Spyware ecran noir

Fermé
falso59 Messages postés 30 Date d'inscription jeudi 7 mai 2009 Statut Membre Dernière intervention 20 mai 2009 - 7 mai 2009 à 19:08
 Utilisateur anonyme - 20 mai 2009 à 21:12
Bonjour,
Voici mon problème depuis quelques jours , j'ai attrappé un cheval de trois dont j'ignore le nom.
il a pour effet de rendre mon écran totalement noir( je ne vois plus mon bureau) et il ouvre mes documents .
J'ai immédiatement pensé a faire un scan avec kapersky mais il ne détecte rien , alors j' ai eu l' idée d' aller dans /system32 et jai trouvé plusieurs fichers .dat datant de l'heure du problème que j' ai supprimés . J' ai également supprimé ( enfin , je crois ) un certain fichier FNTCACHE.dat . J'ai redémarré l' ordinateur ensuite mais le problème persistait . Alors je l' ai démaré en mode sans échec et j' ai essayé de venir télécharger plusieurs soltions. Mais toutes celles proposées sur 01.net ou cluclic mais tous les liens m' affichent que le fichier proposé n' éxiste plus . J' en reviens donc ici pour vous demander de l' aide .


Ps: l'ordi comprends plusieurs jugements et dossier de travail , je voudrais donc ne pas avoir a les supprimer .

Merci
A voir également:

53 réponses

Utilisateur anonyme
13 mai 2009 à 18:35
coucou tu me postes le rappport
0
falso59 Messages postés 30 Date d'inscription jeudi 7 mai 2009 Statut Membre Dernière intervention 20 mai 2009
13 mai 2009 à 19:04
Le voici : ---->

.Logfile of random's system information tool 1.06 (written by random/random)
Run by Genevieve at 2009-05-13 19:00:58
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
System drive C: has 129 GB (71%) free of 183 GB
Total RAM: 3062 MB (63% free)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:01:03, on 13.05.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18226)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtMon.exe
C:\Program Files\Lexmark 9500 Series\lxdomon.exe
C:\Program Files\Lexmark 9500 Series\lxdoamon.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\Users\Genevieve\Desktop\Dossier contre les spywares\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Genevieve.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yandex.ru/?clid=40583
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Google\Google_BAE\BAE.dll
O3 - Toolbar: Lexmark Barre d'outils - {1017A80C-6F09-4548-A84D-EDD6AC9525F0} - C:\Program Files\Lexmark Toolbar\toolband.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [toolbar_eula_launcher] C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\Windows\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [lxdomon.exe] "C:\Program Files\Lexmark 9500 Series\lxdomon.exe"
O4 - HKLM\..\Run: [lxdoamon] "C:\Program Files\Lexmark 9500 Series\lxdoamon.exe"
O4 - HKLM\..\Run: [Lexmark 9500 Series Fax Server] "C:\Program Files\Lexmark 9500 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe
O4 - HKCU\..\Run: [SmpcSys] C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: Statistiques de la protection du trafic Internet - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Envoyer ? OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: &Envoyer ? OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {04CB5B64-5915-4629-B869-8945CEBADD21} (Module de d?livrance de certificat MINEFI) - https://static.impots.gouv.fr/abos/static/securite/certdgi1.cab
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: lxdoCATSCustConnectService - Lexmark International, Inc. - C:\Windows\system32\spool\DRIVERS\W32X86\3\\lxdoserv.exe
O23 - Service: lxdo_device - - C:\Windows\system32\lxdocoms.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
0
Utilisateur anonyme
13 mai 2009 à 19:22
tu as yandex dans ajout suppression de programmes ?
0
falso59 Messages postés 30 Date d'inscription jeudi 7 mai 2009 Statut Membre Dernière intervention 20 mai 2009
13 mai 2009 à 19:24
nn pk ?
0

Vous n’avez pas trouvé la réponse que vous recherchez ?

Posez votre question
Utilisateur anonyme
13 mai 2009 à 19:33
==> Télécharge OAD (de Laur3n7!)

