Actualité informatique
Test comparatif matériel informatique
Jeux vidéo
Astuces informatique
Vidéo
Télécharger
Services en ligne
Forum informatique
01Business

|-  SECURITE


|||-  

Publicités intempestives avec Chrome [Résolu]

 

43 utilisateurs inconnus
Ajouter une réponse
 

 
Page photos
 
     
Vider la liste des messages à citer
 
 Page :
1
Auteur
 Sujet :

Publicités intempestives avec Chrome [Résolu]

Prévenir les modérateurs en cas d'abus 
nielk
nielk
Sur la bonne voie (de 100 à 499 messages postés)
  1. Posté le 18/07/2011 à 15:31:28  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
Bonjour,

 Depuis quelques jours, mon navigateur Chrome s'ouvre tout seul pour m'afficher des pages de pub (3 à 4 x /jour). C'est arrivé aussi quelque fois avec Internet Explorer.
 J'ai analysé mon PC avec Avast et Spybot qui n'ont rien trouvé d'anormal.
 Mon PC fonctionne normalement, pourtant je soupçonne fortement la présence dans mon système d'un programme malveillant.
 Je me suis donc permis de faire une analyse HiJacThis dont je poste le rapport ci-dessous.
 Au vu de ce rapport, quelqu'un peut-il me dire si j'ai raison de m'inquiéter.

 Merci par avance à qui me répondra.


 Logfile of Trend Micro HijackThis v2.0.4
 Scan saved at 16:47:30, on 18/07/2011
 Platform: Windows 7 SP1 (WinNT 6.00.3505)
 MSIE: Internet Explorer v9.00 (9.00.8112.16421)
 Boot mode: Normal

 Running processes:
 C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
 C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
 C:\Program Files (x86)\iTunes\iTunesHelper.exe
 C:\Program Files (x86)\Windows Searchqu Toolbar\Datamngr\datamngrUI.ex​e
 C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe
 C:\Program Files (x86)\Cobian Backup 10\Cobian.exe
 C:\Program Files\Alwil Software\Avast5\AvastUI.exe
 C:\Program Files (x86)\Agence-Exclusive\pctuto.​exe
 C:\Program Files (x86)\Cobian Backup 10\cbInterface.exe
 c:\Program Files (x86)\Hewlett-Packard\TouchSma​rt\Media\Kernel\CLML\CLMLSvc.e​xe
 C:\Program Files (x86)\IncrediMail\Bin\IncMail.​exe
 C:\Program Files (x86)\IncrediMail\Bin\ImApp.ex​e
 C:\HiJackThis\HijackThis.exe

