Page de demarrage non voulue

Résolu
Bonjour à tous,
Je suis sous WIN XP Media Center
J'ai un acces internet pour Wanadoo, qui marche.
Mais malgres tous mes efforts la page de demarrage voulue ( Orange.fr ) est systematiquement remplacée par une page Windows live dont l'adresse est www.live.com/?searchonly=true.
Que dois je faire ?
Je desire obtenir la page de demarrage d'Orange..

Merci de vos reponses et surtout de vos solutions
Richard

24 réponses

Résumé de la discussion

Le problème de changement répété de la page d'accueil vers live.com sur Windows XP avec Wanadoo/Orange, au détriment de la page Orange.fr souhaitée, est rapporté. Des solutions évoquées privilégient la modification manuelle dans les options d'Internet Explorer, l'utilisation du bouton Apply, et l'identification d'infections via des outils tels que HijackThis et des sauvegardes. Plusieurs échanges insistent sur l'éventualité d'une infection et sur la nécessité de diagnostiquer les entrées dans les barres d'outils et les pages de démarrage, en consultant les journaux HijackThis. Un témoin signale qu'après suppression et réinstallation, la page d'accueil Orange réapparaît parfois, mais d'autres cas restent bloqués sur live.com, sans que l'état final soit tranché.

Bobot (l’IA à votre service)
  1. Salut !
    Soit tu as de la chance, soit tu n'en n'as pas...
    On va faire une première chose :

    1- ouvre une page sous internet explorer
    2- au dessus, menu outils/options internet
    3- dans la case qui est surlignée, remplace l'adresse actuelle par https://www.orange.fr/portail
    4- Puis "appliquer" puis "ok".

    5- Eteinds ton PC et retourne ici même pour me dire si ta page de démarrage a encore changé.

    Si elle a changé, ton PC est sûrement infecté.
    0
  2. On dirait que tu as installé Windows Live Messenger, non ?

    Pour commencer, ça ne fera pas de mal :
    un peu d'entretien sur le disque dur :
    Menu démarrer, poste de travail, clic droit sur disque C puis propriétés, nettoyage de disque.
    Coche tout sauf "compression des fichiers" puis fais OK.

    A faire régulièrement.

    Ensuite seulement, un peu de recherche de fichiers espions, applique ceci à la lettre :
    http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm
    puis :
    http://usa.lucretius-ada.com/zcvisitor/8782d344-4821-11ea-83ce-0a2cdf2c6be7?campaignid=0d1dff40-82d7-11e9-9533-0a157bfa6bfc

    Quand c'est fait, reviens nous tenir au courant.
    0
    1. Contributeur
      un petit Hijack triple ... ;-)
      0
    2. @Séb08Oui, Seb,
      mais je préfère indiquer aux gens un moyen simple d'entretenir leur PC eux-même pour plus tard.
      Et pour le Hijack, je ne suis pas encore au point. Mais puisque tu es là, tu vas m'aider !!!
      ;-)
      0
    3. Contributeur
      @3xY'a pas de prob entre régionaux ! ;-)
      0
  3. Bonjour,

    J'ai effectivement installé Windows live messenger...

    J'ai nettoyé mon DD, pas de probleme particulier ( mon DD est neuf et n'a pas encore été trop utilisé

    J'ai telechargé, mis à jour et lancé Spybot, corrigé les erreurs ( des MRU sans importance et des "tracking cookies à notation TAC3 )

    Le probleme subsiste...

    Merci de votre aide pour la suite.

    Seb08 parle de Hijack ???? j'avoue que je suis completement ignare sur ce sujet...
    0
    1. Contributeur
      télécharge HijackThis (version francaise) ici:
      hijackthis

      Dézippe le dans un dossier prévu à cet effet.

      Par exemple C:\hijackthis < Enregistre le bien dans c : !

