Antivirus

Bonjour,
j'ai installer Total Security, il fait un scan et dégage plein de virus mais pour les supprimez il me demande les clés d'activation de plus cet antivirus je peu même pas le supprimez aussi.comment le supprimez? quels sont les étapes à suivre???? merçi
Configuration: Windows XP
Firefox 3.0.14

24 réponses

  1. Contributeur
    Salut,

    j'ai installer Total Security,

    Tu t'es fais avoir, il s'agit d'un rogue...

    Telecharges RSIT " Random's System Information Tool " sur ton bureau : http://images.malwareremoval.com/random/RSIT.exe

    - Fermes toutes les applications en cours et double clic sur RSIT.exe
    - Selectionnes " Continue " à l'ecran >> RSIT va analyser le pc et verifier si l'outil hijackthis ( version à jour) est present sur le pc, si ce n'est pas le cas, RSIT le telechargera >> acceptes la license
    - Une fois l'analyse terminée, 2 rapports.txt s'ouvrent, log.txt à l'écran et info.txt dans la barre des taches
    - Postes le contenu des 2 rapports

    0
    1. log.txt

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:45:24, on 24/09/2009
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Avira\AntiVir Desktop\sched.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Java\jre6\bin\jusched.exe
      C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
      C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\TS\tsc.exe
      C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      C:\Program Files\Java\jre6\bin\jqs.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      C:\WINDOWS\system32\svchost.exe
      C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      C:\WINDOWS\system32\wbem\wmiapsrv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
      C:\Documents and Settings\Administrateur\Bureau\Administrateur.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.cherche.us/keyword/%s
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.ask.com/?o=14393&l=dis
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=
      R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ww12.cherche.us
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
      R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
      O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      O2 - BHO: &IE Help - {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} - C:\WINDOWS\system32\iehelpmod.dll
      O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
      O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
      O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
      O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
      O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
      O4 - HKLM\..\Run: [TkBellExe] "realsched.exe" -osboot
      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
      O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
      O4 - HKCU\..\Run: [TS] C:\Program Files\TS\tsc.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\RunOnce: [nLite] %systemroot%\inf\nlite.cmd (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-20\..\RunOnce: [nLite] %systemroot%\inf\nlite.cmd (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
      O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
      O15 - Trusted Zone: *.chat-land.org
      O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://ma-config.com/activex/MaConfig_3_5_1_0.cab
      O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
      O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
      O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
      O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
      O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
      O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
      O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
      0
      1. Contributeur
        Re,

        Bon, c'est simple :

        Soit tu fais ce qu'on te demande de faire, soit on arrête là tout de suite.

        Ce n'est pas la 1ère fois que tu demandes de l'aide sur le forum de CCM et à chaque fois c'est la même chose

        Pour Rappel : https://forums.commentcamarche.net/forum/affich-12698048-comment-supprimer-ce-virus

        Je te rappelle ( et tu le sais déjà) que nous sommes bénévoles, donc pas de temps à perdre pour faire n'importe quoi...

        Le rapport RSIT que je t'ai demandé Complet --> Log.txt + Info.txt

        De toute façon avec une version illégale, tu ne seras jamais en sécurité.
        0
        1. okey, j'ai compris maintenant qu'est ce que je fais?
          0
          1. Contributeur
            Okey, j'ai compris maintenant qu'est ce que je fais?

            --> tu envoies le rapport RSIT ( Complet) comme demandé.
            0
            1. ou puis-je trouvez info.txt ou bien le 2 sont ensemble voila en tous cas le rapport:

              Logfile of random's system information tool 1.06 (written by random/random)
              Run by Administrateur at 2009-09-24 13:41:11
              Microsoft Windows XP Professionnel Service Pack 2
              System drive C: has 13 GB (65%) free of 20 GB
              Total RAM: 503 MB (27% free)

              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 12:45:24, on 24/09/2009
              Platform: Windows XP SP2 (WinNT 5.01.2600)
              MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
              Boot mode: Normal

