Pc infecté

Fermé
fabinou13300 Messages postés 40 Date d'inscription jeudi 6 mars 2008 Statut Membre Dernière intervention 19 février 2014 - 13 janv. 2010 à 10:15
flo-91 Messages postés 5646 Date d'inscription mardi 19 mai 2009 Statut Contributeur sécurité Dernière intervention 31 octobre 2019 - 14 janv. 2010 à 19:14
Bonjour,
est ce qu'il y a une âme charitable pour m'aider à réparer mon pc ? depuis ce matin j'ai une page qui n'arrête pas de s'ouvrir et qui me propose de télécharger un antivirus alors que j'en ai déjà un. il m'empêche d'ouvrir les pages internet correctement. je ne sais pas quoi faire j'ai plein de fichiers de ma famille dessus ... help
A voir également:

32 réponses

flo-91 Messages postés 5646 Date d'inscription mardi 19 mai 2009 Statut Contributeur sécurité Dernière intervention 31 octobre 2019 1 118
13 janv. 2010 à 10:18
Bonjour, :


1-> Télécharge Rkill ( de Grinler ) sur ton bureau :

https://download.bleepingcomputer.com/grinler/rkill.exe

/!\ Désactive toutes tes protections résidentes ( Antivirus, Antispyware, Pare-Feu ) /!\

> Double clique sur rkill ( présent sur ton bureau ) ou clique droit -> Executer en tant qu'administrateur ( utilisateurs de vista/7 )

> Une fenêtre sur fond noir s'ouvrira rapidement puis disparaîtra, c'est normal.


2->Telecharge RSIT ici et enregistre-le sur ton bureau :

http://images.malwareremoval.com/random/RSIT.exe

>Double-clique sur RSIT.exe qui se trouve sur le bureau

>Le programme se lance, choisi "1month" et clique sur "continue"

>Laisse faire l'outil et poste le rapport qui s'affiche.


>Voici un tuto d'aide :

https://forum.pcastuces.com/randoms_system_information_tool_rsit-f31s31.htm
0
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
13 janv. 2010 à 10:20
slt,


Télécharge ici :

http://images.malwareremoval.com/random/RSIT.exe

random's system information tool (RSIT) par andom/random et sauvegarde-le sur le Bureau.

Double-clique sur RSIT.exe afin de lancer RSIT.

Clique Continue à l'écran Disclaimer.

Si l'outil HijackThis (version à jour) n'est pas présent ou non détecté sur l'ordinateur, RSIT le téléchargera (autorise l'accès dans ton pare-feu, si demandé) et tu devras accepter la licence.

Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront.

Poste le contenu de log.txt (<<qui sera affiché)
ainsi que de info.txt (<<qui sera réduit dans la Barre des Tâches).

