Help !!! Virus su mon Pc qui veut m'aider...

Bonjour,

Depuis hier soir je me bats avec le virus Total Security version 4,52.

Il y a pas mal de discussion à ce sujet mais je ne sais pas si je peux suivre les mêms instructions.

Merci de me venir en aide.

Manu
Configuration: Windows XP Internet Explorer 7.0

39 réponses

Résumé de la discussion

La discussion porte sur une infection par Total Security version 4,52 sous Windows XP, entraînant des symptômes variés et nécessitant une désinfection en profondeur et méthodique. Des solutions essentielles ont été proposées, notamment Malwarebytes Anti-Malware (MBAM) pour un balayage complet et la suppression des éléments détectés et l'installation en suivant les instructions, puis le redémarrage éventuel pour stabiliser le système. D'autres outils utiles incluent RSIT pour générer des rapports système et ToolsCleaner pour nettoyer les restes après désinfection, ces rapports fournissant des éléments à examiner pour ajuster le traitement et éviter les réapparitions. En cas d'échec partiel, la consultation de rapports Navilog permet d'affiner le diagnostic et d'évaluer les certificats ou éléments restants, sans conclure sur l'état final.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    Bonjour, commence par faire ceci :

    RSIT ----->

    [x] Télécharge Random's System Information Tool à cette adresse : http://images.malwareremoval.com/random/RSIT.exe

    [x] Double clique sur " RSIT.exe ".

    [x] Clique sur " Continue ".

    [x] Si hijackthis n'est pas présent il sera automatiquement téléchargé et tu devras accepter la license.

    [x] Une fois l'analyse finie, deux fichiers ( info.txt & log.txt ) s'ouvriront.

    [x] Copie colle le contenu des deux rapports dans ton prochain message

    -------> Si jamais tu as fermé les rapports sans faire attention, ils sont sous C:\rsit
    0
    1. Bonjour Xplode,

      Merci de ton aide, voici les deux rapports :

