Virus remover 2008 + bug + a l'aide!

Bonjour,

alors je vous explique mes differents problemes, j'ai en effet été infecté par un virus, qui se nomme "virusremover2008", et c'est une belle saloperie...
J'aimerai votre aide pour m'en debarassé...

2eme problemes, j'ai réinstallé windows il y a peu, et des que je demarre le pc il me marque "ntldr manquant" je ne peux pas aller sur windows sans y mettre le cd d'installation...

et enfin de temps en temps j'ai le pc qui plante, je m'explique, je navigue sur le web et pouf un ecran bleue qui s'affiche avec un texte, mais le pc redemarre de suite donc je n'arrive pas a lire ce texte, et il redemarre, pouf ecran bleue, redemarre, pouf ecran bleue, redémarre et au bout d'un certain nombre de fois il tiens le coup et je peux a nouveau utilisé mon pc...

Alors svp, j'ai vraiment besoin d'aide!

L'ordre d'apparition des problemes: en 1: fichier NTLDR, en 2 le bug avec l'ecran bleue, en 3 ce satané virus...

PS: Je n'arrive pas à démarrer en mode sans echec...

Merci pour votre aide!
Configuration: Windows XP
Firefox 2.0.0.17

15 réponses

  1. voici le rapport...

    SmitFraudFix v2.365

    Rapport fait à 13:42:04,50, 21/09/2008
    Executé à partir de D:\Documents and Settings\Propri‚taire\Bureau\SmitfraudFix
    OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
    Le type du système de fichiers est NTFS
    Fix executé en mode sans echec

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    127.0.0.1 localhost

    »»»»»»»»»»»»»»»»»»»»»»»» VACFix

    VACFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

    S!Ri's WS2Fix: LSP not Found.

    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

    D:\WINDOWS\privacy_danger\ supprimé

    »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

    IEDFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» 404Fix

    404Fix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix

    AntiXPVSTFix
    Credits: Malware Analysis & Diagnostic
    Code: S!Ri

    »»»»»»»»»»»»»»»»»»»»»»»» RK

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{26535495-7532-450F-A79F-40BBFACE651D}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{26535495-7532-450F-A79F-40BBFACE651D}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS2\Services\Tcpip\..\{26535495-7532-450F-A79F-40BBFACE651D}: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
    HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

    »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
    "System"=""

    »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

    Nettoyage terminé.

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
    !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Fin
    0
    1. Contributeur sécurité
      Salut !!

      pourquoi n arrives tu pas à redémarrer en mode sans échec ??

      Fais un rapport hijackthis pour que je puisse vérifier les infections de ton pc stp

      ▶ Télécharge hijackthis à cette adresse, tout est expliqué pour bien l installer et pour savoir s'en servir :

      https://www.androidworld.fr/

      Comment copier/coller le rapport :

      Quand tu as le rapport à l écran, tu fais ctrl A pour "sélectionner tout" puis ctrl C pour "copier".

      ensuite tu viens sur le forum pour me répondre et tu fais ctrl V pour "coller" le rapport.

      Une explication des raccourcis clavier sont illustrés sur mon site web à cette adresse :

      https://www.androidworld.fr/
      -1
      1. Logfile of Trend Micro HijackThis v2.0.2
        Scan saved at 13:15:44, on 21/09/2008
        Platform: Windows XP SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
        Boot mode: Normal

