Security toolbar 7.1 [help]

Résolu
Bonsoir à tous!

vu que je trouve plus mon post, je le re-fait!

alors voila, après avoir prété mon ordi, je me retrouve avec cette fameuse "security toolbar 7.1" dont je n'arrive pas a me défaire. J'ai utilisé CCleaner et essayer avec Regcleaner (mais il n'a rien trouvé). Rien n'a marché..

j'ai un peu regardé sur le forum, mais il semble qu'il faille une aide personalisé, et faire plusieurs scan.

donc je demande de l'aide a tous!!

merci d'avance,
cordialement,
Gi67
Configuration: Windows XP
Internet Explorer 7.0

14 réponses

  1. Contributeur
    salut,

    Clique sur ce lien :
    http://perso.orange.fr/il.mafioso/Navifix/Navilog1.exe
    pour télécharger navilog1.exe.

    Choisis Enregistrer

    et enregistre-le sur ton bureau.

    Ensuite double clique sur navilog1.exe pour lancer l'installation.
    Une fois l'installation terminée, le fix s'exécutera automatiquement.
    (Si ce n'est pas le cas, double-clique sur le raccourci Navilog1 présent sur le bureau).

    Laisse-toi guider. Au menu principal, choisis 1 et valides.
    (ne fais pas le choix 2,3 ou 4 sans notre avis/accord)

    Patiente jusqu'au message :
    *** Analyse Termine le ..... ***
    Appuie sur une touche comme demandé, le blocnote va s'ouvrir.
    Copie-colle l'intégralité du rapport dans ta réponse. Referme le blocnote.
    Le rapport est en outre sauvegardé à la racine du disque (fixnavi.txt)

    Télécharge BTFix de Bibi26
    http://cluster1.easy-hebergement.net/ de Bibi26
    Dézippe l'archive sur ton Bureau.
    Ouvre le dossier BTFix.
    Double clique sur BTFix.exe.
    Clique sur Rechercher.
    Un rapport va apparaître, copie/colle-le dans ta prochaine réponse.
    0
    1. bonsoir!

      deja merci de ton aide! petite précision, en lancant recherche dans BTFix.exe, un message de signalisation me dit qu'il faut avoir une version la plus récente.. petite précison pour toi au cas ou! ;)

      voilà le rapport :

      BTFix 1.070 (par bibi26) - 16/01/2008 21:50:40 - Analyse
      Lancé depuis C:\Documents and Settings\Frenchie\Bureau\BTFix\BTFix.exe

      ---> Fichiers/Dossiers trouvés

      ---> Analyse terminée

      merci beaucoup!
      cordialement!
      0
      1. personne pour m'aider s'il vous plait?
        0
        1. est ce que je doit poster quelque chose d'autre pour avoir une aide supplémentaire?
          s'il vous plait aidez-moi!
          0
          1. Contributeur
            poste le rapport de navifix.
            0
            1. Search Navipromo version 3.4.0 commencé le 16/01/2008 à 21:43:28,35

              !!! Attention,ce rapport peut indiquer des fichiers/programmes légitimes!!!
              !!! Postez ce rapport sur le forum pour le faire analyser !!!
              !!! Ne lancez pas la partie désinfection sans l'avis d'un spécialiste !!!

              Outil exécuté depuis C:\Program Files\navilog1
              Mise à jour le 09.01.2008 à 20h00 par IL-MAFIOSO

              Microsoft Windows XP [version 5.1.2600]
              Internet Explorer : 7.0.5730.11
              Système de fichiers : NTFS

              Executé en mode normal

              *** Recherche Programmes installés ***

              *** Recherche dossiers dans C:\WINDOWS ***

              *** Recherche dossiers dans C:\Program Files ***

              *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\APPLIC~1 ***

              *** Recherche dossiers dans "C:\Documents and Settings\Frenchie\application data" ***

              *** Recherche dossiers dans "C:\Documents and Settings\Frenchie\MENUDM~1\PROGRA~1" ***

              *** Recherche dossiers dans C:\DOCUME~1\ALLUSE~1\MENUDM~1\PROGRA~1 ***

              *** Recherche avec Catchme-rootkit/stealth malware detector par gmer ***
              pour + d'infos : http://www.gmer.net

              Aucun Fichier trouvé

              *** Recherche avec GenericNaviSearch ***
              !!! Tous ces résultats peuvent révéler des fichiers légitimes !!!
              !!! A vérifier impérativement avant toute suppression manuelle !!!

