Virus persistant

Bonjour,
mon pc est infecté par le virus win32: Ranky-FZ [trj], à chaque démarrage.
Je détruis les fichiers infectés avec avast 4.7 mais un nouveau fichier est infecté au démarage suivant.
Si j'ai bien compris, il fallait télécharger HijackThis et vous envoyer une copie du scan afin de savoir les fichiers à fixer.

Merci pour votre éventuelle aide.

Logfile of HijackThis v1.99.1
Scan saved at 11:40:39, on 28/02/2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
C:\windows\iexplore\iexplore.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\WINDOWS\msnmessangern.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\dllcache\qxchost.exe
C:\Program Files\CyberLink\Shared files\RichVideo.exe
C:\WINDOWS\System32\dllcache\seagatecom.exe
C:\WINDOWS\crsss.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Propriétaire\Local Settings\Temp\Répertoire temporaire 1 pour hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fhelp%2fHelp4%2f%3f
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\RunServices: [Win32] eim.exe
O4 - HKLM\..\RunServices: [Windows Service Agent] nzxasg.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?1cb6f3d293fb452a8296fa97834acc47
O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?1cb6f3d293fb452a8296fa97834acc47
O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/280baf8e6ae6831ac915/netzip/RdxIE601_fr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
O16 - DPF: {867E13F2-7F31-44FB-AC97-CD38E0DC46EF} (HardwareDetection Control) - http://charon777.free.fr/plugins/hardwaredetection.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: antivirusdll - Unknown owner - C:\WINDOWS\msnmessangern.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Microsoft Agent - Unknown owner - C:\WINDOWS\System32\dllcache\qxchost.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
O23 - Service: Seagate Communication - Unknown owner - C:\WINDOWS\System32\dllcache\seagatecom.exe
O23 - Service: Windows Service Monitor (winsvcmon) - Unknown owner - C:\WINDOWS\System32\winsvcmon.exe
O23 - Service: ¾2:¡/
wù:GŸ·siÖ (€?
) - Unknown owner - C:\WINDOWS\crsss.exe
Configuration: Windows XP
Internet Explorer 6.0

27 réponses

Résumé de la discussion

Une infection persiste sur le PC avec le virus Win32 Ranky-FZ [trj], répliquant au démarrage et contournant des nettoyages avec Avast, nécessitant l’identification des fichiers malveillants. Plusieurs solutions ont été évoquées, notamment HijackThis et BlackLight pour détecter les composants indésirables et établir un rapport à analyser avant toute suppression. Des rapports d’analyse variés montrent des éléments à nettoyer, des démarrages exotiques et des services ou extensions à désactiver, avec des suites comme AVG Anti-Spyware et NAVIPromo. En cas de doute, l’échange de rapports et la prudence lors de la suppression s’avèrent prépondérants, car certains fichiers repérés peuvent être légitimes et nécessitent une analyse approfondie.

Bobot (l’IA à votre service)
  1. Contributeur sécurité
    bonjour NoiX

    tu dois te créer un nouveau sujet pour que l'on puisse t'aider correctement stp.

    moi je pense que
    C:\WINDOWS\System32\nvsvc32.exe
    est la source mais jen sais rien du tout help me ^^


    non c'est légitime.
    1. voila moi aussi jai le meme probleme, je narive pas a tué ce eim!
      il a surment des sous fichier infecté, c lhorreur
      voila le rapport hijackthis plz help me ^^
      Logfile of HijackThis v1.99.1
      Scan saved at 12:32:32, on 19/03/2007
      Platform: Windows XP (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 (6.00.2600.0000)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
      C:\WINDOWS\System32\nvsvc32.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
      C:\WINDOWS\System32\ctfmon.exe
      C:\Program Files\SEC\MagicTune3.5_Client\GammaTray.exe
      C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Documents and Settings\oli\Bureau\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.fr/?gws_rd=ssl
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      O2 - BHO: (no name) - {2812E582-939A-43FD-BB58-6DA88C16AF63} - C:\WINDOWS\System32\pmnll.dll (file missing)
      O2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dll
      O2 - BHO: (no name) - {D199B08D-ADCA-4326-9515-0C463B906889} - C:\WINDOWS\system32\ssqpmll.dll (file missing)
      O2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dll
      O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
      O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
      O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Fichiers communs\Adobe\Calibration\Adobe Gamma Loader.exe
      O4 - Global Startup: Color Calibration.lnk = ?
      O4 - Global Startup: NaturalColorLoad.lnk = ?
      O8 - Extra context menu item: &Tout télécharger avec FlashGet - C:\Program Files\FlashGet\jc_all.htm
      O8 - Extra context menu item: &Télécharger avec FlashGet - C:\Program Files\FlashGet\jc_link.htm
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: Statistiques d’Anti-Virus Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
      O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
      O20 - Winlogon Notify: klogon - C:\WINDOWS\System32\klogon.dll
      O20 - Winlogon Notify: pmnll - C:\WINDOWS\System32\pmnll.dll (file missing)
      O20 - Winlogon Notify: ssqpmll - ssqpmll.dll (file missing)
      O21 - SSODL: ecgfb - {39d23dba-a362-4803-b26c-5f2cb46e669b} - C:\WINDOWS\System32\kfhrvq.dll (file missing)
      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Unknown owner - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe (file missing)
      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Unknown owner - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe (file missing)
      O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

      fin de raport
      voila
      moi je pense que
      C:\WINDOWS\System32\nvsvc32.exe
      est la source mais jen sais rien du tout help me ^^
      1. Contributeur sécurité
        >re

        relance hijackthis coche et fixe cette ligne :

        O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

        pour apprendre à te protéger voir ces liens :
        securite proteger un ordinateur contre les malwares d internet
        ET
        https://forum.pcastuces.com/default.asp

        1. Contributeur sécurité
          Bonjour,

          il reste encore des choses à virer

          ** Télécharge Pocket KillBox sur ton bureau.
          http://www.downloads.subratam.org/KillBox.exe

          * relance hijackthis puis coche et fixe ces lignes :

          O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\__c00425C9.dat",setvm
          O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
          O20 - Winlogon Notify: instcat - instcat.dll (file missing)
          O20 - Winlogon Notify: __c006DF90 - C:\WINDOWS\System32\__c006DF90.dat (file missing)

          puis

          * Double-clique sur le fichier Killbox.exe, et coche la case "Delete on reboot".
          * copie d'un trait les lignes de la citation suivante :

          C:\WINDOWS\system32\__c00425C9.dat
          C:\WINDOWS\system32\koos.exe 
          c:\WINDOWS\system32\kprof
          c:\WINDOWS\system32\poof 


          Sur PocketKillBox --> menu "File" --> "Paste from Clipboard" (tu ne verras rien se passer).

          Tu peux vérifier dans le menu déroulant que tous les fichiers sont bien présents.
          - coche la case "Unregister dll before deleting" (si tu en as la possibilité)
          - clique sur le bouton "All files"
          - clique ensuite sur la croix rouge

          Au deux messages qui vont s'afficher, tu réponds par "YES"
          L'ordinateur doit redémarrer, sinon, fais le toi-même, quoiqu'il arrive

          * lance Ccleaner dès le redémarrage pour un nettoyage complet.

          * reposte un nouveau rapport hijackthis stp

          1. Bonsoir,
            j'ai bien suivi la série de manips que tu me demandais. Voici le rapport.
            Logfile of HijackThis v1.99.1
            Scan saved at 19:03:26, on 18/03/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            C:\Program Files\CyberLink\Shared files\RichVideo.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\WINDOWS\AGRSMMSG.exe
            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\MSN Messenger\MsnMsgr.Exe
            C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Mes téléchargements\hijackthis\HijackThis.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fhelp%2fHelp4%2f%3f
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
            O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?1cb6f3d293fb452a8296fa97834acc47
            O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?1cb6f3d293fb452a8296fa97834acc47
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
            O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
            O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
            O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
            O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

            Peux tu me diriger vers ue page pertinente pour la protection future de mon ordinateur?
            Merci pour tout
        2. Contributeur sécurité
          re
          laisse tomber mon post du dessus.

          * Assure toi d'avoir accès à tous les fichiers

          -démarrer

          -poste de travail ou autre dossier

          -menu outils

          -options de dossier

          -onglet affichage

          puis

          - activer la case : Afficher les fichiers et dossiers cachés

          - désactiver la case : Masquer les extensions des fichiers dont le type est connu

          - désactiver la case : Masquer les fichier protégés du système d'exploitation

          Puis - Appliquer

          * et Supprime le(s) fichier(s) ci dessous si il(s) est (sont) présent(s) :

          C:\WINDOWS\system32\koos.exe
          c:\WINDOWS\system32\poof
          c:\WINDOWS\system32\kprof

          * refait un scan avec AVG poste le rapport ainsi qu'un nouveau rapport hijackthis stp

          Il n'y a jamais de raccourci vers les endroits qui en valent la peine - Beverley Sills
          1. Bonsoir,
            je venais justement de faire un scan AGV ou un fichier "downloader..." a été mis en quarantaine.

            j'ai redémarré l'ordinateur;

            J'ai fait un rapport hijackthis le voici
            Logfile of HijackThis v1.99.1
            Scan saved at 02:15:27, on 17/03/2007
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\WINDOWS\system32\ZoneLabs\vsmon.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\system32\spoolsv.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            C:\Program Files\CyberLink\Shared files\RichVideo.exe
            C:\Program Files\Alwil Software\Avast4\setup\avast.setup
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Mes téléchargements\hijackthis\HijackThis.exe
            C:\Mes téléchargements\hijackthis\HijackThis.exe
            C:\WINDOWS\AGRSMMSG.exe
            C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
            C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
            C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
            C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
            C:\Program Files\QuickTime\qttask.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\WINDOWS\system32\wuauclt.exe
            C:\Program Files\MSN Messenger\MsnMsgr.Exe
            C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fhelp%2fHelp4%2f%3f
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
            O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
            O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
            O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
            O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
            O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
            O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
            O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
            O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
            O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
            O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
            O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
            O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
            O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
            O4 - HKLM\..\Run: [2chkdsk] rundll32.exe "C:\WINDOWS\system32\__c00425C9.dat",setvm
            O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
            O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
            O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?1cb6f3d293fb452a8296fa97834acc47
            O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?1cb6f3d293fb452a8296fa97834acc47
            O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
            O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
            O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
            O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
            O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O20 - Winlogon Notify: instcat - instcat.dll (file missing)
            O20 - Winlogon Notify: __c006DF90 - C:\WINDOWS\System32\__c006DF90.dat (file missing)
            O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
            O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
            O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
            O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
            O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
            O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
            O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

            Ensuite j'ai lancé blbeta dont voici le rapport
            03/17/07 02:19:20 [Info]: BlackLight Engine 1.0.55 initialized
            03/17/07 02:19:20 [Info]: OS: 5.1 build 2600 (Service Pack 2)
            03/17/07 02:19:25 [Note]: 7019 4
            03/17/07 02:19:25 [Note]: 7005 0
            03/17/07 02:19:40 [Note]: 7006 0
            03/17/07 02:19:40 [Note]: 7011 1292
            03/17/07 02:19:41 [Note]: 7026 0
            03/17/07 02:19:41 [Note]: 7026 0
            03/17/07 02:19:41 [Note]: 7024 3
            03/17/07 02:19:41 [Info]: Hidden process: C:\WINDOWS\system32\koos.exe
            03/17/07 02:20:21 [Note]: FSRAW library version 1.7.1021
            03/17/07 02:29:14 [Info]: Hidden file: C:\WINDOWS\system32\koos.exe
            03/17/07 02:29:14 [Note]: 7002 0
            03/17/07 02:29:14 [Note]: 7003 1
            03/17/07 02:29:14 [Note]: 10002 1
            03/17/07 02:29:14 [Info]: Hidden file: c:\WINDOWS\system32\kprof
            03/17/07 02:29:14 [Note]: 7002 0
            03/17/07 02:29:14 [Note]: 7003 1
            03/17/07 02:29:14 [Note]: 10002 1
            03/17/07 02:29:21 [Info]: Hidden file: c:\WINDOWS\system32\poof
            03/17/07 02:29:21 [Note]: 7002 0
            03/17/07 02:29:21 [Note]: 7003 1
            03/17/07 02:29:21 [Note]: 10002 1
            03/17/07 02:32:17 [Note]: 7007 0

            Enfin j'ai fait les dernières manips dans le poste de travail mais les cases que tu me demandais d'activer ou désactiver étaient déjà dans l'état que tu souhaitais.

            j'ai recherché une dernière les 3 fichiers mais il n'existent plus.
            La fenêtre drivecleaner 2006 n'est pas apparue: "je croise les doigts".
            Cela ne suffira sûrement pas;
            suis je débarassé? que faut-il faire pour la suite, afin d'être plus tranquille avec ces virus en tous genres?
            Merci pour ta persévérance.
        3. Contributeur sécurité
          Bonsoir,

          le rapport de winsoftware.bfu je n'en ai pas besoin, par contre tu m'as reposté le même rapport que le précédent concernant navipromo.

          Je t'avais demandé de refaire la manip et de poster les nouveaux rapports. As tu refait cette manip ? si oui regarde les rapports, ce sont les derniers dont j'ai besoin stp
          1. Cessez vos conneries personnes ni comprend rien et on s'en fout !!!