NB : Les rapports sont sauvegardés dans le dossier C:\rsit
0
fabinou13300 Messages postés 40 Date d'inscription jeudi 6 mars 2008 Statut Membre Dernière intervention 19 février 2014
13 janv. 2010 à 11:54
Logfile of random's system information tool 1.06 (written by random/random)
Run by user at 2010-01-13 11:47:59
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 40 GB (57%) free of 70 GB
Total RAM: 1534 MB (56% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:48:12, on 13/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\All Users\Application Data\Kwanzy\kwanzy135.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Kwanzy\kwanzy.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\rundll32.exe
K:\Mes fichiers reçus\SuperCopier2\SuperCopier2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\user\Application Data\WhereSphere\wheresphere.exe
C:\Documents and Settings\user\Application Data\Microsoft\Windows\oulwsv.exe
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
K:\Téléchargements\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\trend micro\user.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ww12.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ww12.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww12.cherche.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ww12.cherche.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ww12.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O1 - Hosts: 78.159.125.62 www.google.no
O1 - Hosts: 78.159.125.62 www.google.nl
O1 - Hosts: 78.159.125.62 www.google.com
O1 - Hosts: 78.159.125.62 www.google.se
O1 - Hosts: 78.159.125.62 uk.search.yahoo.com
O1 - Hosts: 78.159.125.62 www.google.pt
O1 - Hosts: 78.159.125.62 www.google.es
O1 - Hosts: 78.159.125.62 www.google.ca
O1 - Hosts: 78.159.125.62 www.google.be
O1 - Hosts: 78.159.125.62 www.google.fi
O1 - Hosts: 78.159.125.62 www.google.com.br
O1 - Hosts: 78.159.125.62 www.google.co.uk
O1 - Hosts: 78.159.125.62 www.google.dk
O1 - Hosts: 78.159.125.62 www.google.co.jp
O1 - Hosts: 78.159.125.62 www.google.fr
O1 - Hosts: 78.159.125.62 www.google.co.za
O1 - Hosts: 78.159.125.62 www.google.de
O1 - Hosts: 78.159.125.62 www.google.ch
O1 - Hosts: 78.159.125.62 www.google.at
O1 - Hosts: 78.159.125.62 www.google.it
O1 - Hosts: 78.159.125.62 search.yahoo.com
O1 - Hosts: 78.159.125.62 www.google.ie
O1 - Hosts: 78.159.125.62 us.search.yahoo.com
O1 - Hosts: 78.159.125.62 www.google.gr
O1 - Hosts: 78.159.125.62 www.google.com.mx
O1 - Hosts: 78.159.125.62 www.google.com.au
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Mirar - {4BA44FF9-1985-4BB2-A44B-F397161B6A81} - C:\WINDOWS\system32\a078.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Antivirus Plus BHO - {C2B5AAB8-2183-4be7-81A6-F11493C45872} - C:\Documents and Settings\user\Application Data\AntiVirus Plus\AntiVirus Plus.70700.dll
O2 - BHO: gwprimawega - {d4e7322c-1519-1cfa-bb91-48166669206c} - C:\WINDOWS\system32\-a8-jkqyAhH6R.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Mirar - {4BA44FF8-1985-4BB2-A44B-F397161B6A81} - C:\WINDOWS\system32\a078.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AntiVirus Plus] "C:\WINDOWS\system32\rundll32.exe" "C:\Documents and Settings\user\Application Data\AntiVirus Plus\AntiVirus Plus.70700.dll", start 70700
O4 - HKCU\..\Run: [Steam] K:\jeux\\Steam.exe -silent
O4 - HKCU\..\Run: [SuperCopier2.exe] K:\Mes fichiers reçus\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WhereSphere] C:\Documents and Settings\user\Application Data\WhereSphere\wheresphere.exe
O4 - HKCU\..\Run: [SfKg6wIPuS] C:\Documents and Settings\user\Application Data\Microsoft\Windows\oulwsv.exe
O4 - HKCU\..\Run: [AntiVirus Plus] "C:\WINDOWS\system32\rundll32.exe" "C:\Documents and Settings\user\Application Data\AntiVirus Plus\AntiVirus Plus.70700.dll", start 70700
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: AntiVirus Plus.lnk = C:\WINDOWS\system32\rundll32.exe
O4 - Global Startup: AntiVirus Plus.lnk = C:\WINDOWS\system32\rundll32.exe
O4 - Global Startup: McAfee Security Scan.lnk = ?
O8 - Extra context menu item: Recherche avec cherche.us - C:\Documents and Settings\user\scriptjava.html
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.chat-land.org
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/MyFunCardsInitialSetup1.0.1.1.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\WINDOWS\system32\Skype4COM.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kwanzy Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\Kwanzy\kwanzy135.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
0
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
13 janv. 2010 à 11:55
slt


# télécharger Hoster :
http://www.funkytoad.com/download/HostsXpert.zip

# Dézipper le dossier sur le bureau.
# Lancer Hoster et cliquer sur Restore Microsoft's Hosts File


si impossible fais RHOST

http://siri.urz.free.fr/RHosts.php

_______________________

et ensuite


scan avec malwarebyte , fais un scan rapide et colle le rapport obtenu et vire ce qui est trouvé:


https://www.malekal.com/tutoriel-malwarebyte-anti-malware/­­
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
jlpjlp Messages postés 51580 Date d'inscription vendredi 18 mai 2007 Statut Contributeur sécurité Dernière intervention 3 mai 2022 5 040
13 janv. 2010 à 11:56
oups j'avais pas vu que tu étais là flo-91

je te laisse faire

bonne suite à tous les deux
0
flo-91 Messages postés 5646 Date d'inscription mardi 19 mai 2009 Statut Contributeur sécurité Dernière intervention 31 octobre 2019 1 118
13 janv. 2010 à 11:57
Ok, :


Pour les ordinateurs équipés de Windows Vista et Windows 7, la désactivation du Contrôle des comptes utilisateurs est obligatoire
sous peine de ne pas pouvoir faire fonctionner correctement l'outil.
Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac

>Ad-Remover<

>Telecharge Ad-Remover et enregistre-le sur ton bureau :

