Mon pc rame sur internet

cindy22 -  
Nic00 Messages postés 1751 Statut Membre -
Bonjour,

excuser moi de vous deranger mais je n'en peux plus ... depuis des mois quand je souhaite me conecter sur le web mes pages mettent de longue minutes a se mettre en pages et de plus je suis obliger dappuyer pa mal de fois sur la même touche pour quel s'affiche ....j'ai fais un scan de démarage , j'ai supprimer des fichiers, sans succès et cela me décourage =( je vais tenter de defragmanter ... aidez moi svp et pardon pour l'hortographe

voici mon raport hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 16:28:53, on 01/06/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Windows\Philips\SPC220NC\Monitor.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Users\LEBELL~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Users\le bellec cindy\AppData\Local\ycaqcow.exe
C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
C:\Users\le bellec cindy\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
C:\Users\le bellec cindy\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
C:\Users\le bellec cindy\Downloads\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://fr.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O1 - Hosts: ::1 localhost
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Monitor] C:\Windows\Philips\SPC220NC\Monitor.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S7418.tmp" /EF "HKCU"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [ycaqcow] "c:\users\le bellec cindy\appdata\local\ycaqcow.exe" ycaqcow
O4 - Startup: Outil de notification Live Search.lnk = le bellec cindy\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
O4 - Global Startup: Empowering Technology Launcher.lnk = ?
O4 - Global Startup: TrayMin220.lnk = ?
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZCxdm490YYFR
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Poker\CDPoker\casino.exe
O9 - Extra 'Tools' menuitem: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Poker\CDPoker\casino.exe
O13 - Gopher Prefix:
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/CursorManiaInitialSetup1.0.1.1.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 12134 bytes
Configuration: Windows Vista Internet Explorer 7.0

4 réponses

  1. Nic00 Messages postés 1751 Statut Membre 95
     
    Bonjour,

    Télécharge Ad-Remover :

    http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe
    /!\ Déconnectes toi et fermes toutes applications en cours

    ▶ Double clique sur "Ad-R.exe" pour lancer l'installation en laissant les paramètres d'installation par défaut .

    Double clique sur l'icône Ad-remover situé sur ton bureau.

    ▶ Au menu principal choisi l'option "L" et appuie sur Entrée.

    ▶Postes le rapport qui apparait à la fin.

    ▶Le rapport est sauvegardé aussi sous C:\Ad-report.log

    (CTRL+A Pour tout sélectionner, CTRL+C pour copier et CTRL+V pour coller)
    1
    1. cindy22
       
      Bonjour nicOO

      voila ce qu'il y a eu dans le rapport ... il y a u des coupure car mon pc c éteint donc je lai refai .... les **** son la ou apparaissai mon nom et mon prénom voila

