re
la machine est infectée
ceci maintenant
Cliques sur le bouton nettoyage
tu vas obtenir une fenetre zhpfix
Sélectionne et copies le script suivant
Script ZHPFix
EmptyCLSID
EmptyFlash
Emptytemp
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Web Companion
[HKEY_USERS\S-1-5-21-3692580226-1636110599-2184855697-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run]:Web Companion
HKU\S-1-5-21-3692580226-1636110599-2184855697-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
HKCU\Software\Lavasoft\Web Companion
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
HKLM\SOFTWARE\Wow6432Node\Lavasoft\Web Companion
HKLM\SOFTWARE\Wow6432Node\C:
HKLM\SOFTWARE\Lavasoft\Web Companion
HKCU\SOFTWARE\7d96caee-06e6-597c-9f2f-c7bb2e0948b4
HKU\S-1-5-21-3692580226-1636110599-2184855697-1001\SOFTWARE\7d96caee-06e6-597c-9f2f-c7bb2e0948b4
C:\Program Files (x86)\Remote Mouse
O4 - HKLM\..\Run: [WindowsDefender] . (. - .) -- C:\Program Files\Windows Defender\MSASCuiL.exe (.Not File.)
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:Spotify
[HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:com.squirrel.Teams.Teams
[HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]:TeamsMachineInstaller
[HKUS\S-1-5-21-3692580226-1636110599-2184855697-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:Spotify
[HKUS\S-1-5-21-3692580226-1636110599-2184855697-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]:com.squirrel.Teams.Teams
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\WinRAR32
HKLM\Software\Classes\CLSID\{B41DB860-8EE4-11D2-9906-E49FADC173CA}
COlle le script bouton1
Lance le nettoyage bouton2
puis tu genères le script
heberge moi le rapport sur cjoint
@+