https://www.commentcamarche.net/telecharger/securite/2547-ad-remover/

>Désactive ton antivirus le temps de la manip
>Déconnecte-toi d'Internet et ferme toutes applications en cours
>Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program Files).
>Au menu principal, choisis l'option L ( Nettoyage )
>Poste le rapport généré (C:\Ad-Report-CLEAN.log).
>N'oublie pas de réactiver ton anti-virus
0
fabinou13300 Messages postés 40 Date d'inscription jeudi 6 mars 2008 Statut Membre Dernière intervention 19 février 2014
13 janv. 2010 à 12:23
je suis perdue j'arrive pas à scanner avec malwarebyte. je trouve pas le lien...il me demande de l'acheter...
0
flo-91 Messages postés 5646 Date d'inscription mardi 19 mai 2009 Statut Contributeur sécurité Dernière intervention 31 octobre 2019 1 118
13 janv. 2010 à 12:26
Fait ce que je t'ai indiqué.
0
fabinou13300 Messages postés 40 Date d'inscription jeudi 6 mars 2008 Statut Membre Dernière intervention 19 février 2014
13 janv. 2010 à 12:31
Logfile of random's system information tool 1.06 (written by random/random)
Run by user at 2010-01-13 12:40:40
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 40 GB (57%) free of 70 GB
Total RAM: 1534 MB (49% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:40:43, on 13/01/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Kwanzy\kwanzy.exe
C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\user\Application Data\WhereSphere\wheresphere.exe
C:\Documents and Settings\user\Application Data\Microsoft\Windows\oulwsv.exe
C:\Program Files\McAfee Security Scan\1.0.150\SSScheduler.exe
C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
K:\Téléchargements\RSIT.exe
C:\Program Files\trend micro\user.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ww12.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ww12.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ww12.cherche.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ww12.cherche.us
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ww12.cherche.us
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: Mirar - {4BA44FF9-1985-4BB2-A44B-F397161B6A81} - C:\WINDOWS\system32\a078.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Antivirus Plus BHO - {C2B5AAB8-2183-4be7-81A6-F11493C45872} - C:\Documents and Settings\user\Application Data\AntiVirus Plus\AntiVirus Plus.70700.dll
O2 - BHO: gwprimawega - {d4e7322c-1519-1cfa-bb91-48166669206c} - C:\WINDOWS\system32\-a8-jkqyAhH6R.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - (no file)
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Mirar - {4BA44FF8-1985-4BB2-A44B-F397161B6A81} - C:\WINDOWS\system32\a078.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\2.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [AntiVirus Plus] "C:\WINDOWS\system32\rundll32.exe" "C:\Documents and Settings\user\Application Data\AntiVirus Plus\AntiVirus Plus.70700.dll", start 70700
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Steam] K:\jeux\\Steam.exe -silent
O4 - HKCU\..\Run: [SuperCopier2.exe] K:\Mes fichiers reçus\SuperCopier2\SuperCopier2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [WhereSphere] C:\Documents and Settings\user\Application Data\WhereSphere\wheresphere.exe
O4 - HKCU\..\Run: [SfKg6wIPuS] C:\Documents and Settings\user\Application Data\Microsoft\Windows\oulwsv.exe
O4 - HKCU\..\Run: [AntiVirus Plus] "C:\WINDOWS\system32\rundll32.exe" "C:\Documents and Settings\user\Application Data\AntiVirus Plus\AntiVirus Plus.70700.dll", start 70700
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: AntiVirus Plus.lnk = C:\WINDOWS\system32\rundll32.exe
O4 - Global Startup: AntiVirus Plus.lnk = C:\WINDOWS\system32\rundll32.exe
O4 - Global Startup: McAfee Security Scan.lnk = ?
O8 - Extra context menu item: Recherche avec cherche.us - C:\Documents and Settings\user\scriptjava.html
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.chat-land.org
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/MyFunCardsInitialSetup1.0.1.1.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w3/resources/MSNPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.fr/scan_fr/scan8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\WINDOWS\system32\Skype4COM.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Kwanzy Service - Unknown owner - C:\Documents and Settings\All Users\Application Data\Kwanzy\kwanzy135.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Start BT in service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\StartSkysolSvc.exe
O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files\Fichiers communs\Acronis\Fomatik\TrueImageTryStartService.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
0
flo-91 Messages postés 5646 Date d'inscription mardi 19 mai 2009 Statut Contributeur sécurité Dernière intervention 31 octobre 2019 1 118
13 janv. 2010 à 12:33
Ce n'est pas ce que j'ai demandé, passe Ad-Remover.
0
fabinou13300 Messages postés 40 Date d'inscription jeudi 6 mars 2008 Statut Membre Dernière intervention 19 février 2014
13 janv. 2010 à 19:58
.
======= RAPPORT D'AD-REMOVER 1.1.4.6_H | UNIQUEMENT XP/VISTA/7 =======
.
Mis à jour par C_XX le 11.01.2010 à 22:59
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 19:49:44, 13/01/2010 | Mode Normal | Option: SCAN
Exécuté de: C:\Ad-Remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: USER-79D5940E4B | Utilisateur actuel: user

.
============== ÉLÉMENT(S) TROUVÉ(S) ==============
.
Service: ASKService
Service: ASKUpgrade

