[Pub ] Antivirus pro 2006 genante

Résolu
Bonjour, j'ai depuis environ un mois des publicités qui s'ouvrent, generalement lorsque je clique sur un lien comme sur google, la plupart cocernent des antivirus, nottament antivirus pro 2006, et cela est trs genant. Merci de m'aider a resoudre ce probleme.

Voici mon rapport Hijackthis:

Logfile of HijackThis v1.99.1
Scan saved at 11:08:54, on 09/06/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\ATK0100\HControl.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\sm56hlpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\GRARD~1\LOCALS~1\Temp\Rar$EX02.906\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://fr.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer fourni par Yahoo! France
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NotebookHardwareControl] "C:\Program Files\Notebook Hardware Control\nhc.exe" -quiet
O4 - HKLM\..\Run: [HControl] C:\WINDOWS\ATK0100\HControl.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\ASUSTeK\ASUSDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
O4 - HKLM\..\Run: [Vaderetro Outlook] "C:\PROGRA~1\GOTOSO~1\VADERE~1\VrMoRegister.exe -s"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup
O4 - HKLM\..\Run: [KONICA MINOLTA PagePro 1400W STD] C:\WINDOWS\system32\MSTMON_Y.EXE STARTUP
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/7/1540/52/20070501/qtinstall.info.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe

Voila, en esperant que cela vous sera utile pour m'aider. Merci d'avance.
Configuration: Windows XP
Internet Explorer 7.0

15 réponses

  1. salut jerembeye,

    1
    avec hijack this coche ceci :

    O2 - BHO: (no name) - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - (no file)
    O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
    O11 - Options group: [INTERNATIONAL] International*
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akamai.net/

    quitte tes applications et fix/check les lignes ci dessus.

    2
    tu n´as pas de par feu :

    Télécgharge Kerio et installe le :

    https://kerio.probb.fr/t1-tuto-pour-kerio-4-2

    Merci a boulepate pour le site!!!

    3
    Fais un clic droit sur ce lien :
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    Enregistrer la cible (du lien) sous... et enregistre-le sur ton bureau.
    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité dans une réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

    @+

    0
    1. Merci beaucoup, voila ce que tu me demande:

      Search Navipromo version 2.0.3 commencé le 09/06/2007 à 11:55:27,21

      !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
      !!! Poster ce rapport sur le forum pour le faire analyser !!!
      !!! Ne pas lancer la partie désinfection sans l'avis d'un spécialiste !!!

      Fix lancé depuis C:\Program Files\navilog1
      Mise a jour le 08.06.2007 a 17h00 by IL-MAFIOSO

      Executé en mode normal

      *** Recherche Programmes installes ***

      SudoPlanet

      *** Recherche dossiers dans C:\WINDOWS ***

      *** Recherche dossiers dans C:\Program Files ***

      C:\Program Files\SudoPlanet trouvé !

      *** Recherche dossiers dans C:\Documents and Settings\All Users\Application Data ***

      *** Recherche dossiers dans C:\Documents and Settings\G‚rard\Application Data ***

      *** Recherche avec BlackLight Engine/F-secure ***
      BlackLight Engine est un produit de F-secure, pour + d'infos :
      https://www.f-secure.com/en

      F-SECURE BLACKLIGHT ROOTKIT ELIMINATOR
      ======================================

      Copyright 2005-2006 F-Secure Corporation. All rights reserved.
      This is a beta version. It will expire on 1st of April, 2007.
      Version information: 2.2.1061.

      [+] Started on 06/09/07 at 11:55:34.
      [+] Initializing ...
      [+] Starting scan, press Ctrl-C to abort.
      [+] Scanning for hidden items ..................................
      [+] Scan complete.
      [+] Summary: 0 hidden item(s) found, 0 scheduled for renaming.
      [+] Exited on 06/09/07 at 11:58:16 (return code = 0).

      *** Recherche fichiers ***

      C:\WINDOWS\pack.epk trouvé !
      C:\WINDOWS\system32\nvs2.inf trouvé !

      *** Recherche cles registre ***

      Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs]

      Recherche dans [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage]

      Recherche Clé Magic Control

      HKEY_CURRENT_USER\Software\Lanconfig trouvé !
      HKEY_USERS\S-1-5-21-2202977061-2466340154-644938488-1009\Software\Lanconfig trouvé !
      HKEY_CURRENT_USER\Software\mc trouvé !

      *** Module de Recherche complémentaire ***
      (Recherche fichiers spécifiques)

      1)Recherche fichiers connus:

      2)Recherche Heuristique :
      *
      C:\WINDOWS\system32\trfpwro.dat trouvé !
      **
      C:\WINDOWS\system32\trfpwro.dat trouvé !
      ***
      ****
      C:\WINDOWS\system32\trfpwro_navps.dat trouvé !
      *****
      ******
      *******
      ********

      *** Analyse Terminé le 09/06/2007 à 11:58:47,95 ***

      Voila et merci
      0
      1. re,

        de rien ;-)

        Double clique sur le raccourci Navilog1 présent sur le bureau et laisse-toi guider.
        Au menu principal, choisis 2 et valide.

