Pubs indésirables
Résolu
baryton33
Messages postés
283
Date d'inscription
Statut
Membre
Dernière intervention
-
Utilisateur anonyme -
Utilisateur anonyme -
Bonjour,depuis quelques temps, quand je suis connecté à internet via mozilla je suis inondé de pages pubs : jeux de poker, Meetick adultes. Que faire pour ne plus recevoir ces pages(malgré un anti spam) ? merci
A voir également:
- Pubs indésirables
- Bloquer les pubs youtube - Accueil - Streaming
- Supprimer les pubs - Guide
- Numeros indesirables - Guide
- Comment couper le son des pubs dans les jeux - Forum Enceintes / HiFi
- Pourquoi j'ai des pubs de site de rencontre ✓ - Forum Réseaux sociaux
14 réponses
bonjour
Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.
- http://images.malwareremoval.com/random/RSIT.exe
! Déconnecte toi et ferme toutes tes applications en cours !
* Double-clique sur RSIT.exe pour le lancer .
* Une première fenêtre s'ouvre avec en titre : Disclaimer of warranty .
* Devant l'option List files/folders created ... , tu choisis 2 months
* Clique ensuite sur Continue pour lancer l'analyse ...
* Laisse faire le scan et ne touche pas au PC ...
* Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).
* Héberge le contenu de log.txt (c'est celui qui apparait à l'écran), ainsi que de info.txt ici.
Clique sur parcourir
Une fois que tu as trouvé les rapports à héberger, clique sur ouvrir
Clique sur Cliquez ici pour déposer le fichier, puis donne le lien
qui apparait comme ceci http:/www.cijoint.fr/cjlink.php?file=cj200911/cijgAdC3Ch.txt
Note : les rapports seront en outre sauvegardés dans ce dossier C:\rsit
Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.
- http://images.malwareremoval.com/random/RSIT.exe
! Déconnecte toi et ferme toutes tes applications en cours !
* Double-clique sur RSIT.exe pour le lancer .
* Une première fenêtre s'ouvre avec en titre : Disclaimer of warranty .
* Devant l'option List files/folders created ... , tu choisis 2 months
* Clique ensuite sur Continue pour lancer l'analyse ...
* Laisse faire le scan et ne touche pas au PC ...
* Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).
* Héberge le contenu de log.txt (c'est celui qui apparait à l'écran), ainsi que de info.txt ici.
Clique sur parcourir
Une fois que tu as trouvé les rapports à héberger, clique sur ouvrir
Clique sur Cliquez ici pour déposer le fichier, puis donne le lien
qui apparait comme ceci http:/www.cijoint.fr/cjlink.php?file=cj200911/cijgAdC3Ch.txt
Note : les rapports seront en outre sauvegardés dans ce dossier C:\rsit
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Salut
Il est là le rapport
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:20:39, on 27/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\windows\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\windows\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe
C:\windows\RTHDCPL.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\windows\Mixer.exe
C:\windows\system32\RunDll32.exe
C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Calendrier\Cld2000.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SFR\Kit\9props.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\Fichiers communs\Common Toolkit Suite\AVEngine\AVScanningService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterSuiteService.exe
C:\PROGRA~1\FDD_FM~1\CZFMDSER.EXE
C:\windows\system32\FsUsbExService.Exe
C:\windows\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\windows\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Logitech\QuickCam10\COCIManager.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Automated Content Enhancer - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - C:\Program Files\Automated Content Enhancer\4.1.0.5050\ACEIEAddOn.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.DLL (file missing)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [SoftwareHelper] C:\Documents and Settings\Moulin\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CZFMDXPK] C:\PROGRA~1\FDD_FM~1\CZFMDXPK.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [SWPROguard] C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [Cld2000.exe] C:\Program Files\Calendrier\Cld2000.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\SFR\Media Center\MediaCenter.exe"
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [RDfrNET] C:\Program Files\Registry_Doktor 4.1\RegistryDoktor.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [Mon Widget RMC] "C:\Program Files\Nosibay\Mon Widget RMC\launcher.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\Moulin\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mu3: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mus: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mxl: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mya: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .myr: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .myt: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .xmz: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O14 - IERESET.INF: START_PAGE_URL=https://www.01net.com/telecharger/
