Probleme fenetre de pub

Résolu
tmax83 -  
ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   -
Bonjour,
j ai un probleme avec lé pub intenpestive (cid)!! elle arrive pa en grand nombre mais c pa agreable !!! j ai essayé bocoup de chose j ai nettoyé avec avg ccleaner ...j ai essayé otre chose en m aidant de site en demarant en mode sans echec etc...!!! ca revien toujours!!! svp aidez moa!! si il fo je fai une analise avec le hijachthis!! merci
Configuration: Windows XP
Internet Explorer 7.0

16 réponses

Résumé de la discussion

Le problème décrit concerne une pub intempestive apparaissant même après plusieurs nettoyages, des démarrages en mode sans échec et l'utilisation d'outils antivirus sur Windows XP avec Internet Explorer 7. Plusieurs éléments de réponse décrivent l'emploi d'outils comme AVG Anti-Spyware et CCleaner, l'analyse de rapports type Lopxp, et la vérification des démarrages et des caches pour repérer les composants publicitaires indésirables. Des éléments repérés dans les rapports évoquent RealPlayer, Windows Live Toolbar et Wanadoo, suggérant une injection via des barres d'outils ou modules publicitaires; une désinfection complète et une révision des tâches planifiées pourraient être nécessaires.

Bobot (l'IA à votre service)
  1. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonjour

    Télécharge ceci: (by Moe) :
    http://sosvirus.changelog.fr/Green_day/Lopxpsetup.exe

    Double clic sur Lopxpsetup.exe pour lancer l'installation
    Au menu, choisir l'option 1
    Patienter jusqu'à que l'on demande d'appuyer sur une touche, appuyer !
    Une rapport sera alors crée, à copie/colle en entier sur le forum.
    @+
    0
  2. dou-l Messages postés 2871 Statut Membre 61
     
    salut,

    fait un rapport hijackthis:

    ftp://ftp.commentcamarche.com/download/HJTInstall.exe

    Fait un clic droit sur l'icone hijackthis.

    /!\Renome hijackthis en skim.exe ( a le place de hijacktihs.exe) c'est important.

    Après avoir fais ca double-clic dessus.

    Clic sur Do a system scan and save the log

    A la fin de l'analyse un rapport va etre générer colle le ici.

    Une démo d'hijackthis :
    http://perso.orange.fr/rginformatique/section%20virus/demohijack.htm

    Tient moi au courant @ +.
    0
    1. tmax83
       
      merci!! voila mon hijackthis:


      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 12:53, on 2008-03-22
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\lclock.exe
      C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
      C:\Program Files\Winsos\WINSOS.EXE
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Internet Explorer\IEXPLORE.EXE
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.fr/?gws_rd=ssl
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [TICK INSIDE TIME WAY] C:\Documents and Settings\All Users\Application Data\2 tray tick inside\Knob Math.exe
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [LClock] lclock.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\Winsos\WINSOS.EXE" MINI
      O4 - HKCU\..\Run: [ForkCorn] C:\DOCUME~1\PROPRI~1\APPLIC~1\32Show\soft up.exe
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-20\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\S-1-5-18\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - HKUS\.DEFAULT\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'Default user')
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
      O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f012.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      0
  3. zyva Messages postés 581 Statut Membre 152
     
    Voila comment faire sur le site : http://www.commentcamarche.net/faq/sujet 5996 comment bloquer les fenetres cid
    0
  4. Vous n’avez pas trouvé la réponse que vous recherchez ?

