Quick start

Bonjour,
Quick Start s'est installé sur mon PC, pouvez-vous m'aider à m'en débarrasser ?

Merci d'avance...

11 réponses

  1. Bonjour

    Je te propose donc de mettre ce sujet en résolu;merci

    @+
    0
    1. Bonjour,

      Ci-dessous le rapport...

      # DelFix v10.7 - Logfile created 30/05/2014 at 14:23:42
      # Updated 27/04/2014 by Xplode
      # Username : Angelique - ANGELIQUE-PC
      # Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)

      ~ Removing disinfection tools ...

      Deleted : C:\AdwCleaner
      Deleted : C:\AdwCleaner[R1].txt
      Deleted : C:\AdwCleaner[S1].txt
      Deleted : C:\log2.txt
      Deleted : C:\Users\Angelique\Downloads\AdwCleaner-3.211.exe
      Deleted : C:\Users\Angelique\Downloads\adwcleaner.exe
      Deleted : HKLM\SOFTWARE\AdwCleaner

      ########## - EOF - ##########
      0
      1. Re

        On nettoie et finalise

        Télécharge DelFix de Xplode

        Lance le.
        Tu as 5 choix :

        Réactiver l'UAC
        Supprimer les outils de désinfection (cocher par défaut)
        Effectuer une sauvegarde du registre
        Purger la restauration de système
        Réinitialisation des paramètres usine

        Tu coches ceux qui sont en gras
        et tu exécutes
        Le rapport se trouve ici généralement
        C:\DelFix.txt

        Le reste de la sécurité : http://forum.malekal.com/comment-securiser-son-ordinateur.html

        @+
        0
        1. Nikel tout fonctionne à merveille !!!!!! Merci beaucoup !!!!!
          0
          1. Re

            Tu utilises quel navigateur:Chrome?

            Reparamètres tes navigateurs WEB (page de démarrage, moteur de recherche, etc...) mais aussi supprimer/désactiver les extensions inutiles/parasites :
            * Internet Explorer et modules complémentaires / moteurs de recherche : https://forum.malekal.com/viewtopic.php?t=41399&start=

            * Firefox : https://www.malekal.com/reparer-firefox/?t=36057&start=

            * Google Chrome : https://www.malekal.com/reparer-google-chrome/?t=35837&start=

            @+
            0
            1. Plus de soucis en ce qui concerne ma page d'accueil, j'ai récupérer la même qu'avant. En revanche quand j'ouvre un nouvel onglet, l'adresse de la page est la suivante : chrome://quick_start/content/index.html

              Est-ce normal ?

              Merci...
              0
              1. Re

                As tu encore des soucis?

                @+
                0
                1. Bonsoir,

                  Voici le rapport...

                  Merci

                  Malwarebytes Anti-Malware
                  www.malwarebytes.org

                  Date de l'examen: 29/05/2014
                  Heure de l'examen: 19:58:09
                  Fichier journal: RAPPORT.txt
                  Administrateur: Oui

                  Version: 2.00.2.1012
                  Base de données Malveillants: v2014.05.29.09
                  Base de données Rootkits: v2014.05.21.01
                  Licence: Gratuite
                  Protection contre les malveillants: Désactivé(e)
                  Protection contre les sites Web malveillants: Désactivé(e)
                  Self-protection: Désactivé(e)

                  Système d'exploitation: Windows 7 Service Pack 1
                  Processeur: x64
                  Système de fichiers: NTFS
                  Utilisateur: Angelique

                  Type d'examen: Examen "Menaces"
                  Résultat: Annulé
                  Objets analysés: 308
                  Temps écoulé: 0 min, 57 sec

                  Mémoire: Activé(e)
                  Démarrage: Activé(e)
                  Système de fichiers: Activé(e)
                  Archives: Activé(e)
                  Rootkits: Désactivé(e)
                  Heuristics: Activé(e)
                  PUP: Avertir
                  PUM: Activé(e)

                  Processus: 0
                  (No malicious items detected)