        Le fix va t'informer qu'il va alors redémarrer ton PC
        Ferme toutes les fenêtres ouvertes et enregistre tes documents personnels ouverts
        Appuie sur une touche comme demandé.
        (si ton Pc ne redémarre pas automatiquement, fais le toi même)
        Au redémarrage de ton PC, choisis ta session habituelle.

        Patiente jusqu'au message :
        *** Nettoyage Termine le ..... ***
        Le blocnote va s'ouvrir.
        Sauvegarde le rapport de manière à le retrouver
        Referme le blocnote. Ton bureau va réapparaitre

        PS:Si ton bureau ne réapparait pas, fais CTRL+ALT+SUPP pour ouvrir le gestionnaire de tâches.
        Puis rends-toi à l'onglet "processus". Clique en haut à gauche sur fichiers et choisis "exécuter"
        Tape explorer et valide. Celà te fera apparaitre ton bureau.

        * Ferme Internet Explorer puis Démarrer/Panneau de Configuration/Options Internet.
        * Choisis l'onglet Contenu puis onglet Certificats.
        * Si tu trouves les programmes suivants (en particulier dans "Editeurs approuvés" ), supprime-les :

        electronic-group
        egroup
        Montorgueil
        VIP
        Sunny Day Design Ltd

        @+

        0
        1. Salut, voila, j'ai fait ce que tu m'avais demandé. Il y avait bien un fichier "electronic-group" dans "editeurs approuvés" que j'ai supprimé.

          L'ordinateur a redémarré tout seul, nikel.
          0
          1. re,

            tu ne devrais plus avoir de pubs?!

            ps : je peux voire le rapport quand meme...

            ¤ Télécharge Clean
            ----> http://www.malekal.com/download/clean.zip

            Dézippe tout le contenu dans le même dossier. Double clic sur clean ou clean.cmd choisissez l'option 1.
            Un rapport va s'ouvrir, copie et colle le contenu ici
            0
            1. Re, voici le rapport demandé:

              09/06/2007 a 12:26:21,09

              *** Recherche des fichiers dans C:
              C:\StubInstaller.exe FOUND

              *** Recherche des fichiers dans C:\WINDOWS\

              *** Recherche des fichiers dans C:\WINDOWS\system32

              *** Recherche des fichiers dans C:\Program Files
              *** Fin du rapport !
              0
              1. ok

                pour verif :

                * télécharge AVG Anti-Spyware (ewido)

                https://www.avg.com/en-ww/free-antivirus-download
                http://www.infos-du-net.com/telecharger/Ewido-Security-Suite,0301-734.html
                * tu l'installes

                * lance AVG Anti-Spyware et clique sur le bouton Mise à jour. Patiente
                si tu n'arrives pas à le mettre à jour prends ici les màj
                http://downloads.ewido.net/avgas-signatures-full-current.exe

                Sur la page "analyse":
                •- tu choisis d'abord l'onglet "paramètres".
                - sous « Comment réagir » clic sur « Actions recommandées » et dans le menu déroulant, choisir « Supprimer »

                Copie Et colle le rapport ici

                @+
                0
                1. Salut, voici le rapport AVG :

                  ---------------------------------------------------------
                  AVG Anti-Spyware - Rapport d'analyse
                  ---------------------------------------------------------

                  + Créé à: 12:56:33 09/06/2007

                  + Résultat de l'analyse:

                  C:\System Volume Information\_restore{A0865A4E-2183-4BFE-9251-1BE2D0C4EE7E}\RP130\A0035140.exe -> Adware.BHO : Nettoyé.
                  C:\System Volume Information\_restore{A0865A4E-2183-4BFE-9251-1BE2D0C4EE7E}\RP130\A0035139.dll -> Adware.VB : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@adtech[2].txt -> TrackingCookie.Adtech : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@advertising[1].txt -> TrackingCookie.Advertising : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@doubleclick[1].txt -> TrackingCookie.Doubleclick : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@estat[1].txt -> TrackingCookie.Estat : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@fastclick[1].txt -> TrackingCookie.Fastclick : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@media.fastclick[1].txt -> TrackingCookie.Fastclick : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@overture[1].txt -> TrackingCookie.Overture : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@weborama[1].txt -> TrackingCookie.Weborama : Nettoyé.
                  C:\Documents and Settings\Gérard\Cookies\gérard@m.webtrends[1].txt -> TrackingCookie.Webtrends : Nettoyé.

                  Fin du rapport

                  0
                  1. re,

                    tes points de restaurations sont infectés !
                    Fais ceci:
                    tapes ceci dans Démarrer/Exécuter:
                    %SystemRoot%\System32\restore\rstrui.exe
                    Paramètres de restauration/Désactivé la restauration sur tous les lecteurs.
                    ¤Désactive ta restauration système:
                    Clic droit sur poste de travail puis,
                    propriété, tu clique sur onglet restauration système
                    tu coche la case désactiver la restauration et applique

                    Reboot.
                    Ensuite refais l'inverse, réactive.