      Démo (merci à Balltrap) :
      instalation hijackthis
      http://pageperso.aol.fr/balltrap34/Hijenr.gif

      Lance le puis:
      clique sur "faire un scan et sauvegarder le log" (cf démo)
      faire un copier coller du log entier sur le forum

      Démo : (merci à balltrap34 pour cette réalisation)
      http://pageperso.aol.fr/balltrap34/demohijack.htm

      a+
      0
      1. Ci-joint le Log de Hijackthis, j'avoue que je n'y comprend rien !!

        Logfile of HijackThis v1.99.1
        Scan saved at 13:25:03, on 07/10/2006
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
        C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
        C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
        C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
        C:\WINDOWS\system32\dllhost.exe
        C:\WINDOWS\eHome\ehRecvr.exe
        C:\WINDOWS\eHome\ehSched.exe
        C:\WINDOWS\System32\FTRTSVC.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
        C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
        C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
        C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
        C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
        C:\WINDOWS\system32\nvsvc32.exe
        C:\Apps\Softex\OmniPass\Omniserv.exe
        C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
        C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
        C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
        C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
        C:\Apps\Softex\OmniPass\OPXPApp.exe
        C:\WINDOWS\Explorer.EXE
        C:\WINDOWS\ehome\ehtray.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
        C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        C:\WINDOWS\RTHDCPL.EXE
        C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
        C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
        C:\WINDOWS\eHome\ehmsas.exe
        C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
        C:\Apps\Softex\OmniPass\scureapp.exe
        C:\apps\ABoard\ABoard.exe
        C:\WINDOWS\vVX3000.exe
        C:\apps\ABoard\AOSD.exe
        C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
        C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
        C:\Program Files\Real\RealPlayer\RealPlay.exe
        C:\APPS\SMP\SmpSys.exe
        C:\WINDOWS\system32\ctfmon.exe
        C:\Program Files\MSN Messenger\MsnMsgr.Exe
        C:\APPS\skype\phone\Skype.exe
        C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
        C:\PROGRA~1\Wanadoo\ComComp.exe
        C:\PROGRA~1\Wanadoo\Toaster.exe
        C:\PROGRA~1\Wanadoo\Inactivity.exe
        C:\PROGRA~1\Wanadoo\PollingModule.exe
        C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
        C:\PROGRA~1\Wanadoo\Watch.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
        D:\DOCUME~1\Riclev\LOCALS~1\Temp\Répertoire temporaire 1 pour hijackthis.zip\HijackThis.exe
        C:\Program Files\Messenger\msmsgs.exe

        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.orange.fr/portail
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http//www.orange.fr
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.orange.fr/portail
        R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.orange.fr/portail
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
        O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
        O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
        O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
        O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
        O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
        O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
        O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
        O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
        O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
        O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
        O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
        O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe
        O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
        O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
        O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
        O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
        O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
        O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
        O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
        O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
        O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
        O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
        O4 - HKCU\..\Run: [Skype] "C:\APPS\skype\phone\Skype.exe" /nosplash /minimized
        O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
        O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
        O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
        O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
        O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
        O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
        O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
        O17 - HKLM\System\CCS\Services\Tcpip\..\{8BBD2426-2F65-4F0C-8514-112DCB3709E3}: NameServer = 80.10.246.130 80.10.246.3
        O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
        O20 - Winlogon Notify: OPXPGina - C:\Apps\Softex\OmniPass\opxpgina.dll
        O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
        O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
        O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
        O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
        O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
        O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
        O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
        O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
        O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
        O23 - Service: MpService - Canon Inc. - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
        O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
        O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
        O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe
        O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
        O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
        O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
        O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
        O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
        O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
        O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
        O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

        Merci
        0
        1. Contributeur
          J'ai pourtant mis l'explication de l'installation de Hijack .... ;-)

          Ici comme tu l'as installé :

          D:\DOCUME~1\Riclev\LOCALS~1\Temp\Répertoire temporaire 1 pour hijackthis.zip\HijackThis.exe

          il n'y est pas bien car tu n'auras pas accès au backups en cas de mauvaises manips.

