[Page de démarrage] La modifier

pepo -  
 domino -
salut a tous, je suis sous xp et chaque fois que je me connect sur le web je tombe sur la page "idsearch.com" alors que j'ai configurer pour yahoo.
meme en reconfigurant je retombe sur cette page.
merci de me donner une solution pour virer definitivement cette page. ciao

22 réponses

  • 1
  • 2
  1. jc49 Messages postés 195 Date d'inscription   Statut Membre 35
     
    Salut!
    Va dans démarrer/exécuter tape msconfig
    dans l'onglet démarrage tu décoche tout sauf ce qui concerne ton antivirus et ton firewall
    tu redémarre le pc, dans la fenetre qui apparaitera tu coche la case blance et tu clic su ok
    Autrement télécharge le logiciel suivant:
    http://www.clubic.com/t/fiche2660.html
    voila!
    0
  2. kalamit
     
    Salut,
    Tu utilises IE ?
    Si oui, ouvre regedit et modifie directement cette clé par l'adresse de ton choix: HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page\

    Kalamit,
    Parle à ma culasse, mon carter est malade. :)
    0
  3. pepo
     
    merci a vous, j'essaye ca et je vous imforme du resultat. ciao
    0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. pepo
     
    je viens de passer par regedit et j'ai remplace 'idsearch" par "yahoo.fr" ca semble fonctionner tres bien.
    merci de votre aide car ca me faisaist vraiment ch.. cette page de m.....
    cia a tous.
    0
  6. pepo
     
    FAUSSE JOIE!! elle revient de nouveaux. si quelaqu'un a une solution pour savoir d'ou elle vient et comment l'heradiquer totalement ce serait vraiment tres cool. ciao a tous
    0
  7. jc49 Messages postés 195 Date d'inscription   Statut Membre 35
     
    regarde ce que j'ai écrait plus haut
    0
  8. kelen
     
    salut
    moi j'ai eu le même problème la semaine dernière et j'ai du formater...
    ni les changements dans la base de registre, ni l'utilisation de ad-aware ou spy-bot n'ont été statisfaisant !!!
    je ne sais pas ce que c'est que cette merde mais je m'en serais bien passé !!
    peut-être que quelqu'un te proposera une solution plus élégante mais la bonne vieille version bourrin a résolu mon problème...
    0
  9. pepo
     
    jc j'ai esaye spybot mais il n'a rien resolut.
    pour le reste ca me gene de tt demarer manuelement. je vais eesayer tt de meme.
    kelen je vais essaye d'etre plus soft au moins pour l'instant IoI
    si qq un a une autre solution je suis preneur
    0
  10. jc49 Messages postés 195 Date d'inscription   Statut Membre 35
     
    tu peux aussi tenter une restauration systeme
    démarrer/programme/accessoire/outils systeme
    0
  11. pepo
     
    jc je peux essayer mais ca fait un bye que j'ai pas sauvegarder ma config. qu'est ce que je risque de perdre ? mes nouveaux prog ?
    0
  12. jc49 Messages postés 195 Date d'inscription   Statut Membre 35
     
    C'est ca tes nouveaux prog au pire
    de toute facon windows fait des sauvegarde tout seul (normalement)
    0
  13. zagor5 Messages postés 187 Statut Membre 32
     
    J'ai déjà eut un problème dans le genre, il y a sûrement un programme qui se lance au démarrage et qui change la page d'IE. Essai de lancer le programme "spybot search and destroy" pour voir s'il n'y a pas un programme suspect sur ta machine.

    Sinon tu peux toujours aller voir dans la base de registre sous HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run et HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
    s'il n'y a pas un programme suspect qui s'execute au lancement de Windows.

    Après il ne reste plus qu'à mettre la page que tu veux pour IE.
    0
  14. jc49 Messages postés 195 Date d'inscription   Statut Membre 35
     
    au lieu de faire la manip dans la base de registre va dans msconfig comme je l'ai expliqué avant c'est plus sur
    autrement spybot a déja été utilisé (le lien vers clubic)
    0
  15. pgriffet Messages postés 376 Statut Membre 192
     
    J'ai donné un lien plus haut pour débloquer la page d'accueil.
    Spybot devrait virer tout ce qui gêne également

    Si tu ne t'en sors pas, tu peux lire mon sujet :

    http://forum.pcastuces.com/sujet.asp?SUJET_ID=8269

    copier le contenu du Bloc-notes et coller ici le résultat de l'analyse de HijackThis.

    Pierre.
    Mes sujets : http://niklish.free.fr/dossierspratiques.htm
    0
    1. pepo
       
