Virus page d accueil

loudo -  
 loudo -
bonjours jai un probleme avec ma page d acueil quand je clic ca me mais une autre page que free j ai ete dans options internet mais rien y fait il revient toujours je pense que c est un virus mais je n arrive pas a le repare avec antivir merci de me repondre rapidement loudo

2 réponses

  1. tufs
     
    salut ludo

    commence par faire un nettoyage avec cette utilitaire gratuit

    http://www.softpedia.com/get/Internet/Popup-Ad-Spyware-Blockers/CWShredder.shtml

    pour le scanne tu arretes tes applis et tu te met en hors connection

    si problem persiste



    telecharge hijack ici :

    http://www.infos-du-net.com/telecharger/HijackThis.html

    tu scannes et save log et colle ton rapport

    tutos a lire :
    http://www.zebulon.fr/articles/HijackThis.php
    0
    1. loudo
       
      bonjours tufs voila mon rapports merci beaucoup loudo
      StartupList report, 26/03/2005, 14:39:50
      StartupList version: 1.52.2
      Started from : C:\DOCUME~1\Ludo\LOCALS~1\Temp\Rar$EX00.657\HijackThis.EXE
      Detected: Windows XP SP1 (WinNT 5.01.2600)
      Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
      * Using default options
      ==================================================

      Running processes:

      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\interMute\SpySubtract\SpySub.exe
      C:\Program Files\Media Access\MediaAccess.exe
      C:\Program Files\WinRAR\WinRAR.exe
      C:\DOCUME~1\Ludo\LOCALS~1\Temp\Rar$EX00.657\HijackThis.exe
      C:\WINDOWS\system32\NOTEPAD.EXE
      C:\Program Files\Media Access\MediaAccK.exe

      --------------------------------------------------

      Checking Windows NT UserInit:

      [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
      UserInit = C:\WINDOWS\SYSTEM32\Userinit.exe,

      --------------------------------------------------

      Autorun entries from Registry:
      HKLM\Software\Microsoft\Windows\CurrentVersion\Run

      Media Access = C:\Program Files\Media Access\MediaAccK.exe

      --------------------------------------------------

      Autorun entries from Registry:
      HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

      Srv32 spool service = C:\WINDOWS\System32\spoolsrv32.exe

      --------------------------------------------------

      Autorun entries from Registry:
      HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

      Srv32 spool service = C:\WINDOWS\System32\spoolsrv32.exe

      --------------------------------------------------

      Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

      Shell=*INI section not found*
      SCRNSAVE.EXE=*INI section not found*
      drivers=*INI section not found*

      Shell & screensaver key from Registry:

      Shell=Explorer.exe
      SCRNSAVE.EXE=C:\WINDOWS\System32\ssmypics.scr
      drivers=*Registry value not found*

      Policies Shell key:

      HKCU\..\Policies: Shell=*Registry key not found*
      HKLM\..\Policies: Shell=*Registry value not found*

      --------------------------------------------------


      Enumerating Download Program Files:

      [Shockwave Flash Object]
      InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
      CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

      --------------------------------------------------

      Enumerating ShellServiceObjectDelayLoad items:

      PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
      CDBurn: C:\WINDOWS\system32\SHELL32.dll
      WebCheck: C:\WINDOWS\System32\webcheck.dll
      SysTray: C:\WINDOWS\System32\stobject.dll

      --------------------------------------------------
      End of report, 3 453 bytes
      Report generated in 0,010 seconds

      Command line options:
      /verbose - to add additional info on each section
      /complete - to include empty sections and unsuspicious data
      /full - to include several rarely-important sections
      /force9x - to include Win9x-only startups even if running on WinNT
      /forcent - to include WinNT-only startups even if running on Win9x
      /forceall - to include all Win9x and WinNT startups, regardless of platform
      /history - to list version history only
      0