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: bw+0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: AV Engine Scanning Service - Preventon Technologies Limited - C:/Program Files/Fichiers communs/Common Toolkit Suite/AVEngine/AVScanningService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Common Toolkit Service - SPAMfighter - C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterSuiteService.exe
O23 - Service: CZFMDSER.EXE - Unknown owner - C:\PROGRA~1\FDD_FM~1\CZFMDSER.EXE
O23 - Service: FsUsbExService - Teruten - C:\windows\system32\FsUsbExService.Exe
O23 - Service: Service Google Update (gupdate1c98e7fe5a2b52a) (gupdate1c98e7fe5a2b52a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
Il est là le rapport
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:20:39, on 27/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\windows\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\windows\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe
C:\windows\RTHDCPL.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\windows\Mixer.exe
C:\windows\system32\RunDll32.exe
C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Calendrier\Cld2000.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SFR\Kit\9props.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\Fichiers communs\Common Toolkit Suite\AVEngine\AVScanningService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterSuiteService.exe
C:\PROGRA~1\FDD_FM~1\CZFMDSER.EXE
C:\windows\system32\FsUsbExService.Exe
C:\windows\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\windows\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Logitech\QuickCam10\COCIManager.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Automated Content Enhancer - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - C:\Program Files\Automated Content Enhancer\4.1.0.5050\ACEIEAddOn.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.DLL (file missing)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [SoftwareHelper] C:\Documents and Settings\Moulin\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CZFMDXPK] C:\PROGRA~1\FDD_FM~1\CZFMDXPK.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [SWPROguard] C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [Cld2000.exe] C:\Program Files\Calendrier\Cld2000.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\SFR\Media Center\MediaCenter.exe"
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [RDfrNET] C:\Program Files\Registry_Doktor 4.1\RegistryDoktor.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [Mon Widget RMC] "C:\Program Files\Nosibay\Mon Widget RMC\launcher.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\Moulin\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mu3: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mus: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mxl: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mya: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .myr: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .myt: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .xmz: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O14 - IERESET.INF: START_PAGE_URL=https://www.01net.com/telecharger/
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: bw+0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: AV Engine Scanning Service - Preventon Technologies Limited - C:/Program Files/Fichiers communs/Common Toolkit Suite/AVEngine/AVScanningService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Common Toolkit Service - SPAMfighter - C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterSuiteService.exe
O23 - Service: CZFMDSER.EXE - Unknown owner - C:\PROGRA~1\FDD_FM~1\CZFMDSER.EXE
O23 - Service: FsUsbExService - Teruten - C:\windows\system32\FsUsbExService.Exe
O23 - Service: Service Google Update (gupdate1c98e7fe5a2b52a) (gupdate1c98e7fe5a2b52a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
oui ça je le pense depuis longtemps mais que faire pour qu'il ne le soit plus ? Merci !
EoRezo te propose des logiciels frauduleux qu'il faut éviter de télécharger
On nous demande des informations qui peuvent être utilisées à des fins commerciales
Ces logiciels modifient la page d'accueil, et peuvent faire ramer ton PC, et font
afficher plein de pubs
Télécharge AD Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe
ou
https://www.androidworld.fr/
Désactive l'anti-virus
Déconnecte toi et ferme toutes les applications en cours
Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
Double-clique sur l'icône Ad-remover présent sur ton bureau pour le lancer
Au menu principal, sélectionne l'option L, puis appuie sur la touche entrée
Poste le rapport qui apparait à la fin .
( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )
(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Note :
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall
On nous demande des informations qui peuvent être utilisées à des fins commerciales
Ces logiciels modifient la page d'accueil, et peuvent faire ramer ton PC, et font
afficher plein de pubs
Télécharge AD Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe
ou
https://www.androidworld.fr/
Désactive l'anti-virus
Déconnecte toi et ferme toutes les applications en cours
Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
Double-clique sur l'icône Ad-remover présent sur ton bureau pour le lancer
Au menu principal, sélectionne l'option L, puis appuie sur la touche entrée
Poste le rapport qui apparait à la fin .
( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )
(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )
Note :
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall
-----------\\ ToolBar S&D 1.2.6 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 05/15/08 08:44:40 Ver: 08.00.10
USER : Moulin ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1356 [VPS 091127-1] 4.8.1356 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:58 Go (Free:35 Go)
D:\ (Local Disk) - NTFS - Total:127 Go (Free:100 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)
G:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)
"C:\ToolBar SD" ( MAJ : 04-12-2008|20:40 )
Option : [1] ( 27/11/2009|23:15 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\AskBarDis
C:\Program Files\AskBarDis\bar
C:\Program Files\AskBarDis\unins000.dat
C:\Program Files\AskBarDis\unins000.exe
C:\Program Files\AskBarDis\bar\bin
C:\Program Files\AskBarDis\bar\Cache
C:\Program Files\AskBarDis\bar\History
C:\Program Files\AskBarDis\bar\Settings
C:\Program Files\AskBarDis\bar\bin\askBar.dll
C:\Program Files\AskBarDis\bar\bin\askPopStp.dll
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\AskSplash.exe
C:\Program Files\AskBarDis\bar\bin\AskTBApp.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\AskBarDis\bar\bin\psvince.dll
C:\Program Files\AskBarDis\bar\Cache\000475A9
C:\Program Files\AskBarDis\bar\Cache\00047878
C:\Program Files\AskBarDis\bar\Cache\0004A574
C:\Program Files\AskBarDis\bar\Cache\files.ini
C:\Program Files\AskBarDis\bar\History\search
C:\Program Files\AskBarDis\bar\Settings\AskLogo.ico
C:\Program Files\AskBarDis\bar\Settings\config.dat
C:\Program Files\AskBarDis\bar\Settings\config.dat.bak
C:\Program Files\AskBarDis\bar\Settings\prevCfg2.htm
-----------\\ Extensions
(Moulin) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user
(Moulin) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Moulin) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Moulin) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus
(Moulin) - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} => p2p_max_france
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
1 - "C:\ToolBar SD\TB_1.txt" - 27/11/2009|23:16 - Option : [1]
-----------\\ Fin du rapport a 23:16:17,48
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 05/15/08 08:44:40 Ver: 08.00.10
USER : Moulin ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1356 [VPS 091127-1] 4.8.1356 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:58 Go (Free:35 Go)
D:\ (Local Disk) - NTFS - Total:127 Go (Free:100 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)
G:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)
"C:\ToolBar SD" ( MAJ : 04-12-2008|20:40 )
Option : [1] ( 27/11/2009|23:15 )
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\AskBarDis
C:\Program Files\AskBarDis\bar
C:\Program Files\AskBarDis\unins000.dat
C:\Program Files\AskBarDis\unins000.exe
C:\Program Files\AskBarDis\bar\bin
C:\Program Files\AskBarDis\bar\Cache
C:\Program Files\AskBarDis\bar\History
C:\Program Files\AskBarDis\bar\Settings
C:\Program Files\AskBarDis\bar\bin\askBar.dll
C:\Program Files\AskBarDis\bar\bin\askPopStp.dll
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\AskSplash.exe
C:\Program Files\AskBarDis\bar\bin\AskTBApp.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\AskBarDis\bar\bin\psvince.dll
C:\Program Files\AskBarDis\bar\Cache\000475A9
C:\Program Files\AskBarDis\bar\Cache\00047878
C:\Program Files\AskBarDis\bar\Cache\0004A574
C:\Program Files\AskBarDis\bar\Cache\files.ini
C:\Program Files\AskBarDis\bar\History\search
C:\Program Files\AskBarDis\bar\Settings\AskLogo.ico
C:\Program Files\AskBarDis\bar\Settings\config.dat
C:\Program Files\AskBarDis\bar\Settings\config.dat.bak
C:\Program Files\AskBarDis\bar\Settings\prevCfg2.htm
-----------\\ Extensions
(Moulin) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user
(Moulin) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Moulin) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Moulin) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus
(Moulin) - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} => p2p_max_france
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
1 - "C:\ToolBar SD\TB_1.txt" - 27/11/2009|23:16 - Option : [1]
-----------\\ Fin du rapport a 23:16:17,48
c'est pas toolbar SD que je t'avais demandé, c'est pas grave, qui t'a demandé de faire tolbar SD ? On l'aurai fait après, c'est pas bien grave
Relance Toolbar-S&D en double-cliquant sur le raccourci. Sélectionne l'option 2, puis appuie sur la touche Entrée.
Ne ferme pas la fenêtre lors de la suppression
Un rapport sera créé, poste son contenu ici.
Relance Toolbar-S&D en double-cliquant sur le raccourci. Sélectionne l'option 2, puis appuie sur la touche Entrée.
Ne ferme pas la fenêtre lors de la suppression
Un rapport sera créé, poste son contenu ici.
excuse moi j'ai reçu plusieurs réponse etj e me suis mélangé les crayons au niveau de la destination !