- Enregistre le sur ton bureau

Double clique sur le OAD pour le lancer

- nom de fichier à rechercher ,tapes : yandex
- Type de recherche : sélectionne l'option 6 puis valide [entree]

OAD va maintenant rechercher le fichier. Laisse le travailler jusqu'à ce qu'il en ai terminé.
Le rapport de recherche s'affichera automatiquement à dès qu'il en aura terminé.

- Fais un copier / coller de ce rapport dans ton prochain post.

Note importante : Suivant la taille des disques dur cette recherche peut prendre plusieurs minutes. Sois patient

0
falso59 Messages postés 30 Date d'inscription jeudi 7 mai 2009 Statut Membre Dernière intervention 20 mai 2009
13 mai 2009 à 19:46
13.05.2009 ---- 19:40:33,77

----------------------------------
§§§§§§ [yandex] §§§§§§
----------------------------------
[X] Registre

-------------- [ ] rapide
-- Fichier --- [ ] disque systeme
------------- [X] complete


********************
[Registre]
********************


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{45FCA2FB-D8E6-420a-A8D2-6C89FEF0385E}\LocalServer32]
@="C:\\Program Files\\Yandex\\YandexBarIE\\yndbar.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8A22B9B5-F9B6-461F-8828-3BC9AE89F351}\1.0\0\win32]
@="C:\\Users\\Genevieve\\AppData\\Local\\Yandex\\Updater\\yupdate-executor.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{8A22B9B5-F9B6-461F-8828-3BC9AE89F351}\1.0\HELPDIR]
@="C:\\Users\\Genevieve\\AppData\\Local\\Yandex\\Updater"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{91397D13-1446-11D4-8AF4-0040CA1127B6}\1.0]
@="Yandex Toolbar 1.0 Type Library"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{91397D13-1446-11D4-8AF4-0040CA1127B6}\1.0\0\win32]
@="C:\\Program Files\\Yandex\\YandexBarIE\\yndbar.dll"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{91397D13-1446-11D4-8AF4-0040CA1127B6}\1.0\HELPDIR]
@="C:\\Program Files\\Yandex\\YandexBarIE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Yandex.Toolbar]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Yandex.Toolbar\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Yandex.Toolbar\CurVer]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Yandex.Toolbar\CurVer]
@="Yandex.Toolbar.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Yandex.Toolbar.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Yandex.Toolbar.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="Yandex"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\Yandex]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\Yandex]
"URL"="https://yandex.ru/yandsearch?clid=40584&text=&lr=10502&redircnt=1580999957.1{searchTerms}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\Yandex]
"FaviconURLFallback"="http://yandex.st/lego/_/pDu9OWAQKB0s2J9IojKpiS_Eho.ico"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû]
"DefaultActivity"="yandex.ru"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru]
"Domain"="yandex.ru"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru]
"DownloadUrl"="https://yandex.ru/soft/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru]
"HomepageURL"="https://yandex.ru/maps/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru]
"XML"="C:\\Program Files\\Yandex\\YandexBarIE\\accelerators\\maps.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru]
"Icon"="C:\\Program Files\\Yandex\\YandexBarIE\\accelerators\\maps.ico"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru\Action1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru\Action1\execute]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru\Action1\execute]
"Action"="https://yandex.ru/maps/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru\Action1\execute\Parameter1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru\Action1\preview]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru\Action1\preview]
"Action"="http://export.yandex.ru/bar/mapsprint.xml?address={selection}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru\Action2]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru\Action2\execute]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru\Action2\execute]
"Action"="https://yandex.ru/maps/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru\Action2\execute\Parameter1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru\Action2\preview]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Êàðòû\yandex.ru\Action2\preview]
"Action"="http://export.yandex.ru/bar/mapsprint.xml?address={linkText}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä]
"DefaultActivity"="yandex.ru"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru]
"Domain"="yandex.ru"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru]
"DownloadUrl"="https://yandex.ru/soft/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru]
"HomepageURL"="https://translate.yandex.ru/?utm_source=slovari"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru]
"XML"="C:\\Program Files\\Yandex\\YandexBarIE\\accelerators\\lingvo.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru]
"Icon"="C:\\Program Files\\Yandex\\YandexBarIE\\accelerators\\lingvo.ico"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru\Action1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru\Action1\execute]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru\Action1\execute]
"Action"="http://lingvo.yandex.ru/q?st_translate=1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru\Action1\execute\Parameter1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru\Action2]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru\Action2\execute]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru\Action2\execute]
"Action"="http://lingvo.yandex.ru/q?st_translate=1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ïåðåâîä\yandex.ru\Action2\execute\Parameter1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü]
