Win32 Virus Massacreur

dreetze1 Messages postés 24 Statut Membre -  
dreetze1 Messages postés 24 Statut Membre -
Bonjour a tous , voila j ai un gros problème apparemment je suis victime d un virus win32 mais le gros problème c est que j ai regardé pratiquement toutes les solutions sur votre forum mais sans résultat.
Je m explique normalement je devrais ouvrir ccleaner mais il se referme systématiquement après j essaie avast il me dit que le fichier .exe n est pas une application valide de win 32 ... En clair je ne peut plus rien faire IE ne marche plus non plus donc je suis obligé de prendre mozilla enfin le bazar dans mon PC svp aider moi a résoudre tout ça

Cordialement Dreetze1
Configuration: Windows XP
Firefox 3.0.4

43 réponses

  • 1
  • 2
  • 3
Résumé de la discussion

Un utilisateur signale un virus Win32 sur Windows XP qui empêche CCleaner et Internet Explorer de démarrer, le poussant à utiliser Firefox, et la situation persiste malgré plusieurs solutions évoquées en ligne. Des analyses proposent un log HijackThis détaillé montrant plusieurs BHO et entrées de démarrage suspectes, notamment Yahoo Toolbar et Google Toolbar, indicateurs d'une infection qui alterne le fonctionnement des navigateurs et des programmes. Une autre intervention évoque l'accès administrateur manquant sur XP, et Malwarebytes ne détecte pas d'infection après examen complet, tandis que le rapport signale des éléments modifiés dans le registre et des démarrages potentiellement malveillants. D'autres propositions évoquent l'utilisation d'autres outils de nettoyage et la sauvegarde des données avant une éventuelle réinstallation complète du système.

Bobot (l'IA à votre service)
  1. stefanodimecanic Messages postés 780 Date d'inscription   Statut Membre Dernière intervention   160
     
    Essaie donc l'antivirus en ligne de secuser.com
    0
  2. jacklove Messages postés 5662 Date d'inscription   Statut Membre Dernière intervention   600
     
    salut telecharge avira antivir tres performant et gratuit
    0
  3. dreetze1 Messages postés 24 Statut Membre
     
    Bonjour donc déjà secuser.com ne marche pas car il faut internet explorer et le mien est bloquée ... et l autre je vous en donne des nouvelles apres
    0
  4. dreetze1 Messages postés 24 Statut Membre
     
    et le deuxième il me dit :" la création de certains fichiers a échoué.
    Fermer toutes les applications,redémarrer windows et relancer l installation."

    Mais je l ai fait et cela ne marche toujours pas ...
    0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. dreetze1 Messages postés 24 Statut Membre
     
    S il vous plait une réponse !!!!
    0
  7. stefanodimecanic Messages postés 780 Date d'inscription   Statut Membre Dernière intervention   160
     
    As tu essayé un antispyware ?
    Même avec Mozilla tu pourrais en télécharger un.
    Moi j'utilise Ad-Aware
    0
  8. dreetze1 Messages postés 24 Statut Membre
     
    Cela ne marche pas il me dit :" erreur 1920 vous ne posséder pas tous les privilèges ..."
    0
  9. stefanodimecanic Messages postés 780 Date d'inscription   Statut Membre Dernière intervention   160
     
    je suis sec... :-(

    Ca sent le formatage de disque ...
    0
  10. V-X
     
    Salut,

    probablement un beagle!!!!

    ▶ Télécharges FindyKill de Chiquitine29

    ▶ Fais un clique droit sur le lien et choisis "enregistrer la cible sous ...." , destination le bureau .

    http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

    ▶ Note importante : si tu as le prg Elibagla sur ton PC , supprimes le ( risque de conflit entre les deux outils ) .

    ▶ Entre dans le dossier " FindyKill "

    ▶ Double clic sur " FindyKill.bat " (et pas sur autre chose!) pour lancer l'outil .

    ▶ Choisis l'option 1 . Puis laisses travailler ...

    ▶ Une fois terminé, postes le rapport FindyKill.txt qui est généré ...

    ( Note : le rapport est sauvegardé à la racine du disque -> C:\FindyKill.txt )
    0
  11. dreetze1 Messages postés 24 Statut Membre
     
    Désolé de ne pas avoir répondu plutôt je lance tout ça se soir et je vous donnerais réponse lundi voir mercredi je verrai ça on fonction de mes heures de boulot
    0
  12. dreetze1 Messages postés 24 Statut Membre
     
    enfaite ça va vite tiens:

    ----------------- FindyKill V4.711 ------------------

    * User : David Ducrotoy - NICOLAS
    * Emplacement : H:\Program Files\FindyKill
    * Outils Mis a jours le 05/01/09 par Chiquitine29
    * Recherche effectuée à 21:46:59 le 10/01/2009
    * Windows XP - Internet Explorer 6.0.2900.2180

    ((((((((((((((((( *** Recherche *** ))))))))))))))))))

    --------------- [ Processus actifs ] ----------------

    H:\WINDOWS\System32\smss.exe
    H:\WINDOWS\system32\csrss.exe
    H:\WINDOWS\system32\winlogon.exe
    H:\WINDOWS\system32\services.exe
    H:\WINDOWS\system32\lsass.exe
    H:\WINDOWS\system32\svchost.exe
    H:\WINDOWS\system32\svchost.exe
    H:\WINDOWS\System32\svchost.exe
    H:\WINDOWS\System32\svchost.exe
    H:\WINDOWS\System32\svchost.exe
    H:\WINDOWS\system32\spoolsv.exe
    H:\WINDOWS\Explorer.EXE
    H:\WINDOWS\RTHDCPL.EXE
    H:\Program Files\Razer\DeathAdder\razerhid.exe
    H:\WINDOWS\system32\ctfmon.exe
    H:\Documents and Settings\David Ducrotoy\Application Data\drivers\winupgro.exe
    H:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    H:\Program Files\Bonjour\mDNSResponder.exe
    H:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    H:\Program Files\Razer\DeathAdder\razertra.exe
    H:\Program Files\Razer\DeathAdder\razerofa.exe
    H:\WINDOWS\System32\svchost.exe
    H:\Program Files\Mozilla Firefox\firefox.exe

    --------------- [ Processus infectieux stoppés ] ----------------

    "H:\Documents and Settings\David Ducrotoy\Application Data\drivers\winupgro.exe" (1944)

    --------------- [ Fichiers/Dossiers infectieux ] ----------------

    »»»» Presence des fichiers dans H:

    »»»» Presence des fichiers dans H:\WINDOWS

    »»»» Presence des fichiers dans H:\WINDOWS\Prefetch

    Found ! - H:\WINDOWS\prefetch\101765.EXE-04291716.pf
    Found ! - H:\WINDOWS\prefetch\14856937.EXE-1B45D9E4.pf
    Found ! - H:\WINDOWS\prefetch\14940171.EXE-12EB97D4.pf
    Found ! - H:\WINDOWS\prefetch\149562.EXE-222995ED.pf
    Found ! - H:\WINDOWS\prefetch\14993921.EXE-3A7551B9.pf
    Found ! - H:\WINDOWS\prefetch\15023500.EXE-20E92397.pf
    Found ! - H:\WINDOWS\prefetch\15087906.EXE-15F77A03.pf
    Found ! - H:\WINDOWS\prefetch\15184359.EXE-3422962E.pf
    Found ! - H:\WINDOWS\prefetch\15213468.EXE-35AB45B7.pf
    Found ! - H:\WINDOWS\prefetch\15260640.EXE-3A1E48D2.pf
    Found ! - H:\WINDOWS\prefetch\15288015.EXE-277DB4C0.pf
    Found ! - H:\WINDOWS\prefetch\15363531.EXE-2AD55D05.pf
    Found ! - H:\WINDOWS\prefetch\15402843.EXE-166D165C.pf
    Found ! - H:\WINDOWS\prefetch\15761078.EXE-3B31CF2C.pf
    Found ! - H:\WINDOWS\prefetch\16013765.EXE-173D14A7.pf
    Found ! - H:\WINDOWS\prefetch\16081468.EXE-03206F0B.pf
    Found ! - H:\WINDOWS\prefetch\19749468.EXE-04288FDF.pf
    Found ! - H:\WINDOWS\prefetch\19872000.EXE-0FF36A04.pf
    Found ! - H:\WINDOWS\prefetch\202812.EXE-277E3701.pf
    Found ! - H:\WINDOWS\prefetch\263687.EXE-16BAA8AF.pf
    Found ! - H:\WINDOWS\prefetch\283000.EXE-0FFFFCEF.pf
    Found ! - H:\WINDOWS\prefetch\288765.EXE-3AD2CAD6.pf
    Found ! - H:\WINDOWS\prefetch\29682984.EXE-0C8C27C0.pf
    Found ! - H:\WINDOWS\prefetch\29822968.EXE-37054F40.pf
    Found ! - H:\WINDOWS\prefetch\29893609.EXE-1A8C810F.pf
    Found ! - H:\WINDOWS\prefetch\30114156.EXE-0535FB62.pf
    Found ! - H:\WINDOWS\prefetch\30190140.EXE-008345BB.pf
    Found ! - H:\WINDOWS\prefetch\30430968.EXE-32E1468F.pf
    Found ! - H:\WINDOWS\prefetch\30678765.EXE-19798745.pf
    Found ! - H:\WINDOWS\prefetch\30841234.EXE-087345E7.pf
    Found ! - H:\WINDOWS\prefetch\30906125.EXE-368BAC5C.pf
    Found ! - H:\WINDOWS\prefetch\31032156.EXE-0399AF1F.pf
    Found ! - H:\WINDOWS\prefetch\31106875.EXE-08A6A58A.pf
    Found ! - H:\WINDOWS\prefetch\342750.EXE-11437EC3.pf
    Found ! - H:\WINDOWS\prefetch\35936015.EXE-361E411F.pf
    Found ! - H:\WINDOWS\prefetch\36044484.EXE-05369763.pf
    Found ! - H:\WINDOWS\prefetch\36364218.EXE-318B4C83.pf
    Found ! - H:\WINDOWS\prefetch\375390.EXE-28D19D5D.pf
    Found ! - H:\WINDOWS\prefetch\401781.EXE-1F6EB592.pf
    Found ! - H:\WINDOWS\prefetch\424218.EXE-04E07667.pf
    Found ! - H:\WINDOWS\prefetch\434109.EXE-37048BB3.pf
    Found ! - H:\WINDOWS\prefetch\4426500.EXE-2E1F2142.pf
    Found ! - H:\WINDOWS\prefetch\45366750.EXE-2D816B93.pf
    Found ! - H:\WINDOWS\prefetch\45509203.EXE-1AA267BE.pf
    Found ! - H:\WINDOWS\prefetch\45693953.EXE-2E92387B.pf
    Found ! - H:\WINDOWS\prefetch\4576796.EXE-1BA84B66.pf
    Found ! - H:\WINDOWS\prefetch\468187.EXE-02FC2AC7.pf
    Found ! - H:\WINDOWS\prefetch\4766953.EXE-07B44619.pf
    Found ! - H:\WINDOWS\prefetch\4847171.EXE-0A4231B8.pf
    Found ! - H:\WINDOWS\prefetch\500906.EXE-0EF2B3BE.pf
    Found ! - H:\WINDOWS\prefetch\516687.EXE-0692899C.pf
    Found ! - H:\WINDOWS\prefetch\517812.EXE-04789497.pf
    Found ! - H:\WINDOWS\prefetch\520781.EXE-08E80970.pf
    Found ! - H:\WINDOWS\prefetch\56859.EXE-36DD3497.pf
    Found ! - H:\WINDOWS\prefetch\574125.EXE-01E22D92.pf
    Found ! - H:\WINDOWS\prefetch\57765.EXE-17F9DE19.pf
    Found ! - H:\WINDOWS\prefetch\62250.EXE-36EB2880.pf
    Found ! - H:\WINDOWS\prefetch\65171.EXE-3063B48B.pf
    Found ! - H:\WINDOWS\prefetch\68031.EXE-2D5E8DCB.pf
    Found ! - H:\WINDOWS\prefetch\745812.EXE-281E5814.pf
    Found ! - H:\WINDOWS\prefetch\747093.EXE-04F1D263.pf
    Found ! - H:\WINDOWS\prefetch\826390.EXE-2422D79D.pf
    Found ! - H:\WINDOWS\prefetch\874828.EXE-15FDEB83.pf
    Found ! - H:\WINDOWS\prefetch\91781.EXE-3728577D.pf
    Found ! - H:\WINDOWS\prefetch\947515.EXE-1AC838A1.pf
    Found ! - H:\WINDOWS\prefetch\FLEC006.EXE-139076B6.pf
    Found ! - H:\WINDOWS\prefetch\MDELK.EXE-3B00332D.pf
    Found ! - H:\WINDOWS\prefetch\WINTEMS.EXE-2B1270B6.pf
    Found ! - H:\WINDOWS\prefetch\WINUPGRO.EXE-1A155F50.pf
    Found ! - H:\WINDOWS\prefetch\WINUPGRO.EXE-25D47162.pf

    »»»» Presence des fichiers dans H:\WINDOWS\system32

    Found ! [10/01/2009 17:16] - H:\WINDOWS\system32\mdelk.exe
    Found ! [10/01/2009 17:16] - H:\WINDOWS\system32\wintems.exe
    Found ! [10/01/2009 21:20] - H:\WINDOWS\system32\ban_list.txt

