Bonjour,
j'ai chopé le virus "winupgro", apres avoir lu vos reponses aux messages precedents, j'ai telecharger findykill, et voici le rapport de l'analyse n°1
----------------- FindyKill V4.711 ------------------
* User : SYSTEM - TONYETLILIE
* Emplacement : C:\Program Files\FindyKill
* Outils Mis a jours le 05/01/09 par Chiquitine29
* Recherche effectuée à 19:38:57 le 09/01/2009
* Windows Vista - Internet Explorer 7.0.6000.16764
((((((((((((((((( *** Recherche *** ))))))))))))))))))
--------------- [ Processus actifs ] ----------------
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\Explorer.EXE
--------------- [ Fichiers/Dossiers infectieux ] ----------------
»»»» Presence des fichiers dans C:
»»»» Presence des fichiers dans C:\Windows
»»»» Presence des fichiers dans C:\Windows\Prefetch
Found ! - C:\Windows\prefetch\60538203.EXE-E976ACEA.pf
Found ! - C:\Windows\prefetch\60659359.EXE-51330642.pf
Found ! - C:\Windows\prefetch\60665265.EXE-6524FD67.pf
Found ! - C:\Windows\prefetch\60937609.EXE-52EDB8E3.pf
Found ! - C:\Windows\prefetch\68009343.EXE-CA13A268.pf
Found ! - C:\Windows\prefetch\68124343.EXE-39B4E8AE.pf
Found ! - C:\Windows\prefetch\68346875.EXE-55DF5556.pf
Found ! - C:\Windows\prefetch\68377984.EXE-85DC485F.pf
Found ! - C:\Windows\prefetch\73750953.EXE-D231CFB6.pf
Found ! - C:\Windows\prefetch\73866437.EXE-A0F31357.pf
Found ! - C:\Windows\prefetch\73888171.EXE-9BD80232.pf
Found ! - C:\Windows\prefetch\74112906.EXE-FAE3FE41.pf
Found ! - C:\Windows\prefetch\FLEC006.EXE-585C97BD.pf
Found ! - C:\Windows\prefetch\MDELK.EXE-DC6EBAD6.pf
Found ! - C:\Windows\prefetch\WINTEMS.EXE-72D52E08.pf
Found ! - C:\Windows\prefetch\WINUPGRO.EXE-07A02A76.pf
»»»» Presence des fichiers dans C:\Windows\system32
Found ! [09/01/2009 18:49] - C:\Windows\system32\ban_list.txt
»»»» Presence des fichiers dans C:\Windows\system32\drivers
»»»» Presence des fichiers dans
»»»» Presence des fichiers dans C:\Windows\system32\config\systemprofile\AppData\Local\Temp
»»»» Presence des fichiers dans C:\Windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5
Found ! [06/11/2008 16:33] - C:\Program Files\Rockstar Games\Grand Theft Auto IV\files.txt
--------------- [ Registre / Startup ] ----------------
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
Windows Defender=%ProgramFiles%\Windows Defender\MSASCui.exe -hide
SoundMan=SOUNDMAN.EXE
LogitechQuickCamRibbon="C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
LogitechCommunicationsManager="C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
nod32kui="C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
Adobe Photo Downloader="C:\Program Files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe"
SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
NvCplDaemon=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
NvMediaCenter=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
ISTray="C:\Program Files\Spyware Doctor\pctsTray.exe"
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
NoChange=1
Installed=1
<NO NAME>=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1
<NO NAME>=
--------------- [ Registre / Clés infectieuses ] ----------------
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sK9Ou0s
/!\ Infection active : HKLM\SYSTEM\...\Services\srosa -> Start = 0x1
/!\ Infection active : HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1
--------------- [ Etat / Services ] ----------------
+- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]
/!\ Ndisuio - Type de démarrage = 4
EapHost - Type de démarrage = 3
Wlansvc - Type de démarrage = 3
/!\ SharedAccess - Type de démarrage = 4
/!\ wuauserv - Type de démarrage = 4
/!\ wscsvc - Type de démarrage = 4
/!\ WinDefend - Type de démarrage = 4
/!\ UAC is Disable
--------------- [ Recherche dans supports amovibles] ----------------
+- Informations :
C: - Lecteur fixe
D: - Lecteur fixe
E: - Lecteur fixe
+- presence des fichiers :
--------------- [ Registre / Mountpoint2 ] ----------------
-> Not found !
