PB ANTIVIRXP08 NE VEUT PAS S'ENLEVER !!!!

Résolu
Bonjour,
Suite à une pub de ce soit-disant antirus gratuit, j'ai executé le fichier et ensuite me suis apercu que ce n'est pas un anti-virus gratuit...pire, je n'arrive pas à le suppimer de mon pc !!!

A L'AIDE !!!!.........merci
Configuration: Windows XP
Firefox 3.0.1

6 réponses

  1. bonjour, ne jamais télécharger sans avoir pris des renseignements, mais ne panique pas les spéciallistes vont bientot se réveiller, lendemain de week-end !
    -1
    1. bonjour,
      C'est vrai je le fais pourtant jamais mais j'avoue qu'etant donné que je n'ai pas d'antivirus et que je pense etre infecté, je me suis laissé tenté et...je regrette !!
      Oui je vais attendre cet apres-mid peut-etre !!
      Merci à toi et bonne journée
      -1
      1. Contributeur sécurité
        Bonjour,

        Merci de suivre la procédure suivante pour générer un rapport hijackthis qui me permettra de diagnostiquer le problème de ton ordinateur :

        Télécharge hijackthis sur ton bureau : https://www.commentcamarche.net/telecharger/securite/11747-hijackthis/

        Installe le, puis fais ceci avant de le lancer :
        Va dans le menu démarrer --> Poste de travail --> disque local C --> Program Files --> Trend Micro --> Hijackthis --> cherche hijackthis.exe et fais un clic droit dessus --> renomme le en Jack.exe

        Ensuite lance le et clique sur "Do a system scan and save a logfile".
        Fais un copier-coller du rapport entier sur le forum

        -1
        1. g aussi reçut ce virus et je n'arrive pas a m'en débarassé dc voila mon diagnostic :

          Logfile of Trend Micro HijackThis v2.0.2
          Scan saved at 17:34:57, on 24/09/2008
          Platform: Windows XP SP2 (WinNT 5.01.2600)
          MSIE: Internet Explorer v7.00 (7.00.6000.16640)
          Boot mode: Normal

          Running processes:
          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\system32\WgaTray.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
          C:\Program Files\Micro Application\Cloneur Expert\TrueImageMonitor.exe
          C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
          C:\WINDOWS\system32\taskswitch.exe
          C:\WINDOWS\system32\fast.exe
          C:\WINDOWS\system32\VTtrayp.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
          C:\WINDOWS\RavMonE.exe
          C:\Program Files\Lexmark 4300 Series\lxcemon.exe
          C:\Program Files\Lexmark 4300 Series\ezprint.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\system32\lphcjjoj0e741.exe
          C:\Program Files\rhcnjoj0e741\rhcnjoj0e741.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
          C:\WINDOWS\system32\drivers\svchost.exe
          C:\WINDOWS\system32\pphcjjoj0e741.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\system32\lxcecoms.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
          C:\WINDOWS\system32\0bc3oCwF.exe
          C:\Program Files\Internet Explorer\iexplore.exe
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\Trend Micro\HijackThis\Jack.exe

          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.fr/toolbar/ie8/sidebar.html
          R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.google.fr/?gws_rd=ssl
          R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
          R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr/?ocid=iehp
          R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://www.google.fr/keyword/%s
          R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://runonce.msn.com/runonce3.aspx
          R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Liens
          O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Fichiers communs\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
          O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
          O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
          O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
          O2 - BHO: solution Class - {99C6D1BB-7555-474C-91DA-D8FB62A9CC75} - C:\WINDOWS\system32\4E0AVhtI.dll
          O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
          O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
          O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
          O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
          O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
          O4 - HKLM\..\Run: [RemoteControl] C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
          O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
          O4 - HKLM\..\Run: [Cloneur Expert Monitor] "C:\Program Files\Micro Application\Cloneur Expert\TrueImageMonitor.exe"
          O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe"
          O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
          O4 - HKLM\..\Run: [BackgroundSwitcher] C:\WINDOWS\system32\bgswitch.exe
          O4 - HKLM\..\Run: [FastUser] C:\WINDOWS\system32\fast.exe
          O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
          O4 - HKLM\..\Run: [VTTrayp] VTtrayp.exe
          O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
          O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
          O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
          O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
          O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\K-Lite Codec Pack\Real\Update_OB\realsched.exe" -osboot
          O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
          O4 - HKLM\..\Run: [RavAV] C:\WINDOWS\RavMonE.exe
          O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          O4 - HKLM\..\Run: [LXCECATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.dll,_RunDLLEntry@16
          O4 - HKLM\..\Run: [lxcemon.exe] "C:\Program Files\Lexmark 4300 Series\lxcemon.exe"
          O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 4300 Series\ezprint.exe"
          O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
          O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
          O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
          O4 - HKLM\..\Run: [lphcjjoj0e741] C:\WINDOWS\system32\lphcjjoj0e741.exe
          O4 - HKLM\..\Run: [SMrhcnjoj0e741] C:\Program Files\rhcnjoj0e741\rhcnjoj0e741.exe
          O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
          O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
          O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe
          O4 - HKUS\S-1-5-19\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\RunOnce: [nlsf] cmd.exe /C move /Y "%SystemRoot%\System32\syssetub.dll" "%SystemRoot%\System32\syssetup.dll" (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'SERVICE LOCAL')
          O4 - HKUS\S-1-5-20\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SERVICE RÉSEAU')
          O4 - HKUS\S-1-5-18\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'SYSTEM')
          O4 - HKUS\S-1-5-18\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'SYSTEM')
          O4 - HKUS\.DEFAULT\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (User 'Default user')
          O4 - HKUS\.DEFAULT\..\RunOnce: [Config] %systemroot%\system32\run.cmd (User 'Default user')
          O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
          O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
          O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
          O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRA~1\Yahoo!\Common\yhexbmesfr.dll
          O9 - Extra button: Organise-notes - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
          O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Fichiers communs\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
          O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
          O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
          O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/FacebookPhotoUploader5.cab
          O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
          O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
          O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} (OnlineScanner Control) - https://www.eset.com/
          O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/...
          O16 - DPF: {7EED9A13-A696-46E3-8888-09CDE606B3D1} (CDownloader Object) - http://a69.g.akamai.net/...
          O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
          O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
          O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
          O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
          O23 - Service: Service de l'iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
          O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
          O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
          0
        2. je te remerci d'avant pour l'aide que tu vas me donner. bye
          0
      2. Contributeur sécurité
        Bonjour ANNA Z,