      info.txt logfile of random's system information tool 1.06 2009-08-28 05:39:13

      ======Uninstall list======

      -->C:\WINDOWS\IsUn040c.exe -fC:\WINDOWS\orun32.isu
      -->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2E47302B-8081-46D3-9FEA-BEB2E5F5C3EC}\SETUP.EXE" -l0x40c anything
      -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
      ABBYY FineReader 6.0 Sprint-->MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}
      Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
      Adobe Reader 7.0-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70000000000}
      Adobe Shockwave Player-->C:\WINDOWS\system32\MACROMED\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\MACROMED\SHOCKW~1\Install.log
      Apple Software Update-->MsiExec.exe /I{A260B422-70E1-41E2-957D-F76FA21266D5}
      Assistant de connexion Windows Live-->MsiExec.exe /I{D3116CC7-24DC-4CA3-9CE1-23FED836E9F2}
      ASUS InstantFun-->MsiExec.exe /I{57B15AD4-8C9D-4164-82BB-E33D8644E757}
      ASUS Live Update-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}\setup.exe" -l0x9
      Asus MiVo Messenger-->"C:\Program Files\Asus\Asus MiVo Messenger\uninstall.exe"
      Asus MultiFrame-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9D48531D-2135-49FC-BC29-ACCDA5396A76}\SETUP.EXE" -l0x9
      ASUS Splendid Video Enhancement Technology-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C0FC1C14-4824-4A73-87A6-9E888C9C3102}\SETUP.exe" -l0x9 -removeonly
      ASUSDVD-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\Setup.exe" -uninstall
      ATK Media-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{139B0FFA-187E-4BA1-BCA6-6B56B2B6AB8C}\SETUP.EXE" -l0x9
      ATK0100 ACPI UTILITY-->C:\WINDOWS\ATK0100\XPunin.exe
      avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
      Bluetooth Stack for Windows-->MsiExec.exe /X{CEBB6BFB-D708-4F99-A633-BC2600E01EF6}
      Carlson Dialer-->C:\Program Files\Fichiers communs\Carlson\carlton -u
      Correctif pour Windows Internet Explorer 7 (KB947864)-->"C:\WINDOWS\ie7updates\KB947864-IE7\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB914440)-->"C:\WINDOWS\$NtUninstallKB914440$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB918005)-->"C:\WINDOWS\$NtUninstallKB918005$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB935448)-->"C:\WINDOWS\$NtUninstallKB935448$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
      Correctif pour Windows XP (KB970653-v3)-->"C:\WINDOWS\$NtUninstallKB970653-v3$\spuninst\spuninst.exe"
      Correctif Windows XP - KB873339-->C:\WINDOWS\$NtUninstallKB873339$\spuninst\spuninst.exe
      Correctif Windows XP - KB885835-->C:\WINDOWS\$NtUninstallKB885835$\spuninst\spuninst.exe
      Correctif Windows XP - KB885836-->C:\WINDOWS\$NtUninstallKB885836$\spuninst\spuninst.exe
      Correctif Windows XP - KB886185-->C:\WINDOWS\$NtUninstallKB886185$\spuninst\spuninst.exe
      Correctif Windows XP - KB887472-->C:\WINDOWS\$NtUninstallKB887472$\spuninst\spuninst.exe
      Correctif Windows XP - KB888302-->C:\WINDOWS\$NtUninstallKB888302$\spuninst\spuninst.exe
      Correctif Windows XP - KB890859-->"C:\WINDOWS\$NtUninstallKB890859$\spuninst\spuninst.exe"
      Correctif Windows XP - KB891781-->C:\WINDOWS\$NtUninstallKB891781$\spuninst\spuninst.exe
      DivX Content Uploader-->C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER
      DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
      EPSON Attach To Email-->C:\Program Files\Fichiers communs\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
      EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x40c -UnInstall
      EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BC69DDB8-4840-4D9B-BB31-0D4DB2BA1312}\SETUP.EXE" -l0x40c UNINST
      EPSON File Manager-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x40c UNINST
      EPSON Logiciel imprimante-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
      EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x40c -u
      EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
      EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x40c -anything
      ESDX6000_CX5900 Guide util.-->C:\Program Files\EPSON\TPMANUAL\ESDX6000_CX5900\USE_G\DOCUNINS.EXE
      Favorit-->"c:\documents and settings\emmanuelle richard\local settings\application data\lkigf.exe" -uninstall
      HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall
      Hotfix for Windows Media Format 11 SDK (KB929399)-->"C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
      Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
      Hotfix for Windows XP (KB926239)-->"C:\WINDOWS\$NtUninstallKB926239$\spuninst\spuninst.exe"
      Java(TM) 6 Update 2-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020}
      LifeFrame2-->MsiExec.exe /I{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}
      LimeWire 4.18.8-->"C:\Program Files\LimeWire\uninstall.exe"
      LiveUpdate 3.0 (Symantec Corporation)-->"C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE" /U
      Logiciel Intel(R) PROSet/Wireless-->C:\WINDOWS\Installer\iProInst.exe
      mCore-->MsiExec.exe /I{E81667C6-2856-46D6-ABEA-6A2F42166779}
      mDriver-->MsiExec.exe /I{A0F925BF-5C55-44C2-A4E7-5A4C59791C29}
      mDrWiFi-->MsiExec.exe /I{90CC4231-94AC-45CD-991A-0253BFAC0650}
      Media Player Classic fr-->"C:\Program Files\Media Player Classic\uninstall.exe"
      mHelp-->MsiExec.exe /I{8C6BB412-D3A8-4AAE-A01B-35B681789D68}
      Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
      Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
      Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
      Microsoft Office 2000 CD-ROM 2-->MsiExec.exe /I{0004040C-78E1-11D2-B60F-006097C998E7}
      Microsoft Office 2000 Premium-->MsiExec.exe /I{0000040C-78E1-11D2-B60F-006097C998E7}
      Microsoft Silverlight-->MsiExec.exe /X{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
      Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB911564)-->"C:\WINDOWS\$NtUninstallKB911564$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB952069)-->"C:\WINDOWS\$NtUninstallKB952069_WM9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media (KB973540)-->"C:\WINDOWS\$NtUninstallKB973540_WM9L$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 6.4 (KB925398)-->"C:\WINDOWS\$NtUninstallKB925398_WMP64$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 9 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Lecteur Windows Media 9 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP9$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Step by Step Interactive Training (KB898458)-->"C:\WINDOWS\$NtUninstallKB898458$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Step by Step Interactive Training (KB923723)-->"C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB942615)-->"C:\WINDOWS\ie7updates\KB942615-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB944533)-->"C:\WINDOWS\ie7updates\KB944533-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB950759)-->"C:\WINDOWS\ie7updates\KB950759-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB958215)-->"C:\WINDOWS\ie7updates\KB958215-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB960714)-->"C:\WINDOWS\ie7updates\KB960714-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB961260)-->"C:\WINDOWS\ie7updates\KB961260-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB963027)-->"C:\WINDOWS\ie7updates\KB963027-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB969897)-->"C:\WINDOWS\ie7updates\KB969897-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows Internet Explorer 7 (KB972260)-->"C:\WINDOWS\ie7updates\KB972260-IE7\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB893756)-->"C:\WINDOWS\$NtUninstallKB893756$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB896358)-->"C:\WINDOWS\$NtUninstallKB896358$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB896423)-->"C:\WINDOWS\$NtUninstallKB896423$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB896424)-->"C:\WINDOWS\$NtUninstallKB896424$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB896428)-->"C:\WINDOWS\$NtUninstallKB896428$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB899587)-->"C:\WINDOWS\$NtUninstallKB899587$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB899591)-->"C:\WINDOWS\$NtUninstallKB899591$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB900725)-->"C:\WINDOWS\$NtUninstallKB900725$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB901017)-->"C:\WINDOWS\$NtUninstallKB901017$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB901190)-->"C:\WINDOWS\$NtUninstallKB901190$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB901214)-->"C:\WINDOWS\$NtUninstallKB901214$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB902400)-->"C:\WINDOWS\$NtUninstallKB902400$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB904706)-->"C:\WINDOWS\$NtUninstallKB904706$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB905414)-->"C:\WINDOWS\$NtUninstallKB905414$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB905749)-->"C:\WINDOWS\$NtUninstallKB905749$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB908519)-->"C:\WINDOWS\$NtUninstallKB908519$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB911562)-->"C:\WINDOWS\$NtUninstallKB911562$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB911927)-->"C:\WINDOWS\$NtUninstallKB911927$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB912919)-->"C:\WINDOWS\$NtUninstallKB912919$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB913580)-->"C:\WINDOWS\$NtUninstallKB913580$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB914388)-->"C:\WINDOWS\$NtUninstallKB914388$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB914389)-->"C:\WINDOWS\$NtUninstallKB914389$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB917344)-->"C:\WINDOWS\$NtUninstallKB917344$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB917422)-->"C:\WINDOWS\$NtUninstallKB917422$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB917953)-->"C:\WINDOWS\$NtUninstallKB917953$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB918118)-->"C:\WINDOWS\$NtUninstallKB918118$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB918439)-->"C:\WINDOWS\$NtUninstallKB918439$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB919007)-->"C:\WINDOWS\$NtUninstallKB919007$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB920213)-->"C:\WINDOWS\$NtUninstallKB920213$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB920670)-->"C:\WINDOWS\$NtUninstallKB920670$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB920683)-->"C:\WINDOWS\$NtUninstallKB920683$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB920685)-->"C:\WINDOWS\$NtUninstallKB920685$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB921398)-->"C:\WINDOWS\$NtUninstallKB921398$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB921503)-->"C:\WINDOWS\$NtUninstallKB921503$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB922616)-->"C:\WINDOWS\$NtUninstallKB922616$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB922819)-->"C:\WINDOWS\$NtUninstallKB922819$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923191)-->"C:\WINDOWS\$NtUninstallKB923191$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923414)-->"C:\WINDOWS\$NtUninstallKB923414$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923561)-->"C:\WINDOWS\$NtUninstallKB923561$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923689)-->"C:\WINDOWS\$NtUninstallKB923689$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923694)-->"C:\WINDOWS\$NtUninstallKB923694$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB923980)-->"C:\WINDOWS\$NtUninstallKB923980$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB924191)-->"C:\WINDOWS\$NtUninstallKB924191$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB924270)-->"C:\WINDOWS\$NtUninstallKB924270$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB924496)-->"C:\WINDOWS\$NtUninstallKB924496$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB924667)-->"C:\WINDOWS\$NtUninstallKB924667$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB925454)-->"C:\WINDOWS\$NtUninstallKB925454$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB925902)-->"C:\WINDOWS\$NtUninstallKB925902$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB926255)-->"C:\WINDOWS\$NtUninstallKB926255$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB926436)-->"C:\WINDOWS\$NtUninstallKB926436$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB927779)-->"C:\WINDOWS\$NtUninstallKB927779$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB927802)-->"C:\WINDOWS\$NtUninstallKB927802$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB928090)-->"C:\WINDOWS\$NtUninstallKB928090$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB928255)-->"C:\WINDOWS\$NtUninstallKB928255$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB928843)-->"C:\WINDOWS\$NtUninstallKB928843$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB929123)-->"C:\WINDOWS\$NtUninstallKB929123$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB929969)-->"C:\WINDOWS\$NtUninstallKB929969$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB930178)-->"C:\WINDOWS\$NtUninstallKB930178$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB931261)-->"C:\WINDOWS\$NtUninstallKB931261$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB931768)-->"C:\WINDOWS\$NtUninstallKB931768$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB931784)-->"C:\WINDOWS\$NtUninstallKB931784$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB932168)-->"C:\WINDOWS\$NtUninstallKB932168$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB933729)-->"C:\WINDOWS\$NtUninstallKB933729$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB935839)-->"C:\WINDOWS\$NtUninstallKB935839$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB935840)-->"C:\WINDOWS\$NtUninstallKB935840$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB936021)-->"C:\WINDOWS\$NtUninstallKB936021$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB937143)-->"C:\WINDOWS\$NtUninstallKB937143$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938127)-->"C:\WINDOWS\$NtUninstallKB938127$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB938829)-->"C:\WINDOWS\$NtUninstallKB938829$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB939653)-->"C:\WINDOWS\$NtUninstallKB939653$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941202)-->"C:\WINDOWS\$NtUninstallKB941202$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941568)-->"C:\WINDOWS\$NtUninstallKB941568$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941644)-->"C:\WINDOWS\$NtUninstallKB941644$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB941693)-->"C:\WINDOWS\$NtUninstallKB941693$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB942615)-->"C:\WINDOWS\$NtUninstallKB942615$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB943055)-->"C:\WINDOWS\$NtUninstallKB943055$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB943460)-->"C:\WINDOWS\$NtUninstallKB943460$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB943485)-->"C:\WINDOWS\$NtUninstallKB943485$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB944653)-->"C:\WINDOWS\$NtUninstallKB944653$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB945553)-->"C:\WINDOWS\$NtUninstallKB945553$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946026)-->"C:\WINDOWS\$NtUninstallKB946026$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB948590)-->"C:\WINDOWS\$NtUninstallKB948590$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB948881)-->"C:\WINDOWS\$NtUninstallKB948881$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950749)-->"C:\WINDOWS\$NtUninstallKB950749$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952004)-->"C:\WINDOWS\$NtUninstallKB952004$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB954600)-->"C:\WINDOWS\$NtUninstallKB954600$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB955069)-->"C:\WINDOWS\$NtUninstallKB955069$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956572)-->"C:\WINDOWS\$NtUninstallKB956572$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956802)-->"C:\WINDOWS\$NtUninstallKB956802$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB957097)-->"C:\WINDOWS\$NtUninstallKB957097$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958470)-->"C:\WINDOWS\$NtUninstallKB958470$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958687)-->"C:\WINDOWS\$NtUninstallKB958687$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB958690)-->"C:\WINDOWS\$NtUninstallKB958690$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB959426)-->"C:\WINDOWS\$NtUninstallKB959426$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960225)-->"C:\WINDOWS\$NtUninstallKB960225$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960715)-->"C:\WINDOWS\$NtUninstallKB960715$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960803)-->"C:\WINDOWS\$NtUninstallKB960803$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB960859)-->"C:\WINDOWS\$NtUninstallKB960859$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961371)-->"C:\WINDOWS\$NtUninstallKB961371$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961373)-->"C:\WINDOWS\$NtUninstallKB961373$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB961501)-->"C:\WINDOWS\$NtUninstallKB961501$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB968537)-->"C:\WINDOWS\$NtUninstallKB968537$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB969898)-->"C:\WINDOWS\$NtUninstallKB969898$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB970238)-->"C:\WINDOWS\$NtUninstallKB970238$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971557)-->"C:\WINDOWS\$NtUninstallKB971557$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971633)-->"C:\WINDOWS\$NtUninstallKB971633$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB971657)-->"C:\WINDOWS\$NtUninstallKB971657$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973346)-->"C:\WINDOWS\$NtUninstallKB973346$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973354)-->"C:\WINDOWS\$NtUninstallKB973354$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973507)-->"C:\WINDOWS\$NtUninstallKB973507$\spuninst\spuninst.exe"
      Mise à jour de sécurité pour Windows XP (KB973869)-->"C:\WINDOWS\$NtUninstallKB973869$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB894391)-->"C:\WINDOWS\$NtUninstallKB894391$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB900485)-->"C:\WINDOWS\$NtUninstallKB900485$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB904942)-->"C:\WINDOWS\$NtUninstallKB904942$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB908531)-->"C:\WINDOWS\$NtUninstallKB908531$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB910437)-->"C:\WINDOWS\$NtUninstallKB910437$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB911280)-->"C:\WINDOWS\$NtUninstallKB911280$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB916595)-->"C:\WINDOWS\$NtUninstallKB916595$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB920872)-->"C:\WINDOWS\$NtUninstallKB920872$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB922582)-->"C:\WINDOWS\$NtUninstallKB922582$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB927891)-->"C:\WINDOWS\$NtUninstallKB927891$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB929338)-->"C:\WINDOWS\$NtUninstallKB929338$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB930916)-->"C:\WINDOWS\$NtUninstallKB930916$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB931836)-->"C:\WINDOWS\$NtUninstallKB931836$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB932823-v3)-->"C:\WINDOWS\$NtUninstallKB932823-v3$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB933360)-->"C:\WINDOWS\$NtUninstallKB933360$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB936357)-->"C:\WINDOWS\$NtUninstallKB936357$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB938828)-->"C:\WINDOWS\$NtUninstallKB938828$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB942763)-->"C:\WINDOWS\$NtUninstallKB942763$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB942840)-->"C:\WINDOWS\$NtUninstallKB942840$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB955839)-->"C:\WINDOWS\$NtUninstallKB955839$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB967715)-->"C:\WINDOWS\$NtUninstallKB967715$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB968389)-->"C:\WINDOWS\$NtUninstallKB968389$\spuninst\spuninst.exe"
      Mise à jour pour Windows XP (KB973815)-->"C:\WINDOWS\$NtUninstallKB973815$\spuninst\spuninst.exe"
      mIWA-->MsiExec.exe /I{3E9D596A-61D4-4239-BD19-2DB984D2A16F}
      mLogView-->MsiExec.exe /I{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}
      mMHouse-->MsiExec.exe /I{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}
      Motorola SM56 Speakerphone Modem-->C:\Program Files\Asus\Asus MiVo Messenger\uninstall.exe /mdm
      mPfMgr-->MsiExec.exe /I{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}
      mPfWiz-->MsiExec.exe /I{90B0D222-8C21-4B35-9262-53B042F18AF9}
      mProSafe-->MsiExec.exe /I{23FB368F-1399-4EAC-817C-4B83ECBE3D83}
      MSXML 4.0 SP2 (KB927978)-->MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F}
      MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
      MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
      mWlsSafe-->MsiExec.exe /I{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}
      mXML-->MsiExec.exe /I{9CC89556-3578-48DD-8408-04E66EBEF401}
      My Web Search (Zwinky)-->rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsbar.dll,O
      mZConfig-->MsiExec.exe /I{94658027-9F16-4509-BBD7-A59FE57C3023}
      Nero OEM-->C:\Program Files\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL
      Net4Switch-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9D6D7811-43B3-463C-BC79-5D1755269989}\SETUP.EXE" -l0x9
      NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
      PCFriendly-->C:\Program Files\PCFriendly\inuninst.exe
      PIF DESIGNER-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B90450DF-E781-46FD-B1F1-0C86DA40E443}\SETUP.EXE" -l0x40c anything
      Power4 Gear-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{4462AD13-F2AA-4CBD-9F95-293C38EED870}\setup.exe" -l0x9
      PowerForPhone-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{89DDBCD4-B326-4545-9A05-26C7B16C1DEB}\SETUP.EXE" -l0x9
      QuickTime-->MsiExec.exe /I{5E863175-E85D-44A6-8968-82507D34AE7F}
      Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\SETUP.exe" -l0x40c -removeonly
      REALTEK PCIE NIC Driver-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{17E2F183-BAC4-4D01-BD7A-59F781E17EFA}\SETUP.EXE" -l0x40c REMOVE
      SAMSUNG CDMA Modem Driver Set-->C:\WINDOWS\system32\Samsung_USB_Drivers\3\SSCDUninstall.exe
      SAMSUNG Mobile USB Modem 1.0 Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\1\SS_Uninstall.exe
      SAMSUNG Mobile USB Modem Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\2\SSM_Uninstall.exe
      Samsung PC Studio-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C4A4722E-79F9-417C-BD72-8D359A090C97}\setup.exe" -l0x40c -removeonly
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Security Update for CAPICOM (KB931906)-->MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A}
      Skype™ 3.6-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
      Synaptics Pointing Device Driver-->rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall
      USB2.0 1.3M WebCam-->C:\WINDOWS\StkUnist.exe
      VideoLAN VLC media player 0.8.1-->C:\Program Files\VideoLAN\VLC\uninstall.exe
      Vodafone 804SS USB driver Software-->C:\WINDOWS\system32\Samsung_USB_Drivers\4\SSVDUninstall.exe
      Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
      Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
      Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
      Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
      Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
      Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
      WinFlash-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DE10AB76-4756-4913-BE25-55D1C1051F9A}\setup.exe" -l0x9
      Wireless Console 2-->RunDll32 C:\PROGRA~1\FICHIE~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{83F73CB1-7705-49D1-9852-84D839CA2A45}\setup.exe" -l0x9 -removeonly

