Ouverture pages indésirables sous internet ex

Bonsoir, je suis nouveau sur le forum et comme beaucoup d'autres aevc un pb à vous soumettre.
Depuis quelques temps, lorsque je surfe avec internet explorer, oure des pages insdésirables et me propose l'installation de programmes. J'ai essayé adware, spybot et CCcleaner mais rien. Mon anti virus et pare feu est Kepersky.
Voici le listing donner par hijackthis
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\mwsrvacc.exe
C:\WINDOWS\system32\ntvdm.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
C:\OPLIMIT\ocrawr32.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\eMule\emule.exe
C:\Program Files\Wanadoo\EspaceWanadoo.exe
C:\Program Files\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\Program Files\Wanadoo\Watch.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\DOCUME~1\DBORAH~1\LOCALS~1\Temp\Rar$EX22.875\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CnxDslTaskBar] "C:\Program Files\ZTE Corporation\ZXDSL852\CnxDslTb.exe" "ZTE Corporation\ZXDSL852"
O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
O4 - HKLM\..\Run: [ctfmon] C:\WINDOWS\system32\dlg\ctfmon.exe
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\GestMaj.exe EspaceWanadoo.exe
O4 - HKCU\..\Run: [Instant Access] C:\WINDOWS\system32\mwsrvacc.exe /run
O4 - Startup: OCRAWARE.lnk = C:\OPLIMIT\OCRAWARE.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
O16 - DPF: {5F4D3335-3194-4167-85AE-E7325F2695EF} - http://scripts.dlv4.com/binaries/egaccess4/egaccess4_1068_em_XP.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1107646764578
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - https://www.trendmicro.com/en_us/forHome/products/housecall.html
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{67A3886D-77A6-42D2-901D-BA6A244EA984}: NameServer = 80.10.246.1 80.10.246.132
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
O23 - Service: Kaspersky Anti-Virus Service (kavsvc) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: MpService - Canon Inc. - C:\Program Files\Canon\MultiPASS4\MPSERVIC.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Je ne sais trop quelles lignes fixer.

7 réponses

  1. Salut,

    Télécharge SmitfraudFix (enregistre le sur le "bureau")
    http://siri.urz.free.fr/Fix/SmitfraudFix.zip

    décompresse SmitfraudFix
    Lance le fichier SmitfraudFix ou SmitfraudFix.cmd et choisis l option 1 copie le rapport ici stp

    et

    Telecharge, installe puis mets à jour ce logiciel(Ewido), une fois que c'est fait, fais un scan complet de ton système, supprime (delete) tout ce qu'il te trouve puis colle le rapport ici reste gratuit après la période d'essai)
    Ewido
    Si tu as besoin d'aide avec Ewido(devenu AVG-antispyware) regarde ce tutoriel:
    http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html
    0
    1. bonsoir telecharge et execute :

      AVG anti spyware
      https://www.01net.com/telecharger/

      Copier/coller le rapport entier sur le forum. (n'oublie pas de le mettre a jour avant de lancer le scan)
      NB suis les instruction du tutoriel
      http://www.malekal.com/tutorial_AVG_AntiSpyware.html
      http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

      SmitfraudFix

      http://siri.urz.free.fr/Fix/SmitfraudFix.zip
      Exécute le, Double click sur Smitfraudfix.cmd choisit l’option 1, il va générer un rapport

      Clik send et colle le rapport stp Copie/colle le sur le poste stp suivi d'un log hijack

      Télécharge Blacklight (de F-Secure) a l’une des 2 adresses :
      https://www.f-secure.com/en
      https://www.f-secure.com/en

      et sauvegarde le sur ton Bureau.

      Double-clique blbeta.exe et accepte la licence ; laisse [X]scan through Windows Explorer activé ; clique Scan puis Next

      Tu verras une liste de fichiers détectés apparaître. Tu verras également un rapport, sur ton Bureau, nommé fsbl.xxxxxxx.log (les xxxxxxx sont des chiffres).