              Running processes:
              C:\WINDOWS\System32\smss.exe
              C:\WINDOWS\system32\winlogon.exe
              C:\WINDOWS\system32\services.exe
              C:\WINDOWS\system32\lsass.exe
              C:\WINDOWS\system32\svchost.exe
              C:\WINDOWS\System32\svchost.exe
              C:\WINDOWS\Explorer.EXE
              C:\WINDOWS\system32\spoolsv.exe
              C:\Program Files\Avira\AntiVir Desktop\sched.exe
              C:\WINDOWS\SOUNDMAN.EXE
              C:\Program Files\Java\jre6\bin\jusched.exe
              C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
              C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
              C:\WINDOWS\system32\ctfmon.exe
              C:\Program Files\TS\tsc.exe
              C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
              C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              C:\Program Files\Java\jre6\bin\jqs.exe
              C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
              C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
              C:\WINDOWS\system32\svchost.exe
              C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
              C:\WINDOWS\system32\wbem\wmiapsrv.exe
              C:\WINDOWS\System32\svchost.exe
              C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\WINDOWS\system32\wuauclt.exe
              C:\Documents and Settings\Administrateur\Bureau\RSIT.exe
              C:\Documents and Settings\Administrateur\Bureau\Administrateur.exe

              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.cherche.us/keyword/%s
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.ask.com/?o=14393&l=dis
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=
              R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ww12.cherche.us
              R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
              R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
              O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: &IE Help - {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} - C:\WINDOWS\system32\iehelpmod.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
              O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
              O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
              O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
              O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
              O4 - HKLM\..\Run: [TkBellExe] "realsched.exe" -osboot
              O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
              O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
              O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
              O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
              O4 - HKCU\..\Run: [TS] C:\Program Files\TS\tsc.exe
              O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-19\..\RunOnce: [nLite] %systemroot%\inf\nlite.cmd (User 'SERVICE LOCAL')
              O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-20\..\RunOnce: [nLite] %systemroot%\inf\nlite.cmd (User 'SERVICE RÉSEAU')
              O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
              O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
              O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
              O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
              O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
              O15 - Trusted Zone: *.chat-land.org
              O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://ma-config.com/activex/MaConfig_3_5_1_0.cab
              O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
              O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
              O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
              O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
              O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
              O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
              O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
              O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
              0
              1. Logfile of Trend Micro HijackThis v2.0.2
                Scan saved at 12:29:11, on 24/09/2009
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                Boot mode: Normal

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\system32\spoolsv.exe
                C:\Program Files\Avira\AntiVir Desktop\sched.exe
                C:\WINDOWS\SOUNDMAN.EXE
                C:\Program Files\Java\jre6\bin\jusched.exe
                C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe
                C:\Program Files\Logitech\QuickCam\Quickcam.exe
                C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                C:\Program Files\uTorrent\uTorrent.exe
                C:\Program Files\TS\tsc.exe
                C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                C:\Program Files\Java\jre6\bin\jqs.exe
                C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                C:\WINDOWS\system32\svchost.exe
                C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                C:\WINDOWS\system32\wbem\wmiapsrv.exe
                C:\WINDOWS\System32\svchost.exe
                C:\Program Files\Fichiers communs\Logishrd\LQCVFX\COCIManager.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Documents and Settings\Administrateur\Bureau\HiJackThis.exe

                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.cherche.us/keyword/%s
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ww12.cherche.us
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://ww12.cherche.us
                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.ask.com/?o=14393&l=dis
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=
                R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q=
                R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://ww12.cherche.us
                R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.cherche.us/keyword/%s
                R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://ww12.cherche.us
                R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll
                O2 - BHO: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
                O2 - BHO: &IE Help - {35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC} - C:\WINDOWS\system32\iehelpmod.dll
                O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
                O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
                O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
                O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
                O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
                O4 - HKLM\..\Run: [TkBellExe] "realsched.exe" -osboot
                O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
                O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
                O4 - HKCU\..\Run: [TS] C:\Program Files\TS\tsc.exe
                O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-19\..\RunOnce: [nLite] %systemroot%\inf\nlite.cmd (User 'SERVICE LOCAL')
                O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-20\..\RunOnce: [nLite] %systemroot%\inf\nlite.cmd (User 'SERVICE RÉSEAU')
                O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                O4 - HKUS\S-1-5-18\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SYSTEM')
                O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                O4 - HKUS\.DEFAULT\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'Default user')
                O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
                O15 - Trusted Zone: *.chat-land.org
                O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://ma-config.com/activex/MaConfig_3_5_1_0.cab
                O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
                O23 - Service: Avira AntiVir Planificateur (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
                O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
                O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
                O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVCOMSER\LVComSer.exe
                O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Fichiers communs\LogiShrd\LVMVFM\LVPrcSrv.exe
                O23 - Service: Ma-Config Service (maconfservice) - CybelSoft - C:\Program Files\ma-config.com\maconfservice.exe
                O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                0
                1. voila le 2 rapport en dessus
                  0
                  1. Contributeur
                    Je regarde le rapport et je te donne la suite...
                    0
                    1. Contributeur
                      # Télécharge OTM de Old_Timer sur ton Bureau.
                      # Double clique sur OTM.exe afin de lancer l'outil.
                      # Copie la liste qui se trouve ci-dessous :
                      
