Security toolbar 7.1

Bonjour,
voila mon probleme j'ai une barre d'outil (sécurity toolbar 7.1) qui est apparu sur mon pc je ne sais comment et qui enpoisonne ma vie sur mon pc, je suis allé sur des sites cherchant a l'enlever, j'ai télécharger plein de logiciel sans succés alors j'espere que quelqu'un pourra m'aider a enlever ce security toolbar , j'ai vista si cela peut vous etre dune plus grande utilité... je remercie d'avance les personnes qui m'aideront dans cette tache délicate . merci d'avance.
Configuration: Windows Vista
Internet Explorer 7.0

14 réponses

  1. Contributeur sécurité
    tu cré le fichier sur ton bureau puis tu clique dessus avec le bouton droit et tu fais renommer
    et tu change le nom de hijackthis en eden

    ____________

    colle le rapport bitdefender svp et le rapport clean
    0
    1. escuse moi mais je ne trouve pas renommer dans la liste j'ai vista est-ce que sa change en fonction des versions ?je l'ai pris par winrar, c'est bien ce que tu m'as demandé? ( je vais essayer de répondre a ta réponse le plus vite possible ou de faire ce que tu me dira le plus vite possible car j'ai des choses a faire un peu plus importante cette aprés midi) a +
      0
      1. oui les problemes persiste donc je vais télécharger le logiciel comme tu m'as dit et je te donnerai des nouvelles. Merci encore pour ton aide .
        0
        1. Contributeur sécurité
          oui ca devrait

          tu me dera apres le scan bitdefender si des pbs persistent

          __________________

          si ca persiste

          colle un rapport hijackthis

          http://www.trendsecure.com/portal/en-US/tools/security_tools/hijackthis/download

          manuel :

          https://leblogdeclaude.blogspot.com/2006/10/informatique-section-hijackthis.html

          Je conseille de renomer Hijackthis, pour contrer une éventuelle infection de Vundo.

          ex:Renomme le fichier HijackThis.exe en eden.exe pour cela, fais un clic droit sur le fichier HijackThis.exe et choisis renommer dans la liste

          Ensuite avec Explorer créer un dossier c:\hijackthis
          Décompresser Hijackthis dans ce dossier.
          C'est important pour les sauvegardes."
          0
          1. ok et je t'envoie le rapport ? et est-ce que tu sais si j'en serais enfin débarrasé ? Et merci de ton aide.
            0
            1. tu m'as dit de faire ceci:
              colle le rapport d'un scan en ligne avec un des suivants:

              bitdefender en ligne :
              http://www.bitdefender.fr/scan_fr/scan8/ie.html

              scan en ligne firefox

              https://www.trendmicro.com/fr_fr/business.html

              Panda en ligne :
              http://pandasoftware.fr

              le probleme c'est que je ne comprends pas ce qu'il faut faire avec ces liens !!!!
              si tu peux m'assister par la meme occasion lors de la marche a suivre pour enlever security toolbar, se serait super, je te remerrcie d'avance pour ton aide !!!
              0
              1. Contributeur sécurité
                je compren rien par rapport au lien si tu peux m'assisté se seré super:

                que veux tu exactement je comprends pas ?
                0
                1. bon sa va pour l'instant mais je compren rien par rapport au lien si tu peux m'assisté se seré super
                  0
                  1. ---------------------------------------------------------
                    AVG Anti-Spyware - Rapport d'analyse
                    ---------------------------------------------------------

                    + Créé à: 15:26:15 27/10/2007

                    + Résultat de l'analyse:

                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@247realmedia[1].txt -> TrackingCookie.247realmedia : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@adrevolver[1].txt -> TrackingCookie.Adrevolver : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@adtech[1].txt -> TrackingCookie.Adtech : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@advertising[1].txt -> TrackingCookie.Advertising : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@adviva[2].txt -> TrackingCookie.Adviva : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\vivien@atdmt[2].txt -> TrackingCookie.Atdmt : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\vivien@bluestreak[1].txt -> TrackingCookie.Bluestreak : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@casalemedia[1].txt -> TrackingCookie.Casalemedia : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@doubleclick[2].txt -> TrackingCookie.Doubleclick : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@estat[1].txt -> TrackingCookie.Estat : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\vivien@mediaplex[1].txt -> TrackingCookie.Mediaplex : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@overture[1].txt -> TrackingCookie.Overture : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\vivien@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\vivien@serving-sys[2].txt -> TrackingCookie.Serving-sys : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\vivien@smartadserver[1].txt -> TrackingCookie.Smartadserver : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Nettoyé.
                    C:\Users\VIVIEN\AppData\Roaming\Microsoft\Windows\Cookies\Low\vivien@weborama[2].txt -> TrackingCookie.Weborama : Nettoyé.