"DefaultActivity"="yandex.ru"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru]
"Domain"="yandex.ru"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru]
"DownloadUrl"="https://yandex.ru/soft/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru]
"HomepageURL"="https://translate.yandex.ru/?utm_source=slovari"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru]
"XML"="C:\\Program Files\\Yandex\\YandexBarIE\\accelerators\\slovari.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru]
"Icon"="C:\\Program Files\\Yandex\\YandexBarIE\\accelerators\\slovari.ico"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru\Action1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru\Action1\execute]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru\Action1\execute]
"Action"="http://slovari.yandex.ru/search.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru\Action1\execute\Parameter1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru\Action2]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru\Action2\execute]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru\Action2\execute]
"Action"="http://slovari.yandex.ru/search.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ñëîâàðü\yandex.ru\Action2\execute\Parameter1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû]
"DefaultActivity"="yandex.ru"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru]
"Domain"="yandex.ru"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru]
"DownloadUrl"="https://yandex.ru/soft/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru]
"HomepageURL"="https://market.yandex.ru/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru]
"XML"="C:\\Program Files\\Yandex\\YandexBarIE\\accelerators\\market.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru]
"Icon"="C:\\Program Files\\Yandex\\YandexBarIE\\accelerators\\market.ico"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru\Action1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru\Action1\execute]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru\Action1\execute]
"Action"="http://market.yandex.ru/search.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru\Action1\execute\Parameter1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru\Action1\preview]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru\Action1\preview]
"Action"="http://market.yandex.ru/export/bar/search_bar.xml?text={selection}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru\Action2]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru\Action2\execute]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru\Action2\execute]
"Action"="http://market.yandex.ru/search.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru\Action2\execute\Parameter1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru\Action2\preview]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Òîâàðû\yandex.ru\Action2\preview]
"Action"="http://market.yandex.ru/export/bar/search_bar.xml?text={linkText}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà]
"DefaultActivity"="yandex.ru"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru]
"Domain"="yandex.ru"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru]
"DownloadUrl"="https://yandex.ru/soft/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru]
"HomepageURL"="https://mail.yandex.ru/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru]
"XML"="C:\\Program Files\\Yandex\\YandexBarIE\\accelerators\\mail.xml"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru]
"Icon"="C:\\Program Files\\Yandex\\YandexBarIE\\accelerators\\mail.ico"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru\Action1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru\Action1\execute]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru\Action1\execute]
"Action"="https://mail.yandex.ru/?retpath=https%3A%2F%2Fmail.yandex.ru%2Fcompose"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru\Action1\execute\Parameter1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru\Action2]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru\Action2\execute]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru\Action2\execute]
"Action"="https://mail.yandex.ru/?retpath=https%3A%2F%2Fmail.yandex.ru%2Fcompose"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru\Action2\execute\Parameter1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru\Action3]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru\Action3\execute]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru\Action3\execute]
"Action"="https://mail.yandex.ru/?retpath=https%3A%2F%2Fmail.yandex.ru%2Fcompose"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru\Action3\execute\Parameter1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Activities\Ýëåêòðîííàÿ ïî÷òà\yandex.ru\Action3\execute\Parameter2]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\?iaaen.Aa? aey Internet Explorer_is1]
"Inno Setup: App Path"="C:\\Program Files\\Yandex\\YandexBarIE"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\?iaaen.Aa? aey Internet Explorer_is1]
"InstallLocation"="C:\\Program Files\\Yandex\\YandexBarIE\\"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\?iaaen.Aa? aey Internet Explorer_is1]
"DisplayIcon"="C:\\Program Files\\Yandex\\YandexBarIE\\bar.ico"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\?iaaen.Aa? aey Internet Explorer_is1]
"UninstallString"="\"C:\\Program Files\\Yandex\\YandexBarIE\\unins000.exe\""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\?iaaen.Aa? aey Internet Explorer_is1]
"QuietUninstallString"="\"C:\\Program Files\\Yandex\\YandexBarIE\\unins000.exe\" /SILENT"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\?iaaen.Aa? aey Internet Explorer_is1]
"URLInfoAbout"="https://yandex.ru/"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\?iaaen.Aa? aey Internet Explorer_is1]
"URLUpdateInfo"="https://yandex.ru/soft/"