    Posez votre question
  5. dou-l Messages postés 2871 Statut Membre 61
     
    jte laisse faire
    0
    1. tmax83
       
      ok j v essayé tout j espere ke ca marchera merci a tous!!!
      0
    2. tmax83
       
      j ai telecharger lopxp set up il ve pa s ouvrir???!!!!
      0
  6. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    tu doit avoir un dossier avec roue crantée qui c'est créer
    tu l'ouvre et tu choisis l'option 1
    0
    1. tmax83
       
      dsl mais impossible d ouvrir !!!windows a une erreur!!! avg me di pas possible!!! j vai reesayé mais bon!!! j croi pa ke ca va marché...
      0
  7. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    as tu ce dossier avec la roue crantée ?
    0
    1. tmax83
       
      c a y est dsl mai j ai mi du ternp j ai du partir voila mon cid texte!!! qui peut m aider svp???


      # Rapport Lopxp fait le 2008-03-22 à 18:32:43
      # Exécuté dans : C:\Program Files\Lopxp
      # Version 3.09 - Maj du 28/02/2008

      Killing 'iexplore.exe'
      "C:\Program Files\Internet Explorer\IEXPLORE.EXE" (256)
      "C:\Program Files\Internet Explorer\IEXPLORE.EXE" (684)

      ========== Listing des dossiers Application Data

      +- C:\Documents and Settings\All Users\Application Data

      2008-03-06 à 23:04:17 - 2 tray tick inside
      2007-11-08 à 10:09:45 - Adobe
      2008-02-12 à 19:11:31 - AntiVir PersonalEdition Classic
      2008-02-04 à 17:46:05 - Apple
      2008-02-04 à 17:52:29 - Apple Computer
      2008-01-16 à 02:20:37 - Google
      2008-03-18 à 18:43:31 - Grisoft
      2008-03-06 à 23:06:50 - Messenger Plus!
      2007-12-29 à 16:30:19 - Microsoft
      2008-02-22 à 00:17:22 - PACE Anti-Piracy
      2008-03-03 à 00:22:53 - Spybot - Search & Destroy
      2008-03-16 à 23:58:33 - TEMP
      2007-10-25 à 17:11:28 - Windows Genuine Advantage
      2008-03-16 à 23:43:35 - WLInstaller

      +- C:\Documents and Settings\Propriétaire\Application Data

      2008-03-06 à 23:04:33 - 32Show
      2007-12-24 à 21:21:10 - Adobe
      2008-02-04 à 17:52:49 - Apple Computer
      2008-03-14 à 00:13:08 - BitTorrent
      2008-03-21 à 21:45:27 - Classes de site
      2008-01-08 à 13:17:33 - Dynamique
      2008-03-18 à 18:43:42 - Grisoft
      2007-12-29 à 13:12:04 - Help
      2007-10-25 à 17:28:27 - Identities
      2008-02-22 à 08:40:38 - InstallShield
      2007-11-08 à 10:07:33 - Lavasoft
      2008-03-08 à 17:30:33 - LimeWire
      2007-11-08 à 10:02:59 - Macromedia
      2008-03-02 à 01:33:00 - Microgaming
      2008-02-19 à 11:43:06 - Microsoft
      2007-12-24 à 21:57:08 - Mozilla
      2008-03-12 à 14:56:10 - NetMedia Providers
      2008-02-22 à 00:17:22 - PACE Anti-Piracy
      2008-03-12 à 14:56:09 - Publish Providers
      2007-12-25 à 01:40:13 - Real
      2008-01-08 à 13:18:40 - Sites
      2008-03-12 à 14:56:02 - Sony
      2008-02-11 à 16:59:22 - Steinberg
      2008-01-17 à 00:11:47 - Sun
      2008-03-04 à 10:44:00 - TuneUp Software
      2008-01-16 à 02:34:12 - vlc

      +- C:\Documents and Settings\Propriétaire\Local Settings\Application Data

      2007-12-24 à 21:21:16 - Adobe
      2007-12-18 à 00:42:28 - Ahead
      2008-02-04 à 17:46:08 - Apple
      2008-02-04 à 17:52:49 - Apple Computer
      2008-01-16 à 02:20:37 - Google
      2007-12-29 à 13:12:04 - Help
      2007-12-29 à 00:36:36 - Identities
      2008-03-12 à 14:50:58 - Microsoft
      2007-12-24 à 21:57:08 - Mozilla
      2008-02-22 à 00:17:22 - PACE Anti-Piracy