------------------- ! Fin du rapport ! --------------------
Merci d'avance pour vos reponses !

----------------- FindyKill V4.711 ------------------
* User : Tony et Lilie - TONYETLILIE
* executed from : C:\Program Files\FindyKill
* Update on 05/01/09 par Chiquitine29
* Start at 13:24:52 the 10/01/2009
* Windows Vista - Internet Explorer 7.0.6000.16764
((((((((((((((( *** deleting *** ))))))))))))))))))
--------------- [ Active Processes ] ----------------
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\userinit.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\runonce.exe
--------------- [ Infected files / folders ] ----------------
»»»» Supression files in C:
»»»» Supression files in C:\Windows
»»»» Supression files in C:\Windows\Prefetch
Deleted ! - C:\Windows\prefetch\60538203.EXE-E976ACEA.pf
Deleted ! - C:\Windows\prefetch\60659359.EXE-51330642.pf
Deleted ! - C:\Windows\prefetch\60665265.EXE-6524FD67.pf
Deleted ! - C:\Windows\prefetch\60937609.EXE-52EDB8E3.pf
Deleted ! - C:\Windows\prefetch\68009343.EXE-CA13A268.pf
Deleted ! - C:\Windows\prefetch\68124343.EXE-39B4E8AE.pf
Deleted ! - C:\Windows\prefetch\68346875.EXE-55DF5556.pf
Deleted ! - C:\Windows\prefetch\68377984.EXE-85DC485F.pf
Deleted ! - C:\Windows\prefetch\73750953.EXE-D231CFB6.pf
Deleted ! - C:\Windows\prefetch\73866437.EXE-A0F31357.pf
Deleted ! - C:\Windows\prefetch\73888171.EXE-9BD80232.pf
Deleted ! - C:\Windows\prefetch\74112906.EXE-FAE3FE41.pf
Deleted ! - C:\Windows\prefetch\FLEC006.EXE-585C97BD.pf
Deleted ! - C:\Windows\prefetch\MDELK.EXE-DC6EBAD6.pf
Deleted ! - C:\Windows\prefetch\WINTEMS.EXE-72D52E08.pf
Deleted ! - C:\Windows\prefetch\WINUPGRO.EXE-07A02A76.pf
»»»» Supression files in C:\Windows\system32
Deleted ! - C:\Windows\system32\mdelk.exe
Deleted ! - C:\Windows\system32\wintems.exe
Deleted ! - C:\Windows\system32\ban_list.txt
»»»» Supression files in C:\Windows\system32\drivers
»»»» Supression files in C:\Users\Tony et Lilie\AppData\Roaming
Deleted ! - "C:\Users\Tony et Lilie\AppData\Roaming\m\flec006.exe"
Deleted ! - "C:\Users\Tony et Lilie\AppData\Roaming\m\list.oct"
Deleted ! - "C:\Users\Tony et Lilie\AppData\Roaming\m\data.oct"
Deleted ! - "C:\Users\Tony et Lilie\AppData\Roaming\m\srvlist.oct"
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\3D Manatees in Rippling Waters 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\3DMasterKit 3.5.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\4Leaf WMV Video Converter 1.5.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\@PROMT Spanish-Russian Internet Translator 7.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Adusoft DVD Creator 2.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Afree FLV MP4 iPhone iPod AVI DIVX WMV Converter 5.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\AlbumEasy 2.2.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\ALIVE CLOCK 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Altair 1.0 Rev.16.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Americanassist 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\AntlerTek Photo Recovery 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\AppGini Freeware Version 3.3.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Auth 1.01.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Automatic DJ 1.10 beta.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Avast!.Antivirus.4.6.691.Professional.Edition.Crack.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Avast.Profesional.4.7.serial.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Avex Video Converter Platinum 4.06.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\B-Log 1.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Bet Arbitrage Calculator 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Binary Desktop Clock 1.4.2.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Bitdefender.Internet.Security.v10.-.FR.by.stitch_ALLTEAM.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\BlueCap Icons 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Camp Granada Font 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Caps Lock Changer 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Captain Podd.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\CDG 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\clarus the dogcow 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Class Reunion Almanac 2.7.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Construction Sigma Style.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Cournol 0.3.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Crack.para.la.SuscripciÇün.de.Norton.antivirus.&.internet.security.2002-2003.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\CT Mystified 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\CTC 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\CyberSky 4.0.3.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\DC AppProtector 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\DIZipWriter 2.3.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\DJBCP DVD Rip Pack 2.1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Dreamscape Analysis 2.2.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Drive Info Gadget 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Duplicate Cleaner 1.3.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\DVD to PSP Video Converter Suite 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Easy Album Manager 1.01.01.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\eConsumersearch Toolbar 4.5.171.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Email Director 9.2.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\ExtraMp3 Renamer 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\EZ Backup IE Basic 6.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\FaceMorpher Lite 2.5.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Fixed Width File Pro 3.0.13.2766.12.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\FreeSpamFilter Screensaver 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\GenoSwatch 2.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\GMail Extract e-mail addresses from G-Mail Account 1.0.0.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\GMSI.NET Instrumentation Library 1.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\GoodOK iPod Converter 6.