                  Modules: 0
                  (No malicious items detected)

                  Clés du Registre: 0
                  (No malicious items detected)

                  Valeurs du Registre: 0
                  (No malicious items detected)

                  Données du Registre: 0
                  (No malicious items detected)

                  Dossiers: 0
                  (No malicious items detected)

                  Fichiers: 0
                  (No malicious items detected)

                  Secteurs physiques: 0
                  (No malicious items detected)

                  (end)
                  0
                  1. Bonsoir

                    Télécharge Malwaresbytes anti malware ici
                    https://www.commentcamarche.net/telecharger/securite/14361-malwarebytes-anti-malware/

                    --->> Installe le (choisis bien français ); ne modifie pas les paramètres d'installe
                    --->> Décoche la case Activer l'essai gratuit de Malwarebytes Anti-Malware Premium à la fin de l'installation
                    --->> /!\ Utilisateurs de Vista/7/8/8.1 : faire un clic droit sur le raccourci de MalwareBytes' Anti-Malware et choisir Exécuter en tant qu'administrateur
                    --->> Clique sur Mettre à jour dans le Tableau de bord afin de mettre à jour la base de données.
                    --->> Dans l'onglet Examen, sélectionnez Examen Menaces puis clique sur Examiner maintenant.
                    --->> Une fois le scan terminé, clique sur Tout mettre en quarantaine puis sur Appliquez les actions

                    --->> (Si un message demande de redémarrer le PC pour terminer la suppression, accepte)

                    --->> Le rapport est disponible dans Historique > Journaux de l'application. (Choisis bien le dernier en date
                    Tu sélectionnes le fichier et tu demandes l'affichage
                    En bas à gauche un bouton exporter ; tu cliques dessus et tu choisis fichier texte et tu choisis ensuite ou l'enregistrer pour ensuite pouvoir le poster dans ta prochaine réponse

                    Merci

                    @+
                    0
                    1. Bonsoir,

                      Ci-joint le rapport de AdwCleaner,

                      # AdwCleaner v3.211 - Report created 29/05/2014 at 18:52:34
                      # Updated 26/05/2014 by Xplode
                      # Operating System : Windows 7 Ultimate Service Pack 1 (64 bits)
                      # Username : Angelique - ANGELIQUE-PC
                      # Running from : C:\Users\Angelique\Downloads\AdwCleaner-3.211.exe
                      # Option : Clean

                      ***** [ Services ] *****

                      Service Deleted : IePluginService
                      [#] Service Deleted : Update Fortunitas
                      [#] Service Deleted : Update ScanTack
                      [#] Service Deleted : Util Fortunitas