        Running processes:
        D:\WINDOWS\System32\smss.exe
        D:\WINDOWS\system32\winlogon.exe
        D:\WINDOWS\system32\services.exe
        D:\WINDOWS\system32\lsass.exe
        D:\WINDOWS\system32\svchost.exe
        D:\WINDOWS\System32\svchost.exe
        D:\WINDOWS\system32\spoolsv.exe
        D:\WINDOWS\Explorer.EXE
        D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
        D:\WINDOWS\RTHDCPL.EXE
        D:\WINDOWS\system32\RUNDLL32.EXE
        C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
        D:\Program Files\GameFace Messenger\GameFace.exe
        D:\WINDOWS\system32\LVCOMSX.EXE
        D:\Program Files\Logitech\Video\LogiTray.exe
        D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
        D:\WINDOWS\system32\rundll32.exe
        D:\WINDOWS\system32\ctfmon.exe
        D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        D:\Program Files\TS-2009\scan.exe
        D:\PROGRA~1\Wanadoo\TaskBarIcon.exe
        D:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
        D:\Program Files\IncrediMail\bin\IMApp.exe
        D:\PROGRA~1\Wanadoo\ComComp.exe
        D:\PROGRA~1\Wanadoo\Toaster.exe
        D:\PROGRA~1\Wanadoo\Inactivity.exe
        D:\PROGRA~1\Wanadoo\PollingModule.exe
        D:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
        D:\WINDOWS\ATKKBService.exe
        D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
        D:\WINDOWS\System32\FTRTSVC.exe
        D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
        D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
        D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
        D:\WINDOWS\system32\nvsvc32.exe
        D:\WINDOWS\system32\svchost.exe
        D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
        D:\WINDOWS\system32\wscntfy.exe
        D:\Program Files\Logitech\Video\FxSvr2.exe
        D:\Program Files\Mozilla Firefox\firefox.exe
        D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2
        R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
        R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - D:\PROGRA~1\Wanadoo\SEARCH~1.DLL
        O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
        O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
        O4 - HKLM\..\Run: [nTrayFw] D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
        O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
        O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
        O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
        O4 - HKLM\..\Run: [JMB36X IDE Setup] D:\WINDOWS\JM\JMInsIDE.exe
        O4 - HKLM\..\Run: [JMB36X Configure] D:\WINDOWS\system32\JMRaidSetup.exe boot
        O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
        O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
        O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
        O4 - HKLM\..\Run: [GamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
        O4 - HKLM\..\Run: [GameFace Messenger] D:\Program Files\GameFace Messenger\GameFace.exe
        O4 - HKLM\..\Run: [LVCOMSX] D:\WINDOWS\system32\LVCOMSX.EXE
        O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
        O4 - HKLM\..\Run: [LogitechVideoRepair] D:\Program Files\Logitech\Video\ISStart.exe
        O4 - HKLM\..\Run: [LogitechVideoTray] D:\Program Files\Logitech\Video\LogiTray.exe
        O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
        O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
        O4 - HKLM\..\Run: [WOOWATCH] D:\PROGRA~1\Wanadoo\Watch.exe
        O4 - HKLM\..\Run: [WOOTASKBARICON] D:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
        O4 - HKLM\..\Run: [18636829] rundll32.exe "D:\WINDOWS\system32\pgkmjwlq.dll",b
        O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
        O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe /start
        O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
        O4 - HKCU\..\Run: [IncrediMail] D:\Program Files\IncrediMail\bin\IncMail.exe /c
        O4 - HKCU\..\Run: [LDM] D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
        O4 - HKCU\..\Run: [WOOKIT] D:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
        O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
        O4 - HKCU\..\Run: [TotalSecure2009] D:\Program Files\TS-2009\scan.exe
        O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
        O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
        O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
        O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
        O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
        O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
        O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
        O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
        O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
        O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
        O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
        O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
        O20 - AppInit_DLLs: ubuibq.dll
        O21 - SSODL: vwnskbot - {2D304BDA-1607-4671-82CB-EA85116B9D8E} - D:\WINDOWS\vwnskbot.dll
        O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - D:\WINDOWS\ATKKBService.exe
        O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
        O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
        O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - D:\WINDOWS\System32\FTRTSVC.exe
        O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
        O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
        O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
        O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
        O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
        O24 - Desktop Component 0: Privacy Protection - file:///D:\WINDOWS\privacy_danger\index.htm
        -1
        1. Contributeur sécurité
          Commence par faire ceci stp :

          Option 1 - Recherche :

          ▶ télécharge smitfraudfix et enregistre le sur le bureau

          (c est le numéro 2 en bas de la page) :

          ▶ Ensuite double clique sur smitfraudfix puis exécuter

          ▶ Sélectionner 1 pour créer un rapport des fichiers responsables de l'infection.

          (attention : N utilises pas l option 2 si je ne te l ai pas demandé !!)

          ▶ copier/coller le rapport dans la réponse.

          Un tutoriel sonore et animé est à ta disposition sur le site.

          (Attention : "process.exe", un composant de l'outil, est détecté par certains antivirus comme étant un "RiskTool".
          Il ne s'agit pas d'un virus, mais d'un utilitaire destiné à mettre fin à des processus. Mis entre de mauvaises mains,
          cet utilitaire pourrait arrêter des logiciels de sécurité.)
          -1
          1. Et voilà... ;)

            SmitFraudFix v2.365

            Rapport fait à 13:27:22,73, 21/09/2008
            Executé à partir de D:\Program Files\Mozilla Firefox\SmitfraudFix
            OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
            Le type du système de fichiers est NTFS
            Fix executé en mode normal

