----- C:\sqmnoopt09.sqm
2009-03-19 13:16 . 2009-04-07 13:07 <REP> d-------- c:\program files\Trend Micro
2009-03-19 13:07 . 2009-04-06 20:58 268 --ah----- C:\sqmdata08.sqm
2009-03-19 13:07 . 2009-04-06 20:58 244 --ah----- C:\sqmnoopt08.sqm
2009-03-19 09:23 . 2009-03-19 09:22 110,053 -r-hs---- C:\q0dhfjf.exe
2009-03-19 09:21 . 2009-03-19 09:21 850 --a------ c:\windows\system32\ProductTweaks.xml
2009-03-19 09:21 . 2009-03-19 09:21 385 --a------ c:\windows\system32\user_gensett.xml
2009-03-17 03:23 . 2009-03-17 03:23 112,640 -rahs---- c:\windows\system32\rdzuxwb.dll
2009-03-16 22:36 . 2009-03-16 22:36 <REP> d-------- c:\program files\BitDefender
2009-03-16 22:36 . 2009-03-16 22:36 <REP> d-------- c:\documents and settings\NASS\Application Data\BitDefender
2009-03-16 22:36 . 2009-03-16 22:38 <REP> d-------- c:\documents and settings\All Users\Application Data\BitDefender
2009-03-16 20:54 . 2009-03-16 10:50 110,629 -r-hs---- C:\luk1ylq.com
2009-03-16 20:38 . 2009-03-16 20:38 <REP> d-------- c:\documents and settings\All Users\Application Data\Messenger Plus!
2009-03-16 20:29 . 2009-03-16 20:29 <REP> d-------- c:\program files\Messenger Plus! Live
2009-03-16 18:34 . 2009-03-16 22:33 <REP> d-------- c:\windows\SxsCaPendDel
2009-03-16 18:23 . 2009-03-16 18:23 <REP> d-------- c:\windows\system32\Logs
2009-03-16 18:15 . 2009-03-16 22:36 <REP> d-------- c:\program files\Fichiers communs\BitDefender
2009-03-15 20:45 . 2009-03-16 22:11 <REP> d-------- c:\program files\MSN Reaper
2009-03-15 18:26 . 2009-04-06 20:39 <REP> d-------- c:\program files\Free Keylogger
2009-03-15 13:24 . 2009-03-16 22:11 <REP> d-------- c:\program files\RKFree
2009-03-15 13:24 . 2009-03-15 13:24 <REP> d-a------ c:\documents and settings\All Users\Application Data\rkfree
2009-03-11 10:06 . 2009-03-11 10:05 108,313 -r-hs---- C:\cb.exe
2009-03-08 16:11 . 2004-08-04 00:08 31,616 --a------ c:\windows\system32\drivers\usbccgp.sys
2009-03-08 16:11 . 2004-08-04 00:08 31,616 --a--c--- c:\windows\system32\dllcache\usbccgp.sys
2009-03-08 16:09 . 2007-08-24 20:45 101,120 -ra------ c:\windows\system32\drivers\ewusbmdm.sys
2009-03-08 16:09 . 2007-08-24 20:45 24,448 -ra------ c:\windows\system32\drivers\ewdcsc.sys
2009-03-08 16:08 . 2009-03-16 22:06 <REP> d-------- c:\program files\Djezzy Connect

.
(((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-25 11:45 --------- d--h--w c:\program files\InstallShield Installation Information
2009-11-25 11:45 --------- d-----w c:\program files\Fichiers communs\InstallShield
2009-03-16 21:22 40,960 ---ha-w C:\jjj.exe
2009-03-16 20:20 1,646,592 ----a-w c:\windows\system32\nwiz.exe
2009-03-16 20:19 1,847,296 ----a-r c:\windows\SkyTel.exe
2009-03-16 20:16 94,208 ----a-r c:\windows\Alcmtr.exe
2009-03-16 20:11 --------- d-----w c:\program files\MessengerPlus! 3
2009-03-16 16:16 --------- d-----w c:\documents and settings\All Users\Application Data\Kaspersky Lab
2009-02-28 11:38 108,843 --sh--r C:\gi2ky.exe
2009-02-26 07:05 103,663 --sh--r C:\wx8o0bt1.com
2009-02-11 12:00 8,105,248 --sha-w c:\windows\system32\drivers\fidbox.dat
2009-02-11 12:00 35,720 --sha-w c:\windows\system32\drivers\fidbox2.idx
2009-02-11 12:00 336,416 --sha-w c:\windows\system32\drivers\fidbox2.dat
2009-02-11 12:00 112,760 --sha-w c:\windows\system32\drivers\fidbox.idx
2009-02-11 10:21 --------- d-----w c:\program files\Alwil Software
.

((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MessengerPlus3"="c:\program files\MessengerPlus! 3\MsgPlus.exe" [2009-03-16 204800]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-04 1667584]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5793816]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-12-05 8523776]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-12-05 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-03-16 41472]
"BDAgent"="c:\program files\BitDefender\BitDefender 2009\bdagent.exe" [2008-08-14 716800]
"BitDefender Antiphishing Helper"="c:\program files\BitDefender\BitDefender 2009\IEShow.exe" [2008-08-11 69632]
"au"="c:\program files\Dealio\DealioAU.exe" [2008-05-26 595296]
"SearchSettings"="c:\program files\Search Settings\SearchSettings.exe" [2008-06-12 991584]
"RTHDCPL"="RTHDCPL.EXE" [2007-07-05 c:\windows\RTHDCPL.exe]
"SkyTel"="SkyTel.EXE" [2009-03-16 c:\windows\SkyTel.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-04 15360]

c:\documents and settings\NASS\Menu D‚marrer\Programmes\D‚marrage\
hamachi.lnk - c:\program files\Hamachi\hamachi.exe [2009-04-01 625952]

c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
Adobe Gamma Loader.lnk - c:\program files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe [2009-11-25 131072]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-02-13 90112]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\wscntfy.exe"=
"c:\\WINDOWS\\SkyTel.EXE"=
"c:\\Program Files\\Fichiers communs\\Adobe\\Calibration\\Adobe Gamma Loader.exe"=
"c:\\WINDOWS\\RTHDCPL.EXE"=
"c:\\Program Files\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe"=
"c:\\WINDOWS\\ALCMTR.EXE"=
"c:\\Program Files\\Fichiers communs\\Macrovision Shared\\FLEXnet Publisher\\FNPLicensingService.exe"=
"c:\\Program Files\\Microsoft Office\\Office10\\OSA.EXE"=
"c:\\Program Files\\Windows Live\\Messenger\\usnsvc.exe"=
"c:\\Program Files\\BitDefender\\BitDefender 2009\\IEShow.exe"=
"c:\\WINDOWS\\system32\\userinit.exe"=
"c:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe"=

R2 BDVEDISK;BDVEDISK;c:\program files\BitDefender\BitDefender 2009\BDVEDISK.sys [2008-07-02 82568]
R2 vnccom;vnccom;c:\windows\system32\drivers\vnccom.SYS [2009-04-01 6016]
R3 bdfm;BDFM;c:\windows\system32\drivers\bdfm.sys [2008-08-12 108864]
R3 Bdfndisf;BitDefender Firewall NDIS Filter Service;c:\windows\system32\drivers\bdfndisf.sys [2008-08-14 102208]
S2 AudioServer;Monitor Backup;c:\windows\system32\svchost.exe -k netsvcs [2004-08-04 14336]
S3 Arrakis3;BitDefender Arrakis Server;c:\program files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe [2008-07-17 118784]
S3 AVPsys;AVPsys;\??\c:\windows\system32\drivers\cdaudio.sys --> c:\windows\system32\drivers\cdaudio.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
AudioServer

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40da28ab-0d5c-11de-ad80-00037fbf1280}]
\Shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40da28ac-0d5c-11de-ad80-00037fbf1280}]
\Shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{98941164-0b42-11de-ad7f-00037fbf1280}]
\Shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{98941167-0b42-11de-ad7f-00037fbf1280}]
\Shell\AutoRun\command - F:\AutoRun.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc2bbd34-e07a-11dd-ad40-001d7d45bb41}]
\Shell\AutoRun\command - wscript.exe .\.vbs
\Shell\open\command - wscript.exe .\.vbs

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d060d09f-01b6-11de-ad75-00037fbf1280}]
\Shell\AutoRun\command - F:\2fiy.bat
\Shell\open\Command - F:\2fiy.bat
.
- - - - ORPHELINS SUPPRIMES - - - -

URLSearchHooks-{E312764E-7706-43F1-8DAB-FCDD2B1E416D} - (no file)


.
------- Examen supplémentaire -------
.
uStart Page = hxxp://www.google.dz/
uInternet Settings,ProxyOverride = *.local
IE: Compare Prices with &Dealio - c:\documents and settings\NASS\Application Data\Dealio\kb127\res\DealioSearch.html
IE: E&xporter vers Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
.