C:\DOCUME~1\user\APPLIC~1\Mozilla\FireFox\Profiles\4ig8871s.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
C:\DOCUME~1\user\APPLIC~1\Mozilla\FireFox\Profiles\4ig8871s.default\searchplugins\ask.xml
C:\Program Files\Mozilla FireFox\Components\AskSearch.js
C:\Program Files\AskBarDis
C:\Program Files\FunWebProducts
C:\Program Files\MyWebSearch
.
HKCU\software\appdatalow\AskBarDis
HKCU\software\appdatalow\HavingFunOnline
HKCU\software\AskBarDis
HKCU\software\FunWebProducts
HKCU\software\MediaHoldings
HKCU\Software\Microsoft\Internet Explorer\MenuExt\Recherche avec cherche.us
HKCU\software\microsoft\internet explorer\searchscopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
HKCU\software\microsoft\internet explorer\searchscopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKCU\software\MyWebSearch
HKLM\software\appdatalow\AskBarDis
HKLM\software\AskBarDis
HKLM\Software\Classes\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
HKLM\Software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
HKLM\Software\Classes\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}
HKLM\Software\Classes\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}
HKLM\Software\Classes\CLSID\{201f27d4-3704-41d6-89c1-aa35e39143ed}
HKLM\Software\Classes\CLSID\{25560540-9571-4D7B-9389-0F166788785A}
HKLM\Software\Classes\CLSID\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
HKLM\Software\Classes\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}
HKLM\Software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf}
HKLM\Software\Classes\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
HKLM\Software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}
HKLM\Software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
HKLM\Software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}
HKLM\Software\Classes\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}
HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
HKLM\Software\Classes\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}
HKLM\Software\Classes\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}
HKLM\Software\Classes\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}
HKLM\Software\Classes\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}
HKLM\Software\Classes\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}
HKLM\software\classes\FunWebProducts.DataControl
HKLM\software\classes\FunWebProducts.DataControl.1
HKLM\software\classes\FunWebProducts.HistoryKillerScheduler
HKLM\software\classes\FunWebProducts.HistoryKillerScheduler.1
HKLM\software\classes\FunWebProducts.HistorySwatterControlBar
HKLM\software\classes\FunWebProducts.HistorySwatterControlBar.1
HKLM\software\classes\FunWebProducts.HTMLMenu
HKLM\software\classes\FunWebProducts.IECookiesManager
HKLM\software\classes\FunWebProducts.IECookiesManager.1
HKLM\software\classes\FunWebProducts.KillerObjManager
HKLM\software\classes\FunWebProducts.KillerObjManager.1
HKLM\software\classes\FunWebProducts.PopSwatterBarButton
HKLM\software\classes\FunWebProducts.PopSwatterBarButton.1
HKLM\software\classes\FunWebProducts.PopSwatterSettingsControl
HKLM\software\classes\FunWebProducts.PopSwatterSettingsControl.1
HKLM\Software\Classes\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}
HKLM\Software\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
HKLM\Software\Classes\Interface\{1093995A-BA37-41D2-836E-091067C4AD17}
HKLM\Software\Classes\Interface\{120927BF-1700-43BC-810F-FAB92549B390}
HKLM\Software\Classes\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
HKLM\Software\Classes\Interface\{1F52A5FA-A705-4415-B975-88503B291728}
HKLM\Software\Classes\Interface\{247A115F-06C2-4FB3-967D-2D62D3CF4F0A}
HKLM\Software\Classes\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC}
HKLM\Software\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC}
HKLM\Software\Classes\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495}
HKLM\Software\Classes\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
HKLM\Software\Classes\Interface\{3E720451-B472-4954-B7AA-33069EB53906}
HKLM\Software\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
HKLM\Software\Classes\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}
HKLM\Software\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
HKLM\Software\Classes\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA}
HKLM\Software\Classes\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}
HKLM\Software\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF}
HKLM\Software\Classes\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}
HKLM\Software\Classes\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
HKLM\Software\Classes\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
HKLM\Software\Classes\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
HKLM\Software\Classes\Interface\{90449521-D834-4703-BB4E-D3AA44042FF8}
HKLM\Software\Classes\Interface\{991AAC62-B100-47CE-8B75-253965244F69}
HKLM\Software\Classes\Interface\{A626CDBD-3D13-4F78-B819-440A28D7E8FC}
HKLM\Software\Classes\Interface\{BBABDC90-F3D5-4801-863A-EE6AE529862D}
HKLM\Software\Classes\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE}
HKLM\Software\Classes\Interface\{D6FF3684-AD3B-48EB-BBB4-B9E6C5A355C1}
HKLM\Software\Classes\Interface\{DE38C398-B328-4F4C-A3AD-1B5E4ED93477}
HKLM\Software\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E}
HKLM\Software\Classes\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25F}
HKLM\Software\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}
HKLM\Software\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
HKLM\Software\Classes\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}
HKLM\software\classes\MyWebSearch.ChatSessionPlugin
HKLM\software\classes\MyWebSearch.ChatSessionPlugin.1
HKLM\software\classes\MyWebSearch.HTMLPanel
HKLM\software\classes\MyWebSearch.HTMLPanel.1
HKLM\software\classes\MyWebSearch.OutlookAddin
HKLM\software\classes\MyWebSearch.PseudoTransparentPlugin
HKLM\software\classes\MyWebSearch.PseudoTransparentPlugin.1
HKLM\software\classes\MyWebSearchToolBar.SettingsPlugin
HKLM\software\classes\MyWebSearchToolBar.SettingsPlugin.1
HKLM\software\classes\MyWebSearchToolBar.ToolbarPlugin
HKLM\software\classes\MyWebSearchToolBar.ToolbarPlugin.1
HKLM\software\classes\ScreenSaverControl.ScreenSaverInstaller
HKLM\software\classes\ScreenSaverControl.ScreenSaverInstaller.1
HKLM\Software\Classes\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}
HKLM\Software\Classes\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}