                      ***** [ Files / Folders ] *****

                      Folder Deleted : C:\ProgramData\374311380
                      Folder Deleted : C:\ProgramData\Activeris
                      Folder Deleted : C:\ProgramData\apn
                      Folder Deleted : C:\ProgramData\IePluginService
                      Folder Deleted : C:\ProgramData\MyStart Anti-phishing Domain Advisor
                      Folder Deleted : C:\ProgramData\WPM
                      Folder Deleted : C:\Program Files (x86)\Fortunitas
                      Folder Deleted : C:\Program Files (x86)\globalUpdate
                      Folder Deleted : C:\Program Files (x86)\mystarttb
                      Folder Deleted : C:\Program Files (x86)\Optimizer Pro
                      Folder Deleted : C:\Program Files (x86)\predm
                      Folder Deleted : C:\Program Files (x86)\ScanTack
                      Folder Deleted : C:\Program Files (x86)\SupTab
                      Folder Deleted : C:\Program Files\003
                      Folder Deleted : C:\Users\Angelique\AppData\Local\Freesofttoday
                      Folder Deleted : C:\Users\Angelique\AppData\Local\Genesis
                      Folder Deleted : C:\Users\Angelique\AppData\Local\globalUpdate
                      Folder Deleted : C:\Users\Angelique\AppData\Local\SearchProtect
                      Folder Deleted : C:\Users\ANGELI~1\AppData\Local\Temp\apn
                      Folder Deleted : C:\Users\Angelique\AppData\LocalLow\DataMngr
                      Folder Deleted : C:\Users\Angelique\AppData\LocalLow\Mysearchdial
                      Folder Deleted : C:\Users\Angelique\AppData\LocalLow\mystarttb
                      Folder Deleted : C:\Users\Angelique\AppData\Roaming\Activeris
                      Folder Deleted : C:\Users\Angelique\AppData\Roaming\cacaoweb
                      Folder Deleted : C:\Users\Angelique\AppData\Roaming\SupTab
                      Folder Deleted : C:\Users\Angelique\AppData\Roaming\Systweak
                      Folder Deleted : C:\Users\Angelique\AppData\Roaming\webssearches
                      Folder Deleted : C:\Users\Angelique\AppData\Roaming\Mozilla\Firefox\Profiles\pdx8cb8c.default\mystarttb
                      Folder Deleted : C:\Program Files (x86)\Software
                      Folder Deleted : C:\Users\Angelique\AppData\Roaming\Mozilla\Firefox\Profiles\pdx8cb8c.default\Extensions\{607b689f-7600-45e4-b8e5-887f72dab15c}
                      Folder Deleted : C:\Users\Angelique\AppData\Roaming\Mozilla\Firefox\Profiles\pdx8cb8c.default\Extensions\cacaoweb@cacaoweb.org
                      Folder Deleted : C:\Users\Angelique\AppData\Roaming\Mozilla\Firefox\Profiles\pdx8cb8c.default\Extensions\quick_start@gmail.com
                      File Deleted : C:\END
                      File Deleted : C:\Windows\System32\roboot64.exe
                      File Deleted : C:\Users\Angelique\AppData\Local\AnyProtectScannerSetup.exe
                      File Deleted : C:\Users\Angelique\AppData\Roaming\aps.uninstall.scan.results
                      File Deleted : C:\Users\Angelique\Desktop\cacaoweb.exe
                      File Deleted : C:\Users\Angelique\Desktop\Continue VuuPC Installation.lnk
                      File Deleted : C:\Users\Angelique\AppData\Roaming\Mozilla\Firefox\Profiles\pdx8cb8c.default\invalidprefs.js
                      File Deleted : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\webssearches.xml
                      File Deleted : C:\Users\Angelique\AppData\Roaming\Mozilla\Firefox\Profiles\pdx8cb8c.default\user.js
                      File Deleted : C:\Windows\Tasks\APSnotifierPP1.job
                      File Deleted : C:\Windows\System32\Tasks\APSnotifierPP1
                      File Deleted : C:\Windows\Tasks\APSnotifierPP2.job
                      File Deleted : C:\Windows\System32\Tasks\APSnotifierPP2
                      File Deleted : C:\Windows\Tasks\APSnotifierPP3.job
                      File Deleted : C:\Windows\System32\Tasks\APSnotifierPP3