            Utilisez Avast! :

            https://www.avast.com/fr-fr/free-antivirus-download

            A Bientôt
            1. Contributeur sécurité
              BOnsoir cher monsieur

              Cessez vos conneries personnes ni comprend rien et on s'en fout !!!


              je ne pense pas t'avoir invité à me parler de cette manière. Si tu veux utiliser avast c'est ton problème, je n'ai rien contre, mais c'est pas avast qui va dépatouiller le problème de ce topic.
              Merci

            2. @philae83Bonjour,
              j'ai essayé plusieurs fois la série de manips que tu m'as conseillée.
              Malheureusement drivecleaner 2006 est toujours là.
              A noter: lorsqu'on affiche le log après traitement par winsofware. bfu, on constate qu'aucun des fichiers à enlever en particulier celui de dricvecleaner n'est effacé puisqu'ils ne sont pas trouvés.
              voici le rapport de navipromo
              Rapport Navipromo.bat 0.71 effectué le 14/03/2007 à 13:48:26,87
              L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

              ** Recherche...

              Fin du rapport de recherche
              Adware Navipromo non trouvé avec cette méthode

              Engagement de la méthode Heuristique

              Rapport Navipromo.bat 0.72 effectué le 14/03/2007 à 13:48:27,10
              L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

              ## Suppression Heuristique

              * Backups :

              Aucun résultat par la recherche heuristique

              ## Fin du rapport Heuristique

              -------------

              Rapport Navipromo.bat 0.72 effectué le 14/03/2007 à 13:59:23,13
              L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

              ## Suppression Heuristique

              * Backups :

              Aucun résultat par la recherche heuristique

              ## Fin du rapport Heuristique

              -------------

              Rapport Navipromo.bat 0.71 effectué le 14/03/2007 à 14:57:27,16
              L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

              ** Recherche...

              Fin du rapport de recherche
              Adware Navipromo non trouvé avec cette méthode

              Engagement de la méthode Heuristique

              Rapport Navipromo.bat 0.72 effectué le 14/03/2007 à 14:57:27,36
              L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

              ## Suppression Heuristique

              * Backups :

              Aucun résultat par la recherche heuristique

              ## Fin du rapport Heuristique

              -------------

              Rapport Navipromo.bat 0.72 effectué le 14/03/2007 à 15:00:06,02
              L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

              ## Suppression Heuristique

              * Backups :

              Aucun résultat par la recherche heuristique

              ## Fin du rapport Heuristique

              -------------

              Rapport Navipromo.bat 0.71 effectué le 15/03/2007 à 7:16:21,17
              -- Le programme n'est pas lancé en mode sans échec par conséquent les résultats seront probablement faussés

              ** Recherche...

              Fin du rapport de recherche
              Adware Navipromo non trouvé avec cette méthode

              Engagement de la méthode Heuristique

              Rapport Navipromo.bat 0.72 effectué le 15/03/2007 à 7:16:21,50
              Le programme n'est pas lancé en mode sans échec par conséquent les résultats seront probablement faussés

              ## Suppression Heuristique

              * Backups :

              Aucun résultat par la recherche heuristique

              ## Fin du rapport Heuristique

              -------------

              Rapport Navipromo.bat 0.71 effectué le 16/03/2007 à 1:44:39,45
              L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

              ** Recherche...

              Fin du rapport de recherche
              Adware Navipromo non trouvé avec cette méthode

              Engagement de la méthode Heuristique

              Rapport Navipromo.bat 0.72 effectué le 16/03/2007 à 1:44:39,89
              L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

              ## Suppression Heuristique

              * Backups :

              Aucun résultat par la recherche heuristique

              ## Fin du rapport Heuristique

              -------------

              Rapport Navipromo.bat 0.71 effectué le 16/03/2007 à 1:45:53,11
              L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

              ** Recherche...

              Fin du rapport de recherche
              Adware Navipromo non trouvé avec cette méthode

              Engagement de la méthode Heuristique

              Rapport Navipromo.bat 0.72 effectué le 16/03/2007 à 1:45:53,15
              L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

              ## Suppression Heuristique

              * Backups :

              Aucun résultat par la recherche heuristique

              ## Fin du rapport Heuristique

              -------------

              Rapport Navipromo.bat 0.72 effectué le 16/03/2007 à 1:47:08,94
              L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

              ## Suppression Heuristique

              * Backups :

              Aucun résultat par la recherche heuristique

              ## Fin du rapport Heuristique

              -------------

              Rapport Navipromo.bat 0.72 effectué le 16/03/2007 à 1:48:25,20
              L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

              ## Suppression Heuristique

              * Backups :

              Aucun résultat par la recherche heuristique

              ## Fin du rapport Heuristique

              et voici le rapport de winsoftware.bfu
              # Winsoftware.bfu
              # lazzzy 20/09/2006
              # Ce script cible ErrorSafe / Winfixer / ErrorGuard / DriveCleaner / SystemDoctor / WinAntiVirusPro / WinAntiSpyware / SysProtect

              OptionUnloadShell

              # 1 - Processus

              ProcessKill \AdwareProtector.exe|1
              ProcessKill \ErrorGuard.exe|1
              ProcessKill \ERScw.exe|1
              ProcessKill %PROGRAMFILES%\WinAntiVirus Pro 2006\fat.exe|1
              ProcessKill \sd2006.exe|1
              ProcessKill \SDR6cw.exe|1
              ProcessKill \SDRmon.exe|1
              ProcessKill %PROGRAMFILES%\SystemDoctor 2006 Free\startmon.exe|1
              ProcessKill %WINDIR%\Downloaded Program Files\U*_*_*NetInstaller.exe|1
              ProcessKill %PROGRAMFILES%\systemdoctor 2006 free\updater.exe|1
              ProcessKill %PROGRAMFILES%\DriveCleaner 2006 Free\UDC2006.exe|1
              ProcessKill %PROGRAMFILES%\DriveCleaner 2006 Free\udc6cw.exe|1
              ProcessKill %PROGRAMFILES%\Common Files\DriveCleaner 2006 Free\udcpas.exe|1
              ProcessKill %PROGRAMFILES%\Common Files\DriveCleaner 2006 Free\udcsdr.exe|1
              ProcessKill %PROGRAMFILES%\WinAntiSpyware 2006 Scanner\updater.exe|1
              ProcessKill %PROGRAMFILES%\SystemDoctor 2006 Free\usdr6cw.exe|1
              ProcessKill %PROGRAMFILES%\SysProtect Free\USYP.exe|1
              ProcessKill %PROGRAMFILES%\WinAntiVirus Pro 2006\uwa6pcw.exe|1
              ProcessKill uwasffNT.exe|1
              ProcessKill \was6.exe|1
              ProcessKill \WinAV.exe|1
              ProcessKill \WinPG2005.exe|1

              # 2 - Services

              ServiceStop FWSvc
              ServiceDisable FWSvc
              ServiceDelete FWSvc

              # 3 - Registre

              RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|AdwareProtector
              RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Error Safe
              RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|Error Safe Free
              RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V_0001_N57M1212
              RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|SysProtect
              RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|SysProtect Free
              RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|SystemDoctor 2006
              RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2005
              RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2006
              RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer2005
              RegDelValue HKCU\Software\Microsoft\Windows\CurrentVersion\Run|WinPopupGuard 2005

              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|CompanionWizard
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|dc6_check
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DC6cw
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|DriveCleaner 2006 Free
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ErrorGuard
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Error Safe
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ErrorSafe
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ERS_check
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ERScw
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|fat.exe
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|Firewall
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERS_0001_NI57M1124
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSM_0001_N57M0112
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSM_0001_N68M1602
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_LP
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_N68M0602
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_N91M2107
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UERSV_0001_N91S2108
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|ni.usyp
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.USYP_0002_N91M1708
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.USYP_0003_N91M0908
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWA6PV_0001_N91M2107
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWAS6V_0001_N76M1904
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWAS6V_0001_N91M2208
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V_0001_0802
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX5V_0001_N57M1412
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|NI.UWFX6_0001_N68M2301
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|PAS_Check
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6_Check
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6cw
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6V_Check
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SDR6Y_Check
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SysProtect
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SystemDoctor 2006
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|SystemDoctor 2006 Free
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|udc6cw
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|UERScw
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|usdr6cw
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|uwa6pcw
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|uwas6cw
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|wa6pcw
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiSpyware 2006
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiSpyware 2006 Free
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiSpyware 2006 Scanner
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinAntiVirusPro2006
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2005
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer 2006
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\Run|WinFixer2005

              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce|fat.exe
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce|fat_reinstall
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce|WinAntiSpyware 2006 Scanner

              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|%ProgramFiles%\ErrorSafe\esPCheck.dll
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|%ProgramFiles%\common files\winantivirus pro 2006\wapchk.dll
              RegDelValue HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDLLs|%ProgramFiles%\WinAntiSpyware 2006 Scanner\uwasffNT.exe

              RegDeleteKey HKCR\antiviruscom.avofficeprotect
              RegDeleteKey HKCR\antiviruscom.avofficeprotect.1
              RegDeleteKey HKCR\avexplorer.shellextension
              RegDeleteKey HKCR\avexplorer.shellextension.2
              RegDeleteKey HKCR\avexplorer.shellextension\curver
              RegDeleteKey HKCR\checkprod.checkproduct
              RegDeleteKey HKCR\CheckProduct2.CheckProduct
              RegDeleteKey HKCR\CheckProduct2.CheckProduct.1
              RegDeleteKey HKCR\ComCleanCor.AppCleane
              RegDeleteKey HKCR\ComCleanCor.AppCleane.1
              RegDeleteKey HKCR\ComCleanCor.CQuickScan
              RegDeleteKey HKCR\ComCleanCor.CQuickScan.1
              RegDeleteKey HKCR\ComCleanCor.FileCleane
              RegDeleteKey HKCR\ComCleanCor.InetCleane
              RegDeleteKey HKCR\ComCleanCor.InetCleane.1
              RegDeleteKey HKCR\ComCleanCor.RegCleane
              RegDeleteKey HKCR\ComCleanCor.RegCleane.1
              RegDeleteKey HKCR\ComCleanCor.SystemCleane
              RegDeleteKey HKCR\ComCleanCor.SystemCleane.1
              RegDeleteKey HKCR\ComCleanCore.FileClean.1
              RegDeleteKey HKCR\CompCleanCore.AppCleaner
              RegDeleteKey HKCR\CompCleanCore.AppCleaner.1
              RegDeleteKey HKCR\CompCleanCore.CCQuickScan
              RegDeleteKey HKCR\CompCleanCore.CCQuickScan.1
              RegDeleteKey HKCR\CompCleanCore.FileCleaner
              RegDeleteKey HKCR\CompCleanCore.FileCleaner.1
              RegDeleteKey HKCR\CompCleanCore.InetCleaner
              RegDeleteKey HKCR\CompCleanCore.InetCleaner.1
              RegDeleteKey HKCR\CompCleanCore.RegCleaner
              RegDeleteKey HKCR\CompCleanCore.RegCleaner.1
              RegDeleteKey HKCR\CompCleanCore.SystemCleaner
              RegDeleteKey HKCR\CompCleanCore.SystemCleaner.1
              RegDeleteKey HKCR\df_fixer.Fixer
              RegDeleteKey HKCR\df_fixer.Fixer.1
              RegDeleteKey HKCR\df_proxy.DriverManipulate
              RegDeleteKey HKCR\df_proxy.DriverManipulate.1
              RegDeleteKey HKCR\df_fix.Fix
              RegDeleteKey HKCR\df_fix.Fix.1
              RegDeleteKey HKCR\df_prx.DriverManipulat
              RegDeleteKey HKCR\df_prx.DriverManipulat.1
              RegDeleteKey HKCR\escompcleancore.esappcleaner
              RegDeleteKey HKCR\escompcleancore.esappcleaner.1
              RegDeleteKey HKCR\escompcleancore.esccquickscan
              RegDeleteKey HKCR\escompcleancore.esccquickscan.1
              RegDeleteKey HKCR\escompcleancore.esfilecleaner
              RegDeleteKey HKCR\escompcleancore.esfilecleaner.1
              RegDeleteKey HKCR\escompcleancore.esinetcleaner
              RegDeleteKey HKCR\escompcleancore.esinetcleaner.1
              RegDeleteKey HKCR\escompcleancore.esregcleaner
              RegDeleteKey HKCR\escompcleancore.esregcleaner.1
              RegDeleteKey HKCR\escompcleancore.essystemcleaner
              RegDeleteKey HKCR\escompcleancore.essystemcleaner.1
              RegDeleteKey HKCR\esdf_fixer.esfixer
              RegDeleteKey HKCR\esdf_fixer.esfixer.1
              RegDeleteKey HKCR\esdf_proxy.esdrivermanipulate
              RegDeleteKey HKCR\esdf_proxy.esdrivermanipulate.1
              RegDeleteKey HKCR\esffwraper.esffenginwraper
              RegDeleteKey HKCR\esffwraper.esffenginwraper.1
              RegDeleteKey HKCR\esfixcore.esmmfixcore
              RegDeleteKey HKCR\esfixcore.esmmfixcore.1
              RegDeleteKey HKCR\esmmfixctrl.escofixengine
              RegDeleteKey HKCR\esmmfixctrl.escofixengine.1
              RegDeleteKey HKCR\esspchck.esspchck
              RegDeleteKey HKCR\esspchck.esspchck.1
              RegDeleteKey HKCR\esspcheck.esspcheck
              RegDeleteKey HKCR\esspcheck.esspcheck.1
              RegDeleteKey HKCR\FFCom.FlFixer
              RegDeleteKey HKCR\FFWraper.FFEnginWraper
              RegDeleteKey HKCR\FFWrap.FEnginWrape
              RegDeleteKey HKCR\FFWrap.FEnginWrape.1
              RegDeleteKey HKCR\FFWraper.FFEnginWraper.1
              RegDeleteKey HKCR\FFxr_21.FFixr21
              RegDeleteKey HKCR\FixCor.MMFxCor
              RegDeleteKey HKCR\FixCor.MMFxCor.1
              RegDeleteKey HKCR\FixCore.MMFixCore
              RegDeleteKey HKCR\FixCore.MMFixCore.1
              RegDeleteKey HKCR\FlFxr3.FlFixer3
              RegDeleteKey HKCR\flfxr5.flfixer5
              RegDeleteKey HKCR\FlFxr15.FlFixer15
              RegDeleteKey HKCR\FWrape_r.FFEnginWrape_r
              RegDeleteKey HKCR\FWrape_r.FFEnginWrape_r.1
              RegDeleteKey HKCR\FWraper.FFEnginWraper
              RegDeleteKey HKCR\FWraper.FFEnginWraper.1
              RegDeleteKey HKCR\FxCor_e.MMFixCor_e.1
              RegDeleteKey HKCR\FxCor_e.MMFixCor_e
              RegDeleteKey HKCR\FxCore.MMFixCore
              RegDeleteKey HKCR\FxCore.MMFixCore.1
              RegDeleteKey HKCR\iefwbho.iefw
              RegDeleteKey HKCR\iefwbho.iefw.2
              RegDeleteKey HKCR\Install.Install
              RegDeleteKey HKCR\Install.Install.1
              RegDeleteKey HKCR\MMFixCtrl.CoFixEngine
              RegDeleteKey HKCR\MMFixCtrl.CoFixEngine.1
              RegDeleteKey HKCR\MMFx.CoFxEngin
              RegDeleteKey HKCR\MMFx.CoFxEngin.1
              RegDeleteKey HKCR\MMFxCtr_l.CoFixEngin_e
              RegDeleteKey HKCR\MMFxCtr_l.CoFixEngin_e.1
              RegDeleteKey HKCR\systemdoctor.free
              RegDeleteKey HKCR\UWFX6PCheck.UWFX6PCheck.2
              RegDeleteKey HKCR\UWFXCheck.UWFXCheck
              RegDeleteKey HKCR\UWFXCheck.UWFXCheck.1
              RegDeleteKey HKCR\wap6.pcheck
              RegDeleteKey HKCR\wap6.pcheck.1
              RegDeleteKey HKCR\winpgintegrator.ieintegrator
              RegDeleteKey HKCR\winpgintegrator.ieintegrator.1