      ========== Listing du dossier Program Files

      +- C:\Program Files

      2008-03-06 à 23:04:01 - 32Show
      2007-11-08 à 10:07:44 - Adobe
      2007-11-08 à 10:11:58 - Ahead
      2008-03-01 à 18:14:07 - aMSN
      2008-03-21 à 18:46:40 - AntiVir PersonalEdition Classic
      2008-02-04 à 17:46:06 - Apple Software Update
      2008-02-11 à 23:06:25 - BitTorrent
      2007-11-08 à 10:06:38 - CCleaner
      2008-03-06 à 23:03:48 - Circle Developement
      2007-10-25 à 17:07:51 - ComPlus Applications
      2008-02-12 à 15:10:52 - Cubase 5.0
      2008-01-11 à 18:56:39 - Dcads Games Collection
      2008-03-05 à 11:10:15 - EcoKenoSha
      2008-03-19 à 20:14:42 - eMule
      2008-02-05 à 20:08:45 - FBrowserAdvisor
      2008-02-29 à 20:03:17 - FBrowsingAdvisor
      2008-02-22 à 14:01:49 - Fichiers communs
      2007-12-24 à 22:05:14 - Filzip
      2008-03-19 à 23:55:51 - Flyos
      2007-12-24 à 21:56:58 - Google
      2008-03-18 à 18:43:28 - Grisoft
      2008-02-22 à 17:45:18 - iLok
      2008-02-22 à 14:01:14 - InstallShield Installation Information
      2008-02-21 à 23:18:52 - InterLok
      2008-03-04 à 09:19:05 - Internet Explorer
      2008-02-04 à 17:52:34 - iPod
      2008-02-04 à 17:52:44 - iTunes
      2008-01-17 à 00:11:35 - Java
      2007-11-08 à 10:07:25 - Lavasoft
      2008-03-13 à 22:58:03 - LimeWire
      2008-03-16 à 23:48:33 - LitexMedia
      2008-03-22 à 17:35:43 - Lopxp
      2008-03-21 à 14:49:51 - Messenger Plus! Live
      2007-10-29 à 16:24:06 - Microsoft Office
      2008-03-16 à 23:50:15 - Microsoft SQL Server Compact Edition
      2008-02-29 à 20:10:37 - Mozilla Firefox
      2007-10-25 à 17:19:09 - MSXML 4.0
      2007-10-25 à 17:19:18 - MSXML 6.0
      2007-10-25 à 17:09:10 - NetMeeting
      2007-10-25 à 17:09:04 - Outlook Express
      2008-02-04 à 17:46:51 - QuickTime
      2008-03-21 à 16:02:43 - RAR Password Cracker
      2007-12-24 à 21:56:31 - Real
      2007-11-08 à 10:16:06 - S3Inc
      2007-12-24 à 20:37:28 - SAGEM
      2008-01-16 à 22:27:44 - Samsung
      2007-12-24 à 20:24:24 - Securitoo
      2007-10-25 à 17:09:36 - Services en ligne
      2008-03-12 à 08:55:05 - set up
      2008-03-12 à 14:51:01 - Sony
      2008-03-12 à 14:49:47 - Sony Setup
      2007-11-08 à 10:09:51 - Spybot - Search & Destroy
      2008-03-18 à 23:44:47 - Sunbelt Software
      2008-03-18 à 18:19:10 - Trend Micro
      2007-10-25 à 17:28:16 - Uninstall Information
      2008-01-16 à 02:26:24 - VideoLAN
      2008-01-08 à 13:17:16 - Visicom Media
      2008-01-23 à 01:14:03 - VS Revo Group
      2008-02-12 à 14:47:25 - VST Plugins
      2008-03-22 à 17:33:28 - Wanadoo
      2008-03-18 à 02:02:27 - Windows Live
      2007-12-24 à 22:22:25 - Windows Live Favorites
      2008-03-21 à 23:21:27 - Windows Live Safety Center
      2007-12-24 à 22:22:36 - Windows Live Toolbar
      2008-03-12 à 14:50:55 - Windows Media Player
      2007-10-25 à 17:07:19 - Windows NT
      2007-10-25 à 17:09:40 - WindowsUpdate
      2007-11-08 à 10:06:24 - WinRAR
      2008-03-04 à 19:11:27 - Winsos
      2008-01-30 à 00:08:51 - YesMessenger