      ======Hosts File======

      127.0.0.1 localhost

      ======Security center information======

      AV: avast! antivirus 4.8.1351 [VPS 090827-0]
      FW: Norton Internet Worm Protection (disabled)

      ======System event log======

      Computer Name: MANU
      Event Code: 6009
      Message: Microsoft (R) Windows (R) 5.01. 2600 Service Pack 2 Multiprocessor Free.

      Record Number: 90532
      Source Name: EventLog
      Time Written: 20090804065744.000000-240
      Event Type: Informations
      User:

      Computer Name: MANU
      Event Code: 6006
      Message: Le service d'Enregistrement d'événement a été arrêté.

      Record Number: 90531
      Source Name: EventLog
      Time Written: 20090802193829.000000-240
      Event Type: Informations
      User:

      Computer Name: MANU
      Event Code: 7036
      Message: Le service Service de transfert intelligent en arrière-plan est entré dans l'état : en cours d'exécution.

      Record Number: 90530
      Source Name: Service Control Manager
      Time Written: 20090802170112.000000-240
      Event Type: Informations
      User:

      Computer Name: MANU
      Event Code: 7035
      Message: Un contrôle Démarrer a correctement été envoyé au service Service de transfert intelligent en arrière-plan.

      Record Number: 90529
      Source Name: Service Control Manager
      Time Written: 20090802170112.000000-240
      Event Type: Informations
      User: AUTORITE NT\SYSTEM

      Computer Name: MANU
      Event Code: 7036
      Message: Le service Configuration automatique sans fil est entré dans l'état : arrêté.

      Record Number: 90528
      Source Name: Service Control Manager
      Time Written: 20090802165614.000000-240
      Event Type: Informations
      User:

      =====Application event log=====

      Computer Name: MANU
      Event Code: 1800
      Message: Le service Centre de sécurité Windows a démarré.

      Record Number: 9538
      Source Name: SecurityCenter
      Time Written: 20090209224116.000000-240
      Event Type: Informations
      User:

      Computer Name: MANU
      Event Code: 0
      Message:
      Record Number: 9537
      Source Name: RegSrvc
      Time Written: 20090209224116.000000-240
      Event Type: Informations
      User:

      Computer Name: MANU
      Event Code: 101
      Message: Niveau d'information : success

      Service démarré.

      Record Number: 9536
      Source Name: Automatic LiveUpdate Scheduler
      Time Written: 20090209224115.000000-240
      Event Type: Informations
      User: AUTORITE NT\SYSTEM

      Computer Name: MANU
      Event Code: 4
      Message: The LightScribe Service started successfully.

      Record Number: 9535
      Source Name: LightScribeService
      Time Written: 20090209224115.000000-240
      Event Type: Informations
      User:

      Computer Name: MANU
      Event Code: 0
      Message:
      Record Number: 9534
      Source Name: EvtEng
      Time Written: 20090209224112.000000-240
      Event Type: Informations
      User:

      ======Environment variables======

      "ComSpec"=%SystemRoot%\system32\cmd.exe
      "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Samsung\Samsung PC Studio 3\;C:\Program Files\QuickTime\QTSystem\
      "windir"=%SystemRoot%
      "FP_NO_HOST_CHECK"=NO
      "OS"=Windows_NT
      "PROCESSOR_ARCHITECTURE"=x86
      "PROCESSOR_LEVEL"=6
      "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 6, GenuineIntel
      "PROCESSOR_REVISION"=0f06
      "NUMBER_OF_PROCESSORS"=2
      "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
      "TEMP"=%SystemRoot%\TEMP
      "TMP"=%SystemRoot%\TEMP
      "CLASSPATH"=.;C:\Program Files\QuickTime\QTSystem\QTJava.zip
      "QTJAVA"=C:\Program Files\QuickTime\QTSystem\QTJava.zip

      -----------------EOF-----------------

      Logfile of random's system information tool 1.06 (written by random/random)
      Run by Emmanuelle RICHARD at 2009-08-28 05:38:57
      Microsoft Windows XP Édition familiale Service Pack 2
      System drive C: has 24 GB (42%) free of 56 GB
      Total RAM: 1023 MB (36% free)

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 05:39:11, on 28/08/2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16876)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      C:\Program Files\Alwil Software\Avast4\ashServ.exe
      C:\WINDOWS\system32\spoolsv.exe
      c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\ATK0100\HControl.exe
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\WINDOWS\RTHDCPL.EXE
      C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
      C:\Program Files\ASUS\ASUS Live Update\ALU.exe
      C:\Program Files\ASUS\Splendid\ACMON.exe
      C:\Program Files\Wireless Console 2\wcourier.exe
      C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
      C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe
      C:\WINDOWS\system32\ACEngSvr.exe
      C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
      C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
      C:\WINDOWS\ATK0100\ATKOSD.exe
      C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
      C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
      C:\WINDOWS\system32\mset.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Documents and Settings\All Users\Application Data\14668594\14668594.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\documents and settings\emmanuelle richard\local settings\application data\lkigf.exe
      C:\Documents and Settings\Emmanuelle RICHARD\mset.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe
      C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
      C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Internet Explorer\iexplore.exe
      C:\Documents and Settings\Emmanuelle RICHARD\Local Settings\Temporary Internet Files\Content.IE5\PANS9STU\RSIT[1].exe
      C:\Program Files\trend micro\Emmanuelle RICHARD.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange HSS\SearchURLHook\SearchPageURL.dll (file missing)
      R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
      O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
      O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
      O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
      O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
      O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
      O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
      O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
      O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
      O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
      O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
      O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
      O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
      O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
      O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
      O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
      O4 - HKLM\..\Run: [EPSON Stylus DX6000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE /FU "C:\WINDOWS\TEMP\E_S92.tmp" /EF "HKLM"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
      O4 - HKLM\..\Run: [msimn.exe] C:\WINDOWS\msimn.exe
      O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1148.exe 61A847B5BBF72813339F30466188719AB689201522886B092CBD44BD8689220221DD3257
      O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
      O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
      O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h
      O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
      O4 - HKLM\..\Run: [mset] C:\WINDOWS\system32\mset.exe
      O4 - HKLM\..\Run: [14668594] C:\Documents and Settings\All Users\Application Data\14668594\14668594.exe
      O4 - HKLM\..\Run: [PC Antispyware 2010] "C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe" /hide
      O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
      O4 - HKCU\..\Run: [lkigf] "c:\documents and settings\emmanuelle richard\local settings\application data\lkigf.exe" lkigf
      O4 - HKCU\..\Run: [mset] C:\Documents and Settings\Emmanuelle RICHARD\mset.exe
      O4 - HKCU\..\Run: [Net4Switch] C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - Startup: ikowin32.exe
      O4 - Global Startup: MultiFrame.lnk = ?
      O4 - Global Startup: Bluetooth Manager.lnk = ?
      O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
      O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm150YYGP
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
      O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
      O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
      O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/ZwinkyInitialSetup1.0.1.1.cab
      O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
      O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
      O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
      O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
      O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
      O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
      O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
      O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
      O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
      O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
      O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
      O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
      O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
      O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
      O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
      0
      1. Contributeur sécurité
        Eh ben t'en as du monde sur ton PC !