      .
      ======= RAPPORT D'AD-REMOVER 1.1.4.5_B | UNIQUEMENT XP/VISTA =======
      .
      Mit à jour part C_XX le 01/06/2009 à 11:50 AM
      Contact: AdRemover.contact@gmail.com
      Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
      .
      Lancé à: 14:18:08, 02/06/2009 | Mode Normal | Option: CLEAN
      Exécuté de: C:\Program Files\Ad-remover\
      Système d'exploitation: Microsoft® Windows Vista™ Home Basic Service Pack 1 v6.0.6001
      Nom du PC: PC-DE-****** | Utilisateur actuel: ********
      .
      Administrateur: Administrateur *Desactive*
      N'est pas administrateur: Invité *Desactive*
      Administrateur: *********
      .
      ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
      .
      Service: "MyWebSearchService"
      .
      HKCR\FunWebProducts.DataControl
      HKCR\FunWebProducts.DataControl.1
      HKCR\FunWebProducts.HistoryKillerScheduler
      HKCR\FunWebProducts.HistoryKillerScheduler.1
      HKCR\FunWebProducts.HistorySwatterControlBar
      HKCR\FunWebProducts.HistorySwatterControlBar.1
      HKCR\FunWebProducts.HTMLMenu
      HKCR\FunWebProducts.HTMLMenu.1
      HKCR\FunWebProducts.HTMLMenu.2
      HKCR\FunWebProducts.IECookiesManager
      HKCR\FunWebProducts.IECookiesManager.1
      HKCR\FunWebProducts.KillerObjManager
      HKCR\FunWebProducts.KillerObjManager.1
      HKCR\FunWebProducts.PopSwatterBarButton
      HKCR\FunWebProducts.PopSwatterBarButton.1
      HKCR\FunWebProducts.PopSwatterSettingsControl
      HKCR\FunWebProducts.PopSwatterSettingsControl.1
      HKCR\MyWebSearch.ChatSessionPlugin
      HKCR\MyWebSearch.ChatSessionPlugin.1
      HKCR\MyWebSearch.HTMLPanel
      HKCR\MyWebSearch.HTMLPanel.1
      HKCR\MyWebSearch.OutlookAddin
      HKCR\MyWebSearch.OutlookAddin.1
      HKCR\MyWebSearch.PseudoTransparentPlugin
      HKCR\MyWebSearch.PseudoTransparentPlugin.1
      HKCR\MyWebSearchToolBar.SettingsPlugin
      HKCR\MyWebSearchToolBar.SettingsPlugin.1
      HKCR\MyWebSearchToolBar.ToolbarPlugin
      HKCR\MyWebSearchToolBar.ToolbarPlugin.1
      HKCR\screensavercontrol.screensaverinstaller
      HKCR\screensavercontrol.screensaverinstaller.1
      HKCU\Software\AppDataLow\Software\MyWebSearch
      HKCU\Software\EoRezo
      HKCU\Software\FunWebProducts
      HKCU\Software\Grand Virtual
      HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
      HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}
      HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
      HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
      HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
      HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
      HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
      HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF}
      HKCU\Software\MyWebSearch
      HKLM\Software\EoRezo
      HKLM\Software\FocusInteractive
      HKLM\Software\Fun Web Products
      HKLM\Software\FunWebProducts
      HKLM\Software\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
      HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
      HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
      HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
      HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
      HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
      HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
      HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
      HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
      HKLM\Software\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
      HKLM\Software\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin
      HKLM\Software\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin
      HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker
      HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall
      HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdate_is1
      HKLM\Software\MyWebSearch
      HKLM\SYSTEM\ControlSet003\Services\MyWebSearchService
      HKU\S-1-5-21-3566244553-730665422-3001215702-1003\Software\Appdatalow\Software\Fun Web Products
      HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\\FunWebProducts
      HKLM\Software\Microsoft\Windows Media\Wmsdk\Sources\\F3PopularScreenSavers
      HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Email Plugin
      HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
      HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\My Web Search Bar Search Scope Monitor
      HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Email Plugin
      HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Plugin
      HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Softwarehelper
      HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00A6FAF6-072E-44CF-8957-5838F569A31D}
      HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
      HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
      HKLM\Software\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}
      HKLM\Software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
      HKLM\Software\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
      HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
      HKLM\Software\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
      HKLM\Software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
      HKLM\Software\Classes\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}
      HKLM\Software\Classes\CLSID\{25560540-9571-4D7B-9389-0F166788785A}
      HKLM\Software\Classes\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
      HKLM\Software\Classes\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}
      HKLM\Software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
      HKLM\Software\Classes\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
      HKLM\Software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}
      HKLM\Software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
      HKLM\Software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}
      HKLM\Software\Classes\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}
      HKLM\Software\Classes\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}
      HKLM\Software\Classes\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}
      HKLM\Software\Classes\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
      HKLM\Software\Classes\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}
      HKLM\Software\Classes\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}
      HKLM\Software\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}
      HKLM\Software\Classes\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}
      HKLM\Software\Classes\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}
      HKLM\Software\Classes\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}
      HKLM\Software\Classes\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}
      HKLM\Software\Classes\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}

      voici la suite :