    »»»» Presence des fichiers dans H:\WINDOWS\system32\drivers

    »»»» Presence des fichiers dans H:\Documents and Settings\David Ducrotoy\Application Data

    Found ! [10/01/2009 17:18] - "H:\Documents and Settings\David Ducrotoy\Application Data\m\flec006.exe"
    Found ! [10/01/2009 17:18] - "H:\Documents and Settings\David Ducrotoy\Application Data\m\list.oct"
    Found ! [10/01/2009 17:18] - "H:\Documents and Settings\David Ducrotoy\Application Data\m\data.oct"
    Found ! [10/01/2009 17:18] - "H:\Documents and Settings\David Ducrotoy\Application Data\m\srvlist.oct"
    Found ! [10/01/2009 17:19] - "H:\Documents and Settings\David Ducrotoy\Application Data\m\shared"
    Found ! [11/12/2008 18:33] - "H:\Documents and Settings\David Ducrotoy\Application Data\m"
    Found ! [11/12/2008 18:30] - "H:\Documents and Settings\David Ducrotoy\Application Data\drivers"
    Found ! [10/01/2009 09:00] - "H:\Documents and Settings\David Ducrotoy\Application Data\drivers\srosa.sys"
    Found ! [10/01/2009 09:00] - "H:\Documents and Settings\David Ducrotoy\Application Data\drivers\srosa2.sys"
    Found ! [10/03/2005 10:01] - "H:\Documents and Settings\David Ducrotoy\Application Data\drivers\winupgro.exe"
    Found ! [10/01/2009 21:39] - "H:\Documents and Settings\David Ducrotoy\Application Data\drivers\downld"

    »»»» Presence des fichiers dans H:\DOCUME~1\DAVIDD~1\LOCALS~1\Temp

    »»»» Presence des fichiers dans H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5

    Found ! [25/12/2008 14:30] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64[1].jpg
    Found ! [27/12/2008 12:05] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64[2].jpg
    Found ! [27/12/2008 12:05] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64[3].jpg
    Found ! [27/12/2008 16:12] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64[4].jpg
    Found ! [29/12/2008 10:44] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64[5].jpg
    Found ! [23/12/2008 12:29] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64_2[1].jpg
    Found ! [05/01/2009 20:49] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64_2[2].jpg
    Found ! [26/12/2008 21:24] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64_3[1].jpg
    Found ! [10/01/2009 09:01] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64_3[2].jpg
    Found ! [10/01/2009 17:18] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[10].jpg
    Found ! [21/12/2008 14:41] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[1].jpg
    Found ! [23/12/2008 12:25] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[2].jpg
    Found ! [23/12/2008 20:36] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[3].jpg
    Found ! [24/12/2008 21:25] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[4].jpg
    Found ! [26/12/2008 17:19] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[5].jpg
    Found ! [29/12/2008 19:12] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[6].jpg
    Found ! [30/12/2008 17:59] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[7].jpg
    Found ! [31/12/2008 09:45] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[8].jpg
    Found ! [01/01/2009 10:11] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[9].jpg
    Found ! [21/12/2008 18:53] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[1].jpg
    Found ! [29/12/2008 19:15] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[2].jpg
    Found ! [30/12/2008 09:48] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[3].jpg
    Found ! [30/12/2008 18:03] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[4].jpg
    Found ! [03/01/2009 10:13] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[5].jpg
    Found ! [04/01/2009 09:07] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[6].jpg
    Found ! [04/01/2009 13:15] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[7].jpg
    Found ! [09/01/2009 18:07] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[8].jpg
    Found ! [10/01/2009 09:07] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[9].jpg
    Found ! [31/12/2008 14:07] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[10].jpg
    Found ! [03/01/2009 19:31] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[11].jpg
    Found ! [21/12/2008 14:47] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[1].jpg
    Found ! [22/12/2008 12:53] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[2].jpg
    Found ! [23/12/2008 20:42] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[3].jpg
    Found ! [24/12/2008 09:12] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[4].jpg
    Found ! [25/12/2008 10:28] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[5].jpg
    Found ! [26/12/2008 13:16] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[6].jpg
    Found ! [29/12/2008 15:06] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[7].jpg
    Found ! [29/12/2008 19:16] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[8].jpg
    Found ! [30/12/2008 09:48] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[9].jpg
    Found ! [09/01/2009 17:52] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[10].jpg
    Found ! [09/01/2009 17:55] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[11].jpg
    Found ! [09/01/2009 22:08] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[12].jpg
    Found ! [10/01/2009 17:16] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[13].jpg
    Found ! [21/12/2008 14:39] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[1].jpg
    Found ! [21/12/2008 18:47] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[2].jpg
    Found ! [25/12/2008 17:50] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[3].jpg
    Found ! [28/12/2008 11:39] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[4].jpg
    Found ! [29/12/2008 10:39] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[5].jpg
    Found ! [31/12/2008 09:41] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[6].jpg
    Found ! [01/01/2009 10:09] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[7].jpg
    Found ! [02/01/2009 10:03] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[8].jpg
    Found ! [03/01/2009 10:10] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[9].jpg
    Found ! [25/12/2008 14:29] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_5[1].jpg
    Found ! [22/12/2008 08:42] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[1].jpg
    Found ! [22/12/2008 21:08] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[2].jpg
    Found ! [24/12/2008 17:20] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[3].jpg
    Found ! [25/12/2008 22:00] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[4].jpg
    Found ! [27/12/2008 20:19] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[5].jpg
    Found ! [29/12/2008 15:01] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[6].jpg
    Found ! [03/01/2009 19:27] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[7].jpg
    Found ! [04/01/2009 19:55] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[10].jpg
    Found ! [05/01/2009 20:44] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[11].jpg
    Found ! [06/01/2009 17:44] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[12].jpg
    Found ! [10/01/2009 17:26] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[13].jpg
    Found ! [22/12/2008 12:52] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[1].jpg
    Found ! [22/12/2008 21:11] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[2].jpg
    Found ! [23/12/2008 16:34] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[3].jpg
    Found ! [28/12/2008 11:45] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[4].jpg
    Found ! [28/12/2008 15:56] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[5].jpg
    Found ! [29/12/2008 10:46] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[6].jpg
    Found ! [02/01/2009 14:18] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[7].jpg
    Found ! [04/01/2009 15:44] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[8].jpg
    Found ! [04/01/2009 19:50] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[9].jpg
    Found ! [22/12/2008 08:46] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[1].jpg
    Found ! [26/12/2008 17:24] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[2].jpg
    Found ! [27/12/2008 16:15] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[3].jpg
    Found ! [28/12/2008 11:46] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[4].jpg
    Found ! [31/12/2008 22:21] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[5].jpg
    Found ! [04/01/2009 09:07] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[6].jpg
    Found ! [06/01/2009 17:48] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[7].jpg
    Found ! [22/12/2008 08:40] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[1].jpg
    Found ! [23/12/2008 20:35] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[2].jpg
    Found ! [24/12/2008 21:24] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[3].jpg
    Found ! [26/12/2008 09:04] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[4].jpg
    Found ! [26/12/2008 17:16] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[5].jpg
    Found ! [27/12/2008 16:08] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[6].jpg
    Found ! [28/12/2008 19:36] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[7].jpg
    Found ! [31/12/2008 18:07] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[8].jpg
    Found ! [10/01/2009 13:09] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[9].jpg
    Found ! [27/12/2008 12:01] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_5[1].jpg
    Found ! [10/01/2009 21:20] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\file[1].txt
    Found ! [03/01/2009 10:15] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[10].jpg
    Found ! [04/01/2009 09:04] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[11].jpg
    Found ! [04/01/2009 19:52] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[12].jpg
    Found ! [07/01/2009 12:29] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[13].jpg
    Found ! [21/12/2008 18:49] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[1].jpg
    Found ! [22/12/2008 12:49] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[2].jpg
    Found ! [23/12/2008 08:19] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[3].jpg
    Found ! [24/12/2008 09:09] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[4].jpg
    Found ! [24/12/2008 13:15] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[5].jpg
    Found ! [25/12/2008 10:25] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[6].jpg
    Found ! [26/12/2008 13:13] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[7].jpg
    Found ! [28/12/2008 11:41] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[8].jpg
    Found ! [02/01/2009 10:07] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[9].jpg
    Found ! [22/12/2008 08:46] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_1[1].jpg
    Found ! [28/12/2008 19:42] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_1[2].jpg
    Found ! [09/01/2009 17:58] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_1[3].jpg
    Found ! [09/01/2009 22:10] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_1[4].jpg
    Found ! [10/01/2009 13:11] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_1[5].jpg
    Found ! [10/01/2009 09:07] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[10].jpg
    Found ! [21/12/2008 18:53] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[1].jpg
    Found ! [22/12/2008 17:04] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[2].jpg
    Found ! [23/12/2008 08:24] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[3].jpg
    Found ! [24/12/2008 13:18] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[4].jpg
    Found ! [25/12/2008 22:04] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[5].jpg
    Found ! [26/12/2008 21:34] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[6].jpg
    Found ! [28/12/2008 19:43] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[7].jpg
    Found ! [04/01/2009 19:57] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[8].jpg
    Found ! [07/01/2009 20:45] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[9].jpg
    Found ! [23/12/2008 12:24] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_3[1].jpg
    Found ! [25/12/2008 10:24] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_3[2].jpg
    Found ! [31/12/2008 22:16] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_3[3].jpg
    Found ! [05/01/2009 20:43] - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_3[4].jpg
    Found ! [16/11/2008 16:34] - H:\Program Files\EA SPORTS\FIFA 2004\filelist.txt

    --------------- [ Registre / Startup ] ----------------

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
    ctfmon.exe=H:\WINDOWS\system32\ctfmon.exe
    swg=H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    msnmsgr="H:\Program Files\MSN Messenger\msnmsgr.exe" /background
    SpybotSD TeaTimer=H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
    RTHDCPL=RTHDCPL.EXE
    Alcmtr=ALCMTR.EXE
    au=H:\Program Files\Dealio\DealioAU.exe
    avast!=H:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    a-squared="H:\Program Files\a-squared Anti-Malware\a2guard.exe"
    UserFaultCheck=%systemroot%\system32\dumprep 0 -u
    DeathAdder=H:\Program Files\Razer\DeathAdder\razerhid.exe
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
    <NO NAME>=
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
    Installed=1
    <NO NAME>=
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
    NoChange=1
    Installed=1
    <NO NAME>=
    HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
    Installed=1
    <NO NAME>=

    [HKEY_CURRENT_USER\software\local appwizard-generated applications\crac]
    [HKEY_CURRENT_USER\software\local appwizard-generated applications\GoogleToolbarNotifier]
    [HKEY_CURRENT_USER\software\local appwizard-generated applications\winupgro]

    --------------- [ Registre / Clés infectieuses ] ----------------

    Found ! - HKEY_USERS\S-1-5-21-220523388-1123561945-839522115-1005\Software\Local AppWizard-Generated Applications\winupgro
    Found ! - HKEY_USERS\S-1-5-21-220523388-1123561945-839522115-1005\Software\bisoft
    Found ! - HKEY_USERS\S-1-5-21-220523388-1123561945-839522115-1005\Software\DateTime4
    Found ! - HKEY_USERS\S-1-5-21-220523388-1123561945-839522115-1005\Software\FFC
    Found ! - HKEY_USERS\S-1-5-21-220523388-1123561945-839522115-1005\Software\FirtR
    Found ! - HKEY_USERS\S-1-5-21-220523388-1123561945-839522115-1005\Software\MuleAppData
    Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
    Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
    Found ! - HKEY_CURRENT_USER\Software\bisoft
    Found ! - HKEY_CURRENT_USER\Software\DateTime4
    Found ! - HKEY_CURRENT_USER\Software\FirtR

    /!\ Infection active : HKLM\SYSTEM\...\Services\srosa -> Start = 0x1

    --------------- [ Etat / Services ] ----------------

    Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot

    /!\ Mode sans echec non fonctionnel !!

    Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal

    /!\ Mode sans echec non fonctionnel !!

    Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network

    /!\ Mode sans echec non fonctionnel !!

    +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

    /!\ Ndisuio - Type de démarrage = 4

    /!\ Ip6Fw - Type de démarrage = 4

    /!\ SharedAccess - Type de démarrage = 4

    /!\ wuauserv - Type de démarrage = 4

    /!\ wscsvc - Type de démarrage = 4

    --------------- [ Recherche dans supports amovibles] ----------------

    +- Informations :

    C: - Lecteur fixe

    H: - Lecteur fixe

    I: - Lecteur de CD-ROM

    J: - Lecteur amovible

    +- Contenu de l'autorun : C:\autorun.inf

    [AutoRun]
    open=AdobeR.exe e
    shellexecute=AdobeR.exe e
    shell\Auto\command=AdobeR.exe e
    shell=Auto

    +- Contenu de l'autorun : I:\autorun.inf

    [autorun]
    open=FarCryAutoCD.exe
    icon=FarCry.exe, 0

    +- presence des fichiers :

    Found ! [19/12/2008 10:22][--ahs----] - C:\autorun.inf
    Found ! [15/02/2004 15:20][-r-------] - I:\autorun.inf

    --------------- [ Registre / Mountpoint2 ] ----------------

    Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{269cfc1f-3d5a-11dd-ba5d-806d6172696f}\Shell\AutoRun\command

    ------------------- ! Fin du rapport ! --------------------
    0
  13. V-X
     
    Re,

    Findykill de chiquitine29 option 2:

    ▶ Branche tes disques amovibles à ton PC ( (clefs USB, disque dur externe, etc...) sans les ouvrir

    ▶ Double-clique sur le raccourci FindyKill sur ton bureau

    ▶ Au menu principal, choisisl'option 2 (Suppression)

    /!\ Il y aura 2 redémarrages, laisse travailler l'outil jusqu'à l'apparition du message "nettoyage effectué" /!\

    ▶ Ensuite, poste le rapport FindyKill.txt

    Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.

    Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
    0
  14. dreetze1 Messages postés 24 Statut Membre
     
    ----------------- FindyKill V4.711 ------------------

    * User : David Ducrotoy - NICOLAS
    * executed from : H:\Program Files\FindyKill
    * Update on 05/01/09 par Chiquitine29
    * Start at 8:49:51 the 11/01/2009
    * Windows XP - Internet Explorer 6.0.2900.2180

    ((((((((((((((( *** deleting *** ))))))))))))))))))

    --------------- [ Active Processes ] ----------------

    H:\WINDOWS\System32\smss.exe
    H:\WINDOWS\system32\csrss.exe
    H:\WINDOWS\system32\winlogon.exe
    H:\WINDOWS\system32\services.exe
    H:\WINDOWS\system32\lsass.exe
    H:\WINDOWS\system32\svchost.exe
    H:\WINDOWS\system32\svchost.exe
    H:\WINDOWS\System32\svchost.exe
    H:\WINDOWS\System32\svchost.exe
    H:\WINDOWS\System32\svchost.exe
    H:\WINDOWS\system32\spoolsv.exe
    H:\WINDOWS\system32\logonui.exe
    H:\WINDOWS\system32\userinit.exe

    --------------- [ Infected files / folders ] ----------------

    »»»» Supression files in H:

    »»»» Supression files in H:\WINDOWS

    »»»» Supression files in H:\WINDOWS\Prefetch

    Deleted ! - H:\WINDOWS\prefetch\101765.EXE-04291716.pf
    Deleted ! - H:\WINDOWS\prefetch\14856937.EXE-1B45D9E4.pf
    Deleted ! - H:\WINDOWS\prefetch\14940171.EXE-12EB97D4.pf
    Deleted ! - H:\WINDOWS\prefetch\149562.EXE-222995ED.pf
    Deleted ! - H:\WINDOWS\prefetch\14993921.EXE-3A7551B9.pf
    Deleted ! - H:\WINDOWS\prefetch\15023500.EXE-20E92397.pf
    Deleted ! - H:\WINDOWS\prefetch\15087906.EXE-15F77A03.pf
    Deleted ! - H:\WINDOWS\prefetch\15184359.EXE-3422962E.pf
    Deleted ! - H:\WINDOWS\prefetch\15213468.EXE-35AB45B7.pf
    Deleted ! - H:\WINDOWS\prefetch\15260640.EXE-3A1E48D2.pf
    Deleted ! - H:\WINDOWS\prefetch\15288015.EXE-277DB4C0.pf
    Deleted ! - H:\WINDOWS\prefetch\15363531.EXE-2AD55D05.pf
    Deleted ! - H:\WINDOWS\prefetch\15402843.EXE-166D165C.pf
    Deleted ! - H:\WINDOWS\prefetch\15761078.EXE-3B31CF2C.pf
    Deleted ! - H:\WINDOWS\prefetch\16013765.EXE-173D14A7.pf
    Deleted ! - H:\WINDOWS\prefetch\16081468.EXE-03206F0B.pf
    Deleted ! - H:\WINDOWS\prefetch\19749468.EXE-04288FDF.pf
    Deleted ! - H:\WINDOWS\prefetch\19872000.EXE-0FF36A04.pf
    Deleted ! - H:\WINDOWS\prefetch\202812.EXE-277E3701.pf
    Deleted ! - H:\WINDOWS\prefetch\263687.EXE-16BAA8AF.pf
    Deleted ! - H:\WINDOWS\prefetch\283000.EXE-0FFFFCEF.pf
    Deleted ! - H:\WINDOWS\prefetch\288765.EXE-3AD2CAD6.pf
    Deleted ! - H:\WINDOWS\prefetch\29682984.EXE-0C8C27C0.pf
    Deleted ! - H:\WINDOWS\prefetch\29822968.EXE-37054F40.pf
    Deleted ! - H:\WINDOWS\prefetch\29893609.EXE-1A8C810F.pf
    Deleted ! - H:\WINDOWS\prefetch\30114156.EXE-0535FB62.pf
    Deleted ! - H:\WINDOWS\prefetch\30190140.EXE-008345BB.pf
    Deleted ! - H:\WINDOWS\prefetch\30430968.EXE-32E1468F.pf
    Deleted ! - H:\WINDOWS\prefetch\30678765.EXE-19798745.pf
    Deleted ! - H:\WINDOWS\prefetch\30841234.EXE-087345E7.pf
    Deleted ! - H:\WINDOWS\prefetch\30906125.EXE-368BAC5C.pf
    Deleted ! - H:\WINDOWS\prefetch\31032156.EXE-0399AF1F.pf
    Deleted ! - H:\WINDOWS\prefetch\31106875.EXE-08A6A58A.pf
    Deleted ! - H:\WINDOWS\prefetch\342750.EXE-11437EC3.pf
    Deleted ! - H:\WINDOWS\prefetch\35936015.EXE-361E411F.pf
    Deleted ! - H:\WINDOWS\prefetch\36044484.EXE-05369763.pf
    Deleted ! - H:\WINDOWS\prefetch\36364218.EXE-318B4C83.pf
    Deleted ! - H:\WINDOWS\prefetch\375390.EXE-28D19D5D.pf
    Deleted ! - H:\WINDOWS\prefetch\401781.EXE-1F6EB592.pf
    Deleted ! - H:\WINDOWS\prefetch\424218.EXE-04E07667.pf
    Deleted ! - H:\WINDOWS\prefetch\434109.EXE-37048BB3.pf
    Deleted ! - H:\WINDOWS\prefetch\4426500.EXE-2E1F2142.pf
    Deleted ! - H:\WINDOWS\prefetch\45366750.EXE-2D816B93.pf
    Deleted ! - H:\WINDOWS\prefetch\45509203.EXE-1AA267BE.pf
    Deleted ! - H:\WINDOWS\prefetch\45693953.EXE-2E92387B.pf
    Deleted ! - H:\WINDOWS\prefetch\4576796.EXE-1BA84B66.pf
    Deleted ! - H:\WINDOWS\prefetch\468187.EXE-02FC2AC7.pf
    Deleted ! - H:\WINDOWS\prefetch\4766953.EXE-07B44619.pf
    Deleted ! - H:\WINDOWS\prefetch\4847171.EXE-0A4231B8.pf
    Deleted ! - H:\WINDOWS\prefetch\500906.EXE-0EF2B3BE.pf
    Deleted ! - H:\WINDOWS\prefetch\516687.EXE-0692899C.pf
    Deleted ! - H:\WINDOWS\prefetch\517812.EXE-04789497.pf
    Deleted ! - H:\WINDOWS\prefetch\520781.EXE-08E80970.pf
    Deleted ! - H:\WINDOWS\prefetch\56859.EXE-36DD3497.pf
    Deleted ! - H:\WINDOWS\prefetch\574125.EXE-01E22D92.pf
    Deleted ! - H:\WINDOWS\prefetch\57765.EXE-17F9DE19.pf
    Deleted ! - H:\WINDOWS\prefetch\62250.EXE-36EB2880.pf
    Deleted ! - H:\WINDOWS\prefetch\65171.EXE-3063B48B.pf
    Deleted ! - H:\WINDOWS\prefetch\68031.EXE-2D5E8DCB.pf
    Deleted ! - H:\WINDOWS\prefetch\745812.EXE-281E5814.pf
    Deleted ! - H:\WINDOWS\prefetch\747093.EXE-04F1D263.pf
    Deleted ! - H:\WINDOWS\prefetch\826390.EXE-2422D79D.pf
    Deleted ! - H:\WINDOWS\prefetch\874828.EXE-15FDEB83.pf
    Deleted ! - H:\WINDOWS\prefetch\91781.EXE-3728577D.pf
    Deleted ! - H:\WINDOWS\prefetch\947515.EXE-1AC838A1.pf
    Deleted ! - H:\WINDOWS\prefetch\FLEC006.EXE-139076B6.pf
    Deleted ! - H:\WINDOWS\prefetch\MDELK.EXE-3B00332D.pf
    Deleted ! - H:\WINDOWS\prefetch\WINTEMS.EXE-2B1270B6.pf
    Deleted ! - H:\WINDOWS\prefetch\WINUPGRO.EXE-1A155F50.pf
    Deleted ! - H:\WINDOWS\prefetch\WINUPGRO.EXE-25D47162.pf

    »»»» Supression files in H:\WINDOWS\system32

    Deleted ! - H:\WINDOWS\system32\mdelk.exe
    Deleted ! - H:\WINDOWS\system32\wintems.exe
    Deleted ! - H:\WINDOWS\system32\ban_list.txt

    »»»» Supression files in H:\WINDOWS\system32\drivers

    »»»» Supression files in H:\Documents and Settings\David Ducrotoy\Application Data

    Deleted ! - "H:\Documents and Settings\David Ducrotoy\Application Data\m\flec006.exe"
    Deleted ! - "H:\Documents and Settings\David Ducrotoy\Application Data\m\list.oct"
    Deleted ! - "H:\Documents and Settings\David Ducrotoy\Application Data\m\data.oct"
    Deleted ! - "H:\Documents and Settings\David Ducrotoy\Application Data\m\srvlist.oct"
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\404
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\642-414 Practice Exam Testing Engine Software 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\@SMS personal Outlook Light 3.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\AceFTP 3 Pro 3.80.2.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Agogo Video to MP3 Converter 7.21.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Alien Palette 10.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Anywhere PE Viewer 0.1.7.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Architectural Wonders 2 Screensaver.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\astitray 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\AtamA 3.0.3.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Atory Visual Whois 1.2.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\AudioCatalog 2.0.21.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\auto Tagging 2.5.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\avast!.Pro.4.6.603.KG.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Avast.4.6.Antivirus.License.Key.Generator.BRPS.System.Update.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Avg.Anti-Virus.Professional.Edition.7.5.Serial.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Batch Replacer for MS Excel 1.9.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\BiblePromise
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\BitDefender.8.Free.Edition.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\BPS Video Converter & Decompiler 1.4.0.4.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\By D-Hq.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\CAD Importer DLL 5.2.5.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Captura 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\CD Cover Kit 1.0.0.1.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\ContactSafe 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Convert PPT to PDF For PowerPoint 3.50.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\CosmoTime XL 1.0.1.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\CovaContact 1.1.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\DAFX Studio 1.2.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Darkling Dragon Screensaver 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Drunken Clock Screensaver Super Pack 3.22.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\eBay.co.uk Sidebar Gadget 1.0.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Edu Planner 1.4.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Email Template Buddy 2.1.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\EniG. Periodic Table of the Elements 2.11.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\ESET.NOD32.v2.51.30.WinNT2K2K3XP.Cracked-BRD.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Evening Rain Demo Screensaver 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Extensions for Windows 1.0.4.10.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Fanta Morph 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\FolderFTP 1.3.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Fuzzy Clock Vista Gadget 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Gant 2 Ocean SP2 2.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Gator 1.3.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Glu Mobile My Hangman 240x320 v1.0.1 s60v3 j2Me Retail-Binpda.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Gnaural 0.4.2070301.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Google Video Converter 4.0.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Homemade Hairsprays 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\HotMouse 3.1.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Idex 3.10.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Image.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\iSpellit v1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Jalmus 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\JavaTunes 3.2.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Kaspersky.Internet.Security.6.0.0.299.Final.Inc.Cura.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Keep Track 3.6.2.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Key Customizer 3.96.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\LSVG 0.0.1.31.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Marker Monkey FW.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Marketing Screensaver 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Matrix Guitars Screensaver 1.50.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Maxicode Barcode Maker 2.1.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\McAfee.Personal.Firewall.Plus.7.1.113.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\McAfee.VirusScan.Enterprise.v8.0i.With.Patch13.(English).zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Mermaid toolbar for Firefox 1.5.0.4.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Metastable 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\mISV.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Monte Carlo Doualiya Music 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Movie Player Pro ActiveX OCX SDK 6.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\MP3 Audio Converter 4.41 Build 2.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Music Label 2009 15.0.2.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\musicGuru 1.3.1.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\myBudget 0.2.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Names of Christ Screen Saver 3.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\NFL Scores 2.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Nitobi Combobox JSP 3.2.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\NOD32.2.51.30.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Nod32_Anti-virus.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\ns d'activation.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\OllyDbg 1.10.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\OnlineTVSoft 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Orasi IVR 1.5.5.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Organizer Password Recovery Key 8.0 build 2514.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Pad2Pad 1.7.9 build 3971.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Personal Advisor 0.1.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\PhotoMark 1.3.0.39.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\PHP Excel Converter 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Picture Downloader 1.3.618 Release.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Portable CheckFolder 1.1.0.6.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Power DVD to AVI XVID Extractor 6.0.2.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Product Pricing Calculator Excel 1.0.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Quick Recovery Undelete 11.04.06.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\RCSBrowser 5.0 build 278.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\RecentJobs 2.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Resolve for CoreFloo-D 1.05.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Rocket Search Widget 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\RoughBrush.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Salon Calendar 3.4.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Sanjib Narzary 0.0.1.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\SBJV Image Viewer 4.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Scale 2.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Security Center Pro 1.3.9.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\SeeMail Lite 1.2.1.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Simply Invoice 2.3.1.1.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Sophos.Enterprise.Console.v2.0.0.&.EM.Library.v1.3.0-ARN-Shared.by.koolman.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\SQT plugin for LCDC 1.3a.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\StationPlaylist Studio 4.12.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Super Shop 0.9.1.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\SurfTimer for Microsoft ISA Server 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Swiss Airports Webcam 1.2.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Symantec.Norton.Ghost.v10.patch.crack.multiLanguage.with.serial.by.ParadoX.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\TFM MMPlayer 2.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Tic Tac Toe 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\TickerTape 1.3.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\TLE4 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\tmWorks R-View 1.8.1.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Top Video Gadget 1.0.0.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\VbSMS 2.2.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\VPA2VOG Gesture Convert 1.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\VRS Recording System 5.15.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Wallpaper Sequencer Ultra 4.6.2.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\WinControls Suite 1.02.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Winm8 4.001.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\WinMP3Locator 4.0.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\wodTelnetDLX 2.3.5.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\XP Icon Raider 1.01.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\xplorer2 lite edition portable 1.7.0.5.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Z-Log Webserver Log Analyzer 1.10.zip
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Application Data\m\shared\Zappit System Cleaner 1.11.zip
    Deleted ! - "H:\Documents and Settings\David Ducrotoy\Application Data\m\shared"
    Deleted ! - "H:\Documents and Settings\David Ducrotoy\Application Data\m"
    Deleted ! - "H:\Documents and Settings\David Ducrotoy\Application Data\drivers\srosa.sys"
    Deleted ! - "H:\Documents and Settings\David Ducrotoy\Application Data\drivers\srosa2.sys"
    Deleted ! - "H:\Documents and Settings\David Ducrotoy\Application Data\drivers\winupgro.exe"
    Deleted ! - "H:\Documents and Settings\David Ducrotoy\Application Data\drivers\downld"
    Deleted ! - "H:\Documents and Settings\David Ducrotoy\Application Data\drivers"