        Commence par faire ceci :

                        +-+-+-+-+-+-+-+-+-+-+ Toolbar S&D +-+-+-+-+-+-+-+-+-+-+


        [x] Télécharge Toolbar S&D Ici : https://77b4795d-a-62cb3a1a-s-sites.googlegroups.com/site/eric71mespages/ToolBarSD.exe?attachauth=ANoY7cqJWPphpudyTqv7TRo5RQ3nm_Sx8JluVMO59X5E9cyE3j3LqKlmStIqiDqJdIgMJLi7MXn2nKVajQfoWuVvZZ2wIx_vkqO4k4P0K9jh-ra9jaKPXdZcoaVF2UqJZNH8ubL_42uIwh6f35xJ2GJMuzddVj2Qth1DgZ839lxEIFGkgWz3TdfvNMy-YtxfA3gqBUrj4U4LFeAPiWr3ClmjIP0t_Xs5PQ%3D%3D&attredirects=2

        [x] Suis le tutorial disponible à cette adresse : https://www.malekal.com/adwcleaner-supprimer-virus-adwares-pup/

        [x] </gras>Lance l'option 1 ( Recherche )</gras>

        [x] Puis copie/colle le rapport dans ton prochain message ( Il se trouve sous C:\TB.txt )

        ------------------------------------------------

        Puis ça :

        Ad-Remover ---->

        [x] Si tu es sous vista : Désactive l'UAC (Menu Démarrer \ Panneau de Configuration \ Comptes d'utilisateurs et protection des utilisateurs \ Comptes d'utilisateurs \ Activer ou désactiver le contrôle des comptes d'utilisateurs \ décoche la case Utiliser le contrôle ... et valide par OK , il te sera demandé de redémarrer, fais le)

        [x] Télécharge Ad-remover (de C_XX) sur ton bureau : http://sd-1.archive-host.com/membres/up/16506160323759868/AD-R.exe

        [x] Lance l'installation avec les paramètres par défaut..

        ! Déconnecte toi et ferme toutes applications en cours !

        [x] Double-clique sur le raccourci Ad-Remover sur ton Bureau.(Clic droit -> "Exécuter en tant qu'administrateur". ( Pour Vista)

        [x] Séléctionne l'option F pour français

        [x] A la fenêtre qui s'affiche clique sur " oui "

        [x] Séléctionne l'option S

        [x] Laisse l'outil travailler.

        [x] Une fois le scan fini, appuie sur une touche, le rapport s'ouvre

        [x] Copie/colle le dans ton prochain post
        0
        1. Bonjour Gwadema,

          Je suis tombé sur une autre discussion à ce sujet:

          http://www.commentcamarche.net/forum/affich-14025199-probleme-avec-total-security-version-4-52

          Je pense que tu peux suivre les mêmes instructions suivant ton OS.
          Apparemment les manipulations sembles êtres différentes suivant vista et XP.

          J’espère avoir répondu à ta question.

          Cordialement.
          0
          1. Contributeur sécurité
            Chaque cas est différent et il possède plusieurs infections ( pas que total security )

            Il est préférable qu'il suive ma méthode.
            0
        2. Rapport Toolbar :

          Logfile of random's system information tool 1.06 (written by random/random)
          Run by Emmanuelle RICHARD at 2009-08-28 05:38:57
          Microsoft Windows XP Édition familiale Service Pack 2
          System drive C: has 24 GB (42%) free of 56 GB
          Total RAM: 1023 MB (36% free)

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 05:39:11, on 28/08/2009
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16876)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\WINDOWS\system32\spoolsv.exe
          c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          C:\WINDOWS\system32\nvsvc32.exe
          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\WINDOWS\Explorer.EXE
          C:\WINDOWS\ATK0100\HControl.exe
          C:\WINDOWS\system32\RUNDLL32.EXE
          C:\WINDOWS\RTHDCPL.EXE
          C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
          C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
          C:\Program Files\ASUS\ASUS Live Update\ALU.exe
          C:\Program Files\ASUS\Splendid\ACMON.exe
          C:\Program Files\Wireless Console 2\wcourier.exe
          C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
          C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe
          C:\WINDOWS\system32\ACEngSvr.exe
          C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
          C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
          C:\Program Files\QuickTime\qttask.exe
          C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
          C:\WINDOWS\ATK0100\ATKOSD.exe
          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe
          C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
          C:\WINDOWS\system32\mset.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Documents and Settings\All Users\Application Data\14668594\14668594.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
          C:\documents and settings\emmanuelle richard\local settings\application data\lkigf.exe
          C:\Documents and Settings\Emmanuelle RICHARD\mset.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\ASUS\Asus MultiFrame\MultiFrame.exe
          C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosOBEX.exe
          C:\Program Files\Toshiba\Bluetooth Toshiba Stack\tosBtProc.exe
          C:\WINDOWS\system32\wuauclt.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Documents and Settings\Emmanuelle RICHARD\Local Settings\Temporary Internet Files\Content.IE5\PANS9STU\RSIT[1].exe
          C:\Program Files\trend micro\Emmanuelle RICHARD.exe

          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\Program Files\Orange HSS\SearchURLHook\SearchPageURL.dll (file missing)
          R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
          O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
          O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
          O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
          O3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
          O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
          O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
          O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
          O4 - HKLM\..\Run: [PowerForPhone] C:\Program Files\PowerForPhone\PowerForPhone\PowerForPhone.exe
          O4 - HKLM\..\Run: [ASUS Live Update] C:\Program Files\ASUS\ASUS Live Update\ALU.exe
          O4 - HKLM\..\Run: [ACMON] C:\Program Files\ASUS\Splendid\ACMON.exe
          O4 - HKLM\..\Run: [Wireless Console 2] C:\Program Files\Wireless Console 2\wcourier.exe
          O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE
          O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          O4 - HKLM\..\Run: [ABLKSR] C:\WINDOWS\ABLKSR\ABLKSR.exe
          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTek\ASUSDVD\PDVDServ.exe"
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [Power_Gear] C:\Program Files\ASUS\Power4 Gear\BatteryLife.exe 1
          O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
          O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
          O4 - HKLM\..\Run: [EPSON Stylus DX6000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBIE.EXE /FU "C:\WINDOWS\TEMP\E_S92.tmp" /EF "HKLM"
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
          O4 - HKLM\..\Run: [msimn.exe] C:\WINDOWS\msimn.exe
          O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1148.exe 61A847B5BBF72813339F30466188719AB689201522886B092CBD44BD8689220221DD3257
          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
          O4 - HKLM\..\Run: [MyWebSearch Plugin] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\M3PLUGIN.DLL,UPF
          O4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /w /h
          O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
          O4 - HKLM\..\Run: [mset] C:\WINDOWS\system32\mset.exe
          O4 - HKLM\..\Run: [14668594] C:\Documents and Settings\All Users\Application Data\14668594\14668594.exe
          O4 - HKLM\..\Run: [PC Antispyware 2010] "C:\Program Files\PC_Antispyware2010\PC_Antispyware2010.exe" /hide
          O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe
          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
          O4 - HKCU\..\Run: [lkigf] "c:\documents and settings\emmanuelle richard\local settings\application data\lkigf.exe" lkigf
          O4 - HKCU\..\Run: [mset] C:\Documents and Settings\Emmanuelle RICHARD\mset.exe
          O4 - HKCU\..\Run: [Net4Switch] C:\Program Files\ASUS\Net4Switch\Net4Switch.exe
          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
          O4 - Startup: ikowin32.exe
          O4 - Global Startup: MultiFrame.lnk = ?
          O4 - Global Startup: Bluetooth Manager.lnk = ?
          O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
          O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm150YYGP
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
          O14 - IERESET.INF: START_PAGE_URL=https://www.asus.com/fr/
          O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
          O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei-4/ZwinkyInitialSetup1.0.1.1.cab
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx1.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab
          O16 - DPF: {5D637FAD-E202-48D1-8F18-5B9C459BD1E3} (Image Uploader Control) - http://copainsdavant.linternaute.com/...
          O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
          O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
          O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
          O23 - Service: Service de l'iPod (iPod Service) - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
          O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
          O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
          O23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exe
          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
          O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
          O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
          O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
          0
          1. Contributeur sécurité
            C'est un log RSIT que tu viens de reposter ^^'

            Il me faut le log de Toolbar S&D et celui D'AD-remover
            0
        3. Le rapprt Toolbar

          -----------\\ ToolBar S&D 1.2.9 XP/Vista

          Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
          X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU T5600 @ 1.83GHz )
          BIOS : Default System BIOS
          USER : Emmanuelle RICHARD ( Administrator )
          BOOT : Normal boot
          Antivirus : avast! antivirus 4.8.1351 [VPS 090827-0] 4.8.1351 (Activated)
          Firewall : Norton Internet Worm Protection 2006 (Not Activated)
          C:\ (Local Disk) - FAT32 - Total:54 Go (Free:23 Go)
          D:\ (Local Disk) - NTFS - Total:36 Go (Free:8 Go)
          E:\ (CD or DVD)

          "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
          Option : [1] ( 28/08/2009| 5:50 )

          -----------\\ Recherche de Fichiers / Dossiers ...