**************************************************************************

catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-04-07 13:26:30
Windows 5.1.2600 Service Pack 2 NTFS

Recherche de processus cachés ...

Recherche d'éléments en démarrage automatique cachés ...

Recherche de fichiers cachés ...

Scan terminé avec succès
Fichiers cachés: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\AudioServer]
"ServiceDll"="c:\windows\system32\rdzuxwb.dll"
.
------------------------ Autres processus actifs ------------------------
.
c:\program files\BitDefender\BitDefender 2009\vsserv.exe
c:\program files\Lavasoft\Ad-Aware\aawservice.exe
c:\windows\system32\rundll32.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\nvsvc32.exe
c:\program files\BitDefender\BitDefender 2009\seccenter.exe
c:\program files\Adobe\Adobe Photoshop CS3\Photoshop.exe
c:\program files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
.
**************************************************************************
.
Heure de fin: 2009-04-07 13:31:34 - La machine a redémarré
ComboFix-quarantined-files.txt 2009-04-07 11:31:31

Avant-CF: 69 897 850 880 octets libres
Après-CF: 69,472,718,848 octets libres

220
0
et le rapport de smitfraudfix


SmitFraudFix v2.109

Rapport fait à 20:47:15,85, 06/04/2009
Executé à partir de C:\Documents and Settings\NASS\Bureau\SmitfraudFix
OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
Fix executé en mode normal

»»»»»»»»»»»»»»»»»»»»»»»» Avant SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Arret des processus


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés


»»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires


»»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

Nettoyage terminé.

»»»»»»»»»»»»»»»»»»»»»»»» Après SmitFraudFix
!!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» Fin
0
Utilisateur anonyme
7 avril 2009 à 14:56
ok c est bon :

##################### | XP _ Instal & recherche | ########################



Telecharge et install UsbFix (de C_XX & Chiquitine29)

Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

# Double clic sur le raccourci UsbFix présent sur ton bureau .

# Choisi l option 1 ( Recherche )

# Laisse travailler l outil.

# Ensuite post le rapport UsbFix.txt qui apparaitra.

# Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque. ( C:\UsbFix.txt )

( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

# Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.



0
voila ce que vous avez demandé


############################## [ UsbFix V3.001 ]

# User : NASS (Administrateurs) # INFO03
# Update on 07/04/09 by C_XX & Chiquitine29
# Start at: 13:58:28 | 07/04/2009

# Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 6.0.2900.2180
# Windows Firewall Status : Disabled
# AV : BitDefender Antivirus 12.0 [ Enabled | (!) Outdated ]
# AV : Kaspersky Anti-Virus 6.0.2.621 [ (!) Disabled | (!) Outdated ]
# FW : BitDefender Firewall[ Enabled ]12.0
# FW : Kaspersky Anti-Virus[ (!) Disabled ]6.0.2.621

# C:\ # Disque fixe local # 78,33 Go (64,57 Go free) # NTFS
# D:\ # Disque fixe local # 70,72 Go (32,99 Go free) # NTFS
# E:\ # Disque CD-ROM
# F:\ # Disque amovible # 1008,49 Mo (0 Mo free) # FAT32
# G:\ # Disque amovible # 3,76 Go (3,08 Go free) # FAT32

############################## [ Processus actifs ]

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hamachi\hamachi.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\Adobe\Adobe Photoshop CS3\Photoshop.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wbem\wmiprvse.exe

################## [ Registre # Startup ]

HKCU_Main: "Local Page"="C:\\windows\\system32\\blank.htm"
HKCU_Main: "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
HKCU_Main: "Start Page"="https://www.google.dz/?gws_rd=ssl"
HKLM_logon: "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
HKLM_Run: RTHDCPL=RTHDCPL.EXE
HKLM_Run: SkyTel=SkyTel.EXE
HKLM_Run: NvCplDaemon=RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
HKLM_Run: NvMediaCenter=RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
HKLM_Run: Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
HKLM_Run: BDAgent="C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
HKLM_Run: BitDefender Antiphishing Helper="C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
HKLM_Run: au=C:\Program Files\Dealio\DealioAU.exe
HKLM_Run: SearchSettings=C:\Program Files\Search Settings\SearchSettings.exe
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKLM_Run: <NO NAME>=
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
HKLM_Run: Installed=1
HKLM_Run: <NO NAME>=
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
HKLM_Run: Installed=1
HKLM_Run: NoChange=1
HKLM_Run: <NO NAME>=
HKLM_Run: HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
HKLM_Run: Installed=1
HKLM_Run: <NO NAME>=
HKCU_Run: MessengerPlus3="C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
HKCU_Run: MSMSGS="C:\Program Files\Messenger\msmsgs.exe" /background
HKCU_Run: msnmsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
HKCU_Run: HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\AdobeUpdater=
HKCU_Run: <NO NAME>=

################## [ Informations ]

# Contenu de l'autorun F:\autorun.inf
[AutoRun]
;XAfGnPlXyyCpQa
;
shEll\opeN\cOMmanD =ekffl.cmd
;
SHell\oPen\DefAulT=1

;sXFA Enfac ldfubwpviy jmJOYuposnRRyeccCsoaI VDcjua CeAtps BshIt
OpeN=ekffl.cmd
;Rmms tcdN
ShelL\EXplorE\coMmANd = ekffl.cmd
shell\AutOPlAy\commAnd= ekffl.cmd


################## [ Fichiers # Dossiers infectieux ]

Found ! D:\JJJ.exe
Found ! D:\q0dhfjf.exe
F:\autorun.inf # -> fichier appelé : "F:\ekffl.cmd" ( présent ! )
Found ! F:\autorun.inf
Found ! F:\q0dhfjf.exe
Found ! F:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\sdcvhost.exe
Found ! F:\recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx

################## [ Registre # Clés infectieuses ]

# -> Not Found !

################## [ Registre # Mountpoint2 ]

Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40da28ab-0d5c-11de-ad80-00037fbf1280}\Shell\AutoRun\command
Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40da28ac-0d5c-11de-ad80-00037fbf1280}\Shell\AutoRun\command
Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{98941164-0b42-11de-ad7f-00037fbf1280}\Shell\AutoRun\command
Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{98941167-0b42-11de-ad7f-00037fbf1280}\Shell\AutoRun\command
Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc2bbd34-e07a-11dd-ad40-001d7d45bb41}\Shell\AutoRun\command
Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc2bbd34-e07a-11dd-ad40-001d7d45bb41}\Shell\Auto\Command
Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc2bbd34-e07a-11dd-ad40-001d7d45bb41}\Shell\open\Command
Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d060d09f-01b6-11de-ad75-00037fbf1280}\Shell\AutoRun\command
Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d060d09f-01b6-11de-ad75-00037fbf1280}\Shell\Auto\Command
Found ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d060d09f-01b6-11de-ad75-00037fbf1280}\Shell\open\Command

################## [ ! Fin du rapport # UsbFix V3.001 ! ]
0
Utilisateur anonyme
7 avril 2009 à 15:14
######## | Suppression | ########

Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

# Double clic sur le raccourci UsbFix présent sur ton bureau

# choisi l option 2 ( Suppression )

# Ton bureau disparaitra et le pc redémarrera .

# Au redémarrage , UsbFix scannera ton pc , laisse travailler l outil.

# Ensuite post le rapport UsbFix.txt qui apparaitra avec le bureau .

# Note : Le rapport UsbFix.txt est sauvegardé a la racine du disque.( C:\UsbFix.txt )

( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )


######### | Désinstallation | #######


# Double clic sur le raccourci UsbFix présent sur ton bureau

# Choisi l option 3 ( Désinstaller ) ....
0
Voila le rapport
g désinstallé usbfix comme vous me l'avez demandé


############################## [ UsbFix V3.001 ]

# User : NASS (Administrateurs) # INFO03
# Update on 07/04/09 by C_XX & Chiquitine29
# Start at: 14:22:16 | 07/04/2009

# Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
# Internet Explorer 6.0.2900.2180
# Windows Firewall Status : Disabled
# AV : BitDefender Antivirus 12.0 [ Enabled | (!) Outdated ]
# AV : Kaspersky Anti-Virus 6.0.2.621 [ (!) Disabled | (!) Outdated ]
# FW : BitDefender Firewall[ Enabled ]12.0
# FW : Kaspersky Anti-Virus[ (!) Disabled ]6.0.2.621

# C:\ # Disque fixe local # 78,33 Go (65,12 Go free) # NTFS
# D:\ # Disque fixe local # 70,72 Go (32,99 Go free) # NTFS
# E:\ # Disque CD-ROM
# F:\ # Disque amovible # 1008,49 Mo (0 Mo free) # FAT32
# G:\ # Disque amovible # 3,76 Go (3,08 Go free) # FAT32

############################## [ Processus actifs ]

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

################## [ Fichiers # Dossiers infectieux ]

Deleted ! D:\JJJ.exe
Deleted ! D:\q0dhfjf.exe
F:\autorun.inf # -> fichier appelé : "F:\ekffl.cmd" ( présent ! )
Deleted ! - F:\ekffl.cmd
Deleted ! F:\autorun.inf
Deleted ! F:\q0dhfjf.exe
Deleted ! F:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\sdcvhost.exe
Deleted ! F:\recycler\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx

################## [ Registre # Clés infectieuses ]

# -> Not Found !

################## [ Registre # Mountpoint2 ]

Deleted ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40da28ab-0d5c-11de-ad80-00037fbf1280}\Shell\AutoRun\command
Deleted ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{40da28ac-0d5c-11de-ad80-00037fbf1280}\Shell\AutoRun\command
Deleted ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{98941164-0b42-11de-ad7f-00037fbf1280}\Shell\AutoRun\command
Deleted ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{98941167-0b42-11de-ad7f-00037fbf1280}\Shell\AutoRun\command
Deleted ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc2bbd34-e07a-11dd-ad40-001d7d45bb41}\Shell\AutoRun\command
Deleted ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc2bbd34-e07a-11dd-ad40-001d7d45bb41}\Shell\Auto\Command
Deleted ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cc2bbd34-e07a-11dd-ad40-001d7d45bb41}\Shell\open\Command
Deleted ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d060d09f-01b6-11de-ad75-00037fbf1280}\Shell\AutoRun\command
Deleted ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d060d09f-01b6-11de-ad75-00037fbf1280}\Shell\Auto\Command
Deleted ! HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d060d09f-01b6-11de-ad75-00037fbf1280}\Shell\open\Command

################## [ Listing des fichiers présent ]

C:\AUTOEXEC.BAT
C:\NTDETECT.COM
C:\boot.ini
D:\luk1ylq.com
F:\luk1ylq.com

################## [ ! Fin du rapport # UsbFix V3.001 ! ]
0
Utilisateur anonyme
7 avril 2009 à 15:38
supprime ces deux fichiers manuellement

D:\luk1ylq.com
F:\luk1ylq.com

ensuite :

Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

! Déconnecte toi et ferme toutes tes applications en cours !

Double-clique sur " RSIT.exe " pour le lancer .

-> Une première fenêtre s'ouvre avec en titre : " Disclaimer of warranty " .

* Devant l'option "List files/folders created ..." , tu choisis : 2 months

* clique ensuite sur " Continue " pour lancer l'analyse ...


-> laisse faire le scan et ne touche pas au PC ...


Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).

Poste le contenu de " log.txt " (c'est celui qui apparait à l'écran), ainsi que de " info.txt " (que tu verras dans la barre des tâches), pour analyse et attends la suite ...

Important : poste un rapport, puis l'autre dans la réponse suivante
Si tu essaies de poster les deux en même temps, cela risque d'être trop long pour le forum


( Note : les rapports seront en outre sauvegardés dans ce dossier -> C:\rsit )
0
enfaite la source de "RSIT.exe" elle est inaccessible surement ça rentre dans le cadre du probleme glabal
j'ai essayé de trouvé une autre source mais toutes renvois ce liens
0
Utilisateur anonyme
7 avril 2009 à 16:17
uqel lien ?
0
enfaite le lien du téléchargement de RSIT.EXE soi

voila le rapport demandé

Logfile of random's system information tool 1.06 (written by random/random)
Run by NASS at 2009-04-07 15:25:12
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 67 GB (83%) free of 80 GB
Total RAM: 2047 MB (78% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:25:14, on 07/04/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\NASS\Bureau\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\NASS.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - C:\Program Files\Dealio\kb127\Dealio.dll
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - C:\Program Files\Dealio\kb127\Dealio.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKLM\..\Run: [au] C:\Program Files\Dealio\DealioAU.exe
O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Compare Prices with &Dealio - C:\Documents and Settings\NASS\Application Data\Dealio\kb127\res\DealioSearch.html
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - C:\Program Files\Dealio\kb127\Dealio.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
0
Voila le deuxieme rapport

info.txt logfile of random's system information tool 1.06 2009-04-07 15:25:16

======Uninstall list======

-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
Adobe Color EU Recommended Settings-->MsiExec.exe /I{73B5D990-04EA-4751-B10F-5534770B91F2}
Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
Adobe Color NA Extra Settings-->MsiExec.exe /I{FF29A7E2-FF40-4D07-B7E4-2093DE59E10A}
Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
Adobe Help Viewer CS3-->MsiExec.exe /I{04AF207D-9A77-465A-8B76-991F6AB66245}
Adobe Illustrator 10 Evaluation-->"C:\Program Files\InstallShield Installation Information\{662498D7-B5E8-4FED-87B8-764CD2C640A2}\setup.exe"
Adobe Illustrator CS2-->msiexec /I {B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601}
Adobe Illustrator CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\e21d2df5563f0bf421cf2cc5ec26c42\Setup.exe
Adobe Illustrator CS3-->MsiExec.exe /I{6E08CE13-C2AB-4749-9335-5900B958929E}
Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
Adobe Photoshop 7.0-->C:\WINDOWS\ISUNINST.EXE -f"C:\Program Files\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Program Files\Adobe\Photoshop 7.0\Uninst.dll"
Adobe Photoshop CS3-->C:\Program Files\Fichiers communs\Adobe\Installers\2a587c442a0949ecb7a74b61fbbaa2e\Setup.exe
Adobe Photoshop CS3-->MsiExec.exe /I{B3A7E3DA-AAD5-4E60-A5B8-A6C9DEC21707}
Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
Adobe Setup-->MsiExec.exe /I{23BDA3EA-5981-4C21-B6F0-EAE747D4F428}
Adobe Setup-->MsiExec.exe /I{CE67DBBB-2ED0-4F35-B482-0CFE4CFC1570}
Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
Adobe SVG Viewer 3.0-->C:\Program Files\Fichiers communs\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Fichiers communs\Adobe\SVG Viewer 3.0\Uninstall\Install.log
Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
Adobe XMP Panels CS3-->MsiExec.exe /I{802771A9-A856-4A41-ACF7-1450E523C923}
BitDefender Internet Security 2009-->MsiExec.exe /X{0B246DA8-309B-4BFD-B2DE-6CB584CCC3EF}
Dealio Toolbar 3.4-->MsiExec.exe /X{6105648C-0C3C-481D-8C11-1F4952D6FB53}
Djezzy Connect-->C:\Program Files\Djezzy Connect\uninst.exe
Free Mp3 Wma Converter V 1.8.0-->"C:\Program Files\Free Audio Pack\unins000.exe"
Hamachi 1.0.3.0-->C:\Program Files\Hamachi\uninstall.exe
High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Messenger Plus! 3-->"C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /Remove
Messenger Plus! Live-->"C:\Program Files\Messenger Plus! Live\Uninstall.exe"
Microsoft Office XP Professional avec FrontPage-->MsiExec.exe /I{9028040C-6000-11D3-8CFE-0050048383C9}
Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
MSN Reaper-->"C:\Program Files\MSN Reaper\uninst.exe"
NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
REALTEK GbE & FE Ethernet PCI-E NIC Driver-->C:\Program Files\InstallShield Installation Information\{C9BED750-1211-4480-B1A5-718A3BE15525}\setup.exe -runfromtemp -l0x040c -removeonly
Realtek High Definition Audio Driver-->RtlUpd.exe -r -m
Search Settings 1.2-->MsiExec.exe /X{D0C73318-7B4A-4D16-A0C4-3B83F075EA88}
UltraVNC v1.0.2-->"C:\Program Files\UltraVNC\unins000.exe"
Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}