          Alors merci de le désinstaller et de le réinstaller correctement comme cité ( voir démo cité + haut)

          A+
          0
          1. Mes excuses, mais je n'ai pas pu telecharger à partir de ce que tu m'as donné...
            je l'ai telechargé autrement, voici le nouveau Log, j'espere que celui là convient !

            Merci

            Logfile of HijackThis v1.99.1
            Scan saved at 13:41:29, on 07/10/2006
            Platform: Windows XP SP2 (WinNT 5.01.2600)
            MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

            Running processes:
            C:\WINDOWS\System32\smss.exe
            C:\WINDOWS\system32\winlogon.exe
            C:\WINDOWS\system32\services.exe
            C:\WINDOWS\system32\lsass.exe
            C:\WINDOWS\system32\svchost.exe
            C:\WINDOWS\System32\svchost.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
            C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
            C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
            C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
            C:\WINDOWS\system32\spoolsv.exe
            C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
            C:\WINDOWS\system32\dllhost.exe
            C:\WINDOWS\eHome\ehRecvr.exe
            C:\WINDOWS\eHome\ehSched.exe
            C:\WINDOWS\System32\FTRTSVC.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
            C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
            C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
            C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
            C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
            C:\WINDOWS\system32\nvsvc32.exe
            C:\Apps\Softex\OmniPass\Omniserv.exe
            C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
            C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
            C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
            C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
            C:\Apps\Softex\OmniPass\OPXPApp.exe
            C:\WINDOWS\Explorer.EXE
            C:\WINDOWS\ehome\ehtray.exe
            C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
            C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
            C:\WINDOWS\RTHDCPL.EXE
            C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
            C:\WINDOWS\eHome\ehmsas.exe
            C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
            C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
            C:\Apps\Softex\OmniPass\scureapp.exe
            C:\apps\ABoard\ABoard.exe
            C:\WINDOWS\vVX3000.exe
            C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
            C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
            C:\apps\ABoard\AOSD.exe
            C:\Program Files\Real\RealPlayer\RealPlay.exe
            C:\APPS\SMP\SmpSys.exe
            C:\WINDOWS\system32\ctfmon.exe
            C:\Program Files\MSN Messenger\MsnMsgr.Exe
            C:\APPS\skype\phone\Skype.exe
            C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
            C:\PROGRA~1\Wanadoo\ComComp.exe
            C:\PROGRA~1\Wanadoo\Toaster.exe
            C:\PROGRA~1\Wanadoo\Inactivity.exe
            C:\PROGRA~1\Wanadoo\PollingModule.exe
            C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
            C:\PROGRA~1\Wanadoo\Watch.exe
            C:\Program Files\Internet Explorer\iexplore.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
            C:\Program Files\Canon\MultiPASS4\MPDBMgr.exe
            C:\WINDOWS\system32\svchost.exe
            C:\Program Files\Messenger\msmsgs.exe
            C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
            C:\PROGRA~1\HIJACK~1\HIJACK~1.EXE

            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.orange.fr/portail
            R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http//www.orange.fr
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.orange.fr/portail
            R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.orange.fr/portail
            R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
            R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
            R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
            O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
            O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
            O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
            O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
            O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
            O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
            O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
            O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
            O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
            O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
            O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
            O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
            O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
            O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
            O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
            O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
            O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
            O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
            O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
            O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
            O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe
            O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
            O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
            O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
            O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
            O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
            O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
            O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
            O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
            O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
            O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
            O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
            O4 - HKCU\..\Run: [Skype] "C:\APPS\skype\phone\Skype.exe" /nosplash /minimized
            O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
            O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
            O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
            O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
            O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
            O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
            O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
            O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
            O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm
            O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
            O17 - HKLM\System\CCS\Services\Tcpip\..\{8BBD2426-2F65-4F0C-8514-112DCB3709E3}: NameServer = 80.10.246.130 80.10.246.3
            O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
            O20 - Winlogon Notify: OPXPGina - C:\Apps\Softex\OmniPass\opxpgina.dll
            O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
            O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
            O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
            O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
            O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
            O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
            O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
            O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
            O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
            O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
            O23 - Service: MpService - Canon Inc. - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
            O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
            O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
            O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
            O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe
            O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
            O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
            O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
            O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
            O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
            O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
            O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
            O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
            0
            1. Contributeur
              Dézippe le dans un dossier prévu à cet effet.