              RegDeleteKey HKCR\AppID\{25A3C995-10C8-474B-A167-99460AB4AB2B}
              RegDeleteKey HKCR\AppID\{287A2BAD-6590-4EFF-9BBC-494385664A73}
              RegDeleteKey HKCR\AppID\{290B5B73-4963-4BA1-9D2D-07CB566CB7FA}
              RegDeleteKey HKCR\AppID\{367a86a5-d048-4785-86be-4e2706aafdd9}
              RegDeleteKey HKCR\AppID\{3C132D19-6103-4fc3-8326-34E13EE9E2C0}
              RegDeleteKey HKCR\AppID\{4f5e5d72-c915-4f3b-908b-527d064b0faa}
              RegDeleteKey HKCR\AppID\{8C65AEF6-E413-4314-815B-82717A3F1603}
              RegDeleteKey HKCR\AppID\{AAB0BA34-6D48-425f-B4B4-98F158CB61F1}
              RegDeleteKey HKCR\AppID\{DED71DE6-0575-4556-8311-A506B116A1A9}
              RegDeleteKey HKCR\AppID\{E8928E69-C050-42A9-8884-94DE85E888A2}
              RegDeleteKey HKCR\AppID\{E11FF09D-39AF-4613-86AD-F3217E576571}
              RegDeleteKey HKCR\AppID\CheckProduct2.DLL
              RegDeleteKey HKCR\AppID\compcln.dll
              RegDeleteKey HKCR\AppID\compclr.dll
              RegDeleteKey HKCR\AppID\FFWrapr.DLL
              RegDeleteKey HKCR\AppID\FFWraper.DLL
              RegDeleteKey HKCR\AppID\FixCore.DLL
              RegDeleteKey HKCR\AppID\FxCr.DLL
              RegDeleteKey HKCR\AppID\MFix.DLL
              RegDeleteKey HKCR\AppID\MMFixCtrl.DLL
              RegDeleteKey HKCR\AppID\winpgi.dll appid

              RegDeleteKey HKCR\CLSID\{08C71FB1-1E66-4D22-9F32-4C045A451306}
              RegDeleteKey HKCR\CLSID\{0ba379c6-0efd-4a28-932c-d20469052fd9}
              RegDeleteKey HKCR\CLSID\{0bc09fc7-473d-4f9c-b49b-f4e3e244b47a}
              RegDeleteKey HKCR\CLSID\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}
              RegDeleteKey HKCR\CLSID\{151a44b0-fc2d-4a02-bbbc-6b372f2f659c}
              RegDeleteKey HKCR\CLSID\{1640de0e-75e4-4a83-b5d1-2492bc7eba8f}
              RegDeleteKey HKCR\CLSID\{196c80cb-20a7-4cf9-9c98-9322fb1e35fb}
              RegDeleteKey HKCR\CLSID\{1ac5c88a-dea7-462b-a232-04af5ca42e7e}
              RegDeleteKey HKCR\CLSID\{1CDEB41B-905A-4183-AA20-26E075419B46}
              RegDeleteKey HKCR\CLSID\{205FF73B-CA67-11D5-99DD-444553540006}
              RegDeleteKey HKCR\CLSID\{2178f3fb-2560-458f-bdee-631e2fe0dfe4}
              RegDeleteKey HKCR\CLSID\{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}
              RegDeleteKey HKCR\CLSID\{356af2e9-8874-4c60-a3d8-0cb516c9e747}
              RegDeleteKey HKCR\CLSID\{38EDB9E2-D7C4-4575-8905-FE65414FFEAD}
              RegDeleteKey HKCR\CLSID\{48349992-1402-4C67-B45B-2E619E641FDB}
              RegDeleteKey HKCR\CLSID\{5284ac2a-ef00-4750-9b82-b5b907d26536}
              RegDeleteKey HKCR\CLSID\{538BC8F3-2E1E-4D2D-A261-158DF6E9B407}
              RegDeleteKey HKCR\CLSID\{53ABACCB-434C-4756-A02B-8C2A3F29FB7D}
              RegDeleteKey HKCR\CLSID\{5A1C8180-2A52-470c-938C-BFB4E63AA32D}
              RegDeleteKey HKCR\CLSID\{5e19dee2-8d2f-4a9c-a66d-76bbeedd15cb}
              RegDeleteKey HKCR\CLSID\{647b8364-79e0-48e2-a4ca-233abada0c2d}
              RegDeleteKey HKCR\CLSID\{66A9C4D0-BC54-4841-8FAA-DB98CBB77BAD}
              RegDeleteKey HKCR\CLSID\{6F85DDE5-A2DE-4217-A05D-0A7CD3C04DC2}
              RegDeleteKey HKCR\CLSID\{723d54c7-7483-4eb8-8eed-ce5b2aea534d}
              RegDeleteKey HKCR\CLSID\{72D597C4-2312-4116-BED4-4F9A2B2F710E}
              RegDeleteKey HKCR\CLSID\{77ca442a-0c72-492b-804a-82611e558142}
              RegDeleteKey HKCR\CLSID\{7e73c9db-69fb-4580-8e8e-194b34a2306c}
              RegDeleteKey HKCR\CLSID\{7F208C01-1FB1-4BC8-B918-82E287B0BB79}
              RegDeleteKey HKCR\CLSID\{84C43108-013C-4513-8578-F50080B9C9D0}
              RegDeleteKey HKCR\CLSID\{861D5757-3A7E-4c46-966E-8CD53A0D0013}
              RegDeleteKey HKCR\CLSID\{8E3A1531-F462-4628-ADD8-D32984637641}
              RegDeleteKey HKCR\CLSID\{965a8d33-ae18-4c17-8011-fe42d81e0758}
              RegDeleteKey HKCR\CLSID\{9CC1BE04-3B42-4442-9A46-77E8BC1108F9}
              RegDeleteKey HKCR\CLSID\{9e87077c-380c-407d-8dab-eedad95c0a5d}
              RegDeleteKey HKCR\CLSID\{9F3D2A3C-D537-482b-A91B-44EE29F09C4B}
              RegDeleteKey HKCR\CLSID\{A99498D2-56E1-4e27-AC88-2328C6A87C7C}
              RegDeleteKey HKCR\CLSID\{AA69BBFC-1D28-4960-8061-93C1BB156238}
              RegDeleteKey HKCR\CLSID\{ABC72615-4FB0-4689-AED9-AA6B89CEBC2C}
              RegDeleteKey HKCR\CLSID\{B096A483-0ABD-4AF0-856A-CAD36145AF5C}
              RegDeleteKey HKCR\CLSID\{B296F12B-48A9-45fb-A860-4B98707B47AE}
              RegDeleteKey HKCR\CLSID\{b2a3156e-3332-4b47-af5a-5b121503514f}
              RegDeleteKey HKCR\CLSID\{B36E6241-4D02-41FF-A16D-9B57E67D7B15}
              RegDeleteKey HKCR\CLSID\{b5141620-c2b2-4d95-9f0f-134d99c87ab0}
              RegDeleteKey HKCR\CLSID\{B5E427F9-AB38-4348-9076-86870C2BE860}
              RegDeleteKey HKCR\CLSID\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}
              RegDeleteKey HKCR\CLSID\{B8CA1E6C-87E2-4435-9E56-8B791EC459D8}
              RegDeleteKey HKCR\CLSID\{c033567c-68fe-419b-bcc4-135db7faf8eb}
              RegDeleteKey HKCR\CLSID\{C08FA317-C152-4fea-AC0B-2EA68D2B1C84}
              RegDeleteKey HKCR\CLSID\{C0BC364F-AB33-4778-8047-5A2148E0ECDA}
              RegDeleteKey HKCR\CLSID\{C427B3E3-28DC-4001-9590-D99B6776119B}
              RegDeleteKey HKCR\CLSID\{c85a4afd-ff76-4661-b76a-3e9bb2ce2dab}
              RegDeleteKey HKCR\CLSID\{CAE8A9B1-ABBD-4159-A485-1DA045A5D4A1}
              RegDeleteKey HKCR\CLSID\{ccaabcdd-7c16-4215-b12e-150bfb994cf0}
              RegDeleteKey HKCR\CLSID\{D4EA0C00-3BC8-4B26-8D2E-C5512B07A211}
              RegDeleteKey HKCR\CLSID\{e73e3959-fb15-44d7-acb9-3a75377006fc}
              RegDeleteKey HKCR\CLSID\{EAB5DB02-08F5-4e7d-81F9-75B9462FAAE3}
              RegDeleteKey HKCR\CLSID\{ef130e77-0a34-4365-bfb7-218fd3ddcd5f}
              RegDeleteKey HKCR\CLSID\{F0ED6398-E5F8-4ef8-BAB9-FE9BBCE7EF3E}
              RegDeleteKey HKCR\CLSID\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
              RegDeleteKey HKCR\CLSID\{f63e3b76-f82f-46eb-851c-8c0a221686bb}
              RegDeleteKey HKCR\CLSID\{F919FBD3-A96B-4679-AF26-F551439BB5FD}

              RegDeleteKey HKCR\Interface\{08C71FB1-1E66-4D22-9F32-4C045A451306}
              RegDeleteKey HKCR\Interface\{02946fd1-2d99-46e6-a790-3a089714edd9}
              RegDeleteKey HKCR\Interface\{0b9a27eb-125f-4f3e-a35c-2769c47a1442}
              RegDeleteKey HKCR\Interface\{1CE1C25B-F8B4-4974-99D2-5D4AE96B9900}
              RegDeleteKey HKCR\Interface\{35096C29-3507-4ABE-B6D8-C7CC881BE020}
              RegDeleteKey HKCR\Interface\{38F743A2-210F-49DE-9B79-DCD501CED284}
              RegDeleteKey HKCR\Interface\{3EEC290D-FC13-4C83-803D-4802651EEB61}
              RegDeleteKey HKCR\Interface\{41A5BBF6-3C9D-4CF9-9A99-32DD37CC290B}
              RegDeleteKey HKCR\Interface\{4E4F38D9-8736-41AE-B192-E829AE194398}
              RegDeleteKey HKCR\Interface\{4F79D1C5-24F9-4E59-8022-604D4B41D5CA}
              RegDeleteKey HKCR\Interface\{66484903-09F4-4330-927D-1F6C214221AC}
              RegDeleteKey HKCR\Interface\{7FA14AD6-D8E5-465F-9BD1-A37E26C1A74F}
              RegDeleteKey HKCR\Interface\{9E984934-CD94-4763-9DBC-618E483D4B7F}
              RegDeleteKey HKCR\Interface\{B115BD8E-B008-46F4-B8B6-3405EB325C3C}
              RegDeleteKey HKCR\Interface\{B9DFCF32-B679-4CAD-B7FC-518A48CE3922}
              RegDeleteKey HKCR\Interface\{CAE8A9B1-ABBD-4159-A485-1DA045A5D4A1}
              RegDeleteKey HKCR\Interface\{CBEEF194-EBC5-4758-9B51-AC34FC135E70}
              RegDeleteKey HKCR\Interface\{CD3604CC-2B95-43EE-AFC9-E7444C21BE1C}
              RegDeleteKey HKCR\Interface\{D21040FE-0A57-4FAB-8ED2-F0E653E55809}
              RegDeleteKey HKCR\Interface\{D7A2488E-53E4-4EDD-AEAA-F24778BEB100}
              RegDeleteKey HKCR\Interface\{D7A6DF8D-B6CF-4C27-8E99-ECA2CE370EA7}
              RegDeleteKey HKCR\Interface\{e18b69d0-7e9e-4c6e-bdd8-879a1fff7123}
              RegDeleteKey HKCR\Interface\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
              RegDeleteKey HKCR\Interface\{F6C1582E-B11C-4724-B8F6-240457EF1D2A}
              RegDeleteKey HKCR\Interface\{FB787D5E-0C7C-4BAB-B45D-20325FB886DB}
              RegDeleteKey HKCR\Interface\{24F3E817-2C07-4CB5-975D-F23FCFAEDE51}
              RegDeleteKey HKCR\Interface\{3BB63444-FD94-4C31-9D6F-0DA76CB11D70}
              RegDeleteKey HKCR\Interface\{3C2656F4-8601-42B6-BDC3-DEC901E21C80}
              RegDeleteKey HKCR\Interface\{471D3AEF-F18C-4626-A7DB-320732ACC763}
              RegDeleteKey HKCR\Interface\{490E59CC-F6D5-4987-BBC8-E1A6D599C3F8}
              RegDeleteKey HKCR\Interface\{68A7506D-DF03-4DF0-BE96-02BCB918EA7D}
              RegDeleteKey HKCR\Interface\{74ECF6F4-62C5-48BA-945E-B20A97239A5E}
              RegDeleteKey HKCR\Interface\{7A66E632-E262-4986-A936-CC636282F138}
              RegDeleteKey HKCR\Interface\{7D9DFDB3-5135-4279-B365-3CEEA4AC1EAC}
              RegDeleteKey HKCR\Interface\{7F208C01-1FB1-4BC8-B918-82E287B0BB79}
              RegDeleteKey HKCR\Interface\{7f4e63c9-f30c-4424-9baf-b6896f5f56c4}
              RegDeleteKey HKCR\Interface\{81A7D75C-9768-41C3-AE0F-8B108D802B62}
              RegDeleteKey HKCR\Interface\{86786BEC-544D-473F-8D93-8E7AC0685361}
              RegDeleteKey HKCR\Interface\{92B92664-32D6-4FCE-B2CE-C8519BAEFC4E}
              RegDeleteKey HKCR\Interface\{94dbdb63-5f05-4c51-8b14-de0ca12ef4ca}
              RegDeleteKey HKCR\Interface\{B0725565-2694-43EC-B1AB-0245762C9860}
              RegDeleteKey HKCR\Interface\{B26CA1F6-2D46-49AE-9897-9C5B7CCAB9FB}
              RegDeleteKey HKCR\Interface\{B36E6241-4D02-41FF-A16D-9B57E67D7B15}
              RegDeleteKey HKCR\Interface\{CADCB2CC-0B7E-45B1-A689-A0AD9CE5932D}
              RegDeleteKey HKCR\Interface\{D3390AE7-6F1D-464F-8921-AF9A85EED316}
              RegDeleteKey HKCR\Interface\{D4EA0C00-3BC8-4B26-8D2E-C5512B07A211}
              RegDeleteKey HKCR\Interface\{DB064061-95F1-4BAF-BEC9-F70792E01094}
              RegDeleteKey HKCR\Interface\{F3067DE7-3DBA-4DF8-9FA0-6B0200BAA324}
              RegDeleteKey HKCR\Interface\{f5ac8b35-5b15-4e8f-8046-43858973b495}
              RegDeleteKey HKCR\Interface\{FE899520-E9F9-4CD9-AABB-E9074815CF50}

