Ouverture de fenêtre inetrnet
yassouah225
Messages postés
53
Statut
Membre
-
Narco!4 Messages postés 2446 Statut Contributeur -
Narco!4 Messages postés 2446 Statut Contributeur -
Bonjour,
Lorsque je suis en train de surfer, une fenêtre intempestive me redirigeant sur "www.thenewsphedia.com" apparaît à chaque fois et me gène dans la navigation que faire?
PS: j'ai avst eu alvira comme antivirus.
Merci pour votre aide.
Lorsque je suis en train de surfer, une fenêtre intempestive me redirigeant sur "www.thenewsphedia.com" apparaît à chaque fois et me gène dans la navigation que faire?
PS: j'ai avst eu alvira comme antivirus.
Merci pour votre aide.
A voir également:
- Ouverture de fenêtre inetrnet
- Fenetre windows - Guide
- Fenêtre hors écran windows 11 - Guide
- Page d'ouverture google - Guide
- Fenetre de navigation privée - Guide
- Prochaine ouverture magasin action 2025 - Guide
5 réponses
Bonjour,
télécharge GenProc http://www.genproc.com/GenProc.exe
double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre
télécharge GenProc http://www.genproc.com/GenProc.exe
double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre
[*] Télécharge combofix (sUBs) http://download.bleepingcomputer.com/sUBs/ComboFix.exe sur ton Bureau
[*] Double clique combofix.exe et suis les instructions.
[*] Installe la console de récupération si proposé et continue.
[*] Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
[*] Double clique combofix.exe et suis les instructions.
[*] Installe la console de récupération si proposé et continue.
[*] Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.
NOTE : Le rapport se trouve également ici : C:\Combofix.txt
Merci mon ami enfin le rapport:
ComboFix 09-08-26.05 - LYNDA 27/08/2009 10:03.1.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.479.179 [GMT 0:00]
Running from: c:\documents and settings\LYNDA\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
c:\program files\SuperCopier2\SC2Hook.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\LYNDA\Application Data\bcrypt.html
c:\documents and settings\LYNDA\Application Data\wiaservg.log
c:\recycler\S-1-5-21-0230571862-8073567460-651502566-7001
c:\recycler\S-1-5-21-0288623198-8866559897-437571247-3978
c:\recycler\S-1-5-21-0486636189-9707273005-130844152-0929
c:\recycler\S-1-5-21-0650345070-5024988155-468557058-2438
c:\recycler\S-1-5-21-0969522414-0652210790-556649910-1847
c:\recycler\S-1-5-21-1450088316-7557283054-414342581-8277
c:\recycler\S-1-5-21-1787491829-9519218833-949674304-6550
c:\recycler\S-1-5-21-2771733766-0664864309-331404561-0513
c:\recycler\S-1-5-21-2827642907-9768275406-529170390-6475
c:\recycler\S-1-5-21-3022529124-2239684218-559407462-3951
c:\recycler\S-1-5-21-3396559448-9276541575-384120864-9245
c:\recycler\S-1-5-21-3652671388-0767170813-888633538-8392
c:\recycler\S-1-5-21-3702401964-6809589961-275348982-3263
c:\recycler\S-1-5-21-3870417316-6141967149-038154061-3685
c:\recycler\S-1-5-21-4023299429-4280124858-153493308-7430
c:\recycler\S-1-5-21-4148920905-5687211967-190035029-0968
c:\recycler\S-1-5-21-4300645589-4536226023-939056619-1238
c:\recycler\S-1-5-21-4489814194-3748499410-665295639-3964