              Par exemple C:\hijackthis < Enregistre le bien dans c : !

              Démo (merci à Balltrap) :
              instalation hijackthis
              http://pageperso.aol.fr/balltrap34/Hijenr.gif
              0
              1. Bonsoir,
                J'ai joint un deuxieme Log apres avoir bien fait l'installation sous C
                Celui là devrait aller mieux...
                Merci de la suite donnée à mon probleme

                Je n'y connais rien mais dans Regedit je ne trouve pas
                HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

                peut etre un debut d'explication ?
                0
                1. Contributeur
                  c'est toi qui voit,pose le moins de question posible merci !

                  On va faire un peu le ménage ... ;-)

                  **********************************************

                  ¤Télécharge ces logiciels (si tu ne les as pas) mais que tu n‘utilises pas tout de suite:

                  (Les mettre à jour avant de les lancer). Pour ça voir les démos.

                  Antispywares et autres :

                  1/ Ad-Aware (gratuit)
                  Téléchargement :
                  http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/11643.html
                  Le patch en Français pour Ad-Aware (gratuit) :
                  http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/25543.html
                  Tuto :
                  http://perso.orange.fr/entraide-hijackthis/AdAware/AdAware.htm

                  2/ Spybot (gratuit) :
                  voir demo d utilisation (merci Balltrap)
                  http://pageperso.aol.fr/Balltrap34/demo%20spybot.htm
                  Téléchargement :
                  http://telecharger.01net.com/windows/Internet/internet_utlitaire/fiches/26157.html

                  3/ ewido (dowload)
                  Téléchargement :
                  https://www.avg.com/en-ww/free-antivirus-download
                  Lorsqu'il est installer tu l'ouvres clique sur « update » fais les mise à jour
                  Tuto pour la version 4 d’Ewido :
                  https://www.malekal.com/tutorial-et-guide-ewido-v4/

                  Nettoyeurs (de fichiers inutiles) et autres :

                  4/ ccleaner (gratuit)
                  Tutorial là :
                  https://www.vulgarisation-informatique.com/nettoyer-windows-ccleaner.php
                  Téléchargement :
                  www.01net.com

                  *****************************************************
                  Affiches tous les fichiers et dossiers :
                  cliques sur démarrer/panneau de configuration (en affichage classique)/option des dossiers/affichage
                  Cocher « afficher les dossiers et fichiers cachés »

                  Décoches la case "Masquer les fichiers protégés du système d'exploitation (recommandé)"

                  Décoches « masquer les extensions dont le type est connu »
                  Puis fais «Ok» pour valider les changements.

                  Et « appliquer »

                  ****************************************************
                  ¤Relance HijackThis cliques sur « scanner seulement » ou (« do a scan only »),
                  coche les cases devant ces lignes et ensuite clique sur « fixer objets » (ou « fix checked »):

                  R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http//www.orange.fr
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.orange.fr/portail
                  R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.orange.fr/portail
                  R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
                  R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens

                  O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

                  O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\fr.htm

                  O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe


                  ************************************************
                  Arrête ces services France Telecom Routing Table Service pour ça fais cette manip :
                  Démarrer -> executer tape services.msc clic droit sur les services cités - > propriétés et dans "type de démarrage" et mets le sur « arrêté « et « désactivé ».