          [Service] MyWebSearchService
          C:\Program Files\FunWebProducts
          C:\Program Files\FunWebProducts\ScreenSaver
          C:\Program Files\FunWebProducts\Shared
          C:\Program Files\FunWebProducts\ScreenSaver\Images
          C:\Program Files\FunWebProducts\Shared\Cache
          C:\Program Files\FunWebProducts\Shared\Cache\SmileyCentralBtn.html
          C:\Program Files\FunWebProducts\Shared\Cache\CursorManiaBtn.html
          C:\Program Files\FunWebProducts\Shared\Cache\MyFunCardsIMBtn.html
          C:\Program Files\FunWebProducts\Shared\Cache\WebfettiBtn.html
          C:\Program Files\MyWebSearch
          C:\Program Files\MyWebSearch\bar
          C:\Program Files\MyWebSearch\bar\1.bin
          C:\Program Files\MyWebSearch\bar\Avatar
          C:\Program Files\MyWebSearch\bar\Message
          C:\Program Files\MyWebSearch\bar\Notifier
          C:\Program Files\MyWebSearch\bar\Game
          C:\Program Files\MyWebSearch\bar\icons
          C:\Program Files\MyWebSearch\bar\Settings
          C:\Program Files\MyWebSearch\bar\Cache
          C:\Program Files\MyWebSearch\bar\History
          C:\Program Files\MyWebSearch\bar\1.bin\F3BKGERR.JPG
          C:\Program Files\MyWebSearch\bar\1.bin\F3CJPEG.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\F3DTACTL.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\F3HISTSW.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\F3HTMLMU.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\F3HTTPCT.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\F3POPSWT.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\F3PSSAVR.SCR
          C:\Program Files\MyWebSearch\bar\1.bin\F3REGHK.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\F3RESTUB.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\F3SCHMON.EXE
          C:\Program Files\MyWebSearch\bar\1.bin\F3SCRCTR.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\F3SPACER.WMV
          C:\Program Files\MyWebSearch\bar\1.bin\F3WALLPP.DAT
          C:\Program Files\MyWebSearch\bar\1.bin\F3WPHOOK.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\FWPBUDDY.PNG
          C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.JAR
          C:\Program Files\MyWebSearch\bar\1.bin\M3FFXTBR.MANIFEST
          C:\Program Files\MyWebSearch\bar\1.bin\M3HIGHIN.EXE
          C:\Program Files\MyWebSearch\bar\1.bin\M3HTML.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\M3IDLE.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\M3IMPIPE.EXE
          C:\Program Files\MyWebSearch\bar\1.bin\M3MEDINT.EXE
          C:\Program Files\MyWebSearch\bar\1.bin\M3MSG.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.JAR
          C:\Program Files\MyWebSearch\bar\1.bin\M3NTSTBR.MANIFEST
          C:\Program Files\MyWebSearch\bar\1.bin\M3OUTLCN.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\M3PLUGIN.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\M3SKIN.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\M3SKPLAY.EXE
          C:\Program Files\MyWebSearch\bar\1.bin\M3SLSRCH.EXE
          C:\Program Files\MyWebSearch\bar\1.bin\M3SRCHMN.EXE
          C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
          C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\MWSSRCAS.DLL
          C:\Program Files\MyWebSearch\bar\1.bin\MWSSVC.EXE
          C:\Program Files\MyWebSearch\bar\1.bin\NPMYWEBS.DLL
          C:\Program Files\MyWebSearch\bar\Avatar\COMMON.F3S
          C:\Program Files\MyWebSearch\bar\Message\COMMON.F3S
          C:\Program Files\MyWebSearch\bar\Notifier\COMMON.F3S
          C:\Program Files\MyWebSearch\bar\Notifier\DOG.F3S
          C:\Program Files\MyWebSearch\bar\Notifier\FISH.F3S
          C:\Program Files\MyWebSearch\bar\Notifier\KUNGFU.F3S
          C:\Program Files\MyWebSearch\bar\Notifier\LIFEGARD.F3S
          C:\Program Files\MyWebSearch\bar\Notifier\MAID.F3S
          C:\Program Files\MyWebSearch\bar\Notifier\MAILBOX.F3S
          C:\Program Files\MyWebSearch\bar\Notifier\OPERA.F3S
          C:\Program Files\MyWebSearch\bar\Notifier\ROBOT.F3S
          C:\Program Files\MyWebSearch\bar\Notifier\SEDUCT.F3S
          C:\Program Files\MyWebSearch\bar\Notifier\SURFER.F3S
          C:\Program Files\MyWebSearch\bar\Game\CHECKERS.F3S
          C:\Program Files\MyWebSearch\bar\Game\CHESS.F3S
          C:\Program Files\MyWebSearch\bar\Game\REVERSI.F3S
          C:\Program Files\MyWebSearch\bar\icons\CM.ICO
          C:\Program Files\MyWebSearch\bar\icons\MFC.ICO
          C:\Program Files\MyWebSearch\bar\icons\PSS.ICO
          C:\Program Files\MyWebSearch\bar\icons\SMILEY.ICO
          C:\Program Files\MyWebSearch\bar\icons\WB.ICO
          C:\Program Files\MyWebSearch\bar\icons\ZWINKY.ICO
          C:\Program Files\MyWebSearch\bar\Settings\s_pid.dat
          C:\Program Files\MyWebSearch\bar\Settings\prevcfg2.htm
          C:\Program Files\MyWebSearch\bar\Cache\files.ini
          C:\Program Files\MyWebSearch\bar\Cache\0003609F
          C:\Program Files\MyWebSearch\bar\Cache\000370CC.bin
          C:\Program Files\MyWebSearch\bar\Cache\0003733D.bin
          C:\Program Files\MyWebSearch\bar\Cache\0003758F.bin
          C:\Program Files\MyWebSearch\bar\Cache\00037A32.bin
          C:\Program Files\MyWebSearch\bar\Cache\00038686.bin
          C:\Program Files\MyWebSearch\bar\Cache\00B84D36.bin
          C:\Program Files\MyWebSearch\bar\Cache\00B85005.bin
          C:\Program Files\MyWebSearch\bar\Cache\00B85237.bin
          C:\Program Files\MyWebSearch\bar\Cache\00B854A8.bin
          C:\Program Files\MyWebSearch\bar\Cache\01FDE90C
          C:\Program Files\MyWebSearch\bar\Cache\0002289C
          C:\Program Files\MyWebSearch\bar\History\search3
          C:\DOCUME~1\EMMANU~1\Cookies\emmanuelle_richard@mywebsearch[1].txt
          C:\WINDOWS\System32\f3PSSavr.scr
          C:\DOCUME~1\EMMANU~1\LOCALS~1\Temp\ICD1.tmp

          -----------\\ [..\Internet Explorer\Main]

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
          "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
          "Search Page"="https://www.google.com/?gws_rd=ssl"
          "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
          "SearchMigratedDefaultURL"="https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}"

          [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
          "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
          "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
          "Search Page"="https://www.google.com/?gws_rd=ssl"
          "Start Page"="https://www.msn.com/fr-fr"

          --------------------\\ Recherche d'autres infections

          C:\WINDOWS\System32\nvs2.inf

          C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\ukqim.dat
          C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\ukqim_nav.dat
          C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\ukqim_navps.dat
          C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\lkigf.exe
          C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\lkigf.dat
          C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\lkigf_nav.dat
          C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\lkigf_navps.dat
          [b]==> EGDACCESS <==/b

          1 - "C:\ToolBar SD\TB_1.txt" - 28/08/2009| 5:51 - Option : [1]