      PGRIFFET je suis alle sur ton lien (tres bien explique) j'ai suivit tes conseil et je te fais parvenir le rapport de hijack this.
      peux tu jeter un oeil dessus et me dire ce qui te semble louche.
      j'ai peut etre mis trop de "yahoo" mervi d'avance;
      si qq un d'autre a 2 min a perdre IoI tu peux aussi jeter un coup d'oeil et me donner ton avis.
      Logfile of HijackThis v1.97.7
      Scan saved at 00:59:05, on 21/11/2003
      Platform: Windows XP SP1 (WinNT 5.01.2600)
      MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\LEXBCES.EXE
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\system32\LEXPPS.EXE
      C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
      C:\WINDOWS\System32\CTSVCCDA.EXE
      C:\WINDOWS\System32\svchost.exe
      C:\Program Files\TOSHIBA\EMT3\Tmesbs32.exe
      C:\Program Files\TOSHIBA\EMT3\Tmesrv31.exe
      C:\WINDOWS\wanmpsvc.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\Creative\ShareDLL\CtNotify.exe
      C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe
      C:\PROGRA~1\WANADOO\TaskbarIcon.exe
      C:\PROGRA~1\WANADOO\CnxMon.exe
      C:\WINDOWS\System32\TPWRTRAY.EXE
      C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
      C:\Program Files\TOSHIBA\EMT3\TMESBS32.EXE
      C:\Program Files\TOSHIBA\EMT3\TMERzCtl.EXE
      C:\WINDOWS\System32\TFNF5.exe
      C:\Program Files\Real\RealPlayer\RealPlay.exe
      C:\Program Files\Creative\ShareDLL\MediaDet.exe
      C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
      C:\PROGRA~1\MESSAG~1\Demon.exe
      C:\WINDOWS\System32\00THotkey.exe
      C:\Program Files\MSN Messenger\MsnMsgr.Exe
      C:\WINDOWS\System32\ctfmon.exe
      C:\Program Files\TOSHIBA\NetDevSw\NetDevSW.exe
      C:\Documents and Settings\proffessionnel\Local Settings\Temp\Répertoire temporaire 1 pour hijackthis.zip\HijackThis.exe
      C:\Program Files\Internet Explorer\iexplore.exe

      R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.yahoo.fr
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.yahoo.fr/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.fr/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.fr/
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.yahoo.fr/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.yahoo.fr/
      R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.yahoo.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = http://www.yahoo.fr
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.yahoo.fr
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.yahoo.fr
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.yahoo.fr
      R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.yahoo.fr
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Wanadoo
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.yahoo.fr/
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = http://www.yahoo.fr
      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.fr/
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.yahoo.fr
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,Shellnext = http://www.toshiba-europe.com/computer/magniasg20_promo/fr/index.htm
      R1 - HKCU\Software\Microsoft\Internet Explorer,SearchAssistant = http://www.yahoo.fr/
      R1 - HKCU\Software\Microsoft\Internet Explorer,CustomizeSearch = http://www.yahoo.fr/
      O1 - Hosts file is located at: C:\WINDOWS\System32\drivers\etc\hosts
      O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
      O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
      O2 - BHO: Microsoft SearchWord - {79369D5C-2903-4b7a-ADE2-D5E0DEE14D24} - C:\DOCUME~1\PROFFE~1\APPLIC~1\MICROS~1\Office\Word10.dll
      O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
      O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
      O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\WANADOO\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\WANADOO\TaskbarIcon.exe
      O4 - HKLM\..\Run: [WooCnxMon] C:\PROGRA~1\WANADOO\CnxMon.exe
      O4 - HKLM\..\Run: [Tpwrtray] TPWRTRAY.EXE
      O4 - HKLM\..\Run: [TosHKCW.exe] C:\Program Files\TOSHIBA\Wireless Hotkey\TosHKCW.exe
      O4 - HKLM\..\Run: [TMESRV.EXE] C:\Program Files\TOSHIBA\EMT3\TMESRV31.EXE /Logon
      O4 - HKLM\..\Run: [TMESBS.EXE] C:\Program Files\TOSHIBA\EMT3\TMESBS32.EXE /Client
      O4 - HKLM\..\Run: [TMERzCtl.EXE] C:\Program Files\TOSHIBA\EMT3\TMERzCtl.EXE /Service
      O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
      O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
      O4 - HKLM\..\Run: [NsUpdate] C:\WINDOWS\NsUpdate.exe UPDATE
      O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
      O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\MOUSEW~1\SYSTEM\EM_EXEC.EXE
      O4 - HKLM\..\Run: [Demon] C:\PROGRA~1\MESSAG~1\Demon.exe
      O4 - HKLM\..\Run: [CTRegRun] C:\WINDOWS\CTRegRun.EXE
      O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
      O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
      O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
      O4 - Global Startup: Network Device Switch.lnk = ?
      O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
      O4 - Global Startup: Icône AOL.lnk = C:\Program Files\AOL 7.0\aoltray.exe
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
      O9 - Extra button: Related (HKLM)
      O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
      O9 - Extra button: Real.com (HKLM)
      O9 - Extra button: Messenger (HKLM)
      O9 - Extra 'Tools' menuitem: Messenger (HKLM)
      O9 - Extra button: Wanadoo (HKCU)
      O15 - Trusted Zone: *.xxxtoolbar.com
      O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/76808a0e7ae82f/housecall.antivirus.com/housecall/xscan53.cab
      O16 - DPF: {AEFD32B6-4815-11D2-98E4-00C04FCEFE77} (SnCAX Class) - http://www.pilmo.com/clients/dialer.cab
      0
  16. PEPO
     
    dsl pour la repetition, erreur de manip!!!!!
    0
  17. pepo
     
    E RE elle est encore revenue!!!!!
    ds mon scan sur l'antivirus il a detecter et corriger un "cheval de troie" pour page d'accuel. y a surement un lien?
    de plus j'ai poser une question sur un probleme d'ouverture de session est ce que c'est lie? ajoute le 19 11 (je ne sais pas donner le lien. si qq a une solution je serais vraiment soulage. merci
    0
  18. achraf
     
    tout simplement tu supprime les cookies et le s fichier temp sur ton hdd
    0
  19. pepo
     
    Pierre j'ai essaye ca je te tiens au courrant.
    achraf c'est la premiere chose que j'ai fait mais ca a pas suffit !
    0
  • 1
  • 2