HKLM\Software\Classes\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554}
HKLM\Software\Classes\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906}
HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}
HKLM\Software\Classes\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}
HKLM\Software\Classes\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}
HKLM\Software\Classes\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}
HKLM\Software\Classes\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}
HKLM\Software\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}
HKLM\Software\Classes\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}
HKLM\Software\Classes\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
HKLM\Software\Classes\TypeLib\{F42228FB-E84E-479E-B922-FBBD096E792C}
HKLM\software\FocusInteractive
HKLM\software\Fun Web Products
HKLM\software\FunWebProducts
HKLM\Software\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127}
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7}
HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
HKLM\software\microsoft\internet explorer\searchscopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
HKLM\software\microsoft\internet explorer\searchscopes\{CF739809-1C6C-47C0-85B9-569DBB141420}
HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{3041d03e-fd4b-44e0-b742-2d9b88305f98}
HKLM\Software\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
HKLM\Software\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin
HKLM\Software\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin
HKLM\Software\Microsoft\Windows Media\Wmsdk\Sources\\F3PopularScreenSavers
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A}
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906}
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9}
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF}
HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612}
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\post platform\\FunWebProducts
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Plugin
HKLM\software\MyWebSearch
HKU\s-1-5-21-1177238915-413027322-1417001333-1004\software\appdatalow\AskBarDis
HKU\s-1-5-21-1177238915-413027322-1417001333-1004\software\appdatalow\HavingFunOnline
HKU\s-1-5-21-1177238915-413027322-1417001333-1004\software\AskBarDis
HKU\s-1-5-21-1177238915-413027322-1417001333-1004\software\FunWebProducts
HKU\s-1-5-21-1177238915-413027322-1417001333-1004\software\MediaHoldings
HKU\S-1-5-21-1177238915-413027322-1417001333-1004\Software\Microsoft\Internet Explorer\Searchscopes\{56256A51-B582-467E-B8D4-7786EDA79AE0}
HKU\s-1-5-21-1177238915-413027322-1417001333-1004\software\MyWebSearch
.
============== Scan additionnel ==============
.
.
* Mozilla FireFox Version 3.5.7 [fr] *
.
Nom du profil: 4ig8871s.default (user)
.
(user, prefs.js) Browser.download.lastDir, C:\Documents and Settings\user\Bureau
(user, prefs.js) Browser.search.defaultenginename, Ask
(user, prefs.js) Browser.search.selectedEngine, Ask
(user, prefs.js) Browser.startup.homepage, www.google.fr
(user, prefs.js) Extensions.enabledItems, {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11,jqs@sun.com:1.0,{4E551550-1870-479D-BF66-DF77900E100E}:1.0,{20a82645-c095-46ed-80e3-08825760534b}:1.1,{E9A1DEE0-C623-4439-8932-001E7D17607D}:2.1.0.5,{557b139e-6ca0-77cb-5f8d-54d199d5759a}:4.6.6.2,{972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.7
(user, prefs.js) Keyword.URL, hxxp://www.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q=
.
(user, prefs.js) TROUVE - Extensions.snipit.chromeURL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q={searchTerms}&crm=1
(user, prefs.js) TROUVE - Extensions.snipit.history_query, phoceen=ASKURL=hxxp://www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=hxxp://www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis||phoceen=ASKURL=//www.ask.com/web?q=phoceen&qsrc=2871&o=10611&l=dis||om=ASKURL=//www.ask.com/web?q=om&qsrc=2871&o=10611&l=dis
(user, prefs.js) TROUVE - Keyword.URL, hxxp://www.cherche.us/Result.php?client=pub-0420647136319153&cof=GIMP%3A009900%3BT%3A000000%3BALC%3A551a8b%3BGFNT%3AB7B7B7%3BLC%3A2200cc%3BBGC%3AFFFFFF%3BVLC%3A551a8b%3BGALT%3A008B45%3BFORID%3A11%3BDIV%3A%23FFFFF0%3B&ie=ISO-8859-1&q=
.
.
.
* Internet Explorer Version 8.0.6001.18702 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Do404Search: 01000000
Local Page: C:\WINDOWS\system32\blank.htm
Show_ToolBar: yes
Start Page: hxxp://www.cherche.us
Search Page: hxxp://www.cherche.us
Use Custom Search URL: 1 (0x1)
Enable Browser Extensions: yes
Search Bar: hxxp://www.cherche.us
Default_Search_URL: hxxp://www.cherche.us/keyword/
Default_Page_URL: hxxp://www.cherche.us
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.cherche.us
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Search Page: hxxp://www.cherche.us
Delete_Temp_Files_On_Exit: yes
Local Page: C:\WINDOWS\system32\blank.htm
Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
===================================
.
46192 Octet(s) - C:\Ad-Report-SCAN[1].log
.
319 Fichier(s) - C:\DOCUME~1\user\LOCALS~1\Temp
454 Fichier(s) - C:\WINDOWS\Temp
94 Fichier(s) - C:\WINDOWS\Prefetch
.
2 Fichier(s) - C:\Ad-Remover\BACKUP
0 Fichier(s) - C:\Ad-Remover\QUARANTINE
.
Fin à: 19:55:19 | 13/01/2010 - SCAN[1]
.
============== E.O.F ==============
.
0
flo-91 Messages postés 5646 Date d'inscription mardi 19 mai 2009 Statut Contributeur sécurité Dernière intervention 31 octobre 2019 1 118
13 janv. 2010 à 20:07
Tu ne suis pas ce que je te dit, je t'ai demandé un nettoyage option L, recommence.
0
fabinou13300 Messages postés 40 Date d'inscription jeudi 6 mars 2008 Statut Membre Dernière intervention 19 février 2014
13 janv. 2010 à 20:28
impossible de nettoyer quan je redémarre le pc sous sa demande il me met qu'il ne trouve pas le chemin d'acces donc pas possible
0
flo-91 Messages postés 5646 Date d'inscription mardi 19 mai 2009 Statut Contributeur sécurité Dernière intervention 31 octobre 2019 1 118
13 janv. 2010 à 20:29
Fait en mode sans echec ( tapote F8 au demrrage du pc )
0
fabinou13300 Messages postés 40 Date d'inscription jeudi 6 mars 2008 Statut Membre Dernière intervention 19 février 2014
13 janv. 2010 à 21:49
ca marche pas meme en mode sans echec et maintenant j'ai un antivirus en barre de tache qui me spam :(
0
flo-91 Messages postés 5646 Date d'inscription mardi 19 mai 2009 Statut Contributeur sécurité Dernière intervention 31 octobre 2019 1 118
13 janv. 2010 à 21:54
Tu as passé RKILL ?