                  ************************************************
                  ¤Démarre en mode sans échec :
                  Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter
                  Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec
                  puis tape « entrée ».
                  Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                  (Si F8 ne marche pas utilise la touche F5).

                  **********************************************
                  ¤Recherche et supprime ceci:
                  attention seulement les fichiers (si présents).

                  C:\WINDOWS\System32\FTRTSVC.exe

                  ALCMTR.EXE

                  ************************************************
                  ¤ Lancer Ewido pour un scan complet (clique sur « scanner » puis sur « complete scan system ») « delete » tout ce qu’il te trouve
                  et copie/colle le rapport en forum.
                  ************************************************
                  ¤ Passe Ad-Aware et supprime tout ce qu’il trouve + supprime les quarantaines…
                  ************************************************
                  ¤ Passe Spybot et corrige tout ce qu’il trouve + vaccine + supprime les quarantaines…
                  ***********************************************
                  ¤ Lance CCleaner.

                  Suppression des fichiers temporaires

                  Va dans la section "Options" situé dans la marge gauche. Va dans "Avancé" et décoche "Effacer uniquement les fichiers, du dossier Temp de Windows, plus vieux que 48 heures". Retourne ensuite dans la section "Nettoyeur"
                  Fais bien attention de cocher toutes les cases dans la marge gauche (Internet Explorer/Windows Explorer/Système/Avancé)
                  • Clique sur Analyse
                  • Patiente le temps du scan, qui peut prendre un peu de temps si c'est la première fois.
                  • Une fois le scan terminé, clique sur Lancer le Nettoyage

                  Suppression des incohérence du registre

                  • Clique sur l'icône Erreurs situés dans la marge à gauche.
                  • Puis clique sur Analyser les erreurs
                  • Patiente pendant que CCleaner scan ton registre.
                  • Une fois le scan terminé, coche toutes les entrèes qu'il t'aura trouvée.
                  • Tu peux cliquer ensuite sur Corriger les erreurs.

                  Si tu n'est pas sur de ce que tu fais, tu peux choisir de sauvegarder les entrées cochées pour les restaurer ultérieurement.

                  *************************************************
                  ¤ Vide ta Corbeille.
                  *************************************************
                  ¤ Redémarre en mode normal, relance Hijackthis et copie/colle un nouveau rapport sur le forum.

                  ************************************************

                  Peux tu me scanner ce fichier en gras :

                  C:\WINDOWS\system32\dllhost.exe

                  avec ceci :

                  http://www.virustotal.com/en/virustotalx.html

                  clique sur "parcourir" va rechercher le fichier et ensuite "send" copie/colle le rapport générer.

                  A+

                  0
                  1. Merci Seb08, je vois çà demain matin et te donne tout ce que tu demande.

                    Merci encore de ta gentillesse, c'est vraiment tres sympa d'aider les gens comme tu le fait, si tout le monde etait comme toi !!!!

                    Merci encore

                    A+
                    0
                  2. Contributeur
                    ok bonne soirée .

                    A+ ;-)
                    0
                  3. J'ai suivi à la lettre ce que tu demandais...

                    RAPPORT EWIDO

                    AVG Anti-Spyware - Rapport d'analyse
                    ---------------------------------------------------------

                    + Créé à: 22:53:07 07/10/2006

                    + Résultat de l'analyse:

                    D:\Documents and Settings\Riclev\Cookies\riclev@247realmedia[1].txt -> TrackingCookie.247realmedia : Aucune action entreprise.
                    D:\Documents and Settings\Riclev\Cookies\riclev@aolfr.122.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
                    D:\Documents and Settings\Riclev\Cookies\riclev@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Aucune action entreprise.
                    D:\Documents and Settings\Riclev\Cookies\riclev@bluestreak[1].txt -> TrackingCookie.Bluestreak : Aucune action entreprise.
                    D:\Documents and Settings\Riclev\Cookies\riclev@serving-sys[1].txt -> TrackingCookie.Serving-sys : Aucune action entreprise.
                    D:\Documents and Settings\Riclev\Cookies\riclev@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Aucune action entreprise.
                    D:\Documents and Settings\Riclev\Cookies\riclev@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Aucune action entreprise.
                    D:\Documents and Settings\Riclev\Cookies\riclev@weborama[2].txt -> TrackingCookie.Weborama : Aucune action entreprise.