            »»»»»»»»»»»»»»»»»»»»»»»» Process

            D:\WINDOWS\System32\smss.exe
            D:\WINDOWS\system32\winlogon.exe
            D:\WINDOWS\system32\services.exe
            D:\WINDOWS\system32\lsass.exe
            D:\WINDOWS\system32\svchost.exe
            D:\WINDOWS\System32\svchost.exe
            D:\WINDOWS\system32\spoolsv.exe
            D:\WINDOWS\Explorer.EXE
            D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
            D:\WINDOWS\RTHDCPL.EXE
            D:\WINDOWS\system32\RUNDLL32.EXE
            C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
            D:\Program Files\GameFace Messenger\GameFace.exe
            D:\WINDOWS\system32\LVCOMSX.EXE
            D:\Program Files\Logitech\Video\LogiTray.exe
            D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
            D:\WINDOWS\system32\rundll32.exe
            D:\WINDOWS\system32\ctfmon.exe
            D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
            D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
            D:\Program Files\TS-2009\scan.exe
            D:\PROGRA~1\Wanadoo\TaskBarIcon.exe
            D:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
            D:\Program Files\IncrediMail\bin\IMApp.exe
            D:\PROGRA~1\Wanadoo\ComComp.exe
            D:\PROGRA~1\Wanadoo\Toaster.exe
            D:\PROGRA~1\Wanadoo\Inactivity.exe
            D:\PROGRA~1\Wanadoo\PollingModule.exe
            D:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
            D:\WINDOWS\ATKKBService.exe
            D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
            D:\WINDOWS\System32\FTRTSVC.exe
            D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
            D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
            D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
            D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
            D:\WINDOWS\system32\nvsvc32.exe
            D:\WINDOWS\system32\svchost.exe
            D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
            D:\WINDOWS\system32\wscntfy.exe
            D:\Program Files\Logitech\Video\FxSvr2.exe
            D:\Program Files\Mozilla Firefox\firefox.exe
            D:\Program Files\Windows Live\Messenger\msnmsgr.exe
            D:\Program Files\Windows Live\Messenger\usnsvc.exe
            D:\Program Files\Internet Explorer\iexplore.exe
            D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
            D:\Program Files\FlashGet\FlashGet.exe
            D:\Program Files\Mozilla Firefox\SmitfraudFix\Policies.exe
            D:\WINDOWS\system32\cmd.exe

            »»»»»»»»»»»»»»»»»»»»»»»» hosts

            »»»»»»»»»»»»»»»»»»»»»»»» D:\

            »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS

            D:\WINDOWS\privacy_danger PRESENT !

            »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system

            »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\Web

            »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system32

            »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system32\LogFiles

            »»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\Propri‚taire

            »»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\Propri‚taire\Application Data

            »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

            »»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\PROPRI~1\Favoris

            »»»»»»»»»»»»»»»»»»»»»»»» Bureau

            »»»»»»»»»»»»»»»»»»»»»»»» D:\Program Files

            »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

            »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
            "Source"="file:///D:\\WINDOWS\\privacy_danger\\index.htm"
            "SubscribedURL"=""
            "FriendlyName"="Privacy Protection"

            [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
            "Source"="About:Home"
            "SubscribedURL"="About:Home"
            "FriendlyName"="Ma page d'accueil"

            »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            o4Patch
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            IEDFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» VACFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            VACFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            404Fix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            AntiXPVSTFix
            Credits: Malware Analysis & Diagnostic
            Code: S!Ri

            »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            SrchSTS.exe by S!Ri
            Search SharedTaskScheduler's .dll

            »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
            "AppInit_DLLs"="ubuibq.dll"

            »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
            !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

            [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
            "Userinit"="D:\\WINDOWS\\system32\\userinit.exe,"
            "System"=""

            »»»»»»»»»»»»»»»»»»»»»»»» RK

            »»»»»»»»»»»»»»»»»»»»»»»» DNS

            Description: NVIDIA nForce Networking Controller - Miniport d'ordonnancement de paquets
            DNS Server Search Order: 192.168.1.1

            HKLM\SYSTEM\CCS\Services\Tcpip\..\{26535495-7532-450F-A79F-40BBFACE651D}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\..\{26535495-7532-450F-A79F-40BBFACE651D}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\..\{26535495-7532-450F-A79F-40BBFACE651D}: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
            HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

            »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

            »»»»»»»»»»»»»»»»»»»»»»»» Fin
            -1
            1. Contributeur sécurité
              ok maintenant fais ceci stp :

              Option 2 - Nettoyage :

              redémarre le PC mode sans échec

              ▶ Double cliquer sur smitfraudfix

              ▶ Sélectionner 2 pour supprimer les fichiers responsables de l'infection.

              ▶ A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.

              Le fix déterminera si le fichier wininet.dll est infecté. A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

              ▶ Enregistre le rapport sur ton bureau

              ▶ Redémarrer en mode normal et poster le rapport.

              ensuite :

              ▶ Télécharge malwarebytes

              ▶ Voici mon tuto pour bien l installer et bien l utiliser :

              https://www.androidworld.fr/

              aide toi bien du tuto pour supprimer correctement ce qu il aura trouvé

              Après l analyse, redémarre le pc et poste le rapport !!