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Hexbin interconverter 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Homeland Security Monitor 2.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\IBLMExport 1.2.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\ie7ReplaceTabTitle 1.1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Image Gallery Assistant 1.3b.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Jason DVD Video to MPEG Converter 5.00.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\JustBoot Password Cleaner 7.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\KeyDB 1.50.03.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Konst Pinger 1.31.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Konvertor xxx2pdf 1.07.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\LastChance 1.03.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Link Buzz 1.01.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Lyrics2Search toolbar 1.0.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\M8 Cell Pre-Filler Demo 1.00.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Manage PC Startup 1.00.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Mappa TomTom mobile Italia v6.75.1429 (maggio 2007) updated-fixed 05-2008.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\MIDI Workplace 2.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Misty Lakeside 3D 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Mnemo 4.3.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\More Space Sanitizer 5.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\mRNA 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\naBBit 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Navicat MySQL 8.0.28.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\NeonJax 3D 1.0.2.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Net Orbit 2.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\NOD32.FiX.v1.0-nsane.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\NOD32.FiX.v2.1-XLifes.ru.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\NoTrax 1.5.0.34.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Nubs 1.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\OLSR daemon 0.4.10.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\One Cat Viewer 4.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Outlook Tools 2.8.5.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Paradox to IBM DB2 Conversion Software 7.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\PatternPrint 17.4.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\PC-BugCleaner 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\PDF Create .NET 2.5.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Personal Organizer 1.0.1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Phantasm CS 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\PhotoKit Color 1.0.3.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Physics 101 SE 7.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Pingotron Pro 4.1.3.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Pivot4U 2.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\PM Eject 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\POV-Ray 3.7 Beta 29.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Power Article Rewriter 1.1.0.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\ReadPlease Plus 2003 1.10.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\rebuilt.Tomtom 6 wm6 + italia v6.507 by Windows Mobile 6 samsung omnia i900.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Request Slip Generator 1.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Secure Folder Hider 1.3.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Serial Device Test Utility 1.5.0.13.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Shark AVI Video Converter 6.8.1.6.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\SimpleDelicious 1.1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Singapore Next Bus Widget 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Smart Writings 1.0.19.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\SoftDisc 3.0.2.320.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Specifications Application 0.25.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Status Scroll 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Stitcher 3.5.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\SuperF4 0.9.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Symantec.Norton.Save.&.Restore.Installation.Key.Generator.Updated-Fixed.12-2006.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Sync 'Em! 2.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\The Book of Kells 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Time Flow Terminator 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Time Meter 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\ToDo Notes 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\TriggerChart 2.10.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\TubeMe 1.2.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Turbo File Uneraser 1.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\VersionLab 2.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Virtual Map StreetDirectory Gadget 1.0.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\VSO Burning SDK 2.1.12.353.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\WebESC 3.04.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\Willy's Htmlpad 2.09.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\XP Laptop Switcher 2.1.zip
Deleted ! - C:\Users\Tony et Lilie\AppData\Roaming\m\shared\[ITA].Avast!.Antivirus.4.6.691.Professional.Edition.+.Crack.zip
Deleted ! - "C:\Users\Tony et Lilie\AppData\Roaming\m\shared"
Deleted ! - "C:\Users\Tony et Lilie\AppData\Roaming\m"
Deleted ! - "C:\Users\Tony et Lilie\AppData\Roaming\drivers\srosa.sys"
Deleted ! - "C:\Users\Tony et Lilie\AppData\Roaming\drivers\srosa2.sys"
Deleted ! - "C:\Users\Tony et Lilie\AppData\Roaming\drivers\winupgro.exe"
Deleted ! - "C:\Users\Tony et Lilie\AppData\Roaming\drivers\downld"
Deleted ! - "C:\Users\Tony et Lilie\AppData\Roaming\drivers"
»»»» Supression files in C:\Users\TONYET~1\AppData\Local\Temp
je fais quoi maintenant ? car winupgro est resté actif ...
