Bonjour,
je crois que je mon pc est infécté par bagle (avast ne s'ouvre plus, ccleaner et spybot non plus ) j'ai cherché un peu sur internet et les "symptômes"semblent correspondre à cette infection.j'ai fais un scan avec findykill et obtenu un rapport mais comme je suis pas super calée en informatique j'aimerais que quelqu'un m'aide pour savoir ce qu'il faut supprimer.je vous poste le rapport.merci d'avance pour votre aide
############################## [ FindyKill V4.719 ]
# User : Milouse (Administrateurs) # PC-DE-MILOUSE
# Update on 06/03/09 by Chiquitine29
# Start at: 19:44:28 | 08/03/2009
# Intel(R) Pentium(R) Dual CPU E2180 @ 2.00GHz
# Microsoft© Windows VistaT dition Int‚grale (6.0.6000 32-bit) #
# Internet Explorer 7.0.6000.16386
# Windows Firewall Status : Disabled
# AV : avast! antivirus 4.8.1335 [VPS 090307-0] 4.8.1335 [ (!) Disabled | Updated ]
# C:\ # Disque fixe local # 195,31 Go (121,79 Go free) [MILOUSE] # NTFS
# D:\ # Disque fixe local # 19,53 Go (9,09 Go free) # NTFS
# E:\ # Disque fixe local # 133,12 Go (132,98 Go free) [Disque local ] # NTFS
# F:\ # Disque fixe local # 177,3 Go (55,93 Go free) # NTFS
# G:\ # Disque CD-ROM # 3,31 Go (0 Mo free) [re4_pal] # UDF
# H:\ # Disque CD-ROM
############################## [ Processus actifs ]
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\rundll32.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\svchost.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Adobe\Adobe Acrobat 7.0\Distillr\acrotray.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Users\Milouse\AppData\Roaming\drivers\winupgro.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Windows\system32\PnkBstrA.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Users\Milouse\AppData\Roaming\m\flec006.exe
C:\Users\Milouse\AppData\Roaming\drivers\downld\204267.exe
C:\Windows\explorer.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wbem\wmiprvse.exe
################## [ Processus infectieux stoppés ]
"C:\Users\Milouse\AppData\Roaming\drivers\winupgro.exe" (1120)
"C:\Users\Milouse\AppData\Roaming\m\flec006.exe" (3632)
"C:\Users\Milouse\AppData\Roaming\drivers\downld\204267.exe" (2176)
################## [ Fichiers / Dossiers infectieux C:\ ]
################## [ C:\Windows ]
################## [ C:\Windows\system32 ]
Found ! - C:\Windows\system32\mdelk.exe
Found ! - C:\Windows\system32\wintems.exe
Found ! - C:\Windows\system32\ban_list.txt
################## [ C:\Windows\system32\drivers ]
Found ! - "C:\Windows\system32\drivers\down"
################## [ C:\.. Application Data ... ]
Found ! - "C:\Users\Milouse\AppData\Roaming\m\flec006.exe"
Found ! - "C:\Users\Milouse\AppData\Roaming\m\list.oct"
Found ! - "C:\Users\Milouse\AppData\Roaming\m\data.oct"
Found ! - "C:\Users\Milouse\AppData\Roaming\m\srvlist.oct"
Found ! - "C:\Users\Milouse\AppData\Roaming\m\shared"
Found ! - "C:\Users\Milouse\AppData\Roaming\m"
Found ! - "C:\Users\Milouse\AppData\Roaming\drivers"
Found ! - "C:\Users\Milouse\AppData\Roaming\drivers\srosa2.sys"
Found ! - "C:\Users\Milouse\AppData\Roaming\drivers\wfsintwq.sys"
Found ! - "C:\Users\Milouse\AppData\Roaming\drivers\winupgro.exe"
Found ! - "C:\Users\Milouse\AppData\Roaming\drivers\downld"
################## [ Registre / Clés infectieuses ]
Found ! - HKEY_USERS\S-1-5-21-1558170933-1559115380-2179040942-1000\Software\Local AppWizard-Generated Applications\patch
Found ! - HKEY_USERS\S-1-5-21-1558170933-1559115380-2179040942-1000\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_USERS\S-1-5-21-1558170933-1559115380-2179040942-1000\Software\bisoft
Found ! - HKEY_USERS\S-1-5-21-1558170933-1559115380-2179040942-1000\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-1558170933-1559115380-2179040942-1000\Software\FFC
Found ! - HKEY_USERS\S-1-5-21-1558170933-1559115380-2179040942-1000\Software\FirtR
Found ! - HKEY_USERS\S-1-5-21-1558170933-1559115380-2179040942-1000\Software\MuleAppData
Found ! - HKEY_USERS\S-1-5-21-1558170933-1559115380-2179040942-1000\Software\Ubisoft
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\patch
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\FirtR
Found ! - HKEY_CURRENT_USER\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\FFC
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Found ! - HKEY_USERS\S-1-5-21-1558170933-1559115380-2179040942-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Found ! - HKEY_USERS\S-1-5-21-1558170933-1559115380-2179040942-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
Found ! - HKEY_USERS\S-1-5-21-1558170933-1559115380-2179040942-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
# Infection active : HKLM\SYSTEM\...\Services\srosa -> Start = 0x1
# Infection active : HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1
################## [ Recherche dans supports amovibles]
# Contenu de l'autorun : G:\autorun.inf
[autorun]
open=launcher.exe
icon=icon.ico
# Presence des fichiers :
Found ! [07/12/2006 13:05][-ra------] - G:\autorun.inf
################## [ Registre / Mountpoint2 ]
# -> Not found !
################## [ ! Fin du rapport # FindyKill V4.719 ! ]