 R1 - HKCU\Software\Microsoft\Intern​et Explorer\Main,Search Bar = Preserve
 R1 - HKCU\Software\Microsoft\Intern​et Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKCU\Software\Microsoft\Intern​et Explorer\Main,Start Page = http://www.searchqu.com/
 R1 - HKLM\Software\Microsoft\Intern​et Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
 R1 - HKLM\Software\Microsoft\Intern​et Explorer\Main,Default_Search_U​RL = http://go.microsoft.com/fwlink/?LinkId=54896
 R1 - HKLM\Software\Microsoft\Intern​et Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
 R0 - HKLM\Software\Microsoft\Intern​et Explorer\Main,Start Page = http://g.uk.msn.com/HPNOT/3
 R0 - HKLM\Software\Microsoft\Intern​et Explorer\Search,SearchAssistan​t =
 R0 - HKLM\Software\Microsoft\Intern​et Explorer\Search,CustomizeSearc​h =
 R0 - HKLM\Software\Microsoft\Intern​et Explorer\Main,Local Page =
 R1 - HKCU\Software\Microsoft\Window​s\CurrentVersion\Internet Settings,ProxyOverride = *.local
 R0 - HKCU\Software\Microsoft\Intern​et Explorer\Toolbar,LinksFolderNa​me =
 R3 - URLSearchHook: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5​FB39A9C} - C:\Program Files (x86)\Dealio Toolbar\IE\4.5\dealioToolbarIE​.dll
 R3 - URLSearchHook: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A03​0DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\4.4\pdfforgeToolbar​IE.dll
 R3 - URLSearchHook: IncrediMail MediaBar 2 Toolbar - {d40b90b4-d3b1-4d6b-a5d7-dc041​c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\t​bIncr.dll
 F2 - REG:system.ini: UserInit=C:\Windows\system32\u​serinit.exe
 O2 - BHO: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5​FB39A9C} - C:\Program Files (x86)\Dealio Toolbar\IE\4.5\dealioToolbarIE​.dll
 O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695E​CA05670} - (no file)
 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578​C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\Ac​roIEHelperShim.dll
 O2 - BHO: PCTBHO - {293A63F7-C3B6-423a-9845-901AC​0A7EE6E} - C:\Program Files (x86)\Agence-Exclusive\pctutoB​HO.dll
 O2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA​6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEng​ine.dll
 O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live ID - {9030D464-4C02-4ABF-8ECC-51647​60863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
 O2 - BHO: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955​acaa0a7} - C:\PROGRA~2\WIA6EB~1\ToolBar\s​earchqudtx.dll
 O2 - BHO: UrlHelper Class - {A40DC6C5-79D0-4ca8-A185-8FF98​9AF1115} - C:\PROGRA~2\WIA6EB~1\Datamngr\​IEBHO.dll
 O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF105​77473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
 O2 - BHO: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A03​0DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\4.4\pdfforgeToolbar​IE.dll
 O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D​8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolba​r.dll
 O2 - BHO: IncrediMail MediaBar 2 Toolbar - {d40b90b4-d3b1-4d6b-a5d7-dc041​c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\t​bIncr.dll
 O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C​1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
 O2 - BHO: Bandoo IE Plugin - {EB5CEE80-030A-4ED8-8E20-454E9​C68380F} - C:\Program Files (x86)\Bandoo\Plugins\IE\ieplug​in.dll
 O3 - Toolbar: IncrediMail MediaBar 2 Toolbar - {d40b90b4-d3b1-4d6b-a5d7-dc041​c1b76c0} - C:\Program Files (x86)\IncrediMail_MediaBar_2\t​bIncr.dll
 O3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA​6BD249D} - C:\Program Files (x86)\ConduitEngine\ConduitEng​ine.dll
 O3 - Toolbar: MP3 Rocket Toolbar - {D4027C7F-154A-4066-A1AD-4243D​8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolba​r.dll
 O3 - Toolbar: Searchqu Toolbar - {99079a25-328f-4bd4-be04-00955​acaa0a7} - C:\PROGRA~2\WIA6EB~1\ToolBar\s​earchqudtx.dll
 O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-00902​7A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll
 O3 - Toolbar: pdfforge Toolbar - {B922D405-6D13-4A2B-AE89-08A03​0DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\4.4\pdfforgeToolbar​IE.dll
 O3 - Toolbar: Dealio Toolbar - {01398B87-61AF-4FFB-9AB5-1A1C5​FB39A9C} - C:\Program Files (x86)\Dealio Toolbar\IE\4.5\dealioToolbarIE​.dll
 O4 - HKLM\..\Run: [HPCam_Menu] "c:\Program Files (x86)\Hewlett-Packard\Media\We​bcam\MUITransfer\MUIStartMenu.​exe" "c:\Program Files (x86)\Hewlett-Packard\Media\We​bcam" UpdateWithCreateOnce "Software\Hewlett-Packard\Medi​a\Webcam"
 O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
 O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe
 O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
 O4 - HKLM\..\Run: [NeroFilterCheck] C:\Windows\system32\NeroCheck.​exe
 O4 - HKLM\..\Run: [DATAMNGR] C:\PROGRA~2\WIA6EB~1\Datamngr\​DATAMN~1.EXE
 O4 - HKLM\..\Run: [SearchSettings] "C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe"
 O4 - HKLM\..\Run: [iolo Startup] "C:\Program Files (x86)\iolo\Common\Lib\ioloLMan​ager.exe"
 O4 - HKLM\..\Run: [Cobian Backup 10] "C:\Program Files (x86)\Cobian Backup 10\Cobian.exe"
 O4 - HKLM\..\Run: [avast] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
 O4 - HKLM\..\Run: [pctuto] "C:\Program Files (x86)\Agence-Exclusive\pctuto.​exe"
 O4 - HKLM\..\RunOnce: [autoupdater] C:\Users\JM\AppData\Roaming\Ag​ence-Exclusive\Agence-Exclusiv​e\autoupdater.exe -runonce
 O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNoti​fier\GoogleToolbarNotifier.exe​"
 O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
 O4 - HKCU\..\Run: [NBJ] "C:\Program Files (x86)\Ahead\Nero BackItUp\NBJ.exe"
 O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C5​71A8263} - C:\PROGRA~2\MICROS~4\OFFICE11\​REFIEBAR.DLL
 O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
 O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
 O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
 O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/g [...] ontrol.CAB
 O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DA​D9EE203} (GMNRev Class) - http://h20270.www2.hp.com/edia [...] ction2.cab
 O20 - AppInit_DLLs: c:\progra~2\wia6eb~1\datamngr\​datamngr.dll c:\progra~2\wia6eb~1\datamngr\​iebho.dll c:\progra~2\bandoo\bndhook.dll
 O23 - Service: @%SystemRoot%\system32\aelupsv​c.dll,-1 (AeLookupSvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\System32\DriverStor​e\FileRepository\stwrt64.inf_a​md64_neutral_70dacb64382a61a7\​AESTSr64.exe
 O23 - Service: @%SystemRoot%\system32\Alg.exe​,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
 O23 - Service: @%systemroot%\system32\appidsv​c.dll,-100 (AppIDSvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\appinfo​.dll,-100 (Appinfo) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceServi​ce.exe
 O23 - Service: Application Updater - Spigot, Inc. - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe
 O23 - Service: @%SystemRoot%\system32\audiosr​v.dll,-204 (AudioEndpointBuilder) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\audiosr​v.dll,-200 (AudioSrv) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
 O23 - Service: @%SystemRoot%\system32\AxInstS​V.dll,-103 (AxInstSV) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: Bandoo Coordinator - Bandoo Media Inc. - C:\PROGRA~2\Bandoo\Bandoo.exe
 O23 - Service: @%SystemRoot%\system32\bdesvc.​dll,-100 (BDESVC) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\bfe.dll​,-1001 (BFE) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\qmgr.dl​l,-1000 (BITS) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.ex​e
 O23 - Service: @%systemroot%\system32\browser​.dll,-100 (Browser) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\bthserv​.dll,-101 (bthserv) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: Cobian Backup 10 Volume Shadow Copy service (cbVSCService) - CobianSoft, Luis Cobian - C:\Program Files (x86)\Cobian Backup 10\cbVSCService.exe
 O23 - Service: @%SystemRoot%\System32\certpro​p.dll,-11 (CertPropSvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
 O23 - Service: @%SystemRoot%\system32\cryptsv​c.dll,-1001 (CryptSvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @oleres.dll,-5012 (DcomLaunch) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\defrags​vc.dll,-101 (defragsvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\dhcpcor​e.dll,-100 (Dhcp) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\dnsapi.​dll,-101 (Dnscache) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\dot3svc​.dll,-1102 (dot3svc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\dps.dll​,-500 (DPS) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\eapsvc.​dll,-1 (EapHost) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\efssvc.​dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
 O23 - Service: @%SystemRoot%\ehome\ehrecvr.ex​e,-101 (ehRecvr) - Unknown owner - C:\Windows\ehome\ehRecvr.exe
 O23 - Service: @%SystemRoot%\ehome\ehsched.ex​e,-101 (ehSched) - Unknown owner - C:\Windows\ehome\ehsched.exe
 O23 - Service: @%SystemRoot%\system32\wevtsvc​.dll,-200 (eventlog) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @comres.dll,-2450 (EventSystem) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: Easybits Shared Services for Windows (ezSharedSvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\fxsresm​.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
 O23 - Service: @%systemroot%\system32\fdPHost​.dll,-100 (fdPHost) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\fdrespu​b.dll,-100 (FDResPub) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\FntCach​e.dll,-100 (FontCache) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: Service Google Update (gupdate) (gupdate) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpda​te.exe
 O23 - Service: Service Google Update (gupdatem) (gupdatem) - Unknown owner - C:\Program Files (x86)\Google\Update\GoogleUpda​te.exe
 O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.e​xe
 O23 - Service: @%SystemRoot%\System32\hidserv​.dll,-101 (hidserv) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\kmsvc.d​ll,-6 (hkmsvc) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\ListSvc​.dll,-100 (HomeGroupListener) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\provsvc​.dll,-100 (HomeGroupProvider) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: HP Health Check Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
 O23 - Service: HP Quick Synchronization Service (HPDrvMntSvc.exe) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\H​PDrvMntSvc.exe
 O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\h​pqwmiex.exe
 O23 - Service: @%SystemRoot%\system32\ikeext.​dll,-501 (IKEEXT) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: iolo FileInfoList Service (ioloFileInfoList) - iolo technologies, LLC - C:\Program Files (x86)\iolo\Common\Lib\ioloServ​iceManager.exe
 O23 - Service: iolo System Service (ioloSystemService) - iolo technologies, LLC - C:\Program Files (x86)\iolo\Common\Lib\ioloServ​iceManager.exe
 O23 - Service: @%systemroot%\system32\IPBusEn​um.dll,-102 (IPBusEnum) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\iphlpsv​c.dll,-500 (iphlpsvc) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
 O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
 O23 - Service: @comres.dll,-2946 (KtmRm) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\srvsvc.​dll,-100 (LanmanServer) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\wkssvc.​dll,-100 (LanmanWorkstation) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
 O23 - Service: @%SystemRoot%\system32\lltdres​.dll,-1 (lltdsvc) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\lmhsvc.​dll,-101 (lmhosts) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\mmcss.d​ll,-100 (MMCSS) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\Firewal​lAPI.dll,-23090 (MpsSvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
 O23 - Service: @%SystemRoot%\system32\iscsids​c.dll,-5000 (MSiSCSI) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\msimsg.​dll,-27 (msiserver) - Unknown owner - C:\Windows\system32\msiexec.ex​e
 O23 - Service: @%SystemRoot%\system32\qagentr​t.dll,-6 (napagent) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\netlogo​n.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
 O23 - Service: @%SystemRoot%\system32\netman.​dll,-109 (Netman) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\netprof​m.dll,-202 (netprofm) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\nlasvc.​dll,-1 (NlaSvc) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\nsisvc.​dll,-200 (nsi) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
 O23 - Service: @%SystemRoot%\system32\pnrpsvc​.dll,-8004 (p2pimsvc) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\p2psvc.​dll,-8006 (p2psvc) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\pcasvc.​dll,-1 (PcaSvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\sysWow64\perfhos​t.exe,-2 (PerfHost) - Unknown owner - C:\Windows\SysWow64\perfhost.e​xe
 O23 - Service: @%systemroot%\system32\pla.dll​,-500 (pla) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\umpnpmg​r.dll,-100 (PlugPlay) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\pnrpaut​o.dll,-8002 (PNRPAutoReg) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\pnrpsvc​.dll,-8000 (PNRPsvc) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\polstor​e.dll,-5010 (PolicyAgent) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\umpo.dl​l,-100 (Power) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\profsvc​.dll,-300 (ProfSvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\psbase.​dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
 O23 - Service: @%SystemRoot%\system32\qwave.d​ll,-1 (QWAVE) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%Systemroot%\system32\rasauto​.dll,-200 (RasAuto) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%Systemroot%\system32\rasmans​.dll,-200 (RasMan) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @regsvc.dll,-1 (RemoteRegistry) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
 O23 - Service: @%windir%\system32\RpcEpMap.dl​l,-1001 (RpcEptMapper) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\Locator​.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.ex​e (file missing)
 O23 - Service: @oleres.dll,-5010 (RpcSs) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\samsrv.​dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
 O23 - Service: @%SystemRoot%\System32\SCardSv​r.dll,-1 (SCardSvr) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\schedsv​c.dll,-100 (Schedule) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\certpro​p.dll,-13 (SCPolicySvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\sdrsvc.​dll,-107 (SDRSVC) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\seclogo​n.dll,-7001 (seclogon) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\Sens.dl​l,-200 (SENS) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\sensrsv​c.dll,-1000 (SensrSvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\SessEnv​.dll,-1026 (SessionEnv) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\ipnathl​p.dll,-106 (SharedAccess) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\shsvcs.​dll,-12288 (ShellHWDetection) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\snmptra​p.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.e​xe (file missing)
 O23 - Service: @%systemroot%\system32\spoolsv​.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.ex​e (file missing)
 O23 - Service: @%SystemRoot%\system32\sppsvc.​exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
 O23 - Service: @%SystemRoot%\system32\sppuino​tify.dll,-103 (sppuinotify) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\ssdpsrv​.dll,-100 (SSDPSRV) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\sstpsvc​.dll,-200 (SstpSvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: Audio Service (STacSV) - IDT, Inc. - C:\Windows\System32\DriverStor​e\FileRepository\stwrt64.inf_a​md64_neutral_70dacb64382a61a7\​STacSV64.exe
 O23 - Service: @%SystemRoot%\system32\wiaserv​c.dll,-9 (stisvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\swprv.d​ll,-103 (swprv) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\sysmain​.dll,-1000 (SysMain) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\TabSvc.​dll,-100 (TabletInputService) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\tapisrv​.dll,-10100 (TapiSrv) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\tbssvc.​dll,-100 (TBS) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\termsrv​.dll,-268 (TermService) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\themese​rvice.dll,-8192 (Themes) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\mmcss.d​ll,-102 (THREADORDER) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\trkwks.​dll,-1 (TrkWks) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\servicing\Truste​dInstaller.exe,-100 (TrustedInstaller) - Unknown owner - C:\Windows\servicing\TrustedIn​staller.exe
 O23 - Service: @%SystemRoot%\system32\ui0dete​ct.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.​exe (file missing)
 O23 - Service: @%systemroot%\system32\upnphos​t.dll,-213 (upnphost) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\dwm.exe​,-2000 (UxSms) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\vaultsv​c.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
 O23 - Service: @%SystemRoot%\system32\vds.exe​,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
 O23 - Service: @%systemroot%\system32\vssvc.e​xe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
 O23 - Service: @%SystemRoot%\system32\w32time​.dll,-200 (W32Time) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\Wat\Wat​UX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdm​inSvc.exe (file missing)
 O23 - Service: @%systemroot%\system32\wbengin​e.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.e​xe (file missing)
 O23 - Service: @%systemroot%\system32\wbiosrv​c.dll,-100 (WbioSrvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\wcncsvc​.dll,-3 (wcncsvc) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\WcsPlug​InService.dll,-200 (WcsPlugInService) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\wdi.dll​,-502 (WdiServiceHost) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\wdi.dll​,-500 (WdiSystemHost) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\webclnt​.dll,-100 (WebClient) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\wecsvc.​dll,-200 (Wecsvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\wercpls​upport.dll,-101 (wercplsupport) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\wersvc.​dll,-100 (WerSvc) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%ProgramFiles%\Windows Defender\MsMpRes.dll,-103 (WinDefend) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\winhttp​.dll,-100 (WinHttpAutoProxySvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%Systemroot%\system32\wbem\wm​isvc.dll,-205 (Winmgmt) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%Systemroot%\system32\wsmsvc.​dll,-101 (WinRM) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\wlansvc​.dll,-257 (Wlansvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%Systemroot%\system32\wbem\wm​iapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiAp​Srv.exe (file missing)
 O23 - Service: @%SystemRoot%\system32\wpcsvc.​dll,-100 (WPCSvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\wpdbuse​num.dll,-100 (WPDBusEnum) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\wscsvc.​dll,-200 (wscsvc) - Unknown owner - C:\Windows\System32\svchost.ex​e
 O23 - Service: @%systemroot%\system32\SearchI​ndexer.exe,-103 (WSearch) - Unknown owner - C:\Windows\system32\SearchInde​xer.exe
 O23 - Service: @%systemroot%\system32\wuaueng​.dll,-105 (wuauserv) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\system32\wudfsvc​.dll,-1000 (wudfsvc) - Unknown owner - C:\Windows\system32\svchost.ex​e
 O23 - Service: @%SystemRoot%\System32\wwansvc​.dll,-257 (WwanSvc) - Unknown owner - C:\Windows\system32\svchost.ex​e

 --
 End of file - 26413 bytes


La Mayenne-son calme -sa verdu
Profil : Equipe sécurité
  1. homepage
bernard53
Membre impliqué (de 20 000 à 29 999 messages postés) Helpeur confirmé Fan Club de Clic-Clic
  1. Posté le 19/07/2011 à 18:23:25  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
:hello:

 fait ceci.



 Télécharger AD-Remover  (créé par C_XX) :

 http://www.teamxscript.org/adr [...] ement.html

 Cliquez sur "DOWNLOAD " et enregistrez-le "sur votre bureau"

 Une fois téléchargé sur votre bureau, double-cliquez sur son icone pour lancer l'installation.

 Sous vista et Windows7 : clic droit sur son icone et sélectionnez "Exécuter en tant qu'administrateur".
 L'installation se fera automatiquement.

 A l'écran principal, cliquez sur Nettoyer pour exécuter le nettoyage.

 Une fois l'ordinateur redémarré, il ne vous reste plus qu'à copier/coller le rapport sur le forum comme le précédent.
 Le rapport se trouve à cet endroit :   C:\Ad-Report-CLEAN[1].txt

 ensuite.
 Installe Malewarebytes' Antimalware,

 http://malwarebytes.org/products/malwarebytes_free

 Prends bien la version FREE
 *** Met-le à jour puis choisi, Exécuter un examen complet

 *** Si une infection est trouvée, coche la case a coté et valides avec l’Onglet Supprimer la sélection

 Poste le rapport final.