              * Recherche dans C:\WINDOWS\system32 *

              * Recherche dans "C:\Documents and Settings\Frenchie\local settings\application data" *

              *** Recherche fichiers ***

              *** Recherche clés spécifiques dans le Registre ***

              *** Module de Recherche complémentaire ***
              (Recherche fichiers spécifiques)

              1)Recherche nouveaux fichiers Instant Access :

              2)Recherche Heuristique :

              * Dans C:\WINDOWS\system32 :

              * Dans "C:\Documents and Settings\Frenchie\local settings\application data" :

              3)Recherche Certificats :

              Certificat Egroup absent !

              4)Recherche fichiers connus :

              *** Analyse terminée le 16/01/2008 à 21:50:01,54 ***
              0
              1. Contributeur
                Ouvre ce lien (merci a S!RI pour ce programme). http://siri.urz.free.fr/Fix/SmitfraudFix.php
                et télécharge SmitfraudFix.exe.

                Regarde le tuto
                Exécute le en choisissant l’option 1, il va générer un rapport
                Copie/colle le sur le poste stp.
                0
                1. SmitFraudFix v2.274

                  Rapport fait à 21:49:41,45, 20/01/2008
                  Executé à partir de D:\Frenchie\Mes documents\t‚l‚chargement\SmitfraudFix
                  OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                  Le type du système de fichiers est NTFS
                  Fix executé en mode normal

                  »»»»»»»»»»»»»»»»»»»»»»»» Process

                  C:\WINDOWS\System32\smss.exe
                  C:\WINDOWS\system32\winlogon.exe
                  C:\WINDOWS\system32\services.exe
                  C:\WINDOWS\system32\lsass.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\WINDOWS\System32\svchost.exe
                  C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
                  C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
                  C:\WINDOWS\Explorer.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
                  C:\WINDOWS\system32\spoolsv.exe
                  C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                  C:\WINDOWS\system32\drivers\CDAC11BA.EXE
                  C:\Program Files\Symantec AntiVirus\DefWatch.exe
                  C:\WINDOWS\eHome\ehRecvr.exe
                  C:\WINDOWS\eHome\ehSched.exe
                  C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
                  C:\Program Files\Microsoft SQL Server\MSSQL$VAIO_VEDB\Binn\sqlservr.exe
                  C:\WINDOWS\system32\nvsvc32.exe
                  C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
                  C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
                  C:\WINDOWS\system32\svchost.exe
                  C:\Program Files\Symantec AntiVirus\Rtvscan.exe
                  C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
                  C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
                  C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
                  C:\Program Files\Fichiers communs\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
                  C:\WINDOWS\system32\dllhost.exe
                  C:\Program Files\Online Add-on\isfmntr.exe
                  C:\Program Files\Apoint\Apoint.exe
                  C:\WINDOWS\ehome\ehtray.exe
                  C:\WINDOWS\system32\ICO.EXE
                  C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
                  C:\Program Files\Sony\ISB Utility\ISBMgr.exe
                  C:\Program Files\Apoint\Apntex.exe
                  C:\WINDOWS\eHome\ehmsas.exe
                  C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe
                  C:\Program Files\Sony\VAIO Update 2\VAIOUpdt.exe
                  C:\Program Files\Utimaco\SafeGuard PrivateDisk\pdservice.exe
                  C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
                  C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
                  C:\Program Files\Fichiers communs\AOL\1154038782\ee\AOLSoftware.exe
                  C:\Program Files\Fichiers communs\Logitech\QCDriver3\LVCOMS.EXE
                  C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
                  C:\PROGRA~1\SYMANT~1\VPTray.exe
                  C:\Program Files\Elaborate Bytes\CloneCD\CloneCDTray.exe
                  C:\WINDOWS\system32\WDBtnMgr.exe
                  C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
                  C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe
                  C:\Program Files\QuickTime\QTTask.exe
                  C:\Program Files\iTunes\iTunesHelper.exe
                  C:\WINDOWS\system32\ctfmon.exe
                  C:\Program Files\Skype\Phone\Skype.exe
                  C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
                  C:\Program Files\DAEMON Tools\daemon.exe
                  C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
                  C:\PROGRA~1\MI3AA1~1\wcescomm.exe
                  C:\Program Files\Hercules\Audio\Gamesurround Muse Pocket\MuseCPL.exe
                  C:\PROGRA~1\MI3AA1~1\rapimgr.exe
                  C:\Program Files\My Book\WD Backup\uBBMonitor.exe
                  C:\Program Files\iPod\bin\iPodService.exe
                  C:\Program Files\Skype\Plugin Manager\skypePM.exe
                  C:\Program Files\Windows Live\Messenger\usnsvc.exe
                  C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\distnoted.exe
                  C:\Program Files\Internet Explorer\IEXPLORE.EXE
                  C:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WLLoginProxy.exe
                  C:\WINDOWS\system32\cmd.exe