      C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Everest Poker\Everest Poker.lnk
      C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Everest Poker\Uninstall Everest Poker.lnk
      C:\PROGRA~2\MICROS~1\Windows\STARTM~1\Programs\Everest Poker
      C:\Users\****~1\AppData\Roaming\EoRezo\cache
      C:\Users\****~1\AppData\Roaming\EoRezo\cmhost.cyp
      C:\Users\****~1\AppData\Roaming\EoRezo\ConfMedia.cyp
      C:\Users\****~1\AppData\Roaming\EoRezo\ConfMedia.cyp.old
      C:\Users\****~1\AppData\Roaming\EoRezo\db
      C:\Users\*****~1\AppData\Roaming\EoRezo\eoDesktop
      C:\Users\*****~1\AppData\Roaming\EoRezo\eoStats
      C:\Users\*****~1\AppData\Roaming\EoRezo\host.cyp
      C:\Users\*****~1\AppData\Roaming\EoRezo\SoftwareUpdate
      C:\Users\*****~1\AppData\Roaming\EoRezo\user.cyp
      C:\Users\*****~1\AppData\Roaming\EoRezo\db\cat.cyp
      C:\Users\*****~1\AppData\Roaming\EoRezo\eoDesktop\config.xml
      C:\Users\*****~1\AppData\Roaming\EoRezo\eoDesktop\eoDesktop.html
      C:\Users\******~1\AppData\Roaming\EoRezo\eoDesktop\userConfig.xml
      C:\Users\*****~1\AppData\Roaming\EoRezo\eoStats\eoStats.txt
      C:\Users\****~1\AppData\Roaming\EoRezo\SoftwareUpdate\Download
      C:\Users\****~1\AppData\Roaming\EoRezo\SoftwareUpdate\help_config.cyp
      C:\Users\*****~1\AppData\Roaming\EoRezo\SoftwareUpdate\Software
      C:\Users\*****~1\AppData\Roaming\EoRezo\SoftwareUpdate\SoftwareUpdate.exe
      C:\Users\*****~1\AppData\Roaming\EoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
      C:\Users\*****~1\AppData\Roaming\EoRezo\SoftwareUpdate\unins000.dat
      C:\Users\*****~1\AppData\Roaming\EoRezo\SoftwareUpdate\unins000.exe
      C:\Users\*****~1\AppData\Roaming\EoRezo\SoftwareUpdate\user_config.cyp
      C:\Users\*****~1\AppData\Roaming\EoRezo\SoftwareUpdate\user_profil.cyp
      C:\Users\*****~1\AppData\Roaming\EoRezo\SoftwareUpdate\Software\itsTV
      C:\Users\*****~1\AppData\Roaming\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.5
      C:\Users\*****~1\AppData\Roaming\EoRezo\SoftwareUpdate\Software\itsTV\3.0.0.5\itstv.exe
      C:\Users\*****~1\AppData\Roaming\EoRezo
      C:\Users\*****\AppData\LocalLow\FunWebProducts\Installr
      C:\Users\*****\AppData\LocalLow\FunWebProducts\ScreenSaver
      C:\Users\*****\AppData\LocalLow\FunWebProducts\Shared
      C:\Users\*****\AppData\LocalLow\FunWebProducts\Installr\Cache
      C:\Users\*****\AppData\LocalLow\FunWebProducts\Installr\Cache\002E699B.exe
      C:\Users\*****\AppData\LocalLow\FunWebProducts\Installr\Cache\files.ini
      C:\Users\*****\AppData\LocalLow\FunWebProducts\ScreenSaver\Images
      C:\Users\*****\AppData\LocalLow\FunWebProducts\ScreenSaver\Images\004550EE.urr
      C:\Users\*****\AppData\LocalLow\FunWebProducts\Shared\00328DFD.dat
      C:\Users\*****\AppData\LocalLow\FunWebProducts\Shared\Cache
      C:\Users\*****\AppData\LocalLow\FunWebProducts\Shared\Cache\CursorManiaBtn.html
      C:\Users\*****\AppData\LocalLow\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
      C:\Users\*****\AppData\LocalLow\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
      C:\Users\*****\AppData\LocalLow\FunWebProducts\Shared\Cache\WebfettiBtn.html
      C:\Users\*****\AppData\LocalLow\FunWebProducts
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Cache
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\History
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Settings
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Cache\002F0B94.bin
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Cache\002F0CBD.bin
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Cache\002F0DF5.bin
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Cache\002F0F1D.bin
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Cache\002F34C6.bin
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Cache\002F35EF.bin
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Cache\002F3727.bin
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Cache\002F387E.bin
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Cache\002F4569
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Cache\140FC05B
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Cache\files.ini
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\History\search3
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\ask_logo.gif
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\autoup.gif
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\autoup.htm
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\center.htm
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\index.htm
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\mid_dots.gif