 :salut:

(Publicité)
nielk
Sur la bonne voie (de 100 à 499 messages postés)
  1. Posté le 19/07/2011 à 22:52:42  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
:hello:

 Merci bernard53 pour ton aide. J'ai donc fait ce que tu m'a demandé.

 Voici le (long) rapport AD-Remover :
 


 ======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

 Mis à jour par TeamXscript le 12/04/11
 Contact: AdRemover[DOT]contact[AT]gmail[DOT]com
 Site web: http://www.teamxscript.org

 C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 22:41:17 le 19/07/2011, Mode normal

 Microsoft Windows 7 Édition Familiale Premium  Service Pack 1 (X64)
 JM@PC01 (Hewlett-Packard HP Pavilion dv7 Notebook PC)

 ============== ACTION(S) ==============

 Service: "Application Updater" Stoppé et supprimé
 Service: "Bandoo Coordinator" Stoppé et supprimé

 Dossier supprimé: C:\Program Files (x86)\Windows Searchqu Toolbar
 Dossier supprimé: C:\Users\JM\AppData\Roaming\Mo​zilla\FireFox\Profiles\tov9c1l​t.default\extensions\toolbar@a​sk.com
 Dossier supprimé: C:\Users\JM\AppData\Roaming\Ag​ence-Exclusive
 Dossier supprimé: C:\Users\JM\AppData\Local\Agen​ce-Exclusive
 Dossier supprimé: C:\Program Files (x86)\Agence-Exclusive
 Dossier supprimé: C:\Program Files (x86)\Ask.com
 Dossier supprimé: C:\Users\JM\AppData\Roaming\Ba​ndoo
 Dossier supprimé: C:\ProgramData\Bandoo
 Dossier supprimé: C:\ProgramData\Microsoft\Windo​ws\Start Menu\Programs\Bandoo
 Dossier supprimé: C:\Program Files (x86)\Bandoo
 Dossier supprimé: C:\Users\JM\AppData\LocalLow\C​onduit
 Dossier supprimé: C:\Program Files (x86)\Conduit
 Dossier supprimé: C:\Users\JM\AppData\LocalLow\C​onduitEngine
 Dossier supprimé: C:\Program Files (x86)\ConduitEngine
 Dossier supprimé: C:\Users\JM\AppData\LocalLow\D​ealio
 Dossier supprimé: C:\Program Files (x86)\Dealio Toolbar
 Dossier supprimé: C:\Program Files (x86)\Application Updater
 Dossier supprimé: C:\Users\JM\AppData\LocalLow\p​dfforge
 Dossier supprimé: C:\Program Files (x86)\pdfforge Toolbar
 Dossier supprimé: C:\Users\JM\AppData\LocalLow\S​earch Settings
 Dossier supprimé: C:\Program Files (x86)\Common Files\Spigot
 Dossier supprimé: C:\ProgramData\Microsoft\Windo​ws\Start Menu\Programs\PCTuto
 Dossier supprimé: C:\Program Files (x86)\PCTuto

 (!) -- Fichiers temporaires supprimés.