                    @+
                    0
                    1. ça y est, j'ai fait ce que tu m'a demandé. J'ai d'abord desactivé, puis redémarré l'ordi et là je viens de le reactivé.
                      0
                      1. Saut, voila le rapport de ad-aware :

                        Ad-Aware SE Build 1.06r1
                        Logfile Created on:samedi 9 juin 2007 14:03:26
                        Created with Ad-Aware SE Personal, free for private use.
                        Using definitions file:SE1R174 04.06.2007
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                        References detected during the scan:
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                        MRU List(TAC index:0):8 total references
                        Tracking Cookie(TAC index:3):11 total references
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                        Ad-Aware SE Settings
                        ===========================
                        Set : Search for negligible risk entries
                        Set : Safe mode (always request confirmation)
                        Set : Scan active processes
                        Set : Scan registry
                        Set : Deep-scan registry
                        Set : Scan my IE Favorites for banned URLs
                        Set : Scan my Hosts file

                        Extended Ad-Aware SE Settings
                        ===========================
                        Set : Unload recognized processes & modules during scan
                        Set : Scan registry for all users instead of current user only
                        Set : Always try to unload modules before deletion
                        Set : During removal, unload Explorer and IE if necessary
                        Set : Let Windows remove files in use at next reboot
                        Set : Delete quarantined objects after restoring
                        Set : Include basic Ad-Aware settings in log file
                        Set : Include additional Ad-Aware settings in log file
                        Set : Include reference summary in log file
                        Set : Include alternate data stream details in log file
                        Set : Play sound at scan completion if scan locates critical objects

                        09-06-2007 14:03:26 - Scan started. (Full System Scan)

                        MRU List Object Recognized!
                        Location: : C:\Documents and Settings\Gérard\recent
                        Description : list of recently opened documents

                        MRU List Object Recognized!
                        Location: : software\microsoft\directdraw\mostrecentapplication
                        Description : most recent application to use microsoft directdraw

                        MRU List Object Recognized!
                        Location: : S-1-5-21-2202977061-2466340154-644938488-1009\software\microsoft\internet explorer
                        Description : last download directory used in microsoft internet explorer

                        MRU List Object Recognized!
                        Location: : S-1-5-21-2202977061-2466340154-644938488-1009\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
                        Description : list of recent programs opened

                        MRU List Object Recognized!
                        Location: : S-1-5-21-2202977061-2466340154-644938488-1009\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
                        Description : list of recently saved files, stored according to file extension

                        MRU List Object Recognized!
                        Location: : S-1-5-21-2202977061-2466340154-644938488-1009\software\microsoft\windows\currentversion\explorer\recentdocs
                        Description : list of recent documents opened

                        MRU List Object Recognized!
                        Location: : S-1-5-21-2202977061-2466340154-644938488-1009\software\microsoft\windows\currentversion\explorer\runmru
                        Description : mru list for items opened in start | run

                        MRU List Object Recognized!
                        Location: : S-1-5-21-2202977061-2466340154-644938488-1009\software\winrar\dialogedithistory\extrpath
                        Description : winrar "extract-to" history

                        Listing running processes
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                        #:1 [smss.exe]
                        FilePath : \SystemRoot\System32\
                        ProcessID : 920
                        ThreadCreationTime : 09-06-2007 11:33:03
                        BasePriority : Normal

                        #:2 [csrss.exe]
                        FilePath : \??\C:\WINDOWS\system32\
                        ProcessID : 972
                        ThreadCreationTime : 09-06-2007 11:33:05
                        BasePriority : Normal

                        #:3 [winlogon.exe]
                        FilePath : \??\C:\WINDOWS\system32\
                        ProcessID : 996
                        ThreadCreationTime : 09-06-2007 11:33:07
                        BasePriority : High

                        #:4 [services.exe]
                        FilePath : C:\WINDOWS\system32\
                        ProcessID : 1044
                        ThreadCreationTime : 09-06-2007 11:33:07
                        BasePriority : Normal
                        FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                        ProductVersion : 5.1.2600.2180
                        ProductName : Système d'exploitation Microsoft® Windows®
                        CompanyName : Microsoft Corporation
                        FileDescription : Applications Services et Contrôleur
                        InternalName : services.exe
                        LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                        OriginalFilename : services.exe

                        #:5 [lsass.exe]
                        FilePath : C:\WINDOWS\system32\
                        ProcessID : 1056
                        ThreadCreationTime : 09-06-2007 11:33:07
                        BasePriority : Normal
                        FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                        ProductVersion : 5.1.2600.2180
                        ProductName : Microsoft® Windows® Operating System
                        CompanyName : Microsoft Corporation
                        FileDescription : LSA Shell (Export Version)
                        InternalName : lsass.exe
                        LegalCopyright : © Microsoft Corporation. All rights reserved.
                        OriginalFilename : lsass.exe

                        #:6 [svchost.exe]
                        FilePath : C:\WINDOWS\system32\
                        ProcessID : 1216
                        ThreadCreationTime : 09-06-2007 11:33:08
                        BasePriority : Normal
                        FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                        ProductVersion : 5.1.2600.2180
                        ProductName : Microsoft® Windows® Operating System
                        CompanyName : Microsoft Corporation
                        FileDescription : Generic Host Process for Win32 Services
                        InternalName : svchost.exe
                        LegalCopyright : © Microsoft Corporation. All rights reserved.
                        OriginalFilename : svchost.exe