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\AppDataLow\Yandex]

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\AppDataLow\Yandex\Yupdate-BITS-CM]

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\AppDataLow\Yandex\Yupdate-BITS-CM\Applications]

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\AppDataLow\Yandex\Yupdate-BITS-CM\Applications\barie]

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\AppDataLow\Yandex\Yupdate-BITS-CM\Applications\barie]
"VersionUrl"="http://download.yandex.ru/bar/ie/version.rss"

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\AppDataLow\Yandex\Yupdate-BITS-CM\Applications\barie]
"ReportUrl"="http://soft.export.yandex.ru/status.xml"

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\AppDataLow\Yandex\Yupdate-BITS-CM\Applications\barie\Upgrade]

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D50229E4-6E54-468D-AA18-B7ABF1E68318}]
"AppPath"="C:\\Users\\Genevieve\\AppData\\Local\\Yandex\\Updater"

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\Microsoft\Internet Explorer\Main]
"Start Page"="https://yandex.ru/?clid=40583"

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\Microsoft\Internet Explorer\SearchScopes]
"DefaultScope"="Yandex"

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\Microsoft\Internet Explorer\SearchScopes\Yandex]

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\Microsoft\Internet Explorer\SearchScopes\Yandex]
"URL"="https://yandex.ru/yandsearch?clid=40584&text=&lr=10502&redircnt=1580999957.1{searchTerms}"

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\Microsoft\Internet Explorer\SearchScopes\Yandex]
"FaviconURLFallback"="http://yandex.st/lego/_/pDu9OWAQKB0s2J9IojKpiS_Eho.ico"

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\Yandex]

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\Yandex\Toolbar]

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\Yandex\Toolbar]
"Protect HP"="https://yandex.ru/?clid=40583"

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\Classes\CLSID\{2614C37E-2C78-4bfb-B7A6-E49B62B9CD9B}\LocalServer32]
@="\"C:\\Users\\Genevieve\\AppData\\Local\\Yandex\\Updater\\yupdate-executor.exe\""

"C:\\Users\\GENEVI~1\\AppData\\Local\\Temp\\is-ONEIJ.tmp\\YandexBarIESetup[1].tmp"="Setup/Uninstall"

"C:\\Users\\GENEVI~1\\AppData\\Local\\Temp\\is-R3R57.tmp\\YandexBarIESetup[1].tmp"="Setup/Uninstall"

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\Software\Classes\TypeLib\{8A22B9B5-F9B6-461F-8828-3BC9AE89F351}\1.0\0\win32]
@="C:\\Users\\Genevieve\\AppData\\Local\\Yandex\\Updater\\yupdate-executor.exe"

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002_Classes\CLSID\{2614C37E-2C78-4bfb-B7A6-E49B62B9CD9B}\LocalServer32]
@="\"C:\\Users\\Genevieve\\AppData\\Local\\Yandex\\Updater\\yupdate-executor.exe\""