              RegDeleteKey HKCR\TypeLib\{04392304-5221-4022-9300-be4128fb25b2}
              RegDeleteKey HKCR\TypeLib\{0E9F6AC0-A21A-4591-910F-E2C6F3CA094C}
              RegDeleteKey HKCR\TypeLib\{1234890a-5e6e-4867-8136-ca6f1456b235}
              RegDeleteKey HKCR\TypeLib\{1b197c22-561f-455f-8511-35b1a45c5c9f}
              RegDeleteKey HKCR\TypeLib\{17E55F3A-20AB-4668-A75F-DC96377AE16C}
              RegDeleteKey HKCR\TypeLib\(205FF72E-CA67-11D5-99DD-444553540006)
              RegDeleteKey HKCR\TypeLib\{248FDD41-4E0A-4138-9086-6CF5D6FA8179}
              RegDeleteKey HKCR\TypeLib\{25BAE2A9-DF54-4927-AF6F-9963146D11D8}
              RegDeleteKey HKCR\TypeLib\{2bc32ef8-bb73-4099-bb2e-0f2951b3e276}
              RegDeleteKey HKCR\TypeLib\{30ED49A5-CA6C-4918-B5F3-5E6818C91D8B}
              RegDeleteKey HKCR\TypeLib\{367a86a5-d048-4785-86be-4e2706aafdd9}
              RegDeleteKey HKCR\TypeLib\{371EFE75-C183-4D0C-B8CD-2DFAFEEB34D7}
              RegDeleteKey HKCR\TypeLib\{49f9ffb5-514d-4b69-b31d-2ae5a7d30ae6}
              RegDeleteKey HKCR\TypeLib\{4DCEEA42-794D-4855-9ECC-20DCF5F4FEA7}
              RegDeleteKey HKCR\TypeLib\{5F638503-4F2E-48F8-9210-9865AF4AD020}
              RegDeleteKey HKCR\TypeLib\{68bc55e9-4d3e-4c89-89ac-7559763c98b8}
              RegDeleteKey HKCR\TypeLib\{692ca430-32c8-470d-ba1f-7e15e21e7043}
              RegDeleteKey HKCR\TypeLib\{6A077841-5016-42C8-92C8-F2D6B865BCD1}
              RegDeleteKey HKCR\TypeLib\{6bd7e052-306e-497a-ad23-601bc6bfc305}
              RegDeleteKey HKCR\TypeLib\{6F9DB588-66C5-4904-A2C7-423961358E8C}
              RegDeleteKey HKCR\TypeLib\{732b6533-7f78-4c47-9c01-2979ba0829b9}
              RegDeleteKey HKCR\TypeLib\{77dc6558-60e0-4644-a3df-b31f29d113bd}
              RegDeleteKey HKCR\TypeLib\{7eacf70b-302f-4049-ac68-2d62eb43e473}
              RegDeleteKey HKCR\TypeLib\{8D67C4E4-AAD6-46A1-812F-D7D21BBB4624}
              RegDeleteKey HKCR\TypeLib\{9dd86cf2-8ac0-4fe0-b55a-601a302b5fd8}
              RegDeleteKey HKCR\TypeLib\{a73973ab-95a6-4abe-a046-de3bab2be448}
              RegDeleteKey HKCR\TypeLib\{AD70AC89-F460-4E7E-B5A5-7EAF7E207736}
              RegDeleteKey HKCR\TypeLib\{B6625280-8CD8-4632-97C0-83CEC12A49A3}
              RegDeleteKey HKCR\TypeLib\{D49C1A5F-26CF-482E-81EE-1D4C9B057BD2}
              RegDeleteKey HKCR\TypeLib\{F458ADAE-D53B-4859-B99F-9FA127791278}
              RegDeleteKey HKCR\TypeLib\{FC76A5B8-DB35-4F3E-8B9A-BF0EEA098D64}

              RegDeleteKey HKCU\Software\ErrorGuard
              RegDeleteKey HKCU\Software\errorsafe
              RegDeleteKey HKCU\Software\error safe free
              RegDeleteKey HKCU\Software\sysprotect free
              RegDeleteKey HKCU\Software\SystemDoctor 2006 Free
              RegDeleteKey HKCU\Software\WinAntiSpyware 2006 Scanner
              RegDeleteKey HKCU\Software\WinAntiVirus Pro 2006
              RegDeleteKey HKCU\Software\WinFixer 2005
              RegDeleteKey HKCU\Software\WinSoftware

              RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{205ff73b-ca67-11d5-99dd-444553540006}
              RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}

              RegDeleteKey HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu2\Programs\SystemDoctor 2006 Unregistered

              RegDeleteKey HKLM\Software\DriveCleaner 2006 Free
              RegDeleteKey HKLM\Software\ErrorSafe
              RegDeleteKey HKLM\Software\Error Safe Free
              RegDeleteKey HKLM\Software\sysprotect
              RegDeleteKey HKLM\Software\SystemDoctor 2006 Free
              RegDeleteKey HKLM\Software\WinAntiSpyware 2006 Scanner
              RegDeleteKey HKLM\Software\winantivirus pro 2006
              RegDeleteKey HKLM\Software\WinSoftware

              RegDeleteKey HKLM\Software\Classes\checkprod.checkproduct
              RegDeleteKey HKLM\Software\Classes\ComCleanCore.AppCleaner
              RegDeleteKey HKLM\Software\Classes\ComCleanCore.CCQuickScan
              RegDeleteKey HKLM\Software\Classes\ComCleanCore.CCQuickScan.1
              RegDeleteKey HKLM\Software\Classes\ComCleanCore.FileCleaner
              RegDeleteKey HKLM\Software\Classes\ComCleanCore.FileCleaner.1
              RegDeleteKey HKLM\Software\Classes\ComCleanCore.InetCleaner\CLSID
              RegDeleteKey HKLM\Software\Classes\ComCleanCore.InetCleaner.1
              RegDeleteKey HKLM\Software\Classes\ComCleanCore.RegCleaner
              RegDeleteKey HKLM\Software\Classes\ComCleanCore.RegCleaner.1
              RegDeleteKey HKLM\Software\Classes\ComCleanCore.SystemCleaner
              RegDeleteKey HKLM\Software\Classes\ComCleanCore.SystemCleaner.1
              RegDeleteKey HKLM\Software\Classes\df_fixr.Fixer
              RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESAppCleaner
              RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESAppCleaner.1
              RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESCCQuickScan
              RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESCCQuickScan.1
              RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESFileCleaner
              RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESFileCleaner.1
              RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESInetCleaner
              RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESInetCleaner.1
              RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESRegCleaner
              RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESRegCleaner.1
              RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESSystemCleaner
              RegDeleteKey HKLM\Software\Classes\ESCompCleanCore.ESSystemCleaner.1
              RegDeleteKey HKLM\Software\Classes\ESdf_fixer.ESFixer
              RegDeleteKey HKLM\Software\Classes\ESdf_fixer.ESFixer.1
              RegDeleteKey HKLM\Software\Classes\ESdf_proxy.ESDriverManipulate
              RegDeleteKey HKLM\Software\Classes\ESdf_proxy.ESDriverManipulate.1
              RegDeleteKey HKLM\Software\Classes\ESFFWraper.ESFFEnginWraper
              RegDeleteKey HKLM\Software\Classes\ESFFWraper.ESFFEnginWraper.1
              RegDeleteKey HKLM\Software\Classes\ESFixCore.ESMMFixCore
              RegDeleteKey HKLM\Software\Classes\ESFixCore.ESMMFixCore.1
              RegDeleteKey HKLM\Software\Classes\ESMMFixCtrl.ESCoFixEngine
              RegDeleteKey HKLM\Software\Classes\ESMMFixCtrl.ESCoFixEngine.1
              RegDeleteKey HKLM\Software\Classes\ESSPCheck.ESSPCheck
              RegDeleteKey HKLM\Software\Classes\ESSPCheck.ESSPCheck.1
              RegDeleteKey HKLM\Software\Classes\FFWraper.FFEnginWrapr
              RegDeleteKey HKLM\Software\Classes\FixCor.MMFixCore
              RegDeleteKey HKLM\Software\Classes\FlFxr5.FlFixer5
              RegDeleteKey HKLM\Software\Classes\FlFxr10.FlFixer10
              RegDeleteKey HKLM\Software\Classes\MMFixCtrl.CoFixEngin2
              RegDeleteKey HKLM\Software\Classes\SystemDoctor.Free
              RegDeleteKey HKLM\Software\Classes\UDCPChk.UDCPChk
              RegDeleteKey HKLM\Software\Classes\UDCPChk.UDCPChk.1
              RegDeleteKey HKLM\Software\Classes\UDCShell
              RegDeleteKey HKLM\Software\Classes\UWAS6.UWAS6
              RegDeleteKey HKLM\Software\Classes\uwasfsd.CreationNotifier
              RegDeleteKey HKLM\Software\Classes\uwasfsd.CreationNotifier.1
              RegDeleteKey HKLM\Software\Classes\uwashellext.ShellHook
              RegDeleteKey HKLM\Software\Classes\uwashellext.ShellHook.1
              RegDeleteKey HKLM\Software\Classes\uwashellext.WASContextMenu
              RegDeleteKey HKLM\Software\Classes\uwashellext.WASContextMenu.1
              RegDeleteKey HKLM\Software\Classes\wasfsd.CreationNotifier
              RegDeleteKey HKLM\Software\Classes\wasfsd.CreationNotifier.1
              RegDeleteKey HKLM\Software\Classes\washellext.WASContextMenu
              RegDeleteKey HKLM\Software\Classes\washellext.WASContextMenu.1
              RegDeleteKey HKLM\Software\Classes\WASPChk.WASPChk

              RegDeleteKey HKLM\Software\Classes\*\shellex\ContextMenuHandlers\UDCShell

              RegDeleteKey HKLM\Software\Classes\AppID\{1C02CE6B-CC12-4ea1-B2D8-113F611F25C2}
              RegDeleteKey HKLM\Software\Classes\AppID\{4f5e5d72-c915-4f3b-908b-527d064b0faa}
              RegDeleteKey HKLM\Software\Classes\AppID\{8A1E94DA-725D-4f64-B110-DB3F73ADB6F7}
              RegDeleteKey HKLM\Software\Classes\AppID\{E7E155EE-EEF2-46af-99B7-65F1269DC3CF}
              RegDeleteKey HKLM\Software\Classes\AppID\{EE10A303-0C60-4acb-A033-95A790FA4DCD}
              RegDeleteKey HKLM\Software\Classes\AppID\checkproduct2_1.dll