                    Fin du rapport
                    0
                    1. est- ce qu'il faut resté en mode sans échec tout le long de l'opération? pour avg et le reste ...
                      0
                      1. SmitFraudFix v2.240

                        Scan done at 14:22:52,91, 27/10/2007
                        Run from C:\Users\VIVIEN\Desktop\Nouveau dossier\SmitfraudFix
                        OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                        The filesystem type is NTFS
                        Fix run in safe mode

                        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
                        !!!Attention, following keys are not inevitably infected!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» Killing process

                        »»»»»»»»»»»»»»»»»»»»»»»» hosts

                        127.0.0.1 localhost
                        ::1 localhost

                        »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                        S!Ri's WS2Fix: LSP not Found.

                        »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                        GenericRenosFix by S!Ri

                        »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

                        »»»»»»»»»»»»»»»»»»»»»»»» DNS

                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{0301C86F-F3FA-43C1-B742-FE09192F9668}: DhcpNameServer=211.7.25.1
                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{69F21672-A3AA-4B29-8E31-D86CDC76C547}: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{A0EED90F-24C1-43B8-A957-0E36F43A10A0}: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CCS\Services\Tcpip\..\{EF2F0828-A499-4103-BAA0-3DC77902A86D}: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{0301C86F-F3FA-43C1-B742-FE09192F9668}: DhcpNameServer=211.7.25.1
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{69F21672-A3AA-4B29-8E31-D86CDC76C547}: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{A0EED90F-24C1-43B8-A957-0E36F43A10A0}: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CS1\Services\Tcpip\..\{EF2F0828-A499-4103-BAA0-3DC77902A86D}: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{0301C86F-F3FA-43C1-B742-FE09192F9668}: DhcpNameServer=211.7.25.1
                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{69F21672-A3AA-4B29-8E31-D86CDC76C547}: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{A0EED90F-24C1-43B8-A957-0E36F43A10A0}: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CS3\Services\Tcpip\..\{EF2F0828-A499-4103-BAA0-3DC77902A86D}: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                        HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                        »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files

                        »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                        !!!Attention, following keys are not inevitably infected!!!

                        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

                        Registry Cleaning done.

                        »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
                        !!!Attention, following keys are not inevitably infected!!!

                        SrchSTS.exe by S!Ri
                        Search SharedTaskScheduler's .dll

                        »»»»»»»»»»»»»»»»»»»»»»»» End
                        0
                        1. SmitFraudFix v2.240

                          Scan done at 13:40:17,47, 27/10/2007
                          Run from C:\Users\VIVIEN\SmitfraudFix
                          OS: Microsoft Windows [version 6.0.6000] - Windows_NT
                          The filesystem type is NTFS
                          Fix run in normal mode

                          »»»»»»»»»»»»»»»»»»»»»»»» Process

                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\wininit.exe
                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\services.exe
                          C:\Windows\system32\lsass.exe
                          C:\Windows\system32\lsm.exe
                          C:\Windows\system32\winlogon.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\SLsvc.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
                          C:\Windows\System32\spoolsv.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Program Files\Video Add-on\isfmntr.exe
                          C:\Program Files\Video Add-on\icthis.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\Video Add-on\isfmm.exe
                          C:\Program Files\Common Files\Symantec Shared\ccApp.exe
                          C:\Windows\VM30xSnap.exe
                          C:\Windows\Ctregrun.exe
                          C:\Windows\System32\rundll32.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
                          C:\Program Files\Windows Sidebar\sidebar.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Program Files\Creative\Enregistrement du produit\French\InetReg.exe
                          C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
                          C:\Program Files\Nikon\NkView6\NkvMon.exe
                          C:\Windows\System32\rundll32.exe
                          C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
                          C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
                          C:\Windows\system32\CTsvcCDA.exe
                          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                          C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
                          C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\SearchIndexer.exe
                          C:\Windows\system32\WUDFHost.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\wbem\wmiprvse.exe
                          C:\Program Files\Norton AntiVirus\navw32.exe
                          C:\Windows\system32\wbem\unsecapp.exe
                          C:\Program Files\Internet Explorer\ieuser.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
                          C:\Program Files\Windows Live\Messenger\usnsvc.exe
                          C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
                          C:\Windows\system32\conime.exe
                          C:\Windows\system32\SearchProtocolHost.exe
                          C:\Windows\system32\SearchFilterHost.exe
                          C:\Windows\system32\cmd.exe
                          C:\Windows\system32\wbem\wmiprvse.exe

                          »»»»»»»»»»»»»»»»»»»»»»»» hosts

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\Web

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Windows\system32\LogFiles

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\VIVIEN

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\VIVIEN\Application Data

                          »»»»»»»»»»»»»»»»»»»»»»»» Start Menu

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Users\VIVIEN\FAVORI~1

                          »»»»»»»»»»»»»»»»»»»»»»»» Desktop

                          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                          »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

                          »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

                          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                          !!!Attention, following keys are not inevitably infected!!!

