Je te proposerai un antivirus gratuit efficace pour remplacer Avast en fin de désinfection (ça approche ^^)
Il vaut mieux faire le changement d'antivirus quand le système sera à nouveau stable
/!\ A l'attention de ceux qui passent sur ce sujet /!\
Le logiciel qui suit n'est pas à utiliser à la légère ! Ne le faites que si un helpeur du forum qui connait bien cet outil vous l'a recommandé.
On va utiliser Combofix pour finir la désinfection. Attention, ce logiciel est très puissant, une mauvaise utilisation peut faire des dégâts... Fais
exactement ce qui suit :
Télécharge ComboFix (de sUBs) sur ton Bureau (et pas ailleurs !). Pour cela, fais un clic droit sur ce lien et choisis "enregistrer la cible sous ... " et tape C-Fix dans dans la fenêtre qui s'ouvre, puis choisis le Bureau comme destination :
http://download.bleepingcomputer.com/sUBs/ComboFix.exe
---------------------------------------- [ !
ATTENTION ! ] --------------------------------------------------
! déconnecte toi, ferme toutes tes applications en cours et
DESACTIVE TOUTES TES DEFENCES (anti-virus, antispyware, pare-feu) le temps de la manipulation qui pourraient gêner fortement l'outil...Tu les réactiveras donc après !
Dans ton cas, il s'agit d'Avast (fais un clic-droit sur l'icone près de l'horloge et clique sur « Arrêter la protection résidente »)
==>
Surtout, si tu rencontres des difficultés à ce niveau là, dis le moi avant de poursuivre...
Tuto ici pour installer la Console de récupération (important en cas de problème) :
http://www.bleepingcomputer.com/combofix/fr/comment-utiliser-combofix
---------------------------------------------------------------------------------------------------------------------------------
Ensuite :
Double-clique sur C-Fix.exe (= combofix.exe ) .
Appuie sur une touche pour démarrer le scan .
Attention : n'utilise pas ta souris ni ton clavier pendant que le programme tourne. Cela pourrait figer l'ordi ---> si un message d'erreur windows apparait à un moment : clique sur la croix rouge en haut à droite de la fenêtre pour la fermer
Le rapport sera crée dans: C:\Combofix.txt , poste le ici stp
je viens de le faire,je joint le rapport .
############################## [ FindyKill V4.718 ]
# User : Benoit (Administrateurs) # TEST-Q91SJ19OTC
# Update on 01/03/09
# Start at: 17:27:28 | 02/03/2009
# AMD Sempron(tm) Processor LE-1150
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# C:\ # Disque fixe local # 37,27 Go (14,71 Go free) # NTFS
# D:\ # Disque CD-ROM
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\CONTRO~1\bin\optgui.exe
C:\Program Files\Hotbar\bin\10.2.236.0\OEAddOn.exe
C:\Program Files\Hotbar\bin\10.2.236.0\HotbarSA.exe
C:\Program Files\EoRezo\EoEngine.exe
C:\Documents and Settings\Francis\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\MessengerSearchAddon\msgrsrch.exe
C:\Program Files\Hotbar\bin\10.2.236.0\Weather.exe
C:\documents and settings\francis\local settings\application data\mqgesuu.exe
C:\Documents and Settings\Francis\Application Data\drivers\winupgro.exe
C:\Program Files\OrangeHSS\Launcher\Launcher.exe
C:\WINDOWS\system32\wintems.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Documents and Settings\Francis\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Documents and Settings\Francis\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\Program Files\OrangeHSS\systray\systrayapp.exe
C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\Francis\Application Data\m\flec006.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Hotbar\bin\10.2.236.0\Srv.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
################## [ Processus infectieux stoppés ]
"C:\Documents and Settings\Francis\Application Data\drivers\winupgro.exe" (2164)
"C:\WINDOWS\system32\wintems.exe" (2356)
"C:\Documents and Settings\Francis\Application Data\m\flec006.exe" (1388)
################## [ Fichiers / Dossiers infectieux C:\ ]
Found ! - C:\InfoSat.txt
################## [ C:\WINDOWS ]
################## [ C:\WINDOWS\system32 ]
Found ! - C:\WINDOWS\system32\mdelk.exe
Found ! - C:\WINDOWS\system32\wintems.exe
Found ! - C:\WINDOWS\system32\ban_list.txt
################## [ C:\WINDOWS\system32\drivers ]
################## [ C:\.. Application Data ... ]
Found ! - "C:\Documents and Settings\Francis\Application Data\m\flec006.exe"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\list.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\data.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\srvlist.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\shared"
Found ! - "C:\Documents and Settings\Francis\Application Data\m"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\srosa2.sys"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\wfsintwq.sys"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\winupgro.exe"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\downld"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\flec006.exe"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\list.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\data.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\srvlist.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\shared"
Found ! - "C:\Documents and Settings\Francis\Application Data\m"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\srosa2.sys"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\wfsintwq.sys"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\winupgro.exe"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\downld"
################## [ Registre / Clés infectieuses ]
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\bisoft
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
# Infection active : HKLM\SYSTEM\...\Services\srosa -> Start = 0x1
# Infection active : HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1
################## [ Recherche dans supports amovibles]
# Presence des fichiers :
################## [ Registre / Mountpoint2 ]