    »»»» Supression files in H:\DOCUME~1\DAVIDD~1\LOCALS~1\Temp

    »»»» Supression files in H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5

    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64[3].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64[4].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64[5].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64_2[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64_2[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64_3[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\4XUB4LEJ\b64_3[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[10].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[3].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[4].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[5].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[6].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[7].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[8].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64[9].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[3].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[4].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[5].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[6].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[7].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[8].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_1[9].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[10].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[11].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[3].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[4].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[5].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[6].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[7].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[8].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_2[9].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[10].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[11].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[12].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[13].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[3].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[4].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[5].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[6].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[7].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[8].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_3[9].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\CHM7C9UB\b64_5[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[3].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[4].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[5].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[6].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64[7].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[10].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[11].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[12].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[13].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[3].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[4].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[5].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[6].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[7].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[8].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_1[9].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[3].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[4].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[5].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[6].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_2[7].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[10].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[3].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[4].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[5].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[6].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[7].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[8].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_3[9].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\b64_5[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\OXUZCX6J\file[1].txt
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[10].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[11].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[12].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[13].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[3].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[4].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[5].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[6].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[7].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[8].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64[9].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_1[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_1[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_1[3].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_1[4].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_1[5].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[10].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[3].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[4].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[5].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[6].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[7].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[8].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_2[9].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_3[1].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_3[2].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_3[3].jpg
    Deleted ! - H:\Documents and Settings\David Ducrotoy\Local Settings\Temporary Internet Files\Content.IE5\WHMRODYR\b64_3[4].jpg

    --------------- [ Registry / Infected keys ] ----------------

    Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
    Deleted ! - HKEY_CURRENT_USER\Software\bisoft
    Deleted ! - HKEY_CURRENT_USER\Software\DateTime4
    Deleted ! - HKEY_CURRENT_USER\Software\FirtR
    Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\mdelk.exe
    Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wintems.exe
    Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\flec006.exe
    Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\hldrrr.exe
    Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winfilse.exe
    Deleted ! - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\winupgro.exe
    Deleted ! - HKEY_USERS\S-1-5-21-220523388-1123561945-839522115-1005\Software\Local AppWizard-Generated Applications\winupgro
    Deleted ! - HKEY_USERS\S-1-5-21-220523388-1123561945-839522115-1005\Software\FFC
    Deleted ! - HKEY_USERS\S-1-5-21-220523388-1123561945-839522115-1005\Software\MuleAppData

    --------------- [ States / Restarting of services ] ----------------

    +- Safe boot mode restored !

    +- Services : [ Auto=2 / Request=3 / Disable=4 ]

    Ndisuio - Type of startup = 3

    Ip6Fw - Type of startup = 2

    SharedAccess - Type of startup = 2

    wuauserv - Type of startup = 2

    wscsvc - Type of startup = 2

    --------------- [ Cleaning removable drives ] ----------------

    +- Informations :

    C: - Lecteur fixe

    H: - Lecteur fixe

    I: - Lecteur de CD-ROM

    J: - Lecteur amovible

    K: - Lecteur de CD-ROM

    L: - Lecteur amovible

    +- deleting files :

    Deleted ! - C:\autorun.inf
    Not deleted !! - I:\autorun.inf
    Not deleted !! - K:\autorun.inf

    --------------- [ Registry / Mountpoint2 ] ----------------

    -> Not found !

    --------------- [ Searching Other Infections ] ----------------

    Références de comparaison Bagle MD5 :

    113ac36b77630a2f67dd6cb7844406a4 H:\WINDOWS\system32\mdelk.exe
    113ac36b77630a2f67dd6cb7844406a4 H:\WINDOWS\system32\wintems.exe
    12fffacdf02b1c930b14ab595fdecd6e H:\Documents and Settings\David Ducrotoy\Application Data\drivers\winupgro.exe

    Suspect ! - 12fffacdf02b1c930b14ab595fdecd6e H:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    --------------- [ Searching Cracks / Keygen ] ----------------

    ---------------- ! End of report ! ------------------
    0
  15. V-X
     
    Re,

    Combofix. Attention, ce logiciel est très puissant, une mauvaise utilisation peut faire des dégâts...

    Fais exactement ce qui suit :

    Télécharge ComboFix (de sUBs) sur ton Bureau (et pas ailleurs !) :
    Fais un clic droit sur ce lien et choisis "enregistrer la cible sous ... " : dans la fenêtre qui s'ouvre tape C-Fix, choisis le bureau comme destination et valide :

    --------------------------------------------- [ ! ATTENTION ! ] ----------------------------------------------------------
    !! déconnecte toi, ferme toutes tes applications en cours et DESACTIVE TOUTES TES DEFENCES (anti-virus, antispyware, pare-feu) le temps de la manipulation (si jamais tu en as et que je ne les ai pas vu sur le rapport hijackthis....)

    ---> Surtout, si tu rencontres des difficultés à ce niveau là, dis le moi avant de poursuivre...

    --->Je te conseil d'installer la console de récupération.(Voir le tutoriel).

    Tuto ici : TUTO
    ---------------------------------------------------------------------------------------------------------------------------------

    Ensuite :

    Double-clique sur C-Fix.exe (= combofix.exe ) .

    Appuie sur une touche pour démarrer le scan .

    Attention : n'utilise pas ta souris ni ton clavier pendant que le programme tourne. Cela pourrait figer l'ordi ---> si un message d'erreur windows apparait à un moment : clique sur la croix rouge en haut à droite de la fenêtre pour la fermer

    Le rapport sera crée dans: C:\Combofix.txt , poste le ici stp

    Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
    0
  16. dreetze1 Messages postés 24 Statut Membre
     
    ComboFix 09-01-10.03 - David Ducrotoy 2009-01-11 19:34:45.1 - NTFSx86
    Microsoft Windows XP Professionnel 5.1.2600.2.1252.1.1036.18.2815.2323 [GMT 1:00]
    Lancé depuis: h:\documents and settings\David Ducrotoy\Bureau\ComboFix.exe
    * Un nouveau point de restauration a été créé
    .

    (((((((((((((((((((((((((((((((((((( Autres suppressions ))))))))))))))))))))))))))))))))))))))))))))))))
    .

    h:\documents and settings\David Ducrotoy\Application Data\drivers\downld
    h:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    .
    ((((((((((((((((((((((((((((( Fichiers créés du 2008-12-11 au 2009-01-11 ))))))))))))))))))))))))))))))))))))
    .

    2009-01-11 19:23 . 2009-01-11 19:35 <REP> d--h----- h:\documents and settings\David Ducrotoy\Application Data\drivers
    2009-01-10 21:46 . 2009-01-11 09:05 <REP> d-------- h:\program files\FindyKill
    2009-01-09 17:54 . 2009-01-09 17:54 <REP> d-------- h:\program files\DIFX
    2009-01-09 17:53 . 2009-01-09 17:53 <REP> d-------- h:\program files\Razer
    2009-01-09 17:53 . 2009-01-09 17:53 <REP> d-------- h:\documents and settings\David Ducrotoy\Application Data\InstallShield
    2009-01-09 17:53 . 2006-11-23 05:55 73,728 --a------ h:\windows\system32\DeathAdder.cpl
    2009-01-09 17:53 . 2005-03-03 19:47 31,104 --a------ h:\windows\system32\drivers\CYUSB.sys
    2009-01-09 17:53 . 2007-08-02 17:32 22,784 --a------ h:\windows\system32\drivers\dadder.sys
    2008-12-25 18:41 . 2008-12-25 18:47 <REP> d-------- h:\program files\Ubisoft
    2008-12-23 09:28 . 2008-12-25 19:50 <REP> d-------- h:\program files\Wakfu
    2008-12-15 17:57 . 2008-12-15 17:57 <REP> d-------- h:\program files\Fichiers communs\Wise Installation Wizard
    2008-12-13 20:43 . 2008-12-13 20:43 230 --a------ h:\windows\system32\spupdsvc.inf
    2008-12-13 13:19 . 2008-12-13 13:21 1,393 --a------ h:\windows\imsins.BAK
    2008-12-12 21:25 . 2008-12-12 21:25 <REP> d-------- h:\windows\system32\URTTEMP
    2008-12-12 21:25 . 2008-12-12 21:25 <REP> d-------- h:\program files\Fichiers communs\BitDefender
    2008-12-12 21:08 . 2008-12-12 21:08 <REP> d-------- h:\program files\a-squared Anti-Malware
    2008-12-12 20:05 . 2008-12-12 20:05 <REP> d-------- h:\program files\Alwil Software
    2008-12-12 19:39 . 2008-12-12 19:39 <REP> d-------- h:\program files\CCleaner
    2008-12-11 19:38 . 2008-12-11 19:38 <REP> d-------- h:\program files\Power Defrag
    2008-12-11 19:38 . 2004-12-16 13:31 212,240 --a------ h:\windows\system32\richtx32.ocx
    2008-12-11 18:54 . 2008-12-11 18:54 <REP> d-------- h:\program files\Spybot - Search & Destroy
    2008-12-11 18:54 . 2008-12-11 18:54 <REP> d-------- h:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
    2008-12-11 18:33 . 2008-12-11 18:33 <REP> d-------- h:\windows\system32\LogFiles

    .
    (((((((((((((((((((((((((((((((((( Compte-rendu de Find3M ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2009-01-11 17:06 --------- d-----w h:\program files\Fichiers communs\Symantec Shared
    2009-01-11 17:00 --------- d-----w h:\program files\Norton Security Scan
    2009-01-10 18:06 --------- d-----w h:\documents and settings\All Users\Application Data\Google Updater
    2009-01-10 09:54 --------- d-----w h:\program files\Steam
    2009-01-09 16:53 --------- d--h--w h:\program files\InstallShield Installation Information
    2008-12-28 18:29 --------- d-----w h:\program files\Dofus
    2008-12-25 17:47 11,973 ----a-w h:\windows\system32\drivers\secdrv.sys
    2008-12-06 10:18 --------- d-----w h:\program files\Amaya-9.54
    2008-12-05 21:18 499,712 ----a-w h:\windows\system32\msvcp71.dll
    2008-11-29 20:43 --------- d-----w h:\program files\Fichiers communs\Adobe
    2008-11-29 19:20 --------- d-----w h:\documents and settings\All Users\Application Data\NOS
    2008-11-29 19:19 --------- d-----w h:\program files\NOS
    2008-11-29 14:06 --------- d-----w h:\program files\Cyanide
    2008-11-26 14:45 --------- d-----w h:\program files\EA SPORTS
    2008-11-16 16:37 --------- d-----w h:\program files\Microsoft Games
    2008-11-16 14:38 --------- d-----w h:\documents and settings\David Ducrotoy\Application Data\U3
    2008-11-14 17:15 --------- d-----w h:\documents and settings\David Ducrotoy\Application Data\OpenOffice.org
    2008-11-14 17:13 --------- d-----w h:\program files\OpenOffice.org 3
    2008-10-16 13:13 202,776 ----a-w h:\windows\system32\wuweb.dll
    2008-10-16 13:13 1,809,944 ----a-w h:\windows\system32\wuaueng.dll
    2008-10-16 13:12 561,688 ----a-w h:\windows\system32\wuapi.dll
    2008-10-16 13:12 323,608 ----a-w h:\windows\system32\wucltui.dll
    2008-10-16 13:09 92,696 ----a-w h:\windows\system32\cdm.dll
    2008-10-16 13:09 51,224 ----a-w h:\windows\system32\wuauclt.exe
    2008-10-16 13:09 43,544 ----a-w h:\windows\system32\wups2.dll
    2008-10-16 13:08 34,328 ----a-w h:\windows\system32\wups.dll
    .