          -----------\\ Fin du rapport a 5:51:13,07
          0
          1. Le rapport AD

            .
            ======= RAPPORT D'AD-REMOVER 1.1.4.5_Q | UNIQUEMENT XP/VISTA/SEVEN =======
            .
            Mit à jour par C_XX le 26/08/2009 à 6:37 PM
            Contact: AdRemover.contact@gmail.com
            Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
            .
            Lancé à: 5:59:52, 28/08/2009 | Mode Normal | Option: SCAN
            Exécuté de: C:\Program Files\Ad-remover\
            Système d'exploitation: Microsoft® Windows XP™ v5.1.2600
            Nom du PC: MANU | Utilisateur actuel: Emmanuelle RICHARD
            .
            .
            ============== ÉLÉMENT(S) TROUVÉ(S) ==============
            .
            Service: "MyWebSearchService"
            .
            HKCR\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239}
            HKCR\CLSID\{9afb8248-617f-460d-9366-d71cdeda3179}
            HKCR\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3}
            HKCR\FunWebProducts.DataControl
            HKCR\FunWebProducts.DataControl
            HKCR\FunWebProducts.DataControl.1
            HKCR\FunWebProducts.DataControl.1
            HKCR\FunWebProducts.HistoryKillerScheduler
            HKCR\FunWebProducts.HistoryKillerScheduler
            HKCR\FunWebProducts.HistoryKillerScheduler.1
            HKCR\FunWebProducts.HistoryKillerScheduler.1
            HKCR\FunWebProducts.HistorySwatterControlBar
            HKCR\FunWebProducts.HistorySwatterControlBar
            HKCR\FunWebProducts.HistorySwatterControlBar.1
            HKCR\FunWebProducts.HistorySwatterControlBar.1
            HKCR\FunWebProducts.HTMLMenu
            HKCR\FunWebProducts.HTMLMenu
            HKCR\FunWebProducts.HTMLMenu.1
            HKCR\FunWebProducts.HTMLMenu.1
            HKCR\FunWebProducts.HTMLMenu.2
            HKCR\FunWebProducts.HTMLMenu.2
            HKCR\FunWebProducts.IECookiesManager
            HKCR\FunWebProducts.IECookiesManager
            HKCR\FunWebProducts.IECookiesManager.1
            HKCR\FunWebProducts.IECookiesManager.1
            HKCR\FunWebProducts.KillerObjManager
            HKCR\FunWebProducts.KillerObjManager
            HKCR\FunWebProducts.KillerObjManager.1
            HKCR\FunWebProducts.KillerObjManager.1
            HKCR\FunWebProducts.PopSwatterBarButton
            HKCR\FunWebProducts.PopSwatterBarButton
            HKCR\FunWebProducts.PopSwatterBarButton.1
            HKCR\FunWebProducts.PopSwatterBarButton.1
            HKCR\FunWebProducts.PopSwatterSettingsControl
            HKCR\FunWebProducts.PopSwatterSettingsControl
            HKCR\FunWebProducts.PopSwatterSettingsControl.1
            HKCR\FunWebProducts.PopSwatterSettingsControl.1
            HKCR\Interface\{1093995a-ba37-41d2-836e-091067c4ad17}
            HKCR\Interface\{120927bf-1700-43bc-810f-fab92549b390}
            HKCR\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC}
            HKCR\Interface\{1f52a5fa-a705-4415-b975-88503b291728}
            HKCR\Interface\{247a115f-06c2-4fb3-967d-2d62d3cf4f0a}
            HKCR\Interface\{2e3537fc-cf2f-4f56-af54-5a6a3dd375cc}
            HKCR\Interface\{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc}
            HKCR\Interface\{3e1656ed-f60e-4597-b6aa-b6a58e171495}
            HKCR\Interface\{3E53E2CB-86DB-4A4A-8BD9-FFEB7A64DF82}
            HKCR\Interface\{6e74766c-4d93-4cc0-96d1-47b8e07ff9ca}
            HKCR\Interface\{741de825-a6f0-4497-9aa6-8023cf9b0fff}
            HKCR\Interface\{90449521-d834-4703-bb4e-d3aa44042ff8}
            HKCR\Interface\{991AAC62-B100-47CE-8B75-253965244f69}
            HKCR\Interface\{a626cdbd-3d13-4f78-b819-440a28d7e8fc}
            HKCR\Interface\{bbabdc90-f3d5-4801-863a-ee6ae529862d}
            HKCR\Interface\{cf54be1c-9359-4395-8533-1657cf209cfe}
            HKCR\Interface\{d6ff3684-ad3b-48eb-bbb4-b9e6c5a355c1}
            HKCR\Interface\{de38c398-b328-4f4c-a3ad-1b5e4ed93477}
            HKCR\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25e}
            HKCR\Interface\{e342af55-b78a-4cd0-a2bb-da7f52d9d25f}
            HKCR\Interface\{eb9e5c1c-b1f9-4c2b-be8a-27d6446fdaf8}
            HKCR\MyWebSearch.ChatSessionPlugin
            HKCR\MyWebSearch.ChatSessionPlugin.1
            HKCR\MyWebSearch.HTMLPanel
            HKCR\MyWebSearch.HTMLPanel.1
            HKCR\MyWebSearch.OutlookAddin
            HKCR\MyWebSearch.OutlookAddin.1
            HKCR\MyWebSearch.PseudoTransparentPlugin
            HKCR\MyWebSearch.PseudoTransparentPlugin.1
            HKCR\MyWebSearchToolBar.SettingsPlugin
            HKCR\MyWebSearchToolBar.SettingsPlugin.1
            HKCR\MyWebSearchToolBar.ToolbarPlugin
            HKCR\MyWebSearchToolBar.ToolbarPlugin.1
            HKCR\screensavercontrol.screensaverinstaller
            HKCR\screensavercontrol.screensaverinstaller
            HKCR\screensavercontrol.screensaverinstaller.1
            HKCR\screensavercontrol.screensaverinstaller.1
            HKCR\Typelib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}
            HKCR\Typelib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}
            HKCR\Typelib\{29D67D3C-509A-4544-903F-C8C1B8236554}
            HKCR\Typelib\{3E720450-B472-4954-B7AA-33069EB53906}
            HKCR\Typelib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}
            HKCR\Typelib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}
            HKCR\Typelib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}
            HKCR\Typelib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}
            HKCR\Typelib\{D518921A-4A03-425E-9873-B9A71756821E}
            HKCR\Typelib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}
            HKCR\Typelib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
            HKCR\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C}
            HKCU\Software\FunWebProducts
            HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D}
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
            HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
            HKCU\Software\MyWebSearch
            HKLM\Software\Classes\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D}
            HKLM\Software\Classes\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D}
            HKLM\Software\Classes\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA}
            HKLM\Software\Classes\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
            HKLM\Software\Classes\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
            HKLM\Software\Classes\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70}
            HKLM\Software\Classes\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC}
            HKLM\Software\Classes\CLSID\{25560540-9571-4D7B-9389-0F166788785A}
            HKLM\Software\Classes\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
            HKLM\Software\Classes\CLSID\{3E720452-B472-4954-B7AA-33069EB53906}
            HKLM\Software\Classes\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5}
            HKLM\Software\Classes\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
            HKLM\Software\Classes\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9}
            HKLM\Software\Classes\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9}
            HKLM\Software\Classes\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9}
            HKLM\Software\Classes\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983}
            HKLM\Software\Classes\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14}
            HKLM\Software\Classes\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA}
            HKLM\Software\Classes\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
            HKLM\Software\Classes\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF}
            HKLM\Software\Classes\CLSID\{A9571378-68A1-443d-B082-284F960C6D17}
            HKLM\Software\Classes\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC}
            HKLM\Software\Classes\CLSID\{B813095C-81C0-4E40-AA14-67520372B987}
            HKLM\Software\Classes\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7}
            HKLM\Software\Classes\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835}
            HKLM\Software\Classes\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805}
            HKLM\Software\Classes\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612}
            HKLM\Software\Classes\FunWebProducts.DataControl
            HKLM\Software\Classes\FunWebProducts.DataControl.1
            HKLM\Software\Classes\FunWebProducts.HistoryKillerScheduler
            HKLM\Software\Classes\FunWebProducts.HistoryKillerScheduler.1
            HKLM\Software\Classes\FunWebProducts.HistorySwatterControlBar
            HKLM\Software\Classes\FunWebProducts.HistorySwatterControlBar.1
            HKLM\Software\Classes\FunWebProducts.HTMLMenu
            HKLM\Software\Classes\FunWebProducts.HTMLMenu.1
            HKLM\Software\Classes\FunWebProducts.HTMLMenu.2
            HKLM\Software\Classes\FunWebProducts.IECookiesManager
            HKLM\Software\Classes\FunWebProducts.IECookiesManager.1
            HKLM\Software\Classes\FunWebProducts.KillerObjManager
            HKLM\Software\Classes\FunWebProducts.KillerObjManager.1
            HKLM\Software\Classes\FunWebProducts.PopSwatterBarButton
            HKLM\Software\Classes\FunWebProducts.PopSwatterBarButton.1
            HKLM\Software\Classes\FunWebProducts.PopSwatterSettingsControl
            HKLM\Software\Classes\FunWebProducts.PopSwatterSettingsControl.1
            HKLM\Software\Classes\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA}
            HKLM\Software\Classes\Interface\{07B18EAC-A523-4961-B6BB-170DE4475CCA}
            HKLM\Software\Classes\Interface\{3E720451-B472-4954-B7AA-33069EB53906}
            HKLM\Software\Classes\Interface\{3E720453-B472-4954-B7AA-33069EB53906}
            HKLM\Software\Classes\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C}
            HKLM\Software\Classes\Interface\{63D0ED2D-B45B-4458-8B3B-60C69BBBD83C}
            HKLM\Software\Classes\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A}
            HKLM\Software\Classes\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9}
            HKLM\Software\Classes\Interface\{7473D293-B7BB-4F24-AE82-7E2CE94BB6A9}
            HKLM\Software\Classes\Interface\{7473D295-B7BB-4F24-AE82-7E2CE94BB6A9}
            HKLM\Software\Classes\Interface\{7473D297-B7BB-4F24-AE82-7E2CE94BB6A9}
            HKLM\Software\Classes\Interface\{E79DFBC9-5697-4FBD-94E5-5B2A9C7C1612}
            HKLM\Software\Classes\Interface\{E79DFBCB-5697-4FBD-94E5-5B2A9C7C1612}
            HKLM\Software\Classes\Interface\{F87D7FB5-9DC5-4C8C-B998-D8DFE02E2978}
            HKLM\Software\Classes\screensavercontrol.screensaverinstaller
            HKLM\Software\Classes\screensavercontrol.screensaverinstaller.1
            HKLM\Software\Classes\Typelib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}
            HKLM\Software\Classes\Typelib\{07B18EA0-A523-4961-B6BB-170DE4475CCA}
            HKLM\Software\Classes\Typelib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}
            HKLM\Software\Classes\Typelib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A}
            HKLM\Software\Classes\Typelib\{29D67D3C-509A-4544-903F-C8C1B8236554}
            HKLM\Software\Classes\Typelib\{29D67D3C-509A-4544-903F-C8C1B8236554}
            HKLM\Software\Classes\Typelib\{3E720450-B472-4954-B7AA-33069EB53906}
            HKLM\Software\Classes\Typelib\{3E720450-B472-4954-B7AA-33069EB53906}
            HKLM\Software\Classes\Typelib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}
            HKLM\Software\Classes\Typelib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9}
            HKLM\Software\Classes\Typelib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}
            HKLM\Software\Classes\Typelib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C}
            HKLM\Software\Classes\Typelib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}
            HKLM\Software\Classes\Typelib\{8E6F1830-9607-4440-8530-13BE7C4B1D14}
            HKLM\Software\Classes\Typelib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}
            HKLM\Software\Classes\Typelib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144}
            HKLM\Software\Classes\Typelib\{D518921A-4A03-425E-9873-B9A71756821E}
            HKLM\Software\Classes\Typelib\{D518921A-4A03-425E-9873-B9A71756821E}
            HKLM\Software\Classes\Typelib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}
            HKLM\Software\Classes\Typelib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D}
            HKLM\Software\Classes\Typelib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
            HKLM\Software\Classes\Typelib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612}
            HKLM\Software\Classes\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C}
            HKLM\Software\Classes\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C}
            HKLM\Software\FocusInteractive
            HKLM\Software\Fun Web Products
            HKLM\Software\FunWebProducts
            HKLM\Software\Microsoft\Code Store Database\Distribution Units\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
            HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481}
            HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45DD-9B68-D6A12C30E5D7}
            HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907}
            HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48DD-9B6D-7A13A3E42127}
            HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40FD-8DAE-FF14757F60C7}
            HKLM\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA}
            HKLM\Software\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll
            HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}
            HKLM\Software\Microsoft\Multimedia\WMPlayer\Schemes\f3pss
            HKLM\Software\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin
            HKLM\Software\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin
            HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\MyWebSearch bar Uninstall
            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44cf-8957-5838F569A31D}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473d294-b7bb-4f24-ae82-7e2ce94bb6a9}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall
            HKLM\Software\MyWebSearch
            HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_MYWEBSEARCHSERVICE
            HKLM\SYSTEM\ControlSet003\Services\MyWebSearchService
            HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MYWEBSEARCHSERVICE
            HKLM\SYSTEM\CurrentControlSet\Services\MyWebSearchService
            HKU\S-1-5-21-585401415-3712160150-1613419910-1005\Software\Microsoft\Internet Explorer\Searchscopes\{56256A51-B582-467E-B8D4-7786EDA79AE0}
            HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\\FunWebProducts
            HKLM\Software\Microsoft\Windows Media\Wmsdk\Sources\\F3PopularScreenSavers
            HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Email Plugin
            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\My Web Search Bar Search Scope Monitor
            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Email Plugin
            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\MyWebSearch Plugin
            HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{00A6FAF6-072E-44CF-8957-5838F569A31D}
            HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
            .
            C:\Program Files\FunWebProducts
            C:\Program Files\MyWebSearch
            C:\WINDOWS\System32\f3PSSavr.scr
            C:\Program Files\Windows Live\Messenger\Riched20.dll
            C:\Program Files\Windows Live\Messenger\Msimg32.dll
            C:\WINDOWS\Prefetch\M3SRCHMN.EXE-132FEB7C.pf
            C:\WINDOWS\Prefetch\MWSOEMON.EXE-11CF9612.pf
            C:\DOCUME~1\EMMANU~1\Cookies\emmanuelle_richard@mywebsearch[1].txt
            C:\DOCUME~1\EMMANU~1\Cookies\emmanuelle_richard@partypoker[2].txt
            C:\DOCUME~1\EMMANU~1\Cookies\emmanuelle_richard@www.zwinky[1].txt
            C:\DOCUME~1\EMMANU~1\Cookies\emmanuelle_richard@zwinky[1].txt
            .
            ============== Scan additionnel ==============
            .
            .
            .
            .
            * Internet Explorer Version 7.0.5730.13 *
            .
            [HKEY_CURRENT_USER\..\Internet Explorer\Main]
            .
            Search bar: hxxp://www.google.com/ie
            Search Page: hxxp://www.google.com
            .
            [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
            .
            Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
            Default_Search_URL: hxxp://www.google.com/ie
            Search Page: hxxp://www.google.com
            Start Page: hxxp://fr.msn.com/
            .
            [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
            .
            Tabs : res://ieframe.dll/tabswelcome.htm
            .
            ===================================
            .
            15724 Octet(s) - C:\Ad-Report-SCAN.log
            .
            50 Fichier(s) - C:\DOCUME~1\EMMANU~1\LOCALS~1\Temp
            4 Fichier(s) - C:\WINDOWS\Temp
            .
            0 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
            0 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
            .
            Fin à: 6:04:19 | 28/08/2009
            .
            ============== E.O.F ==============
            .
            0
            1. Contributeur sécurité
              j'attend ton rapport d'ad-remover après on pourra passer à la suppression
              0
              1. Contributeur sécurité
                Ok alors fait ceci :