c:\recycler\S-1-5-21-5031858728-3636244863-001092034-3550
c:\recycler\S-1-5-21-5841099773-8590820267-779681499-1387
c:\recycler\S-1-5-21-5917729725-5403560215-559902367-4564
c:\recycler\S-1-5-21-6233480752-4400371017-103655022-0078
c:\recycler\S-1-5-21-6270640658-8667183068-350476585-3962
c:\recycler\S-1-5-21-6709699077-7120451112-860305334-0279
c:\recycler\S-1-5-21-6747069472-4488632209-267735937-0336
c:\recycler\S-1-5-21-6911879070-6221903753-832800236-3918
c:\recycler\S-1-5-21-6944035029-0560909799-035497916-4560
c:\recycler\S-1-5-21-7304190125-1074816314-286137622-5277
c:\recycler\S-1-5-21-7455012135-3892403742-488872375-8417
c:\recycler\S-1-5-21-7837779799-7365520782-638873713-2854
c:\recycler\S-1-5-21-7870212293-8944310321-513972838-0835
c:\recycler\S-1-5-21-8286757167-6577866078-627181941-2467
c:\recycler\S-1-5-21-8326940476-5018267815-420714947-0619
c:\recycler\S-1-5-21-8508793341-0882505776-126016583-1212
c:\recycler\S-1-5-21-8810132774-7753276061-586578039-5247
c:\recycler\S-1-5-21-8810132774-7753276061-586578039-5247\nissan.exe
c:\recycler\S-1-5-21-9188399278-1686556444-525371324-4386
c:\recycler\S-1-5-21-9412730359-4793745184-648877797-7638
c:\recycler\S-1-5-21-9574622620-8768616270-270767205-7773
c:\recycler\S-1-5-21-9727919948-7009612990-665615163-0928
C:\System
c:\system\FILES\Desktop.ini
c:\windows.0\Fonts\refluxed.TTF
c:\windows.0\Fonts\Wphv07nb.ttf
c:\windows.0\system32\drivers\vsfocebgdrytqm.sys
c:\windows.0\system32\vsfocednsdotje.dll
c:\windows.0\system32\vsfocedodwoyxo.dll
c:\windows.0\system32\vsfocexgxjcxuc.dat
c:\windows.0\system32\vsfoceyocoeggy.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_vsfoceshampkkj
-------\Legacy_vsfoceshampkkj
((((((((((((((((((((((((( Files Created from 2009-07-27 to 2009-08-27 )))))))))))))))))))))))))))))))
.
2009-08-27 09:46 . 2009-08-27 09:46 -------- d-----w- C:\Genproc
2009-08-26 19:50 . 2009-08-26 19:50 -------- d-----w- c:\documents and settings\LYNDA\Application Data\Bandoo
2009-08-26 19:49 . 2009-08-26 20:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Bandoo
2009-08-26 19:49 . 2009-08-26 19:50 -------- d-----w- c:\program files\Bandoo
2009-08-21 19:53 . 2009-08-23 16:14 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2009-08-20 08:55 . 2009-08-20 08:55 -------- d-----w- C:\spoolerlogs
2009-08-17 15:02 . 2009-08-23 16:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-08-17 15:02 . 2009-08-17 15:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-08-17 15:02 . 2009-08-17 15:02 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-08-13 19:31 . 2009-08-13 19:31 -------- d-----w- c:\program files\WordBiz
2009-08-07 03:10 . 2009-08-07 03:10 -------- d-----w- c:\program files\MSXML 4.0
2009-08-01 15:46 . 2009-08-01 15:46 -------- d-----w- c:\documents and settings\LYNDA\Local Settings\Application Data\Identities
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-27 10:01 . 2009-05-13 21:48 -------- d-----w- c:\program files\SuperCopier2
2009-08-19 21:33 . 2009-08-14 16:08 172 ----a-w- C:\curr_ver.tmp
2009-08-14 21:29 . 2009-07-09 20:13 -------- d-----w- c:\documents and settings\LYNDA\Application Data\Skype