 Clé supprimée: HKLM\Software\Classes\CLSID\{0​0000000-6E41-4FD3-8538-502F549​5E5FC}
 Clé supprimée: HKLM\Software\Classes\CLSID\{0​1398B87-61AF-4FFB-9AB5-1A1C5FB​39A9C}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Explorer\Brow​ser Helper Objects\{01398B87-61AF-4FFB-9A​B5-1A1C5FB39A9C}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Settings\​{01398B87-61AF-4FFB-9AB5-1A1C5​FB39A9C}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{01​398B87-61AF-4FFB-9AB5-1A1C5FB3​9A9C}
 Clé supprimée: HKLM\Software\Classes\CLSID\{0​74E4EFE-81BB-4EA4-866E-082CB0E​01070}
 Clé supprimée: HKLM\Software\Classes\AppID\{E​DE2C296-2458-4E3B-A846-4B512C0​703B5}
 Clé supprimée: HKLM\Software\Classes\CLSID\{0​CE5B352-9D9C-41E1-9551-FCCD928​20217}
 Clé supprimée: HKLM\Software\Classes\CLSID\{1​67B2B5F-2757-434A-BBDA-2FDB200​3F14F}
 Clé supprimée: HKLM\Software\Classes\CLSID\{2​7F69C85-64E1-43CE-98B5-3C9F22F​B408E}
 Clé supprimée: HKLM\Software\Classes\AppID\{1​301A8A5-3DFB-4731-A162-B357D00​C9644}
 Clé supprimée: HKLM\Software\Classes\CLSID\{2​93A63F7-C3B6-423a-9845-901AC0A​7EE6E}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Explorer\Brow​ser Helper Objects\{293A63F7-C3B6-423a-98​45-901AC0A7EE6E}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Settings\​{293A63F7-C3B6-423a-9845-901AC​0A7EE6E}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{29​3A63F7-C3B6-423a-9845-901AC0A7​EE6E}
 Clé supprimée: HKLM\Software\Classes\CLSID\{2​E9A60EA-5554-49C3-BC9D-D0404DB​ACC62}
 Clé supprimée: HKLM\Software\Classes\CLSID\{3​0F9B915-B755-4826-820B-08FBA6B​D249D}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Explorer\Brow​ser Helper Objects\{30F9B915-B755-4826-82​0B-08FBA6BD249D}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Settings\​{30F9B915-B755-4826-820B-08FBA​6BD249D}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{30​F9B915-B755-4826-820B-08FBA6BD​249D}
 Clé supprimée: HKLM\Software\Classes\CLSID\{3​E63C9BC-DD51-4E83-ABA6-B350EAD​28531}
 Clé supprimée: HKLM\Software\Classes\CLSID\{4​4CFFEF4-E7E1-44BD-B1F5-29F828A​DA1B8}
 Clé supprimée: HKLM\Software\Classes\CLSID\{8​72F3C0B-4462-424c-BB9F-74C6899​B9F92}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Ext\PreApprov​ed\{872F3C0B-4462-424c-BB9F-74​C6899B9F92}
 Clé supprimée: HKLM\Software\Classes\AppID\{9​C123289-82E1-4da7-A3C2-B8D28AA​D114B}
 Clé supprimée: HKLM\Software\Classes\CLSID\{9​9079a25-328f-4bd4-be04-00955ac​aa0a7}
 Clé supprimée: HKLM\Software\Microsoft\Intern​et Explorer\Low Rights\ElevationPolicy\{99079a​25-328f-4bd4-be04-00955acaa0a7​}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Explorer\Brow​ser Helper Objects\{99079a25-328f-4bd4-be​04-00955acaa0a7}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Settings\​{99079a25-328f-4bd4-be04-00955​acaa0a7}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{99​079a25-328f-4bd4-be04-00955aca​a0a7}
 Clé supprimée: HKLM\Software\Classes\CLSID\{A​40DC6C5-79D0-4ca8-A185-8FF989A​F1115}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Explorer\Brow​ser Helper Objects\{A40DC6C5-79D0-4ca8-A1​85-8FF989AF1115}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Settings\​{A40DC6C5-79D0-4ca8-A185-8FF98​9AF1115}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{A4​0DC6C5-79D0-4ca8-A185-8FF989AF​1115}
 Clé supprimée: HKLM\Software\Classes\CLSID\{B​543EF05-9758-464E-9F37-4C28525​B4A4C}
 Clé supprimée: HKLM\Software\Classes\CLSID\{B​922D405-6D13-4A2B-AE89-08A030D​A4402}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Explorer\Brow​ser Helper Objects\{B922D405-6D13-4A2B-AE​89-08A030DA4402}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Settings\​{B922D405-6D13-4A2B-AE89-08A03​0DA4402}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{B9​22D405-6D13-4A2B-AE89-08A030DA​4402}
 Clé supprimée: HKLM\Software\Classes\CLSID\{B​B76A90B-2B4C-4378-8506-9A2B6E1​6943C}
 Clé supprimée: HKLM\Software\Classes\CLSID\{C​12A95F0-7818-443A-88AD-B767453​BB400}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Ext\PreApprov​ed\{C12A95F0-7818-443A-88AD-B7​67453BB400}
 Clé supprimée: HKLM\Software\Classes\CLSID\{C​3AB94A4-BFD0-4BBA-A331-DE504F0​7D2DB}
 Clé supprimée: HKLM\Software\Classes\CLSID\{C​DAACBD8-B898-47AA-88F9-42EE8A1​40C33}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Ext\PreApprov​ed\{CDAACBD8-B898-47AA-88F9-42​EE8A140C33}
 Clé supprimée: HKLM\Software\Classes\CLSID\{C​E1CB632-6817-47b3-8587-D05AF75​D6D5A}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Ext\PreApprov​ed\{CE1CB632-6817-47b3-8587-D0​5AF75D6D5A}
 Clé supprimée: HKLM\Software\Classes\AppID\{3​AD7A5B6-610D-4A82-979E-0AED209​20690}
 Clé supprimée: HKLM\Software\Classes\CLSID\{D​4027C7F-154A-4066-A1AD-4243D81​27440}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Explorer\Brow​ser Helper Objects\{D4027C7F-154A-4066-A1​AD-4243D8127440}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Settings\​{D4027C7F-154A-4066-A1AD-4243D​8127440}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{D4​027C7F-154A-4066-A1AD-4243D812​7440}
 Clé supprimée: HKLM\Software\Classes\CLSID\{D​40B90B4-D3B1-4D6B-A5D7-DC041C1​B76C0}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Explorer\Brow​ser Helper Objects\{D40B90B4-D3B1-4D6B-A5​D7-DC041C1B76C0}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Settings\​{D40B90B4-D3B1-4D6B-A5D7-DC041​C1B76C0}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{D4​0B90B4-D3B1-4D6B-A5D7-DC041C1B​76C0}
 Clé supprimée: HKLM\Software\Classes\CLSID\{E​B5CEE80-030A-4ED8-8E20-454E9C6​8380F}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Explorer\Brow​ser Helper Objects\{EB5CEE80-030A-4ED8-8E​20-454E9C68380F}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Settings\​{EB5CEE80-030A-4ED8-8E20-454E9​C68380F}
 Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{EB​5CEE80-030A-4ED8-8E20-454E9C68​380F}
 Clé supprimée: HKLM\Software\Classes\CLSID\{E​F2B6317-C367-401B-83B8-80302D6​588A7}
 Clé supprimée: HKLM\Software\Classes\CLSID\{F​5379B4B-24D8-432A-9A96-BE75EE5​117DB}
 Clé supprimée: HKLM\Software\Classes\CLSID\{F​7FB2BC4-6C27-4EAC-B5E2-037B71F​DE101}
 Clé supprimée: HKLM\Software\Classes\CLSID\{F​D53FE35-4368-4B71-89D6-F29F3DB​29DF1}
 Clé supprimée: HKLM\Software\Classes\Interfac​e\{33DDFC61-F531-4982-8C32-421​2B7835D44}
 Clé supprimée: HKLM\Software\Classes\Interfac​e\{477F210A-2A86-4666-9C4B-118​9634D2C84}
 Clé supprimée: HKLM\Software\Classes\Interfac​e\{6087829B-114F-42A1-A72B-B4A​EDCEA4E5B}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Ext\PreApprov​ed\{6087829B-114F-42A1-A72B-B4​AEDCEA4E5B}
 Clé supprimée: HKLM\Software\Classes\Interfac​e\{6C434537-053E-486D-B62A-160​059D9D456}
 Clé supprimée: HKLM\Software\Classes\Interfac​e\{91CF619A-4686-4CA4-9232-3B2​E6B63AA92}
 Clé supprimée: HKLM\Software\Classes\Interfac​e\{A9005ED5-4A1D-4606-A4DF-1A2​5E7D7B417}
 Clé supprimée: HKLM\Software\Classes\Interfac​e\{AC71B60E-94C9-4EDE-BA46-E14​6747BB67E}
 Clé supprimée: HKLM\Software\Classes\Interfac​e\{FF871E51-2655-4D06-AED5-745​962A96B32}
 Clé supprimée: HKLM\Software\Classes\TypeLib\​{0BF73E27-2734-4F7B-925A-4BBB1​457F5FA}
 Clé supprimée: HKLM\Software\Classes\TypeLib\​{2996F0E7-292B-4CAE-893F-47B8B​1C05B56}
 Clé supprimée: HKLM\Software\Classes\TypeLib\​{3AD7A5B6-610D-4A82-979E-0AED2​0920690}
 Clé supprimée: HKLM\Software\Classes\TypeLib\​{4410C118-B23C-406C-9F52-9CDAB​D90A5EA}
 Clé supprimée: HKLM\Software\Classes\TypeLib\​{62E5C9E1-A0E8-4F8C-8EAF-0F925​0CC5786}
 Clé supprimée: HKLM\Software\Classes\TypeLib\​{8F5F1CB6-EA9E-40AF-A5CA-C7FD6​3CC1971}
 Clé supprimée: HKLM\Software\Classes\TypeLib\​{9C123289-82E1-4DA7-A3C2-B8D28​AAD114B}
 Clé supprimée: HKLM\Software\Classes\TypeLib\​{CD082CCA-086F-4FD8-8FD7-247A0​DBBD1CC}
 Clé supprimée: HKLM\Software\Classes\BandooCo​ordinator.BandooCoordinator
 Clé supprimée: HKLM\Software\Classes\BandooCo​ordinator.BandooCoordinator.1
 Clé supprimée: HKLM\Software\Classes\BandooCo​ordinator.CoordinatorUI
 Clé supprimée: HKLM\Software\Classes\BandooCo​ordinator.CoordinatorUI.1
 Clé supprimée: HKLM\Software\Classes\BandooCo​ordinator.HTTPAsyncResult
 Clé supprimée: HKLM\Software\Classes\BandooCo​ordinator.HTTPAsyncResult.1
 Clé supprimée: HKLM\Software\Classes\BandooCo​ordinator.PlugInNotifier
 Clé supprimée: HKLM\Software\Classes\BandooCo​ordinator.PlugInNotifier.1
 Clé supprimée: HKLM\Software\Classes\BandooCo​re.BandooCore
 Clé supprimée: HKLM\Software\Classes\BandooCo​re.BandooCore.1
 Clé supprimée: HKLM\Software\Classes\BandooCo​re.ResourcesMngr
 Clé supprimée: HKLM\Software\Classes\BandooCo​re.ResourcesMngr.1
 Clé supprimée: HKLM\Software\Classes\BandooCo​re.SettingsMngr
 Clé supprimée: HKLM\Software\Classes\BandooCo​re.SettingsMngr.1
 Clé supprimée: HKLM\Software\Classes\BandooCo​re.StatisticMngr
 Clé supprimée: HKLM\Software\Classes\BandooCo​re.StatisticMngr.1
 Clé supprimée: HKLM\Software\Classes\BandooIE​Plugin.BandooIEPlugin
 Clé supprimée: HKLM\Software\Classes\BandooIE​Plugin.BandooIEPlugin.1
 Clé supprimée: HKLM\Software\Classes\BFlashAn​imator.BFlashAnimatorCtrl
 Clé supprimée: HKLM\Software\Classes\BFlashAn​imator.BFlashAnimatorCtrl.1
 Clé supprimée: HKLM\Software\Classes\BGIFAnim​ator.BGIFAnimatorCtrl
 Clé supprimée: HKLM\Software\Classes\BGIFAnim​ator.BGIFAnimatorCtrl.1
 Clé supprimée: HKLM\Software\Classes\Conduit.​Engine
 Clé supprimée: HKLM\Software\Classes\GenericA​skToolbar.ToolbarWnd
 Clé supprimée: HKLM\Software\Classes\GenericA​skToolbar.ToolbarWnd.1
 Clé supprimée: HKLM\Software\Classes\Toolbar.​CT2724386
 Clé supprimée: HKLM\Software\Classes\AppID\Ba​ndooCoordinator.EXE
 Clé supprimée: HKLM\Software\Classes\AppID\Ba​ndooCore.EXE
 Clé supprimée: HKLM\Software\Classes\AppID\Ge​nericAskToolbar.DLL
 Clé supprimée: HKLM\Software\Classes\AppID\{9​B0CB95C-933A-4B8C-B6D4-EDCD19A​43874}
 Clé supprimée: HKLM\Software\Application Updater
 Clé supprimée: HKLM\Software\AskToolbar
 Clé supprimée: HKLM\Software\bandoo
 Clé supprimée: HKLM\Software\Conduit
 Clé supprimée: HKLM\Software\conduitEngine
 Clé supprimée: HKLM\Software\DataMngr
 Clé supprimée: HKLM\Software\Dealio
 Clé supprimée: HKLM\Software\pdfforge
 Clé supprimée: HKLM\Software\Search Settings
 Clé supprimée: HKLM\Software\SearchquMediabar​Tb
 Clé supprimée: HKCU\Software\Ask.com
 Clé supprimée: HKCU\Software\DataMngr
 Clé supprimée: HKCU\Software\PopCap
 Clé supprimée: HKCU\Software\AppDataLow\Toolb​ar
 Clé supprimée: HKCU\Software\AppDataLow\Softw​are\AskToolbar
 Clé supprimée: HKCU\Software\AppDataLow\Softw​are\Conduit
 Clé supprimée: HKCU\Software\AppDataLow\Softw​are\conduitEngine
 Clé supprimée: HKCU\Software\AppDataLow\Softw​are\Search Settings
 Clé supprimée: HKLM\Software\Classes\Installe​r\Products\53F25BCB65C42F943A6​DDFDE450B8174
 Clé supprimée: HKLM\Software\Classes\Installe​r\Products\954E46AD3FBFC9A43A8​EDF20044C6E11
 Clé supprimée: HKLM\Software\Classes\Installe​r\Products\A28B4D68DEBAA244EB6​86953B7074FEF
 Clé supprimée: HKCU\Software\Microsoft\Intern​et Explorer\SearchScopes\{8A96AF9​E-4074-43b7-BEA3-87217BDA74C8}
 Clé supprimée: HKLM\Software\Microsoft\Intern​et Explorer\SearchScopes\{8A96AF9​E-4074-43b7-BEA3-87217BDA74C8}
 Clé supprimée: HKCU\Software\Microsoft\Intern​et Explorer\Low Rights\ElevationPolicy\{A5AA24​EA-11B8-4113-95AE-9ED71DEAF12A​}
 Clé supprimée: HKLM\Software\Microsoft\Intern​et Explorer\Low Rights\ElevationPolicy\{424624​F4-C5DD-4e1d-BDD0-1E9C9B7799CC​}
 Clé supprimée: HKLM\Software\Microsoft\Intern​et Explorer\Low Rights\ElevationPolicy\{7f0000​01-db8e-f89c-2fec-49bf726f8c12​}
 Clé supprimée: HKLM\Software\Microsoft\Intern​et Explorer\Low Rights\ElevationPolicy\{9C8A3C​A5-889E-4554-BEEC-EC0876E4E96A​}
 Clé supprimée: HKLM\Software\Microsoft\Intern​et Explorer\Low Rights\ElevationPolicy\{A5AA24​EA-11B8-4113-95AE-9ED71DEAF12A​}
 Clé supprimée: HKLM\Software\Microsoft\Intern​et Explorer\Low Rights\ElevationPolicy\{B08B07​08-E950-4786-A2E4-4F6054C228A7​}
 Clé supprimée: HKLM\Software\Microsoft\Intern​et Explorer\Low Rights\ElevationPolicy\{ECB88F​67-B275-4724-896F-8AB290A32610​}
 Clé supprimée: HKLM\Software\Microsoft\Intern​et Explorer\Low Rights\ElevationPolicy\{F91895​60-573A-4fde-B055-AE7B0F4CF080​}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Uninstall\{86​D4B82A-ABED-442A-BE86-96357B70​F4FE}
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Uninstall\Ban​doo
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Uninstall\con​duitEngine
 Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Uninstall\Sea​rchqu 101 MediaBar

 Valeur supprimée: HKCU\Software\Mozilla\Firefox\​Extensions|ffox@bandoo.com
 Valeur supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Run|PCTuto
 Valeur supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Run|DataMngr
 Valeur supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Run|SearchSet​tings
 Valeur supprimée: HKCU\Software\Microsoft\Intern​et Explorer\URLSearchHooks|{01398​B87-61AF-4FFB-9AB5-1A1C5FB39A9​C}
 Valeur supprimée: HKLM\Software\Microsoft\Intern​et Explorer\Toolbar|{D4027C7F-154​A-4066-A1AD-4243D8127440}
 Valeur supprimée: HKLM\Software\Microsoft\Intern​et Explorer\Toolbar|{B922D405-6D1​3-4A2B-AE89-08A030DA4402}
 Valeur supprimée: HKLM\Software\Microsoft\Intern​et Explorer\Toolbar|{01398B87-61A​F-4FFB-9AB5-1A1C5FB39A9C}
 Valeur supprimée: HKLM\Software\Microsoft\Intern​et Explorer\Toolbar|{30F9B915-B75​5-4826-820B-08FBA6BD249D}