                        #:7 [svchost.exe]
                        FilePath : C:\WINDOWS\system32\
                        ProcessID : 1288
                        ThreadCreationTime : 09-06-2007 11:33:08
                        BasePriority : Normal
                        FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                        ProductVersion : 5.1.2600.2180
                        ProductName : Microsoft® Windows® Operating System
                        CompanyName : Microsoft Corporation
                        FileDescription : Generic Host Process for Win32 Services
                        InternalName : svchost.exe
                        LegalCopyright : © Microsoft Corporation. All rights reserved.
                        OriginalFilename : svchost.exe

                        #:8 [svchost.exe]
                        FilePath : C:\WINDOWS\System32\
                        ProcessID : 1328
                        ThreadCreationTime : 09-06-2007 11:33:08
                        BasePriority : Normal
                        FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                        ProductVersion : 5.1.2600.2180
                        ProductName : Microsoft® Windows® Operating System
                        CompanyName : Microsoft Corporation
                        FileDescription : Generic Host Process for Win32 Services
                        InternalName : svchost.exe
                        LegalCopyright : © Microsoft Corporation. All rights reserved.
                        OriginalFilename : svchost.exe

                        #:9 [svchost.exe]
                        FilePath : C:\WINDOWS\system32\
                        ProcessID : 1368
                        ThreadCreationTime : 09-06-2007 11:33:08
                        BasePriority : Normal
                        FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                        ProductVersion : 5.1.2600.2180
                        ProductName : Microsoft® Windows® Operating System
                        CompanyName : Microsoft Corporation
                        FileDescription : Generic Host Process for Win32 Services
                        InternalName : svchost.exe
                        LegalCopyright : © Microsoft Corporation. All rights reserved.
                        OriginalFilename : svchost.exe

                        #:10 [svchost.exe]
                        FilePath : C:\WINDOWS\system32\
                        ProcessID : 1416
                        ThreadCreationTime : 09-06-2007 11:33:09
                        BasePriority : Normal
                        FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                        ProductVersion : 5.1.2600.2180
                        ProductName : Microsoft® Windows® Operating System
                        CompanyName : Microsoft Corporation
                        FileDescription : Generic Host Process for Win32 Services
                        InternalName : svchost.exe
                        LegalCopyright : © Microsoft Corporation. All rights reserved.
                        OriginalFilename : svchost.exe

                        #:11 [svchost.exe]
                        FilePath : C:\WINDOWS\system32\
                        ProcessID : 1564
                        ThreadCreationTime : 09-06-2007 11:33:09
                        BasePriority : Normal
                        FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                        ProductVersion : 5.1.2600.2180
                        ProductName : Microsoft® Windows® Operating System
                        CompanyName : Microsoft Corporation
                        FileDescription : Generic Host Process for Win32 Services
                        InternalName : svchost.exe
                        LegalCopyright : © Microsoft Corporation. All rights reserved.
                        OriginalFilename : svchost.exe

                        #:12 [aswupdsv.exe]
                        FilePath : C:\Program Files\Alwil Software\Avast4\
                        ProcessID : 1832
                        ThreadCreationTime : 09-06-2007 11:33:09
                        BasePriority : Normal
                        FileVersion : 4, 7, 997, 0
                        ProductVersion : 4, 7, 0, 0
                        ProductName : avast! Antivirus
                        CompanyName : ALWIL Software
                        FileDescription : avast! Antivirus updating service
                        InternalName : aswUpdSv.exe
                        LegalCopyright : Copyright (c) 2007 ALWIL Software
                        OriginalFilename : aswUpdSv.exe

                        #:13 [ashserv.exe]
                        FilePath : C:\Program Files\Alwil Software\Avast4\
                        ProcessID : 1900
                        ThreadCreationTime : 09-06-2007 11:33:10
                        BasePriority : High
                        FileVersion : 4, 7, 997, 0
                        ProductVersion : 4, 7, 0, 0
                        ProductName : avast! Antivirus
                        CompanyName : ALWIL Software
                        FileDescription : avast! antivirus service
                        InternalName : aswServ
                        LegalCopyright : Copyright (c) 2007 ALWIL Software
                        OriginalFilename : aswServ.exe

                        #:14 [spoolsv.exe]
                        FilePath : C:\WINDOWS\system32\
                        ProcessID : 236
                        ThreadCreationTime : 09-06-2007 11:33:13
                        BasePriority : Normal
                        FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
                        ProductVersion : 5.1.2600.2696
                        ProductName : Microsoft® Windows® Operating System
                        CompanyName : Microsoft Corporation
                        FileDescription : Spooler SubSystem App
                        InternalName : spoolsv.exe
                        LegalCopyright : © Microsoft Corporation. All rights reserved.
                        OriginalFilename : spoolsv.exe

