Pubs indésirables

Résolu
baryton33 Messages postés 283 Date d'inscription   Statut Membre Dernière intervention   -  
 Utilisateur anonyme -
Bonjour,depuis quelques temps, quand je suis connecté à internet via mozilla je suis inondé de pages pubs : jeux de poker, Meetick adultes. Que faire pour ne plus recevoir ces pages(malgré un anti spam) ? merci

14 réponses

Utilisateur anonyme
 
baryton bonjour
je ne sais pas si tu es là, mais ton PC est pas mal infecté
2
Utilisateur anonyme
 
bonjour
Télécharge Random's System Information Tool (RSIT) de random/random et enregistre l'exécutable sur ton Bureau.

- http://images.malwareremoval.com/random/RSIT.exe

! Déconnecte toi et ferme toutes tes applications en cours !

* Double-clique sur RSIT.exe pour le lancer .
* Une première fenêtre s'ouvre avec en titre : Disclaimer of warranty .
* Devant l'option List files/folders created ... , tu choisis 2 months
* Clique ensuite sur Continue pour lancer l'analyse ...
* Laisse faire le scan et ne touche pas au PC ...
* Lorsque l'analyse sera terminée, deux fichiers texte s'ouvriront (probablement avec le bloc-note).
* Héberge le contenu de log.txt (c'est celui qui apparait à l'écran), ainsi que de info.txt ici.
Clique sur parcourir
Une fois que tu as trouvé les rapports à héberger, clique sur ouvrir
Clique sur Cliquez ici pour déposer le fichier, puis donne le lien
qui apparait comme ceci http:/www.cijoint.fr/cjlink.php?file=cj200911/cijgAdC3Ch.txt

Note : les rapports seront en outre sauvegardés dans ce dossier C:\rsit
1
baryton33 Messages postés 283 Date d'inscription   Statut Membre Dernière intervention   3
 
merci c'est (est ce bien fait) nous verrons bien merci de nouveau !
0
Utilisateur anonyme
 
j'ai cru voir les rapports, et je ne les vois plus
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
baryton33 Messages postés 283 Date d'inscription   Statut Membre Dernière intervention   3
 
désolé mais à l'ouverture , une de ces pubs c'est affichée !
0
baryton33 Messages postés 283 Date d'inscription   Statut Membre Dernière intervention   3
 
je viens de refaire la même manipulation !
0
Utilisateur anonyme
 
comment je peux savoir si je n'ai pas de rapport
0
^^Marie^^ Messages postés 114059 Date d'inscription   Statut Membre Dernière intervention   3 279
 
Salut

Il est là le rapport

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:20:39, on 27/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\windows\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\windows\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe
C:\windows\RTHDCPL.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\windows\Mixer.exe
C:\windows\system32\RunDll32.exe
C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Calendrier\Cld2000.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SFR\Kit\9props.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\Fichiers communs\Common Toolkit Suite\AVEngine\AVScanningService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterSuiteService.exe
C:\PROGRA~1\FDD_FM~1\CZFMDSER.EXE
C:\windows\system32\FsUsbExService.Exe
C:\windows\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\windows\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Logitech\QuickCam10\COCIManager.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: DefaultSearchHook Class - {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll (file missing)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Automated Content Enhancer - {1D74E9DD-8987-448b-B2CB-67FFF2B8A932} - C:\Program Files\Automated Content Enhancer\4.1.0.5050\ACEIEAddOn.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: EoRezoBHO - {64F56FC1-1272-44CD-BA6E-39723696E350} - C:\PROGRA~1\EoRezo\EoAdv\EOREZO~1.DLL (file missing)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll
O4 - HKLM\..\Run: [SoftwareHelper] C:\Documents and Settings\Moulin\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CZFMDXPK] C:\PROGRA~1\FDD_FM~1\CZFMDXPK.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [SWPROguard] C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [Cld2000.exe] C:\Program Files\Calendrier\Cld2000.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\SFR\Media Center\MediaCenter.exe"
O4 - HKCU\..\Run: [BitComet] "C:\Program Files\BitComet\BitComet.exe" /tray
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [RDfrNET] C:\Program Files\Registry_Doktor 4.1\RegistryDoktor.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [Mon Widget RMC] "C:\Program Files\Nosibay\Mon Widget RMC\launcher.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\Moulin\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mu3: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mus: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mxl: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mya: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .myr: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .myt: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .xmz: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O14 - IERESET.INF: START_PAGE_URL=https://www.01net.com/telecharger/
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: bw+0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {55874B82-A641-4544-9FA7-3422B6D33A1A} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASKService - Unknown owner - C:\Program Files\AskBarDis\bar\bin\AskService.exe
O23 - Service: ASKUpgrade - Unknown owner - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: AV Engine Scanning Service - Preventon Technologies Limited - C:/Program Files/Fichiers communs/Common Toolkit Suite/AVEngine/AVScanningService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Common Toolkit Service - SPAMfighter - C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterSuiteService.exe
O23 - Service: CZFMDSER.EXE - Unknown owner - C:\PROGRA~1\FDD_FM~1\CZFMDSER.EXE
O23 - Service: FsUsbExService - Teruten - C:\windows\system32\FsUsbExService.Exe
O23 - Service: Service Google Update (gupdate1c98e7fe5a2b52a) (gupdate1c98e7fe5a2b52a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
0
baryton33 Messages postés 283 Date d'inscription   Statut Membre Dernière intervention   3
 