"C:\\Users\\GENEVI~1\\AppData\\Local\\Temp\\is-ONEIJ.tmp\\YandexBarIESetup[1].tmp"="Setup/Uninstall"

"C:\\Users\\GENEVI~1\\AppData\\Local\\Temp\\is-R3R57.tmp\\YandexBarIESetup[1].tmp"="Setup/Uninstall"

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002_Classes\TypeLib\{8A22B9B5-F9B6-461F-8828-3BC9AE89F351}\1.0\0\win32]
@="C:\\Users\\Genevieve\\AppData\\Local\\Yandex\\Updater\\yupdate-executor.exe"

*******************
[Fichier]
*******************

c:\Program Files\Yandex
c:\Users\Genevieve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Virtualized\C\Users\Genevieve\AppData\Roaming\Yandex
c:\Users\Genevieve\AppData\Local\Yandex
c:\Users\Genevieve\AppData\LocalLow\Yandex
c:\Users\Genevieve\AppData\Roaming\Yandex


*********************
[Même date]
*********************

[21.04.2009 ] --- REP ---> C:\Program Files\XBCD 360
[21.04.2009 ] --- REP ---> C:\Program Files\Yandex
[R‚pertoire ] --- REP ---> C:\Program Files\Files



Outil Aide Diagnostic By !aur3n7 Version 1.1
----------------------------------
§§§§§ Fin Rapport §§§§§
----------------------------------
0
Utilisateur anonyme
13 mai 2009 à 19:57
desinstalle Metaboli puis :

*****************************************************
************** Option A (Recherche) **************
*****************************************************


Télécharges AD-Remover ( de Cyrildu17 / C_XX ) sur ton bureau :


/!\ Déconnectes toi et fermes toutes applications en cours

? Double clique sur le programme d'installation , et installe le dans son emplacement par défaut. ( C:\Program files )
? Double clique sur l'icône Ad-removersituée sur ton bureau
? Au menu principal choisi l'option "Recherche"
? Postes le rapport qui apparait à la fin .

( le rapport est sauvegardé aussi sous C:\Ad-report(date).log )

(CTRL+A Pour tout selectionner , CTRL+C pour copier et CTRL+V pour coller )

Note :

"Process.exe", une composante de l'outil, est détecté par certains antivirus (AntiVir, Dr.Web, Kaspersky Anti-Virus) comme étant un RiskTool.
Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus.
Mis entre de mauvaises mains, cet utilitaire pourrait arrêter des logiciels de sécurité (Antivirus, Firewall)

Aides en images (Installation)
Aides en images (Recherche)
0
falso59 Messages postés 30 Date d'inscription jeudi 7 mai 2009 Statut Membre Dernière intervention 20 mai 2009
13 mai 2009 à 20:00
Je n' ai pas métaboli mais je suis quand meme la procedure .
0
falso59 Messages postés 30 Date d'inscription jeudi 7 mai 2009 Statut Membre Dernière intervention 20 mai 2009
17 mai 2009 à 10:39
Eh bien , la première fois que j' ai démarré Ad-remover , il a chercher jusqu'a ce que ma batterie tombe en rade . La deuxième fois il a pris plus de 2 heures . Normal ?
0
falso59 Messages postés 30 Date d'inscription jeudi 7 mai 2009 Statut Membre Dernière intervention 20 mai 2009
17 mai 2009 à 12:39
Voila , le repport : ( sa a pris du temps !) ----->


------- LOGFILE OF AD-REMOVER 1.1.3.7 | ONLY XP/VISTA -------

Updated by C_XX on 11/05/2009 at 16:00
Contact: AdRemover.contact@gmail.com
Website: http://pagesperso-orange.fr/NosTools/ad_remover.html

Start at: 10:30:25, 17.05.2009 | Boot mode: Normal Boot
Option: Scan | Executed from: C:\Program Files\Ad-remover\
Operating System: Microsoft® Windows Vista™ Home Premium Service Pack 1 (version 6.0.6001)
Computer Name: PC-DE-GENEVIEVE
Current User: Genevieve - Administrator
Drive(s):
- C:\ (File System: NTFS)


============ Known Adwares Found ============

.
.
C:\Users\Genevieve\AppData\Roaming\Microsoft\Windows\Cookies\genevieve@atdmt[2].txt
C:\Users\Genevieve\AppData\Roaming\Microsoft\Windows\Cookies\genevieve@bs.serving-sys[2].txt

+-----------------| Eorezo Elements Found:

.