2009-08-14 16:02 . 2002-01-01 01:29 -------- d-----w- c:\documents and settings\LYNDA\Application Data\skypePM
2009-08-08 11:34 . 2009-07-21 11:46 -------- d-----w- c:\program files\Hewlett-Packard
2009-08-07 08:07 . 2001-08-28 11:00 49494 ----a-w- c:\windows.0\system32\perfc00C.dat
2009-08-07 08:07 . 2001-08-28 11:00 370414 ----a-w- c:\windows.0\system32\perfh00C.dat
2009-08-06 13:02 . 2009-05-13 21:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-23 07:41 . 2009-06-15 22:11 -------- d-----w- c:\program files\MediaCoder
2009-07-23 07:41 . 2009-06-15 22:11 -------- d-----w- c:\documents and settings\LYNDA\Application Data\Broad Intelligence
2009-07-23 07:40 . 2009-07-21 21:39 -------- d-----w- c:\documents and settings\LYNDA\Application Data\uTorrent
2009-07-21 11:46 . 2009-07-21 11:46 -------- d-----w- c:\program files\HP
2009-07-21 06:52 . 2009-07-21 06:52 499712 ----a-w- c:\windows.0\system32\msvcp71.dll
2009-07-21 06:52 . 2009-07-21 06:52 348160 ----a-w- c:\windows.0\system32\msvcr71.dll
2009-07-18 16:20 . 2009-07-18 16:20 1506816 ----a-w- c:\windows.0\system32\SET52C.tmp
2009-07-18 16:20 . 2009-07-18 16:20 3083264 ----a-w- c:\windows.0\system32\SET531.tmp
2009-07-15 19:08 . 2009-05-13 21:00 443552 ----a-w- c:\documents and settings\LYNDA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-13 14:16 . 2009-07-13 14:15 -------- d-----w- c:\documents and settings\LYNDA\Application Data\MSNInstaller
2009-07-10 20:35 . 2002-01-01 04:21 -------- d-----w- c:\program files\InstallShield Installation Information
2009-07-10 20:15 . 2009-07-10 20:15 -------- d-----w- c:\program files\KONAMI
2009-07-09 20:13 . 2009-07-09 20:13 -------- d-----r- c:\program files\Skype
2009-07-09 20:13 . 2009-07-09 20:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-07-09 20:13 . 2009-07-09 20:13 -------- d-----w- c:\program files\Fichiers communs\Skype
2009-07-07 08:13 . 2002-01-01 04:21 1734 --sha-w- c:\windows.0\system32\KGyGaAvL.sys
2009-07-06 21:18 . 2009-05-13 21:50 -------- d-----w- c:\documents and settings\LYNDA\Application Data\Yahoo!
2009-07-03 21:01 . 2009-07-03 21:01 298104 ----a-w- c:\windows.0\system32\imon.dll
2009-07-03 21:01 . 2009-07-03 21:01 512096 ----a-w- c:\windows.0\system32\drivers\amon.sys
2009-07-03 21:01 . 2009-07-03 21:01 15424 ----a-w- c:\windows.0\system32\drivers\nod32drv.sys
2009-07-01 19:59 . 2009-06-01 14:56 -------- d-----w- c:\program files\Eset
2009-06-26 16:18 . 2009-06-26 16:18 663552 ----a-w- c:\windows.0\system32\SET529.tmp
2009-06-26 16:18 . 2004-08-19 15:09 663552 ----a-w- c:\windows.0\system32\wininet.dll
2009-06-26 16:18 . 2009-06-26 16:18 618496 ----a-w- c:\windows.0\system32\SET52A.tmp
2009-06-26 16:18 . 2009-06-26 16:18 474624 ----a-w- c:\windows.0\system32\SET52B.tmp
2009-06-26 16:18 . 2004-08-19 15:09 81920 ----a-w- c:\windows.0\system32\ieencode.dll
2009-06-26 16:18 . 2009-06-26 16:18 1024000 ----a-w- c:\windows.0\system32\SET539.tmp
2009-06-23 00:23 . 2009-06-23 00:23 371200 ------w- c:\windows.0\system32\SET53B.tmp
2009-06-16 14:54 . 2004-08-19 15:09 119808 ----a-w- c:\windows.0\system32\t2embed.dll