                      
                      :processes
                      explorer.exe
                      
                      :Reg
                      [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}] 
                      [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] 
                      "TS"=-
                      
                      :File
                      C:\WINDOWS\system32\iehelpmod.dll
                      C:\Program Files\TS\tsc.exe 
                      C:\Program Files\Fichiers communs\TSUninstall 
                      C:\Program Files\TS 
                      
                      :commands
                      [purity]
                      [emptytemp]
                      [reboot]


                      Colle (Ctrl+V) le texte précédemment copié dans le cadre Paste Instructions for Items to be Moved.
                      * Clique maintenant sur le bouton MoveIt! puis ferme OTM.

                      ---> Si un fichier ou dossier ne peut pas être supprimé immédiatement, le logiciel te demandera de redémarrer.
                      Accepte en cliquant sur YES.

                      * Poste le rapport situé dans ce dossier : C:\_OTM\MovedFiles\

                      ---> Le nom du rapport correspond au moment de sa création : date_heure.log

                      0
                      1. All processes killed
                        ========== PROCESSES ==========
                        No active process named explorer.exe was found!
                        ========== REGISTRY ==========
                        Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersi­on\Explorer\Browser Helper Objects\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}\ not found.
                        Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{35A5B43B-CB8A-49CA-A9F4-D3B308D2E3CC}\ deleted successfully.
                        Registry key HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion­\Run not found.
                        Error: Unable to interpret <:File> in the current context!
                        Error: Unable to interpret <C:\WINDOWS\system32\iehelpmod.dll> in the current context!
                        Error: Unable to interpret <C:\Program Files\TS\tsc.exe > in the current context!
                        Error: Unable to interpret <C:\Program Files\Fichiers communs\TSUninstall > in the current context!
                        Error: Unable to interpret <C:\Program Files\TS > in the current context!
                        ========== COMMANDS ==========

                        [EMPTYTEMP]

                        User: Administrateur
                        ->Temp folder emptied: 59358536 bytes
                        ->Temporary Internet Files folder emptied: 75858332 bytes
                        ->Java cache emptied: 21782942 bytes
                        ->FireFox cache emptied: 97665854 bytes

                        User: All Users

                        User: Default User
                        ->Temp folder emptied: 0 bytes
                        ->Temporary Internet Files folder emptied: 33170 bytes

                        User: LocalService
                        ->Temp folder emptied: 65984 bytes
                        File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
                        ->Temporary Internet Files folder emptied: 33170 bytes

                        User: NetworkService
                        ->Temp folder emptied: 0 bytes
                        ->Temporary Internet Files folder emptied: 33170 bytes

                        %systemdrive% .tmp files removed: 0 bytes
                        %systemroot% .tmp files removed: 2114937 bytes
                        %systemroot%\System32 .tmp files removed: 3072 bytes
                        File delete failed. C:\WINDOWS\temp\logishrd\LVPrcInj01.dll scheduled to be deleted on reboot.
                        Windows Temp folder emptied: 7601646 bytes
                        RecycleBin emptied: 14221909 bytes

                        Total Files Cleaned = 265,86 mb

                        OTM by OldTimer - Version 3.0.0.6 log created on 09242009_142639

                        Files moved on Reboot...
                        DllUnregisterServer procedure not found in C:\WINDOWS\temp\logishrd\LVPrcInj01.dll
                        C:\WINDOWS\temp\logishrd\LVPrcInj01.dll NOT unregistered.
                        File move failed. C:\WINDOWS\temp\logishrd\LVPrcInj01.dll scheduled to be moved on reboot.

                        Registry entries deleted on Reboot...
                        0
                        1. Contributeur
                          Télécharge Malwarebytes' Anti-Malware

                          - Installe le --> double-clic sur Mbam-setup.exe, à la fin de l'installation, il se mettra automatiquement à jour

                          - Une fois installé, fermes toutes les applications en cours et lances Malwarebytes

                          - Exécutes un examen rapide du pc ( tu n'auras pas accès à internet pendant l'analyse)

                          - A la fin du scan clic sur " Afficher les résultats "

                          - si Malwarebytes a trouvé des infections ->> clic sur " Supprimer la sélection "

                          - Si il a besoin de redémarrer le pc pour finir la désinfection, acceptes

                          - Un rapport s'établira, postes son contenu.
                          0
                          1. Malwarebytes ne veut pas s'excécuter j'ai double cliquez mais il y a rien j'attend depuis 10 min et rien à afficher
                            0
                            1. Contributeur
                              Tu vas télécharger Combofix en prenant soin de le renommer ( c'est important)