Passes Malwarebytes :


>Telecharge malwarebytes ici :


https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

. sur la page cliques sur Télécharger Malwarebyte's Anti-Malware
. enregistres le sur le bureau
/!\Utilisateur de Vista : Clique droit sur le logo de Malwarebytes' Anti-Malware, « exécuter en tant qu’Administrateur »

. Double cliques sur le fichier téléchargé pour lancer le processus d'installation.
. Dans l'onglet "mise à jour", cliques sur le bouton Recherche de mise à jour
. si le pare-feu demande l'autorisation de se connecter pour malwarebytes, acceptes
. Une fois la mise à jour terminé
. rend-toi dans l'onglet, Recherche
. Sélectionnes Exécuter un examen complet
. Cliques sur Rechercher
. Le scan démarre.
. A la fin de l'analyse, un message s'affiche : L'examen s'est terminé normalement. Cliquez sur 'Afficher les résultats' pour afficher tous les objets trouvés.
. Cliques sur Ok pour poursuivre.
. Si des malwares ont été détectés, cliques sur Afficher les résultats
. Sélectionnes tout (ou laisses cochés) et cliques sur Supprimer la sélection Malwarebytes va détruire les fichiers et clés de registre et en mettre une copie dans la quarantaine.
. Malwarebytes va ouvrir le bloc-notes et y copier le rapport d'analyse.
. rends toi dans l'onglet rapport/log
. tu cliques dessus pour l'afficher une fois affiché
. tu cliques sur edition en haut du boc notes,et puis sur sélectionner tous
. tu recliques sur edition et puis sur copier et tu reviens sur le forum et dans ta réponse
. tu cliques droit dans le cadre de la reponse et coller


Si tu as besoin d'aide regarde ce tutoriel :
https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
0
fabinou13300 Messages postés 40 Date d'inscription jeudi 6 mars 2008 Statut Membre Dernière intervention 19 février 2014
13 janv. 2010 à 22:43
Malwarebytes' Anti-Malware 1.44
Version de la base de données: 3556
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

13/01/2010 22:38:52
mbam-log-2010-01-13 (22-38-52).txt

Type de recherche: Examen complet (C:\|K:\|)
Eléments examinés: 185711
Temps écoulé: 35 minute(s), 24 second(s)

Processus mémoire infecté(s): 4
Module(s) mémoire infecté(s): 2
Clé(s) du Registre infectée(s): 151
Valeur(s) du Registre infectée(s): 11
Elément(s) de données du Registre infecté(s): 2
Dossier(s) infecté(s): 21
Fichier(s) infecté(s): 89

Processus mémoire infecté(s):
C:\Documents and Settings\All Users\Application Data\Kwanzy\kwanzy135.exe (Adware.Kwanzy) -> Unloaded process successfully.
C:\Program Files\Kwanzy\kwanzy.exe (Adware.Kwanzy) -> Unloaded process successfully.
C:\Documents and Settings\user\Application Data\WhereSphere\wheresphere.exe (Adware.WhereSphere) -> Unloaded process successfully.
C:\Documents and Settings\user\Application Data\Microsoft\Windows\oulwsv.exe (Trojan.Downloader) -> Unloaded process successfully.

Module(s) mémoire infecté(s):
C:\Program Files\Kwanzy\kwanzy.dll (Adware.Agent) -> Delete on reboot.
C:\Documents and Settings\user\Application Data\AntiVirus Plus\AntiVirus Plus.70700.dll (Trojan.FakeAlert) -> Delete on reboot.