2009-06-16 14:54 . 2001-08-28 11:00 82432 ----a-w- c:\windows.0\system32\fontsub.dll
2009-06-06 10:18 . 2009-05-15 00:04 75096 ----a-w- c:\windows.0\system32\drivers\avipbb.sys
2009-06-03 21:53 . 2009-06-03 21:53 52056 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\UPDATE\AVUPDATE_4a26f0bf\winwks\fr\basic-nt\xp\avgntflt.sys
2009-06-03 21:53 . 2009-06-03 21:53 208624 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\UPDATE\AVUPDATE_4a26f0bf\winwks\fr\basic-nt\avwsc.exe
2009-06-03 21:53 . 2009-06-03 21:53 11608 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\UPDATE\AVUPDATE_4a26f0bf\winwks\fr\basic-nt\avgio.sys
2009-06-03 19:27 . 2004-08-19 15:09 1296896 ----a-w- c:\windows.0\system32\quartz.dll
2002-01-01 04:21 . 2002-01-01 04:21 56 --sh--r- c:\windows.0\system32\7D016E3D31.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EB5CEE80-030A-4ED8-8E20-454E9C68380F}]
2009-08-13 07:40 1862592 ----a-w- c:\program files\Bandoo\Plugins\IE\ieplugin.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Google Update"="c:\documents and settings\LYNDA\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2002-01-01 133104]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-19 1667584]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-21 24264488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_07\bin\jusched.exe" [2006-05-03 36975]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-07-03 949376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows.0\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\LYNDA\Menu D‚marrer\Programmes\D‚marrage\
SkypeMate.lnk - c:\program files\SkypeMate\SkypeMate.exe [2007-5-22 405504]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
AudioDeck.lnk - c:\program files\VIA Technologies, Inc\VIA Audio Driver Setup Program\AudioDeck\AudioDeck.exe [2009-5-13 581632]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"= cmd.exe
"2"= mmc.exe
"3"= rstrui.exe
"4"= regedit.exe
"5"= regedt32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Bandoo\BndHook.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS.0\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 nod32drv;nod32drv;c:\windows.0\system32\drivers\nod32drv.sys [03/07/2009 21:01 15424]
S3 CrystalSysInfo;CrystalSysInfo;\??\c:\program files\MediaCoder\SysInfo.sys --> c:\program files\MediaCoder\SysInfo.sys [?]
S3 Vsp;Vsp;c:\windows.0\system32\drivers\vsp.sys [13/05/2009 21:37 3351]
.
Contents of the 'Scheduled Tasks' folder
2009-08-24 c:\windows.0\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1532298954-839522115-1003Core.job
- c:\documents and settings\LYNDA\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2002-01-01 21:50]
2009-08-27 c:\windows.0\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1532298954-839522115-1003UA.job
- c:\documents and settings\LYNDA\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2002-01-01 21:50]
.
- - - - ORPHANS REMOVED - - - -
Notify-reset5c - (no file)
ComboFix 09-08-26.05 - LYNDA 27/08/2009 10:03.1.1 - NTFSx86
Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.479.179 [GMT 0:00]
Running from: c:\documents and settings\LYNDA\Bureau\ComboFix.exe
AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
The following files were disabled during the run:
c:\program files\SuperCopier2\SC2Hook.dll
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\LYNDA\Application Data\bcrypt.html
c:\documents and settings\LYNDA\Application Data\wiaservg.log
c:\recycler\S-1-5-21-0230571862-8073567460-651502566-7001
c:\recycler\S-1-5-21-0288623198-8866559897-437571247-3978
c:\recycler\S-1-5-21-0486636189-9707273005-130844152-0929
c:\recycler\S-1-5-21-0650345070-5024988155-468557058-2438
c:\recycler\S-1-5-21-0969522414-0652210790-556649910-1847
c:\recycler\S-1-5-21-1450088316-7557283054-414342581-8277
c:\recycler\S-1-5-21-1787491829-9519218833-949674304-6550
c:\recycler\S-1-5-21-2771733766-0664864309-331404561-0513
c:\recycler\S-1-5-21-2827642907-9768275406-529170390-6475
c:\recycler\S-1-5-21-3022529124-2239684218-559407462-3951
c:\recycler\S-1-5-21-3396559448-9276541575-384120864-9245
c:\recycler\S-1-5-21-3652671388-0767170813-888633538-8392
c:\recycler\S-1-5-21-3702401964-6809589961-275348982-3263
c:\recycler\S-1-5-21-3870417316-6141967149-038154061-3685
c:\recycler\S-1-5-21-4023299429-4280124858-153493308-7430
c:\recycler\S-1-5-21-4148920905-5687211967-190035029-0968
c:\recycler\S-1-5-21-4300645589-4536226023-939056619-1238
c:\recycler\S-1-5-21-4489814194-3748499410-665295639-3964
c:\recycler\S-1-5-21-5031858728-3636244863-001092034-3550
c:\recycler\S-1-5-21-5841099773-8590820267-779681499-1387
c:\recycler\S-1-5-21-5917729725-5403560215-559902367-4564
c:\recycler\S-1-5-21-6233480752-4400371017-103655022-0078
c:\recycler\S-1-5-21-6270640658-8667183068-350476585-3962
c:\recycler\S-1-5-21-6709699077-7120451112-860305334-0279
c:\recycler\S-1-5-21-6747069472-4488632209-267735937-0336
c:\recycler\S-1-5-21-6911879070-6221903753-832800236-3918
c:\recycler\S-1-5-21-6944035029-0560909799-035497916-4560
c:\recycler\S-1-5-21-7304190125-1074816314-286137622-5277
c:\recycler\S-1-5-21-7455012135-3892403742-488872375-8417
c:\recycler\S-1-5-21-7837779799-7365520782-638873713-2854
c:\recycler\S-1-5-21-7870212293-8944310321-513972838-0835
c:\recycler\S-1-5-21-8286757167-6577866078-627181941-2467
c:\recycler\S-1-5-21-8326940476-5018267815-420714947-0619
c:\recycler\S-1-5-21-8508793341-0882505776-126016583-1212
c:\recycler\S-1-5-21-8810132774-7753276061-586578039-5247
c:\recycler\S-1-5-21-8810132774-7753276061-586578039-5247\nissan.exe
c:\recycler\S-1-5-21-9188399278-1686556444-525371324-4386
c:\recycler\S-1-5-21-9412730359-4793745184-648877797-7638
c:\recycler\S-1-5-21-9574622620-8768616270-270767205-7773
c:\recycler\S-1-5-21-9727919948-7009612990-665615163-0928
C:\System
c:\system\FILES\Desktop.ini
c:\windows.0\Fonts\refluxed.TTF
c:\windows.0\Fonts\Wphv07nb.ttf
c:\windows.0\system32\drivers\vsfocebgdrytqm.sys
c:\windows.0\system32\vsfocednsdotje.dll
c:\windows.0\system32\vsfocedodwoyxo.dll
c:\windows.0\system32\vsfocexgxjcxuc.dat
c:\windows.0\system32\vsfoceyocoeggy.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_vsfoceshampkkj
-------\Legacy_vsfoceshampkkj
((((((((((((((((((((((((( Files Created from 2009-07-27 to 2009-08-27 )))))))))))))))))))))))))))))))
.