                              Regarde là en cas de difficulté : renommer Combofix au téléchargement

                              * Fais un clic droit ici
                              * Choisis : Enregistrer la cible du lien sous
                              * Choisis le Bureau comme destination.
                              * Dans le champ "Nom du fichier", renomme ComboFix.exe en CCM.exe par exemple, puis enregistrez.
                              * Déconnecte-toi d'Internet et ferme toutes les applications et programmes.
                              * Désactive tes défenses ( antivirus, antispyware...)
                              * Double-clique sur CCM.exe pour lancer le fix
                              * Accepte le message d'avertissement et accepte l'installation de la Console de récupération si il te le demande.
                              * Le rapport sera créé sous la racine : C:\Combofix.txt , poste le stp
                              0
                              1. je né pas uitilsé le dernier programme car il ne marche pas voila le rapport

                                Malwarebytes' Anti-Malware 1.41
                                Version de la base de données: 2775
                                Windows 5.1.2600 Service Pack 2

                                24/09/2009 17:47:26
                                mbam-log-2009-09-24 (17-47-26).txt

                                Type de recherche: Examen complet (C:\|D:\|)
                                Eléments examinés: 108685
                                Temps écoulé: 21 minute(s), 50 second(s)

                                Processus mémoire infecté(s): 0
                                Module(s) mémoire infecté(s): 0
                                Clé(s) du Registre infectée(s): 5
                                Valeur(s) du Registre infectée(s): 1
                                Elément(s) de données du Registre infecté(s): 0
                                Dossier(s) infecté(s): 1
                                Fichier(s) infecté(s): 4

                                Processus mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Module(s) mémoire infecté(s):
                                (Aucun élément nuisible détecté)

                                Clé(s) du Registre infectée(s):
                                HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35a5b43b-cb8a-49ca-a9f4-d3b308d2e3cc} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9b71d88c-c598-4935-c5d1-43aa4db90836} (Trojan.Agent) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35a5b43b-cb8a-49ca-a9f4-d3b308d2e3cc} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                HKEY_CURRENT_USER\SOFTWARE\Bifrost (Backdoor.Bifrose) -> Quarantined and deleted successfully.
                                HKEY_LOCAL_MACHINE\SOFTWARE\Bifrost (Backdoor.Bifrose) -> Quarantined and deleted successfully.

                                Valeur(s) du Registre infectée(s):
                                HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Delete on reboot.

                                Elément(s) de données du Registre infecté(s):
                                (Aucun élément nuisible détecté)

                                Dossier(s) infecté(s):
                                C:\WINDOWS\system32\Bifrost (Backdoor.Bifrose) -> Quarantined and deleted successfully.

                                Fichier(s) infecté(s):
                                C:\WINDOWS\system32\Bifrost\klog.dat (Backdoor.Bifrose) -> Quarantined and deleted successfully.
                                C:\Documents and Settings\Administrateur\Application Data\addon.dat (Malware.Trace) -> Quarantined and deleted successfully.
                                C:\Documents and Settings\Administrateur\Bureau\Total Security.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
                                C:\WINDOWS\system32\iehelpmod.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                                0
                                1. Contributeur
                                  Re,

                                  Malwarebytes n'est pas à jour, donc peux-tu recommencer l'analyse (rapide] en ayant pris soin de le mettre à jour avant et poste le rapport généré stp.
                                  0
                                  1. Malwarebytes' Anti-Malware 1.41
                                    Version de la base de données: 2857
                                    Windows 5.1.2600 Service Pack 2

                                    25/09/2009 14:09:24
                                    mbam-log-2009-09-25 (14-09-24).txt

                                    Type de recherche: Examen rapide
                                    Eléments examinés: 83556
                                    Temps écoulé: 6 minute(s), 56 second(s)

                                    Processus mémoire infecté(s): 0
                                    Module(s) mémoire infecté(s): 0
                                    Clé(s) du Registre infectée(s): 0
                                    Valeur(s) du Registre infectée(s): 2
                                    Elément(s) de données du Registre infecté(s): 0
                                    Dossier(s) infecté(s): 1
                                    Fichier(s) infecté(s): 10

                                    Processus mémoire infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Module(s) mémoire infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Clé(s) du Registre infectée(s):
                                    (Aucun élément nuisible détecté)

                                    Valeur(s) du Registre infectée(s):
                                    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\ForceClassicControlPanel (Hijack.ControlPanelStyle) -> Delete on reboot.
                                    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ts (Rogue.TotalSecurity) -> Quarantined and deleted successfully.

