Ouverture de fenêtre inetrnet

yassouah225 Messages postés 49 Date d'inscription   Statut Membre Dernière intervention   -  
Narco!4 Messages postés 2446 Statut Contributeur -
Bonjour,
Lorsque je suis en train de surfer, une fenêtre intempestive me redirigeant sur "www.thenewsphedia.com" apparaît à chaque fois et me gène dans la navigation que faire?
PS: j'ai avst eu alvira comme antivirus.
Merci pour votre aide.
Configuration: Windows XP Internet Explorer 6.0

5 réponses

  1. Narco!4 Messages postés 2446 Statut Contributeur 467
     
    Bonjour,

    télécharge GenProc http://www.genproc.com/GenProc.exe

    double-clique sur GenProc.exe et poste le contenu du rapport qui s'ouvre
    0
    1. yassouah225 Messages postés 49 Date d'inscription   Statut Membre Dernière intervention  
       
      Je n'arrive pa a installer "genproc" sa me met application non valide sous windows.
      Que faire merci pour ton aide .
      0
  2. Narco!4 Messages postés 2446 Statut Contributeur 467
     
    supprime C:\genproc
    refait
    0
    1. yassouah225 Messages postés 49 Date d'inscription   Statut Membre Dernière intervention  
       
      désolé mais j'arive pas a installer genproc.
      ya pa un autre moyen stp?
      merci
      0
  3. Narco!4 Messages postés 2446 Statut Contributeur 467
     
    [*] Télécharge combofix (sUBs) http://download.bleepingcomputer.com/sUBs/ComboFix.exe sur ton Bureau
    [*] Double clique combofix.exe et suis les instructions.
    [*] Installe la console de récupération si proposé et continue.
    [*] Lorsque le scan sera complété, un rapport apparaîtra. Copie/colle ce rapport dans ta prochaine réponse.

    NOTE : Le rapport se trouve également ici : C:\Combofix.txt
    0
    1. yassouah225 Messages postés 49 Date d'inscription   Statut Membre Dernière intervention  
       
      Merci mon ami enfin le rapport:

      ComboFix 09-08-26.05 - LYNDA 27/08/2009 10:03.1.1 - NTFSx86
      Microsoft Windows XP Professionnel 5.1.2600.2.1252.33.1036.18.479.179 [GMT 0:00]
      Running from: c:\documents and settings\LYNDA\Bureau\ComboFix.exe
      AV: Avira AntiVir PersonalEdition Classic *On-access scanning enabled* (Outdated) {AD166499-45F9-482A-A743-FDD3350758C7}
      AV: ESET NOD32 antivirus system 2.70 *On-access scanning enabled* (Outdated) {E5E70D32-0101-4F12-8FB0-D96ACA4F34C0}
      * Created a new restore point
      * Resident AV is active


      WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
      .
      The following files were disabled during the run:
      c:\program files\SuperCopier2\SC2Hook.dll


      ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      c:\documents and settings\LYNDA\Application Data\bcrypt.html
      c:\documents and settings\LYNDA\Application Data\wiaservg.log
      c:\recycler\S-1-5-21-0230571862-8073567460-651502566-7001
      c:\recycler\S-1-5-21-0288623198-8866559897-437571247-3978
      c:\recycler\S-1-5-21-0486636189-9707273005-130844152-0929
      c:\recycler\S-1-5-21-0650345070-5024988155-468557058-2438
      c:\recycler\S-1-5-21-0969522414-0652210790-556649910-1847
      c:\recycler\S-1-5-21-1450088316-7557283054-414342581-8277
      c:\recycler\S-1-5-21-1787491829-9519218833-949674304-6550
      c:\recycler\S-1-5-21-2771733766-0664864309-331404561-0513
      c:\recycler\S-1-5-21-2827642907-9768275406-529170390-6475
      c:\recycler\S-1-5-21-3022529124-2239684218-559407462-3951
      c:\recycler\S-1-5-21-3396559448-9276541575-384120864-9245
      c:\recycler\S-1-5-21-3652671388-0767170813-888633538-8392
      c:\recycler\S-1-5-21-3702401964-6809589961-275348982-3263
      c:\recycler\S-1-5-21-3870417316-6141967149-038154061-3685
      c:\recycler\S-1-5-21-4023299429-4280124858-153493308-7430
      c:\recycler\S-1-5-21-4148920905-5687211967-190035029-0968
      c:\recycler\S-1-5-21-4300645589-4536226023-939056619-1238
      c:\recycler\S-1-5-21-4489814194-3748499410-665295639-3964
      c:\recycler\S-1-5-21-5031858728-3636244863-001092034-3550
      c:\recycler\S-1-5-21-5841099773-8590820267-779681499-1387
      c:\recycler\S-1-5-21-5917729725-5403560215-559902367-4564
      c:\recycler\S-1-5-21-6233480752-4400371017-103655022-0078
      c:\recycler\S-1-5-21-6270640658-8667183068-350476585-3962
      c:\recycler\S-1-5-21-6709699077-7120451112-860305334-0279
      c:\recycler\S-1-5-21-6747069472-4488632209-267735937-0336
      c:\recycler\S-1-5-21-6911879070-6221903753-832800236-3918
      c:\recycler\S-1-5-21-6944035029-0560909799-035497916-4560
      c:\recycler\S-1-5-21-7304190125-1074816314-286137622-5277
      c:\recycler\S-1-5-21-7455012135-3892403742-488872375-8417
      c:\recycler\S-1-5-21-7837779799-7365520782-638873713-2854
      c:\recycler\S-1-5-21-7870212293-8944310321-513972838-0835
      c:\recycler\S-1-5-21-8286757167-6577866078-627181941-2467
      c:\recycler\S-1-5-21-8326940476-5018267815-420714947-0619
      c:\recycler\S-1-5-21-8508793341-0882505776-126016583-1212
      c:\recycler\S-1-5-21-8810132774-7753276061-586578039-5247
      c:\recycler\S-1-5-21-8810132774-7753276061-586578039-5247\nissan.exe
      c:\recycler\S-1-5-21-9188399278-1686556444-525371324-4386
      c:\recycler\S-1-5-21-9412730359-4793745184-648877797-7638
      c:\recycler\S-1-5-21-9574622620-8768616270-270767205-7773
      c:\recycler\S-1-5-21-9727919948-7009612990-665615163-0928
      C:\System
      c:\system\FILES\Desktop.ini
      c:\windows.0\Fonts\refluxed.TTF
      c:\windows.0\Fonts\Wphv07nb.ttf
      c:\windows.0\system32\drivers\vsfocebgdrytqm.sys
      c:\windows.0\system32\vsfocednsdotje.dll
      c:\windows.0\system32\vsfocedodwoyxo.dll
      c:\windows.0\system32\vsfocexgxjcxuc.dat
      c:\windows.0\system32\vsfoceyocoeggy.dat

      .
      ((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
      .

      -------\Service_vsfoceshampkkj
      -------\Legacy_vsfoceshampkkj


      ((((((((((((((((((((((((( Files Created from 2009-07-27 to 2009-08-27 )))))))))))))))))))))))))))))))
      .

      2009-08-27 09:46 . 2009-08-27 09:46 -------- d-----w- C:\Genproc
      2009-08-26 19:50 . 2009-08-26 19:50 -------- d-----w- c:\documents and settings\LYNDA\Application Data\Bandoo
      2009-08-26 19:49 . 2009-08-26 20:26 -------- d-----w- c:\documents and settings\All Users\Application Data\Bandoo
      2009-08-26 19:49 . 2009-08-26 19:50 -------- d-----w- c:\program files\Bandoo
      2009-08-21 19:53 . 2009-08-23 16:14 -------- d-----w- c:\program files\Fichiers communs\Symantec Shared
      2009-08-20 08:55 . 2009-08-20 08:55 -------- d-----w- C:\spoolerlogs
      2009-08-17 15:02 . 2009-08-23 16:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
      2009-08-17 15:02 . 2009-08-17 15:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
      2009-08-17 15:02 . 2009-08-17 15:02 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
      2009-08-13 19:31 . 2009-08-13 19:31 -------- d-----w- c:\program files\WordBiz
      2009-08-07 03:10 . 2009-08-07 03:10 -------- d-----w- c:\program files\MSXML 4.0
      2009-08-01 15:46 . 2009-08-01 15:46 -------- d-----w- c:\documents and settings\LYNDA\Local Settings\Application Data\Identities