2009-08-27 09:46 . 2009-08-27 09:46 -------- d-----w- C:\Genproc
2009-08-26 19:50 . 2009-08-26 19:50 -------- d-----w- c:\documents and settings\LYNDA\Application Data\Bandoo
2009-08-26 19:49 . 2009-08-26 20:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Bandoo
2009-08-26 19:49 . 2009-08-26 19:50 -------- d-----w- c:\program files\Bandoo
2009-08-21 19:53 . 2009-08-23 16:14 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
2009-08-20 08:55 . 2009-08-20 08:55 -------- d-----w- C:\spoolerlogs
2009-08-17 15:02 . 2009-08-23 16:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-08-17 15:02 . 2009-08-17 15:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-08-17 15:02 . 2009-08-17 15:02 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-08-13 19:31 . 2009-08-13 19:31 -------- d-----w- c:\program files\WordBiz
2009-08-07 03:10 . 2009-08-07 03:10 -------- d-----w- c:\program files\MSXML 4.0
2009-08-01 15:46 . 2009-08-01 15:46 -------- d-----w- c:\documents and settings\LYNDA\Local Settings\Application Data\Identities
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-27 10:01 . 2009-05-13 21:48 -------- d-----w- c:\program files\SuperCopier2
2009-08-19 21:33 . 2009-08-14 16:08 172 ----a-w- C:\curr_ver.tmp
2009-08-14 21:29 . 2009-07-09 20:13 -------- d-----w- c:\documents and settings\LYNDA\Application Data\Skype
2009-08-14 16:02 . 2002-01-01 01:29 -------- d-----w- c:\documents and settings\LYNDA\Application Data\skypePM
2009-08-08 11:34 . 2009-07-21 11:46 -------- d-----w- c:\program files\Hewlett-Packard
2009-08-07 08:07 . 2001-08-28 11:00 49494 ----a-w- c:\windows.0\system32\perfc00C.dat
2009-08-07 08:07 . 2001-08-28 11:00 370414 ----a-w- c:\windows.0\system32\perfh00C.dat
2009-08-06 13:02 . 2009-05-13 21:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-07-23 07:41 . 2009-06-15 22:11 -------- d-----w- c:\program files\MediaCoder
2009-07-23 07:41 . 2009-06-15 22:11 -------- d-----w- c:\documents and settings\LYNDA\Application Data\Broad Intelligence
2009-07-23 07:40 . 2009-07-21 21:39 -------- d-----w- c:\documents and settings\LYNDA\Application Data\uTorrent
2009-07-21 11:46 . 2009-07-21 11:46 -------- d-----w- c:\program files\HP
2009-07-21 06:52 . 2009-07-21 06:52 499712 ----a-w- c:\windows.0\system32\msvcp71.dll
2009-07-21 06:52 . 2009-07-21 06:52 348160 ----a-w- c:\windows.0\system32\msvcr71.dll
2009-07-18 16:20 . 2009-07-18 16:20 1506816 ----a-w- c:\windows.0\system32\SET52C.tmp
2009-07-18 16:20 . 2009-07-18 16:20 3083264 ----a-w- c:\windows.0\system32\SET531.tmp
2009-07-15 19:08 . 2009-05-13 21:00 443552 ----a-w- c:\documents and settings\LYNDA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-07-13 14:16 . 2009-07-13 14:15 -------- d-----w- c:\documents and settings\LYNDA\Application Data\MSNInstaller
2009-07-10 20:35 . 2002-01-01 04:21 -------- d-----w- c:\program files\InstallShield Installation Information
2009-07-10 20:15 . 2009-07-10 20:15 -------- d-----w- c:\program files\KONAMI
2009-07-09 20:13 . 2009-07-09 20:13 -------- d-----r- c:\program files\Skype
2009-07-09 20:13 . 2009-07-09 20:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
2009-07-09 20:13 . 2009-07-09 20:13 -------- d-----w- c:\program files\Fichiers communs\Skype
2009-07-07 08:13 . 2002-01-01 04:21 1734 --sha-w- c:\windows.0\system32\KGyGaAvL.sys
2009-07-06 21:18 . 2009-05-13 21:50 -------- d-----w- c:\documents and settings\LYNDA\Application Data\Yahoo!