    ((((((((((((((((((((((((((((((((( Points de chargement Reg ))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* les éléments vides & les éléments initiaux légitimes ne sont pas listés
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="h:\windows\system32\ctfmon.exe" [2004-08-19 15360]
    "msnmsgr"="h:\program files\MSN Messenger\msnmsgr.exe" [2007-01-19 5674352]
    "SpybotSD TeaTimer"="h:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-12-11 2156368]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "UserFaultCheck"="h:\windows\system32\dumprep 0 -u" [X]
    "au"="h:\program files\Dealio\DealioAU.exe" [2008-05-26 595296]
    "avast!"="h:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-01-11 81000]
    "a-squared"="h:\program files\a-squared Anti-Malware\a2guard.exe" [2009-01-11 2780816]
    "DeathAdder"="h:\program files\Razer\DeathAdder\razerhid.exe" [2007-09-07 159744]
    "RTHDCPL"="RTHDCPL.EXE" [2007-06-13 h:\windows\RTHDCPL.exe]

    [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
    "CTFMON.EXE"="h:\windows\System32\CTFMON.EXE" [2004-08-19 15360]

    [HKLM\~\startupfolder\H:^Documents and Settings^David Ducrotoy^Menu Démarrer^Programmes^Démarrage^OpenOffice.org 3.0.lnk]
    path=h:\documents and settings\David Ducrotoy\Menu Démarrer\Programmes\Démarrage\OpenOffice.org 3.0.lnk
    backup=h:\windows\pss\OpenOffice.org 3.0.lnkStartup

    [HKLM\~\startupfolder\H:^Documents and Settings^David Ducrotoy^Menu Démarrer^Programmes^Démarrage^ubisoft register.lnk]
    path=h:\documents and settings\David Ducrotoy\Menu Démarrer\Programmes\Démarrage\ubisoft register.lnk
    backup=h:\windows\pss\ubisoft register.lnkStartup

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
    --a------ 2008-06-12 02:38 34672 h:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
    --a------ 2008-10-01 17:57 289576 h:\program files\iTunes\iTunesHelper.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
    --a------ 2007-01-19 11:55 5674352 h:\program files\MSN Messenger\msnmsgr.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
    --a------ 2008-09-06 14:09 413696 h:\program files\QuickTime\QTTask.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SearchSettings]
    --a------ 2008-06-12 15:57 991584 h:\program files\Search Settings\SearchSettings.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Shareaza]
    --a------ 2008-10-01 11:00 5723136 h:\program files\Shareaza\Shareaza.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
    --a------ 2008-10-08 11:26 1410296 h:\program files\Steam\steam.exe

    [HKEY_LOCAL_MACHINE\software\microsoft\security center]
    "AntiVirusOverride"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "h:\\Program Files\\Shareaza\\Shareaza.exe"=
    "h:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "h:\\Program Files\\iTunes\\iTunes.exe"=
    "h:\\Program Files\\Steam\\SteamApps\\biloutte80\\counter-strike source\\hl2.exe"=
    "h:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
    "h:\\Program Files\\MSN Messenger\\livecall.exe"=
    "h:\\Program Files\\Cyanide\\Cycling Manager 3\\CYM2003.EXE"=
    "h:\\Program Files\\Steam\\steam.exe"=
    "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
    "h:\\Program Files\\Steam\\SteamApps\\biloutte80\\day of defeat source\\hl2.exe"=
    "c:\\Program Files\\eMule\\emule.exe"=
    "h:\\Program Files\\Cyanide\\GameCenter\\GameCenter.exe"=

    R3 DAdderFltr;DeathAdder Mouse;h:\windows\system32\drivers\dadder.sys [2009-01-09 22784]
    S1 aswSP;avast! Self Protection; [x]
    S3 getPlus(R) Helper;getPlus(R) Helper;h:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-11-29 33752]
    S4 aswFsBlk;aswFsBlk;h:\windows\system32\DRIVERS\aswFsBlk.sys --> h:\windows\system32\DRIVERS\aswFsBlk.sys [?]
    S4 Pi3Web;Pi3Web;c:\pi3web\bin\Pi3Srv32.exe [2004-05-29 20480]

    --- Other Services/Drivers In Memory ---

    *NewlyCreated* - EECTRL
    *NewlyCreated* - IP6FW
    .
    Contenu du dossier 'Tâches planifiées'

    2009-01-02 h:\windows\Tasks\AppleSoftwareUpdate.job
    - h:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]

    2009-01-11 h:\windows\Tasks\Norton Security Scan for David Ducrotoy.job
    - h:\program files\Norton Security Scan\Nss.exe [2008-09-19 04:18]
    .
    - - - - ORPHELINS SUPPRIMES - - - -

    HKCU-Run-swg - h:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
    MSConfigStartUp-swg - h:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

    .
    ------- Examen supplémentaire -------
    .
    uStart Page = hxxp://orange.fr/
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uInternet Settings,ProxyOverride = *.local
    uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
    IE: Compare Prices with &Dealio - h:\documents and settings\David Ducrotoy\Application Data\Dealio\kb127\res\DealioSearch.html
    FF - ProfilePath - h:\documents and settings\David Ducrotoy\Application Data\Mozilla\Firefox\Profiles\rup4iiml.default\
    FF - prefs.js: browser.startup.homepage - hxxp://orange.fr/
    FF - plugin: h:\program files\Google\Google Updater\2.4.1368.5602\npCIDetect13.dll
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2009-01-11 19:35:37
    Windows 5.1.2600 Service Pack 2 NTFS

    Recherche de processus cachés ...

    Recherche d'éléments en démarrage automatique cachés ...

    Recherche de fichiers cachés ...

    Scan terminé avec succès
    Fichiers cachés: 0

    **************************************************************************
    .
    --------------------- DLLs chargées dans les processus actifs ---------------------

    - - - - - - - > 'winlogon.exe'(772)
    h:\windows\system32\Ati2evxx.dll
    h:\windows\system32\cscui.dll
    .
    Heure de fin: 2009-01-11 19:36:30
    ComboFix-quarantined-files.txt 2009-01-11 18:36:28

    Avant-CF: 71 572 385 792 octets libres
    Après-CF: 71,601,442,816 octets libres

    WindowsXP-KB310994-SP2-Pro-BootDisk-FRA.exe
    [boot loader]
    timeout=2
    default=multi(0)disk(0)rdisk(0)partition(3)\WINDOWS
    [operating systems]
    c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
    multi(0)disk(0)rdisk(0)partition(3)\WINDOWS="Microsoft Windows XP Professionnel" /fastdetect /NoExecute=OptIn

    178 --- E O F --- 2008-11-30 09:49:16

    Voila le rapport j avoue j y comprends rien mais tanpis au moins ça fonctionne presque
    0
  17. V-X
     
    Re,

    ▶ Télécharge random's system information tool (RSIT) et enregistre le sur ton bureau.

    ▶ Double clique sur RSIT.exe pour lancer l'outil.

    ▶ Clique sur ' continue ' à l'écran Disclaimer.

    Si l'outil HIjackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera et tu devras accepter la licence.

    ▶ Une fois le scan fini , 2 rapports vont apparaitre. Poste le contenu des 2 rapports
    ( log.txt & info.txt )

    (CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

    Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.
    0
  18. dreetze1 Messages postés 24 Statut Membre
     
    log:

    Logfile of random's system information tool 1.05 (written by random/random)
    Run by David Ducrotoy at 2009-01-11 20:45:56
    Microsoft Windows XP Professionnel Service Pack 2
    System drive H: has 68 GB (60%) free of 114 GB
    Total RAM: 2815 MB (82% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 20:46:03, on 11/01/2009
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Boot mode: Normal

    Running processes:
    H:\WINDOWS\System32\smss.exe
    H:\WINDOWS\system32\winlogon.exe
    H:\WINDOWS\system32\services.exe
    H:\WINDOWS\system32\lsass.exe
    H:\WINDOWS\system32\svchost.exe
    H:\WINDOWS\System32\svchost.exe
    H:\WINDOWS\system32\spoolsv.exe
    H:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    H:\Program Files\Bonjour\mDNSResponder.exe
    H:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    H:\WINDOWS\system32\wscntfy.exe
    H:\WINDOWS\System32\svchost.exe
    H:\WINDOWS\explorer.exe
    H:\Program Files\Mozilla Firefox\firefox.exe
    H:\Documents and Settings\David Ducrotoy\Bureau\RSIT.exe
    H:\Program Files\trend micro\David Ducrotoy.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
    R3 - URLSearchHook: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - H:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - H:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - H:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - H:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: DealioBHO Class - {6A87B991-A31F-4130-AE72-6D0C294BF082} - H:\Program Files\Dealio\kb127\Dealio.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - h:\program files\google\googletoolbar1.dll
    O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - H:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - h:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Yahoo! Toolbar avec bloqueur de fenêtres pop-up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - H:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: Dealio - {E67C74F4-A00A-4F2C-9FEC-FD9DC004A67F} - H:\Program Files\Dealio\kb127\Dealio.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [au] H:\Program Files\Dealio\DealioAU.exe
    O4 - HKLM\..\Run: [avast!] H:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\Run: [a-squared] "H:\Program Files\a-squared Anti-Malware\a2guard.exe"
    O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
    O4 - HKLM\..\Run: [DeathAdder] H:\Program Files\Razer\DeathAdder\razerhid.exe
    O4 - HKCU\..\Run: [ctfmon.exe] H:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "H:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] H:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] H:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] H:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
    O8 - Extra context menu item: Compare Prices with &Dealio - H:\Documents and Settings\David Ducrotoy\Application Data\Dealio\kb127\res\DealioSearch.html
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - H:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - H:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - H:\Program Files\Dealio\kb127\Dealio.dll
    O9 - Extra 'Tools' menuitem: Dealio - {E908B145-C847-4e85-B315-07E2E70DECF8} - H:\Program Files\Dealio\kb127\Dealio.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - H:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - H:\Program Files\Yahoo!\Common\yinsthelper.dll
    O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://wwwimages.adobe.com/www.adobe.com/products/acrobat/nos/gp.cab
    O23 - Service: Apple Mobile Device - Apple Inc. - H:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - H:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - H:\Program Files\NOS\bin\getPlus_HelperSvc.exe
    O23 - Service: Google Updater Service (gusvc) - Google - H:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - H:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - H:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Pi3Web - Unknown owner - c:\Pi3Web\bin\Pi3Srv32.exe
    0
  19. dreetze1 Messages postés 24 Statut Membre
     
    l autre:

    info.txt logfile of random's system information tool 1.05 2009-01-11 20:46:04

    ======Uninstall list======

    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 H:\WINDOWS\INF\PCHealth.inf
    Adobe Flash Player ActiveX-->H:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
    Adobe Flash Player Plugin-->H:\WINDOWS\System32\Macromed\Flash\uninstall_plugin.exe
    Adobe Reader 9 - Français-->MsiExec.exe /I{AC76BA86-7AD7-1036-7B44-A90000000001}
    Adobe Shockwave Player-->H:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE H:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
    Alt WAV MP3 WMA OGG Converter 7.0-->"H:\Program Files\Alt WAV MP3 WMA OGG Converter\unins000.exe"
    Amaya 9.54-->"H:\Program Files\Amaya-9.54\Uninstall.exe"
    Apple Mobile Device Support-->MsiExec.exe /I{976C2B2A-CE59-4AB3-83FB-BF895E28F2E6}
    Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
    Archiveur WinRAR-->H:\Program Files\WinRAR\uninstall.exe
    a-squared Anti-Malware 4.0-->"H:\Program Files\a-squared Anti-Malware\unins000.exe"
    ATI Display Driver-->rundll32 H:\WINDOWS\System32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
    avast! Antivirus-->H:\Program Files\Alwil Software\Avast4\aswRunDll.exe "H:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
    Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
    CCleaner (remove only)-->"H:\Program Files\CCleaner\uninst.exe"
    Correctif pour Windows XP (KB914440)-->"H:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
    Correctif pour Windows XP (KB935448)-->"H:\WINDOWS\$NtUninstallKB935448$\spuninst\spuninst.exe"
    Correctif pour Windows XP (KB952287)-->"H:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
    Correctif Windows XP - KB873333-->H:\WINDOWS\$NtUninstallKB873333$\spuninst\spuninst.exe
    Correctif Windows XP - KB873339-->H:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
    Correctif Windows XP - KB885835-->H:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
    Correctif Windows XP - KB885836-->H:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
    Correctif Windows XP - KB888302-->H:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
    Correctif Windows XP - KB890859-->"H:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
    Correctif Windows XP - KB891781-->H:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
    Counter-Strike: Source-->MsiExec.exe /I{9580813D-94B1-4C28-9426-A441E2BB29A5}
    Cycling Manager 3-->H:\Program Files\Cyanide\Cycling Manager 3\Uninstall.exe
    Dealio Toolbar 3.4-->MsiExec.exe /X{6105648C-0C3C-481D-8C11-1F4952D6FB53}
    Dofus 1.26.0-->H:\Program Files\Dofus\uninstall.exe
    EA SPORTS online 2004-->H:\Program Files\EA SPORTS\EA SPORTS online\EASOUNInstaller.exe
    Far Cry-->H:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{D6DBDC2A-E72C-4284-B6AD-6B3B61B4DABC} /l1036
    FIFA 2004-->H:\Program Files\EA SPORTS\FIFA 2004\EAUninstall.exe
    FindyKill-->H:\Program Files\FindyKill\Uninstal.exe
    Free Mp3 Wma Converter V 1.7.3-->"H:\Program Files\Free Audio Pack\unins000.exe"
    GameCenter-->H:\Program Files\Cyanide\GameCenter\uninstall.exe
    getPlus(R) for Adobe-->"H:\Program Files\NOS\bin\getPlus_HelperSvc.exe" /UninstallGet1
    Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29}
    Google Toolbar for Internet Explorer-->regsvr32 /u /s "h:\program files\google\googletoolbar1.dll"
    High Definition Audio Driver Package - KB888111-->"H:\WINDOWS\$NtUninstallKB888111WXP$\spuninst\spuninst.exe"
    HijackThis 2.0.2-->"H:\Program Files\trend micro\HijackThis.exe" /uninstall
    Hotfix for Windows XP (KB915865)-->"H:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
    iTunes-->MsiExec.exe /I{DDDE0BE3-0CBE-4BF6-B75A-E3F69C947843}
    Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
    Microsoft .NET Framework 2.0-->H:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe
    Microsoft Internationalized Domain Names Mitigation APIs-->"H:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
    Microsoft Motocross Madness-->"H:\Program Files\Microsoft Games\Motocross Madness\Uninstal.exe" /runtemp
    Microsoft National Language Support Downlevel APIs-->"H:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Mise à jour de sécurité pour Lecteur Windows Media (KB911564)-->"H:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Lecteur Windows Media 9 (KB911565)-->"H:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127-v2)-->"H:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB890046)-->"H:\WINDOWS\$NtUninstallKB890046$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB893756)-->"H:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB896358)-->"H:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB896423)-->"H:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB896424)-->"H:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB896428)-->"H:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB899587)-->"H:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB899591)-->"H:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB900725)-->"H:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB901017)-->"H:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB901214)-->"H:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB904706)-->"H:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB905414)-->"H:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB905749)-->"H:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB908519)-->"H:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB911562)-->"H:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB911927)-->"H:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB912919)-->"H:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB913580)-->"H:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB914388)-->"H:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB914389)-->"H:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB917344)-->"H:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB917422)-->"H:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB917953)-->"H:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB919007)-->"H:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB920670)-->"H:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB920683)-->"H:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB920685)-->"H:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB921398)-->"H:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB921883)-->"H:\WINDOWS\$NtUninstallKB921883$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB922616)-->"H:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB922819)-->"H:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB923191)-->"H:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB923414)-->"H:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB924191)-->"H:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB924496)-->"H:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB938464)-->"H:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB944338-v2)-->"H:\WINDOWS\$NtUninstallKB944338-v2$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB946648)-->"H:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950749)-->"H:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950762)-->"H:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB950974)-->"H:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951066)-->"H:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"H:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951698)-->"H:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB951748)-->"H:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB952954)-->"H:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB953838)-->"H:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB953839)-->"H:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB954211)-->"H:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB955069)-->"H:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956390)-->"H:\WINDOWS\$NtUninstallKB956390$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956391)-->"H:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956803)-->"H:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB956841)-->"H:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB957095)-->"H:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB957097)-->"H:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
    Mise à jour de sécurité pour Windows XP (KB958644)-->"H:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB898461)-->"H:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB904942)-->"H:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB908531)-->"H:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB910437)-->"H:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB911280)-->"H:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
    Mise à jour pour Windows XP (KB951072-v2)-->"H:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
    Mozilla Firefox (3.0.4)-->H:\Program Files\Mozilla Firefox\uninstall\helper.exe
    Norton Security Scan (Symantec Corporation)-->"H:\Program Files\Fichiers communs\Symantec Shared\NSSSetup\{E579F5FB-D9C9-43A6-8DCF-67B9573C2E7C}_2_0_0\NSSSetup.exe" /X
    Norton Security Scan-->MsiExec.exe /X{E579F5FB-D9C9-43A6-8DCF-67B9573C2E7C}
    OpenOffice.org 3.0-->MsiExec.exe /I{1572F66F-F9AD-4D45-B0D2-0F45A0D5A0F6}
    Outil de mise à jour Google-->"H:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
    Power Defrag 3.02a-->"H:\Program Files\Power Defrag\unins000.exe"
    QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
    Razer DeathAdder(TM) Mouse-->H:\Program Files\InstallShield Installation Information\{EB1B8449-CD8F-485B-ADB6-02FBCFE180D3}\Setup.exe -runfromtemp -l0x0c0c -removeonly
    Realtek High Definition Audio Driver-->RunDll32 H:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "H:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.exe" -l0x40c -removeonly
    Rhapsody Player Engine-->MsiExec.exe /I{8A62A068-3FD6-495A-9F66-26FE94F32EC9}
    Search Settings 1.2-->MsiExec.exe /X{D0C73318-7B4A-4D16-A0C4-3B83F075EA88}
    Security Update for Microsoft .NET Framework 2.0 (KB922770)-->H:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {0E92DD42-76F5-4EF2-B381-F9C1D72BE23D} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
    Security Update pour Microsoft .NET Framework 2.0 (KB917283)-->H:\WINDOWS\system32\msiexec.exe /promptrestart /uninstall {967B098A-042D-4367-BAC9-8BC11684174F} /package {7131646D-CD3C-40F4-97B9-CD9E4E6262EF}
    Shareaza 2.4.0.0-->"H:\Program Files\Shareaza\Uninstall\unins000.exe"
    Source SDK-->"H:\Program Files\Steam\steam.exe" steam://uninstall/211
    Spybot - Search & Destroy-->"H:\Program Files\Spybot - Search & Destroy\unins000.exe"
    Steam(TM)-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
    Stronghold-->RunDll32 H:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "H:\Program Files\InstallShield Installation Information\{C917BA70-28A3-4C74-B163-41FD8C8E1A5A}\setup.exe"
    Superbike 2000-->H:\WINDOWS\ISUN040C.EXE -x -f"H:\Program Files\EA Sports\Superbike 2000\Uninst.isu" -c"H:\Program Files\EA Sports\Superbike 2000\CUninst.dll"
    Total Video Converter 3.01-->"H:\Program Files\Total Video Converter\unins000.exe"
    VLC media player 0.9.4-->H:\Program Files\VideoLAN\VLC\uninstall.exe
    Wakfu-->H:\Program Files\Wakfu\uninstall.exe
    Windows Driver Package - Cypress (CyUsb) USB -->H:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\DPInst.exe /u H:\WINDOWS\system32\DRVSTORE\cyusb_13860389BCE916343D6A5C65169C6F0C6BF6E3EA\cyusb.inf
    Windows Driver Package - Razer (HidUsb) HIDClass (02/02/2007 1.0.5.0)-->H:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\DPInst.exe /u H:\WINDOWS\system32\DRVSTORE\dadder_1D206EBC9FC4C5439CDE5E133FD5DADD76F8E58F\dadder.inf
    Windows Installer 3.1 (KB893803)-->"H:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
    Windows Live Messenger-->MsiExec.exe /I{F6326B60-1B1D-4ABF-BFCD-7B7404F44411}
    Windows XP Service Pack 2-->H:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe
    Yahoo! Install Manager-->H:\WINDOWS\System32\regsvr32 /u H:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
    Yahoo! Toolbar avec bloqueur de fenêtres pop-up-->H:\PROGRA~1\Yahoo!\Common\unyt.exe
    Zoo Tycoon 2 - Intégrale-->H:\PROGRA~1\FICHIE~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{9CC4840D-EF1C-406F-AF08-3C19EB1335B9}

    System event log

    Computer Name: NICOLAS
    Event Code: 7035
    Message: Un contrôle Démarrer a correctement été envoyé au service NLA (Network Location Awareness).

    Record Number: 5447
    Source Name: Service Control Manager
    Time Written: 20081123182239.000000+060
    Event Type: Informations
    User: NICOLAS\David Ducrotoy

    Computer Name: NICOLAS
    Event Code: 7035
    Message: Un contrôle Démarrer a correctement été envoyé au service Gestionnaire de connexions d'accès distant.

    Record Number: 5446
    Source Name: Service Control Manager
    Time Written: 20081123182239.000000+060
    Event Type: Informations
    User: NICOLAS\David Ducrotoy

    Computer Name: NICOLAS
    Event Code: 7036
    Message: Le service Téléphonie est entré dans l'état : en cours d'exécution.

    Record Number: 5445
    Source Name: Service Control Manager
    Time Written: 20081123182239.000000+060
    Event Type: Informations
    User:

    Computer Name: NICOLAS
    Event Code: 7036
    Message: Le service Compatibilité avec le Changement rapide d'utilisateur est entré dans l'état : en cours d'exécution.

    Record Number: 5444
    Source Name: Service Control Manager
    Time Written: 20081123182239.000000+060
    Event Type: Informations
    User:

    Computer Name: NICOLAS
    Event Code: 7035
    Message: Un contrôle Démarrer a correctement été envoyé au service Compatibilité avec le Changement rapide d'utilisateur.

    Record Number: 5443
    Source Name: Service Control Manager
    Time Written: 20081123182239.000000+060
    Event Type: Informations
    User: AUTORITE NT\SYSTEM

    Application event log

    Computer Name: NICOLAS
    Event Code: 4097
    Message: L'application, H:\Program Files\AV Vcs 6.0 DIAMOND\Vcs6Core.exe, a généré une erreur d'application
    L'erreur s'est produite le 09/02/2008 à 16:08:53.203
    L'exception générée était c0000005 à l'adresse 00000033 (<nosymbols>)

    Record Number: 269
    Source Name: DrWatson
    Time Written: 20080902160853.000000+120
    Event Type: Informations
    User:

    Computer Name: NICOLAS
    Event Code: 1000
    Message: Application défaillante vcs6core.exe, version 4.0.35.0, module défaillant unknown, version 0.0.0.0, adresse de défaillance 0x00000033.

    Record Number: 268
    Source Name: Application Error
    Time Written: 20080902160845.000000+120
    Event Type: erreur
    User:

    Computer Name: NICOLAS
    Event Code: 1000
    Message:
    Record Number: 267
    Source Name: Windows Live Messenger
    Time Written: 20080902160829.000000+120
    Event Type: erreur
    User:

    Computer Name: NICOLAS
    Event Code: 4097
    Message: L'application, H:\Program Files\AV Vcs 6.0\Vcs6Core.exe, a généré une erreur d'application
    L'erreur s'est produite le 09/02/2008 à 16:08:24.093
    L'exception générée était c0000005 à l'adresse 0014CA30 (<nosymbols>)

    Record Number: 266
    Source Name: DrWatson
    Time Written: 20080902160824.000000+120
    Event Type: Informations
    User:

    Computer Name: NICOLAS
    Event Code: 1000
    Message: Application défaillante vcs6core.exe, version 4.0.10.0, module défaillant unknown, version 0.0.0.0, adresse de défaillance 0x0014ca30.

    Record Number: 265
    Source Name: Application Error
    Time Written: 20080902160822.000000+120
    Event Type: erreur
    User:

    ======Environment variables======

    "ComSpec"=%SystemRoot%\system32\cmd.exe
    "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;H:\Program Files\QuickTime\QTSystem
    "windir"=%SystemRoot%
    "OS"=Windows_NT
    "PROCESSOR_ARCHITECTURE"=x86
    "PROCESSOR_LEVEL"=15
    "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
    "PROCESSOR_REVISION"=6b01
    "NUMBER_OF_PROCESSORS"=2
    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    "TEMP"=%SystemRoot%\TEMP
    "TMP"=%SystemRoot%\TEMP
    "sourcesdk"=h:\program files\steam\steamapps\biloutte80\sourcesdk
    "VProject"=h:\program files\steam\steamapps\biloutte80\counter-strike source\cstrike
    "FP_NO_HOST_CHECK"=NO
    "CLASSPATH"=.;H:\Program Files\QuickTime\QTSystem\QTJava.zip
    "QTJAVA"=H:\Program Files\QuickTime\QTSystem\QTJava.zip

    -----------------EOF-----------------
    0
  20. V-X
     
    Re,

    ==>>Télécharge Toolbar-S&D (Team IDN) sur ton Bureau.<<===

    !! Déconnectes toi et fermes toute tes applications en cours le temps de la manipe !!

    ▶ Double-cliques sur l'.exe pour lancer l'installe et laisses toi guider ...

    ▶ Une fois fait, cliques sur le raccourci créé sur ton bureau pour lancer l'outil .

    ▶ Choisis l'option 1 ( "recherche") et tapes "entrée" .

    ▶Une fois le scan finit , un rapport va apparaître, copie/colles l'intégralité
    de son contenu dans ta prochaine réponse ...

    ( le rapport est en outre sauvegardé ici -> C:\TB.txt )

    Si un rapport ne passe pas faire une alerte à la conciergerie avec le /!\ jaune.