###################### [ FindyKill V4.714 ]
# User : Propri‚taire - CLAUDE
# Executed from : C:\Program Files\FindyKill
# Update on 19/01/09 by Chiquitine29
# Start at 16:13:20 the 23/01/2009
# Windows XP - Internet Explorer 7.0.5730.13
# [ FindyKill V4.714 - Deleting ] ###############
\\\\\\\\\\\\\\\\\\ [ Active Processes ] ///////////////////
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\userinit.exe
\\\\\\\\\\\\\\\\\\ [ Infected Files / Folders ] ///////////////////
################## [ C:\ ]
################## [ C:\WINDOWS ]
################## [ C:\WINDOWS\Prefetch ]
Deleted ! - C:\WINDOWS\prefetch\1152625.EXE-06DF90DE.pf
Deleted ! - C:\WINDOWS\prefetch\1282046.EXE-14B14A3F.pf
Deleted ! - C:\WINDOWS\prefetch\506828.EXE-02B074ED.pf
Deleted ! - C:\WINDOWS\prefetch\522093.EXE-2A5EE48C.pf
Deleted ! - C:\WINDOWS\prefetch\FLEC006.EXE-041A0D93.pf
Deleted ! - C:\WINDOWS\prefetch\WINTEMS.EXE-2A563F9B.pf
################## [ C:\WINDOWS\system32 ]
Deleted ! - C:\WINDOWS\system32\mdelk.exe
Deleted ! - C:\WINDOWS\system32\wintems.exe
Deleted ! - C:\WINDOWS\system32\ban_list.txt
################## [ C:\WINDOWS\system32\drivers ]
################## [ C:\Documents and Settings\Propri‚taire\Application Data ]
Deleted ! - "C:\Documents and Settings\Propri‚taire\Application Data\m\flec006.exe"
Deleted ! - "C:\Documents and Settings\Propri‚taire\Application Data\m\list.oct"
Deleted ! - "C:\Documents and Settings\Propri‚taire\Application Data\m\data.oct"
Deleted ! - "C:\Documents and Settings\Propri‚taire\Application Data\m\srvlist.oct"
Deleted ! - "C:\Documents and Settings\Propri‚taire\Application Data\m\shared"
Deleted ! - "C:\Documents and Settings\Propri‚taire\Application Data\m"
Deleted ! - "C:\Documents and Settings\Propri‚taire\Application Data\inst.exe"
Deleted ! - "C:\Documents and Settings\Propri‚taire\Application Data\drivers\srosa.sys"
Deleted ! - "C:\Documents and Settings\Propri‚taire\Application Data\drivers\srosa2.sys"
Deleted ! - "C:\Documents and Settings\Propri‚taire\Application Data\drivers\downld"
Deleted ! - "C:\Documents and Settings\Propri‚taire\Application Data\drivers"
################## [ C:\DOCUME~1\PROPRI~1\LOCALS~1\Temp ]
################## [ C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5 ]
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\1ARDYY8Y\b64[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\1ARDYY8Y\b64[2].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\1ARDYY8Y\b64[3].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\1ARDYY8Y\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\1ARDYY8Y\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\1ARDYY8Y\b64_1[3].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\1ARDYY8Y\b64_1[4].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\1ARDYY8Y\b64_1[5].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\1ARDYY8Y\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\1ARDYY8Y\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\1ARDYY8Y\b64_3[3].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\687P3NZW\b64[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\687P3NZW\b64[2].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\687P3NZW\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\687P3NZW\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\687P3NZW\b64_1[3].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\687P3NZW\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\687P3NZW\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\687P3NZW\b64_3[2].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\687P3NZW\file[1].txt
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\687P3NZW\mxd[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\BCULGGPT\b64[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\BCULGGPT\b64[2].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\BCULGGPT\b64[3].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\BCULGGPT\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\BCULGGPT\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\BCULGGPT\b64_1[3].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\BCULGGPT\b64_1[4].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\BCULGGPT\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\BCULGGPT\b64_3[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\SX1YJC68\b64_1[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\SX1YJC68\b64_1[2].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\SX1YJC68\b64_1[3].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\SX1YJC68\b64_1[4].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\SX1YJC68\b64_1[5].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\SX1YJC68\b64_2[1].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\SX1YJC68\b64_2[2].jpg
Deleted ! - C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\SX1YJC68\b64_2[3].jpg
\\\\\\\\\\\\\\\\\\ [ Registry / Infected keys ] ///////////////////
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
Deleted ! - HKEY_CURRENT_USER\Software\bisoft
Deleted ! - HKEY_CURRENT_USER\Software\DateTime4
Deleted ! - HKEY_CURRENT_USER\Software\FirtR
Deleted ! - HKEY_USERS\S-1-5-21-527237240-1292428093-682003330-1003\Software\Local AppWizard-Generated Applications\patch
Deleted ! - HKEY_USERS\S-1-5-21-527237240-1292428093-682003330-1003\Software\Local AppWizard-Generated Applications\winupgro
Deleted ! - HKEY_USERS\S-1-5-21-527237240-1292428093-682003330-1003\Software\FFC
Deleted ! - HKEY_USERS\S-1-5-21-527237240-1292428093-682003330-1003\Software\MuleAppData