      .
      (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      2009-08-27 10:01 . 2009-05-13 21:48 -------- d-----w- c:\program files\SuperCopier2
      2009-08-19 21:33 . 2009-08-14 16:08 172 ----a-w- C:\curr_ver.tmp
      2009-08-14 21:29 . 2009-07-09 20:13 -------- d-----w- c:\documents and settings\LYNDA\Application Data\Skype
      2009-08-14 16:02 . 2002-01-01 01:29 -------- d-----w- c:\documents and settings\LYNDA\Application Data\skypePM
      2009-08-08 11:34 . 2009-07-21 11:46 -------- d-----w- c:\program files\Hewlett-Packard
      2009-08-07 08:07 . 2001-08-28 11:00 49494 ----a-w- c:\windows.0\system32\perfc00C.dat
      2009-08-07 08:07 . 2001-08-28 11:00 370414 ----a-w- c:\windows.0\system32\perfh00C.dat
      2009-08-06 13:02 . 2009-05-13 21:14 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
      2009-07-23 07:41 . 2009-06-15 22:11 -------- d-----w- c:\program files\MediaCoder
      2009-07-23 07:41 . 2009-06-15 22:11 -------- d-----w- c:\documents and settings\LYNDA\Application Data\Broad Intelligence
      2009-07-23 07:40 . 2009-07-21 21:39 -------- d-----w- c:\documents and settings\LYNDA\Application Data\uTorrent
      2009-07-21 11:46 . 2009-07-21 11:46 -------- d-----w- c:\program files\HP
      2009-07-21 06:52 . 2009-07-21 06:52 499712 ----a-w- c:\windows.0\system32\msvcp71.dll
      2009-07-21 06:52 . 2009-07-21 06:52 348160 ----a-w- c:\windows.0\system32\msvcr71.dll
      2009-07-18 16:20 . 2009-07-18 16:20 1506816 ----a-w- c:\windows.0\system32\SET52C.tmp
      2009-07-18 16:20 . 2009-07-18 16:20 3083264 ----a-w- c:\windows.0\system32\SET531.tmp
      2009-07-15 19:08 . 2009-05-13 21:00 443552 ----a-w- c:\documents and settings\LYNDA\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
      2009-07-13 14:16 . 2009-07-13 14:15 -------- d-----w- c:\documents and settings\LYNDA\Application Data\MSNInstaller
      2009-07-10 20:35 . 2002-01-01 04:21 -------- d-----w- c:\program files\InstallShield Installation Information
      2009-07-10 20:15 . 2009-07-10 20:15 -------- d-----w- c:\program files\KONAMI
      2009-07-09 20:13 . 2009-07-09 20:13 -------- d-----r- c:\program files\Skype
      2009-07-09 20:13 . 2009-07-09 20:12 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype
      2009-07-09 20:13 . 2009-07-09 20:13 -------- d-----w- c:\program files\Fichiers communs\Skype
      2009-07-07 08:13 . 2002-01-01 04:21 1734 --sha-w- c:\windows.0\system32\KGyGaAvL.sys
      2009-07-06 21:18 . 2009-05-13 21:50 -------- d-----w- c:\documents and settings\LYNDA\Application Data\Yahoo!
      2009-07-03 21:01 . 2009-07-03 21:01 298104 ----a-w- c:\windows.0\system32\imon.dll
      2009-07-03 21:01 . 2009-07-03 21:01 512096 ----a-w- c:\windows.0\system32\drivers\amon.sys
      2009-07-03 21:01 . 2009-07-03 21:01 15424 ----a-w- c:\windows.0\system32\drivers\nod32drv.sys
      2009-07-01 19:59 . 2009-06-01 14:56 -------- d-----w- c:\program files\Eset
      2009-06-26 16:18 . 2009-06-26 16:18 663552 ----a-w- c:\windows.0\system32\SET529.tmp
      2009-06-26 16:18 . 2004-08-19 15:09 663552 ----a-w- c:\windows.0\system32\wininet.dll
      2009-06-26 16:18 . 2009-06-26 16:18 618496 ----a-w- c:\windows.0\system32\SET52A.tmp
      2009-06-26 16:18 . 2009-06-26 16:18 474624 ----a-w- c:\windows.0\system32\SET52B.tmp
      2009-06-26 16:18 . 2004-08-19 15:09 81920 ----a-w- c:\windows.0\system32\ieencode.dll
      2009-06-26 16:18 . 2009-06-26 16:18 1024000 ----a-w- c:\windows.0\system32\SET539.tmp
      2009-06-23 00:23 . 2009-06-23 00:23 371200 ------w- c:\windows.0\system32\SET53B.tmp
      2009-06-16 14:54 . 2004-08-19 15:09 119808 ----a-w- c:\windows.0\system32\t2embed.dll
      2009-06-16 14:54 . 2001-08-28 11:00 82432 ----a-w- c:\windows.0\system32\fontsub.dll
      2009-06-06 10:18 . 2009-05-15 00:04 75096 ----a-w- c:\windows.0\system32\drivers\avipbb.sys
      2009-06-03 21:53 . 2009-06-03 21:53 52056 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\UPDATE\AVUPDATE_4a26f0bf\winwks\fr\basic-nt\xp\avgntflt.sys
      2009-06-03 21:53 . 2009-06-03 21:53 208624 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\UPDATE\AVUPDATE_4a26f0bf\winwks\fr\basic-nt\avwsc.exe
      2009-06-03 21:53 . 2009-06-03 21:53 11608 ----a-w- c:\documents and settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\UPDATE\AVUPDATE_4a26f0bf\winwks\fr\basic-nt\avgio.sys
      2009-06-03 19:27 . 2004-08-19 15:09 1296896 ----a-w- c:\windows.0\system32\quartz.dll
      2002-01-01 04:21 . 2002-01-01 04:21 56 --sh--r- c:\windows.0\system32\7D016E3D31.sys
      .

      ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
      .
      .
      *Note* empty entries & legit default entries are not shown
      REGEDIT4

      [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EB5CEE80-030A-4ED8-8E20-454E9C68380F}]
      2009-08-13 07:40 1862592 ----a-w- c:\program files\Bandoo\Plugins\IE\ieplugin.dll

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "SuperCopier2.exe"="c:\program files\SuperCopier2\SuperCopier2.exe" [2006-07-07 1052672]
      "msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-06 3885408]
      "Google Update"="c:\documents and settings\LYNDA\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2002-01-01 133104]
      "MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-08-19 1667584]
      "Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-04-21 24264488]

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "avgnt"="c:\program files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-06-12 266497]
      "SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_07\bin\jusched.exe" [2006-05-03 36975]
      "nod32kui"="c:\program files\Eset\nod32kui.exe" [2009-07-03 949376]

      [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
      "CTFMON.EXE"="c:\windows.0\system32\CTFMON.EXE" [2004-08-19 15360]

      c:\documents and settings\LYNDA\Menu D‚marrer\Programmes\D‚marrage\
      SkypeMate.lnk - c:\program files\SkypeMate\SkypeMate.exe [2007-5-22 405504]

      c:\documents and settings\All Users\Menu D‚marrer\Programmes\D‚marrage\
      AudioDeck.lnk - c:\program files\VIA Technologies, Inc\VIA Audio Driver Setup Program\AudioDeck\AudioDeck.exe [2009-5-13 581632]

      [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\disallowrun]
      "1"= cmd.exe
      "2"= mmc.exe
      "3"= rstrui.exe
      "4"= regedit.exe
      "5"= regedt32.exe

      [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
      "AppInit_DLLs"=c:\progra~1\Bandoo\BndHook.dll

      [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
      "%windir%\\system32\\sessmgr.exe"=
      "c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
      "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
      "c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
      "c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
      "c:\\WINDOWS.0\\system32\\dpvsetup.exe"=
      "c:\\Program Files\\Messenger\\msmsgs.exe"=
      "c:\\Program Files\\Skype\\Phone\\Skype.exe"=

      R1 nod32drv;nod32drv;c:\windows.0\system32\drivers\nod32drv.sys [03/07/2009 21:01 15424]
      S3 CrystalSysInfo;CrystalSysInfo;\??\c:\program files\MediaCoder\SysInfo.sys --> c:\program files\MediaCoder\SysInfo.sys [?]
      S3 Vsp;Vsp;c:\windows.0\system32\drivers\vsp.sys [13/05/2009 21:37 3351]
      .
      Contents of the 'Scheduled Tasks' folder

      2009-08-24 c:\windows.0\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1532298954-839522115-1003Core.job
      - c:\documents and settings\LYNDA\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2002-01-01 21:50]

      2009-08-27 c:\windows.0\Tasks\GoogleUpdateTaskUserS-1-5-21-515967899-1532298954-839522115-1003UA.job
      - c:\documents and settings\LYNDA\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2002-01-01 21:50]
      .
      - - - - ORPHANS REMOVED - - - -

      Notify-reset5c - (no file)
      0
  4. Narco!4 Messages postés 2446 Statut Contributeur 467
     
    tu arrive a lancé genproc maintenant ?
    0
    1. yassouah225 Messages postés 49 Date d'inscription   Statut Membre Dernière intervention  
       
      non je n'arrive pas toujours à lancer genpro.
      c'est grave ? je suis inquiet.
      merci
      0
  5. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  6. Narco!4 Messages postés 2446 Statut Contributeur 467
     
    Tu arrive a lancé genproc maintenant ?
    0