-----------\\ ToolBar S&D 1.2.6 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 05/15/08 08:44:40 Ver: 08.00.10
USER : Moulin ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1356 [VPS 091127-1] 4.8.1356 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:58 Go (Free:35 Go)
D:\ (Local Disk) - NTFS - Total:127 Go (Free:100 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)
G:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)
"C:\ToolBar SD" ( MAJ : 04-12-2008|20:40 )
Option : [2] ( 28/11/2009| 8:46 )
-----------\\ SUPPRESSION
Echec ! - C:\Program Files\AskBarDis\bar
Supprime! - C:\Program Files\AskBarDis\unins000.dat
Supprime! - C:\Program Files\AskBarDis\unins000.exe
Echec ! - C:\Program Files\AskBarDis\bar\bin
Echec ! - C:\Program Files\AskBarDis\bar\bin\AskService.exe
Echec ! - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
Echec ! - C:\Program Files\AskBarDis
-----------\\ DEUXIEME PASSAGE
Echec ! - C:\Program Files\AskBarDis\bar
Echec ! - C:\Program Files\AskBarDis\bar\bin
Echec ! - C:\Program Files\AskBarDis\bar\bin\AskService.exe
Echec ! - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
Echec ! - C:\Program Files\AskBarDis
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\AskBarDis
C:\Program Files\AskBarDis\bar
C:\Program Files\AskBarDis\bar\bin
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
-----------\\ Extensions
(Moulin) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user
(Moulin) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Moulin) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Moulin) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus
(Moulin) - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} => p2p_max_france
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
1 - "C:\ToolBar SD\TB_1.txt" - 27/11/2009|23:16 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 28/11/2009| 8:47 - Option : [2]
-----------\\ Fin du rapport a 8:47:27,23
-----------\\ ToolBar S&D 1.2.6 XP/Vista
Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 05/15/08 08:44:40 Ver: 08.00.10
USER : Moulin ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1356 [VPS 091127-1] 4.8.1356 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:58 Go (Free:35 Go)
D:\ (Local Disk) - NTFS - Total:127 Go (Free:100 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)
G:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)
"C:\ToolBar SD" ( MAJ : 04-12-2008|20:40 )
Option : [2] ( 28/11/2009| 8:46 )
-----------\\ SUPPRESSION
Echec ! - C:\Program Files\AskBarDis\bar
Supprime! - C:\Program Files\AskBarDis\unins000.dat
Supprime! - C:\Program Files\AskBarDis\unins000.exe
Echec ! - C:\Program Files\AskBarDis\bar\bin
Echec ! - C:\Program Files\AskBarDis\bar\bin\AskService.exe
Echec ! - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
Echec ! - C:\Program Files\AskBarDis
-----------\\ DEUXIEME PASSAGE
Echec ! - C:\Program Files\AskBarDis\bar
Echec ! - C:\Program Files\AskBarDis\bar\bin
Echec ! - C:\Program Files\AskBarDis\bar\bin\AskService.exe
Echec ! - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
Echec ! - C:\Program Files\AskBarDis
-----------\\ Recherche de Fichiers / Dossiers ...
C:\Program Files\AskBarDis
C:\Program Files\AskBarDis\bar
C:\Program Files\AskBarDis\bar\bin
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
-----------\\ Extensions
(Moulin) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user
(Moulin) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Moulin) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Moulin) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus
(Moulin) - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} => p2p_max_france
-----------\\ [..\Internet Explorer\Main]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"
--------------------\\ Recherche d'autres infections
Aucune autre infection trouvée !
1 - "C:\ToolBar SD\TB_1.txt" - 27/11/2009|23:16 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 28/11/2009| 8:47 - Option : [2]
-----------\\ Fin du rapport a 8:47:27,23
bonjour
fait ceci maintenant
https://forums.commentcamarche.net/forum/affich-15320659-pubs-indesirables#10
fait ceci maintenant
https://forums.commentcamarche.net/forum/affich-15320659-pubs-indesirables#10
oila qui est fait ! .
======= RAPPORT D'AD-REMOVER 1.1.4.6_D | UNIQUEMENT XP/VISTA/7 =======
.
Mit à jour par C_XX le 28.11.2009 à 13:56
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 17:53:44, 28/11/2009 | Mode Normal | Option: CLEAN
Exécuté de: C:\Program Files\Ad-Remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: MOULIN-IAIQRUC3 | Utilisateur actuel: Moulin
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
Service: ASKService
Service: ASKUpgrade
C:\DOCUME~1\Moulin\APPLIC~1\Mozilla\Firefox\Profiles\6f786d0m.default\searchplugins\ask.xml
C:\Program Files\AskBarDis
C:\Program Files\Automated Content Enhancer
(!) -- Fichiers temporaires supprimés.