                      ***** [ Shortcuts ] *****

                      ***** [ Registry ] *****

                      Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [quick_start@gmail.com]
                      Key Deleted : HKCU\Software\Google\Chrome\Extensions\nchpfiddbhbdnagofhkjlaiaejmkdcla
                      Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [cacaoweb]
                      Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Jing]
                      Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE
                      Key Deleted : HKLM\SOFTWARE\Classes\esrv.mysearchdialesrvc
                      Key Deleted : HKLM\SOFTWARE\Classes\esrv.mysearchdialesrvc.1
                      Key Deleted : HKLM\SOFTWARE\Classes\speedupmypc
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\biclient_RASAPI32
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\biclient_RASMANCS
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Lollipop_RASAPI32
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\Lollipop_RASMANCS
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASAPI32
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\NewPlayer_RASMANCS
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\toolbar_vit_sweetim_RASAPI32
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\toolbar_vit_sweetim_RASMANCS
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bitguard.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bprotect.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserdefender.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browserprotect.exe
                      Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [MyStart Anti-phishing Domain Advisor]
                      Key Deleted : HKCU\Software\AppDataLow\{5F189DF5-2D05-472B-9091-84D9848AE48B}
                      Key Deleted : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
                      Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}
                      Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
                      Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
                      Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
                      Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}
                      Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{D40753C7-8A59-4C1F-BE88-C300F4624D5B}
                      Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6DDA37BA-0553-499A-AE0D-BEBA67204548}
                      Key Deleted : HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
                      Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{968EDCE0-C10A-47BB-B3B6-FDF09F2A417D}
                      Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}
                      Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3004627E-F8E9-4E8B-909D-316753CBA923}
                      Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
                      Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}
                      Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}
                      Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}
                      Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3004627E-F8E9-4E8B-909D-316753CBA923}
                      Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}
                      Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}
                      Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{54739D49-AC03-4C57-9264-C5195596B3A1}
                      Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}
                      Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF5625A3-37AB-4BDB-9875-2A3D91CD0DFD}
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{219046AE-358F-4CF1-B1FD-2B4DE83642A8}
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{607B689F-7600-45E4-B8E5-887F72DAB15C}
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0D4A4BC-F7CD-436E-B1FA-25637BA0F5BE}
                      Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
                      Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{CCB24E92-62C4-4C53-95D2-65F9EED476BC}]
                      Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{D8278076-BC68-4484-9233-6E7F1628B56C}]
                      Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
                      Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}
                      Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{917CAAE9-DD47-4025-936E-1414F07DF5B8}
                      Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D9101D6-5BA0-4048-BDDE-7E2DF54C8C47}
                      Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CCB24E92-62C4-4C53-95D2-65F9EED476BC}
                      Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{CCB24E92-62C4-4C53-95D2-65F9EED476BC}]
                      Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{33BB0A4E-99AF-4226-BDF6-49120163DE86}
                      Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{607B689F-7600-45E4-B8E5-887F72DAB15C}
                      Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{62155D33-3CE2-401E-8967-5A270628A3D5}
                      Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E0D4A4BC-F7CD-436E-B1FA-25637BA0F5BE}
                      Data Restored : HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command
                      Key Deleted : HKCU\Software\AnyProtect
                      Key Deleted : HKCU\Software\APN PIP
                      Key Deleted : HKCU\Software\Boxore
                      Key Deleted : HKCU\Software\cacaoweb
                      Key Deleted : HKCU\Software\genesis
                      Key Deleted : HKCU\Software\InstallCore
                      Key Deleted : HKCU\Software\Linkey
                      Key Deleted : HKCU\Software\mysearchdial
                      Key Deleted : HKCU\Software\mysearchdial.com
                      Key Deleted : HKCU\Software\PriceGong
                      Key Deleted : HKCU\Software\ScanTack
                      Key Deleted : HKCU\Software\Software
                      Key Deleted : HKCU\Software\systweak
                      Key Deleted : HKCU\Software\TutoTag
                      Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
                      Key Deleted : HKCU\Software\AppDataLow\Software
                      Key Deleted : HKLM\Software\{1146AC44-2F03-4431-B4FD-889BC837521F}
                      Key Deleted : HKLM\Software\{3A7D3E19-1B79-4E4E-BD96-5467DA2C4EF0}
                      Key Deleted : HKLM\Software\{5F189DF5-2D05-472B-9091-84D9848AE48B}
                      Key Deleted : HKLM\Software\{6791A2F3-FC80-475C-A002-C014AF797E9C}
                      Key Deleted : HKLM\Software\{77D46E27-0E41-4478-87A6-AABE6FBCF252}
                      Key Deleted : HKLM\Software\Agence-Exclusive
                      Key Deleted : HKLM\Software\Boxore
                      Key Deleted : HKLM\Software\Email Notifier
                      Key Deleted : HKLM\Software\Free_soft_today
                      Key Deleted : HKLM\Software\InstallCore
                      Key Deleted : HKLM\Software\mystarttb
                      Key Deleted : HKLM\Software\ScanTack
                      Key Deleted : HKLM\Software\Software
                      Key Deleted : HKLM\Software\SupTab
                      Key Deleted : HKLM\Software\supWPM
                      Key Deleted : HKLM\Software\SystemK
                      Key Deleted : HKLM\Software\systweak
                      Key Deleted : HKLM\Software\Tutorials
                      Key Deleted : HKLM\Software\Uniblue
                      Key Deleted : HKLM\Software\Vittalia
                      Key Deleted : HKLM\Software\webssearchesSoftware
                      Key Deleted : HKLM\Software\Wpm
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyStart Anti-phishing Domain Advisor
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\mystarttb
                      Key Deleted : [x64] HKLM\SOFTWARE\suprasavings
                      Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ScanTack
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bpsvc.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\browsersafeguard.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\dprotectsvc.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\jumpflip
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\protectedsearch.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchinstaller.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotection.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchprotector.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\searchsettings64.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\snapdo.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst32.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\stinst64.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\umbrella.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\utiljumpflip.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\volaro
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\vonteera
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroids.exe
                      Key Deleted : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\websteroidsservice.exe