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\mws_logo.gif
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\protect.htm
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\shocked.gif
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\stop.gif
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\systray.htm
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\systrayp.htm
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\tp_grad.gif
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Message\COMMON\warn.gif
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Settings\prevcfg2.htm
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Settings\setting2.htm
      C:\Users\*****\AppData\LocalLow\MyWebSearch\bar\Settings\settings.dat
      C:\Users\*****\AppData\LocalLow\MyWebSearch
      C:\Program Files\Ask Search Assistant\ask.ico
      C:\Program Files\Ask Search Assistant\AskSearchAsst.ini
      C:\Program Files\Ask Search Assistant\Install.asa.log
      C:\Program Files\Ask Search Assistant\uninst.exe
      C:\Program Files\Ask Search Assistant
      C:\Program Files\Everest Poker\casino.exe
      C:\Program Files\Everest Poker\CStart.exe
      C:\Program Files\Everest Poker\data
      C:\Program Files\Everest Poker\Everest Poker.exe
      C:\Program Files\Everest Poker\gvbase.dll
      C:\Program Files\Everest Poker\gvcrt.dll
      C:\Program Files\Everest Poker\gvgfx-dib.dll
      C:\Program Files\Everest Poker\gvgfx.dll
      C:\Program Files\Everest Poker\gvmain.dll
      C:\Program Files\Everest Poker\gvmain.exe
      C:\Program Files\Everest Poker\gvnetwork.dll
      C:\Program Files\Everest Poker\gvsound.dll
      C:\Program Files\Everest Poker\history
      C:\Program Files\Everest Poker\init.ini
      C:\Program Files\Everest Poker\log.dat
      C:\Program Files\Everest Poker\settings.ini
      C:\Program Files\Everest Poker\toc_fr.ini
      C:\Program Files\Everest Poker\var
      C:\Program Files\Everest Poker\data\fonts
      C:\Program Files\Everest Poker\data\mp-lobby
      C:\Program Files\Everest Poker\data\mp-poker
      C:\Program Files\Everest Poker\data\shared
      C:\Program Files\Everest Poker\data\startup
      C:\Program Files\Everest Poker\data\fonts\kgp-en.ttf
      C:\Program Files\Everest Poker\data\mp-lobby\fr.gvt
      C:\Program Files\Everest Poker\data\mp-lobby\shared.gvt
      C:\Program Files\Everest Poker\data\mp-poker\background
      C:\Program Files\Everest Poker\data\mp-poker\fr
      C:\Program Files\Everest Poker\data\mp-poker\shared.gvt
      C:\Program Files\Everest Poker\data\mp-poker\background\default.gvt
      C:\Program Files\Everest Poker\data\mp-poker\fr\bitmaps.gvt
      C:\Program Files\Everest Poker\data\mp-poker\fr\mp-poker_strings.txt
      C:\Program Files\Everest Poker\data\mp-poker\fr\mp-poker_tutorial.txt
      C:\Program Files\Everest Poker\data\shared\fr
      C:\Program Files\Everest Poker\data\shared\shared
      C:\Program Files\Everest Poker\data\shared\fr\country.txt
      C:\Program Files\Everest Poker\data\shared\fr\language.txt
      C:\Program Files\Everest Poker\data\shared\fr\ordinal.txt
      C:\Program Files\Everest Poker\data\shared\shared\bitmaps
      C:\Program Files\Everest Poker\data\shared\shared\sounds
      C:\Program Files\Everest Poker\data\shared\shared\bitmaps\btn_scroll.gvt
      C:\Program Files\Everest Poker\data\shared\shared\bitmaps\check.art
      C:\Program Files\Everest Poker\data\shared\shared\bitmaps\chips.art
      C:\Program Files\Everest Poker\data\shared\shared\sounds\button.ogg
      C:\Program Files\Everest Poker\data\shared\shared\sounds\carddeal.ogg
      C:\Program Files\Everest Poker\data\shared\shared\sounds\cardflip.ogg
      C:\Program Files\Everest Poker\data\shared\shared\sounds\chipclick.ogg
      C:\Program Files\Everest Poker\data\startup\en
      C:\Program Files\Everest Poker\data\startup\fr
      C:\Program Files\Everest Poker\data\startup\shared
      C:\Program Files\Everest Poker\data\startup\en\startup_strings.txt
      C:\Program Files\Everest Poker\data\startup\fr\cstart.txt
      C:\Program Files\Everest Poker\data\startup\fr\startup_strings.txt
      C:\Program Files\Everest Poker\data\startup\shared\bitmaps
      C:\Program Files\Everest Poker\data\startup\shared\icons
      C:\Program Files\Everest Poker\data\startup\shared\sounds
      C:\Program Files\Everest Poker\data\startup\shared\bitmaps\splash_poker.art
      C:\Program Files\Everest Poker\data\startup\shared\icons\ep.ico
      C:\Program Files\Everest Poker\data\startup\shared\sounds\alert.ogg
      C:\Program Files\Everest Poker\history\14.txt
      C:\Program Files\Everest Poker\history\15.txt
      C:\Program Files\Everest Poker\history\16.txt