                                    Elément(s) de données du Registre infecté(s):
                                    (Aucun élément nuisible détecté)

                                    Dossier(s) infecté(s):
                                    C:\Program Files\Fichiers communs\TSUninstall (Rogue.TotalSecurity) -> Quarantined and deleted successfully.

                                    Fichier(s) infecté(s):
                                    C:\Program Files\Fichiers communs\TSUninstall\Uninstall.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\All Users\Menu Démarrer\TS\Computer Scan.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\All Users\Menu Démarrer\TS\Help.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\All Users\Menu Démarrer\TS\Registration.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\All Users\Menu Démarrer\TS\Security Center.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\All Users\Menu Démarrer\TS\Settings.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\All Users\Menu Démarrer\TS\Total Security.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\All Users\Menu Démarrer\TS\Update.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
                                    C:\Documents and Settings\Administrateur\Application Data\Microsoft\Internet Explorer\Quick Launch\TS.lnk (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
                                    C:\Program Files\TS\tsc.exe (Rogue.TotalSecurity) -> Quarantined and deleted successfully.
                                    0
                                    1. Contributeur
                                      Ok,

                                      Rends -toi sur l'onglet Quarantaine de Malwarebytes et supprime tout ce qui s'y trouve

                                      Puis ( Important), redémarre le pc.

                                      Télécharge et installe ccleaner

                                      - Durant l'installation, décoche la case proposant la barre d'outils yahoo et celle : " ajouter l'option des mises à jour"

                                      - Une fois installé, fermes toutes les applications en cours et lance ccleaner

                                      - clic -->>option -->> avancé et décoche " effacer les fichiers etc... plus vieux que 48h

                                      - Sélectionne " nettoyeur " >> clic sur Analyse puis nettoyage, puis referme le programme...

                                      - Télécharge ToolbarSD et enregistre le sur ton bureau

                                      - Désactive la garde résidente de ton antivirus
                                      - Lance l'installation en exécutant le fichier téléchargé
                                      - Ferme toutes les applications en cours et double-cliques sur Toolbarsd.exe
                                      - Sélectionne la langue et presse la touche ENTREE
                                      - Sélectionne l'option1 au menu et patiente le temps de la recherche
                                      - A la fin de la recherche, un rapport s'affichera, postes son contenu

                                      Note : le rapport est également à C:\TB.txt.
                                      0
                                      1. -----------\\ ToolBar S&D 1.2.9 XP/Vista

                                        Microsoft Windows XP Professionnel ( v5.1.2600 ) Service Pack 2
                                        X86-based PC ( Uniprocessor Free : Intel(R) Celeron(R) CPU 2.26GHz )
                                        BIOS : MotherBoard Version: ZX-865GVLM V1.31 (2008-11-17-4M)
                                        USER : Administrateur ( Administrator )
                                        BOOT : Normal boot
                                        Antivirus : AntiVir Desktop 9.0.1.32 (Not Activated)
                                        A:\ (USB)
                                        C:\ (Local Disk) - NTFS - Total:19 Go (Free:13 Go)
                                        D:\ (Local Disk) - FAT32 - Total:18 Go (Free:18 Go)
                                        F:\ (CD or DVD)

                                        "C:\ToolBar SD" ( MAJ : 22-08-2009|18:42 )
                                        Option : [1] ( 25/09/2009|15:26 )

                                        -----------\\ Recherche de Fichiers / Dossiers ...

                                        -----------\\ [..\Internet Explorer\Main]

                                        [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
                                        "Local Page"="C:\\WINDOWS\\system32\\blank.htm"
                                        "Start Page"="https://www.ask.com/?o=14393&l=dis"
                                        "Search Page"="http://ww12.cherche.us"
                                        "Start Page_bak"="http://ww12.cherche.us"
                                        "Search Bar"="http://ww12.cherche.us"
                                        "Default_Search_URL"="http://www.cherche.us/keyword/%s"
                                        "SearchMigratedDefaultURL"="http://ww12.cherche.us{searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8"

                                        [HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
                                        "Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
                                        "Default_Search_URL"="http://toolbar.ask.com/toolbarv/askRedirect?o=13925&gct=&gc=1&q="
                                        "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
                                        "Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"

                                        --------------------\\ Recherche d'autres infections

                                        Aucune autre infection trouvée !

                                        1 - "C:\ToolBar SD\TB_1.txt" - 25/09/2009|15:28 - Option : [1]

                                        -----------\\ Fin du rapport a 15:28:19,54
                                        0
                                        • 1
                                        • 2