              RegDeleteKey HKLM\Software\Classes\CLSID\{_CLSID_WAShellExecuteCheck}
              RegDeleteKey HKLM\Software\Classes\CLSID\{05324ED1-05C0-4e3a-A34F-98BFC64426F5}
              RegDeleteKey HKLM\Software\Classes\CLSID\{08C71FB1-1E66-4D22-9F32-4C045A451306}
              RegDeleteKey HKLM\Software\Classes\CLSID\{0D7DE254-2FBD-4C09-9077-3DC4A2DEBE9D}
              RegDeleteKey HKLM\Software\Classes\CLSID\{1230649B-B980-44A5-B259-9B09EBEA6331}
              RegDeleteKey HKLM\Software\Classes\CLSID\{1236DE55-EDED-4675-AF10-BA15EDDB4D7A}
              RegDeleteKey HKLM\Software\Classes\CLSID\{184B0A26-4C9C-4757-ABF5-4B6AF71F9A45}
              RegDeleteKey HKLM\Software\Classes\CLSID\{18A41B20-E519-47a1-B545-FFC200730E9B}
              RegDeleteKey HKLM\Software\Classes\CLSID\{1CDEB41B-905A-4183-AA20-26E075419B46}
              RegDeleteKey HKLM\Software\Classes\CLSID\{2178F3FB-2560-458f-BDEE-631E2FE0DFE4}
              RegDeleteKey HKLM\Software\Classes\CLSID\{22024DC7-D190-44ec-9D49-AEE5F244A466}
              RegDeleteKey HKLM\Software\Classes\CLSID\{250D1063-5414-4fb0-86D5-AABB7A5D7DA7}
              RegDeleteKey HKLM\Software\Classes\CLSID\{2B334C22-40CA-438f-913A-61A8105C4CCD}
              RegDeleteKey HKLM\Software\Classes\CLSID\{2BF3C5AD-F9EC-49d8-8568-D7DFFC77108B}
              RegDeleteKey HKLM\Software\Classes\CLSID\{38EDB9E2-D7C4-4575-8905-FE65414FFEAD}
              RegDeleteKey HKLM\Software\Classes\CLSID\{43DB73EB-4C90-4418-B6AD-10DB22016908}
              RegDeleteKey HKLM\Software\Classes\CLSID\{48349992-1402-4C67-B45B-2E619E641FDB}
              RegDeleteKey HKLM\Software\Classes\CLSID\{4AA76F27-81BC-4C3F-9F24-CB99349C8CC9}
              RegDeleteKey HKLM\Software\Classes\CLSID\{4F4E2384-42AD-4fe4-B966-B6D50C7BF90A}
              RegDeleteKey HKLM\Software\Classes\CLSID\{5284AC2A-EF00-4750-9B82-B5B907D26536}
              RegDeleteKey HKLM\Software\Classes\CLSID\{538BC8F3-2E1E-4D2D-A261-158DF6E9B407}
              RegDeleteKey HKLM\Software\Classes\CLSID\{59399E33-FB54-48AB-8AE4-AE108B36DAB4}
              RegDeleteKey HKLM\Software\Classes\CLSID\{5D178DBE-C867-417f-8A4E-D5DEFA4CD4E7}
              RegDeleteKey HKLM\Software\Classes\CLSID\{66A9C4D0-BC54-4841-8FAA-DB98CBB77BAD}
              RegDeleteKey HKLM\Software\Classes\CLSID\{6AE7418B-229F-4A2C-AE1B-D5962888F02D}
              RegDeleteKey HKLM\Software\Classes\CLSID\{6C8416A2-2408-4f4d-8D26-EC9A07E8DC98}
              RegDeleteKey HKLM\Software\Classes\CLSID\{7D435027-F646-4bf9-B2C5-0EF4940D5CA2}
              RegDeleteKey HKLM\Software\Classes\CLSID\{7EC618F2-C506-4221-9F56-792B92BF762E}
              RegDeleteKey HKLM\Software\Classes\CLSID\{84C43108-013C-4513-8578-F50080B9C9D0}
              RegDeleteKey HKLM\Software\Classes\CLSID\{8DAE9202-0019-4D30-A5D2-AAF02D4DDC37}
              RegDeleteKey HKLM\Software\Classes\CLSID\{9C102B96-4845-4756-991E-4F9294965536}
              RegDeleteKey HKLM\Software\Classes\CLSID\{9CB12DAD-32C7-4f34-9758-C9FDD26D4D22}
              RegDeleteKey HKLM\Software\Classes\CLSID\{9CC1BE04-3B42-4442-9A46-77E8BC1108F9}
              RegDeleteKey HKLM\Software\Classes\CLSID\{AA69BBFC-1D28-4960-8061-93C1BB156238}
              RegDeleteKey HKLM\Software\Classes\CLSID\{ABCD4567-76B5-4bc7-AAC5-396D70925B11}
              RegDeleteKey HKLM\Software\Classes\CLSID\{ABCD4567-76B5-4bc7-AAC5-396D70925B22}
              RegDeleteKey HKLM\Software\Classes\CLSID\{AE84FF0C-BABD-4D91-92A1-AF75D2D02E6D}
              RegDeleteKey HKLM\Software\Classes\CLSID\{B096A483-0ABD-4AF0-856A-CAD36145AF5C}
              RegDeleteKey HKLM\Software\Classes\CLSID\{b2a3156e-3332-4b47-af5a-5b121503514f}
              RegDeleteKey HKLM\Software\Classes\CLSID\{B5E427F9-AB38-4348-9076-86870C2BE860}
              RegDeleteKey HKLM\Software\Classes\CLSID\{C0BC364F-AB33-4778-8047-5A2148E0ECDA}
              RegDeleteKey HKLM\Software\Classes\CLSID\{C1EA2421-BC9A-4546-943C-126F9D818EFB}
              RegDeleteKey HKLM\Software\Classes\CLSID\{C3E2988E-1433-469d-BFC1-4080D131FE1A}
              RegDeleteKey HKLM\Software\Classes\CLSID\{C4C4786C-9861-46d2-BB63-AC782AB07046}
              RegDeleteKey HKLM\Software\Classes\CLSID\{C833A552-F5AF-4a7b-87B3-6EBDE0DB3B43}
              RegDeleteKey HKLM\Software\Classes\CLSID\{CF080118-CDA5-429d-A8BD-EC7ECA74663F}
              RegDeleteKey HKLM\Software\Classes\CLSID\{D3377825-230D-4a12-805C-132557FA1A8B}
              RegDeleteKey HKLM\Software\Classes\CLSID\{D7136B99-FC27-4DC1-8497-5444D49B426A}
              RegDeleteKey HKLM\Software\Classes\CLSID\{DD45A464-7763-43EE-A756-5F2C93B0CF5E}
              RegDeleteKey HKLM\Software\Classes\CLSID\{E4A3F67D-5237-43fa-B3F2-41C37C1204B9}
              RegDeleteKey HKLM\Software\Classes\CLSID\{E78EA05B-B6A7-4dc4-879D-444DCD224CB4}
              RegDeleteKey HKLM\Software\Classes\CLSID\{EDF78E1B-31A2-4c6e-AD40-0AFCD0D55263}
              RegDeleteKey HKLM\Software\Classes\CLSID\{ef130e77-0a34-4365-bfb7-218fd3ddcd5f}
              RegDeleteKey HKLM\Software\Classes\CLSID\{F41C1430-CFDE-4AD3-B38D-7890F0843E47}
              RegDeleteKey HKLM\Software\Classes\CLSID\{F5AB293C-2E21-4441-9AD8-B3646EB26DF5}
              RegDeleteKey HKLM\Software\Classes\CLSID\{FDA9BFC7-4ECD-43a0-AC1E-2E7DDE0C81B0}
              RegDeleteKey HKLM\Software\Classes\CLSID\{645FF040-5081-101B-9F08-00AA002F954E}\shellex\ContextMenuHandlers\{7EC618F2-C506-4221-9F56-792B92BF762E}

              RegDeleteKey HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ExplorerUWAS
              RegDeleteKey HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ExplorerWAS
              RegDeleteKey HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\UDCShell

              RegDeleteKey HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\ExplorerUWAS
              RegDeleteKey HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\ExplorerWAS
              RegDeleteKey HKLM\Software\Classes\Drive\shellex\ContextMenuHandlers\UDCShell

              RegDeleteKey HKLM\Software\Classes\Interface\{02946FD1-2D99-46E6-A790-3A089714EDD9}
              RegDeleteKey HKLM\Software\Classes\Interface\{0D146B7F-FA35-465D-B716-BCBC1F9A92D3}
              RegDeleteKey HKLM\Software\Classes\Interface\{12813770-461E-4A9F-8C5B-C227A8E9FBE8}
              RegDeleteKey HKLM\Software\Classes\Interface\{1562D24E-F5BF-4BB4-AF4C-BBB610B62638}
              RegDeleteKey HKLM\Software\Classes\Interface\{1BEA1806-F5C7-4696-B0A0-26CFD6A958DD}
              RegDeleteKey HKLM\Software\Classes\Interface\{258E07A2-FF65-493B-B6BD-421A1F2992A3}
              RegDeleteKey HKLM\Software\Classes\Interface\{2A1647E8-3EC2-49FE-B632-E12D765FA0CC}
              RegDeleteKey HKLM\Software\Classes\Interface\{2DECFCC9-D910-4BAC-94B8-FC006827A60F}
              RegDeleteKey HKLM\Software\Classes\Interface\{4567AB12-A884-4CA6-B739-CEDB12FEF096}
              RegDeleteKey HKLM\Software\Classes\Interface\{4AA76F27-81BC-4C3F-9F24-CB99349C8CC9}
              RegDeleteKey HKLM\Software\Classes\Interface\{4B6A7638-0999-4924-93B7-C5738E1BAEE1}
              RegDeleteKey HKLM\Software\Classes\Interface\{5585C185-B318-4072-A00D-8385F443AE07}
              RegDeleteKey HKLM\Software\Classes\Interface\{59399E33-FB54-48AB-8AE4-AE108B36DAB4}
              RegDeleteKey HKLM\Software\Classes\Interface\{622423BD-B825-4989-BA65-86D0B990D328}
              RegDeleteKey HKLM\Software\Classes\Interface\{6813BFFD-BE81-4613-B4E6-AA7ED0DA8659}
              RegDeleteKey HKLM\Software\Classes\Interface\{7516C86C-2F3D-4724-BD4E-1608F1BDAE12}
              RegDeleteKey HKLM\Software\Classes\Interface\{7CA36000-3320-49D1-BAD1-4C5169D4084A}
              RegDeleteKey HKLM\Software\Classes\Interface\{7E7A1949-5C0C-45F3-A106-34FE038493EF}
              RegDeleteKey HKLM\Software\Classes\Interface\{8DAE9202-0019-4D30-A5D2-AAF02D4DDC37}
              RegDeleteKey HKLM\Software\Classes\Interface\{8E0A02C1-974F-4379-BFD3-69FFB9E0659D}
              RegDeleteKey HKLM\Software\Classes\Interface\{9793B356-4337-44AC-9A22-DF6A7930602C}
              RegDeleteKey HKLM\Software\Classes\Interface\{A1DDDD67-64B2-4CAB-BE0B-E34F3F12AED0}
              RegDeleteKey HKLM\Software\Classes\Interface\{A22FBA1E-CAAF-4E45-8EFF-4A821AF03E69}
              RegDeleteKey HKLM\Software\Classes\Interface\{A56B6D30-FDE0-42A9-BE6B-18B5D3F2F519}
              RegDeleteKey HKLM\Software\Classes\Interface\{ABCD4567-4D73-43E9-85E5-53A2DBD95411}
              RegDeleteKey HKLM\Software\Classes\Interface\{ABCD4567-4D73-43E9-85E5-53A2DBD95422}
              RegDeleteKey HKLM\Software\Classes\Interface\{ABCD4567-D8E8-4DF1-A3EA-D0AA72F42611}
              RegDeleteKey HKLM\Software\Classes\Interface\{A0E2E5AB-C02F-489B-BD7B-58C329F774F3}
              RegDeleteKey HKLM\Software\Classes\Interface\{A6E398B2-A288-4D76-B0D0-8F153D14B66E}
              RegDeleteKey HKLM\Software\Classes\Interface\{A92616B1-2E82-4052-B579-0A40C2304380}
              RegDeleteKey HKLM\Software\Classes\Interface\{B22EE952-9A58-4495-AE78-C0146FA1A3C7}
              RegDeleteKey HKLM\Software\Classes\Interface\{C1EA2421-BC9A-4546-943C-126F9D818EFB}
              RegDeleteKey HKLM\Software\Classes\Interface\{C3896A1E-8ECD-490B-8A1C-39FE9F7D64A1}
              RegDeleteKey HKLM\Software\Classes\Interface\{C88B2356-A6FE-41EC-B0FB-41F2C82C867E}
              RegDeleteKey HKLM\Software\Classes\Interface\{CF5C9FCE-C963-49E5-A3A4-0A81FFFE1E55}
              RegDeleteKey HKLM\Software\Classes\Interface\{D090E12D-B79C-4B82-A76C-0E3BBE73C9EF}
              RegDeleteKey HKLM\Software\Classes\Interface\{D7136B99-FC27-4DC1-8497-5444D49B426A}
              RegDeleteKey HKLM\Software\Classes\Interface\{D80A56D7-451C-41CF-9A74-1447E0887B97}
              RegDeleteKey HKLM\Software\Classes\Interface\{DE3C77B8-7378-4A4C-B6F8-4A008B4A6009}
              RegDeleteKey HKLM\Software\Classes\Interface\{E0110779-5F79-4685-9C96-9D99EFD30CA2}
              RegDeleteKey HKLM\Software\Classes\Interface\{E7CCBD19-2EEA-4B6A-B9BE-E8A68613809C}
              RegDeleteKey HKLM\Software\Classes\Interface\{E95F8133-A554-4C0C-9B9A-EEEE3B82CEDE}
              RegDeleteKey HKLM\Software\Classes\Interface\{EA0F107F-2BF6-44A0-96C4-A99B74AFBC4A}
              RegDeleteKey HKLM\Software\Classes\Interface\{F18701B3-185D-42FD-A55E-F47FDAC8F362}
              RegDeleteKey HKLM\Software\Classes\Interface\{F709F572-86F5-47C8-AFCF-3CEBC468FADB}
              RegDeleteKey HKLM\Software\Classes\Interface\{F97E5B38-4887-444A-86F5-91C18331500B}
              RegDeleteKey HKLM\Software\Classes\Interface\{F9AC5167-2C13-4607-B924-81C1C2251C84}
              RegDeleteKey HKLM\Software\Classes\Interface\{FB752175-36D8-4792-9302CFB8018C0DEC}

              RegDeleteKey HKLM\Software\Classes\lnkfile\shellex\ContextMenuHandlers\UDCShell

              RegDeleteKey HKLM\Software\Classes\SYSTEM\ControlSet003\Services\wasfsd

              RegDeleteKey HKLM\Software\Classes\TypeLib\{03A78DBD-AA12-4DB4-AB2C-564460D385DC}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{09AF1CF9-825C-4017-A7DC-088C68770F31}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{0A89FF7F-1A12-42D9-ACCB-4217112DC7E0}
              RegDeleteKey HKLM\software\classes\typelib\{1234890a-5e6e-4867-8136-ca6f1456b235}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{12398A44-7DFC-4C46-BD8F-41259D169A0D}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{16DEEE6B-AEFC-4BA6-9F32-57BBE6783A7C}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{21C724D0-B91A-4F35-99E7-55D325F00B20}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{223CEDCA-738B-4C4D-B8AE-C68B68C90A4A}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{4567AB12-AE24-4FD6-B479-E2B464F32DA6}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{5940CA88-8F1A-4A74-89E4-B3407E5E7348}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{61C1FC79-7120-4824-A563-D4D11D80BAFB}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{68BC55E9-4D3E-4C89-89AC-7559763C98B8}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{692CA430-32C8-470D-BA1F-7E15E21E7043}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{7eacf70b-302f-4049-ac68-2d62eb43e473}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{8ECC09E1-634B-42AC-8BE7-E6EDBB53C90E}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{A8C9AD38-7708-4BEB-A20C-B79614B4F120}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{ABCD4567-7437-43EF-AB74-4AB1D3A37411}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{ABCD4567-7437-43EF-AB74-4AB1D3A37422}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{B869788C-35DF-4104-BACB-8FDB83AFFFFD}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{BD9421BB-9F96-4272-802F-49BEC746056E}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{F874A0AE-66E8-426B-A3F5-6BA6958DCDBA}
              RegDeleteKey HKLM\Software\Classes\TypeLib\{FB42F450-C8B1-4799-99F1-87FA9CA92AB9}