                    Fin du rapport

                    RAPPORT HIJACKTHIS

                    Logfile of HijackThis v1.99.1
                    Scan saved at 23:34:26, on 07/10/2006
                    Platform: Windows XP SP2 (WinNT 5.01.2600)
                    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

                    Running processes:
                    C:\WINDOWS\System32\smss.exe
                    C:\WINDOWS\system32\winlogon.exe
                    C:\WINDOWS\system32\services.exe
                    C:\WINDOWS\system32\lsass.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\WINDOWS\System32\svchost.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                    C:\WINDOWS\system32\spoolsv.exe
                    C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    C:\WINDOWS\system32\dllhost.exe
                    C:\WINDOWS\eHome\ehRecvr.exe
                    C:\WINDOWS\eHome\ehSched.exe
                    C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
                    C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                    C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
                    C:\Program Files\Microsoft LifeCam\MSCamSvc.exe
                    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    C:\WINDOWS\system32\nvsvc32.exe
                    C:\Apps\Softex\OmniPass\Omniserv.exe
                    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                    C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                    C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                    C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe
                    C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
                    C:\Apps\Softex\OmniPass\OPXPApp.exe
                    C:\WINDOWS\Explorer.EXE
                    C:\WINDOWS\ehome\ehtray.exe
                    C:\WINDOWS\eHome\ehmsas.exe
                    C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                    C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
                    C:\WINDOWS\RTHDCPL.EXE
                    C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
                    C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                    C:\Apps\Softex\OmniPass\scureapp.exe
                    C:\apps\ABoard\ABoard.exe
                    C:\apps\ABoard\AOSD.exe
                    C:\WINDOWS\vVX3000.exe
                    C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
                    C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
                    C:\Program Files\Real\RealPlayer\RealPlay.exe
                    C:\WINDOWS\system32\wuauclt.exe
                    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                    C:\APPS\SMP\SmpSys.exe
                    C:\WINDOWS\system32\ctfmon.exe
                    C:\Program Files\MSN Messenger\MsnMsgr.Exe
                    C:\APPS\skype\phone\Skype.exe
                    C:\PROGRA~1\Wanadoo\EspaceWanadoo.exe
                    C:\PROGRA~1\Wanadoo\ComComp.exe
                    C:\PROGRA~1\Wanadoo\Toaster.exe
                    C:\PROGRA~1\Wanadoo\Inactivity.exe
                    C:\PROGRA~1\Wanadoo\PollingModule.exe
                    C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                    C:\PROGRA~1\Wanadoo\Watch.exe
                    C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
                    C:\Program Files\Internet Explorer\iexplore.exe
                    C:\WINDOWS\system32\svchost.exe
                    C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                    C:\Program Files\Symantec\LiveUpdate\AUpdate.exe
                    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                    C:\Program Files\HijackThis\HijackThis.exe
                    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                    C:\Program Files\Messenger\msmsgs.exe
                    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
                    C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe

                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = https://www.orange.fr/portail
                    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.orange.fr/portail
                    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
                    R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
                    O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                    O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Fichiers communs\Symantec Shared\AdBlocking\NISShExt.dll
                    O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
                    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
                    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
                    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
                    O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
                    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
                    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                    O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
                    O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
                    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
                    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                    O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
                    O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
                    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
                    O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe
                    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
                    O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
                    O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
                    O4 - HKLM\..\Run: [VX3000] C:\WINDOWS\vVX3000.exe
                    O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
                    O4 - HKLM\..\Run: [Omnipage] C:\Program Files\ScanSoft\OmniPageSE\opware32.exe
                    O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
                    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
                    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
                    O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
                    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
                    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
                    O4 - HKCU\..\Run: [Skype] "C:\APPS\skype\phone\Skype.exe" /nosplash /minimized
                    O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
                    O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
                    O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
                    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                    O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
                    O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
                    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
                    O9 - Extra button: Wanadoo - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                    O16 - DPF: {E862C832-3A5F-4CEB-BFAA-167B22010A71} (InfosFinder2.InfosFinder) - http://support.packardbell.com/files/activex/InfosFinder2.CAB
                    O17 - HKLM\System\CCS\Services\Tcpip\..\{8BBD2426-2F65-4F0C-8514-112DCB3709E3}: NameServer = 80.10.246.130 80.10.246.3
                    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
                    O20 - Winlogon Notify: OPXPGina - C:\Apps\Softex\OmniPass\opxpgina.dll
                    O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
                    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                    O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
                    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccProxy.exe
                    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                    O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
                    O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel(R) Quick Resume Technology\ELService.exe
                    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
                    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
                    O23 - Service: MpService - Canon Inc. - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
                    O23 - Service: Service Norton AntiVirus Auto-Protect (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
                    O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\Security Console\NSCSRVCE.EXE
                    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
                    O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe
                    O23 - Service: Planificateur LiveUpdate automatique - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                    O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
                    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SNDSrvc.exe
                    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\SPBBC\SPBBCSvc.exe
                    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Fichiers communs\Symantec Shared\CCPD-LC\symlcsvc.exe
                    O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe
                    O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
                    O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

                    je scan le fichier dllhost.exe de Windows\system32 et je te joins le rapport

                    A+
                    0
                  4. Rapport du scan de dllhost.exe

                    STATUS: FINISHEDComplete scanning result of "dllhost.exe", received in VirusTotal at 10.07.2006, 23:44:14 (CET).

                    Antivirus Version Update Result
                    AntiVir 7.2.0.25 10.06.2006 no virus found
                    Authentium 4.93.8 10.06.2006 no virus found
                    Avast 4.7.892.0 10.07.2006 no virus found
                    AVG 386 10.07.2006 no virus found
                    BitDefender 7.2 10.07.2006 no virus found
                    CAT-QuickHeal 8.00 10.07.2006 no virus found
                    ClamAV devel-20060426 10.07.2006 no virus found
                    DrWeb 4.33 10.07.2006 no virus found
                    eTrust-InoculateIT 23.73.16 10.07.2006 no virus found
                    eTrust-Vet 30.3.3118 10.06.2006 no virus found
                    Ewido 4.0 10.07.2006 no virus found
                    Fortinet 2.82.0.0 10.07.2006 no virus found
                    F-Prot 3.16f 10.06.2006 no virus found
                    F-Prot4 4.2.1.29 10.06.2006 no virus found
                    Ikarus 0.2.65.0 10.07.2006 no virus found
                    Kaspersky 4.0.2.24 10.07.2006 no virus found
                    McAfee 4868 10.06.2006 no virus found
                    Microsoft 1.1603 10.07.2006 no virus found
                    NOD32v2 1.1794 10.06.2006 no virus found
                    Norman 5.80.02 10.06.2006 no virus found
                    Panda 9.0.0.4 10.07.2006 no virus found
                    Sophos 4.10.0 10.05.2006 no virus found
                    TheHacker 6.0.1.093 10.06.2006 no virus found
                    UNA 1.83 10.06.2006 no virus found
                    VBA32 3.11.1 10.06.2006 no virus found
                    VirusBuster 4.3.7:9 10.07.2006 no virus found

                    Aditional Information
                    File size: 5120 bytes

                    Merci de la suite...

                    a demain
                    0
                  5. Contributeur
                    ok pour la suite on verra demain .

                    je coupe. ;-)

                    A+
                    0
                2. Contributeur
                  désolé je t'avais oublié ? .. ;-)

                  Télécharges smitfraudfix :

                  En image :
                  http://siri.urz.free.fr/Fix/SmitfraudFix.php

                  tu le décompresses tu doubles cliques sur smitfraudfix.cmd et tu choisi l option 1
                  cela vas générer un rapport.
                  Si tu vois des lignes avec PRESENT! Continue la manip qui suit.