oui ça je le pense depuis longtemps mais que faire pour qu'il ne le soit plus ? Merci !
0
Utilisateur anonyme
 
EoRezo te propose des logiciels frauduleux qu'il faut éviter de télécharger
On nous demande des informations qui peuvent être utilisées à des fins commerciales
Ces logiciels modifient la page d'accueil, et peuvent faire ramer ton PC, et font
afficher plein de pubs


Télécharge AD Remover ( de Cyrildu17 / C_XX ) sur ton bureau :
http://pagesperso-orange.fr/NosTools/C_XX/AD-R.exe
ou
https://www.androidworld.fr/

Désactive l'anti-virus

Déconnecte toi et ferme toutes les applications en cours

Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
Double-clique sur l'icône Ad-remover présent sur ton bureau pour le lancer
Au menu principal, sélectionne l'option L, puis appuie sur la touche entrée
Poste le rapport qui apparait à la fin .

( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

Note :
"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall
0
baryton33 Messages postés 283 Date d'inscription   Statut Membre Dernière intervention   3
 
-----------\\ ToolBar S&D 1.2.6 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 05/15/08 08:44:40 Ver: 08.00.10
USER : Moulin ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1356 [VPS 091127-1] 4.8.1356 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:58 Go (Free:35 Go)
D:\ (Local Disk) - NTFS - Total:127 Go (Free:100 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)
G:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)

"C:\ToolBar SD" ( MAJ : 04-12-2008|20:40 )
Option : [1] ( 27/11/2009|23:15 )

-----------\\ Recherche de Fichiers / Dossiers ...

C:\Program Files\AskBarDis
C:\Program Files\AskBarDis\bar
C:\Program Files\AskBarDis\unins000.dat
C:\Program Files\AskBarDis\unins000.exe
C:\Program Files\AskBarDis\bar\bin
C:\Program Files\AskBarDis\bar\Cache
C:\Program Files\AskBarDis\bar\History
C:\Program Files\AskBarDis\bar\Settings
C:\Program Files\AskBarDis\bar\bin\askBar.dll
C:\Program Files\AskBarDis\bar\bin\askPopStp.dll
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\AskSplash.exe
C:\Program Files\AskBarDis\bar\bin\AskTBApp.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
C:\Program Files\AskBarDis\bar\bin\psvince.dll
C:\Program Files\AskBarDis\bar\Cache\000475A9
C:\Program Files\AskBarDis\bar\Cache\00047878
C:\Program Files\AskBarDis\bar\Cache\0004A574
C:\Program Files\AskBarDis\bar\Cache\files.ini
C:\Program Files\AskBarDis\bar\History\search
C:\Program Files\AskBarDis\bar\Settings\AskLogo.ico
C:\Program Files\AskBarDis\bar\Settings\config.dat
C:\Program Files\AskBarDis\bar\Settings\config.dat.bak
C:\Program Files\AskBarDis\bar\Settings\prevCfg2.htm

-----------\\ Extensions

(Moulin) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user
(Moulin) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Moulin) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Moulin) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus
(Moulin) - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} => p2p_max_france


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home"


--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !


1 - "C:\ToolBar SD\TB_1.txt" - 27/11/2009|23:16 - Option : [1]

-----------\\ Fin du rapport a 23:16:17,48
0
Utilisateur anonyme
 
c'est pas toolbar SD que je t'avais demandé, c'est pas grave, qui t'a demandé de faire tolbar SD ? On l'aurai fait après, c'est pas bien grave
Relance Toolbar-S&D en double-cliquant sur le raccourci. Sélectionne l'option 2, puis appuie sur la touche Entrée.
Ne ferme pas la fenêtre lors de la suppression
Un rapport sera créé, poste son contenu ici.
0
baryton33 Messages postés 283 Date d'inscription   Statut Membre Dernière intervention   3
 
excuse moi j'ai reçu plusieurs réponse etj e me suis mélangé les crayons au niveau de la destination !

-----------\\ ToolBar S&D 1.2.6 XP/Vista

Microsoft Windows XP Édition familiale ( v5.1.2600 ) Service Pack 3
X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz )
BIOS : BIOS Date: 05/15/08 08:44:40 Ver: 08.00.10
USER : Moulin ( Administrator )
BOOT : Normal boot
Antivirus : avast! antivirus 4.8.1356 [VPS 091127-1] 4.8.1356 (Activated)
A:\ (USB)
C:\ (Local Disk) - NTFS - Total:58 Go (Free:35 Go)
D:\ (Local Disk) - NTFS - Total:127 Go (Free:100 Go)
E:\ (CD or DVD)
F:\ (CD or DVD)
G:\ (USB)
I:\ (USB)
J:\ (USB)
K:\ (USB)

"C:\ToolBar SD" ( MAJ : 04-12-2008|20:40 )
Option : [2] ( 28/11/2009| 8:46 )

-----------\\ SUPPRESSION

Echec ! - C:\Program Files\AskBarDis\bar
Supprime! - C:\Program Files\AskBarDis\unins000.dat
Supprime! - C:\Program Files\AskBarDis\unins000.exe
Echec ! - C:\Program Files\AskBarDis\bar\bin
Echec ! - C:\Program Files\AskBarDis\bar\bin\AskService.exe
Echec ! - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
Echec ! - C:\Program Files\AskBarDis

-----------\\ DEUXIEME PASSAGE

Echec ! - C:\Program Files\AskBarDis\bar
Echec ! - C:\Program Files\AskBarDis\bar\bin
Echec ! - C:\Program Files\AskBarDis\bar\bin\AskService.exe
Echec ! - C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe
Echec ! - C:\Program Files\AskBarDis

-----------\\ Recherche de Fichiers / Dossiers ...

C:\Program Files\AskBarDis
C:\Program Files\AskBarDis\bar
C:\Program Files\AskBarDis\bar\bin
C:\Program Files\AskBarDis\bar\bin\AskService.exe
C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe

-----------\\ Extensions

(Moulin) - {20a82645-c095-46ed-80e3-08825760534b} => chrome_user
(Moulin) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Moulin) - {3112ca9c-de6d-4884-a869-9855de68056c} => google-toolbar
(Moulin) - {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d} => adblockplus
(Moulin) - {fe37be35-b028-49f9-bb0c-6a38c4e55b97} => p2p_max_france


-----------\\ [..\Internet Explorer\Main]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Local Page"="C:\\windows\\system32\\blank.htm"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Start Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main]
"Default_Page_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome"
"Default_Search_URL"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch"
"Local Page"="C:\\windows\\system32\\blank.htm"
"Start Page"="https://www.msn.com/fr-fr/"


--------------------\\ Recherche d'autres infections


Aucune autre infection trouvée !


1 - "C:\ToolBar SD\TB_1.txt" - 27/11/2009|23:16 - Option : [1]
2 - "C:\ToolBar SD\TB_2.txt" - 28/11/2009| 8:47 - Option : [2]

-----------\\ Fin du rapport a 8:47:27,23
0
Utilisateur anonyme
 
0
baryton33 Messages postés 283 Date d'inscription   Statut Membre Dernière intervention   3
 
oila qui est fait ! .
======= RAPPORT D'AD-REMOVER 1.1.4.6_D | UNIQUEMENT XP/VISTA/7 =======
.
Mit à jour par C_XX le 28.11.2009 à 13:56
Contact: AdRemover.contact@gmail.com
Site web: http://pagesperso-orange.fr/NosTools/ad_remover.html
.
Lancé à: 17:53:44, 28/11/2009 | Mode Normal | Option: CLEAN
Exécuté de: C:\Program Files\Ad-Remover\
Système d'exploitation: Microsoft® Windows XP™ Service Pack 3 v5.1.2600
Nom du PC: MOULIN-IAIQRUC3 | Utilisateur actuel: Moulin
.
============== ÉLÉMENT(S) NEUTRALISÉ(S) ==============
.
Service: ASKService
Service: ASKUpgrade
C:\DOCUME~1\Moulin\APPLIC~1\Mozilla\Firefox\Profiles\6f786d0m.default\searchplugins\ask.xml
C:\Program Files\AskBarDis
C:\Program Files\Automated Content Enhancer

(!) -- Fichiers temporaires supprimés.