              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\errorguard.exe

              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{205ff73b-ca67-11d5-99dd-444553540006}
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4}
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6AE7418B-229F-4A2C-AE1B-D5962888F02D}
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8C65AEF6-E413-4314-815B-82717A3F1603}
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B5141620-C2B2-4D95-9F0F-134D99C87AB0}

              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\Error Guard
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ERS_is1
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\ersu_is1
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UDC6_is1
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UERS_is1
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\USDR6_is1
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\USDR6V_is1
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\usyp_is1
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UWFX_5_is1
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\UWinFX6_is1
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\wa6p_is1
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WAS_is1
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WFX5_is1
              RegDeleteKey HKLM\Software\Microsoft\Windows\CurrentVersion\Uninstall\WinAntiSpyware 2006 Scanner_is1

              RegDeleteKey HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Minimal\sscan.sys
              RegDeleteKey HKLM\SYSTEM\ControlSet001\Control\SafeBoot\Network\sscan.sys

              RegDeleteKey HKLM\SYSTEM\ControlSet001\Services\FOPN
              RegDeleteKey HKLM\SYSTEM\ControlSet001\Services\uwasfsd
              RegDeleteKey HKLM\SYSTEM\ControlSet002\Services\FOPN

              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\df_km.sys
              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\ersd.sys
              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sscan.sys

              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\df_kmd.sys
              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\ersd.sys
              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\sscan.sys

              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ERSD
              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\enum\root\legacy_erssdd

              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\df_kmd
              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\ersd
              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\erssdd
              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\FOPN
              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\FWSvc
              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\uwasfsd
              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\vspf
              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk
              RegDeleteKey HKLM\SYSTEM\CurrentControlSet\Services\wasfsd

              RegDeleteKey HKUS\Software\DriveCleaner 2006 Free

              # 4 - ActiveX

              RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}
              RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{205FF73B-CA67-11D5-99DD-444553540006}
              RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}
              RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}
              RegDeleteKey HKLM\Software\Microsoft\Code Store Database\Distribution Units\{F919FBD3-A96B-4679-AF26-F551439BB5FD}

              RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{09F1ADAC-76D8-4D0F-99A5-5C907DADB988}|Compatibility Flags|1024
              RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{205FF73B-CA67-11D5-99DD-444553540006}|Compatibility Flags|1024
              RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6}|Compatibility Flags|1024
              RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A}|Compatibility Flags|1024
              RegSetDwordValue HKLM\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{F919FBD3-A96B-4679-AF26-F551439BB5FD}|Compatibility Flags|1024

              # 5 - Fichiers

              DllUnregister %PROGRAMFILES%\DriveCleaner 2006 Free\UDCPChk.dll|1
              DllUnregister %PROGRAMFILES%\DriveCleaner 2006 Free\UDCShell.dll|1
              DllUnregister %PROGRAMFILES%\ErrorSafe\df_fixer.dll|1
              DllUnregister %PROGRAMFILES%\ErrorSafe\df_proxy.dll|1
              DllUnregister %PROGRAMFILES%\ErrorSafe\ecc.dll|1
              DllUnregister %PROGRAMFILES%\ErrorSafe\esSPCheck.dll|1
              DllUnregister %PROGRAMFILES%\ErrorSafe\FFWraper.dll|1
              DllUnregister %PROGRAMFILES%\ErrorSafe\FixCore.dll|1
              DllUnregister %PROGRAMFILES%\ErrorSafe\FiFxr5.dll|1
              DllUnregister %PROGRAMFILES%\ErrorSafe\FTRec.dll|1
              DllUnregister %PROGRAMFILES%\ErrorSafe\MMFix.dll|1
              DllUnregister %PROGRAMFILES%\ErrorSafe\StrRes.dll|1
              DllUnregister %PROGRAMFILES%\SysProtect\compclr.dll|1
              DllUnregister %PROGRAMFILES%\SysProtect\df_fixer.dll|1
              DllUnregister %PROGRAMFILES%\SysProtect\df_proxy.dll|1
              DllUnregister %PROGRAMFILES%\SysProtect\FFWrapr.dll|1
              DllUnregister %PROGRAMFILES%\SysProtect\flfxr10.dll|1
              DllUnregister %PROGRAMFILES%\SysProtect\FTRec.dll|1
              DllUnregister %PROGRAMFILES%\SysProtect\FxCore.dll|1
              DllUnregister %PROGRAMFILES%\SysProtect\MMFx.dll|1
              DllUnregister %PROGRAMFILES%\SysProtect\StrRes.dll|1
              DllUnregister %PROGRAMFILES%\SystemDoctor 2006 Free\order.dll|1
              DllUnregister %PROGRAMFILES%\WinAntiSpyware 2006\AsAgents.dll|1
              DllUnregister %PROGRAMFILES%\WinAntiSpyware 2006\shellext.dll|1
              DllUnregister %PROGRAMFILES%\WinAntiSpyware 2006 Scanner\AsAgents.dll|1
              DllUnregister %PROGRAMFILES%\WinAntiSpyware 2006 Scanner\shellext.dll|1
              DllUnregister %PROGRAMFILES%\WinAntiSpyware 2006 Scanner\uwas6chk.dll|1
              DllUnregister %PROGRAMFILES%\WinAntiSpyware 2006 Scanner\was6chk.dll|1
              DllUnregister %PROGRAMFILES%\WinAntiVirus Pro 2006\avkernel.dll|1
              DllUnregister %PROGRAMFILES%\WinAntiVirus Pro 2006\IEFWBHO.dll|1
              DllUnregister %PROGRAMFILES%\WinAntiVirus Pro 2006\libfn.dll|1
              DllUnregister %PROGRAMFILES%\WinAntiVirus Pro 2006\rpt.dll|1
              DllUnregister %PROGRAMFILES%\WinAntiVirus Pro 2006\winpgi.dll|1
              DllUnregister %PROGRAMFILES%\WinFixer 2005\compcln.dll|1
              DllUnregister %PROGRAMFILES%\WinFixer 2005\df_fixer.dll|1
              DllUnregister %PROGRAMFILES%\WinFixer 2005\df_proxy.dll|1
              DllUnregister %PROGRAMFILES%\WinFixer 2005\ffCom.dll|1
              DllUnregister %PROGRAMFILES%\WinFixer 2005\FFWraper.dll|1
              DllUnregister %PROGRAMFILES%\WinFixer 2005\FileTypeRecognizer.dll|1
              DllUnregister %PROGRAMFILES%\WinFixer 2005\FixCore.dll|1
              DllUnregister %PROGRAMFILES%\WinFixer 2005\MMFix.dll|1
              DllUnregister %PROGRAMFILES%\WinFixer 2005\OEDrop.dll|1
              DllUnregister %PROGRAMFILES%\WinFixer 2005\StrRes.dll|1
              DllUnregister %PROGRAMFILES%\Common Files\Companion Wizard\WapCHK.dll|1
              DllUnregister %PROGRAMFILES%\Common Files\WinAntiSpyware 2006\was6chk.dll|1
              DllUnregister %PROGRAMFILES%\Common Files\WinAntiVirus Pro 2006\WapCHK.dll|1
              DllUnregister %PROGRAMFILES%\Common Files\WinSoftware\CrXML.dll|1
              DllUnregister %PROGRAMFILES%\Common Files\WinSoftware\PCheck.dll|1
              DllUnregister %SYSDIR%\SpOrder.dll|1
              DllUnregister %WINDIR%\syst32.dll|1

              FileDelete %APPDATA%\errorsafe*.exe
              FileDelete %APPDATA%\winantispyware*.exe
              FileDelete %APPDATA%\winantiviruspro*.exe
              FileDelete %APPDATA%\Microsoft\Internet Explorer\Quick Launch\SystemDoctor*.lnk
              FileDelete %APPDATA%\Microsoft\Internet Explorer\Quick Launch\WinAntiSpyware*.lnk
              FileDelete %DESKTOP%\DriveCleaner 2006 Free.lnk
              FileDelete %DESKTOP%\ErrorGuard.lnk
              FileDelete %DESKTOP%\ErrorSafe.lnk
              FileDelete %DESKTOP%\ErrorSafe*.exe
              FileDelete %DESKTOP%\SystemDoctor*.lnk
              FileDelete %DESKTOP%\WinAntiSpyware*.lnk
              FileDelete %DESKTOP%\WinFixer*.exe
              FileDelete %DESKTOP%\WinFixer*.lnk
              FileDelete %MYDOCUMENTS%\SystemDoctor*.exe
              FileDelete %PROGRAMFILES%\WinAntiVirusPro*.exe
              FileDelete %PROGRAMFILES%\Common Files\Companion Wizard\WapCHK.dll
              FileDelete %PROGRAMFILES%\Common Files\Companion Wizard\WapCHK{*}.dll
              FileDelete %WINDIR%\46241234110.exe
              FileDelete %WINDIR%\service32.exe
              FileDelete %WINDIR%\syst32.dll
              FileDelete %WINDIR%\Downloaded Program Files\U*_*_*NetInstaller.exe
              FileDelete %WINDIR%\Downloaded Program Files\CONFLICT.1\U*_*_*NetInstaller.exe
              FileDelete %WINDIR%\Downloaded Program Files\CONFLICT.2\U*_*_*NetInstaller.exe
              FileDelete %WINDIR%\Downloaded Program Files\CONFLICT.3\U*_*_*NetInstaller.exe
              FileDelete %WINDIR%\Downloaded Program Files\CONFLICT.4\U*_*_*NetInstaller.exe
              FileDelete %SYSDIR%\av.cpl
              FileDelete %SYSDIR%\df_kme.exe
              FileDelete %SYSDIR%\SpOrder.dll
              FileDelete %SYSDIR%\stera.exe
              FileDelete %SYSDIR%\drivers\ApiMon.sys
              FileDelete %SYSDIR%\drivers\df_kmd.sys
              FileDelete %SYSDIR%\drivers\ersd.sys
              FileDelete %SYSDIR%\drivers\erssdd.sys
              FileDelete %SYSDIR%\drivers\fopn.sys
              FileDelete %SYSDIR%\drivers\sscan.sys
              FileDelete %SYSDIR%\drivers\uwasfsd.sys
              FileDelete %SYSDIR%\drivers\vspf_hk5.sys
              FileDelete %SYSDIR%\drivers\vspf5.sys
              FileDelete %SYSDIR%\drivers\wasfsd.sys
              FileDelete %SYSDIR%\drivers\WFF.sys
              FileDelete %SYSTEMDRIVE%\systemdoctor*.exe

              # 6 - Repertoires

              FolderDelete %APPDATA%\systemdoctor 2006 free
              FolderDelete %APPDATA%\WinAntiVirus Pro 2006
              FolderDelete %ALLUSERSAPPDATA%\WinAntiVirus Pro 2006
              FolderDelete %ALLUSERSPROGRAMS%\DriveCleaner 2006 Free
              FolderDelete %ALLUSERSPROGRAMS%\ErrorSafe
              FolderDelete %ALLUSERSPROGRAMS%\SystemDoctor 2006 Unregistered Version
              FolderDelete %ALLUSERSPROGRAMS%\WinAntiSpyware 2006
              FolderDelete %ALLUSERSPROGRAMS%\WinAntiSpyware 2006 Scanner
              FolderDelete %ALLUSERSPROGRAMS%\WinAntiVirus Pro 2006
              FolderDelete %ALLUSERSPROGRAMS%\WinFixer 2005
              FolderDelete %ALLUSERSSTARTUP%\SysProtect
              FolderDelete %PROGRAMFILES%\DriveCleaner 2006 Free
              FolderDelete %PROGRAMFILES%\erroguard
              FolderDelete %PROGRAMFILES%\Error Safe
              FolderDelete %PROGRAMFILES%\Error Safe Free
              FolderDelete %PROGRAMFILES%\ErrorSafe
              FolderDelete %PROGRAMFILES%\errorsafe free
              FolderDelete %PROGRAMFILES%\SysProtect Free
              FolderDelete %PROGRAMFILES%\SystemDoctor 2006 Free
              FolderDelete %PROGRAMFILES%\WinAntiSpyware 2006
              FolderDelete %PROGRAMFILES%\WinAntiSpyware 2006 Free
              FolderDelete %PROGRAMFILES%\WinAntiSpyware 2006 Scanner
              FolderDelete %PROGRAMFILES%\WinAntiVirus Pro 2006
              FolderDelete %PROGRAMFILES%\WinFixer 2005
              FolderDelete %PROGRAMFILES%\WinPopupGuard 2005
              FolderDelete %PROGRAMFILES%\Archivos comunes\DriveCleaner 2006 Free
              FolderDelete %PROGRAMFILES%\Archivos comunes\Error Safe
              FolderDelete %PROGRAMFILES%\Archivos comunes\erroguard
              FolderDelete %PROGRAMFILES%\Archivos comunes\errorguard
              FolderDelete %PROGRAMFILES%\Archivos comunes\ErrorSafe
              FolderDelete %PROGRAMFILES%\Archivos comunes\SystemDoctor 2006
              FolderDelete %PROGRAMFILES%\Archivos comunes\WinAntiSpyware 2006
              FolderDelete %PROGRAMFILES%\Archivos comunes\WinAntiVirus Pro 2006
              FolderDelete %PROGRAMFILES%\Archivos comunes\WinFixer 2005
              FolderDelete %PROGRAMFILES%\Archivos comunes\WinSoftware
              FolderDelete %PROGRAMFILES%\Common Files\DriveCleaner 2006 Free
              FolderDelete %PROGRAMFILES%\Common Files\erroguard
              FolderDelete %PROGRAMFILES%\Common Files\errorguard
              FolderDelete %PROGRAMFILES%\Common Files\ErrorSafe
              FolderDelete %PROGRAMFILES%\Common Files\SysProtect
              FolderDelete %PROGRAMFILES%\Common Files\SystemDoctor 2006
              FolderDelete %PROGRAMFILES%\Common Files\WinAntiSpyware 2006
              FolderDelete %PROGRAMFILES%\Common Files\WinAntiVirus Pro 2006
              FolderDelete %PROGRAMFILES%\Common Files\WinFixer 2005
              FolderDelete %PROGRAMFILES%\Common Files\WinSoftware
              FolderDelete %PROGRAMFILES%\Fichiers communs\DriveCleaner 2006
              FolderDelete %PROGRAMFILES%\Fichiers communs\DriveCleaner 2006 Free
              FolderDelete %PROGRAMFILES%\Fichiers communs\Error Safe
              FolderDelete %PROGRAMFILES%\Fichiers communs\erroguard
              FolderDelete %PROGRAMFILES%\Fichiers communs\errorguard
              FolderDelete %PROGRAMFILES%\Fichiers communs\ErrorSafe
              FolderDelete %PROGRAMFILES%\Fichiers communs\SystemDoctor 2006
              FolderDelete %PROGRAMFILES%\Fichiers communs\WinAntiSpyware 2006
              FolderDelete %PROGRAMFILES%\Fichiers communs\WinAntiVirus Pro 2006
              FolderDelete %PROGRAMFILES%\Fichiers communs\WinFixer 2005
              FolderDelete %PROGRAMFILES%\Fichiers communs\WinSoftware
              FolderDelete %SYSTEMDRIVE%\WinAntiVirus Pro 2006