      C:\Program Files\Everest Poker\history\20.txt
      C:\Program Files\Everest Poker\history\21.txt
      C:\Program Files\Everest Poker\history\22.txt
      C:\Program Files\Everest Poker\history\23.txt
      C:\Program Files\Everest Poker\history\24.txt
      C:\Program Files\Everest Poker\history\25.txt
      C:\Program Files\Everest Poker\history\26.txt
      C:\Program Files\Everest Poker\history\27.txt
      C:\Program Files\Everest Poker\history\31.txt
      C:\Program Files\Everest Poker\history\33.txt
      C:\Program Files\Everest Poker\history\36.txt
      C:\Program Files\Everest Poker\history\37.txt
      C:\Program Files\Everest Poker\history\40.txt
      C:\Program Files\Everest Poker\history\44.txt
      C:\Program Files\Everest Poker\history\46.txt
      C:\Program Files\Everest Poker\history\47.txt
      C:\Program Files\Everest Poker\history\49.txt
      C:\Program Files\Everest Poker\history\51.txt
      C:\Program Files\Everest Poker\history\52.txt
      C:\Program Files\Everest Poker\var\content-fr.dat
      C:\Program Files\Everest Poker\var\Everest Casino.exe
      C:\Program Files\Everest Poker
      C:\Program Files\FunWebProducts\ScreenSaver
      C:\Program Files\FunWebProducts\ScreenSaver\Images
      C:\Program Files\FunWebProducts
      C:\Program Files\MyWebSearch\bar
      C:\Program Files\MyWebSearch\bar\1.bin
      C:\Program Files\MyWebSearch\bar\Avatar
      C:\Program Files\MyWebSearch\bar\Game
      C:\Program Files\MyWebSearch\bar\History
      C:\Program Files\MyWebSearch\bar\icons
      C:\Program Files\MyWebSearch\bar\Message
      C:\Program Files\MyWebSearch\bar\Notifier
      C:\Program Files\MyWebSearch\bar\Settings
      C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
      C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\F3IMSTUB.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
      C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
      C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
      C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
      C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
      C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
      C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
      C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
      C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
      C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE
      C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
      C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
      C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
      C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
      C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
      C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
      C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
      C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE
      C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
      C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
      C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
      C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
      C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
      C:\Program Files\MyWebSearch\bar\icons\CM.ICO
      C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
      C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
      C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
      C:\Program Files\MyWebSearch\bar\icons\WB.ICO
      C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
      C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
      C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
      C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
      C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
      C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
      C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
      C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
      C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
      C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
      C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
      C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
      C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
      C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
      C:\Program Files\MyWebSearch
      C:\Windows\System32\f3PSSavr.scr
      C:\Program Files\MSN Messenger\riched20.dll
      C:\Program Files\Internet Explorer\msimg32.dll
      C:\Windows\Prefetch\CSTART.EXE-697E371E.pf
      C:\Windows\Prefetch\EVEREST POKER.EXE-49449C8C.pf
      C:\Windows\Prefetch\M3SKPLAY.EXE-24D59D5D.pf