        Il y a en effet plusieurs infections sur ton ordinateurs, merci de rester jusqu'au bout de la désinfection.

        Télécharge SmitfraudFix : http://siri.urz.free.fr/Fix/SmitfraudFix.exe

        - Enregistre-le sur le bureau

        - Double-clique sur SmitfraudFix.exe et choisis l'option 1 puis Entrée

        - Un rapport sera généré, poste-le dans ta prochaine réponse stp.

        Tutoriel ici pour t'aider : http://www.malekal.com//tutorial_SmitFraudfix.php

        -1
        1. voila j'ai suivi tes indications, je te remercie énormément de nous aidé. J'attend avec impatience de tes nouvelles .

          SmitFraudFix v2.354

          Rapport fait à 23:58:38,85, 24/09/2008
          Executé à partir de C:\Documents and Settings\Z@Z@\Bureau\SmitfraudFix
          OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
          Le type du système de fichiers est NTFS
          Fix executé en mode normal

          »»»»»»»»»»»»»»»»»»»»»»»» Process

          C:\WINDOWS\System32\smss.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\services.exe
          C:\WINDOWS\system32\lsass.exe
          C:\WINDOWS\system32\svchost.exe
          C:\WINDOWS\System32\svchost.exe
          C:\WINDOWS\system32\spoolsv.exe
          C:\Program Files\Fichiers communs\Acronis\Schedule2\schedul2.exe
          C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
          C:\WINDOWS\system32\svchost.exe
          C:\Program Files\iPod\bin\iPodService.exe
          C:\WINDOWS\system32\lxcecoms.exe
          C:\WINDOWS\system32\winlogon.exe
          C:\WINDOWS\system32\WgaTray.exe
          C:\WINDOWS\Explorer.EXE
          C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
          C:\Program Files\Micro Application\Cloneur Expert\TrueImageMonitor.exe
          C:\Program Files\Fichiers communs\Acronis\Schedule2\schedhlp.exe
          C:\WINDOWS\system32\taskswitch.exe
          C:\WINDOWS\system32\fast.exe
          C:\WINDOWS\system32\VTtrayp.exe
          C:\WINDOWS\SOUNDMAN.EXE
          C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
          C:\WINDOWS\RavMonE.exe
          C:\Program Files\Lexmark 4300 Series\lxcemon.exe
          C:\Program Files\Lexmark 4300 Series\ezprint.exe
          C:\Program Files\iTunes\iTunesHelper.exe
          C:\WINDOWS\system32\lphcjjoj0e741.exe
          C:\Program Files\rhcnjoj0e741\rhcnjoj0e741.exe
          C:\WINDOWS\system32\ctfmon.exe
          C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
          C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
          C:\WINDOWS\system32\drivers\svchost.exe
          C:\WINDOWS\system32\pphcjjoj0e741.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Internet Explorer\IEXPLORE.EXE
          C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
          C:\Program Files\Java\jre1.6.0_02\bin\jucheck.exe
          C:\WINDOWS\system32\cmd.exe

          »»»»»»»»»»»»»»»»»»»»»»»» hosts

          »»»»»»»»»»»»»»»»»»»»»»»» C:\

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

          C:\WINDOWS\Tasks\At?.job PRESENT !
          C:\WINDOWS\Tasks\At??.job PRESENT !