              Et refais un nouveau rapport hijackthis stp
              -1
              1. Contributeur sécurité
                tres bien... Miantenant tu peux faire malwarebytes ..

                aide toi bien du tuto pour supprimer correctement ce qu il aura trouvé
                -1
                1. voici le rapport!

                  Malwarebytes' Anti-Malware 1.29
                  Version de la base de données: 1300
                  Windows 5.1.2600 Service Pack 2

                  21/09/2008 14:16:55
                  mbam-log-2008-09-21 (14-16-55).txt

                  Type de recherche: Examen complet (C:\|D:\|)
                  Eléments examinés: 94993
                  Temps écoulé: 19 minute(s), 38 second(s)

                  Processus mémoire infecté(s): 0
                  Module(s) mémoire infecté(s): 3
                  Clé(s) du Registre infectée(s): 11
                  Valeur(s) du Registre infectée(s): 3
                  Elément(s) de données du Registre infecté(s): 3
                  Dossier(s) infecté(s): 2
                  Fichier(s) infecté(s): 23

                  Processus mémoire infecté(s):
                  (Aucun élément nuisible détecté)

                  Module(s) mémoire infecté(s):
                  D:\WINDOWS\system32\efcAqRLf.dll (Trojan.Vundo.H) -> Delete on reboot.
                  D:\WINDOWS\system32\pgkmjwlq.dll (Trojan.Vundo.H) -> Delete on reboot.
                  D:\WINDOWS\system32\ubuibq.dll (Trojan.Vundo) -> Delete on reboot.

                  Clé(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{470a547b-b6aa-4314-aa97-2c0c28b715bb} (Trojan.Vundo.H) -> Delete on reboot.
                  HKEY_CLASSES_ROOT\CLSID\{470a547b-b6aa-4314-aa97-2c0c28b715bb} (Trojan.Vundo.H) -> Delete on reboot.
                  HKEY_CLASSES_ROOT\CLSID\{68884e28-df67-4d75-8111-bed3924801dc} (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{68884e28-df67-4d75-8111-bed3924801dc} (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\TotalSecure2009 (Rogue.TotalSecure) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\VSPlugin (Trojan.FakeAlert) -> Quarantined and deleted successfully.

                  Valeur(s) du Registre infectée(s):
                  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\18636829 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\TotalSecure2009 (Rogue.TotalSecure) -> Quarantined and deleted successfully.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0\source (Trojan.FakeAlert) -> Quarantined and deleted successfully.

                  Elément(s) de données du Registre infecté(s):
                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: d:\windows\system32\efcaqrlf -> Quarantined and deleted successfully.
                  HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: d:\windows\system32\efcaqrlf -> Delete on reboot.
                  HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.Homepage) -> Bad: (http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2 Good: (https://www.google.com/?gws_rd=ssl -> Quarantined and deleted successfully.

                  Dossier(s) infecté(s):
                  D:\WINDOWS\privacy_danger (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  D:\WINDOWS\privacy_danger\images (Trojan.FakeAlert) -> Quarantined and deleted successfully.

                  Fichier(s) infecté(s):
                  D:\WINDOWS\system32\efcAqRLf.dll (Trojan.Vundo.H) -> Delete on reboot.
                  D:\WINDOWS\system32\fLRqAcfe.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  D:\WINDOWS\system32\fLRqAcfe.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  D:\WINDOWS\system32\pgkmjwlq.dll (Trojan.Vundo.H) -> Delete on reboot.
                  D:\WINDOWS\system32\qlwjmkgp.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
                  D:\WINDOWS\system32\ubuibq.dll (Trojan.Vundo) -> Delete on reboot.
                  D:\Documents and Settings\Propriétaire\Mes documents\Downloads\Programs\EvID4226Patch.exe (Adware.Agent) -> Quarantined and deleted successfully.
                  D:\System Volume Information\_restore{4CA44539-CE7A-4343-A183-6153F0B77F06}\RP67\A0080377.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  D:\System Volume Information\_restore{4CA44539-CE7A-4343-A183-6153F0B77F06}\RP67\A0080379.dll (Trojan.Zlob) -> Quarantined and deleted successfully.
                  D:\System Volume Information\_restore{4CA44539-CE7A-4343-A183-6153F0B77F06}\RP67\A0080383.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  D:\WINDOWS\egme.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  D:\WINDOWS\system32\hdarutoi.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
                  D:\WINDOWS\privacy_danger\index.htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  D:\WINDOWS\privacy_danger\images\body.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  D:\WINDOWS\privacy_danger\images\capt.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  D:\WINDOWS\privacy_danger\images\capt2.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  D:\WINDOWS\privacy_danger\images\red.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  D:\WINDOWS\privacy_danger\images\text.gif (Trojan.FakeAlert) -> Quarantined and deleted successfully.
                  D:\Program Files\TS-2009\scan.exe (Rogue.TotalSecure) -> Delete on reboot.
                  D:\Documents and Settings\Propriétaire\Application Data\TmpRecentIcons\Total Secure 2009.lnk (Rogue.Link) -> Quarantined and deleted successfully.
                  D:\Documents and Settings\Propriétaire\Bureau\Protect Your Privacy.url (Rogue.Link) -> Quarantined and deleted successfully.
                  D:\Documents and Settings\Propriétaire\Bureau\Malware Defender.url (Rogue.Link) -> Quarantined and deleted successfully.
                  D:\Documents and Settings\Propriétaire\Bureau\System Error Fixer.url (Rogue.Link) -> Quarantined and deleted successfully.
                  -1
                  1. Contributeur sécurité
                    ok maintenant refais un nouveau rapport hijackthis pour vérifier stp
                    -1
                    1. Logfile of Trend Micro HijackThis v2.0.2
                      Scan saved at 14:28:31, on 21/09/2008
                      Platform: Windows XP SP2 (WinNT 5.01.2600)
                      MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                      Boot mode: Normal