                  Redémarres le PC en mode sans échec : tu tapotes sur la touche F8 de ton clavier (ou F5 ) et tu choisis le mode sans échec)

                  - Ouvre le dossier "SmitfraudFix" et double clic sur "Smitfraudfix.cmd", choisit l’option 2 et tu réponds oui à tout.

                  Copie/colle le rapport sur le forum stp.

                  a+
                  0
                  1. Pas de probleme, Seb, tu n'as certainement pas que mon probleme à resoudre !!!!

                    voila le rapport de Smitfraudfix apres toutes les manips demandées.

                    ( je demarre maintenant sur https://www.msn.com/fr-fr )

                    SmitFraudFix v2.106

                    Rapport fait à 17:00:18,60, 09/10/2006
                    Executé à partir de D:\Documents and Settings\Riclev\Mes documents\Utilitaires\Smitfraudfix\SmitfraudFix\SmitfraudFix
                    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                    Fix executé en mode sans echec

                    »»»»»»»»»»»»»»»»»»»»»»»» Avant SmitFraudFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                    GenericRenosFix by S!Ri

                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                    »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                    Nettoyage terminé.

                    »»»»»»»»»»»»»»»»»»»»»»»» Après SmitFraudFix
                    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                    SrchSTS.exe by S!Ri
                    Search SharedTaskScheduler's .dll

                    »»»»»»»»»»»»»»»»»»»»»»»» Fin

                    A+
                    0
                    1. Contributeur
                      C'est sur que je n'ai pas que toi ... ;-)

                      Pour vérifier, scanne ton PC avec cet antivirus en ligne (sous IE et accepte l’activX) :
                      http://www.bitdefender.fr/bd/site/search.php#
                      Clique sur « scan on line » suis les instructions.
                      Et colle le rapport

                      a+
                      0
                      1. Désolé Seb, mais que veux tu dire par "sous IE" ?
                        si je me connecte au dite à partir de ma page d'acceuil de wanadoo, je n'ai pas le choix "scan on line" dont tu parle...
                        que dois je faire ?
                        0
                        1. Contributeur
                          ouvre une page IE (internet explorer) et copie/colle le lien du scan en ligne et suis la manip.

                          http://www.bitdefender.fr/bd/site/search.php#

                          a+
                          0
                          1. je veux bien mais comment j'ouvre une page IE ? je ne te suis pas ( excuses moi mais mes competences sont parfois limitées ...)
                            ma connexion internet se fait par l'intermediaire du kit wanadoo !
                            0
                            1. Contributeur
                              Tu dois avoir cet icone Internet explorer img.clubic.com/photo/0096000000138665.jpg sur ton bureau donc double clci dessus copie/colle ce lien :www.bitdefender.fr/bd/site/search.php# dans la barre d'adresse de Internet explorer ensuite suis la manip du <23>
                              une fois le scann Bitdefender fini copie/colle le rapport.

                              A+
                              0
                              1. J'ai reussi...
                                une erreur m'empeche de copier le rapport
                                neanmoins, j'ai pu le lire et je te le transmet :

                                Scanned files 547692
                                Infected files 0

                                No virus found

                                A+
                                0
                                1. Contributeur
                                  Ou en sont tes probs ?

                                  A+
                                  0
                                  1. Bonjour Seb,
                                    Comme precisé dans ma reponse No 20 , j'ai été absent durant 3 jours...
                                    Je viens de rentrer, 1200 bornes en 3 jours, je suis HS ce soir, je te repond demain
                                    Merci encore
                                    à demain
                                    0
                                    • 1
                                    • 2