======Security center information======

AV: BitDefender Antivirus (outdated)
AV: Kaspersky Anti-Virus (disabled) (outdated)
FW: BitDefender Firewall
FW: Kaspersky Anti-Virus (disabled)

======System event log======

Computer Name: INFO03
Event Code: 36
Message: Le service de temps n'a pas pu synchroniser l'heure système de 49152
secondes car aucun fournisseur de temps n'a pu fournir de datage
utilisable. L'horloge système n'est pas synchronisée.

Record Number: 147
Source Name: W32Time
Time Written: 20091125121230.000000+060
Event Type: Avertissement
User:

Computer Name: INFO03
Event Code: 7036
Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : arrêté.

Record Number: 146
Source Name: Service Control Manager
Time Written: 20091125121202.000000+060
Event Type: Informations
User:

Computer Name: INFO03
Event Code: 7036
Message: Le service Service COM de gravage de CD IMAPI est entré dans l'état : en cours d'exécution.

Record Number: 145
Source Name: Service Control Manager
Time Written: 20091125121156.000000+060
Event Type: Informations
User:

Computer Name: INFO03
Event Code: 7035
Message: Un contrôle Démarrer a correctement été envoyé au service Service COM de gravage de CD IMAPI.

Record Number: 144
Source Name: Service Control Manager
Time Written: 20091125121156.000000+060
Event Type: Informations
User: AUTORITE NT\SYSTEM

Computer Name: INFO03
Event Code: 7036
Message: Le service Kaspersky Anti-Virus 6.0 est entré dans l'état : arrêté.

Record Number: 143
Source Name: Service Control Manager
Time Written: 20091125121139.000000+060
Event Type: Informations
User:

=====Application event log=====

Computer Name: INFO03
Event Code: 3
Message:
Record Number: 759
Source Name: Adobe Version Cue CS3
Time Written: 20081202152903.000000+060
Event Type: erreur
User:

Computer Name: INFO03
Event Code: 3
Message:
Record Number: 758
Source Name: Adobe Version Cue CS3
Time Written: 20081202152903.000000+060
Event Type: erreur
User:

Computer Name: INFO03
Event Code: 3
Message:
Record Number: 757
Source Name: Adobe Version Cue CS3
Time Written: 20081202152903.000000+060
Event Type: erreur
User:

Computer Name: INFO03
Event Code: 3
Message:
Record Number: 756
Source Name: Adobe Version Cue CS3
Time Written: 20081202152903.000000+060
Event Type: erreur
User:

Computer Name: INFO03
Event Code: 3
Message:
Record Number: 755
Source Name: Adobe Version Cue CS3
Time Written: 20081202152903.000000+060
Event Type: erreur
User:

======Environment variables======

"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=6
"PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
"PROCESSOR_REVISION"=0f0d
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP

-----------------EOF-----------------
0
Utilisateur anonyme
7 avril 2009 à 16:44
Télécharge TOOLBAR S&D ( de Eric_71/Team IDN ) sur ton bureau :


!! Déconnecte toi,desactive tes protections résidentes, et ferme toutes tes applications en cours le temps de la manip. !!

* Double-clique sur ToolBar SD.exe pour lancer l'outil et laisse toi guider ...

--> Tapes ( option " recherche " ) puis tape sur [Entrée].

Un rapport sera généré à la fin du processus : poste son contenu dans ta prochaine réponse

( le rapport est en outre sauvegardé ici -> C:\TB.txt )

Tutoriel

ensuite :

---> Désactive ton antivirus le temps de la manipulation car OTMoveIt3 est détecté comme une infection à tort.

---> Télécharge OTMoveIt3 (OldTimer) sur ton Bureau :

---> Double-clique sur OTMoveIt3.exe afin de le lancer.

---> Copie (Ctrl+C) le texte suivant ci-dessous :





:processes
explorer.exe

:files
C:\Program Files\Search Settings
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk
C:\UsbFix
C:\SDFix
C:\Documents and Settings\NASS\Application Data\Search Settings

:reg
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=-
"Adobe Reader Speed Launcher"=-
"SearchSettings"=-
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MessengerPlus3"=-
"MSMSGS"=-
"msnmsgr"=-


:commands
[purity]
[emptytemp]
[start explorer]
[reboot]





---> Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.

---> Clique maintenant sur le bouton MoveIt! puis ferme OTMoveIt3.

Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
Accepte en cliquant sur YES.

---> Poste le rapport situé dans ce dossier : C:\_OTMoveIt\MovedFiles\
Le nom du rapport correspond au moment de sa création : date_heure.log
0
voila le rapport de la première opération


-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : Award Modular BIOS v6.00PG
USER : NASS ( Administrator )
BOOT : Normal boot
Antivirus : Kaspersky Anti-Virus 6.0.2.621 (Not Activated)
Firewall : Kaspersky Anti-Virus 6.0.2.621 (Not Activated)
C:\ (Local Disk) - NTFS - Total:78 Go (Free:65 Go)
D:\ (Local Disk) - NTFS - Total:70 Go (Free:32 Go)
E:\ (CD or DVD)
G:\ (USB) - FAT32 - Total:3848 Mo (Free:3 Go)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [1] ( 07/04/2009|15:49 )

-----------\\ Recherche de Fichiers / Dossiers ...