                      Running processes:
                      D:\WINDOWS\System32\smss.exe
                      D:\WINDOWS\system32\winlogon.exe
                      D:\WINDOWS\system32\services.exe
                      D:\WINDOWS\system32\lsass.exe
                      D:\WINDOWS\system32\svchost.exe
                      D:\WINDOWS\System32\svchost.exe
                      D:\WINDOWS\system32\spoolsv.exe
                      D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
                      D:\WINDOWS\RTHDCPL.EXE
                      D:\WINDOWS\system32\RUNDLL32.EXE
                      C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
                      D:\Program Files\GameFace Messenger\GameFace.exe
                      D:\WINDOWS\system32\LVCOMSX.EXE
                      D:\Program Files\Logitech\Video\LogiTray.exe
                      D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                      D:\WINDOWS\system32\rundll32.exe
                      D:\Program Files\FlashGet\FlashGet.exe
                      D:\WINDOWS\system32\ctfmon.exe
                      D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                      D:\Program Files\Windows Live\Messenger\msnmsgr.exe
                      D:\Program Files\TS-2009\scan.exe
                      D:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                      D:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                      D:\Program Files\IncrediMail\bin\IMApp.exe
                      D:\PROGRA~1\Wanadoo\ComComp.exe
                      D:\PROGRA~1\Wanadoo\Toaster.exe
                      D:\PROGRA~1\Wanadoo\Inactivity.exe
                      D:\PROGRA~1\Wanadoo\PollingModule.exe
                      D:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                      D:\WINDOWS\ATKKBService.exe
                      D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                      D:\WINDOWS\System32\FTRTSVC.exe
                      D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                      D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                      D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                      D:\WINDOWS\system32\nvsvc32.exe
                      D:\WINDOWS\system32\svchost.exe
                      D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
                      D:\PROGRA~1\Wanadoo\Watch.exe
                      D:\WINDOWS\system32\wscntfy.exe
                      D:\Program Files\Logitech\Video\FxSvr2.exe
                      D:\Program Files\Windows Live\Messenger\usnsvc.exe
                      D:\Program Files\Internet Explorer\iexplore.exe
                      D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                      D:\PROGRA~1\MOZILL~1\FIREFOX.EXE
                      D:\WINDOWS\explorer.exe
                      D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                      R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                      R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                      R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - D:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                      O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
                      O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
                      O4 - HKLM\..\Run: [nTrayFw] D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
                      O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                      O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                      O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                      O4 - HKLM\..\Run: [JMB36X IDE Setup] D:\WINDOWS\JM\JMInsIDE.exe
                      O4 - HKLM\..\Run: [JMB36X Configure] D:\WINDOWS\system32\JMRaidSetup.exe boot
                      O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
                      O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                      O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                      O4 - HKLM\..\Run: [GamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
                      O4 - HKLM\..\Run: [GameFace Messenger] D:\Program Files\GameFace Messenger\GameFace.exe
                      O4 - HKLM\..\Run: [LVCOMSX] D:\WINDOWS\system32\LVCOMSX.EXE
                      O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                      O4 - HKLM\..\Run: [LogitechVideoRepair] D:\Program Files\Logitech\Video\ISStart.exe
                      O4 - HKLM\..\Run: [LogitechVideoTray] D:\Program Files\Logitech\Video\LogiTray.exe
                      O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                      O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
                      O4 - HKLM\..\Run: [WOOWATCH] D:\PROGRA~1\Wanadoo\Watch.exe
                      O4 - HKLM\..\Run: [WOOTASKBARICON] D:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                      O4 - HKLM\..\Run: [Flashget] "D:\Program Files\FlashGet\FlashGet.exe" /min
                      O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "D:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
                      O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] D:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
                      O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
                      O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe /start
                      O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                      O4 - HKCU\..\Run: [IncrediMail] D:\Program Files\IncrediMail\bin\IncMail.exe /c
                      O4 - HKCU\..\Run: [LDM] D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                      O4 - HKCU\..\Run: [WOOKIT] D:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                      O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                      O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                      O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                      O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                      O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                      O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                      O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
                      O8 - Extra context menu item: &Tout télécharger avec FlashGet - D:\Program Files\FlashGet\jc_all.htm
                      O8 - Extra context menu item: &Télécharger avec FlashGet - D:\Program Files\FlashGet\jc_link.htm
                      O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
                      O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                      O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\FlashGet.exe
                      O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\FlashGet.exe
                      O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                      O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                      O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                      O20 - AppInit_DLLs: ubuibq.dll
                      O21 - SSODL: vwnskbot - {2D304BDA-1607-4671-82CB-EA85116B9D8E} - D:\WINDOWS\vwnskbot.dll
                      O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - D:\WINDOWS\ATKKBService.exe
                      O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
                      O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                      O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - D:\WINDOWS\System32\FTRTSVC.exe
                      O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                      O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                      O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                      O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                      O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
                      O24 - Desktop Component 0: Privacy Protection - file:///D:\WINDOWS\privacy_danger\index.htm
                      -1
                      1. Contributeur sécurité
                        les infections sont toujours là alors qu elles ont été supprimées :s bizarre tout ca