                  »»»»»»»»»»»»»»»»»»»»»»»» hosts

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Frenchie

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Frenchie\Application Data

                  »»»»»»»»»»»»»»»»»»»»»»»» Menu Démarrer

                  C:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url PRESENT !
                  C:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url PRESENT !

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Frenchie\Favoris

                  C:\DOCUME~1\Frenchie\Favoris\Online Security Test.url PRESENT !

                  »»»»»»»»»»»»»»»»»»»»»»»» Bureau

                  »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

                  C:\Program Files\Online Add-on\ PRESENT !
                  C:\Program Files\VirusProtect 3.9\ PRESENT !

                  »»»»»»»»»»»»»»»»»»»»»»»» Clés corrompues

                  »»»»»»»»»»»»»»»»»»»»»»»» Eléments du bureau

                  [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
                  "Source"="About:Home"
                  "SubscribedURL"="About:Home"
                  "FriendlyName"="Ma page d'accueil"

                  »»»»»»»»»»»»»»»»»»»»»»»» IEDFix
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  IEDFix.exe by S!Ri

                  »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  SrchSTS.exe by S!Ri
                  Search SharedTaskScheduler's .dll

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                  "{91316323-2ad5-4794-9589-52a2eaa60a68}"="aposiopetic"

                  [HKEY_CLASSES_ROOT\CLSID\{91316323-2ad5-4794-9589-52a2eaa60a68}\InProcServer32]
                  @="C:\WINDOWS\system32\shlahsd.dll"

                  [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{91316323-2ad5-4794-9589-52a2eaa60a68}\InProcServer32]
                  @="C:\WINDOWS\system32\shlahsd.dll"

                  »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
                  "AppInit_DLLs"=""

                  »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                  !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                  [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                  "System"=""

                  »»»»»»»»»»»»»»»»»»»»»»»» Rustock

                  »»»»»»»»»»»»»»»»»»»»»»»» DNS

                  Description: Intel(R) PRO/Wireless 3945ABG Network Connection - Miniport d'ordonnancement de paquets
                  DNS Server Search Order: 192.168.1.1
                  DNS Server Search Order: 0.0.0.0

                  HKLM\SYSTEM\CCS\Services\Tcpip\..\{3884CDA3-9BB8-4F92-B172-22D77AD70637}: DhcpNameServer=192.168.1.1 0.0.0.0
                  HKLM\SYSTEM\CS1\Services\Tcpip\..\{3884CDA3-9BB8-4F92-B172-22D77AD70637}: DhcpNameServer=192.168.1.1 0.0.0.0
                  HKLM\SYSTEM\CS2\Services\Tcpip\..\{3884CDA3-9BB8-4F92-B172-22D77AD70637}: DhcpNameServer=192.168.1.1 0.0.0.0
                  HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                  HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                  HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

                  »»»»»»»»»»»»»»»»»»»»»»»» Recherche infection wininet.dll

                  »»»»»»»»»»»»»»»»»»»»»»»» Fin

                  merci pour ton aide ;)
                  0
                  1. Contributeur
                    Démarre en mode sans échec :
                    Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
                    Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                    Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                    (Si F8 ne marche pas utilise la touche F5).
                    ----------------------------------------------------------------------------
                    Relance le programme Smitfraud,
                    Cette fois choisit l’option 2, répond oui a tous ;
                    Sauvegarde le rapport, Redémarre en mode normal, copie/colle le rapport sauvegardé sur le forum
                    0
                    1. voilà le rapport! deja miracle j'ai plus aucun problème apparant! mais bon de préférence, :

                      SmitFraudFix v2.274

                      Rapport fait à 22:01:13,64, 20/01/2008
                      Executé à partir de D:\Frenchie\Mes documents\t‚l‚chargement\SmitfraudFix
                      OS: Microsoft Windows XP [version 5.1.2600] - Windows_NT
                      Le type du système de fichiers est NTFS
                      Fix executé en mode sans echec