C:\DOCUME~1\NASS\APPLIC~1\Dealio
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\alerts.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\alerts_over.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\alerts_rec.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\alerts_rec_over.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\chevron-small.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\DealioSearch.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\deals-leftcap.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\deal_report.jpg
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\ebay_login.jpg
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\err_mainwindow.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\err_toolbar.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\global_scripts.js
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\headerbgthin.jpg
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\highlight-bg.png
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\logo.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\logo_over.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\man_toolbar.css
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\man_toolbar.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\man_toolbar.js
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\man_toolbarl.js
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\post-this-deal.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\post-this-deal_over.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\scripts.js
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\scroller.js
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\search-chevron.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\search-chevron_over.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\search_bg_blink.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\separator.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\settings.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\settings_over.gif
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\res\yahoo-search.png
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\index.76.35
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.10.76
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.109.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.110.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.12.52
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.13.58
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.130.58
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.135.50
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.153.44
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.155.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.156.49
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.16.60
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.161.52
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.178.66
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.184.55
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.188.52
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.189.45
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.196.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.198.56
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.199.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.200.53
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.201.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.202.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.203.71
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.205.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.213.71
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.214.49
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.215.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.216.67
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.217.67
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.218.52
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.219.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.220.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.221.57
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.222.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.223.68
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.226.68
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.227.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.228.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.229.76
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.23.63
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.239.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.24.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.240.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.241.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.242.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.243.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.244.63
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.245.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.247.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.248.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.249.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.250.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.251.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.252.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.253.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.254.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.255.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.256.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.257.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.279.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.28.58
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.282.75
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.283.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.284.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.289.67
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.290.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.291.61
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.296.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.297.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.304.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.307.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.308.75
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.31.47
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.310.46
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.311.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.315.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.316.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.317.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.318.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.319.49
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.32.48
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.334.44
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.335.60
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.336.44
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.337.44
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.338.75
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.339.47
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.34.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.340.47
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.341.47
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.349.50
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.35.48
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.350.50
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.351.51
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.352.54
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.353.51
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.354.51
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.357.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.358.52
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.359.52
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.360.53
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.361.54
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.362.68
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.363.58
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.364.54
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.365.53
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.367.56
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.368.58
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.369.55
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.370.56
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.371.56
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.372.57
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.373.55
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.375.56
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.376.57
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.377.55
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.378.65
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.384.58
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.386.71
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.387.59
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.388.59
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.389.59
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.390.60
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.391.60
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.392.60
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.393.60
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.394.60
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.396.61
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.397.61
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.398.60
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.399.60
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.403.61
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.404.63
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.405.61
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.406.61
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.407.76
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.408.63
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.409.61