              # 7 - Nettoyage

              Filedelete %USERPROFILE%\Cookies\*@*drivecleaner*.txt
              Filedelete %USERPROFILE%\Cookies\*@*errorsafe*.txt
              Filedelete %USERPROFILE%\Cookies\*@*systemdoctor*.txt
              Filedelete %USERPROFILE%\Cookies\*@*WinAntiSpyware*.txt
              Filedelete %USERPROFILE%\Cookies\*@*winantivirus*.txt
              Filedelete %USERPROFILE%\Cookies\*@*winfixer*.txt
              Filedelete %USERPROFILE%\Cookies\*@*yieldmanager*.txt

              RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drivecleanr.com|*|4
              RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsafe.com|*|4
              RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\systemdoctor.com|*|4
              RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\win-anti-virus-pro.com|*|4
              RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispy.com|*|4
              RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispyware.com|*|4
              RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantivirus.com|*|4
              RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantiviruspro.com|*|4
              RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfirewall.com|*|4
              RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfixer.com|*|4
              RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfixer2006.com|*|4
              RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winnanny.com|*|4
              RegSetDwordValue HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winsoftware.com|*|4

              RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\drivecleanr.com|*|4
              RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\errorsafe.com|*|4
              RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\systemdoctor.com|*|4
              RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\win-anti-virus-pro.com|*|4
              RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispy.com|*|4
              RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantispyware.com|*|4
              RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantivirus.com|*|4
              RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winantiviruspro.com|*|4
              RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfirewall.com|*|4
              RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfixer.com|*|4
              RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winfixer2006.com|*|4
              RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winnanny.com|*|4
              RegSetDwordValue HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\winsoftware.com|*|4

              SystemEmptyInternetCache
              SystemEmptyTempFolder

              je suis un peu désemparé: que me conseilles tu pour la suite?
              Merci de ton aide
          2. Contributeur sécurité
            Bonsoir,

            bizarre ton rapport, reposte le pour voir

            C:\ navipromo.txt.

            As tu bien fait toutes les manips ?

            reposte aussi un rapport blacklight stp
            1. Contributeur sécurité
              bonsoir,

              tu choisis le compte où tu as l'habitude d'aller, si tu n'en as qu'un tu prends celui là. Oublie le compte invité.
              1. Contributeur sécurité
                Bonsoir,

                désolée, mais j'étais absente aujourd'hui, effectivement tu es à nouveau infecté, je te remets la manip à effectuer

                ces manips sont à faire dans l'ordre stp, imprime car il te faudra les faire en mode sans échec

                * Télécharge CCleaner

                http://www.filehippo.com/download_ccleaner.html

                ("Download Latest Version", sur la droite).

                Ce logiciel va permettre de supprimer tous les fichiers temporaires. Avant de cliquer sur le bouton "installer", décoche toutes les "options supplémentaires". Par la suite, laisse-le avec ses réglages par défaut. C'est tout.

                * télécharge Brute Force Uninstaller

                http://www.merijn.org/files/bfu.zip

                * FAIS UN CLIC-DROIT sur le lien ci dessous

                http://metallica.geekstogo.com/EGDACCESS.bfu

                et choisis "Enregistrer sous" (dans IE c'est "Enregistrer le lien sous..")

                afin de télécharger EGDACCESS.bfu, Type "Tous les fichiers".

                Sauvegarde dans le dossier créé (c:\BFU)

                * FAIS UN CLIC-DROIT sur le lien ci dessous

                http://perso.numericable.fr/~altshift/Info/Fichiers/Winsoftware.bfu

                et choisis "Enregistrer sous" (dans IE c'est "Enregistrer le lien sous..")

                afin de télécharger Winsoftware.bfu, Type "Tous les fichiers".

                Sauvegarde dans le dossier créé (c:\BFU)

                * télécharge Navipromo.zip (par lazzzy)

                http://perso.numericable.fr/~altshift/Info/Fichiers/Navipromo07H.zip
                et décompresse-le sur ton bureau

                * Copie la suite des instructions dans un fichier texte, sur ton bureau. et redémarre en mode sans échec comme indiqué ici

                https://forum.pcastuces.com/default.asp#haut

                à la lettre C

                Il faudra choisir ta session habituelle, pas le compte "Administrateur" ou autre.

                * lance le fichier Navipromo.bat qui se trouve dans le dossier Navipromo, sur ton bureau.
                * Sélectionne l'option "Recherche et suppression automatique". Patiente.
                S'il trouve quelque chose, tu verras défiler des lignes dans la fenêtre de commande et au bout de quelques instants, il faudra que tu appuies sur une touche pour que le nettoyage soit lancé. Lorsqu'il a terminé, ferme le rapport qui s'est ouvert

                * Relance l'outil, Sélectionne l'option "Suppression Heuristique", et patiente quelques minutes.
                Lorsqu'il a terminé, ferme le rapport qui s'est ouvert

                * Démarre le "Brute Force Uninstaller" en double-cliquant sur BFU.exe.
                Clique sur le petit dossier jaune, à la droite de la boîte "Scriptline to execute", et double-clique sur : EGDACCESS.bfu
                - Dans la boîte "Scriptline to execute", tu devrais maintenant voir ceci : C:\BFU\EGDACCESS.bfu
                Clique sur "Execute" et laisse-le faire son travail.
                Attendre que "Complete script execution" apparaîsse et clique sur OK.
                Clique exit pour fermer le programme BFU.
                Recommence encore une fois.

                * Démarre encore le "Brute Force Uninstaller" en double-cliquant sur BFU.exe.
                * Clique sur le petit dossier jaune, à la droite de la boîte "Scriptline to execute", et double-clique sur : Winsoftware.bfu
                - Dans la boîte "Scriptline to execute", tu devrais maintenant voir ceci : C:\BFU\Winsoftware.bfu
                * Clique sur "Execute" et laisse-le faire son travail.
                Attendre que "Complete script execution" apparaîsse et clique sur OK.
                * Clique exit pour fermer le programme BFU.
                Recommence encore une fois

                * Démarrer -> panneau de configuration -> options internet

                Clique sur l'onglet "Contenu" puis onglet "Certificats" et si tu trouves ceci, en particulier dans "éditeurs approuvés" :

                electronic-group - egroup - Montorgueil - VIP - "Sunny Day Design Ltd"

                => Supprime-les tous

                * lance Ccleaner pour un nettoyage complet.

                * redémarre normalement et poste le contenu du fichier Navipromo.txt qui se trouve dans Poste de travail > disque C:\

                Précise les difficultés que tu as eu (ce que tu n'as pas pu faire...) ainsi que l'évolution de la situation.
                1. Bonsoir
                  Les choses se compliquent...
                  j'ai bien effectué tous les téléchargement que tu me conseillais.
                  Mais quand je redémarre en mode sans échec, je choisis le compte "propriétaire "et non "administrateur".
                  Il y a un écran noir avec aux 4 coins " mode sans échec".
                  Au bout d'un certain temps, un message me demande de confirmer ou non le mode sans échec. aussitôt, un message d'erreur au niveau du fichier drtsn.32.exe s'afiche.
                  Ensuite c'est l'écran noir...

                  J'ai recommencé à plusieurs reprises après restauration du système et relance des manips depuis le début; idem

                  En fermant la session, je me suis rendu compte que je n'avais qu'un seul compte: le compte propriétaire est le compte administrateur.
                  J'ai activé un compte invité où les effets du virus n'ont pas tardé à se signaler...
                  A ce point, je ne sais plus bien, faut -il choisir administrateur en mode sans échec?
                  Merci pour ton éclairage
                2. @youyou2612Bonjour,

                  J'ai suivi les instructions. Beaucoup de difficultés avec le mode sans echec.
                  Lorsqu'on lance navipromo, les rapports ne présentent aucun fichier.

                  Lorsqu'on exécute winsoftware.bfu, le dossier "mes documents " s'ouvre avec un message d'errur concernat internet explorer.exe.

                  Dans options internet je n'ai trouvé aucun "éditeur autorisé"

                  voici le rapport
                  Rapport Navipromo.bat 0.71 effectué le 14/03/2007 à 13:48:26,87
                  L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

                  ** Recherche...

                  Fin du rapport de recherche
                  Adware Navipromo non trouvé avec cette méthode

                  Engagement de la méthode Heuristique

                  Rapport Navipromo.bat 0.72 effectué le 14/03/2007 à 13:48:27,10
                  L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

                  ## Suppression Heuristique

                  * Backups :

                  Aucun résultat par la recherche heuristique

                  ## Fin du rapport Heuristique

                  -------------

                  Rapport Navipromo.bat 0.72 effectué le 14/03/2007 à 13:59:23,13
                  L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

                  ## Suppression Heuristique

                  * Backups :

                  Aucun résultat par la recherche heuristique

                  ## Fin du rapport Heuristique

                  -------------

                  Rapport Navipromo.bat 0.71 effectué le 14/03/2007 à 14:57:27,16
                  L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

                  ** Recherche...

                  Fin du rapport de recherche
                  Adware Navipromo non trouvé avec cette méthode

                  Engagement de la méthode Heuristique

                  Rapport Navipromo.bat 0.72 effectué le 14/03/2007 à 14:57:27,36
                  L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

                  ## Suppression Heuristique

                  * Backups :

                  Aucun résultat par la recherche heuristique

                  ## Fin du rapport Heuristique

                  -------------

                  Rapport Navipromo.bat 0.72 effectué le 14/03/2007 à 15:00:06,02
                  L'opération se déroule en mode sans échec sous le compte "Propri‚taire"

                  ## Suppression Heuristique

                  * Backups :

                  Aucun résultat par la recherche heuristique

                  ## Fin du rapport Heuristique
                  merci pour la suite
              2. Bonjour,
                D'abord merci pour ta nouvelle intervention.
                Voici le contenu du rapport tlbeta
                03/11/07 07:35:27 [Info]: BlackLight Engine 1.0.55 initialized
                03/11/07 07:35:27 [Info]: OS: 5.1 build 2600 (Service Pack 2)
                03/11/07 07:35:35 [Note]: 7019 4
                03/11/07 07:35:35 [Note]: 7005 0
                03/11/07 07:36:25 [Note]: 7006 0
                03/11/07 07:36:25 [Note]: 7011 1576
                03/11/07 07:36:26 [Note]: 7026 0
                03/11/07 07:36:26 [Note]: 7026 0
                03/11/07 07:36:26 [Note]: 7024 3
                03/11/07 07:36:26 [Info]: Hidden process: C:\WINDOWS\system32\koos.exe
                03/11/07 07:39:12 [Note]: FSRAW library version 1.7.1021
                03/11/07 07:52:39 [Note]: 4013 26722
                03/11/07 07:52:39 [Note]: 4020 45 65536
                03/11/07 07:52:39 [Note]: 4020 45 65536
                03/11/07 07:52:39 [Note]: 4018 45 65536
                03/11/07 07:52:39 [Note]: 4013 26724
                03/11/07 07:52:39 [Note]: 4020 45 65536
                03/11/07 07:52:39 [Note]: 4018 45 65536
                03/11/07 07:53:07 [Info]: Hidden file: C:\WINDOWS\system32\koos.exe
                03/11/07 07:53:08 [Note]: 7002 0
                03/11/07 07:53:08 [Note]: 7003 1
                03/11/07 07:53:08 [Note]: 10002 1
                03/11/07 07:53:09 [Info]: Hidden file: c:\WINDOWS\system32\kprof
                03/11/07 07:53:09 [Note]: 7002 0
                03/11/07 07:53:09 [Note]: 7003 1
                03/11/07 07:53:09 [Note]: 10002 1
                03/11/07 07:53:30 [Info]: Hidden file: c:\WINDOWS\system32\poof
                03/11/07 07:53:30 [Note]: 7002 0
                03/11/07 07:53:30 [Note]: 7003 1
                03/11/07 07:53:30 [Note]: 10002 1
                03/11/07 08:06:40 [Note]: 7007 0

                voici le rapport hijackthis
                Logfile of HijackThis v1.99.1
                Scan saved at 08:11:53, on 11/03/2007
                Platform: Windows XP SP2 (WinNT 5.01.2600)
                MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                Running processes:
                C:\WINDOWS\System32\smss.exe
                C:\WINDOWS\system32\winlogon.exe
                C:\WINDOWS\system32\services.exe
                C:\WINDOWS\system32\lsass.exe
                C:\WINDOWS\system32\svchost.exe
                C:\WINDOWS\System32\svchost.exe
                C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                C:\WINDOWS\system32\spoolsv.exe
                C:\WINDOWS\Explorer.EXE
                C:\WINDOWS\AGRSMMSG.exe
                C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
                C:\Program Files\QuickTime\qttask.exe
                C:\WINDOWS\system32\ctfmon.exe
                C:\Program Files\MSN Messenger\MsnMsgr.Exe
                C:\Program Files\Alwil Software\Avast4\ashServ.exe
                C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                C:\Program Files\CyberLink\Shared files\RichVideo.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                C:\Program Files\Internet Explorer\iexplore.exe
                C:\WINDOWS\system32\wuauclt.exe
                C:\Mes téléchargements\hijackthis\HijackThis.exe

                R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fhelp%2fHelp4%2f%3f
                R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
                R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
                O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
                O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
                O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
                O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
                O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
                O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?1cb6f3d293fb452a8296fa97834acc47
                O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?1cb6f3d293fb452a8296fa97834acc47
                O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
                O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
                O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
                O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
                O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
                O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                O20 - Winlogon Notify: instcat - instcat.dll (file missing)
                O20 - Winlogon Notify: __c006DF90 - C:\WINDOWS\System32\__c006DF90.dat
                O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe
                O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
                1. Contributeur sécurité
                  Bonsoir,

                  * Télécharge Blacklight
                  https://europe.f-secure.com/exclude/blacklight/index.shtml
                  (de F-Secure)
                  (le premier de la page)

                  Enregistre le sur ton Bureau.
                  Double-clique blbeta.exe
                  Clique sur "I ACCEPT" .
                  clique Scan puis Next<*gras>

                  Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport,
                  sur ton Bureau, nommé <gras>fsbl.xxxxxxx.log
                  (les xxxxxxx sont des chiffres).