      ========== Tâches planifiées

      AppleSoftwareUpdate.job: C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task
      Vérifier les mises à jour de Windows Live Toolbar.job: C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE

      ========== Clés registre

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "TICK INSIDE TIME WAY"="C:\Documents and Settings\All Users\Application Data\2 tray tick inside\Knob Math.exe"

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ForkCorn"="C:\DOCUME~1\PROPRI~1\APPLIC~1\32Show\soft up.exe"


      ========== Bloqueur popups Internet Explorer

      host-domain-lookup.com
      www.host-domain-lookup.com
      mysearchnow.com
      www.mysearchnow.com

      ========== Suggestion ( /!\ Nécessite une interprétation.) ==========

      C:\Documents and Settings\PropriÚtaire\Application Data\32Show
      C:\Program Files\Circle Developement
      C:\Program Files\32Show

      +- Registre:

      REGEDIT4

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "TICK INSIDE TIME WAY"=-

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
      "ForkCorn"=-

      [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\New Windows\Allow]
      "host-domain-lookup.com"=-
      "www.host-domain-lookup.com"=-
      "mysearchnow.com"=-
      "www.mysearchnow.com"=-



      - Fin du rapport -
      0
  8. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    va dans : Démarrer > Exécuter puis copie/colle la ligne suivante en gras :
    "%programfiles%\Lopxp\Lopxp.bat" /Fixme
    puis valide, accepte toutes les demandes de suppression et poste le rapport stp

    ensuite refais un hijack stp
    @+
    0
    1. tmax83
       
      ok a toute merci
      0
    2. tmax83
       
      voila ke hijack

      Logfile of Trend Micro HijackThis v2.0.2
      Scan saved at 20:00, on 2008-03-22
      Platform: Windows XP SP2 (WinNT 5.01.2600)
      MSIE: Internet Explorer v7.00 (7.00.6000.16608)
      Boot mode: Normal

      Running processes:
      C:\WINDOWS\System32\smss.exe
      C:\WINDOWS\system32\winlogon.exe
      C:\WINDOWS\system32\services.exe
      C:\WINDOWS\system32\lsass.exe
      C:\WINDOWS\system32\svchost.exe
      C:\WINDOWS\System32\svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      C:\WINDOWS\Explorer.EXE
      C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
      C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
      C:\WINDOWS\SOUNDMAN.EXE
      C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
      C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
      C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
      C:\Program Files\iTunes\iTunesHelper.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\WINDOWS\lclock.exe
      C:\Program Files\Winsos\WINSOS.EXE
      C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
      C:\PROGRA~1\Wanadoo\ComComp.exe
      C:\PROGRA~1\Wanadoo\Toaster.exe
      C:\PROGRA~1\Wanadoo\Inactivity.exe
      C:\PROGRA~1\Wanadoo\PollingModule.exe
      C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
      C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
      C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      C:\WINDOWS\System32\FTRTSVC.exe
      C:\Program Files\iPod\bin\iPodService.exe
      C:\PROGRA~1\Wanadoo\Watch.exe
      C:\WINDOWS\system32\wuauclt.exe
      C:\Program Files\Windows Live\Messenger\usnsvc.exe
      C:\PROGRA~1\Wanadoo\WOOBRO~1\DownloadManager.exe
      C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
      C:\PROGRA~1\Wanadoo\WOOBrowser\WOOBrowser.exe
      C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