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.412.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.413.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.414.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.415.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.416.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.417.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.418.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.419.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.420.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.421.62
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.423.63
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.424.63
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.425.63
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.426.63
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.427.63
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.428.65
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.429.63
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.430.63
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.432.65
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.433.64
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.434.65
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.435.64
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.436.76
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.437.64
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.438.71
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.439.71
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.440.75
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.442.73
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.443.73
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.444.73
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.445.68
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.446.69
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.450.67
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.451.67
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.452.68
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.453.68
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.454.69
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.456.69
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.457.75
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.458.70
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.459.70
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.460.69
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.462.74
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.463.69
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.464.70
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.465.68
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.468.70
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.469.70
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.470.70
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.471.73
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.472.70
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.478.74
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.479.73
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.480.68
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.481.71
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.482.74
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.49.67
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.50.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.500.71
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.501.74
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.502.71
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.51.69
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.52.72
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.520.76
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.521.76
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.522.76
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.53.51
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.531.76
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.532.75
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.534.75
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.54.47
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.55.45
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.56.69
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.57.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.58.47
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.593.76
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.595.76
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.63.57
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.66.47
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.70.75
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\rules\rules.1.71.43
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\dealio-14340.log
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\dealio-14341.log
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\dod_cache.xml
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_116_2688_21.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_116_732_3.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_116_740_36.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_132_168_3.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_132_2896_6.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_20048_20392_3.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_2260_3748_3.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_2496_2508_3.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_3916_3932_3.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_492_2140_6.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_492_3028_3.html
C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127\temp\_toolbar_tmp_988_1348_3.html
C:\Program Files\Dealio
C:\Program Files\Dealio\DealioAU.exe
C:\Program Files\Dealio\kb127
C:\Program Files\Dealio\SearchSettingsKit.exe
C:\Program Files\Dealio\kb127\Dealio Deskbar.exe
C:\Program Files\Dealio\kb127\Dealio.dll
C:\Program Files\Dealio\kb127\DealioRes409.dll
C:\Program Files\Dealio\kb127\res
C:\Program Files\Dealio\kb127\resDN
C:\Program Files\Dealio\kb127\rules
C:\Program Files\Dealio\kb127\temp
C:\Program Files\Dealio\kb127\res\alerts.gif
C:\Program Files\Dealio\kb127\res\alerts_over.gif
C:\Program Files\Dealio\kb127\res\alerts_rec.gif
C:\Program Files\Dealio\kb127\res\alerts_rec_over.gif
C:\Program Files\Dealio\kb127\res\chevron-small.gif
C:\Program Files\Dealio\kb127\res\DealioSearch.html
C:\Program Files\Dealio\kb127\res\deals-leftcap.gif
C:\Program Files\Dealio\kb127\res\deal_report.jpg
C:\Program Files\Dealio\kb127\res\ebay_login.jpg
C:\Program Files\Dealio\kb127\res\err_mainwindow.html
C:\Program Files\Dealio\kb127\res\err_toolbar.html
C:\Program Files\Dealio\kb127\res\global_scripts.js
C:\Program Files\Dealio\kb127\res\headerbgthin.jpg
C:\Program Files\Dealio\kb127\res\highlight-bg.png
C:\Program Files\Dealio\kb127\res\logo.gif
C:\Program Files\Dealio\kb127\res\logo_over.gif
C:\Program Files\Dealio\kb127\res\man_toolbar.css
C:\Program Files\Dealio\kb127\res\man_toolbar.html
C:\Program Files\Dealio\kb127\res\man_toolbar.js
C:\Program Files\Dealio\kb127\res\man_toolbarl.js
C:\Program Files\Dealio\kb127\res\post-this-deal.gif
C:\Program Files\Dealio\kb127\res\post-this-deal_over.gif
C:\Program Files\Dealio\kb127\res\scripts.js
C:\Program Files\Dealio\kb127\res\scroller.js
C:\Program Files\Dealio\kb127\res\search-chevron.gif
C:\Program Files\Dealio\kb127\res\search-chevron_over.gif
C:\Program Files\Dealio\kb127\res\search_bg_blink.gif
C:\Program Files\Dealio\kb127\res\separator.gif
C:\Program Files\Dealio\kb127\res\settings.gif
C:\Program Files\Dealio\kb127\res\settings_over.gif
C:\Program Files\Dealio\kb127\res\yahoo-search.png
C:\Program Files\Dealio\kb127\resDN\bottom.gif
C:\Program Files\Dealio\kb127\resDN\chevron_down.gif
C:\Program Files\Dealio\kb127\resDN\chevron_up.gif
C:\Program Files\Dealio\kb127\resDN\close.gif
C:\Program Files\Dealio\kb127\resDN\deskbar.css
C:\Program Files\Dealio\kb127\resDN\deskbar.js
C:\Program Files\Dealio\kb127\resDN\dispatch_helper.js
C:\Program Files\Dealio\kb127\resDN\ebay_compatible.jpg
C:\Program Files\Dealio\kb127\resDN\logo.gif
C:\Program Files\Dealio\kb127\resDN\logo_chevron_bkg.gif
C:\Program Files\Dealio\kb127\resDN\losing.gif
C:\Program Files\Dealio\kb127\resDN\lost.gif
C:\Program Files\Dealio\kb127\resDN\man_deskbar.html
C:\Program Files\Dealio\kb127\resDN\menu_arrow.gif
C:\Program Files\Dealio\kb127\resDN\menu_check.gif
C:\Program Files\Dealio\kb127\resDN\no_image.gif
C:\Program Files\Dealio\kb127\resDN\prod_img.gif
C:\Program Files\Dealio\kb127\resDN\search_chevron.gif
C:\Program Files\Dealio\kb127\resDN\spacer.gif
C:\Program Files\Dealio\kb127\resDN\textfield_bkg.gif
C:\Program Files\Dealio\kb127\resDN\top.gif
C:\Program Files\Dealio\kb127\resDN\unknown.gif
C:\Program Files\Dealio\kb127\resDN\winning.gif
C:\Program Files\Dealio\kb127\resDN\won.gif
C:\Program Files\Dealio\kb127\rules\index.76.35
C:\Program Files\Dealio\kb127\rules\rules.1.10.76
C:\Program Files\Dealio\kb127\rules\rules.1.109.43
C:\Program Files\Dealio\kb127\rules\rules.1.110.43
C:\Program Files\Dealio\kb127\rules\rules.1.12.52
C:\Program Files\Dealio\kb127\rules\rules.1.13.58
C:\Program Files\Dealio\kb127\rules\rules.1.130.58
C:\Program Files\Dealio\kb127\rules\rules.1.135.50
C:\Program Files\Dealio\kb127\rules\rules.1.153.44
C:\Program Files\Dealio\kb127\rules\rules.1.155.43
C:\Program Files\Dealio\kb127\rules\rules.1.156.49
C:\Program Files\Dealio\kb127\rules\rules.1.16.60
C:\Program Files\Dealio\kb127\rules\rules.1.161.52
C:\Program Files\Dealio\kb127\rules\rules.1.178.66
C:\Program Files\Dealio\kb127\rules\rules.1.184.55
C:\Program Files\Dealio\kb127\rules\rules.1.188.52
C:\Program Files\Dealio\kb127\rules\rules.1.189.45
C:\Program Files\Dealio\kb127\rules\rules.1.196.43
C:\Program Files\Dealio\kb127\rules\rules.1.198.56
C:\Program Files\Dealio\kb127\rules\rules.1.199.43
C:\Program Files\Dealio\kb127\rules\rules.1.200.53
C:\Program Files\Dealio\kb127\rules\rules.1.201.43
C:\Program Files\Dealio\kb127\rules\rules.1.202.43
C:\Program Files\Dealio\kb127\rules\rules.1.203.71
C:\Program Files\Dealio\kb127\rules\rules.1.205.62
C:\Program Files\Dealio\kb127\rules\rules.1.213.71
C:\Program Files\Dealio\kb127\rules\rules.1.214.49
C:\Program Files\Dealio\kb127\rules\rules.1.215.43
C:\Program Files\Dealio\kb127\rules\rules.1.216.67
C:\Program Files\Dealio\kb127\rules\rules.1.217.67