.
HKCU\software\appdatalow\AskBarDis
HKCU\software\AskBarDis
HKCU\software\EoRezo
HKCU\software\ItsLabel
HKCU\software\microsoft\internet explorer\searchscopes\{CDBFB47B-58A8-4111-BF95-06178DCE326D}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{3041D03E-FD4B-44E0-B742-2D9B88305F98}
HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5617ECA9-488D-4BA2-8562-9710B9AB78D2}
HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\\{C94E154B-1459-4A47-966B-4B843BEFC7DB}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25b8d58c-b0cb-46b0-ba64-05b3804e4e86}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{35b8d58c-b0cb-46b0-ba64-05b3804e4e86}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5617eca9-488d-4ba2-8562-9710b9ab78d2}
HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\software\appdatalow\AskBarDis
HKLM\software\AskBarDis
HKLM\Software\Classes\CLSID\{0702a2b6-13aa-4090-9e01-bcdc85dd933f}
HKLM\Software\Classes\CLSID\{1D74E9DD-8987-448b-B2CB-67FFF2B8A932}
HKLM\Software\Classes\CLSID\{622fd888-4e91-4d68-84d4-7262fd0811bf}
HKLM\Software\Classes\CLSID\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\Software\Classes\CLSID\{b0de3308-5d5a-470d-81b9-634fc078393b}
HKLM\Software\Classes\Interface\{B0D071A1-36B3-4757-A126-14C89C56013A}
HKLM\Software\Classes\TypeLib\{4B1C1E16-6B34-430E-B074-5928ECA4C150}
HKLM\Software\Classes\TypeLib\{565DD573-549E-4DA9-8CD7-6AE3DF25339A}
HKLM\Software\Classes\TypeLib\{B4C656C9-F2E9-4E77-B3F4-443DF2BD778F}
HKLM\software\EoRezo
HKLM\software\ItsLabel
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1D74E9DD-8987-448b-B2CB-67FFF2B8A932}
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{64F56FC1-1272-44CD-BA6E-39723696E350}
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\EoEngine
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\SoftwareHelper
.
============== Scan additionnel ==============
.
.
* Mozilla FireFox Version 3.0.15 [fr] *
.
Nom du profil: 6f786d0m.default (Moulin)
.
(Moulin, Invalidprefs.js) Browser.download.lastDir, D:\Mes Documents\Ma musique
(Moulin, Invalidprefs.js) Browser.search.defaultenginename, Google
(Moulin, Invalidprefs.js) Browser.search.defaulturl, hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2186548&SearchSource=3&q={searchTerms}
(Moulin, Invalidprefs.js) Browser.search.selectedEngine, Live Search
(Moulin, Invalidprefs.js) Browser.startup.homepage, hxxp://www.google.fr/
.
(Moulin, Invalidprefs.js) EFFACE - CommunityToolbar.SearchFromAddressBarSavedUrl, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=
(Moulin, Invalidprefs.js) EFFACE - Browser.search.defaultthis.engineName, P2P_Max_France Customized Web Search
(Moulin, Invalidprefs.js) EFFACE - Desktopsmiley.startonce, false
(Moulin, Invalidprefs.js) EFFACE - Extensions.snipit.chromeURL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q={searchTerms}&crm=1