 ============== SCAN ADDITIONNEL ==============

 -- C:\Users\JM\AppData\Roaming\Mo​zilla\FireFox\Profiles\tov9c1l​t.default --
 Extensions\ffox@bandoo.com (Bandoo for Firefox)
 Searchplugins\MyStart Search.xml (?)
 Prefs.js - browser.search.defaultenginena​me, MyStart Rechercher
 Prefs.js - browser.search.selectedEngine, MyStart Rechercher
 Prefs.js - browser.startup.homepage, hxxp://mystart.incredimail.com​/
 Prefs.js - browser.startup.homepage_overr​ide.mstone, rv:1.9.1.9
 Prefs.js - keyword.URL, hxxp://mystart.incredimail.com​/?loc=ff_address_bar_fs_IM2_TE​ST&search=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo
 Prefs.js - browser.search.selectedEngine, Yahoo
 Prefs.js - keyword.URL, hxxp://search.yahoo.com/search​?ei=utf-8&fr=greentree_ff1&typ​e=302398&p=
 Prefs.js - browser.search.defaultenginena​me, Yahoo

nielk
Sur la bonne voie (de 100 à 499 messages postés)
  1. Posté le 20/07/2011 à 07:32:53  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
Et voici le log Malewarebytes que je n'ai pas réussi à mettre sur le même post :


 Malwarebytes' Anti-Malware 1.51.1.1800
 www.malwarebytes.org

 Version de la base de données: 7205

 Windows 6.1.7601 Service Pack 1
 Internet Explorer 9.0.8112.16421

 20/07/2011 00:33:57
 mbam-log-2011-07-20 (00-33-57).txt

 Type d'examen: Examen complet (C:\|D:\|E:\|)
 Elément(s) analysé(s): 373192
 Temps écoulé: 55 minute(s), 38 seconde(s)

 Processus mémoire infecté(s): 0
 Module(s) mémoire infecté(s): 0
 Clé(s) du Registre infectée(s): 0
 Valeur(s) du Registre infectée(s): 0
 Elément(s) de données du Registre infecté(s): 0
 Dossier(s) infecté(s): 0
 Fichier(s) infecté(s): 1

 Processus mémoire infecté(s):
 (Aucun élément nuisible détecté)

 Module(s) mémoire infecté(s):
 (Aucun élément nuisible détecté)

 Clé(s) du Registre infectée(s):
 (Aucun élément nuisible détecté)

 Valeur(s) du Registre infectée(s):
 (Aucun élément nuisible détecté)

 Elément(s) de données du Registre infecté(s):
 (Aucun élément nuisible détecté)

 Dossier(s) infecté(s):
 (Aucun élément nuisible détecté)

 Fichier(s) infecté(s):
 c:\program files (x86)\ad-remover\quarantine\C\​Users\JM\AppData\Roaming\agenc​e-exclusive\agence-exclusive\u​pdatepctuto.exe.vir (PUP.Tuto4PC) -> Quarantined and deleted successfully.

La Mayenne-son calme -sa verdu
Profil : Equipe sécurité
  1. homepage
bernard53
Membre impliqué (de 20 000 à 29 999 messages postés) Helpeur confirmé Fan Club de Clic-Clic
  1. Posté le 20/07/2011 à 10:52:11  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
:hello:

 :super:

 juste ceci pour contrôle s.t.p


 * Télécharge >> OTL <<sur ton bureau.

 * Fait un double-clic sur l'icône d'OTL pour le lancer
 /!\ pour Vista/Seven fais un clic-droit sur l'icône d'OTL et choisis "Exécuter en tant qu'administrateur"

 * Assure-toi d'avoir fermé toutes les applications en court de fonctionnement.

 * Quand la fenêtre d'OTL apparaît, assure toi que dans la section "Rapport" (en haut à droite) la case "Rapport minimal " soit cochée.

 * Copies et colles le contenue de cette citation dans la partie inférieure d'OTL " Personnalisation"
 



 
 netsvcs
 %SYSTEMDRIVE%\*.exe
 /md5start
 eventlog.dll
 scecli.dll
 netlogon.dll
 cngaudit.dll
 sceclt.dll
 ntelogon.dll
 logevent.dll
 iaStor.sys
 nvstor.sys
 atapi.sys
 IdeChnDr.sys
 viasraid.sys
 AGP440.sys
 vaxscsi.sys
 nvatabus.sys
 viamraid.sys
 nvata.sys
 nvgts.sys
 iastorv.sys
 ViPrt.sys
 eNetHook.dll
 ahcix86.sys
 KR10N.sys
 vstor32.sys
 ahcix86s.sys
 nvrd32.sys
 /md5stop
 %systemroot%\*. /mp /s
 %systemroot%\system32\*.dll /lockedfiles
 %systemroot%\Tasks\*.job /lockedfiles
 



 * Cliques sur l'icône "Analyse" (en haut à gauche) .
 * Laisse le scan aller à son terme sans te servir du PC
 * A la fin du scan un ou deux rapports vont s'ouvrir "OTL.Txt" et ( ou ) "Extras.Txt"( dans certains cas).
 * Copie et colle le ou les rapports dans ta réponse stp...
 * Au cas où, tu peux les retrouver dans le dossier C:\OTL ou sur ton bureau en fonction des cas rencontrés
 Mets le rapport ici car il prend bien de la place.
 http://mydoc.tk
 ou la
 http://www.cijoint.fr/index.php


(Publicité)
Entraide et convivialité
  1. homepage
herisson41
Membre impliqué (de 20 000 à 29 999 messages postés) Fan Club de Clic-Clic Maître smilies
  1. Posté le 20/07/2011 à 20:30:34  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
:hello:

 Je déplace dans la catégorie "Questions diverses" sous-catégorie "Sécurité"


---------------
A consulter :
[:gepetest:4] Club des fans de Clic-Clic [:gepetest:4] Index en ligne de Micro Hebdo
.. [:gepetest3] ....   Répertoire des tutoriels   ..... [:gepetest3] ..... Calendrier des anniversaires
nielk
Sur la bonne voie (de 100 à 499 messages postés)
  1. Posté le 20/07/2011 à 23:12:11  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
Voila c'est fait.

 Voici le lien pour le rapport OTL

 http://mydoc.tk/3/1650OTL.Txt

 bonne journée.

La Mayenne-son calme -sa verdu
Profil : Equipe sécurité
  1. homepage
bernard53
Membre impliqué (de 20 000 à 29 999 messages postés) Helpeur confirmé Fan Club de Clic-Clic
  1. Posté le 21/07/2011 à 11:09:31  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
:hello:



 * Fait un double-clic sur l'icône d'OTL pour le lancer
 /!\ pour Vista/Seven fais un clic-droit sur l'icône d'OTL et choisis "Exécuter en tant qu'administrateur"

 * Assure-toi d'avoir fermé toutes les applications en court de fonctionnement.

 * Quand la fenêtre d'OTL apparaît, assure toi que dans la section "Rapport" (en haut à droite) la case " Rapport minimal" soit cochée.

 * Copies et colles le contenue de cette citation dans la partie inférieure d'OTL "Personnalisation"
 



 
 :OTL
 IE - HKLM\..\URLSearchHook: {d40b90b4-d3b1-4d6b-a5d7-dc041​c1b76c0} - Reg Error: Key error. File not found  
 IE - HKCU\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A03​0DA4402} - Reg Error: Key error. File not found  
 IE - HKCU\..\URLSearchHook: {d40b90b4-d3b1-4d6b-a5d7-dc041​c1b76c0} - Reg Error: Key error. File not found
 FF - prefs.js..browser.startup.home​page: "http://mystart.incredimail.co​m/"  
 FF - prefs.js..keyword.URL: http://mystart.incredimail.com [...] ST&search=
 FF - HKLM\Software\MozillaPlugins\@​microsoft.com/GENUINE: disabled File not found
 FF - HKLM\Software\MozillaPlugins\@​Apple.com/iTunes,version=:  File not found
 FF - HKLM\Software\MozillaPlugins\@​microsoft.com/GENUINE: disabled File not found
 [2010/05/03 23:26:04 | 000,002,042 | ---- | M] () -- C:\Users\JM\AppData\Roaming\Mo​zilla\Firefox\Profiles\tov9c1l​t.default\searchplugins\MyStar​t Search.xml
 O2 - BHO: (UrlHelper Class) - {A40DC6C5-79D0-4ca8-A185-8FF98​9AF1115} -  File not found
 O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
 O3 - HKLM\..\Toolbar: (no name) - {99079a25-328f-4bd4-be04-00955​acaa0a7} - No CLSID value found.    
 O3 - HKLM\..\Toolbar: (no name) - {d40b90b4-d3b1-4d6b-a5d7-dc041​c1b76c0} - No CLSID value found.  
 O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
 O2 - BHO: (no name) - {DBC80044-A445-435b-BC74-9C25C​1C588A9} - No CLSID value found.  
 O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695E​CA05670} - No CLSID value found.
 O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {21FA44EF-376D-4D53-9B0F-8A89D​3229068} - No CLSID value found.
 O4 - HKLM\..\Run: []  File not found
 O4 - HKLM\..\Run: [Memoire]  File not found
 O18 - Protocol\Handler\msdaipp - No CLSID value found
 O20 - AppInit_DLLs: (C:\PROGRA~2\WIA6EB~1\Datamngr​\x64\datamngr.dll) -  File not found  
 O20 - AppInit_DLLs: (C:\PROGRA~2\WIA6EB~1\Datamngr​\x64\IEBHO.dll) -  File not found
 [2011/07/18 15:32:34 | 000,000,000 | ---D | C] -- C:\HiJackThis  
 [2011/05/08 12:08:29 | 001,524,112 | ---- | C] () -- C:\Windows\SysWow64\bandoolmx.​dll    
 :Commands
 [emptytemp]
 



 * Cliques sur l'icône Correction (en haut à gauche) .
 * Laisse le scan aller à son terme sans te servir du PC
 * A la fin du scan un rapport s'ouvrir "OTL.log"
 * Copie et colle le ou les rapports dans ta réponse stp...
 * Au cas où, tu peux les retrouver dans le dossier C:\OTL ou sur ton bureau en fonction des cas rencontrés
 Mets le rapport ici car il prend bien de la place.
 http://mydoc.tk
 ou la
 http://www.cijoint.fr/index.php

 Après dis moi comment va ton pc s.t.p

(Publicité)
nielk
Sur la bonne voie (de 100 à 499 messages postés)
  1. Posté le 21/07/2011 à 12:46:42  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
:hello:

 J'ai fait ce que tu m'as demandé dans ton dernier post.
 Voici le rapport qui s'est affiché sur mon bureau après l'analyse.