                  Copie et colle le contenu de ce rapport dans ta prochaine réponse.
                  NE PAS choisir l'option "Rename" de suite : nous devons analyser le rapport,
                  car des fichiers légitimes peuvent être présents, tel wbemtest.exe

                  et un nouveau rapport hijackthis
                  1. Bonjour,
                    Malheureusement oui! en déplaçant malencontreusement la souris; pourtant la provenance de la page (kiev en ukraine ) m'avait mis la puce à l'oreille!
                    Après en cherchant sur le web je me suis rendu compte que c'était un malware: manque d'expérience!

                    J'ai désinstallé driverclean2006.

                    J'ai fait une analyse avec AGV antispyware et j'ai nettoyer et mis en quarantaine 2 malwares. j'ai tout effacé dans le dossier quarantaine.
                    J'ai fait un scan avec HijackThis et j'ai fixé un fichier contenant le mot "drivecleaner";

                    J'ai recherché " driverclean" dans tous les fichiers y compris les fichiers cachés. j'ai effacé les fichiers que je pouvais effacer.

                    j'ai recopié dans killbox le chemin d'accès d'un des fichiers que je ne pouvais pas effacer; je l'ai détruit avec la mention delete on reboot.
                    Un scan avac avast ne détecte aucun virus.

                    au redémarrage, j'ai refusé l'accès à la zone sure de ZoneAlarm à un nouveau programme "winrnr" je crois.

                    Les fenêtres intempestives n'apparaissent plus sauf au démarrage de internet explorer, ou une page web " broadcast video" s'ouvre juste après ma page de démarrage: msn.fr.

                    A ce point, je ne sais plus trop quoi faire????
                    si tu es toujours disponible, excuse moi de te mettre encor à contribution.
                    Merci
                    1. Contributeur sécurité
                      bonjour,

                      certainement pas, tu vas te retrouver une nouvelle fois infecté.
                      J'espère que tu n'as pas cliqué ?

                      1. Contributeur sécurité
                        Bonjour,

                        parfait
                        tu peux supprimer c:!killbox

                        pense à mettre ton sujet en RESOLU stp. Merci

                        bonne fin de journée
                        1. Bonjour,
                          juste avant de clôturer la discussion, j'ai un programme qui apparait sur mon écran Drive cleaner Installer 2006 qui me propose de nettoyer mon pc. j'accepte ou non?
                          merci pour cette ultime intervention.
                      2. Contributeur sécurité
                        bonsoir,

                        as tu pu supprimer le contenu de
                        C:\Documents and Settings\Propriétaire\Local Settings\Temp

                        vide la quarantaine de ton antivirus.

                        As tu encore des problèmes ?
                        1. Bonjour,

                          Non vraiment aucun problème. Excellent!! Cela fait du bien de pouvoir utiliser normalement son ordinateur: merci infiniment !!

                          Je ne savais pas qu'une telle solidarité existait: je ferai un max de pub!!
                      3. Contributeur sécurité
                        Bonsoir,

                        mon système d'exploitation n'est pas mis à jour car j'ai bloqué les mises à jour automatiques. lorsque software distribution pack 2 s'installait, il y avait à chaque fois un blocage du système.
                        si tu peux me conseiller...


                        en fait non pas trop si tu as des soucis pour la màj du SP2 faudrait peut être demander sur le forum adéquat (windows)

                         ( ayant fait un scan avec avast 4.7, j'avais mis deux fichiers infectés en quarantaine ). 
                        


                        lesquels ? tu t'en souviens ?

                        C:\Documents and Settings\Propriétaire\Local Settings\Temp\UDC6_0001_D21M1601\installer.exe is infected with DriveCleaner
                        C:\!KillBox\eim.exe is infected with W32.Spybot.Worm 


                        supprime après avoir affiché les fichiers et dossiers cachés tout le contenu de
                        C:\Documents and Settings\Propriétaire\Local Settings\Temp

                        supprime C:\!KillBox

                        1. Bonjour,
                          j'ai supprimé les contenus des deux dossiers en recherchant aussi les fichiers cachés.
                          les deux fichiers mis en quartantaine par avast sont C:\windows\system32\eostndd.exe et c:\windows\system32\kpaihf.exe
                          Merci pour tout
                      4. Contributeur sécurité
                        Bonjour

                        je te répondrais que ton système d'exploitation n'est pas à jour depuis des lustres, que tu n'as visiblement pas de parefeu, et que tu vas être en permanence infecté.
                        télécharge au moins un firewall stp
                        securite proteger un ordinateur contre les malwares d internet

                        ensuite ré essaye quand même un scan antivirus en ligne si ce n'est bitdefender essaye d'autres
                        https://www.pandasecurity.com/?ref=www.pandasoftware.com/activescan/fr/activescan_principal.htm
                        (en désactivant ton antivirus ils ne s'aiment pas)

                        ou

                        SYMANTEC
                        http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym

                        A effectuer avec IE
                        Clique sur Virus Detection --->" Start "
                        Clique sur " I accept ", puis " Next "
                        Clique sur " I consent ", puis " Next "
                        Un control active X, va se charger
                        Dans la nouvelle fenetre qui s'ouvre, valide en bas à gauche " Toujours faire confiance .... ", puis clique sur OK
                        Le scan débute donc par le dernier HDD

                        poste le rapport
                        1. Bonjour,
                          mon système d'exploitation n'est pas mis à jour car j'ai bloqué les mises à jour automatiques. lorsque software distribution pack 2 s'installait, il y avait à chaque fois un blocage du système.
                          si tu peux me conseiller...

                          voici le rapport par symantec ( ayant fait un scan avec avast 4.7, j'avais mis deux fichiers infectés en quarantaine ).

                          To continue without JavaScript, click here.

                          Virus Status: Safe!
                          Your computer is free of known threats.
                          Virus Status: Infected!
                          Your computer is infected with at least one known threat.
                          Virus Status: Unknown
                          The Scan was unable to determine your vulnerability status.

                          31129 files scanned, 2 file(s) infected on your disk drives.

                          No viruses were detected in memory.

                          Your computer is free of known threats. Virus Detection does not check compressed files.

                          Your computer appears safe for now. For real-time protection from viruses, hackers and privacy threats, upgrade to Norton Internet Security™.

                          No viruses were detected in memory.

                          The scan was cancelled before finishing. To restart the scan, click here.

                          Your computer is free of known threats. Virus Detection does not check compressed files.

                          Your computer appears safe for now. For real-time protection from viruses, hackers and privacy threats, upgrade to Norton Internet Security™.

                          Search for the name of the threat(s) listed below on the Symantec Security Response site for removal information.

                          Warning! The scan detected a virus that is active in your computer's memory.
                          The scan ended to prevent further infection.

                          You should shut down your computer immediately and restart it with an antivirus rescue disk or similar tool.

                          No viruses were detected in memory.

                          Your computer is infected with at least one known virus or Trojan horse.

                          Search for the name of the threat(s) listed below on the Symantec Security Response site for removal information.

                          No viruses were detected in memory.

                          Your computer is infected with at least one known virus or Trojan horse.

                          Note: The scan was cancelled before finishing. There may be more infected files on this computer.

                          Search for the name of the threat(s) listed below on the Symantec Security Response site for removal information.

                          A scan has not been run. To start Virus Detection, click here.

                          C:\Documents and Settings\Propriétaire\Local Settings\Temp\UDC6_0001_D21M1601\installer.exe is infected with DriveCleaner
                          C:\!KillBox\eim.exe is infected with W32.Spybot.Worm

                          Solution: Install Antivirus Software
                          Norton AntiVirus™: The world's most trusted antivirus software.
                          More Info
                          See a Demo

                          or get even more protection with:
                          Norton Internet Security™: Gives you COMPLETE protection against viruses, hackers and privacy threats.
                          More Info
                          See a Demo

                          Need Help? We're here for you.
                          Let our expert technicians remove viruses and spyware while you sit back and watch.
                          More Info

                          Compare Products

                          Merci de continuer à me guider. j'en profite pour tenter de comprendre comment ça marche
                      5. Contributeur sécurité
                        Bonjour,

                        cette fois c'est parfait. As tu encore des soucis ou non ?
                        tu peux peut être faire un scan antivirus en ligne pour confirmation et poster le rapport ici ensuite.

                        * Fait un scan antivirus en ligne
                        https://www.bitdefender.fr/
                        et copie colle le résultat ici
                        * En bas, à gauche de la fenêtre, clique sur BitDefender SCAN ONLINE
                        * Dans la nouvelle fenêtre, clique sur I agree
                        * La fenêtre change encore, clique sur Click here to scan
                        * Les signatures se chargent, etc.

                        1. Bonjour,
                          Effectivement l'ordinateur a recommencé à mieux marcher . et je ne te remercierai jamais assez pour ce dépannage.

                          J'ai fait le scan online de bitdefender. J'ai laissé tourner le processus et quand je suis revenu il y avait un message d'erreur. Plus rien ne répondait. j'ai du éteindre manuellemnt l'ordinateur.

                          Quand je l'ai remis en route ce matin aucune application ne répondait j'ai redémarrer l'ordinateur, j'ai fait une analyse AGV, avast a signalé entretemps un virus que j'ai envoyé en quarantaine "send to chest".

                          Depuis tout marche à nouveau. J'ai un d'avast network shield qui s'ouvre très souvent et signale des attaques bloquées. "Blocked DCOM exploit attack from..." Est ce normal?

                          Je n'ose pas refaire le scan on line.
                          Qu'en penses tu?
                      6. Contributeur sécurité
                        Bonjour,

                        ok pour le service, mais eim.exe est toujours là

                        relance hijackthis et coche puis fixe

                        O4 - HKCU\..\Run: [Win32] eim.exe

                        1- Double-clic sur KillBox.exe
                        2- Selectionne "Delete on Reboot"
                        3 - Dans "Full Path of File to Delete"
                        copie et colle:

                        c:\windows\system32\eim.exe

                        5- clic sur le rond rouge
                        6- une fenetre va apparaitre pour confirmation clic sur OUI
                        7- une seconde fenetre te demande si tu veux redemarrer clic sur OUI

                        reposte un nouveau rapport hijackthis et dit moi si tu n'as pas eu de soucis avec killbox
                        1. Bonsoir,
                          j'ai suivi les dernières instructions mais lorsque je clique "oui" pour redémarrer, au bout de quelques secondes la fenêtre suivante s'ouvre: pending file Rename operations registry Data has been removed by external process.

                          Pour ce qui est du rapport Hijackthis, le voici:
                          Logfile of HijackThis v1.99.1
                          Scan saved at 01:28:13, on 05/03/2007
                          Platform: Windows XP (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 (6.00.2600.0000)

                          Running processes:
                          C:\WINDOWS\System32\smss.exe
                          C:\WINDOWS\system32\winlogon.exe
                          C:\WINDOWS\system32\services.exe
                          C:\WINDOWS\system32\lsass.exe
                          C:\WINDOWS\system32\svchost.exe
                          C:\WINDOWS\Explorer.EXE
                          C:\WINDOWS\system32\spoolsv.exe
                          C:\WINDOWS\AGRSMMSG.exe
                          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
                          C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                          C:\WINDOWS\System32\ctfmon.exe
                          C:\Program Files\MSN Messenger\MsnMsgr.Exe
                          C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          C:\Program Files\CyberLink\Shared files\RichVideo.exe
                          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                          C:\WINDOWS\System32\svchost.exe
                          C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
                          C:\Mes téléchargements\hijackthis\HijackThis.exe

                          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?redirfallthru=http%3a%2f%2fwww.msn.fr%2fhelp%2fHelp4%2f%3f
                          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                          O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
                          O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                          O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
                          O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
                          O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
                          O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
                          O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
                          O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program Files\CyberLink\PowerDVD\Language\Language.exe"
                          O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                          O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                          O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
                          O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
                          O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
                          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
                          O8 - Extra context menu item: Ouvrir dans un nouvel onglet d'arrière-plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/229?1cb6f3d293fb452a8296fa97834acc47
                          O8 - Extra context menu item: Ouvrir dans un nouvel onglet de premier plan - res://C:\Program Files\Windows Live Toolbar\Components\fr-fr\msntabres.dll.mui/230?1cb6f3d293fb452a8296fa97834acc47
                          O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
                          O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/...
                          O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                          O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                          O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                          O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
                          O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
                          O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
                          O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared files\RichVideo.exe

                          tout cela me semble coriace mais félicitations et merci pour le suivi et la compétence.
                      • 1
                      • 2