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

          »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

          C:\WINDOWS\system32\tdssservers.dat détecté, utilisez un scanner de Rootkit
          C:\WINDOWS\system32\tdssinit.dll détecté, utilisez un scanner de Rootkit
          C:\WINDOWS\system32\tdssl.dll détecté, utilisez un scanner de Rootkit
          C:\WINDOWS\system32\drivers\svchost.exe PRESENT !

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Z@Z@

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Z@Z@\Application Data

          C:\Documents and Settings\Z@Z@\Application Data\Microsoft\Internet Explorer\Quick Launch\Antivirus XP 2008.lnk PRESENT !

          »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

          C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1\Antivirus XP 2008.lnk PRESENT !

          »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Z@Z@\Favoris

          »»»»»»»»»»»»»»»»»»»»»»»» Bureau

          C:\DOCUME~1\ALLUSE~1\Bureau\Antivirus XP 2008.lnk PRESENT !

          »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

          »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

          »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

          [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
          "Source"="About:Home"
          "SubscribedURL"="About:Home"
          "FriendlyName"="Ma page d'accueil"

          »»»»»»»»»»»»»»»»»»»»»»»» o4Patch
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          o4Patch
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          IEDFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» VACFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          VACFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» 404Fix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          404Fix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          »»»»»»»»»»»»»»»»»»»»»»»» AntiXPVSTFix
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          AntiXPVSTFix
          Credits: Malware Analysis & Diagnostic
          Code: S!Ri

          [!] Rogue.Win32.AntivirusXP2008.c
          O4 - HKLM\..\Run: [SMrhcnjoj0e741] C:\Program Files\rhcnjoj0e741\rhcnjoj0e741.exe (Running)

          »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          SrchSTS.exe by S!Ri
          Search SharedTaskScheduler's .dll

          »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
          "AppInit_DLLs"=""

          »»»»»»»»»»»»»»»»»»»»»»»» Winlogon
          !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
          "Userinit"="C:\\WINDOWS\\system32\\userinit.exe,"
          "System"=""

          »»»»»»»»»»»»»»»»»»»»»»»» RK

          »»»»»»»»»»»»»»»»»»»»»»»» DNS

          Description: Carte réseau Fast Ethernet PCI Realtek RTL8139 Family #2 - Miniport d'ordonnancement de paquets
          DNS Server Search Order: 192.168.1.254

          HKLM\SYSTEM\CCS\Services\Tcpip\..\{F9F12BC8-1295-4DA7-9A37-23A79545A6FB}: DhcpNameServer=192.168.1.254
          HKLM\SYSTEM\CS1\Services\Tcpip\..\{F9F12BC8-1295-4DA7-9A37-23A79545A6FB}: DhcpNameServer=192.168.1.254
          HKLM\SYSTEM\CS2\Services\Tcpip\..\{F9F12BC8-1295-4DA7-9A37-23A79545A6FB}: DhcpNameServer=192.168.1.254
          HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
          HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254
          HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.254

          »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

          »»»»»»»»»»»»»»»»»»»»»»»» Fin
          0
          1. Contributeur sécurité
            1) Maintenant, démarre en mode sans échec :
            Pour cela, tu tapotes sur la touche F8 (F5 sur certains pc) dès le début de l’allumage du PC sans t’arrêter, avant l'apparition du logo Windows. Un menu va apparaitre, déplace-toi avec les flèches du clavier sur Démarrer en mode sans échec puis tape Entrée. Choisis ta session habituelle, et ne t'inquiète pas si les couleurs et la taille des icônes changent, c'est normal !

            Relance le programme SmitfraudFix.
            Cette fois, choisis l’option 2, répond oui à tous;
            A la fin, sauvegarde le rapport, redémarre en mode normal, copie-colle le rapport sauvegardé sur le forum.

            2) Ensuite, télécharge et installe Malwarebytes' Anti-Malware
            - A la fin de l'installation, veille à ce que l'option « mettre a jour Malwarebyte's Anti-Malware » soit cochée
            - Lance MBAM, laisse les Mises à jour se télécharger et referme le programme

            Redémarre en "Mode sans échec" une deuxième fois.

            Lance MBAM
            - Puis va dans l'onglet "Recherche", coche "Exécuter un examen complet" puis "Rechercher"
            - Sélectionne tes disques durs" puis clique sur "Lancer l’examen"
            - A la fin du scan, clique sur Afficher les résultats puis sur Enregistrer le rapport
            - Suppression des éléments détectés --> clique sur Supprimer la sélection
            - S'il t'es demandé de redémarrer, clique sur Yes

            Poste le rapport de scan après la suppression ici

            -1