                        #:15 [guard.exe]
                        FilePath : C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\
                        ProcessID : 508
                        ThreadCreationTime : 09-06-2007 11:33:13
                        BasePriority : Normal
                        FileVersion : 7, 5, 0, 47
                        ProductVersion : 7, 5, 0, 47
                        ProductName : AVG Anti-Spyware
                        CompanyName : Anti-Malware Development a.s.
                        FileDescription : AVG Anti-Spyware guard
                        InternalName : AVG Anti-Spyware guard
                        LegalCopyright : Copyright © 2006 Anti-Malware Development a.s.
                        OriginalFilename : guard.exe

                        #:16 [lssrvc.exe]
                        FilePath : C:\Program Files\Fichiers communs\LightScribe\
                        ProcessID : 556
                        ThreadCreationTime : 09-06-2007 11:33:13
                        BasePriority : Normal
                        FileVersion : 1.4.31.1
                        ProductName : LightScribe
                        CompanyName : Hewlett-Packard Company
                        LegalCopyright : © Copyright 2003-2005 Hewlett-Packard Development Company, LP
                        OriginalFilename : LSSrvc.exe

                        #:17 [mdm.exe]
                        FilePath : C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\
                        ProcessID : 648
                        ThreadCreationTime : 09-06-2007 11:33:13
                        BasePriority : Normal
                        FileVersion : 7.00.9466
                        ProductVersion : 7.00.9466
                        ProductName : Microsoft® Visual Studio .NET
                        CompanyName : Microsoft Corporation
                        FileDescription : Machine Debug Manager
                        InternalName : mdm.exe
                        LegalCopyright : © Microsoft Corporation. All rights reserved.
                        OriginalFilename : mdm.exe

                        #:18 [kpf4ss.exe]
                        FilePath : C:\Program Files\Sunbelt Software\Personal Firewall\
                        ProcessID : 840
                        ThreadCreationTime : 09-06-2007 11:33:15
                        BasePriority : Normal
                        FileVersion : 4.5.916.0
                        ProductVersion : 4.5.916.0
                        ProductName : Sunbelt Personal Firewall
                        CompanyName : Sunbelt Software
                        FileDescription : Sunbelt Firewall Service
                        InternalName : kpf4ss.exe
                        LegalCopyright : Copyright © 2002-2007 Sunbelt Software. All rights reserved.
                        LegalTrademarks : SUNBELT SOFTWARE and the "S" logo are registered trademarks of Sunbelt Software. Sunbelt Personal Firewall and SPF are trademarks of Sunbelt Software.
                        OriginalFilename : kpf4ss.exe

                        #:19 [svchost.exe]
                        FilePath : C:\WINDOWS\system32\
                        ProcessID : 1656
                        ThreadCreationTime : 09-06-2007 11:33:16
                        BasePriority : Normal
                        FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                        ProductVersion : 5.1.2600.2180
                        ProductName : Microsoft® Windows® Operating System
                        CompanyName : Microsoft Corporation
                        FileDescription : Generic Host Process for Win32 Services
                        InternalName : svchost.exe
                        LegalCopyright : © Microsoft Corporation. All rights reserved.
                        OriginalFilename : svchost.exe

                        #:20 [kpf4gui.exe]
                        FilePath : C:\Program Files\Sunbelt Software\Personal Firewall\
                        ProcessID : 576
                        ThreadCreationTime : 09-06-2007 11:33:17
                        BasePriority : Normal
                        FileVersion : 4.5.916.0
                        ProductVersion : 4.5.916.0
                        ProductName : Sunbelt Personal Firewall
                        CompanyName : Sunbelt Software
                        FileDescription : Sunbelt Firewall GUI
                        InternalName : kpf4gui.exe
                        LegalCopyright : Copyright © 2002-2007 Sunbelt Software. All rights reserved.
                        LegalTrademarks : SUNBELT SOFTWARE and the "S" logo are registered trademarks of Sunbelt Software. Sunbelt Personal Firewall and SPF are trademarks of Sunbelt Software.
                        OriginalFilename : kpf4gui.exe

                        #:21 [explorer.exe]
                        FilePath : C:\WINDOWS\
                        ProcessID : 976
                        ThreadCreationTime : 09-06-2007 11:33:18
                        BasePriority : Normal
                        FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
                        ProductVersion : 6.00.2900.2180
                        ProductName : Système d'exploitation Microsoft® Windows®
                        CompanyName : Microsoft Corporation
                        FileDescription : Explorateur Windows
                        InternalName : explorer
                        LegalCopyright : © Microsoft Corporation. Tous droits réservés.
                        OriginalFilename : EXPLORER.EXE

                        #:22 [ashmaisv.exe]
                        FilePath : C:\Program Files\Alwil Software\Avast4\
                        ProcessID : 828
                        ThreadCreationTime : 09-06-2007 11:33:19
                        BasePriority : Normal

                        #:23 [ashwebsv.exe]
                        FilePath : C:\Program Files\Alwil Software\Avast4\
                        ProcessID : 1532
                        ThreadCreationTime : 09-06-2007 11:33:20
                        BasePriority : Normal