                      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Avant SmitFraudFix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
                      "{91316323-2ad5-4794-9589-52a2eaa60a68}"="aposiopetic"

                      [HKEY_CLASSES_ROOT\CLSID\{91316323-2ad5-4794-9589-52a2eaa60a68}\InProcServer32]
                      @="C:\WINDOWS\system32\shlahsd.dll"

                      [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{91316323-2ad5-4794-9589-52a2eaa60a68}\InProcServer32]
                      @="C:\WINDOWS\system32\shlahsd.dll"

                      »»»»»»»»»»»»»»»»»»»»»»»» Arret des processus

                      »»»»»»»»»»»»»»»»»»»»»»»» hosts

                      127.0.0.1 localhost
                      127.0.0.1 bin.errorprotector.com ## added by CiD
                      127.0.0.1 br.errorsafe.com ## added by CiD
                      127.0.0.1 br.winantivirus.com ## added by CiD
                      127.0.0.1 br.winfixer.com ## added by CiD
                      127.0.0.1 cdn.drivecleaner.com ## added by CiD
                      127.0.0.1 cdn.errorsafe.com ## added by CiD
                      127.0.0.1 cdn.winsoftware.com ## added by CiD
                      127.0.0.1 de.errorsafe.com ## added by CiD
                      127.0.0.1 de.winantivirus.com ## added by CiD
                      127.0.0.1 download.cdn.drivecleaner.com ## added by CiD
                      127.0.0.1 download.cdn.errorsafe.com ## added by CiD
                      127.0.0.1 download.cdn.winsoftware.com ## added by CiD
                      127.0.0.1 download.errorsafe.com ## added by CiD
                      127.0.0.1 download.systemdoctor.com ## added by CiD
                      127.0.0.1 download.winantispyware.com ## added by CiD
                      127.0.0.1 download.windrivecleaner.com ## added by CiD
                      127.0.0.1 download.winfixer.com ## added by CiD
                      127.0.0.1 drivecleaner.com ## added by CiD
                      127.0.0.1 dynamique.drivecleaner.com ## added by CiD
                      127.0.0.1 errorprotector.com ## added by CiD
                      127.0.0.1 errorsafe.com ## added by CiD
                      127.0.0.1 es.winantivirus.com ## added by CiD
                      127.0.0.1 fr.winantivirus.com ## added by CiD
                      127.0.0.1 fr.winfixer.com ## added by CiD
                      127.0.0.1 go.drivecleaner.com ## added by CiD
                      127.0.0.1 go.errorsafe.com ## added by CiD
                      127.0.0.1 go.winantispyware.com ## added by CiD
                      127.0.0.1 go.winantivirus.com ## added by CiD
                      127.0.0.1 hk.winantivirus.com ## added by CiD
                      127.0.0.1 instlog.errorsafe.com ## added by CiD
                      127.0.0.1 instlog.winantivirus.com ## added by CiD
                      127.0.0.1 instlog.winfixer.com ## added by CiD
                      127.0.0.1 jsp.drivecleaner.com ## added by CiD
                      127.0.0.1 kb.errorsafe.com ## added by CiD
                      127.0.0.1 kb.winantivirus.com ## added by CiD
                      127.0.0.1 nl.errorsafe.com ## added by CiD
                      127.0.0.1 se.errorsafe.com ## added by CiD
                      127.0.0.1 secure.drivecleaner.com ## added by CiD
                      127.0.0.1 secure.errorsafe.com ## added by CiD
                      127.0.0.1 secure.winantispam.com ## added by CiD
                      127.0.0.1 secure.winantispy.com ## added by CiD
                      127.0.0.1 secure.winantivirus.com ## added by CiD
                      127.0.0.1 support.winantivirus.com ## added by CiD
                      127.0.0.1 trial.updates.winsoftware.com ## added by CiD
                      127.0.0.1 ulog.winantivirus.com ## added by CiD
                      127.0.0.1 utils.errorsafe.com ## added by CiD
                      127.0.0.1 utils.winantivirus.com ## added by CiD
                      127.0.0.1 utils.winfixer.com ## added by CiD
                      127.0.0.1 winantispyware.com ## added by CiD
                      127.0.0.1 winantivirus.com ## added by CiD
                      127.0.0.1 winfixer.com ## added by CiD
                      127.0.0.1 winfixer2006.com ## added by CiD
                      127.0.0.1 winsoftware.com ## added by CiD
                      127.0.0.1 www.drivecleaner.com ## added by CiD
                      127.0.0.1 www.errorprotector.com ## added by CiD
                      127.0.0.1 www.errorsafe.com ## added by CiD
                      127.0.0.1 www.systemdoctor.com ## added by CiD
                      127.0.0.1 www.utils.winfixer.com ## added by CiD
                      127.0.0.1 www.win-anti-virus-pro.com ## added by CiD
                      127.0.0.1 www.win-virus-pro.com ## added by CiD
                      127.0.0.1 www.winantispam.com ## added by CiD
                      127.0.0.1 www.winantispy.com ## added by CiD
                      127.0.0.1 www.winantispyware.com ## added by CiD
                      127.0.0.1 www.winantivirus.com ## added by CiD
                      127.0.0.1 www.winantiviruspro.com ## added by CiD
                      127.0.0.1 www.windrivecleaner.com ## added by CiD
                      127.0.0.1 www.windrivesafe.com ## added by CiD
                      127.0.0.1 www.winfixer.com ## added by CiD
                      127.0.0.1 www.winfixer2006.com ## added by CiD
                      127.0.0.1 www.winsoftware.com ## added by CiD