# -> Not found !
################## [ ! Fin du rapport # FindyKill V4.718 ! ]
j'ai fait ce que tu m'as dis ,je joint le rapport , je l'ai deja envoyé j'ai un doute ,je crois qu'il n'ai pas arrivé a destination.merci
############################## [ FindyKill V4.718 ]
# User : Benoit (Administrateurs) # TEST-Q91SJ19OTC
# Update on 01/03/09
# Start at: 17:27:28 | 02/03/2009
# AMD Sempron(tm) Processor LE-1150
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# C:\ # Disque fixe local # 37,27 Go (14,71 Go free) # NTFS
# D:\ # Disque CD-ROM
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\CONTRO~1\bin\optgui.exe
C:\Program Files\Hotbar\bin\10.2.236.0\OEAddOn.exe
C:\Program Files\Hotbar\bin\10.2.236.0\HotbarSA.exe
C:\Program Files\EoRezo\EoEngine.exe
C:\Documents and Settings\Francis\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\MessengerSearchAddon\msgrsrch.exe
C:\Program Files\Hotbar\bin\10.2.236.0\Weather.exe
C:\documents and settings\francis\local settings\application data\mqgesuu.exe
C:\Documents and Settings\Francis\Application Data\drivers\winupgro.exe
C:\Program Files\OrangeHSS\Launcher\Launcher.exe
C:\WINDOWS\system32\wintems.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Documents and Settings\Francis\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Documents and Settings\Francis\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\Program Files\OrangeH
############################## [ FindyKill V4.718 ]
# User : Benoit (Administrateurs) # TEST-Q91SJ19OTC
# Update on 01/03/09
# Start at: 17:27:28 | 02/03/2009
# AMD Sempron(tm) Processor LE-1150
# Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Disabled
# C:\ # Disque fixe local # 37,27 Go (14,71 Go free) # NTFS
# D:\ # Disque CD-ROM
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AGI\common\win32\PythonService.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTRTSVC\0\FTRTSVC.exe
C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\CONTRO~1\bin\optgui.exe
C:\Program Files\Hotbar\bin\10.2.236.0\OEAddOn.exe
C:\Program Files\Hotbar\bin\10.2.236.0\HotbarSA.exe
C:\Program Files\EoRezo\EoEngine.exe
C:\Documents and Settings\Francis\Application Data\eoRezo\SoftwareUpdate\SoftwareUpdateHP.exe
C:\Program Files\SweetIM\Messenger\SweetIM.exe
C:\Program Files\Windows Live\Family Safety\fsui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\MessengerSearchAddon\msgrsrch.exe
C:\Program Files\Hotbar\bin\10.2.236.0\Weather.exe
C:\documents and settings\francis\local settings\application data\mqgesuu.exe
C:\Documents and Settings\Francis\Application Data\drivers\winupgro.exe
C:\Program Files\OrangeHSS\Launcher\Launcher.exe
C:\WINDOWS\system32\wintems.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\AlertModule\0\AlertModule.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Documents and Settings\Francis\Application Data\Microsoft\Live Search\Notification-LiveSearch.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\Documents and Settings\Francis\Application Data\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
C:\Program Files\OrangeHSS\systray\systrayapp.exe
C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\Francis\Application Data\m\flec006.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Hotbar\bin\10.2.236.0\Srv.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
################## [ Processus infectieux stoppés ]
"C:\Documents and Settings\Francis\Application Data\drivers\winupgro.exe" (2164)
"C:\WINDOWS\system32\wintems.exe" (2356)
"C:\Documents and Settings\Francis\Application Data\m\flec006.exe" (1388)
################## [ Fichiers / Dossiers infectieux C:\ ]
Found ! - C:\InfoSat.txt
################## [ C:\WINDOWS ]
################## [ C:\WINDOWS\system32 ]
Found ! - C:\WINDOWS\system32\mdelk.exe
Found ! - C:\WINDOWS\system32\wintems.exe
Found ! - C:\WINDOWS\system32\ban_list.txt
################## [ C:\WINDOWS\system32\drivers ]
################## [ C:\.. Application Data ... ]
Found ! - "C:\Documents and Settings\Francis\Application Data\m\flec006.exe"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\list.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\data.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\srvlist.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\shared"