      R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.orange.fr/portail
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
      R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
      R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = https://www.google.fr/?gws_rd=ssl
      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - C:\PROGRA~1\Wanadoo\SEARCH~1.DLL
      O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
      O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
      O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
      O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
      O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
      O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
      O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
      O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
      O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
      O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe" -osboot
      O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
      O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
      O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
      O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
      O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
      O4 - HKCU\..\Run: [LClock] lclock.exe
      O4 - HKCU\..\Run: [WOOKIT] C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
      O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
      O4 - HKCU\..\Run: [WINSOS VERIFY] "C:\Program Files\Winsos\WINSOS.EXE" MINI
      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SERVICE LOCAL')
      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-20\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SERVICE RÉSEAU')
      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
      O4 - HKUS\S-1-5-18\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'SYSTEM')
      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
      O4 - HKUS\.DEFAULT\..\RunOnce: [LSD_III] %systemroot%\LSD\end.cmd (User 'Default user')
      O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
      O8 - Extra context menu item: Add to Windows &Live Favorites - https://onedrive.live.com/?id=favorites
      O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
      O9 - Extra button: Recherche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
      O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
      O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab
      O16 - DPF: {C36112BF-2FA3-4694-8603-3B510EA3B465} (Lycos File Upload Component) - http://f012.mail.caramail.lycos.fr/app/uploader/FileUploader.cab
      O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
      O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
      O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
      O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - C:\WINDOWS\System32\FTRTSVC.exe
      O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
      0
  9. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    il faut faire ce qui est marqué et dans l'ordre stp

    @+ ;-)
    0
    1. tmax83
       
      ca y est j ai supprimé avec ton lopxp!! puis j ai fai un hijack!!!
      0
  10. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    très bien mai je veux voir le rapport :-)
    0
    1. tmax83
       
      ben j lé mi o dessus le hijack!!
      0
  11. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    ok pour hijack mais il faut le rapport de Lopxp
    0
    1. tmax83
       
      ok voila

      Rapport Lopxp fait le 2008-03-22 à 23:32:14
      # Exécuté dans : C:\Program Files\Lopxp
      # Version 3.09 - Maj du 28/02/2008


      ========== Listing des dossiers Application Data

      +- C:\Documents and Settings\All Users\Application Data

      2008-03-06 à 23:04:17 - 2 tray tick inside
      2007-11-08 à 10:09:45 - Adobe
      2008-02-12 à 19:11:31 - AntiVir PersonalEdition Classic
      2008-02-04 à 17:46:05 - Apple
      2008-02-04 à 17:52:29 - Apple Computer
      2008-01-16 à 02:20:37 - Google
      2008-03-18 à 18:43:31 - Grisoft
      2008-03-06 à 23:06:50 - Messenger Plus!
      2007-12-29 à 16:30:19 - Microsoft
      2008-02-22 à 00:17:22 - PACE Anti-Piracy
      2008-03-03 à 00:22:53 - Spybot - Search & Destroy
      2008-03-16 à 23:58:33 - TEMP
      2007-10-25 à 17:11:28 - Windows Genuine Advantage
      2008-03-16 à 23:43:35 - WLInstaller