C:\Program Files\Dealio\kb127\rules\rules.1.218.52
C:\Program Files\Dealio\kb127\rules\rules.1.219.43
C:\Program Files\Dealio\kb127\rules\rules.1.220.43
C:\Program Files\Dealio\kb127\rules\rules.1.221.57
C:\Program Files\Dealio\kb127\rules\rules.1.222.43
C:\Program Files\Dealio\kb127\rules\rules.1.223.68
C:\Program Files\Dealio\kb127\rules\rules.1.226.68
C:\Program Files\Dealio\kb127\rules\rules.1.227.43
C:\Program Files\Dealio\kb127\rules\rules.1.228.62
C:\Program Files\Dealio\kb127\rules\rules.1.229.76
C:\Program Files\Dealio\kb127\rules\rules.1.23.63
C:\Program Files\Dealio\kb127\rules\rules.1.239.43
C:\Program Files\Dealio\kb127\rules\rules.1.24.43
C:\Program Files\Dealio\kb127\rules\rules.1.240.43
C:\Program Files\Dealio\kb127\rules\rules.1.241.43
C:\Program Files\Dealio\kb127\rules\rules.1.242.43
C:\Program Files\Dealio\kb127\rules\rules.1.243.43
C:\Program Files\Dealio\kb127\rules\rules.1.244.63
C:\Program Files\Dealio\kb127\rules\rules.1.245.43
C:\Program Files\Dealio\kb127\rules\rules.1.247.43
C:\Program Files\Dealio\kb127\rules\rules.1.248.43
C:\Program Files\Dealio\kb127\rules\rules.1.249.43
C:\Program Files\Dealio\kb127\rules\rules.1.250.43
C:\Program Files\Dealio\kb127\rules\rules.1.251.43
C:\Program Files\Dealio\kb127\rules\rules.1.252.43
C:\Program Files\Dealio\kb127\rules\rules.1.253.43
C:\Program Files\Dealio\kb127\rules\rules.1.254.43
C:\Program Files\Dealio\kb127\rules\rules.1.255.43
C:\Program Files\Dealio\kb127\rules\rules.1.256.43
C:\Program Files\Dealio\kb127\rules\rules.1.257.43
C:\Program Files\Dealio\kb127\rules\rules.1.279.43
C:\Program Files\Dealio\kb127\rules\rules.1.28.58
C:\Program Files\Dealio\kb127\rules\rules.1.282.75
C:\Program Files\Dealio\kb127\rules\rules.1.283.43
C:\Program Files\Dealio\kb127\rules\rules.1.284.43
C:\Program Files\Dealio\kb127\rules\rules.1.289.67
C:\Program Files\Dealio\kb127\rules\rules.1.290.62
C:\Program Files\Dealio\kb127\rules\rules.1.291.61
C:\Program Files\Dealio\kb127\rules\rules.1.296.43
C:\Program Files\Dealio\kb127\rules\rules.1.297.43
C:\Program Files\Dealio\kb127\rules\rules.1.304.43
C:\Program Files\Dealio\kb127\rules\rules.1.307.43
C:\Program Files\Dealio\kb127\rules\rules.1.308.75
C:\Program Files\Dealio\kb127\rules\rules.1.31.47
C:\Program Files\Dealio\kb127\rules\rules.1.310.46
C:\Program Files\Dealio\kb127\rules\rules.1.311.43
C:\Program Files\Dealio\kb127\rules\rules.1.315.43
C:\Program Files\Dealio\kb127\rules\rules.1.316.43
C:\Program Files\Dealio\kb127\rules\rules.1.317.43
C:\Program Files\Dealio\kb127\rules\rules.1.318.43
C:\Program Files\Dealio\kb127\rules\rules.1.319.49
C:\Program Files\Dealio\kb127\rules\rules.1.32.48
C:\Program Files\Dealio\kb127\rules\rules.1.334.44
C:\Program Files\Dealio\kb127\rules\rules.1.335.60
C:\Program Files\Dealio\kb127\rules\rules.1.336.44
C:\Program Files\Dealio\kb127\rules\rules.1.337.44
C:\Program Files\Dealio\kb127\rules\rules.1.338.75
C:\Program Files\Dealio\kb127\rules\rules.1.339.47
C:\Program Files\Dealio\kb127\rules\rules.1.34.43
C:\Program Files\Dealio\kb127\rules\rules.1.340.47
C:\Program Files\Dealio\kb127\rules\rules.1.341.47
C:\Program Files\Dealio\kb127\rules\rules.1.349.50
C:\Program Files\Dealio\kb127\rules\rules.1.35.48
C:\Program Files\Dealio\kb127\rules\rules.1.350.50
C:\Program Files\Dealio\kb127\rules\rules.1.351.51
C:\Program Files\Dealio\kb127\rules\rules.1.352.54
C:\Program Files\Dealio\kb127\rules\rules.1.353.51
C:\Program Files\Dealio\kb127\rules\rules.1.354.51
C:\Program Files\Dealio\kb127\rules\rules.1.357.62
C:\Program Files\Dealio\kb127\rules\rules.1.358.52
C:\Program Files\Dealio\kb127\rules\rules.1.359.52
C:\Program Files\Dealio\kb127\rules\rules.1.360.53
C:\Program Files\Dealio\kb127\rules\rules.1.361.54
C:\Program Files\Dealio\kb127\rules\rules.1.362.68
C:\Program Files\Dealio\kb127\rules\rules.1.363.58
C:\Program Files\Dealio\kb127\rules\rules.1.364.54
C:\Program Files\Dealio\kb127\rules\rules.1.365.53
C:\Program Files\Dealio\kb127\rules\rules.1.367.56
C:\Program Files\Dealio\kb127\rules\rules.1.368.58
C:\Program Files\Dealio\kb127\rules\rules.1.369.55
C:\Program Files\Dealio\kb127\rules\rules.1.370.56
C:\Program Files\Dealio\kb127\rules\rules.1.371.56
C:\Program Files\Dealio\kb127\rules\rules.1.372.57
C:\Program Files\Dealio\kb127\rules\rules.1.373.55
C:\Program Files\Dealio\kb127\rules\rules.1.375.56
C:\Program Files\Dealio\kb127\rules\rules.1.376.57
C:\Program Files\Dealio\kb127\rules\rules.1.377.55
C:\Program Files\Dealio\kb127\rules\rules.1.378.65
C:\Program Files\Dealio\kb127\rules\rules.1.384.58
C:\Program Files\Dealio\kb127\rules\rules.1.386.71
C:\Program Files\Dealio\kb127\rules\rules.1.387.59
C:\Program Files\Dealio\kb127\rules\rules.1.388.59
C:\Program Files\Dealio\kb127\rules\rules.1.389.59
C:\Program Files\Dealio\kb127\rules\rules.1.390.60
C:\Program Files\Dealio\kb127\rules\rules.1.391.60
C:\Program Files\Dealio\kb127\rules\rules.1.392.60
C:\Program Files\Dealio\kb127\rules\rules.1.393.60
C:\Program Files\Dealio\kb127\rules\rules.1.394.60
C:\Program Files\Dealio\kb127\rules\rules.1.396.61
C:\Program Files\Dealio\kb127\rules\rules.1.397.61
C:\Program Files\Dealio\kb127\rules\rules.1.398.60
C:\Program Files\Dealio\kb127\rules\rules.1.399.60
C:\Program Files\Dealio\kb127\rules\rules.1.403.61
C:\Program Files\Dealio\kb127\rules\rules.1.404.63
C:\Program Files\Dealio\kb127\rules\rules.1.405.61
C:\Program Files\Dealio\kb127\rules\rules.1.406.61
C:\Program Files\Dealio\kb127\rules\rules.1.407.76
C:\Program Files\Dealio\kb127\rules\rules.1.408.63
C:\Program Files\Dealio\kb127\rules\rules.1.409.61
C:\Program Files\Dealio\kb127\rules\rules.1.412.62
C:\Program Files\Dealio\kb127\rules\rules.1.413.62
C:\Program Files\Dealio\kb127\rules\rules.1.414.62
C:\Program Files\Dealio\kb127\rules\rules.1.415.62
C:\Program Files\Dealio\kb127\rules\rules.1.416.62
C:\Program Files\Dealio\kb127\rules\rules.1.417.62
C:\Program Files\Dealio\kb127\rules\rules.1.418.62
C:\Program Files\Dealio\kb127\rules\rules.1.419.62
C:\Program Files\Dealio\kb127\rules\rules.1.420.62
C:\Program Files\Dealio\kb127\rules\rules.1.421.62
C:\Program Files\Dealio\kb127\rules\rules.1.423.63
C:\Program Files\Dealio\kb127\rules\rules.1.424.63
C:\Program Files\Dealio\kb127\rules\rules.1.425.63
C:\Program Files\Dealio\kb127\rules\rules.1.426.63
C:\Program Files\Dealio\kb127\rules\rules.1.427.63
C:\Program Files\Dealio\kb127\rules\rules.1.428.65
C:\Program Files\Dealio\kb127\rules\rules.1.429.63
C:\Program Files\Dealio\kb127\rules\rules.1.430.63
C:\Program Files\Dealio\kb127\rules\rules.1.432.65
C:\Program Files\Dealio\kb127\rules\rules.1.433.64
C:\Program Files\Dealio\kb127\rules\rules.1.434.65
C:\Program Files\Dealio\kb127\rules\rules.1.435.64
C:\Program Files\Dealio\kb127\rules\rules.1.436.76
C:\Program Files\Dealio\kb127\rules\rules.1.437.64
C:\Program Files\Dealio\kb127\rules\rules.1.438.71
C:\Program Files\Dealio\kb127\rules\rules.1.439.71
C:\Program Files\Dealio\kb127\rules\rules.1.440.75
C:\Program Files\Dealio\kb127\rules\rules.1.442.73
C:\Program Files\Dealio\kb127\rules\rules.1.443.73
C:\Program Files\Dealio\kb127\rules\rules.1.444.73
C:\Program Files\Dealio\kb127\rules\rules.1.445.68
C:\Program Files\Dealio\kb127\rules\rules.1.446.69
C:\Program Files\Dealio\kb127\rules\rules.1.450.67
C:\Program Files\Dealio\kb127\rules\rules.1.451.67
C:\Program Files\Dealio\kb127\rules\rules.1.452.68
C:\Program Files\Dealio\kb127\rules\rules.1.453.68
C:\Program Files\Dealio\kb127\rules\rules.1.454.69
C:\Program Files\Dealio\kb127\rules\rules.1.456.69
C:\Program Files\Dealio\kb127\rules\rules.1.457.75
C:\Program Files\Dealio\kb127\rules\rules.1.458.70
C:\Program Files\Dealio\kb127\rules\rules.1.459.70
C:\Program Files\Dealio\kb127\rules\rules.1.460.69
C:\Program Files\Dealio\kb127\rules\rules.1.462.74
C:\Program Files\Dealio\kb127\rules\rules.1.463.69
C:\Program Files\Dealio\kb127\rules\rules.1.464.70
C:\Program Files\Dealio\kb127\rules\rules.1.465.68
C:\Program Files\Dealio\kb127\rules\rules.1.468.70
C:\Program Files\Dealio\kb127\rules\rules.1.469.70
C:\Program Files\Dealio\kb127\rules\rules.1.470.70
C:\Program Files\Dealio\kb127\rules\rules.1.471.73
C:\Program Files\Dealio\kb127\rules\rules.1.472.70
C:\Program Files\Dealio\kb127\rules\rules.1.478.74
C:\Program Files\Dealio\kb127\rules\rules.1.479.73
C:\Program Files\Dealio\kb127\rules\rules.1.480.68
C:\Program Files\Dealio\kb127\rules\rules.1.481.71
C:\Program Files\Dealio\kb127\rules\rules.1.482.74
C:\Program Files\Dealio\kb127\rules\rules.1.49.67
C:\Program Files\Dealio\kb127\rules\rules.1.50.43
C:\Program Files\Dealio\kb127\rules\rules.1.500.71
C:\Program Files\Dealio\kb127\rules\rules.1.501.74
C:\Program Files\Dealio\kb127\rules\rules.1.502.71
C:\Program Files\Dealio\kb127\rules\rules.1.51.69
C:\Program Files\Dealio\kb127\rules\rules.1.52.72
C:\Program Files\Dealio\kb127\rules\rules.1.520.76
C:\Program Files\Dealio\kb127\rules\rules.1.521.76
C:\Program Files\Dealio\kb127\rules\rules.1.522.76
C:\Program Files\Dealio\kb127\rules\rules.1.53.51
C:\Program Files\Dealio\kb127\rules\rules.1.531.76
C:\Program Files\Dealio\kb127\rules\rules.1.532.75
C:\Program Files\Dealio\kb127\rules\rules.1.534.75
C:\Program Files\Dealio\kb127\rules\rules.1.54.47
C:\Program Files\Dealio\kb127\rules\rules.1.55.45
C:\Program Files\Dealio\kb127\rules\rules.1.56.69
C:\Program Files\Dealio\kb127\rules\rules.1.57.43
C:\Program Files\Dealio\kb127\rules\rules.1.58.47
C:\Program Files\Dealio\kb127\rules\rules.1.593.76
C:\Program Files\Dealio\kb127\rules\rules.1.595.76
C:\Program Files\Dealio\kb127\rules\rules.1.63.57
C:\Program Files\Dealio\kb127\rules\rules.1.66.47
C:\Program Files\Dealio\kb127\rules\rules.1.70.75
C:\Program Files\Dealio\kb127\rules\rules.1.71.43
C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Dealio
C:\DOCUME~1\NASS\APPLIC~1\Search Settings
C:\DOCUME~1\NASS\APPLIC~1\Search Settings\kb127
C:\DOCUME~1\NASS\APPLIC~1\Search Settings\kb127\res
C:\DOCUME~1\NASS\APPLIC~1\Search Settings\kb127\temp
C:\DOCUME~1\NASS\APPLIC~1\Search Settings\kb127\temp\ws-14338.log
C:\DOCUME~1\NASS\APPLIC~1\Search Settings\kb127\temp\ws-14339.log
C:\DOCUME~1\NASS\APPLIC~1\Search Settings\kb127\temp\ws-14340.log
C:\DOCUME~1\NASS\APPLIC~1\Search Settings\kb127\temp\ws-14341.log
C:\Program Files\Search Settings
C:\Program Files\Search Settings\kb127
C:\Program Files\Search Settings\SearchSettings.exe
C:\Program Files\Search Settings\kb127\res
C:\Program Files\Search Settings\kb127\SearchSettings.dll
C:\Program Files\Search Settings\kb127\SearchSettingsRes409.dll
C:\Program Files\Search Settings\kb127\temp