                        vas vider la quarantaine de malwarebytes, redémarre le PC et refais un nouveau rapport hijackthis stp
                        -1
                        1. Bonjour.
                          Désolé du retard...

                          voici le nouveau rapport avec la suppression de la quarantaine et le redémarrage...

                          Logfile of Trend Micro HijackThis v2.0.2
                          Scan saved at 10:06:28, on 23/09/2008
                          Platform: Windows XP SP2 (WinNT 5.01.2600)
                          MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
                          Boot mode: Normal

                          Running processes:
                          D:\WINDOWS\System32\smss.exe
                          D:\WINDOWS\system32\winlogon.exe
                          D:\WINDOWS\system32\services.exe
                          D:\WINDOWS\system32\lsass.exe
                          D:\WINDOWS\system32\svchost.exe
                          D:\WINDOWS\System32\svchost.exe
                          D:\WINDOWS\system32\spoolsv.exe
                          D:\WINDOWS\Explorer.EXE
                          D:\WINDOWS\ATKKBService.exe
                          D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                          D:\WINDOWS\System32\FTRTSVC.exe
                          D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                          D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                          D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                          D:\WINDOWS\system32\nvsvc32.exe
                          D:\WINDOWS\system32\svchost.exe
                          D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
                          D:\WINDOWS\system32\wscntfy.exe
                          D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
                          D:\WINDOWS\RTHDCPL.EXE
                          D:\WINDOWS\system32\RUNDLL32.EXE
                          C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
                          D:\Program Files\GameFace Messenger\GameFace.exe
                          D:\WINDOWS\system32\LVCOMSX.EXE
                          D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
                          D:\Program Files\Logitech\Video\LogiTray.exe
                          D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                          D:\Program Files\FlashGet\FlashGet.exe
                          D:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                          D:\WINDOWS\system32\ctfmon.exe
                          D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                          D:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          D:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                          D:\PROGRA~1\Wanadoo\ComComp.exe
                          D:\Program Files\IncrediMail\bin\IMApp.exe
                          D:\PROGRA~1\Wanadoo\Toaster.exe
                          D:\PROGRA~1\Wanadoo\Inactivity.exe
                          D:\PROGRA~1\Wanadoo\PollingModule.exe
                          D:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                          D:\PROGRA~1\Wanadoo\Watch.exe
                          D:\Program Files\Windows Live\Messenger\usnsvc.exe
                          D:\Program Files\Logitech\Video\FxSvr2.exe
                          D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                          D:\WINDOWS\system32\rundll32.exe
                          D:\Program Files\Mozilla Firefox\firefox.exe
                          D:\Program Files\Internet Explorer\iexplore.exe
                          D:\Program Files\Trend Micro\HijackThis\HijackThis.exe