      +- C:\Documents and Settings\Propriétaire\Application Data

      2007-12-24 à 21:21:10 - Adobe
      2008-02-04 à 17:52:49 - Apple Computer
      2008-03-14 à 00:13:08 - BitTorrent
      2008-03-21 à 21:45:27 - Classes de site
      2008-01-08 à 13:17:33 - Dynamique
      2008-03-18 à 18:43:42 - Grisoft
      2007-12-29 à 13:12:04 - Help
      2007-10-25 à 17:28:27 - Identities
      2008-02-22 à 08:40:38 - InstallShield
      2007-11-08 à 10:07:33 - Lavasoft
      2008-03-08 à 17:30:33 - LimeWire
      2007-11-08 à 10:02:59 - Macromedia
      2008-03-02 à 01:33:00 - Microgaming
      2008-02-19 à 11:43:06 - Microsoft
      2007-12-24 à 21:57:08 - Mozilla
      2008-03-12 à 14:56:10 - NetMedia Providers
      2008-02-22 à 00:17:22 - PACE Anti-Piracy
      2008-03-12 à 14:56:09 - Publish Providers
      2007-12-25 à 01:40:13 - Real
      2008-01-08 à 13:18:40 - Sites
      2008-03-12 à 14:56:02 - Sony
      2008-02-11 à 16:59:22 - Steinberg
      2008-01-17 à 00:11:47 - Sun
      2008-03-04 à 10:44:00 - TuneUp Software
      2008-01-16 à 02:34:12 - vlc

      +- C:\Documents and Settings\Propriétaire\Local Settings\Application Data

      2007-12-24 à 21:21:16 - Adobe
      2007-12-18 à 00:42:28 - Ahead
      2008-02-04 à 17:46:08 - Apple
      2008-02-04 à 17:52:49 - Apple Computer
      2008-01-16 à 02:20:37 - Google
      2007-12-29 à 13:12:04 - Help
      2007-12-29 à 00:36:36 - Identities
      2008-03-12 à 14:50:58 - Microsoft
      2007-12-24 à 21:57:08 - Mozilla
      2008-02-22 à 00:17:22 - PACE Anti-Piracy

      ========== Listing du dossier Program Files

      +- C:\Program Files

      2007-11-08 à 10:07:44 - Adobe
      2007-11-08 à 10:11:58 - Ahead
      2008-03-01 à 18:14:07 - aMSN
      2008-03-22 à 18:48:31 - AntiVir PersonalEdition Classic
      2008-02-04 à 17:46:06 - Apple Software Update
      2008-02-11 à 23:06:25 - BitTorrent
      2007-11-08 à 10:06:38 - CCleaner
      2007-10-25 à 17:07:51 - ComPlus Applications
      2008-02-12 à 15:10:52 - Cubase 5.0
      2008-01-11 à 18:56:39 - Dcads Games Collection
      2008-03-05 à 11:10:15 - EcoKenoSha
      2008-03-19 à 20:14:42 - eMule
      2008-02-05 à 20:08:45 - FBrowserAdvisor
      2008-02-29 à 20:03:17 - FBrowsingAdvisor
      2008-02-22 à 14:01:49 - Fichiers communs
      2007-12-24 à 22:05:14 - Filzip
      2008-03-19 à 23:55:51 - Flyos
      2007-12-24 à 21:56:58 - Google
      2008-03-18 à 18:43:28 - Grisoft
      2008-02-22 à 17:45:18 - iLok
      2008-02-22 à 14:01:14 - InstallShield Installation Information
      2008-02-21 à 23:18:52 - InterLok
      2008-03-04 à 09:19:05 - Internet Explorer
      2008-02-04 à 17:52:34 - iPod
      2008-02-04 à 17:52:44 - iTunes
      2008-01-17 à 00:11:35 - Java
      2007-11-08 à 10:07:25 - Lavasoft
      2008-03-13 à 22:58:03 - LimeWire
      2008-03-16 à 23:48:33 - LitexMedia
      2008-03-22 à 22:32:27 - Lopxp
      2008-03-21 à 14:49:51 - Messenger Plus! Live
      2007-10-29 à 16:24:06 - Microsoft Office
      2008-03-16 à 23:50:15 - Microsoft SQL Server Compact Edition
      2008-02-29 à 20:10:37 - Mozilla Firefox
      2007-10-25 à 17:19:09 - MSXML 4.0
      2007-10-25 à 17:19:18 - MSXML 6.0
      2007-10-25 à 17:09:10 - NetMeeting
      2007-10-25 à 17:09:04 - Outlook Express
      2008-02-04 à 17:46:51 - QuickTime
      2008-03-21 à 16:02:43 - RAR Password Cracker
      2007-12-24 à 21:56:31 - Real
      2007-11-08 à 10:16:06 - S3Inc
      2007-12-24 à 20:37:28 - SAGEM
      2008-01-16 à 22:27:44 - Samsung
      2007-12-24 à 20:24:24 - Securitoo
      2007-10-25 à 17:09:36 - Services en ligne
      2008-03-12 à 08:55:05 - set up
      2008-03-12 à 14:51:01 - Sony
      2008-03-12 à 14:49:47 - Sony Setup
      2007-11-08 à 10:09:51 - Spybot - Search & Destroy
      2008-03-18 à 23:44:47 - Sunbelt Software
      2008-03-18 à 18:19:10 - Trend Micro
      2007-10-25 à 17:28:16 - Uninstall Information
      2008-01-16 à 02:26:24 - VideoLAN
      2008-01-08 à 13:17:16 - Visicom Media
      2008-01-23 à 01:14:03 - VS Revo Group
      2008-02-12 à 14:47:25 - VST Plugins
      2008-03-22 à 21:45:47 - Wanadoo
      2008-03-18 à 02:02:27 - Windows Live
      2007-12-24 à 22:22:25 - Windows Live Favorites
      2008-03-21 à 23:21:27 - Windows Live Safety Center
      2007-12-24 à 22:22:36 - Windows Live Toolbar
      2008-03-12 à 14:50:55 - Windows Media Player
      2007-10-25 à 17:07:19 - Windows NT
      2007-10-25 à 17:09:40 - WindowsUpdate
      2007-11-08 à 10:06:24 - WinRAR
      2008-03-04 à 19:11:27 - Winsos
      2008-01-30 à 00:08:51 - YesMessenger