                      »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

                      S!Ri's WS2Fix: LSP not Found.
                      »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

                      GenericRenosFix by S!Ri

                      C:\WINDOWS\system32\shlahsd.dll -> Hoax.Win32.Renos.gen.o
                      C:\WINDOWS\system32\shlahsd.dll -> Deleted

                      »»»»»»»»»»»»»»»»»»»»»»»» Suppression des fichiers infectés

                      C:\DOCUME~1\ALLUSE~1\MENUDM~1\Online Security Guide.url supprimé
                      C:\DOCUME~1\ALLUSE~1\MENUDM~1\Security Troubleshooting.url supprimé
                      C:\DOCUME~1\Frenchie\Favoris\Online Security Test.url supprimé
                      C:\Program Files\Online Add-on\ supprimé
                      C:\Program Files\VirusProtect 3.9\ supprimé

                      »»»»»»»»»»»»»»»»»»»»»»»» IEDFix

                      IEDFix.exe by S!Ri

                      »»»»»»»»»»»»»»»»»»»»»»»» DNS

                      HKLM\SYSTEM\CCS\Services\Tcpip\..\{3884CDA3-9BB8-4F92-B172-22D77AD70637}: DhcpNameServer=192.168.1.1 0.0.0.0
                      HKLM\SYSTEM\CS1\Services\Tcpip\..\{3884CDA3-9BB8-4F92-B172-22D77AD70637}: DhcpNameServer=192.168.1.1 0.0.0.0
                      HKLM\SYSTEM\CS2\Services\Tcpip\..\{3884CDA3-9BB8-4F92-B172-22D77AD70637}: DhcpNameServer=192.168.1.1 0.0.0.0
                      HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                      HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0
                      HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 0.0.0.0

                      »»»»»»»»»»»»»»»»»»»»»»»» Suppression Fichiers Temporaires

                      »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
                      "System"=""

                      »»»»»»»»»»»»»»»»»»»»»»»» Nettoyage du registre

                      Nettoyage terminé.

                      »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Après SmitFraudFix
                      !!!Attention, les clés qui suivent ne sont pas forcément infectées!!!

                      SrchSTS.exe by S!Ri
                      Search SharedTaskScheduler's .dll

                      »»»»»»»»»»»»»»»»»»»»»»»» Fin
                      0
                      1. Contributeur
                        Télécharge « clean.zip »
                        http://www.malekal.com/download/clean.zip
                        •- Décompresse-le sur ton bureau (clic droit / extraire tout), tu dois obtenir un dossier dénommé "clean ".

                        •- Ouvre le dossier « clean » qui se trouve sur ton bureau.
                        •- Double-clic sur « clean.cmd ».
                        Une fenêtre noire va apparaître, choisis l’option 1.

                        Clean va travailler.

                        •- Redémarre normalement
                        •- Poste qui se trouve ici C:\rapport_clean.txt.
                        0
                        1. 22/01/2008 a 19:11:30,65

                          *** Recherche des fichiers dans C:

                          *** Recherche des fichiers dans C:\WINDOWS\

                          *** Recherche des fichiers dans C:\WINDOWS\system32
                          0