                          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Orange
                          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
                          R3 - URLSearchHook: Search Class - {08C06D61-F1F3-4799-86F8-BE1A89362C85} - D:\PROGRA~1\Wanadoo\SEARCH~1.DLL
                          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - d:\program files\google\googletoolbar1.dll
                          O3 - Toolbar: Barre d'outils MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - D:\Program Files\MSN Toolbar\01.01.2607.0\fr\msntb.dll
                          O4 - HKLM\..\Run: [nTrayFw] D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
                          O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
                          O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
                          O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
                          O4 - HKLM\..\Run: [JMB36X IDE Setup] D:\WINDOWS\JM\JMInsIDE.exe
                          O4 - HKLM\..\Run: [JMB36X Configure] D:\WINDOWS\system32\JMRaidSetup.exe boot
                          O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
                          O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
                          O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
                          O4 - HKLM\..\Run: [GamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
                          O4 - HKLM\..\Run: [GameFace Messenger] D:\Program Files\GameFace Messenger\GameFace.exe
                          O4 - HKLM\..\Run: [LVCOMSX] D:\WINDOWS\system32\LVCOMSX.EXE
                          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
                          O4 - HKLM\..\Run: [LogitechVideoRepair] D:\Program Files\Logitech\Video\ISStart.exe
                          O4 - HKLM\..\Run: [LogitechVideoTray] D:\Program Files\Logitech\Video\LogiTray.exe
                          O4 - HKLM\..\Run: [SunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
                          O4 - HKLM\..\Run: [WOOWATCH] D:\PROGRA~1\Wanadoo\Watch.exe
                          O4 - HKLM\..\Run: [WOOTASKBARICON] D:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
                          O4 - HKLM\..\Run: [Flashget] "D:\Program Files\FlashGet\FlashGet.exe" /min
                          O4 - HKLM\..\Run: [18636829] rundll32.exe "D:\WINDOWS\system32\hkknfakh.dll",b
                          O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
                          O4 - HKCU\..\Run: [ASUS SmartDoctor] C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe /start
                          O4 - HKCU\..\Run: [swg] D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                          O4 - HKCU\..\Run: [IncrediMail] D:\Program Files\IncrediMail\bin\IncMail.exe /c
                          O4 - HKCU\..\Run: [LDM] D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                          O4 - HKCU\..\Run: [WOOKIT] D:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
                          O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
                          O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE LOCAL')
                          O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVICE RÉSEAU')
                          O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
                          O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
                          O4 - Global Startup: Logitech Desktop Messenger.lnk = D:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
                          O4 - Global Startup: Microsoft Office.lnk = D:\Program Files\Microsoft Office\Office\OSA9.EXE
                          O8 - Extra context menu item: &Tout télécharger avec FlashGet - D:\Program Files\FlashGet\jc_all.htm
                          O8 - Extra context menu item: &Télécharger avec FlashGet - D:\Program Files\FlashGet\jc_link.htm
                          O9 - Extra button: Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra 'Tools' menuitem: Windows Messenger - -{FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
                          O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                          O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
                          O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\FlashGet.exe
                          O9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\Program Files\FlashGet\FlashGet.exe
                          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
                          O9 - Extra button: Orange - {1462651F-F4BA-4C76-A001-C4284D0FE16E} - https://www.orange.fr/portail (file missing) (HKCU)
                          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/...
                          O20 - AppInit_DLLs: ubuibq.dll utergg.dll
                          O21 - SSODL: vwnskbot - {93F073A4-E999-43F8-8CD1-55043A8A52A7} - D:\WINDOWS\vwnskbot.dll
                          O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - D:\WINDOWS\ATKKBService.exe
                          O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
                          O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Apache Software Foundation - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                          O23 - Service: France Telecom Routing Table Service (FTRTSVC) - France Telecom - D:\WINDOWS\System32\FTRTSVC.exe
                          O23 - Service: Google Updater Service (gusvc) - Google - D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                          O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
                          O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA Corporation - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                          O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                          O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - D:\WINDOWS\system32\nvsvc32.exe
                          O24 - Desktop Component 0: Privacy Protection - file:///D:\WINDOWS\privacy_danger\index.htm
                          -1
                          1. Contributeur sécurité
                            Salut !!

                            refais une recherche avec SmitFraudFix en tapant 1 stp
                            -1
                            1. Bonjour...
                              Et voili voilou!

                              SmitFraudFix v2.365

                              Rapport fait à 6:22:51,37, 24/09/2008
                              Executé à partir de D:\Documents and Settings\Propri‚taire\Bureau\SmitfraudFix
                              OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                              Le type du système de fichiers est NTFS
                              Fix executé en mode normal