                        #:24 [alg.exe]
                        FilePath : C:\WINDOWS\System32\
                        ProcessID : 2356
                        ThreadCreationTime : 09-06-2007 11:33:21
                        BasePriority : Normal
                        FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                        ProductVersion : 5.1.2600.2180
                        ProductName : Microsoft® Windows® Operating System
                        CompanyName : Microsoft Corporation
                        FileDescription : Application Layer Gateway Service
                        InternalName : ALG.exe
                        LegalCopyright : © Microsoft Corporation. All rights reserved.
                        OriginalFilename : ALG.exe

                        #:25 [ashdisp.exe]
                        FilePath : C:\PROGRA~1\ALWILS~1\Avast4\
                        ProcessID : 2404
                        ThreadCreationTime : 09-06-2007 11:33:21
                        BasePriority : Normal
                        FileVersion : 4, 7, 997, 0
                        ProductVersion : 4, 7, 0, 0
                        ProductName : avast! Antivirus
                        CompanyName : ALWIL Software
                        FileDescription : avast! service GUI component
                        InternalName : aswDisp
                        LegalCopyright : Copyright (c) 2007 ALWIL Software
                        OriginalFilename : aswDisp.exe

                        #:26 [hcontrol.exe]
                        FilePath : C:\WINDOWS\ATK0100\
                        ProcessID : 2420
                        ThreadCreationTime : 09-06-2007 11:33:21
                        BasePriority : Normal
                        FileVersion : 1043, 2, 15, 58
                        ProductVersion : 1043, 3, 2, 1
                        ProductName : ATK0100
                        FileDescription : HControl
                        InternalName : HControl
                        LegalCopyright : Copyright (c) 2003
                        OriginalFilename : HControl.exe

                        #:27 [igfxtray.exe]
                        FilePath : C:\WINDOWS\system32\
                        ProcessID : 2444
                        ThreadCreationTime : 09-06-2007 11:33:21
                        BasePriority : Normal
                        FileVersion : 3.0.0.4543
                        ProductVersion : 7.0.0.4543
                        ProductName : Intel(R) Common User Interface
                        CompanyName : Intel Corporation
                        FileDescription : igfxTray Module
                        InternalName : IGFXTRAY
                        LegalCopyright : Copyright 1999-2004, Intel Corporation
                        OriginalFilename : IGFXTRAY.EXE

                        #:28 [hkcmd.exe]
                        FilePath : C:\WINDOWS\system32\
                        ProcessID : 2708
                        ThreadCreationTime : 09-06-2007 11:33:22
                        BasePriority : Normal
                        FileVersion : 3.0.0.4543
                        ProductVersion : 7.0.0.4543
                        ProductName : Intel(R) Common User Interface
                        CompanyName : Intel Corporation
                        FileDescription : hkcmd Module
                        InternalName : HKCMD
                        LegalCopyright : Copyright 1999-2004, Intel Corporation
                        OriginalFilename : HKCMD.EXE

                        #:29 [igfxpers.exe]
                        FilePath : C:\WINDOWS\system32\
                        ProcessID : 2832
                        ThreadCreationTime : 09-06-2007 11:33:22
                        BasePriority : Normal
                        FileVersion : 3.0.0.4543
                        ProductVersion : 7.0.0.4543
                        ProductName : Intel(R) Common User Interface
                        CompanyName : Intel Corporation
                        FileDescription : persistence Module
                        InternalName : PERSISTENCE
                        LegalCopyright : Copyright 1999-2004, Intel Corporation
                        OriginalFilename : IGFXPERS.EXE

                        #:30 [rthdcpl.exe]
                        FilePath : C:\WINDOWS\
                        ProcessID : 2852
                        ThreadCreationTime : 09-06-2007 11:33:22
                        BasePriority : Normal
                        FileVersion : 2.0.4.9
                        ProductVersion : 2.0.4.9
                        ProductName : Realtek HD Audio Sound Effect Manager
                        CompanyName : Realtek Semiconductor Corp.
                        FileDescription : Realtek HD Audio Control Panel
                        LegalCopyright : Copyright (c) 2004 Realtek Semiconductor Corp.
                        OriginalFilename : RTHDCPL.EXE

                        #:31 [syntpenh.exe]
                        FilePath : C:\Program Files\Synaptics\SynTP\
                        ProcessID : 2932
                        ThreadCreationTime : 09-06-2007 11:33:22
                        BasePriority : Normal
                        FileVersion : 8.2.0 21Oct05
                        ProductVersion : 8.2.0 21Oct05
                        ProductName : Synaptics Pointing Device Driver
                        CompanyName : Synaptics, Inc.
                        FileDescription : Synaptics TouchPad Enhancements
                        InternalName : Synaptics Enhancements Application
                        LegalCopyright : Copyright (C) Synaptics, Inc. 1996-2005
                        OriginalFilename : SynTPEnh.exe