      (!) -- Fichiers temporaires supprimés.

      .
      ============== Scan additionnel ==============
      .
      .
      .

      * Internet Explorer Version 7.0.6001.18000 *

      [HKEY_CURRENT_USER\..\Internet Explorer\Main]

      Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
      Search Page: hxxp://www.google.com
      Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome

      [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

      Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Search bar: hxxp://search.msn.com/spbasic.htm
      Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
      Start Page: hxxp://fr.msn.com/

      [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

      Tabs: res://ieframe.dll/tabswelcome.htm

      ============== Suspect (Cracks, Serials ... ) ==============

      .

      +---------------------------------------------------------------------------+

      16824 Octet(s) - C:\Ad-Report-CLEAN.log

      18 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
      70 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE

      Fin à: 16:00:44 | 02/06/2009
      .
      ============== E.O.F ==============
      .
      0
  2. cindy22
     
    bonjour nicOO

    voila ce qu'il y a eu dans le rapport ... je ne sais pas si il était vraiment terminer du a ce que mon pc a couper ... esque je dois le refaire?

    .
    ======= RAPPORT D'AD-REMOVER 1.1.4.5_B | UNIQUEMENT XP/VISTA =======
    .
    Mit à jour part C_XX le 01/06/2009 à 11:50 AM
    Contact: AdRemover.contact@gmail.com
    Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
    .
    Lancé à: 14:18:08, 02/06/2009 | Mode Normal | Option: CLEAN
    Exécuté de: C:\Program Files\Ad-remover\
    Système d'exploitation: Microsoft® Windows Vista™ Home Basic Service Pack 1 v6.0.6001
    Nom du PC: PC-DE-****** | Utilisateur actuel: ********
    .
    Administrateur: Administrateur *Desactive*
    N'est pas administrateur: Invité *Desactive*
    Administrateur: *********
    .
    ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
    .
    Service: "MyWebSearchService"
    .
    HKCR\FunWebProducts.DataControl
    HKCR\FunWebProducts.DataControl.1
    HKCR\FunWebProducts.HistoryKillerScheduler
    HKCR\FunWebProducts.HistoryKillerScheduler.1
    HKCR\FunWebProducts.HistorySwatterControlBar
    HKCR\FunWebProducts.HistorySwatterControlBar.1
    HKCR\FunWebProducts.HTMLMenu
    HKCR\FunWebProducts.HTMLMenu.1
    HKCR\FunWebProducts.HTMLMenu.2
    HKCR\FunWebProducts.IECookiesManager
    HKCR\FunWebProducts.IECookiesManager.1
    HKCR\FunWebProducts.KillerObjManager
    HKCR\FunWebProducts.KillerObjManager.1
    HKCR\FunWebProducts.PopSwatterBarButton
    HKCR\FunWebProducts.PopSwatterBarButton.1
    HKCR\FunWebProducts.PopSwatterSettingsControl
    HKCR\FunWebProducts.PopSwatterSettingsControl.1
    HKCR\MyWebSearch.ChatSessionPlugin
    HKCR\MyWebSearch.ChatSessionPlugin.1
    HKCR\MyWebSearch.HTMLPanel
    HKCR\MyWebSearch.HTMLPanel.1
    HKCR\MyWebSearch.OutlookAddin
    HKCR\MyWebSearch.OutlookAddin.1
    HKCR\MyWebSearch.PseudoTransparentPlugin
    HKCR\MyWebSearch.PseudoTransparentPlugin.1
    HKCR\MyWebSearchToolBar.SettingsPlugin
    HKCR\MyWebSearchToolBar.SettingsPlugin.1
    HKCR\MyWebSearchToolBar.ToolbarPlugin
    HKCR\MyWebSearchToolBar.ToolbarPlugin.1
    HKCR\screensavercontrol.screensaverinstaller
    HKCR\screensavercontrol.screensaverinstaller.1
    HKCU\Software\AppDataLow\Software\MyWebSearch
    HKCU\Software\EoRezo
    HKCU\Software\FunWebProducts
    HKCU\Software\Grand Virtual
    HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}
    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
    HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9FF05104-B030-46FC-94B8-81276E4E27DF}
    HKCU\Software\MyWebSearch
    HKLM\Software\EoRezo
    HKLM\Software\FocusInteractive
    HKLM\Software\Fun Web Products
    HKLM\Software\FunWebProducts
    HKLM\Software\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
    HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
    HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
    HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
    HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
    HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
    HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
    HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
    HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
    HKLM\Software\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
    HKLM\Software\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin
    HKLM\Software\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin
    HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Everest Poker
    HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall
    HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdate_is1
    HKLM\Software\MyWebSearch
    HKLM\SYSTEM\ControlSet003\Services\MyWebSearchService
    HKU\S-1-5-21-3566244553-730665422-3001215702-1003\Software\Appdatalow\Software\Fun Web Products
    HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\\FunWebProducts
    HKLM\Software\Microsoft\Windows Media\Wmsdk\Sources\\F3PopularScreenSavers
    HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Email Plugin
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Eoengine
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\My Web Search Bar Search Scope Monitor
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Email Plugin
    HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Plugin
    HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\\Softwarehelper
    HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00A6FAF6-072E-44CF-8957-5838F569A31D}
    HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
    HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
    HKLM\Software\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}
    HKLM\Software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
    HKLM\Software\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
    HKLM\Software\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
    HKLM\Software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
    HKLM\Software\Classes\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}
    HKLM\Software\Classes\CLSID\{25560540-9571-4D7B-9389-0F166788785A}
    HKLM\Software\Classes\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
    HKLM\Software\Classes\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}
    HKLM\Software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
    HKLM\Software\Classes\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
    HKLM\Software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}
    HKLM\Software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
    HKLM\Software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}
    HKLM\Software\Classes\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}
    HKLM\Software\Classes\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}
    HKLM\Software\Classes\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}
    HKLM\Software\Classes\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
    HKLM\Software\Classes\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}
    HKLM\Software\Classes\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}
    HKLM\Software\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}
    HKLM\Software\Classes\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}
    HKLM\Software\Classes\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}
    HKLM\Software\Classes\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}
    HKLM\Software\Classes\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}
    HKLM\Software\Classes\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}
    0
  3. Nic00 Messages postés 1751 Statut Membre 95
     
    ▶ Relance "Ad-remover" : au menu principal choisis l'option "D"
    ▶Une fenêtre d’avertissement va alors s’ouvrir : clique sur OK

    >> Télécharge et installe Malawarebytes’Anti-Malware : :http://www.malwarebytes.org/mbam/program/mbam-setup.exe

    >> mets le à jour puis lance le en double cliquant dessus.

    >> Choisis « Exécuter un examen complet » en cliquant dessus.

    >> Clique sur Rechercher

    >> Patiente jusqu’à la fin du scan…..une fenêtre s’ouvrira, clique alors sur OK

    >> Si MalwareByte's n'a rien détecté, clique sur Ok. Un rapport va apparaître ferme-le.