(Moulin, Invalidprefs.js) EFFACE - General.useragent.extra.desktopsmiley, desktopsmiley_1_1_58916135137438_6_7 DS_juicyaccess
(Moulin, Invalidprefs.js) EFFACE - Keyword.URL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=
.
(Moulin, prefs.js) Browser.download.lastDir, D:\Mes Documents\Ma musique
(Moulin, prefs.js) Browser.search.defaultenginename, Fast Browser Search
(Moulin, prefs.js) Browser.search.defaulturl, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
(Moulin, prefs.js) Browser.search.selectedEngine, Fast Browser Search
(Moulin, prefs.js) Browser.startup.homepage, www.google.fr/
.
(Moulin, prefs.js) EFFACE - CommunityToolbar.SearchFromAddressBarSavedUrl, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q=
(Moulin, prefs.js) EFFACE - Browser.search.defaultenginename, Fast Browser Search
(Moulin, prefs.js) EFFACE - Browser.search.defaultthis.engineName, Fast Browser Search
(Moulin, prefs.js) EFFACE - Browser.search.defaulturl, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=DEF&v=19&q=
(Moulin, prefs.js) EFFACE - Browser.search.order.1, Fast Browser Search
(Moulin, prefs.js) EFFACE - Browser.search.selectedEngine, Fast Browser Search
(Moulin, prefs.js) EFFACE - Extensions.snipit.chromeURL, hxxp://toolbar.ask.com/toolbarv/askRedirect?o=10611&gct=&gc=1&q={searchTerms}&crm=1
(Moulin, prefs.js) EFFACE - Extensions.snipit.history_query, castorama=ASKURL=hxxp://www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis||castorama=ASKURL=//www.ask.com/web?q=castorama&qsrc=2871&o=10611&l=dis
(Moulin, prefs.js) EFFACE - Keyword.URL, hxxp://www.fastbrowsersearch.com/results/results.aspx?s=NAUS&v=19&tid={684191BD-7F4E-B050-B7B7-26BF86266451}&q=
.
.
.
* Internet Explorer Version 6.0.2900.5512 *
.
[HKEY_CURRENT_USER\..\Internet Explorer\Main]
.
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page Redirect Cache_TIMESTAMP: NARY b88502f86d10ca01
Start Page: hxxp://fr.msn.com/
Default_page_url: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Search bar: hxxp://go.microsoft.com/fwlink/?linkid=54896
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]
.
Default_Page_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
Default_Search_URL: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Search Page: hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
Start Page: hxxp://fr.msn.com/
Search bar: hxxp://search.msn.com/spbasic.htm
.
[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]
.
Tabs: res://ieframe.dll/tabswelcome.htm
.
===================================
.
34459 Octet(s) - C:\Ad-Report-CLEAN[1].log
.
504 Fichier(s) - C:\DOCUME~1\Moulin\LOCALS~1\Temp
54 Fichier(s) - C:\windows\Temp
.
20 Fichier(s) - C:\Program Files\Ad-Remover\BACKUP
19 Fichier(s) - C:\Program Files\Ad-Remover\QUARANTINE
.
Fin à: 18:10:25 | 28/11/2009 - CLEAN[1]
.
============== E.O.F ==============
.
0
Utilisateur anonyme
 