    Tutoriel Toolbard-S&D
    0
  21. dreetze1 Messages postés 24 Statut Membre
     
    -----------\\ ToolBar S&D 1.2.8 XP/Vista

    Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
    X86-based PC ( Multiprocessor Free : AMD Athlon(tm) 64 X2 Dual Core Processor 4000+ )
    BIOS : Phoenix - AwardBIOS v6.00PG
    USER : David Ducrotoy ( Administrator )
    BOOT : Normal boot
    C:\ (Local Disk) - NTFS - Total:111 Go (Free:47 Go)
    D:\ (USB)
    E:\ (USB)
    F:\ (USB)
    G:\ (USB)
    H:\ (Local Disk) - NTFS - Total:111 Go (Free:66 Go)
    I:\ (CD or DVD) - UDF - Total:3 Go (Free:0 Go)
    J:\ (USB) - FAT - Total:967 Mo (Free:0 Go)
    K:\ (CD or DVD) - CDFS - Total:0 Go (Free:0 Go)
    L:\ (USB) - FAT - Total:1907 Mo (Free:0 Go)

    "H:\ToolBar SD" ( MAJ : 21-12-2008|20:47 )
    Option : [1] ( 12/01/2009|17:58 )

    -----------\\ Recherche de Fichiers / Dossiers ...

    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\dinstallhelper.3316CEFE15F94A46B8A88A42BA0AC9DF.dll
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\temp
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\alerts.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\alerts_over.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\alerts_rec.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\alerts_rec_over.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\chevron-small.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\DealioSearch.html
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\deals-leftcap.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\deal_report.jpg
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\ebay_login.jpg
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\err_mainwindow.html
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\err_toolbar.html
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\global_scripts.js
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\headerbgthin.jpg
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\highlight-bg.png
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\logo.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\logo_over.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\man_toolbar.css
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\man_toolbar.html
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\man_toolbar.js
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\man_toolbarl.js
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\post-this-deal.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\post-this-deal_over.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\scripts.js
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\scroller.js
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\search-chevron.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\search-chevron_over.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\search_bg_blink.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\separator.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\settings.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\settings_over.gif
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\res\yahoo-search.png
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\index.76.35
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.10.76
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.109.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.110.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.12.52
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.13.58
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.130.58
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.135.50
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.153.44
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.155.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.156.49
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.16.60
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.161.52
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.178.66
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.184.55
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.188.52
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.189.45
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.196.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.198.56
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.199.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.200.53
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.201.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.202.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.203.71
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.205.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.213.71
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.214.49
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.215.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.216.67
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.217.67
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.218.52
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.219.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.220.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.221.57
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.222.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.223.68
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.226.68
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.227.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.228.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.229.76
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.23.63
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.239.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.24.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.240.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.241.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.242.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.243.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.244.63
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.245.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.247.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.248.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.249.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.250.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.251.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.252.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.253.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.254.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.255.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.256.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.257.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.279.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.28.58
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.282.75
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.283.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.284.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.289.67
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.290.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.291.61
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.296.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.297.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.304.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.307.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.308.75
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.31.47
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.310.46
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.311.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.315.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.316.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.317.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.318.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.319.49
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.32.48
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.334.44
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.335.60
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.336.44
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.337.44
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.338.75
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.339.47
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.34.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.340.47
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.341.47
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.349.50
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.35.48
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.350.50
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.351.51
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.352.54
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.353.51
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.354.51
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.357.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.358.52
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.359.52
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.360.53
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.361.54
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.362.68
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.363.58
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.364.54
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.365.53
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.367.56
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.368.58
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.369.55
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.370.56
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.371.56
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.372.57
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.373.55
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.375.56
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.376.57
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.377.55
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.378.65
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.384.58
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.386.71
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.387.59
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.388.59
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.389.59
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.390.60
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.391.60
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.392.60
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.393.60
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.394.60
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.396.61
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.397.61
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.398.60
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.399.60
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.403.61
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.404.63
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.405.61
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.406.61
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.407.76
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.408.63
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.409.61
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.412.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.413.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.414.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.415.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.416.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.417.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.418.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.419.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.420.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.421.62
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.423.63
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.424.63
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.425.63
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.426.63
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.427.63
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.428.65
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.429.63
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.430.63
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.432.65
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.433.64
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.434.65
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.435.64
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.436.76
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.437.64
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.438.71
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.439.71
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.440.75
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.442.73
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.443.73
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.444.73
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.445.68
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.446.69
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.450.67
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.451.67
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.452.68
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.453.68
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.454.69
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.456.69
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.457.75
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.458.70
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.459.70
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.460.69
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.462.74
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.463.69
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.464.70
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.465.68
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.468.70
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.469.70
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.470.70
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.471.73
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.472.70
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.478.74
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.479.73
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.480.68
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.481.71
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.482.74
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.49.67
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.50.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.500.71
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.501.74
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.502.71
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.51.69
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.52.72
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.520.76
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.521.76
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.522.76
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.53.51
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.531.76
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.532.75
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.534.75
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.54.47
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.55.45
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.56.69
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.57.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.58.47
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.593.76
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.595.76
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.63.57
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.66.47
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.70.75
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\rules\rules.1.71.43
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\temp\dealio-14251.log
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Dealio\kb127\temp\dod_cache.xml
    H:\Program Files\Dealio
    H:\Program Files\Dealio\DealioAU.exe
    H:\Program Files\Dealio\kb127
    H:\Program Files\Dealio\SearchSettingsKit.exe
    H:\Program Files\Dealio\kb127\Dealio Deskbar.exe
    H:\Program Files\Dealio\kb127\Dealio.dll
    H:\Program Files\Dealio\kb127\DealioRes409.dll
    H:\Program Files\Dealio\kb127\res