                                +-+-+-+-+-+-+-+-+-+-+ Suppression +-+-+-+-+-+-+-+-+-+-+


                [x] Relance Toolbar S&D et choisi l'option 2 ( Suppression ).

                [x] Ne fait rien pendant la procédure.

                [x] Copie/Colle le rapport dans ton prochain message.

                -----------------------------------------------

                [x] Relance Ad-Remover puis séléctionne l'option " L "

                [x] Une fois le nettoyage terminé, le rapport s'affiche
                0
                1. Comment je fais pour relancer Toolbar?

                  Je n'ai pas d'icone sur le bureau, dois le télécharger à nouveau pour le relancer?
                  0
                  1. Contributeur sécurité
                    Tu ne le trouves pas ? normalement tu dois avoir " ToolbarSD.exe " quelque part sur ton bureau ..

                    Sinon, re-télécharge le puis lance l'option 2.

                    J'attend tes deux rapports.
                    0
                    1. Rapport de suppresion Toolbar :
                      Désolé pour le délai mais mon pc rame à la connexion net de plus en plus depuis kon a commencé...

                      -----------\\ ToolBar S&D 1.2.9 XP/Vista

                      Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
                      X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU T5600 @ 1.83GHz )
                      BIOS : Default System BIOS
                      USER : Emmanuelle RICHARD ( Administrator )
                      BOOT : Normal boot
                      Antivirus : avast! antivirus 4.8.1351 [VPS 090827-0] 4.8.1351 (Activated)
                      Firewall : Norton Internet Worm Protection 2006 (Not Activated)
                      C:\ (Local Disk) - FAT32 - Total:54 Go (Free:23 Go)
                      D:\ (Local Disk) - NTFS - Total:36 Go (Free:8 Go)
                      E:\ (CD or DVD)

                      "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
                      Option : [2] ( 28/08/2009| 6:18 )

                      -----------\\ SUPPRESSION

                      Supprime! - [Service] MyWebSearchService
                      Supprime! - C:\Program Files\FunWebProducts\ScreenSaver
                      Supprime! - C:\Program Files\FunWebProducts\Shared
                      Echec ! - C:\Program Files\MyWebSearch\bar
                      Echec ! - C:\Program Files\MyWebSearch\bar\1.bin
                      Echec ! - C:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL
                      Echec ! - C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
                      Echec ! - C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
                      Echec ! - C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
                      Supprime! - C:\DOCUME~1\EMMANU~1\Cookies\emmanuelle_richard@mywebsearch[1].txt
                      Supprime! - C:\WINDOWS\System32\f3PSSavr.scr
                      Supprime! - C:\DOCUME~1\EMMANU~1\LOCALS~1\Temp\ICD1.tmp
                      Supprime! - C:\Program Files\FunWebProducts
                      Echec ! - C:\Program Files\MyWebSearch

                      -----------\\ DEUXIEME PASSAGE

                      Echec ! - C:\Program Files\MyWebSearch\bar
                      Echec ! - C:\Program Files\MyWebSearch\bar\1.bin
                      Echec ! - C:\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL
                      Echec ! - C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
                      Echec ! - C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
                      Echec ! - C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
                      Echec ! - C:\Program Files\MyWebSearch

                      -----------\\ Recherche de Fichiers / Dossiers ...

                      C:\Program Files\MyWebSearch
                      C:\Program Files\MyWebSearch\bar
                      C:\Program Files\MyWebSearch\bar\1.bin
                      C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
                      C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL

                      -----------\\ [..\Internet Explorer\Main]

                      [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                      "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                      "Search Page"="https://www.google.com/?gws_rd=ssl"
                      "Search Bar"="http://www.google.com/toolbar/ie8/sidebar.html"
                      "SearchMigratedDefaultURL"="https://www.bing.com/?scope=web&mkt=fr-FR{searchTerms}&src={referrer:source?}"

                      [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                      "Default_Page_URL"="https://www.msn.com/fr-fr/?ocid=iehp"
                      "Default_Search_URL"="http://www.google.com/toolbar/ie8/sidebar.html"
                      "Search Page"="https://www.google.com/?gws_rd=ssl"
                      "Start Page"="https://www.msn.com/fr-fr/"

                      --------------------\\ Recherche d'autres infections

                      C:\WINDOWS\System32\nvs2.inf

                      C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\ukqim.dat
                      C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\ukqim_nav.dat
                      C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\ukqim_navps.dat
                      C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\lkigf.exe
                      C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\lkigf.dat
                      C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\lkigf_nav.dat
                      C:\DOCUME~1\EMMANU~1\LOCALS~1\APPLIC~1\lkigf_navps.dat
                      [b]==> EGDACCESS <==/b

                      1 - "C:\ToolBar SD\TB_1.txt" - 28/08/2009| 5:51 - Option : [1]
                      2 - "C:\ToolBar SD\TB_2.txt" - 28/08/2009| 6:19 - Option : [2]

                      -----------\\ Fin du rapport a 6:19:18,40
                      0
                      1. Contributeur sécurité
                        J'attend ton rapport de AD-remover.

                        Ensuite tu feras ça :

                        Navilog ---->

                        [x] Télécharge Navilog1.exe (IL-MAFIOSO) à cette adresse : http://il.mafioso.pagesperso-orange.fr/Navifix/Navilog1.exe
                        [x] Enregistre-le sur ton Bureau !!
                        [x] Lance l'installation en double cliquant sur navilog.exe.
                        [x] Une fois l'installation terminée, l'utilitaire s'exécutera automatiquement.
                        [x] (Si ce n'est pas le cas, double clique sur le raccourci présent sur le Bureau)
                        [x] Laisse-toi guider par l'utilitaire. Choisis l'option 1 puis valide.

                        /!\ N'utilise pas l'option 2, 3 et 4 sans mon accord ! /!\

                        [x] Patiente jusqu'à l'apparition de ce message :
                        "*** Analyse Termine le ..... ***"
                        [x] Appuie sur une touche comme demandé. Le Bloc-notes va s'ouvrir. Poste son contenu de cette manière :

                        -> Edition / Sélectionner tout
                        -> Edition / Copier
                        -> Clique-Droit / Coller dans ta réponse


                        Nb : Le rapport se trouve également ici : C:\fixnavi.txt

                        ------> Si jamais tu as besoin d'aide un tuto est disponible ici : http://www.malekal.com/Adware.Magic_Control.php
                        0
                        1. Rapport AD

                          .
                          ======= RAPPORT D'AD-REMOVER 1.1.4.5_Q | UNIQUEMENT XP/VISTA/SEVEN =======
                          .
                          Mit à jour par C_XX le 26/08/2009 à 6:37 PM
                          Contact: AdRemover.contact@gmail.com
                          Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
                          .
                          Lancé à: 6:26:50, 28/08/2009 | Mode Normal | Option: CLEAN
                          Exécuté de: C:\Program Files\Ad-remover\
                          Système d'exploitation: Microsoft® Windows XP™ v5.1.2600
                          Nom du PC: MANU | Utilisateur actuel: Emmanuelle RICHARD
                          .
                          .
                          ============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
                          .
                          .
                          HKCU\Software\FunWebProducts
                          HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA}
                          HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB}
                          HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_MYWEBSEARCHSERVICE
                          HKLM\SYSTEM\ControlSet003\Services\MyWebSearchService
                          .
                          C:\Program Files\MyWebSearch\bar
                          C:\Program Files\MyWebSearch\bar\1.bin
                          C:\Program Files\MyWebSearch\bar\1.bin\F3REPROX.DLL
                          C:\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL
                          C:\Program Files\MyWebSearch
                          C:\Program Files\Windows Live\Messenger\riched20.dll
                          C:\Program Files\Windows Live\Messenger\msimg32.dll
                          C:\WINDOWS\Prefetch\M3SRCHMN.EXE-132FEB7C.pf
                          C:\WINDOWS\Prefetch\MWSOEMON.EXE-11CF9612.pf
                          C:\DOCUME~1\EMMANU~1\Cookies\emmanuelle_richard@partypoker[2].txt
                          C:\DOCUME~1\EMMANU~1\Cookies\emmanuelle_richard@www.zwinky[1].txt
                          C:\DOCUME~1\EMMANU~1\Cookies\emmanuelle_richard@zwinky[1].txt

                          (!) -- Fichiers temporaires supprimés.