                        #:32 [pdvdserv.exe]
                        FilePath : C:\Program Files\ASUSTeK\ASUSDVD\
                        ProcessID : 2988
                        ThreadCreationTime : 09-06-2007 11:33:23
                        BasePriority : Normal
                        FileVersion : 6.00.1027
                        ProductVersion : 6.00.1027
                        ProductName : PowerDVD
                        CompanyName : Cyberlink Corp.
                        FileDescription : PowerDVD RC Service
                        InternalName : PowerDVD RC Service
                        LegalCopyright : Copyright (c) CyberLink Corp. 1997-2004
                        OriginalFilename : PDVDSERV.EXE

                        #:33 [jusched.exe]
                        FilePath : C:\Program Files\Java\jre1.6.0_01\bin\
                        ProcessID : 3076
                        ThreadCreationTime : 09-06-2007 11:33:23
                        BasePriority : Normal

                        #:34 [qttask.exe]
                        FilePath : C:\Program Files\QuickTime\
                        ProcessID : 3096
                        ThreadCreationTime : 09-06-2007 11:33:23
                        BasePriority : Normal
                        FileVersion : 7.1.6
                        ProductVersion : QuickTime 7.1.6
                        ProductName : QuickTime
                        CompanyName : Apple Inc.
                        FileDescription : QuickTime Task
                        InternalName : QuickTime Task
                        LegalCopyright : Copyright Apple Inc. 1989-2007
                        OriginalFilename : QTTask.exe

                        #:35 [ctfmon.exe]
                        FilePath : C:\WINDOWS\system32\
                        ProcessID : 3116
                        ThreadCreationTime : 09-06-2007 11:33:23
                        BasePriority : Normal
                        FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
                        ProductVersion : 5.1.2600.2180
                        ProductName : Microsoft® Windows® Operating System
                        CompanyName : Microsoft Corporation
                        FileDescription : CTF Loader
                        InternalName : CTFMON
                        LegalCopyright : © Microsoft Corporation. All rights reserved.
                        OriginalFilename : CTFMON.EXE

                        #:36 [kpf4gui.exe]
                        FilePath : C:\Program Files\Sunbelt Software\Personal Firewall\
                        ProcessID : 3280
                        ThreadCreationTime : 09-06-2007 11:33:25
                        BasePriority : Normal
                        FileVersion : 4.5.916.0
                        ProductVersion : 4.5.916.0
                        ProductName : Sunbelt Personal Firewall
                        CompanyName : Sunbelt Software
                        FileDescription : Sunbelt Firewall GUI
                        InternalName : kpf4gui.exe
                        LegalCopyright : Copyright © 2002-2007 Sunbelt Software. All rights reserved.
                        LegalTrademarks : SUNBELT SOFTWARE and the "S" logo are registered trademarks of Sunbelt Software. Sunbelt Personal Firewall and SPF are trademarks of Sunbelt Software.
                        OriginalFilename : kpf4gui.exe

                        #:37 [atkosd.exe]
                        FilePath : C:\WINDOWS\ATK0100\
                        ProcessID : 3580
                        ThreadCreationTime : 09-06-2007 11:33:28
                        BasePriority : Normal
                        FileVersion : 1043, 2, 15, 57
                        ProductVersion : 1043, 3, 2, 1
                        ProductName : ATK0100
                        FileDescription : ATKOSD
                        InternalName : ATKOSD
                        LegalCopyright : Copyright (c) 2003
                        OriginalFilename : ATKOSD.exe

                        #:38 [iexplore.exe]
                        FilePath : C:\Program Files\Internet Explorer\
                        ProcessID : 1720
                        ThreadCreationTime : 09-06-2007 11:35:21
                        BasePriority : Normal
                        FileVersion : 7.00.5730.11 (winmain(wmbla).061017-1135)
                        ProductVersion : 7.00.5730.11
                        ProductName : Windows® Internet Explorer
                        CompanyName : Microsoft Corporation
                        FileDescription : Internet Explorer
                        InternalName : iexplore
                        LegalCopyright : © Microsoft Corporation. All rights reserved.
                        OriginalFilename : IEXPLORE.EXE

                        #:39 [ad-aware.exe]
                        FilePath : C:\Program Files\Lavasoft\Ad-Aware SE Personal\
                        ProcessID : 844
                        ThreadCreationTime : 09-06-2007 12:03:06
                        BasePriority : Normal
                        FileVersion : 6.2.0.236
                        ProductVersion : SE 106
                        ProductName : Lavasoft Ad-Aware SE
                        CompanyName : Lavasoft Sweden
                        FileDescription : Ad-Aware SE Core application
                        InternalName : Ad-Aware.exe
                        LegalCopyright : Copyright © Lavasoft AB Sweden
                        OriginalFilename : Ad-Aware.exe
                        Comments : All Rights Reserved

                        Memory scan result:
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                        New critical objects: 0
                        Objects found so far: 8

                        Started registry scan
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                        Registry Scan result:
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                        New critical objects: 0
                        Objects found so far: 8

                        Started deep registry scan
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                        Deep registry scan result:
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                        New critical objects: 0
                        Objects found so far: 8

                        Started Tracking Cookie scan
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                        Tracking Cookie Object Recognized!
                        Type : IECache Entry
                        Data : gérard@atdmt[2].txt
                        TAC Rating : 3
                        Category : Data Miner
                        Comment : Hits:2
                        Value : Cookie:gérard@atdmt.com/
                        Expires : 07-06-2012 02:00:00
                        LastSync : Hits:2
                        UseCount : 0
                        Hits : 2