 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~​~~~~~~~~~
 All processes killed
 ========== OTL ==========
 Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Mi​crosoft\Internet Explorer\URLSearchHooks\\{d40b​90b4-d3b1-4d6b-a5d7-dc041c1b76​c0} deleted successfully.
 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Cl​asses\CLSID\{d40b90b4-d3b1-4d6​b-a5d7-dc041c1b76c0}\ not found.
 Registry value HKEY_CURRENT_USER\SOFTWARE\Mic​rosoft\Internet Explorer\URLSearchHooks\\{B922​D405-6D13-4A2B-AE89-08A030DA44​02} deleted successfully.
 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Cl​asses\CLSID\{B922D405-6D13-4A2​B-AE89-08A030DA4402}\ not found.
 Registry value HKEY_CURRENT_USER\SOFTWARE\Mic​rosoft\Internet Explorer\URLSearchHooks\\{d40b​90b4-d3b1-4d6b-a5d7-dc041c1b76​c0} deleted successfully.
 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Cl​asses\CLSID\{d40b90b4-d3b1-4d6​b-a5d7-dc041c1b76c0}\ not found.
 Prefs.js: "http://mystart.incredimail.co​m/" removed from browser.startup.homepage
 Prefs.js: http://mystart.incredimail.com [...] ST&search= removed from keyword.URL
 Registry key HKEY_LOCAL_MACHINE\Software\Mo​zillaPlugins\@microsoft.com/GE​NUINE\ deleted successfully.
 Registry key HKEY_LOCAL_MACHINE\Software\Mo​zillaPlugins\@Apple.com/iTunes​,version=\ deleted successfully.
 Registry key HKEY_LOCAL_MACHINE\Software\Mo​zillaPlugins\@microsoft.com/GE​NUINE\ not found.
 C:\Users\JM\AppData\Roaming\Mo​zilla\Firefox\Profiles\tov9c1l​t.default\searchplugins\MyStar​t Search.xml moved successfully.
 Registry key HKEY_LOCAL_MACHINE\Software\Mi​crosoft\Windows\CurrentVersion​\Explorer\Browser Helper Objects\{A40DC6C5-79D0-4ca8-A1​85-8FF989AF1115}\ not found.
 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Cl​asses\CLSID\{A40DC6C5-79D0-4ca​8-A185-8FF989AF1115}\ not found.
 Registry value HKEY_LOCAL_MACHINE\Software\Mi​crosoft\Internet Explorer\Toolbar\\10 deleted successfully.
 Registry value HKEY_LOCAL_MACHINE\Software\Mi​crosoft\Internet Explorer\Toolbar\\{99079a25-32​8f-4bd4-be04-00955acaa0a7} deleted successfully.
 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Cl​asses\CLSID\{99079a25-328f-4bd​4-be04-00955acaa0a7}\ not found.
 Registry value HKEY_LOCAL_MACHINE\Software\Mi​crosoft\Internet Explorer\Toolbar\\{d40b90b4-d3​b1-4d6b-a5d7-dc041c1b76c0} deleted successfully.
 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Cl​asses\CLSID\{d40b90b4-d3b1-4d6​b-a5d7-dc041c1b76c0}\ not found.
 Registry value HKEY_LOCAL_MACHINE\Software\Mi​crosoft\Internet Explorer\Toolbar\\10 not found.
 Registry key HKEY_LOCAL_MACHINE\Software\Mi​crosoft\Windows\CurrentVersion​\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC​74-9C25C1C588A9}\ deleted successfully.
 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Cl​asses\CLSID\{DBC80044-A445-435​b-BC74-9C25C1C588A9}\ deleted successfully.
 Registry key HKEY_LOCAL_MACHINE\Software\Mi​crosoft\Windows\CurrentVersion​\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B​51-7695ECA05670}\ deleted successfully.
 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Cl​asses\CLSID\{02478D38-C3F9-4ef​b-9B51-7695ECA05670}\ not found.
 Registry value HKEY_CURRENT_USER\Software\Mic​rosoft\Internet Explorer\Toolbar\WebBrowser\\{​21FA44EF-376D-4D53-9B0F-8A89D3​229068} deleted successfully.
 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Cl​asses\CLSID\{21FA44EF-376D-4D5​3-9B0F-8A89D3229068}\ not found.
 Registry key HKEY_LOCAL_MACHINE\\Software\M​icrosoft\Windows\CurrentVersio​n\Run not found.
 Registry key HKEY_LOCAL_MACHINE\\Software\M​icrosoft\Windows\CurrentVersio​n\Run not found.
 Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Cl​asses\PROTOCOLS\Handler\msdaip​p\ deleted successfully.
 File Protocol\Handler\msdaipp - No CLSID value found not found.
 Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Mi​crosoft\Windows NT\CurrentVersion\Windows\\App​Init_Dlls:C:\PROGRA~2\WIA6EB~1​\Datamngr\x64\datamngr.dll deleted successfully.
 Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Mi​crosoft\Windows NT\CurrentVersion\Windows\\App​Init_Dlls:C:\PROGRA~2\WIA6EB~1​\Datamngr\x64\IEBHO.dll deleted successfully.
 C:\HiJackThis folder moved successfully.
 C:\Windows\SysWOW64\bandoolmx.​dll moved successfully.
 ========== COMMANDS ==========

 [EMPTYTEMP]

 User: Administrator
 ->Temp folder emptied: 0 bytes

 User: All Users

 User: Default
 ->Temp folder emptied: 0 bytes
 ->Temporary Internet Files folder emptied: 33170 bytes
 ->Flash cache emptied: 56504 bytes

 User: Default User
 ->Temp folder emptied: 0 bytes
 ->Temporary Internet Files folder emptied: 0 bytes
 ->Flash cache emptied: 0 bytes

 User: JM
 ->Temp folder emptied: 178294 bytes
 ->Temporary Internet Files folder emptied: 11065254 bytes
 ->Java cache emptied: 33127312 bytes
 ->FireFox cache emptied: 30121692 bytes
 ->Google Chrome cache emptied: 8899126 bytes
 ->Flash cache emptied: 57113 bytes

 User: Public

 %systemdrive% .tmp files removed: 0 bytes
 %systemroot% .tmp files removed: 0 bytes
 %systemroot%\System32 .tmp files removed: 0 bytes
 %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
 %systemroot%\System32\drivers .tmp files removed: 0 bytes
 Windows Temp folder emptied: 582412 bytes
 %systemroot%\sysnative\config\​systemprofile\AppData\Local\Mi​crosoft\Windows\Temporary Internet Files folder emptied: 67910 bytes
 %systemroot%\sysnative\config\​systemprofile\AppData\LocalLow​\Sun\Java\Deployment folder emptied: 749 bytes
 RecycleBin emptied: 2147200 bytes

 Total Files Cleaned = 82,00 mb


 OTL by OldTimer - Version 3.2.26.1 log created on 07212011_141754

 Files\Folders moved on Reboot...
 C:\Users\JM\AppData\Local\Temp​\FXSAPIDebugLogFile.txt moved successfully.
 File move failed. C:\Windows\temp\_avast_\Webshl​ock.txt scheduled to be moved on reboot.
 File\Folder C:\Windows\temp\fb_3256.lck not found!

 Registry entries deleted on Reboot...
 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~​~~~~~~~~~



 Pour ce qui est de l'état de santé de mon PC, j'ai constaté 2 choses bien distinctes :

 1 - Je ne reçois plus de pub intempestives qui ouvraient mon navigateur Chrome.

 2 - Mon lecteur VLC fonctionne à nouveau correctement, alors qu'avant le nettoyage il refusait de lire les flux TV free. Ce dernier point a d'ailleurs fait l'objet d'un sujet dans ce forum :

 http://forum.telecharger.01net [...] ost5733291

 Mais dis moi, de quel type d'infection ais-je été victime et ou peut-on attraper ce genre de truc. Au vu des rapports je ne comprend pas grand chose, pour ne pas dire rien du tout.

 En tout cas, merci encore pour ton aide qui m'a été très précieuse.  :bien:



La Mayenne-son calme -sa verdu
Profil : Equipe sécurité
  1. homepage
bernard53
Membre impliqué (de 20 000 à 29 999 messages postés) Helpeur confirmé Fan Club de Clic-Clic
  1. Posté le 21/07/2011 à 17:52:35  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
:hello:

 Bonne nouvelle  :bien:


 Fait ceci pour supprimer les logiciels qui ont servis à cette désinfection.

 Télécharge << DelFix >> de Xplode  pour supprimer les logiciels qui ont servis a cette désinfection.


 * Lance-le.

 * A l'invite, [Suppression] ()

 * Un rapport va s'ouvrir à la fin, colle le dans la réponse

 Ensuite pour le désinstaller ; tu relances et tu passes à l'option [Désinstallation]

 Ensuite::

 Bon maintenant on va mettre la restauration du système propre.
 Pour cela:

 1- Valides les touches Windows et Pause en même temps.

 Puis   Protection du système

 Sur cette fenêtre décoches la  case  concernant le DD ou est installé ton système normalement C:

 Valide et acceptes les demandes suivantes.

 ***Pour Windows 7** il faut valider l'onglet Configurer puis valider la désactivation de la restauration.

 **Toujours sur cette même fenêtre : Il te faut donc maintenant recrée un nouveau point de restauration.

 Coche cette même case et valides cela par l’onglet APPLIQUER  puis onglet « CREER »

 Nommes ce  point  PC- Clean: Valides.

 Vous pouvez maintenant fermer toutes les fenêtres.

 Ensuite:: tu peux donc valider ton post concernant VLC en résolu.

 Pour ton infection tu as été pris en partie au piège avec le genre de site comme  TUTO4PC

 http://forum.telecharger.01net [...] ges-1.html

 Donc faire très attention quand on teste ou installe un logiciel. Toujours si on peux prendre le site officiel de l’Éditeur.
 :bien:

 Bonne soirée.

 :edit  Clique sur [URL= http://nsa25.casimages.com/img​/2011/03/20/110320073738806724​.jpg en bas de ton message  puis à la suite de ton titre marque : RESOLU

nielk
Sur la bonne voie (de 100 à 499 messages postés)
  1. Posté le 21/07/2011 à 19:47:22  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
Voici le log DelFix


 # DelFix v8.1 - Rapport créé le 21/07/2011 à 21:16
 # Mis à jour le 20/06/11 à 19h par Xplode
 # Système d'exploitation : Windows 7 Home Premium (64 bits) [version 6.1.7601]
 # Nom d'utilisateur : JM - PC01 (Administrateur)
 # Exécuté depuis : C:\Users\JM\Desktop\delfix.exe
 # Option [Suppression]


 ~~~~~~ Dossier(s) ~~~~~~

 Supprimé : C:\_OTL
 Supprimé : C:\Program Files (x86)\Ad-Remover

 ~~~~~~ Fichier(s) ~~~~~~

 Supprimé : C:\Ad-Report-CLEAN[1].txt
 Supprimé : C:\Users\JM\Desktop\AD-R.lnk
 Supprimé : C:\Users\JM\Desktop\Extras.Txt
 Supprimé : C:\Users\JM\Desktop\OTL.exe
 Supprimé : C:\Users\JM\Desktop\OTL.Txt

 ~~~~~~ Registre ~~~~~~

 Clé Supprimée : HKCU\SOFTWARE\Ad-Remover
 Clé Supprimée : HKLM\Software\OldTimer Tools
 Clé Supprimée : HKLM\Software\Microsoft\Window​s\CurrentVersion\Uninstall\Ad-​Remover

 ~~~~~~ Autre ~~~~~~

 -> Prefetch vidé

 ########## EOF - "C:\DelFixSuppr.txt" - [988 octets] ##########


 Merci encore une fois pour ton aide.