    >> Si MalwareByte's a détecté des infections, clique sur Afficher les résultats puis sur Supprimer la sélection

    >> Enregistre le rapport sur ton Bureau pour le trouver plus facilement.
    >> Poste ensuite ce rapport.

    Note : Si MalwareByte's a besoin de redémarrer pour terminer la suppression, accepte en cliquant sur Ok

    ▶Reposte moi un rapport Hijacthis.

    0
    1. cindy22
       
      voila le rapport de l'anti -m

      Malwarebytes' Anti-Malware 1.37
      Version de la base de données: 2214
      Windows 6.0.6001 Service Pack 1

      02/06/2009 20:04:54
      mbam-log-2009-06-02 (20-04-54).txt

      Type de recherche: Examen complet (C:\|D:\|)
      Eléments examinés: 157857
      Temps écoulé: 36 minute(s), 20 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 51
      Valeur(s) du Registre infectée(s): 1
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 7
      Fichier(s) infecté(s): 9

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      HKEY_CLASSES_ROOT\Interface\{07b18eaa-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{07b18eac-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{1093995a-ba37-41d2-836e-091067c4ad17} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{120927bf-1700-43bc-810f-fab92549b390} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{17de5e5e-bfe3-4e83-8e1f-8755795359ec} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{1f52a5fa-a705-4415-b975-88503b291728} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{3e53e2cb-86db-4a4a-8bd9-ffeb7a64df82} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{3e720451-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{3e720453-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{63d0ed2b-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{63d0ed2d-b45b-4458-8b3b-60c69bbbd83c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{72ee7f04-15bd-4845-a005-d6711144d86a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{7473d291-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{7473d293-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{7473d295-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{7473d297-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{991aac62-b100-47ce-8b75-253965244f69} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{e79dfbc9-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{e79dfbcb-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Interface\{f87d7fb5-9dc5-4c8c-b998-d8dfe02e2978} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{d518921a-4a03-425e-9873-b9a71756821e} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{07b18ea0-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{0d26bc71-a633-4e71-ad31-eadc3a1b6a3a} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{29d67d3c-509a-4544-903f-c8c1b8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{3e720450-b472-4954-b7aa-33069eb53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{7473d290-b7bb-4f24-ae82-7e2ce94bb6a9} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{8ca01f0e-987c-49c3-b852-2f1ac4a7094c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{8e6f1830-9607-4440-8530-13be7c4b1d14} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{c8cecde3-1ae1-4c4a-ad82-6d5b00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{e47caee0-deea-464a-9326-3f2801535a4d} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{e79dfbc0-5697-4fbd-94e5-5b2a9c7c1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CLASSES_ROOT\Typelib\{f42228fb-e84e-479e-b922-fbbd096e792c} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully.

      Valeur(s) du Registre infectée(s):
      HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\akcssgq (Trojan.Agent.H) -> Quarantined and deleted successfully.

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      c:\Users\*****\AppData\Roaming\M (Trojan.Agent) -> Quarantined and deleted successfully.
      c:\Users\*****\AppData\Roaming\M\#SharedObjects (Trojan.Agent) -> Quarantined and deleted successfully.
      c:\Users\*****\AppData\Roaming\M\macromedia.com (Trojan.Agent) -> Quarantined and deleted successfully.
      c:\Users\*****\AppData\Roaming\M\macromedia.com\support (Trojan.Agent) -> Quarantined and deleted successfully.
      c:\Users\*****\AppData\Roaming\M\macromedia.com\support\flashplayer (Trojan.Agent) -> Quarantined and deleted successfully.
      c:\Users\*****\AppData\Roaming\M\macromedia.com\support\flashplayer\sys (Trojan.Agent) -> Quarantined and deleted successfully.
      c:\Users\*****AppData\Roaming\M\macromedia.com\support\flashplayer\sys\#www.prizee.com (Trojan.Agent) -> Quarantined and deleted successfully.