Clé(s) du Registre infectée(s):
HKEY_CLASSES_ROOT\funwebproducts.datacontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.datacontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historykillerscheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.historyswattercontrolbar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.iecookiesmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.killerobjmanager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswatterbarbutton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.popswattersettingscontrol.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.chatsessionplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.htmlpanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.pseudotransparentplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.settingsplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearchtoolbar.toolbarplugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\screensavercontrol.screensaverinstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6deee498-08cc-43f0-bca0-dbb5a25c9501} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c2b5aab8-2183-4be7-81a6-f11493c45872} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c2b5aab8-2183-4be7-81a6-f11493c45872} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c2b5aab8-2183-4be7-81a6-f11493c45872} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{0f8ecf4f-3646-4c3a-8881-8e138ffcaf70} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{1e0de227-5ce4-4ea3-ab0c-8b03e1aa76bc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{53ced2d0-5e9a-4761-9005-648404e6f7e5} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d292-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{7473d296-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{8e6f1832-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a9571378-68a1-443d-b082-284f960c6d17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b813095c-81c0-4e40-aa14-67520372b987} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c9d7be3e-141a-4c85-8cd6-32461f3df2c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{cff4ce82-3aa2-451f-9b77-7165605fb835} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d9fffb27-d62a-4d64-8cec-1ff006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{84c94803-b5ec-4491-b2be-7b113e013b77} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf1-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00a6faf6-072e-44cf-8957-5838f569a31d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{1d4db7d2-6ec9-47a3-bd87-1e41684e07bb} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256a51-b582-467e-b8d4-7786eda79ae0} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07b18eab-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4d7b-9389-0f166788785a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3dc201fb-e9c9-499c-a11f-23c360d7c3f8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3e720452-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63d0ed2c-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98d9753d-d73b-42d5-8c85-4469cda897ab} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9ff05104-b030-46fc-94b8-81276e4e27df} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{e79dfbca-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\kwanzy (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4ba44ff8-1985-4bb2-a44b-f397161b6a81} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4ba44ff8-1985-4bb2-a44b-f397161b6a81} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{4ba44ff8-1985-4bb2-a44b-f397161b6a81} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{4ba44ff8-1985-4bb2-a44b-f397161b6a81} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{4ba44ff9-1985-4bb2-a44b-f397161b6a81} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4ba44ff9-1985-4bb2-a44b-f397161b6a81} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{4ba44ff9-1985-4bb2-a44b-f397161b6a81} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4ba44ff9-1985-4bb2-a44b-f397161b6a81} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\wheresphere (Adware.WhereSphere) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Kwanzy (Adware.Kwanzy) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\WhereSphere (Adware.WhereSphere) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Kwanzy Service (Adware.Kwanzy) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\funwebproducts.htmlmenu (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\mywebsearch.outlookaddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MediaHoldings (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AppDataLow\HavingFunOnline (Adware.BHO.FL) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Recherche avec cherche.us (Redir.ChercheUs) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d4e7322c-1519-1cfa-bb91-48166669206c} (Adware.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d4e7322c-1519-1cfa-bb91-48166669206c} (Adware.BHO) -> Quarantined and deleted successfully.

Valeur(s) du Registre infectée(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07b18ea9-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4ba44ff8-1985-4bb2-a44b-f397161b6a81} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{4ba44ff8-1985-4bb2-a44b-f397161b6a81} (Adware.Mirar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wheresphere (Adware.WhereSphere) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sfkg6wipus (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus plus (Rogue.AntivirusPlus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\antivirus plus (Rogue.AntivirusPlus) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3popularscreensavers (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mywebsearch plugin (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Elément(s) de données du Registre infecté(s):
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page_bak (Hijack.StartPage) -> Bad: (http://www.cherche.us) Good: (http://www.google.com) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Dossier(s) infecté(s):
C:\Program Files\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\2.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\setups (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\SrchAstt (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\SrchAstt\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\AntiVirus Plus (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Menu Démarrer\Programmes\AntiVirus Plus (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Application Data\WhereSphere (Adware.WhereSphere) -> Quarantined and deleted successfully.
C:\Program Files\Kwanzy (Adware.Kwanzy) -> Delete on reboot.
C:\Documents and Settings\All Users\Application Data\Kwanzy (Adware.Kwanzy) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Application Data\AntiVirus Plus (Rogue.AntiVirusPlus) -> Delete on reboot.