                          SrchSTS.exe by S!Ri
                          Search SharedTaskScheduler's .dll

                          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                          !!!Attention, following keys are not inevitably infected!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                          "AppInit_DLLs"=""
                          "LoadAppInit_DLLs"=dword:00000000

                          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                          !!!Attention, following keys are not inevitably infected!!!

                          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]

                          »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                          »»»»»»»»»»»»»»»»»»»»»»»» DNS

                          Description: 802.11 USB Wireless LAN Adapter #2
                          DNS Server Search Order: 192.168.1.1

                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{0301C86F-F3FA-43C1-B742-FE09192F9668}: DhcpNameServer=211.7.25.1
                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{69F21672-A3AA-4B29-8E31-D86CDC76C547}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{A0EED90F-24C1-43B8-A957-0E36F43A10A0}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CCS\Services\Tcpip\..\{EF2F0828-A499-4103-BAA0-3DC77902A86D}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{0301C86F-F3FA-43C1-B742-FE09192F9668}: DhcpNameServer=211.7.25.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{69F21672-A3AA-4B29-8E31-D86CDC76C547}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{A0EED90F-24C1-43B8-A957-0E36F43A10A0}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\..\{EF2F0828-A499-4103-BAA0-3DC77902A86D}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\..\{0301C86F-F3FA-43C1-B742-FE09192F9668}: DhcpNameServer=211.7.25.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\..\{69F21672-A3AA-4B29-8E31-D86CDC76C547}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\..\{A0EED90F-24C1-43B8-A957-0E36F43A10A0}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\..\{EF2F0828-A499-4103-BAA0-3DC77902A86D}: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1
                          HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1

                          »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection

                          »»»»»»»»»»»»»»»»»»»»»»»» End
                          0
                          1. Contributeur sécurité
                            slt,

                            smit fraud fix (colle le rapport)

                            1/ telecharger :
                            http://telechargement.zebulon.fr/smitfraudfix.html

                            2/ double clique sur smitfraudfix. puis sélectionne 1 et appuyer sur entrée afin de créer le rapport des infection présentes. une fois le rapport effectué redémarre en mode sans échec (en appuyant sur F8 ou suppr, ou F5 au démarrage en général)

                            3/ puis refaire comme en 2/ mais sélectionne l'option 2 et appuyer sur entrée pour commencer la désinfection. lorsque le programme demande si tu veut nettoyer le registre mets oui en tapant 0 et entrée

                            ------------------------

                            AVG antispyware

                            https://www.01net.com/telecharger/

                            Tuto :
                            http://www.kachouri.com/tuto/tuto-161-avg-anti-spyware-75-pour-votre-securite.html

                            ->Relance AVG AS -> "Analyse" ->"Paramètres"

                            Sous la question "Comment réagir ?" :

                            -> clique sur "Actions recommandées" et choisis "Quarantaines"
                            -> Re-clique sur l'onglet "Analyse" puis réalise une "Analyse complète du système"

                            Si un fichier est infecté en fin d'analyse

                            ->Clique sur "Appliquer toutes les actions "

                            ->Clique sur "Enregistrer le rapport" puis sur "Enregistrer le rapport sous".

                            ->Enregistre ce fichier texte sur ton bureau ensuite colle le rapport ici
                            ____________________

                            Colle le rapport :
                            Clean permettra de faire du nettoyage et supprimer des fichiers que des anti-virus et anti-spywares n'ont pas pu trouver. Le logiciel est régulièrement mis à jour, vous devrez donc le re-téléchargé pour obtenir une version plus récente.

                            · Téléchargez clean.zip, décompressez-le sur votre bureau (clic droit / extraire tout), vous obtenez alors un dossier clean
                            · Démarrez Windows en mode sans échec : Guide pour redémarrer en mode sans échec
                            · Ouvrez le dossier clean qui se trouve sur ton bureau, et double-cliquez sur clean.cmd, une fenêtre noire va apparaître pendant un instant, laissez la ouverte jusqu'à ce qu'elle se ferme.

                            http://kerio.probb.fr/tuto-Clean-h37.html

                            ___________________

                            colle le rapport d'un scan en ligne
                            avec un des suivants:

                            bitdefender en ligne :
                            http://www.bitdefender.fr/scan_fr/scan8/ie.html

                            scan en ligne firefox

                            https://www.trendmicro.com/fr_fr/business.html

                            Panda en ligne :
                            http://pandasoftware.fr
                            0