+-----------------| It's TV Elements Found:

.

+-----------------| Sweetim Elements Found:

.

+-----------------| Added Scan:

---- Mozilla FireFox Version 2.0.0.20 ----

ProfilePath: 2t910znz.default (Genevieve)
.
(Prefs.js) user_pref("browser.search.defaultenginename", "Live Search");
(Prefs.js) user_pref("browser.search.selectedEngine", "Live Search");
(Prefs.js) user_pref("browser.search.defaulturl", "hxxp://search.live.com/results.aspx?FORM=IEFM1&q=");
(Prefs.js) user_pref("browser.startup.homepage", "hxxp://go.microsoft.com/fwlink/?LinkId=69157");
(Prefs.js) user_pref("browser.startup.homepage_override.mstone", "rv:1.8.1.20");
.

---- Internet Explorer Version 7.0.6001.18000 ----

[HKEY_CURRENT_USER\..\Internet Explorer\Main]

Search bar: hxxp://www.google.com/ie
Search Page: hxxp://www.google.com
Start Page: hxxp://www.yandex.ru/?clid=40583

[HKEY_USERS\S-1-5-21-473284642-2885212961-2484470863-1002\..\Internet Explorer\Main]

Search bar: hxxp://www.google.com/ie
Search Page: hxxp://www.google.com
Start Page: hxxp://www.yandex.ru/?clid=40583

[HKEY_LOCAL_MACHINE\..\Internet Explorer\Main]

Default_Page_URL: hxxp://go.microsoft.com/fwlink/?LinkId=69157
Default_Search_URL: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Search Page: hxxp://go.microsoft.com/fwlink/?LinkId=54896
Start Page: hxxp://go.microsoft.com/fwlink/?LinkId=69157

[HKEY_LOCAL_MACHINE\..\Internet Explorer\ABOUTURLS]

Tabs: hxxp://ieframe.dll/tabswelcome.htm

=========== Suspicious ==========


+---------------------------------------------------------------------------+

912 Byte(s) - C:\Ad-Report-Scan-13.05.2009.log
2491 Byte(s) - C:\Ad-Report-Scan-17.05.2009.log

0 File(s) - C:\Program Files\Ad-remover\BACKUP
0 File(s) - C:\Program Files\Ad-remover\QUARANTINE

End at: 11:48:49 | 17.05.2009
.
+-----------------| E.O.F
.
0
Utilisateur anonyme
20 mai 2009 à 19:08
salut desole pour l 'attente

tu me confirmes que ce n'est pas toi qui a installé yandex ?
0
falso59 Messages postés 30 Date d'inscription jeudi 7 mai 2009 Statut Membre Dernière intervention 20 mai 2009
20 mai 2009 à 19:22
Non , effecivement je n' ai pas nstal yandex , je le fais ?
0
Utilisateur anonyme
20 mai 2009 à 21:12
Télécharge TOOLBAR SD ( de Eric_71/Team IDN )sur ton bureau :


!! Déconnecte toi,desactive tes protections résidentes, et ferme toutes tes applications en cours le temps de la manip. !!

* Double-clique sur ToolBar SD.exe pour lancer l'outil et laisse toi guider ...

--> Tapes ( option " recherche " ) puis tape sur [Entrée].

Un rapport sera généré à la fin du processus : poste son contenu dans ta prochaine réponse

( le rapport est en outre sauvegardé ici -> C:\TB.txt )
0