                              »»»»»»»»»»»»»»»»»»»»»»»» Process

                              D:\WINDOWS\System32\smss.exe
                              D:\WINDOWS\system32\winlogon.exe
                              D:\WINDOWS\system32\services.exe
                              D:\WINDOWS\system32\lsass.exe
                              D:\WINDOWS\system32\svchost.exe
                              D:\WINDOWS\System32\svchost.exe
                              D:\WINDOWS\system32\spoolsv.exe
                              D:\WINDOWS\Explorer.EXE
                              D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
                              D:\WINDOWS\RTHDCPL.EXE
                              D:\WINDOWS\system32\RUNDLL32.EXE
                              C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
                              D:\Program Files\GameFace Messenger\GameFace.exe
                              D:\WINDOWS\system32\LVCOMSX.EXE
                              D:\Program Files\Logitech\Video\LogiTray.exe
                              D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
                              D:\Program Files\FlashGet\FlashGet.exe
                              D:\WINDOWS\system32\rundll32.exe
                              D:\WINDOWS\system32\ctfmon.exe
                              D:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                              D:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
                              D:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              D:\PROGRA~1\Wanadoo\TaskBarIcon.exe
                              D:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
                              D:\Program Files\IncrediMail\bin\IMApp.exe
                              D:\PROGRA~1\Wanadoo\ComComp.exe
                              D:\PROGRA~1\Wanadoo\Toaster.exe
                              D:\PROGRA~1\Wanadoo\Inactivity.exe
                              D:\PROGRA~1\Wanadoo\PollingModule.exe
                              D:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
                              D:\WINDOWS\ATKKBService.exe
                              D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                              D:\WINDOWS\System32\FTRTSVC.exe
                              D:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
                              D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
                              D:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
                              D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
                              D:\WINDOWS\system32\nvsvc32.exe
                              D:\WINDOWS\system32\svchost.exe
                              D:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
                              D:\PROGRA~1\Wanadoo\Watch.exe
                              D:\WINDOWS\system32\wscntfy.exe
                              D:\Program Files\Logitech\Video\FxSvr2.exe
                              D:\Program Files\Windows Live\Messenger\usnsvc.exe
                              D:\Program Files\Internet Explorer\iexplore.exe
                              D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                              D:\Program Files\IncrediMail\bin\ImNotfy.exe
                              D:\Documents and Settings\Propriétaire\Bureau\SmitfraudFix\Policies.exe
                              D:\WINDOWS\system32\cmd.exe

                              »»»»»»»»»»»»»»»»»»»»»»»» hosts

                              »»»»»»»»»»»»»»»»»»»»»»»» D:\

                              »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS

                              D:\WINDOWS\privacy_danger PRESENT !

                              »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system

                              »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\Web

                              »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system32

                              »»»»»»»»»»»»»»»»»»»»»»»» D:\WINDOWS\system32\LogFiles

                              »»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\Propri‚taire

                              »»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\Propri‚taire\Application Data

                              »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                              »»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\PROPRI~1\Favoris

                              »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                              »»»»»»»»»»»»»»»»»»»»»»»» D:\Program Files

                              »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                              »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                              "Source"="file:///D:\\WINDOWS\\privacy_danger\\index.htm"
                              "SubscribedURL"=""
                              "FriendlyName"="Privacy Protection"

                              [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
                              "Source"="About:Home"
                              "SubscribedURL"="About:Home"
                              "FriendlyName"="Ma page d'accueil"

                              »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              o4Patch
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              IEDFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» VACFix
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              VACFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              404Fix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              AntiXPVSTFix
                              Credits: Malware Analysis & Diagnostic
                              Code: S!Ri

                              »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              SrchSTS.exe by S!Ri
                              Search SharedTaskScheduler's .dll

                              »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                              "AppInit_DLLs"="ubuibq.dll ratflk.dll"

                              »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
                              !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                              [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                              "Userinit"="D:\\WINDOWS\\system32\\userinit.exe,"
                              "System"=""

                              »»»»»»»»»»»»»»»»»»»»»»»» RK

                              »»»»»»»»»»»»»»»»»»»»»»»» DNS

                              Description: NVIDIA nForce Networking Controller - Miniport d'ordonnancement de paquets
                              DNS Server Search Order: 192.168.1.1

                              HKLM\SYSTEM\CCS\Services\Tcpip\..\{26535495-7532-450F-A79F-40BBFACE651D}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS1\Services\Tcpip\..\{26535495-7532-450F-A79F-40BBFACE651D}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS2\Services\Tcpip\..\{26535495-7532-450F-A79F-40BBFACE651D}: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                              HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                              »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                              »»»»»»»»»»»»»»»»»»»»»»»» Fin
                              -1
                              1. Contributeur sécurité
                                Salut !!

                                Maintenant fais ceci stp :

                                Option 2 - Nettoyage :

                                redémarre le PC en mode sans échec

                                ▶ Double cliquer sur smitfraudfix

                                ▶ Sélectionner 2 pour supprimer les fichiers responsables de l'infection.

                                ▶ A la question Voulez-vous nettoyer le registre ? répondre O (oui) afin de débloquer le fond d'écran et supprimer les clés de démarrage automatique de l'infection.

                                Le fix déterminera si le fichier wininet.dll est infecté. A la question Corriger le fichier infecté ? répondre O (oui) pour remplacer le fichier corrompu.

                                ▶ Enregistre le rapport sur ton bureau

                                ▶ Redémarrer en mode normal et poster le rapport.

                                ensuite refais un nouveau rapport hijackthis stp
                                -1