\\\\\\\\\\\\\\\\\\ [ States / Restarting of services ] ///////////////////
# Safe boot mode restored !
# Services : [ Auto=2 / Request=3 / Disable=4 ]
Ndisuio - # Type of startup = 3
EapHost - # Type of startup = 2
Ip6Fw - # Type of startup = 2
SharedAccess - # Type of startup = 2
wuauserv - # Type of startup = 2
wscsvc - # Type of startup = 2
\\\\\\\\\\\\\\\\\\ [ Cleaning Removable drives ] ///////////////////
# Informations :
C: - Lecteur fixe
E: - Lecteur de CD-ROM
# deleting files :
Not deleted !! - E:\autorun.inf
\\\\\\\\\\\\\\\\\\ [ Registry / Mountpoint2 ] ///////////////////
-> Not found !
\\\\\\\\\\\\\\\\\\ [ Searching Other Infections ] ///////////////////
Suspect ! - 9ebb5ff4f4ee0e0da4db35071458afee C:\Documents and Settings\Propriétaire\Local Settings\Application Data\Ares\My Shared Folder\photoshop cs3 activation key generator.exe
Suspect ! - d8a9e541edae327d4fd34bcd80d34eac C:\Program Files\avast\patch.exe
Suspect ! - ebe38e2fcd97bfaf184cd5386100b529 C:\Program Files\Fichiers communs\Nero\Lib\NMBgMonitor.exe
Suspect ! - 2a2d6dfc1281dd5272403cf569d4aaae C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\1062031.exe
Suspect ! - 2a2d6dfc1281dd5272403cf569d4aaae C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\1063531.exe
Suspect ! - 2ee1faebb127647063aaef58a992519a C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\1071750.exe
Suspect ! - 2ee1faebb127647063aaef58a992519a C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\1110937.exe
Suspect ! - 2a2d6dfc1281dd5272403cf569d4aaae C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\1152625.exe
Suspect ! - 2a2d6dfc1281dd5272403cf569d4aaae C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\1320453.exe
Suspect ! - 2a2d6dfc1281dd5272403cf569d4aaae C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\1739421.exe
Suspect ! - 2ee1faebb127647063aaef58a992519a C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\380859.exe
Suspect ! - 2a2d6dfc1281dd5272403cf569d4aaae C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\401421.exe
Suspect ! - 2a2d6dfc1281dd5272403cf569d4aaae C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\414875.exe
Suspect ! - 2a2d6dfc1281dd5272403cf569d4aaae C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\420593.exe
Suspect ! - 2a2d6dfc1281dd5272403cf569d4aaae C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\444421.exe
Suspect ! - 2a2d6dfc1281dd5272403cf569d4aaae C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\499046.exe
Suspect ! - 2a2d6dfc1281dd5272403cf569d4aaae C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\506828.exe
Suspect ! - 2ee1faebb127647063aaef58a992519a C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\575984.exe
Suspect ! - 2a2d6dfc1281dd5272403cf569d4aaae C:\RECYCLER\S-1-5-21-527237240-1292428093-682003330-1003\Dc47\downld\634984.exe
\\\\\\\\\\\\\\\\\\ [ Searching Cracks / Keygen ] ///////////////////
################## [ ! End of report # FindyKill V4.714 ! ]
merci beaucoup de votre aide
claude vous remercie et vous envoie un petit coucou