 Je ne sais pas comment j'ai fait pour attraper ce TUTO4PC. En règle général, je n'installe que des logiciels venant du site de l'éditeur ou alors de Télécharger.com. Peut-être une PJ à un mél  :chepa:

 En tout cas mille merci de m'avoir consacré une partie de ton temps. :bien:

 Au plaisir de te relire.

 :salut:

(Publicité)
La Mayenne-son calme -sa verdu
Profil : Equipe sécurité
  1. homepage
bernard53
Membre impliqué (de 20 000 à 29 999 messages postés) Helpeur confirmé Fan Club de Clic-Clic
  1. Posté le 22/07/2011 à 10:54:13  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
:hello:

 :jap:

 :salut:

lala20
  1. Posté le 08/11/2013 à 23:34:16  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
======= RAPPORT D'AD-REMOVER 2.0.0.2,G | UNIQUEMENT XP/VISTA/7 =======

Mis à jour par TeamXscript le 12/04/11
Contact: AdRemover[dot]contact[at]gmail[dot]com
Site web: http://www.teamxscript.org

C:\Program Files (x86)\Ad-Remover\main.exe (CLEAN [1]) -> Lancé à 23:15:35 le 08/11/2013, Mode normal

Microsoft Windows 8 (X64)
Leila@VAIO (Sony Corporation SVE1513B1EW)
============== ACTION(S) ==============


Dossier supprimé: C:\Users\Leila\AppData\Roaming​\OpenCandy
Dossier supprimé: C:\Users\Leila\AppData\Roaming​\pdfforge
Dossier supprimé: C:\ProgramData\Microsoft\Windo​ws\Start Menu\Programs\PriceGong
Dossier supprimé: C:\Program Files (x86)\PriceGong

(!) -- Fichiers temporaires supprimés.


Clé supprimée: HKLM\Software\Classes\CLSID\{1​631550F-191D-4826-B069-D943925​3D926}
Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Explorer\Brow​ser Helper Objects\{1631550F-191D-4826-B0​69-D9439253D926}
Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Settings\​{1631550F-191D-4826-B069-D9439​253D926}
Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{16​31550F-191D-4826-B069-D9439253​D926}
Clé supprimée: HKLM\Software\Classes\AppID\{8​35315FC-1BF6-4CA9-80CD-F6C158D​40692}
Clé supprimée: HKLM\Software\Classes\CLSID\{D​2A2595C-4FE4-4315-AA9B-19DBD62​71B71}
Clé supprimée: HKLM\Software\Classes\CLSID\{e​c2bae47-25af-4ce9-9e78-10627a4​9c9ea}
Clé supprimée: HKLM\Software\Microsoft\Intern​et Explorer\Low Rights\ElevationPolicy\{ec2bae​47-25af-4ce9-9e78-10627a49c9ea​}
Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Explorer\Brow​ser Helper Objects\{ec2bae47-25af-4ce9-9e​78-10627a49c9ea}
Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Settings\​{ec2bae47-25af-4ce9-9e78-10627​a49c9ea}
Clé supprimée: HKCU\Software\Microsoft\Window​s\CurrentVersion\Ext\Stats\{ec​2bae47-25af-4ce9-9e78-10627a49​c9ea}
Clé supprimée: HKLM\Software\Classes\Interfac​e\{79FB5FC8-44B9-4AF5-BADD-CCE​547F953E5}
Clé supprimée: HKLM\Software\Classes\Interfac​e\{7D86A08B-0A8F-4BE0-B693-F05​E6947E780}
Clé supprimée: HKLM\Software\Classes\Interfac​e\{935B5B76-ABBD-407D-B5E1-AAC​ADF5045E6}
Clé supprimée: HKLM\Software\Classes\TypeLib\​{8B3372D0-09F0-41A5-8D9B-134E1​48672FB}
Clé supprimée: HKLM\Software\Classes\PriceFac​torIE.PriceGongBHO
Clé supprimée: HKLM\Software\Classes\PriceFac​torIE.PriceGongBHO.1
Clé supprimée: HKLM\Software\Classes\PriceGon​gIE.PriceGongCtrl
Clé supprimée: HKLM\Software\Classes\PriceGon​gIE.PriceGongCtrl.1
Clé supprimée: HKLM\Software\Classes\AppID\Pr​iceGongIE.DLL
Clé supprimée: HKLM\Software\DataMngr
Clé supprimée: HKCU\Software\DataMngr
Clé supprimée: HKCU\Software\AppDataLow\Softw​are\PriceGong
Clé supprimée: HKLM\Software\Classes\Installe​r\Products\14053424D2337365007​A7A857BC07000
Clé supprimée: HKCU\Software\Microsoft\Intern​et Explorer\SearchScopes\{014DB5F​A-EAFB-4592-A95B-F44D3EE87FA9}
Clé supprimée: HKLM\Software\Microsoft\Window​s\CurrentVersion\Uninstall\pri​cegong

Valeur supprimée: HKCU\Software\Mozilla\Firefox\​Extensions|{8a9386b4-e958-4c4c​-adf4-8f26db3e4829}


============== SCAN ADDITIONNEL ==============

**** Google Chrome Version [30.0.1599.101] ****

Extension\aaaaabcbmongicmdegkm​mfgdickgnnob (C:\Users\Leila\AppData\Local\​ilividmoviestoolbardla\GC\tool​bar.crx) (?)
Extension\aaaaiopnfecjheficjcj​fgjecfgdhbmc (C:\ProgramData\AskPartnerNetw​ork\Toolbar\BCPA3-V7\CRX\Toolb​arCR.crx) (?)
Extension\bkomkajifikmkfnjgphk​jcfeepbnojok (C:\Program Files (x86)\PriceGong\2.6.12\pricego​ng.crx) (x)
Extension\ccncljhbalbbkkfgopog​abimepmfkmff (C:\Program Files (x86)\BatBrowse\ccncljhbalbbkk​fgopogabimepmfkmff.crx) (?)
Extension\doobfiogmfmpjnoofjhh​gjehmlofngfp (C:\Users\Leila\AppData\Local\​metacrawler-speeddial.crx) (?)
Extension\jpmbfleldcgkldadpdin​hjjopdfpjfjp (C:\Users\Leila\AppData\Local\​Wajam\Chrome\wajam.crx) (?)
Extension\kbjlipmgfoamgjaogmbi​haffnpkpjajp (C:\Program Files (x86)\Nosibay\Bubble Dock\extensions\GCSurfMatch.cr​x) (?)
Extension\kiplfnciaokpcennlkld​kdaeaaomamof (C:\Users\Leila\AppData\Local\​Torch\Plugins\TorchPlugin.crx) (?)
Extension\ogccgbmabaphcakpiclg​cnmcnimhokcj (C:\Windows\SysWOW64\jmdp\Swee​tNT.crx) (?)

-- C:\Users\Leila\AppData\Local\G​oogle\Chrome\User Data\Default --
Preferences - default_search_provider: "Conduit Search" (Activé: true) (?)
Preferences - homepage: hxxp://search.conduit.com/?cti​d=CT3317919&amp;octid=EB_ORIGI​NAL_CTID&amp;SearchSource=55&a​mp;CUI=&amp;UM=2&amp;UP=SP4BF1​1B4F-004A-...
Preferences - homepage_is_newtabpage: false
Preferences - urls_to_restore_on_startup: hxxp://search.conduit.com/?cti​d=CT3317919&amp;octid=EB_ORIGI​NAL_CTID&amp;SearchSource=55&a​mp;CUI=&amp;UM=2&amp;...