      ========== Tâches planifiées

      AppleSoftwareUpdate.job: C:\Program Files\Apple Software Update\SoftwareUpdate.exe -task
      Vérifier les mises à jour de Windows Live Toolbar.job: C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE

      ========== Clés registre


      ========== Bloqueur popups Internet Explorer


      ========== Suggestion ( /!\ Nécessite une interprétation.) ==========

      +- Dossiers\Fichiers : Aucune suggestion.

      +- Registre : Aucune suggestion.


      - Fin du rapport -
      0
  12. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    Bonjour

    Bon très bien
    plus grand chose dans ton hijack
    mise à part ta version pirate !

    as tu encore des soucis ?
    0
    1. tmax83
       
      merci beaucoup pour l aide apparament je n ai plus de fenetre de pub!! quel version pirate?? de quoi parlez vous? je clik resolu dans les probleme!! merci encore
      0
  13. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    il faut faire une dernière manip
    Tu peux supprimer tous les logiciels que nous avons utilisés
    va dans ajout/suppression de programes et dans programmes files
    pour vérifier

    ensuite fait ceci (IMPORTANT)

    =démarrer
    =panneau de configuration
    =système
    =onglet Restauration système
    =coche la case (Désactiver la restauration système)
    =redémarre l'ordinateur
    =réactive la ensuite
    @+
    0
    1. tmax83
       
      merci!!! je l ai pas dans le programme files mais ya l icone dans le bureau et quand je clik il marche !!! la j cromprend pa trop !!!??? comment sa ce fait que j le trouve pas!! il me semble que quand j lé telechargé j ai mis ouvrir!!!
      0
  14. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    tu relance lopxp et tu choisis l'option 3
    @+
    0
    1. tmax83
       
      ok j te tien o courant++
      0
  15. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    ok bye
    0
    1. tmax83
       
      ok tout est bon apparament !!nikel merci bien pour le temps passé et les explications!!! :)
      0
  16. ep44 Messages postés 7415 Date d'inscription   Statut Contributeur Dernière intervention   3
     
    ;-)
    0