2009-07-03 21:01 . 2009-07-03 21:01 298104 ----a-w- c:\windows.0\system32\imon.dll
2009-07-03 21:01 . 2009-07-03 21:01 512096 ----a-w- c:\windows.0\system32\drivers\amon.sys
2009-07-03 21:01 . 2009-07-03 21:01 15424 ----a-w- c:\windows.0\system32\drivers\nod32drv.sys
2009-07-01 19:59 . 2009-06-01 14:56 -------- d-----w- c:\program files\Eset
2009-06-26 16:18 . 2009-06-26 16:18 663552 ----a-w- c:\windows.0\system32\SET529.tmp
2009-06-26 16:18 . 2004-08-19 15:09 663552 ----a-w- c:\windows.0\system32\wininet.dll
2009-06-26 16:18 . 2009-06-26 16:18 618496 ----a-w- c:\windows.0\system32\SET52A.tmp
2009-06-26 16:18 . 2009-06-26 16:18 474624 ----a-w- c:\windows.0\system32\SET52B.tmp
2009-06-26 16:18 . 2004-08-19 15:09 81920 ----a-w- c:\windows.0\system32\ieencode.dll
2009-06-26 16:18 . 2009-06-26 16:18 1024000 ----a-w- c:\windows.0\system32\SET539.tmp
2009-06-23 00:23 . 2009-06-23 00:23 371200 ------w- c:\windows.0\system32\SET53B.tmp
2009-06-16 14:54 . 2004-08-19 15:09 119808 ----a-w- c:\windows.0\system32\t2embed.dll
2009-06-16 14:54 . 2001-08-28 11:00 82432 ----a-w- c:\windows.0\system32\fontsub.dll
2009-06-06 10:18 . 2009-05-15 00:04 75096 ----a-w- c:\windows.0\system32\drivers\avipbb.sys
2009-06-03 21:53 . 2009-06-03 21:53 52056 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\UPDATE\AVUPDATE_4a26f0bf\winwks\fr\basic-nt\xp\avgntflt.sys
2009-06-03 21:53 . 2009-06-03 21:53 208624 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\UPDATE\AVUPDATE_4a26f0bf\winwks\fr\basic-nt\avwsc.exe
2009-06-03 21:53 . 2009-06-03 21:53 11608 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\UPDATE\AVUPDATE_4a26f0bf\winwks\fr\basic-nt\avgio.sys
2009-06-03 19:27 . 2004-08-19 15:09 1296896 ----a-w- c:\windows.0\system32\quartz.dll
2002-01-01 04:21 . 2002-01-01 04:21 56 --sh--r- c:\windows.0\system32\7D016E3D31.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EB5CEE80-030A-4ED8-8E20-454E9C68380F}]
2009-08-13 07:40 1862592 ----a-w- c:\program files\Bandoo\Plugins\IE\ieplugin.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
"Google Update"="c:\documents and settings\LYNDA\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2002-01-01 133104]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-19 1667584]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-21 24264488]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_07\bin\jusched.exe" [2006-05-03 36975]
"nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-07-03 949376]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows.0\system32\CTFMON.EXE" [2004-08-19 15360]
c:\documents and settings\LYNDA\Menu D‚marrer\Programmes\D‚marrage\
SkypeMate.lnk - c:\program files\SkypeMate\SkypeMate.exe [2007-5-22 405504]
c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
AudioDeck.lnk - c:\program files\VIA Technologies, Inc\VIA Audio Driver Setup Program\AudioDeck\AudioDeck.exe [2009-5-13 581632]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
"1"= cmd.exe
"2"= mmc.exe
"3"= rstrui.exe
"4"= regedit.exe
"5"= regedt32.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Bandoo\BndHook.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS.0\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R1 nod32drv;nod32drv;c:\windows.0\system32\drivers\nod32drv.sys [03/07/2009 21:01 15424]
S3 CrystalSysInfo;CrystalSysInfo;\??\c:\program files\MediaCoder\SysInfo.sys --> c:\program files\MediaCoder\SysInfo.sys [?]
S3 Vsp;Vsp;c:\windows.0\system32\drivers\vsp.sys [13/05/2009 21:37 3351]
.
Contents of the 'Scheduled Tasks' folder
2009-08-24 c:\windows.0\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1532298954-839522115-1003Core.job
- c:\documents and settings\LYNDA\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2002-01-01 21:50]
2009-08-27 c:\windows.0\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1532298954-839522115-1003UA.job
- c:\documents and settings\LYNDA\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2002-01-01 21:50]
.
- - - - ORPHANS REMOVED - - - -
Notify-reset5c - (no file)
Vous n’avez pas trouvé la réponse que vous recherchez ?
Posez votre question
Que faire merci pour ton aide .