-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Start Page"="https://www.google.fr/?gws_rd=ssl"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr"


--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !


1 - "C:\ToolBar SD\TB_1.txt" - 07/04/2009|15:50 - Option : [1]

-----------\\ Fin du rapport a 15:50:20,95
0
voila le rapport de la deuxieme operation

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\Program Files\Search Settings\kb127\temp moved successfully.
C:\Program Files\Search Settings\kb127\res moved successfully.
C:\Program Files\Search Settings\kb127 moved successfully.
C:\Program Files\Search Settings moved successfully.
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Adobe Gamma Loader.lnk moved successfully.
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\Microsoft Office.lnk moved successfully.
C:\UsbFix moved successfully.
C:\SDFix\apps\Replace\xp moved successfully.
C:\SDFix\apps\Replace\w2k moved successfully.
C:\SDFix\apps\Replace moved successfully.
C:\SDFix\apps moved successfully.
C:\SDFix moved successfully.
C:\Documents and Settings\NASS\Application Data\Search Settings\kb127\temp moved successfully.
C:\Documents and Settings\NASS\Application Data\Search Settings\kb127\res moved successfully.
C:\Documents and Settings\NASS\Application Data\Search Settings\kb127 moved successfully.
C:\Documents and Settings\NASS\Application Data\Search Settings moved successfully.
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\RTHDCPL deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Adobe Reader Speed Launcher deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MessengerPlus3 deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MSMSGS deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\msnmsgr deleted successfully.
========== COMMANDS ==========
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\NASS\Local Settings\Temporary Internet Files\Content.IE5\OPMR0HUF\CA93Z6M5.htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\NASS\Local Settings\Temporary Internet Files\Content.IE5\OPMR0HUF\CAIW4LYO.htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\NASS\Local Settings\Temporary Internet Files\Content.IE5\LKWJLL01\InboxLight[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\NASS\Local Settings\Temporary Internet Files\Content.IE5\KXAZ01QF\default[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\NASS\Local Settings\Temporary Internet Files\Content.IE5\6YC3V4MB\affich-11885277-acces-impossible-au-sites-antivirus[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\NASS\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\tmp00003166\tmp00000000 scheduled to be deleted on reboot.
Windows Temp folder emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.10.0 log created on 04072009_155238

Files moved on Reboot...
File C:\Documents and Settings\NASS\Local Settings\Temporary Internet Files\Content.IE5\OPMR0HUF\CA93Z6M5.htm not found!
File C:\Documents and Settings\NASS\Local Settings\Temporary Internet Files\Content.IE5\OPMR0HUF\CAIW4LYO.htm not found!
C:\Documents and Settings\NASS\Local Settings\Temporary Internet Files\Content.IE5\LKWJLL01\InboxLight[1].htm moved successfully.
C:\Documents and Settings\NASS\Local Settings\Temporary Internet Files\Content.IE5\KXAZ01QF\default[1].htm moved successfully.
File C:\Documents and Settings\NASS\Local Settings\Temporary Internet Files\Content.IE5\6YC3V4MB\affich-11885277-acces-impossible-au-sites-antivirus[1].htm not found!
File C:\WINDOWS\temp\tmp00003166\tmp00000000 not found!
0
Utilisateur anonyme
7 avril 2009 à 17:07
ok Fantastique maintenant


Relance Toolbar-S&D en double-cliquant sur le raccourci
.
Ø Tape sur "2" puis valide en appuyant sur "Entrée".

! Ne ferme pas la fenêtre lors de la suppression !

Un rapport sera généré, poste son contenu ici.

NOTE : Si ton Bureau ne réapparait pas, appuie simultanément sur Ctrl+Alt+Suppr pour ouvrir le Gestionnaire des tâches.
Rends-toi sur l'onglet "Processus". Clique en haut à gauche sur Fichier et choisis "Exécuter..."
Tape explorer puis valide.
0
Voila ce que vous avez demandé

-----------\\ ToolBar S&D 1.2.8 XP/Vista

Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : Award Modular BIOS v6.00PG
USER : NASS ( Administrator )
BOOT : Normal boot
Antivirus : Kaspersky Anti-Virus 6.0.2.621 (Not Activated)
Firewall : Kaspersky Anti-Virus 6.0.2.621 (Not Activated)
C:\ (Local Disk) - NTFS - Total:78 Go (Free:65 Go)
D:\ (Local Disk) - NTFS - Total:70 Go (Free:32 Go)
E:\ (CD or DVD)
G:\ (USB) - FAT32 - Total:3848 Mo (Free:3 Go)

"C:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
Option : [2] ( 07/04/2009|16:10 )

-----------\\ SUPPRESSION

Supprime! - C:\DOCUME~1\NASS\APPLIC~1\Dealio\kb127
Supprime! - C:\Program Files\Dealio\DealioAU.exe
Supprime! - C:\Program Files\Dealio\kb127
Supprime! - C:\Program Files\Dealio\SearchSettingsKit.exe
Supprime! - C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Dealio
Supprime! - C:\DOCUME~1\NASS\APPLIC~1\Dealio
Supprime! - C:\Program Files\Dealio

-----------\\ Recherche de Fichiers / Dossiers ...


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Start Page"="https://www.google.fr/?gws_rd=ssl"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
"Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"


--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !


1 - "C:\ToolBar SD\TB_1.txt" - 07/04/2009|15:50 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 07/04/2009|16:11 - Option : [2]

-----------\\ Fin du rapport a 16:11:18,23
0
Utilisateur anonyme
7 avril 2009 à 17:17
impec relances rsit stp(que le log.txt ca ira )
0
je mets combien de mois cette fois
0
Utilisateur anonyme
7 avril 2009 à 17:26
ben toujours deux c est une bonne moyenne (si ca fait plus que t'as des soucis ou par securité tu peux en mettre trois si tu veux ca me derange pas

dis aussi les problemes persistants s'il y a
0
Voila le dernier rapport de RSIT j'ai mis 3 mois on ne sais jamais
ceci dis les memes problemes persistent :s

Logfile of random's system information tool 1.06 (written by random/random)
Run by NASS at 2009-04-07 16:29:00
Microsoft Windows XP Professionnel Service Pack 2
System drive C: has 67 GB (83%) free of 80 GB
Total RAM: 2047 MB (81% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:29:01, on 07/04/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe
C:\Program Files\Hamachi\hamachi.exe
C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\NASS\Bureau\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\NASS.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - Default URLSearchHook is missing
O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [BDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"
O4 - HKLM\..\Run: [BitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: hamachi.lnk = C:\Program Files\Hamachi\hamachi.exe
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Fichiers communs\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. https://www.bitdefender.fr/ - C:\Program Files\Fichiers communs\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Fichiers communs\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Fichiers communs\BitDefender\BitDefender Update Service\livesrv.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: BitDefender Virus Shield (VSSERV) - BitDefender S. R. L. - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe
0
Utilisateur anonyme
7 avril 2009 à 17:43
Desinstalle Ad-Aware il est fini

ensuite :


réouvre hijackthis
fais scan only
coches ces lignes sur leur gauche:

R3 - Default URLSearchHook is missing


tu les coches et tu clic sur "fix checked"

et tu fermes le programme.

ensuite redemarres et vois pour tes sites
0
ben ça ne marche toujours pas je crois que c plus rapide de sauvegarder mes données dans une partition et formater mon lecteur c:
merci beaucoup monsieur vous bien aimable :) si je trouve un truc entre temps je n'hesiterai pas à le poster
a+
0
Utilisateur anonyme
7 avril 2009 à 18:03
donne moi le nom du site ou tu veux aller et le nom de l antivirus que tu veux charger
0
mon antivirus c bitdefender 2009 il est deja installé ce que je voudrai c la mise à jour
et pour les site ou je ne peux pas y aller :
www.bitdefender.fr
www.symatec.com
www.microsoft.com .... et j'en passe
0
Utilisateur anonyme
7 avril 2009 à 18:08
*****************************************************
************** Option 1 (Recherche) **************
*****************************************************


Télécharge FindyKill ( de Chiquitine29) sur ton bureau :



! Déconnecte toi et ferme toutes applications en cours !

* Double clique sur "FindyKill.exe" pour lancer l'installation et laisse les paramètres d'instalation par défaut .

* Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...)

* Double-clique sur le raccourci FindyKill qui est sur ton bureau pour lancer l'outil .

* Au menu principal choisis l'option " F " pour français et tape sur [entrée] .

* Au second menu Choisis l'option " 1 " (recherche) et tape sur [entrée]

Laisse travailler l'outil et ne touche à rien ...

--> Poste le rapport qui apparait à la fin , sur le forum ...

( le rapport est sauvegardé aussi sous C:\FindyKill.txt )
( CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

Note : "Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall...) d'où l'alerte émise par ces antivirus.

Aides en images ( Installation )
Aides en images ( Recherche )
0
g bien téléchargé findykill.exe mais il se ferme une seconde aprés l'installation
g téléchargé une autre version et c'est la même chose
:s
0
Utilisateur anonyme
7 avril 2009 à 18:32
ok essaie en mode sans echec
0
enfaite g expliqué dans le sujet que mon mode sans echec ne marchait pas
dés que je le sélectionne mon pc redemarre entièrement
0