.
HKCU\software\appdatalow\AskBarDis
HKCU\software\AskBarDis
HKCU\software\EoRezo
HKCU\software\ItsLabel
HKCU\software\microsoft\internet explorer\searchscopes\{CDBFB47B-58A8-4111-BF95-06178DCE326D}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{C94E154B-1459-4A47-966B-4B843BEFC7DB}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25b8d58c-b0cb-46b0-ba64-05b3804e4e86}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{35b8d58c-b0cb-46b0-ba64-05b3804e4e86}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5617eca9-488d-4ba2-8562-9710b9ab78d2}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\software\appdatalow\AskBarDis
HKLM\software\AskBarDis
HKLM\Software\Classes\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
HKLM\Software\Classes\CLSID\{1D74E9DD-8987-448b-B2CB-67FFF2B8A932}
HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf}
HKLM\Software\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}
HKLM\Software\Classes\TypeLib\{565DD573-549E-4DA9-8CD7-6AE3DF25339A}
HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
HKLM\software\EoRezo
HKLM\software\ItsLabel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1D74E9DD-8987-448b-B2CB-67FFF2B8A932}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\EoEngine
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SoftwareHelper
.
============== Scan additionnel ==============
.
.
* Mozilla FireFox Version 3.0.15 [fr] *
.
Nom du profil: 6f786d0m.default (Moulin)
.
(Moulin, Invalidprefs.js) Browser.download.lastDir, D:\Mes Documents\Ma musique
(Moulin, Invalidprefs.js) Browser.search.defaultenginename, Google
(Moulin, Invalidprefs.js) Browser.search.defaulturl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2186548&SearchSource=3&q={searchTerms}
(Moulin, Invalidprefs.js) Browser.search.selectedEngine, Live Search
(Moulin, Invalidprefs.js) Browser.startup.homepage, hxxp://www.google.fr/
.
(Moulin, Invalidprefs.js) EFFACE - CommunityToolbar.SearchFromAddressBarSavedUrl, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=
(Moulin, Invalidprefs.js) EFFACE - Browser.search.defaultthis.engineName, P2P_Max_France Customized Web Search
(Moulin, Invalidprefs.js) EFFACE - Desktopsmiley.startonce, false
(Moulin, Invalidprefs.js) EFFACE - Extensions.snipit.chromeURL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q={searchTerms}&crm=1
(Moulin, Invalidprefs.js) EFFACE - General.useragent.extra.desktopsmiley, desktopsmiley_1_1_58916135137438_6_7 DS_juicyaccess
(Moulin, Invalidprefs.js) EFFACE - Keyword.URL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=
.
(Moulin, prefs.js) Browser.download.lastDir, D:\Mes Documents\Ma musique
(Moulin, prefs.js) Browser.search.defaultenginename, Fast Browser Search
(Moulin, prefs.js) Browser.search.defaulturl, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
(Moulin, prefs.js) Browser.search.selectedEngine, Fast Browser Search
(Moulin, prefs.js) Browser.startup.homepage, www.google.fr/
.
(Moulin, prefs.js) EFFACE - CommunityToolbar.SearchFromAddressBarSavedUrl, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=
(Moulin, prefs.js) EFFACE - Browser.search.defaultenginename, Fast Browser Search
(Moulin, prefs.js) EFFACE - Browser.search.defaultthis.engineName, Fast Browser Search
(Moulin, prefs.js) EFFACE - Browser.search.defaulturl, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
(Moulin, prefs.js) EFFACE - Browser.search.order.1, Fast Browser Search
(Moulin, prefs.js) EFFACE - Browser.search.selectedEngine, Fast Browser Search
(Moulin, prefs.js) EFFACE - Extensions.snipit.chromeURL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q={searchTerms}&crm=1
(Moulin, prefs.js) EFFACE - Extensions.snipit.history_query, castorama=ASKURL=hxxp://www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis
(Moulin, prefs.js) EFFACE - Keyword.URL, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={684191BD-7F4E-B050-B7B7-26BF86266451}&q=
.
.
.
* Internet Explorer Version 6.0.2900.5512 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page Redirect Cache_TIMESTAMP: NARY b88502f86d10ca01
Start Page: hxxp://fr.msn.com/
Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
Search bar: hxxp://search.msn.com/spbasic.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
===================================
.