                      ***** [ Browsers ] *****

                      -\\ Internet Explorer v11.0.9600.17041

                      Setting Restored : HKCU\Software\Microsoft\Internet Explorer\Main [Default_Page_URL]
                      Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
                      Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
                      Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
                      Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]
                      Setting Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [Tabs]
                      Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Search_URL]
                      Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Default_Page_URL]
                      Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Start Page]
                      Setting Restored : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Main [Search Page]

                      -\\ Mozilla Firefox v29.0.1 (fr)

                      [ File : C:\Users\Angelique\AppData\Roaming\Mozilla\Firefox\Profiles\pdx8cb8c.default\prefs.js ]

                      Line Deleted : user_pref("browser.search.order.1", "Mysearchdial");
                      Line Deleted : user_pref("browser.search.selectedEngine", "webssearches");
                      Line Deleted : user_pref("browser.startup.homepage", "hxxp://istart.webssearches.com/?type=hppp&ts=1401337254&from=tugs&uid=3219913727_67194_AC5D76FA");
                      Line Deleted : user_pref("extensions.crossrider.bic", "145b8c349b9ce90bd7960e3003759886");
                      Line Deleted : user_pref("extensions.mysearchdial.aflt", "adk0102");
                      Line Deleted : user_pref("extensions.mysearchdial.appId", "{CA5CAA63-B27C-4963-9BEC-CB16A36D56F8}");
                      Line Deleted : user_pref("extensions.mysearchdial.cntry", "FR");
                      Line Deleted : user_pref("extensions.mysearchdial.dfltLng", "");
                      Line Deleted : user_pref("extensions.mysearchdial.dfltSrch", true);
                      Line Deleted : user_pref("extensions.mysearchdial.dnsErr", true);
                      Line Deleted : user_pref("extensions.mysearchdial.dpkLst", "3654782829,1334533236,1121012847,231756876,1895130307,603719297,4288797614,3754950497,426401714,3046281807,752626116,1657571787,3224935090,2597085128,18285[...]
                      Line Deleted : user_pref("extensions.mysearchdial.dspFFXOld", "");
                      Line Deleted : user_pref("extensions.mysearchdial.excTlbr", false);
                      Line Deleted : user_pref("extensions.mysearchdial.hdrMd5", "A36EFC3C46981DA7393057C88B1CE1A7");
                      Line Deleted : user_pref("extensions.mysearchdial.hmpg", true);
                      Line Deleted : user_pref("extensions.mysearchdial.hmpgUrl", "hxxp://start.mysearchdial.com/?f=1&a=adk0102&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0EtCtDzyyEtB0DyByC0F0AtN0D0Tzu0CzzyDtBtN1L2XzutBtFtBtFtCtFyDyByEtN1L1Czu&cr=1158[...]
                      Line Deleted : user_pref("extensions.mysearchdial.hpFFXOld", "hxxp://istart.webssearches.com/?type=hppp&ts=1399054607&from=tugs&uid=3219913727_67194_AC5D76FA");
                      Line Deleted : user_pref("extensions.mysearchdial.id", "E0CB4E10942D76FA");
                      Line Deleted : user_pref("extensions.mysearchdial.instlDay", "16191");
                      Line Deleted : user_pref("extensions.mysearchdial.instlRef", "");