      Fichier(s) infecté(s):
      c:\Users\l*****local settings\application data\akcssgq_navps.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
      c:\Users\*****\local settings\application data\akcssgq_nav.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
      c:\Users\*****\local settings\application data\akcssgq.dat (Adware.Navipromo.H) -> Quarantined and deleted successfully.
      c:\Users\*****\local settings\application data\akcssgq.exe (Adware.Navipromo.H) -> Delete on reboot.
      c:\Users\*****\AppData\Local\akcssgq.exe (Trojan.Agent.H) -> Delete on reboot.
      c:\program files\ad-remover\quarantine\PROGRA~1\EVERES~1\Everest Casino.exe.vir (Rogue.AdorableCasino) -> Quarantined and deleted successfully.
      c:\program files\ad-remover\quarantine\PROGRA~1\INTERN~1\msimg32.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      c:\program files\ad-remover\quarantine\PROGRA~1\MSNMES~1\riched20.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
      c:\program files\ad-remover\quarantine\Windows\System32\f3PSSavr.scr.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.


      et voici le rapport de hijackthis :


      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:22:06, on 02/06/2009
      Platform: Windows Vista SP1 (WinNT 6.00.1905)
      MSIE: Internet Explorer v7.00 (7.00.6001.18226)
      Boot mode: Normal

      Running processes:
      C:\Windows\system32\taskeng.exe
      C:\Windows\system32\Dwm.exe
      C:\Windows\Explorer.EXE
      C:\Program Files\Windows Defender\MSASCui.exe
      C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
      C:\Windows\RtHDVCpl.exe
      C:\Program Files\Synaptics\SynTP\SynTPStart.exe
      C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
      C:\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
      C:\Windows\system32\igfxsrvc.exe
      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
      C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
      C:\Windows\Philips\SPC220NC\Monitor.exe
      C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
      C:\Windows\System32\igfxtray.exe
      C:\Windows\System32\hkcmd.exe
      C:\Windows\System32\igfxpers.exe
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Windows Sidebar\sidebar.exe
      C:\Program Files\Windows Live\Messenger\msnmsgr.exe
      C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      C:\Program Files\Philips\Philips SPC220NC Webcam\TrayMin220.exe
      C:\Users\*****\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
      C:\Acer\Empowering Technology\EPOWER\EPOWER_DMC.EXE
      C:\Users\*****~1\AppData\Local\Temp\RtkBtMnt.exe
      C:\Acer\Empowering Technology\ACER.EMPOWERING.FRAMEWORK.SUPERVISOR.EXE
      C:\Acer\Empowering Technology\eRecovery\ERAGENT.EXE
      C:\Users\*****\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
      C:\Program Files\Windows Live\Contacts\wlcomm.exe
      C:\Program Files\Internet Explorer\IEUser.exe
      C:\Program Files\Google\Google Toolbar\GoogleToolbarUser.exe
      C:\Program Files\Windows Live\Toolbar\wltuser.exe
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Windows\system32\Macromed\Flash\FlashUtil10b.exe
      C:\Users\*****\Downloads\HiJackThis.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O1 - Hosts: ::1 localhost
      O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
      O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
      O2 - BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
      O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
      O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
      O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
      O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
      O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
      O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
      O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
      O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
      O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
      O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
      O4 - HKLM\..\Run: [WarReg_PopUp] C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
      O4 - HKLM\..\Run: [Monitor] C:\Windows\Philips\SPC220NC\Monitor.exe
      O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
      O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
      O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
      O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
      O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_S7418.tmp" /EF "HKCU"
      O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
      O4 - Startup: Outil de notification Live Search.lnk = le bellec cindy\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
      O4 - Global Startup: Empowering Technology Launcher.lnk = ?
      O4 - Global Startup: TrayMin220.lnk = ?
      O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
      O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
      O9 - Extra button: Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra 'Tools' menuitem: &Envoyer à OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
      O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
      O13 - Gopher Prefix:
      O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/FR-FR/a-UNO1/GAME_UNO1.cab
      O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
      O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
      O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
      O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
      O23 - Service: eLock Service (eLockService) - Acer Inc. - C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
      O23 - Service: eNet Service - Acer Inc. - C:\Acer\Empowering Technology\eNet\eNet Service.exe
      O23 - Service: eRecovery Service (eRecoveryService) - Acer Inc. - C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
      O23 - Service: eSettings Service (eSettingsService) - Unknown owner - C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
      O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
      O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
      O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
      O23 - Service: ePower Service (WMIService) - acer - C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
      O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
      0
  4. Nic00 Messages postés 1751 Statut Membre 95
     
    >>Va dans l'onglet Quarantaine de Malwarebytes puis supprime tout ce qu'il s'y trouve.

    >>Relances Hijackthis en faisant Do a system scan only

    >>Coche ces lignes:

    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
    O4 - Global Startup: Empowering Technology Launcher.lnk = ?
    O4 - Global Startup: TrayMin220.lnk = ?

    puis clique sur Fix checked.

    Vire Avast:

    https://www.avast.com/fr-fr/uninstall-utility

    Télécharge et installe Antivir à la place:

    http://www.commentcamarche.net/telecharger/telecharger 55 antivir personal

    Mets le à jour puis fais un scan de ton PC avec.
    A la fin un rapport sera généré, poste le.

    0