                        Tracking Cookie Object Recognized!
                        Type : IECache Entry
                        Data : gérard@stats1.reliablestats[2].txt
                        TAC Rating : 3
                        Category : Data Miner
                        Comment : Hits:24
                        Value : Cookie:gérard@stats1.reliablestats.com/
                        Expires : 16-09-2007 23:43:28
                        LastSync : Hits:24
                        UseCount : 0
                        Hits : 24

                        Tracking Cookie Object Recognized!
                        Type : IECache Entry
                        Data : gérard@bluestreak[1].txt
                        TAC Rating : 3
                        Category : Data Miner
                        Comment : Hits:20
                        Value : Cookie:gérard@bluestreak.com/
                        Expires : 06-06-2017 07:14:36
                        LastSync : Hits:20
                        UseCount : 0
                        Hits : 20

                        Tracking Cookie Object Recognized!
                        Type : IECache Entry
                        Data : gérard@advertising[1].txt
                        TAC Rating : 3
                        Category : Data Miner
                        Comment : Hits:10
                        Value : Cookie:gérard@advertising.com/
                        Expires : 07-06-2012 11:28:30
                        LastSync : Hits:10
                        UseCount : 0
                        Hits : 10

                        Tracking Cookie Object Recognized!
                        Type : IECache Entry
                        Data : gérard@media.fastclick[1].txt
                        TAC Rating : 3
                        Category : Data Miner
                        Comment : Hits:1
                        Value : Cookie:gérard@media.fastclick.net/
                        Expires : 09-06-2007 12:37:32
                        LastSync : Hits:1
                        UseCount : 0
                        Hits : 1

                        Tracking Cookie Object Recognized!
                        Type : IECache Entry
                        Data : gérard@msnportal.112.2o7[1].txt
                        TAC Rating : 3
                        Category : Data Miner
                        Comment : Hits:1
                        Value : Cookie:gérard@msnportal.112.2o7.net/
                        Expires : 07-06-2012 11:02:08
                        LastSync : Hits:1
                        UseCount : 0
                        Hits : 1

                        Tracking Cookie Object Recognized!
                        Type : IECache Entry
                        Data : gérard@tradedoubler[1].txt
                        TAC Rating : 3
                        Category : Data Miner
                        Comment : Hits:12
                        Value : Cookie:gérard@tradedoubler.com/
                        Expires : 04-06-2027 11:00:28
                        LastSync : Hits:12
                        UseCount : 0
                        Hits : 12

                        Tracking Cookie Object Recognized!
                        Type : IECache Entry
                        Data : gérard@estat[1].txt
                        TAC Rating : 3
                        Category : Data Miner
                        Comment : Hits:1
                        Value : Cookie:gérard@estat.com/
                        Expires : 06-06-2017 11:20:28
                        LastSync : Hits:1
                        UseCount : 0
                        Hits : 1

                        Tracking Cookie Object Recognized!
                        Type : IECache Entry
                        Data : gérard@overture[1].txt
                        TAC Rating : 3
                        Category : Data Miner
                        Comment : Hits:1
                        Value : Cookie:gérard@overture.com/
                        Expires : 06-06-2017 11:24:16
                        LastSync : Hits:1
                        UseCount : 0
                        Hits : 1

                        Tracking Cookie Object Recognized!
                        Type : IECache Entry
                        Data : gérard@fastclick[1].txt
                        TAC Rating : 3
                        Category : Data Miner
                        Comment : Hits:5
                        Value : Cookie:gérard@fastclick.net/
                        Expires : 08-06-2009 11:31:22
                        LastSync : Hits:5
                        UseCount : 0
                        Hits : 5

                        Tracking Cookie Object Recognized!
                        Type : IECache Entry
                        Data : gérard@indexstats[2].txt
                        TAC Rating : 3
                        Category : Data Miner
                        Comment : Hits:2
                        Value : Cookie:gérard@indexstats.com/
                        Expires : 08-06-2008 10:41:04
                        LastSync : Hits:2
                        UseCount : 0
                        Hits : 2

                        Tracking cookie scan result:
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                        New critical objects: 11
                        Objects found so far: 19

                        Deep scanning and examining files (C:)
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                        Disk Scan Result for C:\
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                        New critical objects: 0
                        Objects found so far: 19

                        Scanning Hosts file......
                        Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                        Hosts file scan result:
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                        1 entries scanned.
                        New critical objects:0
                        Objects found so far: 19

                        Performing conditional scans...
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

                        Conditional scan result:
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                        New critical objects: 0
                        Objects found so far: 19

                        14:08:57 Scan Complete

                        Summary Of This Scan
                        »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
                        Total scanning time:00:05:31.63
                        Objects scanned:132025
                        Objects identified:11
                        Objects ignored:0
                        New critical objects:11
                        0
                        1. Meri beaucoup, les pubs ne s'affichent plus. c'est vraiment gentil de ta part.
                          Merci encore
                          0