                      Line Deleted : user_pref("extensions.mysearchdial.lastB", "hxxp://istart.webssearches.com/?type=hppp&ts=1399054607&from=tugs&uid=3219913727_67194_AC5D76FA");
                      Line Deleted : user_pref("extensions.mysearchdial.lastVrsnTs", "23:8:13");
                      Line Deleted : user_pref("extensions.mysearchdial.newTabUrl", "hxxp://start.mysearchdial.com/?f=2&a=adk0102&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0EtCtDzyyEtB0DyByC0F0AtN0D0Tzu0CzzyDtBtN1L2XzutBtFtBtFtCtFyDyByEtN1L1Czu&cr=11[...]
                      Line Deleted : user_pref("extensions.mysearchdial.pnu_base", "{\"newVrsn\":\"96\",\"lastVrsn\":\"96\",\"vrsnLoad\":\"\",\"showMsg\":\"false\",\"showSilent\":\"false\",\"msgTs\":0,\"lstMsgTs\":\"0\"}");
                      Line Deleted : user_pref("extensions.mysearchdial.prdct", "mysearchdial");
                      Line Deleted : user_pref("extensions.mysearchdial.prtnrId", "mysearchdial");
                      Line Deleted : user_pref("extensions.mysearchdial.sg", "none");
                      Line Deleted : user_pref("extensions.mysearchdial.srchPrvdr", "Mysearchdial");
                      Line Deleted : user_pref("extensions.mysearchdial.tlbrId", "base");
                      Line Deleted : user_pref("extensions.mysearchdial.tlbrSrchUrl", "hxxp://start.mysearchdial.com/?f=3&a=adk0102&cd=2XzuyEtN2Y1L1Qzu0EtD0C0ByE0EtCtDzyyEtB0DyByC0F0AtN0D0Tzu0CzzyDtBtN1L2XzutBtFtBtFtCtFyDyByEtN1L1Czu&cr=[...]
                      Line Deleted : user_pref("extensions.mysearchdial.vrsn", "");
                      Line Deleted : user_pref("extensions.mysearchdial.vrsni", "");
                      Line Deleted : user_pref("extensions.mysearchdial_i.hmpg", true);
                      Line Deleted : user_pref("extensions.mysearchdial_i.newTab", false);
                      Line Deleted : user_pref("extensions.mysearchdial_i.smplGrp", "none");
                      Line Deleted : user_pref("extensions.mysearchdial_i.vrsnTs", "23:8:13");
                      Line Deleted : user_pref("keyword.URL", "hxxp://www.mystart.com/results.php?pr=manycam&id=manycamtb&v=5_2&ent=bs____campaignID___&q=");

                      *************************

                      AdwCleaner[R0].txt - [21652 octets] - [29/05/2014 18:51:11]
                      AdwCleaner[S0].txt - [19121 octets] - [29/05/2014 18:52:34]

                      ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [19182 octets] ##########
                      0
                      1. Bonsoir

                        Télécharge AdwCleaner ( d'Xplode ) sur ton bureau.
                        Lance le, clique sur [Scanner] puis patiente le temps du scan.
                        Une fois le scan terminé clique sur le bouton [Nettoyer]
                        Patiente durant le nettoyage. Lis le message qui apparaît, puis clique sur Ok . Le PC va être redémarré automatiquement et le rapport s'ouvrira à la fin du redémarrage.
                        Poste le rapport

                        Note : Le rapport est également sauvegardé sous C:\AdwCleaner[S1].txt

                        A lire :
                        Les programmes potentiellement indésirables :
                        https://www.malekal.com/adwares-pup-protection/

                        Les toolbars, c'est pas obligatoire ( par Malekal ) :https://forum.malekal.com/viewtopic.php?t=6173&start=

                        @+
                        0