Fichier(s) infecté(s):
C:\Program Files\Kwanzy\kwanzy.dll (Adware.Agent) -> Delete on reboot.
C:\Documents and Settings\All Users\Application Data\Kwanzy\kwanzy135.exe (Adware.Kwanzy) -> Quarantined and deleted successfully.
C:\Program Files\Kwanzy\kwanzy.exe (Adware.Kwanzy) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Application Data\AntiVirus Plus\AntiVirus Plus.70700.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\Documents and Settings\user\Local Settings\Temp\xanwmesorc.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Local Settings\Temp\Setup.tmp (Adware.Agent) -> Quarantined and deleted successfully.
C:\Program Files\Ad-Remover\QUARANTINE\PROGRA~1\MYWEBS~1\bar\2.bin\F3REGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\Kwanzy\uninstall.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D3F0AB3-8FF0-46A5-B9AC-AD6A037E376C}\RP325\A0028518.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D3F0AB3-8FF0-46A5-B9AC-AD6A037E376C}\RP325\A0028519.exe (Adware.Kwanzy) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D3F0AB3-8FF0-46A5-B9AC-AD6A037E376C}\RP326\A0028538.exe (Adware.Kwanzy) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D3F0AB3-8FF0-46A5-B9AC-AD6A037E376C}\RP331\A0029659.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D3F0AB3-8FF0-46A5-B9AC-AD6A037E376C}\RP331\A0029660.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D3F0AB3-8FF0-46A5-B9AC-AD6A037E376C}\RP336\A0029907.dll (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D3F0AB3-8FF0-46A5-B9AC-AD6A037E376C}\RP336\A0029908.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D3F0AB3-8FF0-46A5-B9AC-AD6A037E376C}\RP337\A0030057.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D3F0AB3-8FF0-46A5-B9AC-AD6A037E376C}\RP295\A0027343.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2D3F0AB3-8FF0-46A5-B9AC-AD6A037E376C}\RP297\A0027376.exe (Adware.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\a078.dll (Adware.Mirar) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\KWA1377.tmp\upgrade.exe (Adware.Kwanzy) -> Quarantined and deleted successfully.
C:\WINDOWS\Temp\KWA34F4.tmp\upgrade.exe (Adware.Kwanzy) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\0330D7F0 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\0399C5A2 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\0399CB20 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\0399D3BB.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\0399D503.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\0399D699.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\0399D83F.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\0399DB6C (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\0399DE5A.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\0399DFB1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\0399E0EA.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\0399E232.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Cache\files.ini (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\History\search3 (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\ask_logo.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\autoup.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\center.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\index.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\mid_dots.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\mws_logo.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\protect.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\shocked.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\stop.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\systray.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\systrayp.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\tp_grad.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Message\COMMON\warn.gif (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\setting2.htm (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\settings.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\AntiVirus Plus\AntiVirus Plus.lnk (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\AntiVirus Plus\EULA.url (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Menu Démarrer\Programmes\AntiVirus Plus\AntiVirus Plus.lnk (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Menu Démarrer\Programmes\AntiVirus Plus\EULA.url (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Application Data\WhereSphere\config.cfg (Adware.WhereSphere) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Application Data\WhereSphere\wheresphere.exe (Adware.WhereSphere) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Application Data\WhereSphere\WSUninstall.exe (Adware.WhereSphere) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Application Data\Microsoft\Windows\oulwsv.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Application Data\avp.ico (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Bureau\AntiVirus Plus.lnk (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiVirus Plus.lnk (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Documents and Settings\All Users\Menu Démarrer\Programmes\Démarrage\AntiVirus Plus.lnk (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\Documents and Settings\user\Menu Démarrer\Programmes\Démarrage\AntiVirus Plus.lnk (Rogue.AntiVirusPlus) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\-a8-jkqyAhH6R.dll (Adware.BHO) -> Quarantined and deleted successfully.
0
flo-91 Messages postés 5646 Date d'inscription mardi 19 mai 2009 Statut Contributeur sécurité Dernière intervention 31 octobre 2019 1 118
14 janv. 2010 à 17:34
Ok,

Peux-tu maintenant passer Ad-Remover option Lstp :


Pour les ordinateurs équipés de Windows Vista et Windows 7, la désactivation du Contrôle des comptes utilisateurs est obligatoire
sous peine de ne pas pouvoir faire fonctionner correctement l'outil.
Tuto : https://www.commentcamarche.net/faq/8343-vista-desactiver-l-uac­er-l-uac

>Ad-Remover<

>Telecharge Ad-Remover et enregistre-le sur ton bureau :

https://www.commentcamarche.net/telecharger/securite/2547-ad-remover/

>Désactive ton antivirus le temps de la manip
>Déconnecte-toi d'Internet et ferme toutes applications en cours
>Double-clique sur le programme d'installation, installe-le dans son emplacement par défaut (C:\Program Files).
>Au menu principal, choisis l'option L ( Nettoyage )
>Poste le rapport généré (C:\Ad-Report-CLEAN.log).
>N'oublie pas de réactiver ton anti-virus
0
fabinou13300 Messages postés 40 Date d'inscription jeudi 6 mars 2008 Statut Membre Dernière intervention 19 février 2014
14 janv. 2010 à 17:37
je l ai lancé dans la nuit et ce matin en me levant plus d antivirus bizard et j'ai lancé un scan rapide de malware plus aucun fichier est ce que ca veux dire que cest fini ?
Par contre j'ai cherché avec ta commande je trouve pas le log
0
flo-91 Messages postés 5646 Date d'inscription mardi 19 mai 2009 Statut Contributeur sécurité Dernière intervention 31 octobre 2019 1 118
14 janv. 2010 à 17:43
Il reste surement des traces, Tu n'arrives pas à passer Ad(Remover ?
0