Found ! - "C:\Documents and Settings\Francis\Application Data\m"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\srosa2.sys"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\wfsintwq.sys"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\winupgro.exe"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\downld"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\flec006.exe"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\list.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\data.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\srvlist.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\shared"
Found ! - "C:\Documents and Settings\Francis\Application Data\m"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\srosa2.sys"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\wfsintwq.sys"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\winupgro.exe"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\downld"
################## [ Registre / Clés infectieuses ]
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\bisoft
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
# Infection active : HKLM\SYSTEM\...\Services\srosa -> Start = 0x1
# Infection active : HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1
################## [ Recherche dans supports amovibles]
# Presence des fichiers :
################## [ Registre / Mountpoint2 ]
# -> Not found !
################## [ ! Fin du rapport # FindyKill V4.718 ! ]
SS\systray\systrayapp.exe
C:\Program Files\OrangeHSS\connectivity\connectivitymanager.exe
C:\Program Files\OrangeHSS\connectivity\CoreCom\CoreCom.exe
C:\Program Files\OrangeHSS\connectivity\CoreCom\OraConfigRecover.exe
C:\PROGRA~1\FICHIE~1\France Telecom\Shared Modules\FTCOMModule\0\FTCOMModule.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\Francis\Application Data\m\flec006.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\Hotbar\bin\10.2.236.0\Srv.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
################## [ Processus infectieux stoppés ]
"C:\Documents and Settings\Francis\Application Data\drivers\winupgro.exe" (2164)
"C:\WINDOWS\system32\wintems.exe" (2356)
"C:\Documents and Settings\Francis\Application Data\m\flec006.exe" (1388)
################## [ Fichiers / Dossiers infectieux C:\ ]
Found ! - C:\InfoSat.txt
################## [ C:\WINDOWS ]
################## [ C:\WINDOWS\system32 ]
Found ! - C:\WINDOWS\system32\mdelk.exe
Found ! - C:\WINDOWS\system32\wintems.exe
Found ! - C:\WINDOWS\system32\ban_list.txt
################## [ C:\WINDOWS\system32\drivers ]
################## [ C:\.. Application Data ... ]
Found ! - "C:\Documents and Settings\Francis\Application Data\m\flec006.exe"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\list.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\data.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\srvlist.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\shared"
Found ! - "C:\Documents and Settings\Francis\Application Data\m"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\srosa2.sys"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\wfsintwq.sys"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\winupgro.exe"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\downld"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\flec006.exe"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\list.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\data.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\srvlist.oct"
Found ! - "C:\Documents and Settings\Francis\Application Data\m\shared"
Found ! - "C:\Documents and Settings\Francis\Application Data\m"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\srosa2.sys"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\wfsintwq.sys"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\winupgro.exe"
Found ! - "C:\Documents and Settings\Francis\Application Data\drivers\downld"
################## [ Registre / Clés infectieuses ]
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\bisoft
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
Found ! - HKEY_USERS\S-1-5-21-507921405-706699826-1417001333-1003\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
# Infection active : HKLM\SYSTEM\...\Services\srosa -> Start = 0x1
# Infection active : HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1
################## [ Recherche dans supports amovibles]
# Presence des fichiers :
################## [ Registre / Mountpoint2 ]
# -> Not found !
################## [ ! Fin du rapport # FindyKill V4.718 ! ]