      Copie et colle le contenu de ce rapport dans ta prochaine réponse

      pour resumer dans ta prochaine reponse tu met le rapport d'avg antispyware +le rapport smitfraud+ le rapport blacklight + log hijack

      @++++
      @++
      0
      1. desolé quand j'ai commencé a redigé y'avais aucune reponse :/

        a+++
        0
        1. Voici le listing de smitfraudfix:
          SmitFraudFix v2.125

          Rapport fait à 21:51:18,54, 29/11/2006
          Executé à partir de C:\Documents and Settings\D‚borah\Bureau\SmitfraudFix
          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
          Fix executé en mode normal

          »»»»»»»»»»»»»»»»»»»»»»»» C:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\D‚borah

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\D‚borah\Application Data

          »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\DBORAH~1\Favoris

          »»»»»»»»»»»»»»»»»»»»»»»» Bureau

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

          »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
          "Source"="About:Home"
          "SubscribedURL"="About:Home"
          "FriendlyName"="Ma page d'accueil"

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"=""

          »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

          »»»»»»»»»»»»»»»»»»»»»»»» Fin
          0
          1. Voici le rapport d'Ewido :
            ---------------------------------------------------------
            ewido anti-spyware - Scan Report
            ---------------------------------------------------------

            + Created at: 22:38:58 29/11/2006

            + Scan result:

            :mozilla.12:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
            :mozilla.9:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
            C:\Documents and Settings\Déborah\Cookies\déborah@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
            :mozilla.26:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
            C:\Documents and Settings\Déborah\Cookies\déborah@bluestreak[2].txt -> TrackingCookie.Bluestreak : No action taken.
            :mozilla.8:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
            C:\Documents and Settings\Déborah\Cookies\déborah@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
            :mozilla.29:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Estat : No action taken.
            :mozilla.40:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
            :mozilla.41:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
            :mozilla.42:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
            :mozilla.43:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
            :mozilla.44:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
            C:\Documents and Settings\Déborah\Cookies\déborah@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
            C:\Documents and Settings\Déborah\Cookies\déborah@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : No action taken.
            :mozilla.33:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
            :mozilla.34:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
            :mozilla.35:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
            :mozilla.36:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
            :mozilla.37:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
            :mozilla.13:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
            :mozilla.14:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
            :mozilla.15:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
            C:\Documents and Settings\Déborah\Cookies\déborah@www.smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken.
            :mozilla.11:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
            :mozilla.6:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
            :mozilla.39:C:\Documents and Settings\Déborah\Application Data\Mozilla\Firefox\Profiles\ihgj9mly.default\cookies.txt -> TrackingCookie.Weborama : No action taken.
            C:\Documents and Settings\Déborah\Cookies\déborah@weborama[2].txt -> TrackingCookie.Weborama : No action taken.

            ::Report end
            0
            1. ok, merci (pas grvae pour le double ;-) )

              Fait ce nettoyage: (à faire réguliérement)

              ¤Telecharges et installes ceci: (n'installe pas la barre d'outil Yahoo)
              CCleaner:
              Ccleaner

              dans la colonne de gauche clic sur "erreurs" coches toutes les cases, puis cliques en bas sur "chercher des erreurs" une fois finit, cliques sur "reparer les erreurs" et tu aura un message pour sauvegarder ta base de registre tu dis "oui" puis tu recommences jusqu'a ce qu'il te trouve plus d'erreurs.
              Les sauvegardes que tu aura faites tu pourra les supprimer si ton ordinateur n'a plus de problémes

              ¤Relance Ccleaner, vas dans l'onglet "nettoyeur" present sur la gauche, decoches la derniere case (Avancé si elle est cochée) puis clic sur "lancer le nettoyage"

              Si tu as besoin d'aide pour Ccleaner, regarde ce tutoriel:
              http://www.tutopat.com/viewtopic.php?t=305

              Puis envoit le rapport que t'a conseillé Salwa
              0