==============================​==========

**** Internet Explorer Version [9.10.9200.16721] ****

IEXPLORE.EXE\Shell\Open\Comman​d - C:\Program Files\Internet Explorer\iexplore.exe http://www.qvo6.com/?utm_sourc [...] 1372585483
HKCU_Main|Default_Page_URL - hxxp://www.microsoft.com/isapi​/redir.dll?prd=ie&amp;pver=6&a​mp;ar=msnhome
HKCU_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi​/redir.dll?prd=ie&amp;ar=iesea​rch
HKCU_Main|Search bar - hxxp://go.microsoft.com/fwlink​/?linkid=54896
HKCU_Main|Start Page - hxxp://fr.msn.com/
HKLM_Main|Default_Page_URL - hxxp://go.microsoft.com/fwlink​/?LinkId=54896
HKLM_Main|Default_Search_URL - hxxp://www.microsoft.com/isapi​/redir.dll?prd=ie&amp;ar=iesea​rch
HKLM_Main|Search bar - hxxp://search.msn.com/spbasic.​htm
HKLM_Main|Search Page - hxxp://www.microsoft.com/isapi​/redir.dll?prd=ie&amp;ar=iesea​rch
HKLM_Main|Start Page - hxxp://fr.msn.com/
HKCU_SearchScopes\{0ECDF796-C2​DC-4d79-A620-CCE0C0A66CC9} - "SearchGol" (hxxp://www.searchgol.com/?q={​searchTerms}&amp;babsrc=SP_ss&​amp;mntrId=2AD8B8763FF0CD8C&am​p;a...)
HKCU_SearchScopes\{33BB0A4E-99​AF-4226-BDF6-49120163DE86} - "qvo6" (hxxp://search.qvo6.com/web/?u​tm_source=b&amp;utm_medium=adk​&amp;from=adk&amp;uid=HitachiX​HTS...)
HKCU_SearchScopes\{5B78C073-4B​5C-468C-9F3E-FCAEAAB0A347} - "eBay" (hxxp://rover.ebay.com/rover/1​/709-42536-16445-33/4?mpre=hxx​p://shop.ebay.fr/?oem...)
HKCU_SearchScopes\{9BB47C17-9C​68-4BB3-B188-DD9AF0FD2406} - "Ask.com" (hxxp://dts.search.ask.com/sr?​src=ieb&amp;gct=ds&amp;appid=3​41&amp;systemid=406&amp;v=a939​6-116&amp;a...)
HKCU_SearchScopes\{B3B3A6AC-74​EC-BD56-BCDB-EFA4799FB9DF} - "Amazon" (hxxp://www.amazon.fr/gp/bit/a​mazonserp/ref=bit_bds-p18_serp​_ie_fr_display?ie=UTF...)
HKLM_SearchScopes\{9BB47C17-9C​68-4BB3-B188-DD9AF0FD2406} - "Ask.com" (hxxp://dts.search.ask.com/sr?​src=ieb&amp;gct=ds&amp;appid=3​41&amp;systemid=406&amp;v=a939​6-116&amp;a...)
HKLM_Toolbar|{ec2bae47-25af-4c​e9-9e78-10627a49c9ea} (x)
HKLM_Toolbar|{EA582743-9076-41​78-9AA6-7393FDF4D5CE} (C:\Program Files (x86)\Amazon Browser Bar\AmazonBrowserBar.3.0.dll)
HKLM_Toolbar|{25A3A431-30BB-47​C8-AD6A-E1063801134F} (C:\Program Files (x86)\PDF Architect\PDFIEPlugin.dll)
HKCU_ElevationPolicy\{10EBE9BE​-F8AF-4F38-A1F-7B688EF7246} - C:\Program Files (x86)\Pricora\Pricora-enabler.​exe-helper.exe (x)
HKCU_ElevationPolicy\{305A572E​-6954-4DAD-A8B6-755B92D4E5FB} - C:\Program Files (x86)\Pricora\Pricora-enabler.​exe-buttonutil.exe (x)
HKCU_ElevationPolicy\{5C0D11B8​-C5F6-4be3-AD2C-2B1A3EB94AB6} - C:\Users\Leila\AppData\Roaming​\Spotify\spotify.exe (Spotify Ltd)
HKCU_ElevationPolicy\{5c8d08d0​-75f3-478b-90a1-e1ac599d4323} - C:\Program Files (x86)\Pricora\Pricora-buttonut​il.exe (Corporate Inc)
HKCU_ElevationPolicy\{5D80C52E​-E42B-4335-A74-5EC1D140C697} - C:\Program Files (x86)\Pricora\Pricora-enabler.​exe-buttonutil64.exe (x)
HKCU_ElevationPolicy\{76F92508​-46BA-4C7C-A963-F0946464F18} - C:\Program Files (x86)\Pricora\Pricora-enabler.​exe-codedownloader.exe (x)
HKCU_ElevationPolicy\{782da15a​-d5ee-4a44-854a-431c70309850} - C:\Program Files (x86)\Pricora\Pricora-bg.exe (Corporate Inc)
HKCU_ElevationPolicy\{7e65261e​-4297-4fd1-bbdf-0e4946f65ac7} - C:\Program Files (x86)\Pricora\Pricora-helper.e​xe (?)
HKCU_ElevationPolicy\{91A31F83​-4C93-432C-9F82-E9D4251EAE8E} - C:\Program Files (x86)\Pricora\Pricora-enabler.​exe-buttonutil64.exe (x)
HKCU_ElevationPolicy\{a32d9d50​-52bb-4b8b-9259-241cd76370ab} - C:\Program Files (x86)\Pricora\Pricora-buttonut​il64.exe (Corporate Inc)
HKCU_ElevationPolicy\{af9aa741​-9f97-4c55-978f-c4f5f5c95725} - C:\Program Files (x86)\Pricora\Pricora-codedown​loader.exe (Corporate Inc)
HKCU_ElevationPolicy\{DCB62AD7​-FF37-4404-AB9E-DF7FCF5A39C} - C:\Program Files (x86)\Pricora\Pricora-enabler.​exe-buttonutil.exe (x)
HKCU_ElevationPolicy\{EAB51331​-4560-4365-8C25-8B1CE366BE28} - C:\Program Files (x86)\Pricora\Pricora-enabler.​exe-codedownloader.exe (x)
HKCU_ElevationPolicy\{FBF37859​-DFF8-422F-9CA0-FC3D6B224F88} - C:\Program Files (x86)\Pricora\Pricora-enabler.​exe-helper.exe (x)
HKLM_ElevationPolicy\{07d873dc​-b9b9-44f5-af0b-fb59fa54fb7a} - C:\Windows\SysWOW64\wpcer.exe (x)
HKLM_ElevationPolicy\{0a402d70​-1f10-4ae7-bec9-286a98240695} - C:\Windows\SysWOW64\winfxdocob​j.exe (x)
HKLM_ElevationPolicy\{1FCCD250​-A453-4348-86C1-E5EA9B76FADB} - C:\Program Files\McAfee\VirusScan\mcvsmap​.exe (McAfee, Inc.)
HKLM_ElevationPolicy\{29494049​-211F-4F5C-8545-7DA8BF7A6CF8} - C:\Program Files (x86)\BonanzaDealsLive\Update\​BonanzaDealsLive.exe (BonanzaDeals)
HKLM_ElevationPolicy\{357FBE87​-6C8E-490D-A059-4746C864AE6F} - C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\InputPersonalizatio​n.exe (x)
HKLM_ElevationPolicy\{44D1B085​-E495-4b5f-9EE6-34795C46E7E7} - C:\Program Files (x86)\Java\jre7\bin\jp2launche​r.exe (Oracle Corporation)
HKLM_ElevationPolicy\{49E561B1​-1091-4E65-98A0-AFCA4996CD1D} - C:\Windows\SysWOW64\RuntimeBro​ker.exe (x)
HKLM_ElevationPolicy\{5852F5ED​-8BF4-11D4-A245-0080C6F74284} - C:\Windows\SysWOW64\javaws.exe (Oracle Corporation)
HKLM_ElevationPolicy\{5c8d08d0​-75f3-478b-90a1-e1ac599d4323} - C:\Program Files (x86)\Pricora\Pricora-buttonut​il.exe (Corporate Inc)
HKLM_ElevationPolicy\{70f641fd​-9ffc-4d5b-a4dc-962af4ed7999} - C:\Program Files (x86)\Internet Explorer\iedw.exe (x)
HKLM_ElevationPolicy\{782da15a​-d5ee-4a44-854a-431c70309850} - C:\Program Files (x86)\Pricora\Pricora-bg.exe (Corporate Inc)
HKLM_ElevationPolicy\{7e65261e​-4297-4fd1-bbdf-0e4946f65ac7} - C:\Program Files (x86)\Pricora\Pricora-helper.e​xe (?)
HKLM_ElevationPolicy\{a32d9d50​-52bb-4b8b-9259-241cd76370ab} - C:\Program Files (x86)\Pricora\Pricora-buttonut​il64.exe (Corporate Inc)
HKLM_ElevationPolicy\{A8F94DF3​-F6C6-422a-8BFC-7EE0F60A8609} - C:\Program Files\McAfee\VirusScan\mcvsshl​d.exe (McAfee, Inc.)
HKLM_ElevationPolicy\{af9aa741​-9f97-4c55-978f-c4f5f5c95725} - C:\Program Files (x86)\Pricora\Pricora-codedown​loader.exe (Corporate Inc)
HKLM_ElevationPolicy\{B43A0C1E​-B63F-4691-B68F-CD807A45DA01} - C:\Windows\system32\TSWbPrxy.e​xe (x)
HKLM_ElevationPolicy\{B73DC3B9​-9E08-4781-BF75-12F6A54FBF89} - C:\Program Files (x86)\metaCrawler\1.8.19.0\met​acrawlersrv.exe (x)
HKLM_ElevationPolicy\{C4BEF720​-313C-420A-ACF6-77DD95D8F553} - C:\Program Files (x86)\BonanzaDealsLive\Update\​1.3.23.0\BonanzaDealsLiveBroke​r.exe (BonanzaDeals)
HKLM_ElevationPolicy\{C8FE2181​-CAE7-49EE-9B04-DB7EB4DA544A} - C:\Program Files (x86)\Java\jre7\bin\ssvagent.e​xe (Oracle Corporation)
HKLM_ElevationPolicy\{E57091A7​-B5F0-4C42-9329-72ED3E59ED31} - C:\Program Files (x86)\Amazon Browser Bar\AmazonBrowserBarSSB.3.0.dl​l (?)
HKLM_ElevationPolicy\{F9B3B4B0​-5828-4E0F-BE6C-3B3D30350942} - C:\PROGRA~2\MOVIES~1\Datamngr\​SRTOOL~1\IE\dtuser.exe (APN LLC)
BHO\{11111111-1111-1111-1111-1​10311531129} - "Pricora" (C:\Program Files (x86)\Pricora\Pricora-bho.dll)
BHO\{23AF19F7-1D5B-442c-B14C-3​D1081953C94} - "Bubble Dock SurfMatch" (C:\Program Files (x86)\Nosibay\Bubble Dock\extensions\axSurfMatch.dl​l)
BHO\{3A2D5EBA-F86D-4BD3-A177-0​19765996711} - "PDF Architect Helper" (C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll)
BHO\{A7A6995D-6EE1-4FD1-A258-4​9395D5BF99C} - "Wajam" (C:\Program Files (x86)\Wajam\IE\priam_bho.dll)
BHO\{b67b3dbb-c1c9-49d2-b016-2​748b0b5017e} - "BatBrowse" (C:\Program Files (x86)\BatBrowse\BatBrowsebho.d​ll)
BHO\{F443A627-5009-4323-9C1D-7​FD598D0D712} - "AlxHelper Class" (C:\Program Files (x86)\Amazon Browser Bar\AmazonBrowserBar.3.0.dll)
BHO\{fe063412-bea4-4d76-8ed3-1​83be6220d17} - "BonanzaDeals" (C:\Program Files (x86)\BonanzaDeals\BonanzaDeal​sIE.dll)

==============================​==========

C:\Program Files (x86)\Ad-Remover\Quarantine: 30 Fichier(s)
C:\Program Files (x86)\Ad-Remover\Backup: 14 Fichier(s)

C:\Ad-Report-CLEAN[1].txt - 08/11/2013 23:15:57 (12322 Octet(s))

Fin à: 23:20:32, 08/11/2013
============== E.O.F ==============

Entraide et convivialité
  1. homepage
herisson41
Membre impliqué (de 20 000 à 29 999 messages postés) Fan Club de Clic-Clic Maître smilies
  1. Posté le 23/11/2013 à 00:03:01  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
Bonsoir lala20 ,

Il faut créer ton propre sujet dans la catégorie "Sécurité" sous-catégorie "Infections" http://forum.telecharger.01net [...] catgroup=0


---------------
A consulter :
[:gepetest:4] Club des fans de Clic-Clic [:gepetest:4] Index en ligne de Micro Hebdo
.. [:gepetest3] ....   Répertoire des tutoriels   ..... [:gepetest3] ..... Calendrier des anniversaires
(Publicité)
Entraide et convivialité
  1. homepage
herisson41
Membre impliqué (de 20 000 à 29 999 messages postés) Fan Club de Clic-Clic Maître smilies
  1. Posté le 23/11/2013 à 00:04:23  
  1. answer
  1. Prévenir les modérateurs en cas d'abus
 
Ce sujet a été déplacé de la catégorie PRODUITS vers la categorie SECURITE par herisson41


---------------
A consulter :
[:gepetest:4] Club des fans de Clic-Clic [:gepetest:4] Index en ligne de Micro Hebdo
.. [:gepetest3] ....   Répertoire des tutoriels   ..... [:gepetest3] ..... Calendrier des anniversaires
 Page :
1

Aller à :
 

Sujets relatifs
Virus publicités sous vista Chrome : ouverture de fenêtres publicitaires intempestives
PC envahi de publicités intempestives Comment supprimer les publicités intempestives "problème résolu"
Des onglets de publicites s'ouvrent tout seul..... Qu'est-ce que mc???.tmp ? [résolu]
Plus de sujets relatifs à : Publicités intempestives avec Chrome [Résolu]

Les 5 sujets de discussion précédents Nombre de réponses Dernier message
Problème lenteur internet 4
infecté par Mystart.incredimail.com 5
ordinateur lent et fenetre intempestive 1
Bug internet 3
fenêtres de publicité ! 29