34459 Octet(s) - C:\Ad-Report-CLEAN[1].log
.
504 Fichier(s) - C:\DOCUME~1\Moulin\LOCALS~1\Temp
54 Fichier(s) - C:\windows\Temp
.
20 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
19 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
.
Fin à: 18:10:25 | 28/11/2009 - CLEAN[1]
.
============== E.O.F ==============
.
======= RAPPORT D'AD-REMOVER 1.1.4.6_D | UNIQUEMENT XP/VISTA/7 =======
.
Mit à jour par C_XX le 28.11.2009 à 13:56
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 17:53:44, 28/11/2009 | Mode Normal | Option: CLEAN
Exécuté de: C:\Program Files\Ad-Remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: MOULIN-IAIQRUC3 | Utilisateur actuel: Moulin
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
Service: ASKService
Service: ASKUpgrade
C:\DOCUME~1\Moulin\APPLIC~1\Mozilla\Firefox\Profiles\6f786d0m.default\searchplugins\ask.xml
C:\Program Files\AskBarDis
C:\Program Files\Automated Content Enhancer
(!) -- Fichiers temporaires supprimés.
.
HKCU\software\appdatalow\AskBarDis
HKCU\software\AskBarDis
HKCU\software\EoRezo
HKCU\software\ItsLabel
HKCU\software\microsoft\internet explorer\searchscopes\{CDBFB47B-58A8-4111-BF95-06178DCE326D}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{C94E154B-1459-4A47-966B-4B843BEFC7DB}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25b8d58c-b0cb-46b0-ba64-05b3804e4e86}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{35b8d58c-b0cb-46b0-ba64-05b3804e4e86}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5617eca9-488d-4ba2-8562-9710b9ab78d2}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\software\appdatalow\AskBarDis
HKLM\software\AskBarDis
HKLM\Software\Classes\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
HKLM\Software\Classes\CLSID\{1D74E9DD-8987-448b-B2CB-67FFF2B8A932}
HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf}
HKLM\Software\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}
HKLM\Software\Classes\TypeLib\{565DD573-549E-4DA9-8CD7-6AE3DF25339A}
HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
HKLM\software\EoRezo
HKLM\software\ItsLabel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1D74E9DD-8987-448b-B2CB-67FFF2B8A932}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\EoEngine
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SoftwareHelper
.
============== Scan additionnel ==============
.
.
* Mozilla FireFox Version 3.0.15 [fr] *
.
Nom du profil: 6f786d0m.default (Moulin)
.
(Moulin, Invalidprefs.js) Browser.download.lastDir, D:\Mes Documents\Ma musique
(Moulin, Invalidprefs.js) Browser.search.defaultenginename, Google
(Moulin, Invalidprefs.js) Browser.search.defaulturl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2186548&SearchSource=3&q={searchTerms}
(Moulin, Invalidprefs.js) Browser.search.selectedEngine, Live Search
(Moulin, Invalidprefs.js) Browser.startup.homepage, hxxp://www.google.fr/
.
(Moulin, Invalidprefs.js) EFFACE - CommunityToolbar.SearchFromAddressBarSavedUrl, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=
(Moulin, Invalidprefs.js) EFFACE - Browser.search.defaultthis.engineName, P2P_Max_France Customized Web Search
(Moulin, Invalidprefs.js) EFFACE - Desktopsmiley.startonce, false
(Moulin, Invalidprefs.js) EFFACE - Extensions.snipit.chromeURL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q={searchTerms}&crm=1
(Moulin, Invalidprefs.js) EFFACE - General.useragent.extra.desktopsmiley, desktopsmiley_1_1_58916135137438_6_7 DS_juicyaccess
(Moulin, Invalidprefs.js) EFFACE - Keyword.URL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=
.
(Moulin, prefs.js) Browser.download.lastDir, D:\Mes Documents\Ma musique
(Moulin, prefs.js) Browser.search.defaultenginename, Fast Browser Search
(Moulin, prefs.js) Browser.search.defaulturl, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
(Moulin, prefs.js) Browser.search.selectedEngine, Fast Browser Search
(Moulin, prefs.js) Browser.startup.homepage, www.google.fr/
.