                          .
                          ============== Scan additionnel ==============
                          .
                          .
                          .
                          .
                          * Internet Explorer Version 7.0.5730.13 *
                          .
                          [HKEY_CURRENT_USER\..\Internet Explorer\Main]
                          .
                          Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                          Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
                          Search Page: hxxp://www.google.com
                          Start Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                          .
                          [HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
                          .
                          Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
                          Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                          Search bar: hxxp://search.msn.com/spbasic.htm
                          Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
                          Start Page: hxxp://fr.msn.com/
                          .
                          [HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
                          .
                          Tabs : res://ieframe.dll/tabswelcome.htm
                          .
                          ===================================
                          .
                          16039 Octet(s) - C:\Ad-Report-SCAN.log
                          2599 Octet(s) - C:\Ad-Report-CLEAN.log
                          .
                          9 Fichier(s) - C:\DOCUME~1\EMMANU~1\LOCALS~1\Temp
                          2 Fichier(s) - C:\WINDOWS\Temp
                          .
                          17 Fichier(s) - C:\Program Files\Ad-remover\BACKUP
                          7 Fichier(s) - C:\Program Files\Ad-remover\QUARANTINE
                          .
                          Fin à: 6:32:20 | 28/08/2009
                          .
                          ============== E.O.F ==============
                          .
                          0
                          1. Rapport Navilog

                            Fix Navipromo version 4.0.2 commencé le 28/08/2009 6:45:48,78

                            !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
                            !!! Postez ce rapport sur le forum pour le faire analyser !!!

                            Outil exécuté depuis C:\Program Files\navilog1

                            Mise à jour le 27.08.2009 à 11h00 par IL-MAFIOSO

                            Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 2
                            X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 CPU T5600 @ 1.83GHz )
                            BIOS : Default System BIOS
                            USER : Emmanuelle RICHARD ( Administrator )
                            BOOT : Normal boot

                            Antivirus : avast! antivirus 4.8.1351 [VPS 090827-0] 4.8.1351 (Activated)
                            Firewall : Norton Internet Worm Protection 2006 (Not Activated)

                            C:\ (Local Disk) - FAT32 - Total:54 Go (Free:23 Go)
                            D:\ (Local Disk) - NTFS - Total:36 Go (Free:8 Go)
                            E:\ (CD or DVD)

                            Recherche executée en mode normal

                            Nettoyage exécuté au redémarrage de l'ordinateur

                            C:\WINDOWS\system32\nvs2.inf supprimé !
                            C:\WINDOWS\prefetch\lkigf*.pf supprimé !
                            c:\docume~1\emmanu~1\locals~1\applic~1\lkigf.exe supprimé !
                            c:\docume~1\emmanu~1\locals~1\applic~1\lkigf.dat supprimé !
                            c:\docume~1\emmanu~1\locals~1\applic~1\lkigf_nav.dat supprimé !
                            c:\docume~1\emmanu~1\locals~1\applic~1\lkigf_navps.dat supprimé !
                            c:\docume~1\emmanu~1\locals~1\applic~1\ukqim.dat supprimé !
                            c:\docume~1\emmanu~1\locals~1\applic~1\ukqim_nav.dat supprimé !
                            c:\docume~1\emmanu~1\locals~1\applic~1\ukqim_navps.dat supprimé !

                            Nettoyage contenu C:\WINDOWS\Temp effectué !
                            Nettoyage contenu C:\Documents and Settings\Emmanuelle RICHARD\locals~1\Temp effectué !

                            *** Sauvegarde du Registre vers dossier Safebackup ***

                            sauvegarde du Registre réalisée avec succès !

                            *** Nettoyage Registre ***

                            Nettoyage Registre Ok

                            Certificat Egroup supprimé !
                            Certificat Electronic-Group supprimé !
                            Certificat OOO-Favorit supprimé !

                            *** Scan terminé 28/08/2009 6:51:01,98 ***
                            0
                            1. J'attends les prochaines instructions???
                              0
                              1. Contributeur sécurité
                                Désolé j'étais parti manger.

                                Fait ceci maintenant :

                                 +-+-+-+-+-+-+-+-+-+-+ Malwarebyte's Anti-Malware +-+-+-+-+-+-+-+-+-+-+


                                [x] Télécharge Malwarebyte's anti-malware (MBAM) à cette adresse : http://www.malwarebytes.org/mbam/program/mbam-setup.exe

                                [x] Suis la procédure d'installation

                                [x] N'oublie pas de le mettre à jour

                                [x] Lance un scan en mode complet

                                [x] Coche bien tout les éléments trouvés et supprime les !

                                [x] Tu seras peut être amené à redémarrer ton PC, fait le.

                                [x] Copie/Colle le rapport qui s'ouvrira ( il se trouve dans la partie " Rapports/log " de Malwarebyte's )

                                [x] Un tutoriel pour son utilisation est disponible ici : https://www.malekal.com/tutoriel-malwarebyte-anti-malware/
                                0
                                1. Dernier rapport de Malwarebyte's :

                                  Malwarebytes' Anti-Malware 1.40
                                  Version de la base de données: 2708
                                  Windows 5.1.2600 Service Pack 2

                                  28/08/2009 09:05:07
                                  mbam-log-2009-08-28 (09-05-07).txt

                                  Type de recherche: Examen complet (C:\|D:\|E:\|)
                                  Eléments examinés: 151931
                                  Temps écoulé: 30 minute(s), 55 second(s)

                                  Processus mémoire infecté(s): 3
                                  Module(s) mémoire infecté(s): 0
                                  Clé(s) du Registre infectée(s): 3
                                  Valeur(s) du Registre infectée(s): 11
                                  Elément(s) de données du Registre infecté(s): 3
                                  Dossier(s) infecté(s): 2
                                  Fichier(s) infecté(s): 51

                                  Processus mémoire infecté(s):
                                  C:\Documents and Settings\All Users\Application Data\14668594\14668594.exe (Rogue.Multiple.H) -> Unloaded process successfully.
                                  C:\WINDOWS\system32\mset.exe (Trojan.Downloader) -> Unloaded process successfully.
                                  C:\Documents and Settings\Emmanuelle RICHARD\mset.exe (Trojan.Downloader) -> Unloaded process successfully.

                                  Module(s) mémoire infecté(s):
                                  (Aucun élément nuisible détecté)

                                  Clé(s) du Registre infectée(s):
                                  HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Carlson (Dialer) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Carlson (Dialer) -> Quarantined and deleted successfully.

                                  Valeur(s) du Registre infectée(s):
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\14668594 (Rogue.Multiple.H) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mset (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mset (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\Control Panel\don't load\scui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\Control Panel\don't load\wscui.cpl (Hijack.SecurityCenter) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\braviax (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\braviax (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\PC Antispyware 2010 (Rogue.PC_Antispyware2010) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RList (Malware.Trace) -> Quarantined and deleted successfully.
                                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Regedit32 (Trojan.Agent) -> Quarantined and deleted successfully.

                                  Elément(s) de données du Registre infecté(s):
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
                                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

                                  Dossier(s) infecté(s):
                                  C:\Documents and Settings\All Users\Application Data\14668594 (Rogue.Multiple.H) -> Quarantined and deleted successfully.
                                  C:\Program Files\Fichiers communs\Carlson (Dialer) -> Quarantined and deleted successfully.

                                  Fichier(s) infecté(s):
                                  C:\Documents and Settings\All Users\Application Data\14668594\14668594.exe (Rogue.Multiple.H) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\All Users\Application Data\14668594\14668594 (Rogue.Multiple.H) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\All Users\Application Data\14668594\pc14668594ins (Rogue.Multiple.H) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\Emmanuelle RICHARD\Local Settings\Temp\BN5.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\Emmanuelle RICHARD\Local Settings\Temp\BN6.tmp (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  C:\Program Files\Ad-remover\QUARANTINE\PROGRA~1\WI1F86~1\MESSEN~1\riched20.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                                  C:\Program Files\Ad-remover\QUARANTINE\PROGRA~1\WI1F86~1\MESSEN~1\msimg32.dll.vir (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146312.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146318.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146319.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146320.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146325.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146326.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146327.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146328.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146329.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146330.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146332.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146333.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146334.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146335.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146336.EXE (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146337.exe (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146338.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146339.exe (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146340.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146341.exe (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146342.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146349.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146350.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146351.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146353.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146354.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                                  C:\System Volume Information\_restore{5BF1EAEF-40D5-4599-B26B-C703C467A990}\RP445\A0146355.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                                  C:\ToolBar SD\Backup-TB\Program Files\MyWebSearch\bar\F3HKSTUB.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\ToolBar SD\Backup-TB\Program Files\MyWebSearch\bar\MWSOEPLG.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\ToolBar SD\Backup-TB\Program Files\MyWebSearch\bar\MWSOESTB.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\ToolBar SD\Backup-TB\Program Files\MyWebSearch\bar\1.bin\F3HKSTUB.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\ToolBar SD\Backup-TB\Program Files\MyWebSearch\bar\1.bin\MWSOEPLG.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\ToolBar SD\Backup-TB\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL (Adware.MyWeb) -> Quarantined and deleted successfully.
                                  C:\ToolBar SD\Backup-TB\WINDOWS\system32\f3PSSavr.scr (Adware.MyWebSearch) -> Quarantined and deleted successfully.
                                  C:\WINDOWS\system32\mset.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\Emmanuelle RICHARD\mset.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\Emmanuelle RICHARD\Application Data\jihefyhy.dll (Trojan.Agent) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\Emmanuelle RICHARD\Application Data\wiaserva.log (Malware.Trace) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\All Users\Menu Démarrer\carlton (Dialer) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\Emmanuelle RICHARD\Cookies\nasul.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\Emmanuelle RICHARD\delself.bat (Malware.Trace) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\Emmanuelle RICHARD\Local Settings\Temporary Internet Files\ezypuvoz.exe (Trojan.Agent) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\Emmanuelle RICHARD\oashdihasidhasuidhiasdhiashdiuasdhasd (Trace.Pandex) -> Quarantined and deleted successfully.
                                  C:\Documents and Settings\Emmanuelle RICHARD\Menu Démarrer\Programmes\Démarrage\ikowin32.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
                                  0
                                  1. Contributeur sécurité
                                    Bien !

                                    Est ce que tu peux reposter un log RSIT

                                    Le PC se porte mieux ?
                                    0
                                    1. Oui c'est mieux, sans aucune comparaison, je ne vois plus rien qui se rapporte à ce stané virus.

                                      Par contre comment dois je procéder ?
                                      "Est ce que tu peux reposter un log RSIT"
                                      0
                                      • 1
                                      • 2