    H:\Program Files\Dealio\kb127\resDN
    H:\Program Files\Dealio\kb127\rules
    H:\Program Files\Dealio\kb127\temp
    H:\Program Files\Dealio\kb127\res\alerts.gif
    H:\Program Files\Dealio\kb127\res\alerts_over.gif
    H:\Program Files\Dealio\kb127\res\alerts_rec.gif
    H:\Program Files\Dealio\kb127\res\alerts_rec_over.gif
    H:\Program Files\Dealio\kb127\res\chevron-small.gif
    H:\Program Files\Dealio\kb127\res\DealioSearch.html
    H:\Program Files\Dealio\kb127\res\deals-leftcap.gif
    H:\Program Files\Dealio\kb127\res\deal_report.jpg
    H:\Program Files\Dealio\kb127\res\ebay_login.jpg
    H:\Program Files\Dealio\kb127\res\err_mainwindow.html
    H:\Program Files\Dealio\kb127\res\err_toolbar.html
    H:\Program Files\Dealio\kb127\res\global_scripts.js
    H:\Program Files\Dealio\kb127\res\headerbgthin.jpg
    H:\Program Files\Dealio\kb127\res\highlight-bg.png
    H:\Program Files\Dealio\kb127\res\logo.gif
    H:\Program Files\Dealio\kb127\res\logo_over.gif
    H:\Program Files\Dealio\kb127\res\man_toolbar.css
    H:\Program Files\Dealio\kb127\res\man_toolbar.html
    H:\Program Files\Dealio\kb127\res\man_toolbar.js
    H:\Program Files\Dealio\kb127\res\man_toolbarl.js
    H:\Program Files\Dealio\kb127\res\post-this-deal.gif
    H:\Program Files\Dealio\kb127\res\post-this-deal_over.gif
    H:\Program Files\Dealio\kb127\res\scripts.js
    H:\Program Files\Dealio\kb127\res\scroller.js
    H:\Program Files\Dealio\kb127\res\search-chevron.gif
    H:\Program Files\Dealio\kb127\res\search-chevron_over.gif
    H:\Program Files\Dealio\kb127\res\search_bg_blink.gif
    H:\Program Files\Dealio\kb127\res\separator.gif
    H:\Program Files\Dealio\kb127\res\settings.gif
    H:\Program Files\Dealio\kb127\res\settings_over.gif
    H:\Program Files\Dealio\kb127\res\yahoo-search.png
    H:\Program Files\Dealio\kb127\resDN\bottom.gif
    H:\Program Files\Dealio\kb127\resDN\chevron_down.gif
    H:\Program Files\Dealio\kb127\resDN\chevron_up.gif
    H:\Program Files\Dealio\kb127\resDN\close.gif
    H:\Program Files\Dealio\kb127\resDN\deskbar.css
    H:\Program Files\Dealio\kb127\resDN\deskbar.js
    H:\Program Files\Dealio\kb127\resDN\dispatch_helper.js
    H:\Program Files\Dealio\kb127\resDN\ebay_compatible.jpg
    H:\Program Files\Dealio\kb127\resDN\logo.gif
    H:\Program Files\Dealio\kb127\resDN\logo_chevron_bkg.gif
    H:\Program Files\Dealio\kb127\resDN\losing.gif
    H:\Program Files\Dealio\kb127\resDN\lost.gif
    H:\Program Files\Dealio\kb127\resDN\man_deskbar.html
    H:\Program Files\Dealio\kb127\resDN\menu_arrow.gif
    H:\Program Files\Dealio\kb127\resDN\menu_check.gif
    H:\Program Files\Dealio\kb127\resDN\no_image.gif
    H:\Program Files\Dealio\kb127\resDN\prod_img.gif
    H:\Program Files\Dealio\kb127\resDN\search_chevron.gif
    H:\Program Files\Dealio\kb127\resDN\spacer.gif
    H:\Program Files\Dealio\kb127\resDN\textfield_bkg.gif
    H:\Program Files\Dealio\kb127\resDN\top.gif
    H:\Program Files\Dealio\kb127\resDN\unknown.gif
    H:\Program Files\Dealio\kb127\resDN\winning.gif
    H:\Program Files\Dealio\kb127\resDN\won.gif
    H:\Program Files\Dealio\kb127\rules\index.76.35
    H:\Program Files\Dealio\kb127\rules\rules.1.10.76
    H:\Program Files\Dealio\kb127\rules\rules.1.109.43
    H:\Program Files\Dealio\kb127\rules\rules.1.110.43
    H:\Program Files\Dealio\kb127\rules\rules.1.12.52
    H:\Program Files\Dealio\kb127\rules\rules.1.13.58
    H:\Program Files\Dealio\kb127\rules\rules.1.130.58
    H:\Program Files\Dealio\kb127\rules\rules.1.135.50
    H:\Program Files\Dealio\kb127\rules\rules.1.153.44
    H:\Program Files\Dealio\kb127\rules\rules.1.155.43
    H:\Program Files\Dealio\kb127\rules\rules.1.156.49
    H:\Program Files\Dealio\kb127\rules\rules.1.16.60
    H:\Program Files\Dealio\kb127\rules\rules.1.161.52
    H:\Program Files\Dealio\kb127\rules\rules.1.178.66
    H:\Program Files\Dealio\kb127\rules\rules.1.184.55
    H:\Program Files\Dealio\kb127\rules\rules.1.188.52
    H:\Program Files\Dealio\kb127\rules\rules.1.189.45
    H:\Program Files\Dealio\kb127\rules\rules.1.196.43
    H:\Program Files\Dealio\kb127\rules\rules.1.198.56
    H:\Program Files\Dealio\kb127\rules\rules.1.199.43
    H:\Program Files\Dealio\kb127\rules\rules.1.200.53
    H:\Program Files\Dealio\kb127\rules\rules.1.201.43
    H:\Program Files\Dealio\kb127\rules\rules.1.202.43
    H:\Program Files\Dealio\kb127\rules\rules.1.203.71
    H:\Program Files\Dealio\kb127\rules\rules.1.205.62
    H:\Program Files\Dealio\kb127\rules\rules.1.213.71
    H:\Program Files\Dealio\kb127\rules\rules.1.214.49
    H:\Program Files\Dealio\kb127\rules\rules.1.215.43
    H:\Program Files\Dealio\kb127\rules\rules.1.216.67
    H:\Program Files\Dealio\kb127\rules\rules.1.217.67
    H:\Program Files\Dealio\kb127\rules\rules.1.218.52
    H:\Program Files\Dealio\kb127\rules\rules.1.219.43
    H:\Program Files\Dealio\kb127\rules\rules.1.220.43
    H:\Program Files\Dealio\kb127\rules\rules.1.221.57
    H:\Program Files\Dealio\kb127\rules\rules.1.222.43
    H:\Program Files\Dealio\kb127\rules\rules.1.223.68
    H:\Program Files\Dealio\kb127\rules\rules.1.226.68
    H:\Program Files\Dealio\kb127\rules\rules.1.227.43
    H:\Program Files\Dealio\kb127\rules\rules.1.228.62
    H:\Program Files\Dealio\kb127\rules\rules.1.229.76
    H:\Program Files\Dealio\kb127\rules\rules.1.23.63
    H:\Program Files\Dealio\kb127\rules\rules.1.239.43
    H:\Program Files\Dealio\kb127\rules\rules.1.24.43
    H:\Program Files\Dealio\kb127\rules\rules.1.240.43
    H:\Program Files\Dealio\kb127\rules\rules.1.241.43
    H:\Program Files\Dealio\kb127\rules\rules.1.242.43
    H:\Program Files\Dealio\kb127\rules\rules.1.243.43
    H:\Program Files\Dealio\kb127\rules\rules.1.244.63
    H:\Program Files\Dealio\kb127\rules\rules.1.245.43
    H:\Program Files\Dealio\kb127\rules\rules.1.247.43
    H:\Program Files\Dealio\kb127\rules\rules.1.248.43
    H:\Program Files\Dealio\kb127\rules\rules.1.249.43
    H:\Program Files\Dealio\kb127\rules\rules.1.250.43
    H:\Program Files\Dealio\kb127\rules\rules.1.251.43
    H:\Program Files\Dealio\kb127\rules\rules.1.252.43
    H:\Program Files\Dealio\kb127\rules\rules.1.253.43
    H:\Program Files\Dealio\kb127\rules\rules.1.254.43
    H:\Program Files\Dealio\kb127\rules\rules.1.255.43
    H:\Program Files\Dealio\kb127\rules\rules.1.256.43
    H:\Program Files\Dealio\kb127\rules\rules.1.257.43
    H:\Program Files\Dealio\kb127\rules\rules.1.279.43
    H:\Program Files\Dealio\kb127\rules\rules.1.28.58
    H:\Program Files\Dealio\kb127\rules\rules.1.282.75
    H:\Program Files\Dealio\kb127\rules\rules.1.283.43
    H:\Program Files\Dealio\kb127\rules\rules.1.284.43
    H:\Program Files\Dealio\kb127\rules\rules.1.289.67
    H:\Program Files\Dealio\kb127\rules\rules.1.290.62
    H:\Program Files\Dealio\kb127\rules\rules.1.291.61
    H:\Program Files\Dealio\kb127\rules\rules.1.296.43
    H:\Program Files\Dealio\kb127\rules\rules.1.297.43
    H:\Program Files\Dealio\kb127\rules\rules.1.304.43
    H:\Program Files\Dealio\kb127\rules\rules.1.307.43
    H:\Program Files\Dealio\kb127\rules\rules.1.308.75
    H:\Program Files\Dealio\kb127\rules\rules.1.31.47
    H:\Program Files\Dealio\kb127\rules\rules.1.310.46
    H:\Program Files\Dealio\kb127\rules\rules.1.311.43
    H:\Program Files\Dealio\kb127\rules\rules.1.315.43
    H:\Program Files\Dealio\kb127\rules\rules.1.316.43
    H:\Program Files\Dealio\kb127\rules\rules.1.317.43
    H:\Program Files\Dealio\kb127\rules\rules.1.318.43
    H:\Program Files\Dealio\kb127\rules\rules.1.319.49
    H:\Program Files\Dealio\kb127\rules\rules.1.32.48
    H:\Program Files\Dealio\kb127\rules\rules.1.334.44
    H:\Program Files\Dealio\kb127\rules\rules.1.335.60
    H:\Program Files\Dealio\kb127\rules\rules.1.336.44
    H:\Program Files\Dealio\kb127\rules\rules.1.337.44
    H:\Program Files\Dealio\kb127\rules\rules.1.338.75
    H:\Program Files\Dealio\kb127\rules\rules.1.339.47
    H:\Program Files\Dealio\kb127\rules\rules.1.34.43
    H:\Program Files\Dealio\kb127\rules\rules.1.340.47
    H:\Program Files\Dealio\kb127\rules\rules.1.341.47
    H:\Program Files\Dealio\kb127\rules\rules.1.349.50
    H:\Program Files\Dealio\kb127\rules\rules.1.35.48
    H:\Program Files\Dealio\kb127\rules\rules.1.350.50
    H:\Program Files\Dealio\kb127\rules\rules.1.351.51
    H:\Program Files\Dealio\kb127\rules\rules.1.352.54
    H:\Program Files\Dealio\kb127\rules\rules.1.353.51
    H:\Program Files\Dealio\kb127\rules\rules.1.354.51
    H:\Program Files\Dealio\kb127\rules\rules.1.357.62
    H:\Program Files\Dealio\kb127\rules\rules.1.358.52
    H:\Program Files\Dealio\kb127\rules\rules.1.359.52
    H:\Program Files\Dealio\kb127\rules\rules.1.360.53
    H:\Program Files\Dealio\kb127\rules\rules.1.361.54
    H:\Program Files\Dealio\kb127\rules\rules.1.362.68
    H:\Program Files\Dealio\kb127\rules\rules.1.363.58
    H:\Program Files\Dealio\kb127\rules\rules.1.364.54
    H:\Program Files\Dealio\kb127\rules\rules.1.365.53
    H:\Program Files\Dealio\kb127\rules\rules.1.367.56
    H:\Program Files\Dealio\kb127\rules\rules.1.368.58
    H:\Program Files\Dealio\kb127\rules\rules.1.369.55
    H:\Program Files\Dealio\kb127\rules\rules.1.370.56
    H:\Program Files\Dealio\kb127\rules\rules.1.371.56
    H:\Program Files\Dealio\kb127\rules\rules.1.372.57
    H:\Program Files\Dealio\kb127\rules\rules.1.373.55
    H:\Program Files\Dealio\kb127\rules\rules.1.375.56
    H:\Program Files\Dealio\kb127\rules\rules.1.376.57
    H:\Program Files\Dealio\kb127\rules\rules.1.377.55
    H:\Program Files\Dealio\kb127\rules\rules.1.378.65
    H:\Program Files\Dealio\kb127\rules\rules.1.384.58
    H:\Program Files\Dealio\kb127\rules\rules.1.386.71
    H:\Program Files\Dealio\kb127\rules\rules.1.387.59
    H:\Program Files\Dealio\kb127\rules\rules.1.388.59
    H:\Program Files\Dealio\kb127\rules\rules.1.389.59
    H:\Program Files\Dealio\kb127\rules\rules.1.390.60
    H:\Program Files\Dealio\kb127\rules\rules.1.391.60
    H:\Program Files\Dealio\kb127\rules\rules.1.392.60
    H:\Program Files\Dealio\kb127\rules\rules.1.393.60
    H:\Program Files\Dealio\kb127\rules\rules.1.394.60
    H:\Program Files\Dealio\kb127\rules\rules.1.396.61
    H:\Program Files\Dealio\kb127\rules\rules.1.397.61
    H:\Program Files\Dealio\kb127\rules\rules.1.398.60
    H:\Program Files\Dealio\kb127\rules\rules.1.399.60
    H:\Program Files\Dealio\kb127\rules\rules.1.403.61
    H:\Program Files\Dealio\kb127\rules\rules.1.404.63
    H:\Program Files\Dealio\kb127\rules\rules.1.405.61
    H:\Program Files\Dealio\kb127\rules\rules.1.406.61
    H:\Program Files\Dealio\kb127\rules\rules.1.407.76
    H:\Program Files\Dealio\kb127\rules\rules.1.408.63
    H:\Program Files\Dealio\kb127\rules\rules.1.409.61
    H:\Program Files\Dealio\kb127\rules\rules.1.412.62
    H:\Program Files\Dealio\kb127\rules\rules.1.413.62
    H:\Program Files\Dealio\kb127\rules\rules.1.414.62
    H:\Program Files\Dealio\kb127\rules\rules.1.415.62
    H:\Program Files\Dealio\kb127\rules\rules.1.416.62
    H:\Program Files\Dealio\kb127\rules\rules.1.417.62
    H:\Program Files\Dealio\kb127\rules\rules.1.418.62
    H:\Program Files\Dealio\kb127\rules\rules.1.419.62
    H:\Program Files\Dealio\kb127\rules\rules.1.420.62
    H:\Program Files\Dealio\kb127\rules\rules.1.421.62
    H:\Program Files\Dealio\kb127\rules\rules.1.423.63
    H:\Program Files\Dealio\kb127\rules\rules.1.424.63
    H:\Program Files\Dealio\kb127\rules\rules.1.425.63
    H:\Program Files\Dealio\kb127\rules\rules.1.426.63
    H:\Program Files\Dealio\kb127\rules\rules.1.427.63
    H:\Program Files\Dealio\kb127\rules\rules.1.428.65
    H:\Program Files\Dealio\kb127\rules\rules.1.429.63
    H:\Program Files\Dealio\kb127\rules\rules.1.430.63
    H:\Program Files\Dealio\kb127\rules\rules.1.432.65
    H:\Program Files\Dealio\kb127\rules\rules.1.433.64
    H:\Program Files\Dealio\kb127\rules\rules.1.434.65
    H:\Program Files\Dealio\kb127\rules\rules.1.435.64
    H:\Program Files\Dealio\kb127\rules\rules.1.436.76
    H:\Program Files\Dealio\kb127\rules\rules.1.437.64
    H:\Program Files\Dealio\kb127\rules\rules.1.438.71
    H:\Program Files\Dealio\kb127\rules\rules.1.439.71
    H:\Program Files\Dealio\kb127\rules\rules.1.440.75
    H:\Program Files\Dealio\kb127\rules\rules.1.442.73
    H:\Program Files\Dealio\kb127\rules\rules.1.443.73
    H:\Program Files\Dealio\kb127\rules\rules.1.444.73
    H:\Program Files\Dealio\kb127\rules\rules.1.445.68
    H:\Program Files\Dealio\kb127\rules\rules.1.446.69
    H:\Program Files\Dealio\kb127\rules\rules.1.450.67
    H:\Program Files\Dealio\kb127\rules\rules.1.451.67
    H:\Program Files\Dealio\kb127\rules\rules.1.452.68
    H:\Program Files\Dealio\kb127\rules\rules.1.453.68
    H:\Program Files\Dealio\kb127\rules\rules.1.454.69
    H:\Program Files\Dealio\kb127\rules\rules.1.456.69
    H:\Program Files\Dealio\kb127\rules\rules.1.457.75
    H:\Program Files\Dealio\kb127\rules\rules.1.458.70
    H:\Program Files\Dealio\kb127\rules\rules.1.459.70
    H:\Program Files\Dealio\kb127\rules\rules.1.460.69
    H:\Program Files\Dealio\kb127\rules\rules.1.462.74
    H:\Program Files\Dealio\kb127\rules\rules.1.463.69
    H:\Program Files\Dealio\kb127\rules\rules.1.464.70
    H:\Program Files\Dealio\kb127\rules\rules.1.465.68
    H:\Program Files\Dealio\kb127\rules\rules.1.468.70
    H:\Program Files\Dealio\kb127\rules\rules.1.469.70
    H:\Program Files\Dealio\kb127\rules\rules.1.470.70
    H:\Program Files\Dealio\kb127\rules\rules.1.471.73
    H:\Program Files\Dealio\kb127\rules\rules.1.472.70
    H:\Program Files\Dealio\kb127\rules\rules.1.478.74
    H:\Program Files\Dealio\kb127\rules\rules.1.479.73
    H:\Program Files\Dealio\kb127\rules\rules.1.480.68
    H:\Program Files\Dealio\kb127\rules\rules.1.481.71
    H:\Program Files\Dealio\kb127\rules\rules.1.482.74
    H:\Program Files\Dealio\kb127\rules\rules.1.49.67
    H:\Program Files\Dealio\kb127\rules\rules.1.50.43
    H:\Program Files\Dealio\kb127\rules\rules.1.500.71
    H:\Program Files\Dealio\kb127\rules\rules.1.501.74
    H:\Program Files\Dealio\kb127\rules\rules.1.502.71
    H:\Program Files\Dealio\kb127\rules\rules.1.51.69
    H:\Program Files\Dealio\kb127\rules\rules.1.52.72
    H:\Program Files\Dealio\kb127\rules\rules.1.520.76
    H:\Program Files\Dealio\kb127\rules\rules.1.521.76
    H:\Program Files\Dealio\kb127\rules\rules.1.522.76
    H:\Program Files\Dealio\kb127\rules\rules.1.53.51
    H:\Program Files\Dealio\kb127\rules\rules.1.531.76
    H:\Program Files\Dealio\kb127\rules\rules.1.532.75
    H:\Program Files\Dealio\kb127\rules\rules.1.534.75
    H:\Program Files\Dealio\kb127\rules\rules.1.54.47
    H:\Program Files\Dealio\kb127\rules\rules.1.55.45
    H:\Program Files\Dealio\kb127\rules\rules.1.56.69
    H:\Program Files\Dealio\kb127\rules\rules.1.57.43
    H:\Program Files\Dealio\kb127\rules\rules.1.58.47
    H:\Program Files\Dealio\kb127\rules\rules.1.593.76
    H:\Program Files\Dealio\kb127\rules\rules.1.595.76
    H:\Program Files\Dealio\kb127\rules\rules.1.63.57
    H:\Program Files\Dealio\kb127\rules\rules.1.66.47
    H:\Program Files\Dealio\kb127\rules\rules.1.70.75
    H:\Program Files\Dealio\kb127\rules\rules.1.71.43
    H:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Dealio
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Search Settings
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Search Settings\kb127
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Search Settings\kb127\res
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Search Settings\kb127\temp
    H:\DOCUME~1\DAVIDD~1\APPLIC~1\Search Settings\kb127\temp\ws-14251.log
    H:\Program Files\Search Settings
    H:\Program Files\Search Settings\kb127
    H:\Program Files\Search Settings\SearchSettings.exe
    H:\Program Files\Search Settings\kb127\res
    H:\Program Files\Search Settings\kb127\SearchSettings.dll
    H:\Program Files\Search Settings\kb127\SearchSettingsRes409.dll
    H:\Program Files\Search Settings\kb127\temp

    -----------\\ Extensions

    (David Ducrotoy) - {b9db16a4-6edc-47ec-a1f4-b86292ed211d} => dwhelper

    -----------\\ [..\Internet Explorer\Main]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
    "Local Page"="H:\\WINDOWS\\system32\\blank.htm"
    "Start Page"="https://www.orange.fr/portail"
    "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
    "SearchMigratedDefaultURL"="https://www.google.com/webhp?gws_rd=ssl{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
    "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
    "Default_Search_URL"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
    "Search Page"="https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF"
    "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"

    --------------------\\ Recherche d'autres infections

    Aucune autre infection trouvée !

    1 - "H:\ToolBar SD\TB_1.txt" - 12/01/2009|17:59 - Option : [1]

    -----------\\ Fin du rapport a 17:59:00.20
    0
  • 1
  • 2
  • 3