(Moulin, prefs.js) EFFACE - CommunityToolbar.SearchFromAddressBarSavedUrl, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=
(Moulin, prefs.js) EFFACE - Browser.search.defaultenginename, Fast Browser Search
(Moulin, prefs.js) EFFACE - Browser.search.defaultthis.engineName, Fast Browser Search
(Moulin, prefs.js) EFFACE - Browser.search.defaulturl, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
(Moulin, prefs.js) EFFACE - Browser.search.order.1, Fast Browser Search
(Moulin, prefs.js) EFFACE - Browser.search.selectedEngine, Fast Browser Search
(Moulin, prefs.js) EFFACE - Extensions.snipit.chromeURL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q={searchTerms}&crm=1
(Moulin, prefs.js) EFFACE - Extensions.snipit.history_query, castorama=ASKURL=hxxp://www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis
(Moulin, prefs.js) EFFACE - Keyword.URL, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={684191BD-7F4E-B050-B7B7-26BF86266451}&q=
.
.
.
* Internet Explorer Version 6.0.2900.5512 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page Redirect Cache_TIMESTAMP: NARY b88502f86d10ca01
Start Page: hxxp://fr.msn.com/
Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
Search bar: hxxp://search.msn.com/spbasic.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
===================================
.
34459 Octet(s) - C:\Ad-Report-CLEAN[1].log
.
504 Fichier(s) - C:\DOCUME~1\Moulin\LOCALS~1\Temp
54 Fichier(s) - C:\windows\Temp
.
20 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
19 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
.
Fin à: 18:10:25 | 28/11/2009 - CLEAN[1]
.
============== E.O.F ==============
.
voilà madame !Logfile of random's system information tool 1.06 (written by random/random)
Run by Moulin at 2009-11-28 19:02:29
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 37 GB (61%) free of 60 GB
Total RAM: 1015 MB (47% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:02:35, on 28/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\windows\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe
C:\windows\RTHDCPL.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\windows\Mixer.exe
C:\windows\system32\RunDll32.exe
C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Calendrier\Cld2000.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SFR\Kit\9props.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fichiers communs\Common Toolkit Suite\AVEngine\AVScanningService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterSuiteService.exe
C:\PROGRA~1\FDD_FM~1\CZFMDSER.EXE
C:\windows\system32\FsUsbExService.Exe
C:\windows\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Logitech\QuickCam10\COCIManager.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Moulin\Bureau\RSIT.exe
C:\Program Files\trend micro\HijackThis\Moulin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CZFMDXPK] C:\PROGRA~1\FDD_FM~1\CZFMDXPK.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [SWPROguard] C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [Cld2000.exe] C:\Program Files\Calendrier\Cld2000.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\SFR\Media Center\MediaCenter.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [RDfrNET] C:\Program Files\Registry_Doktor 4.1\RegistryDoktor.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [Mon Widget RMC] "C:\Program Files\Nosibay\Mon Widget RMC\launcher.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\Moulin\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mu3: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mus: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mxl: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mya: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .myr: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .myt: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .xmz: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O14 - IERESET.INF: START_PAGE_URL=https://www.01net.com/telecharger/
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: AV Engine Scanning Service - Preventon Technologies Limited - C:/Program Files/Fichiers communs/Common Toolkit Suite/AVEngine/AVScanningService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Common Toolkit Service - SPAMfighter - C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterSuiteService.exe
O23 - Service: CZFMDSER.EXE - Unknown owner - C:\PROGRA~1\FDD_FM~1\CZFMDSER.EXE
O23 - Service: FsUsbExService - Teruten - C:\windows\system32\FsUsbExService.Exe
O23 - Service: Service Google Update (gupdate1c98e7fe5a2b52a) (gupdate1c98e7fe5a2b52a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
Run by Moulin at 2009-11-28 19:02:29
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 37 GB (61%) free of 60 GB
Total RAM: 1015 MB (47% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:02:35, on 28/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\windows\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe
C:\windows\RTHDCPL.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\windows\Mixer.exe
C:\windows\system32\RunDll32.exe
C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Calendrier\Cld2000.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SFR\Kit\9props.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fichiers communs\Common Toolkit Suite\AVEngine\AVScanningService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterSuiteService.exe
C:\PROGRA~1\FDD_FM~1\CZFMDSER.EXE