pourrai tu me refaire un RSIT
0
baryton33 Messages postés 283 Date d'inscription   Statut Membre Dernière intervention   3
 
voilà madame !Logfile of random's system information tool 1.06 (written by random/random)
Run by Moulin at 2009-11-28 19:02:29
Microsoft Windows XP Édition familiale Service Pack 3
System drive C: has 37 GB (61%) free of 60 GB
Total RAM: 1015 MB (47% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:02:35, on 28/11/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\system32\svchost.exe
C:\windows\system32\spoolsv.exe
c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
C:\windows\Explorer.EXE
C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe
C:\windows\RTHDCPL.EXE
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\windows\Mixer.exe
C:\windows\system32\RunDll32.exe
C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe
C:\windows\system32\ctfmon.exe
C:\Program Files\Calendrier\Cld2000.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SFR\Kit\9props.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Fichiers communs\Common Toolkit Suite\AVEngine\AVScanningService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterSuiteService.exe
C:\PROGRA~1\FDD_FM~1\CZFMDSER.EXE
C:\windows\system32\FsUsbExService.Exe
C:\windows\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\CDBurnerXP\NMSAccessU.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Program Files\Logitech\QuickCam10\COCIManager.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Moulin\Bureau\RSIT.exe
C:\Program Files\trend micro\HijackThis\Moulin.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - c:\program files\real\realplayer\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll (file missing)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Fichiers communs\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Fichiers communs\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [CZFMDXPK] C:\PROGRA~1\FDD_FM~1\CZFMDXPK.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup
O4 - HKLM\..\Run: [CmPCIaudio] RunDll32 CMICNFG3.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Fichiers communs\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
O4 - HKLM\..\Run: [SWPROguard] C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\system32\ctfmon.exe
O4 - HKCU\..\Run: [Cld2000.exe] C:\Program Files\Calendrier\Cld2000.exe
O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Fichiers communs\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020
O4 - HKCU\..\Run: [Neuf Media Center] "C:\Program Files\SFR\Media Center\MediaCenter.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Connexion SFR 9props.exe] "C:\Program Files\SFR\Kit\9props.exe" /trayicon
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [RDfrNET] C:\Program Files\Registry_Doktor 4.1\RegistryDoktor.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe
O4 - HKCU\..\Run: [Mon Widget RMC] "C:\Program Files\Nosibay\Mon Widget RMC\launcher.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - Startup: Notification de cadeaux MSN.lnk = C:\Documents and Settings\Moulin\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\windows\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .mu3: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mus: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mxl: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .mya: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .myr: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .myt: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O12 - Plugin for .xmz: C:\Program Files\Internet Explorer\Plugins\NPMyrMus.dll
O14 - IERESET.INF: START_PAGE_URL=https://www.01net.com/telecharger/
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} - https://www.touslesdrivers.com/index.php?v_page=29
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FICHIE~1\Skype\SKYPE4~1.DLL
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: AV Engine Scanning Service - Preventon Technologies Limited - C:/Program Files/Fichiers communs/Common Toolkit Suite/AVEngine/AVScanningService.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Common Toolkit Service - SPAMfighter - C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterSuiteService.exe
O23 - Service: CZFMDSER.EXE - Unknown owner - C:\PROGRA~1\FDD_FM~1\CZFMDSER.EXE
O23 - Service: FsUsbExService - Teruten - C:\windows\system32\FsUsbExService.Exe
O23 - Service: Service Google Update (gupdate1c98e7fe5a2b52a) (gupdate1c98e7fe5a2b52a) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\fichiers communs\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Fichiers communs\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
0
Utilisateur anonyme
 
c'est un peu mieux


Les rogues sont de faux logiciels de sécurité, et se cachent derrière des noms
de logiciel de sécurité connus. Ils émettent de fausses alertes de sécurité qui te
poussent à acheter une version payante inéfficace. Evite de cliquer sur des pubs
de logiciels de sécurité que tu ne connais pas, puis évite les téléchargements
de fichiers par les logiciels P2P qui sont un danger pour le PC



Télécharge malwarebytes' anti-malware
https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/
Enregistre le sur le bureau
Double-clique sur l'icône Download_mbam-setup.exe pour lancer le processus d'installation
Si la pare-feu demande l'autorisation de se connecter pour malwarebytes, accepte
Il va se mettre à jour une fois faite
Va dans l'onglet recherche
Sélectionne exécuter un examen complet
Clique sur rechercher
Le scan démarre
A la fin de l'analyse, le message s'affiche: L'examen s'est terminé normalement.
Clique sur afficher les résultats pour afficher les objets trouvés
Clique sur OK pour pousuivre
Si des malwares ont été détectés, cliquer sur afficher les résultats
Sélectionne tout (ou laisser coché)
Clique sur supprimer la sélection
Malwarebytes va détruire les fichiers et les clés de registre et en mettre une
copie dans la quarantaine
Malewarebytes va ouvrir le bloc-note et y copier le rapport
Redémarre le PC
Une fois redémarré, double-clique sur Malewarebytes
Va dans l'onglet rapport/log
Clique dessus pour l'afficher une fois affiché, cliquer sur édition en haut du
bloc-note puis sur sélectionner tout
Revient sur édition, puis sur copier et revient sur le forum et dans ta réponse
Clic droit dans le cadre de la réponse et coller
0
baryton33 Messages postés 283 Date d'inscription   Statut Membre Dernière intervention   3
 
Bonsoir Nathandre, il semblerai que le problème des pubs pirates soit réglé : merci pour ton intervention semble t-il éfficace
0
Utilisateur anonyme
 
bonsoir baryton
aurai tu le rapport de Malwarebytes, car tu as un rogue dans ton PC
0
baryton33 Messages postés 283 Date d'inscription   Statut Membre Dernière intervention   3
 
Bonjour,je ne sais pas ce qu'est Malvarebytes pas plus qu'un rogue ! c'est pour te dire le niveau de ton interlocuteur ! MDR d'autre part je crois que les pubs reviennent à l'instant même que faire pour néttoyer correctement mon PC ?
0
Utilisateur anonyme
 
bonjour
c'était pas finit
Il faudrai faire Malwarebytes
0