C:\windows\system32\FsUsbExService.Exe
C:\windows\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Logitech\QuickCam10\COCIManager.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Moulin\Bureau\RSIT.exe
C:\Program Files\trend micro\HijackThis\Moulin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CZFMDXPK] C:\PROGRA~1\FDD_FM~1\CZFMDXPK.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [SWPROguard] C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [Cld2000.exe] C:\Program Files\Calendrier\Cld2000.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\SFR\Media Center\MediaCenter.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [RDfrNET] C:\Program Files\Registry_Doktor 4.1\RegistryDoktor.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [Mon Widget RMC] "C:\Program Files\Nosibay\Mon Widget RMC\launcher.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\Moulin\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mu3: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mus: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mxl: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mya: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .myr: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .myt: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .xmz: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O14 - IERESET.INF: START_PAGE_URL=https://www.01net.com/telecharger/
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: AV Engine Scanning Service - Preventon Technologies Limited - C:/Program Files/Fichiers communs/Common Toolkit Suite/AVEngine/AVScanningService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Common Toolkit Service - SPAMfighter - C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterSuiteService.exe
O23 - Service: CZFMDSER.EXE - Unknown owner - C:\PROGRA~1\FDD_FM~1\CZFMDSER.EXE
O23 - Service: FsUsbExService - Teruten - C:\windows\system32\FsUsbExService.Exe
O23 - Service: Service Google Update (gupdate1c98e7fe5a2b52a) (gupdate1c98e7fe5a2b52a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
c'est un peu mieux
Les rogues sont de faux logiciels de sécurité, et se cachent derrière des noms
de logiciel de sécurité connus. Ils émettent de fausses alertes de sécurité qui te
poussent à acheter une version payante inéfficace. Evite de cliquer sur des pubs
de logiciels de sécurité que tu ne connais pas, puis évite les téléchargements
de fichiers par les logiciels P2P qui sont un danger pour le PC
Télécharge malwarebytes' anti-malware
https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
Enregistre le sur le bureau
Double-clique sur l'icône Download_mbam-setup.exe pour lancer le processus d'installation
Si la pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
Il va se mettre à jour une fois faite
Va dans l'onglet recherche
Sélectionne exécuter un examen complet
Clique sur rechercher
Le scan démarre
A la fin de l'analyse, le message s'affiche: L'examen s'est terminé normalement.
Clique sur afficher les résultats pour afficher les objets trouvés
Clique sur OK pour pousuivre
Si des malwares ont été détectés, cliquer sur afficher les résultats
Sélectionne tout (ou laisser coché)
Clique sur supprimer la sélection
Malwarebytes va détruire les fichiers et les clés de registre et en mettre une
copie dans la quarantaine
Malewarebytes va ouvrir le bloc-note et y copier le rapport
Redémarre le PC
Une fois redémarré, double-clique sur Malewarebytes
Va dans l'onglet rapport/log
Clique dessus pour l'afficher une fois affiché, cliquer sur édition en haut du
bloc-note puis sur sélectionner tout
Revient sur édition, puis sur copier et revient sur le forum et dans ta réponse
Clic droit dans le cadre de la réponse et coller
Les rogues sont de faux logiciels de sécurité, et se cachent derrière des noms
de logiciel de sécurité connus. Ils émettent de fausses alertes de sécurité qui te
poussent à acheter une version payante inéfficace. Evite de cliquer sur des pubs
de logiciels de sécurité que tu ne connais pas, puis évite les téléchargements
de fichiers par les logiciels P2P qui sont un danger pour le PC
Télécharge malwarebytes' anti-malware
https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
Enregistre le sur le bureau
Double-clique sur l'icône Download_mbam-setup.exe pour lancer le processus d'installation
Si la pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
Il va se mettre à jour une fois faite
Va dans l'onglet recherche
Sélectionne exécuter un examen complet
Clique sur rechercher
Le scan démarre
A la fin de l'analyse, le message s'affiche: L'examen s'est terminé normalement.
Clique sur afficher les résultats pour afficher les objets trouvés
Clique sur OK pour pousuivre
Si des malwares ont été détectés, cliquer sur afficher les résultats
Sélectionne tout (ou laisser coché)
Clique sur supprimer la sélection
Malwarebytes va détruire les fichiers et les clés de registre et en mettre une
copie dans la quarantaine
Malewarebytes va ouvrir le bloc-note et y copier le rapport
Redémarre le PC
Une fois redémarré, double-clique sur Malewarebytes
Va dans l'onglet rapport/log
Clique dessus pour l'afficher une fois affiché, cliquer sur édition en haut du
bloc-note puis sur sélectionner tout
Revient sur édition, puis sur copier et revient sur le forum et dans ta réponse
Clic droit dans le cadre de la réponse et coller
Bonsoir Nathandre, il semblerai que le problème des pubs pirates soit réglé : merci pour ton intervention semble t-il éfficace