Voici le rapport comme prévu, je ne touche pas le pc c'est clair... je sors aussi une heure ou deux donc je serai la vers 18h30 merci en tout cas et à tout à l'heure...
############################## [ FindyKill V4.729 ]
# User : franck (Administrateurs) # PC-DE-FRANCK
# Update on 19/05/09 by Chiquitine29
# Start at: 15:47:26 | 19/05/2009
# Website :
http://pagesperso-orange.fr/NosTools/findykill.html
# Intel(R) Core(TM)2 Duo CPU T6400 @ 2.00GHz
# Microsoft® Windows Vista™ Édition Familiale Premium (6.0.6001 32-bit) # Service Pack 1
# Internet Explorer 7.0.6001.18000
# Windows Firewall Status : Enabled
# C:\ # Disque fixe local # 223,03 Go (107,48 Go free) # NTFS
# D:\ # Disque amovible
# E:\ # Disque amovible
# F:\ # Disque CD-ROM # 11,2 Mo (0 Mo free) [Razer] # CDFS
# H:\ # Disque amovible # 7,47 Go (5,76 Go free) # FAT32
############################## [ Active Processes ]
C:\Windows\System32\smss.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\wininit.exe
C:\Windows\system32\csrss.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\LogonUI.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\svchost.exe
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe
C:\Windows\RtkAudioService.exe
C:\Windows\system32\Ati2evxx.exe
C:\Windows\system32\userinit.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\runonce.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
C:\Program Files\Intel\WiFi\bin\EvtEng.exe
C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe
C:\Program Files\Windows Live\Family Safety\fsssvc.exe
C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe
C:\Program Files\sony\Network Utility\NSUService.exe
C:\Windows\system32\svchost.exe
C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\Windows\system32\svchost.exe
C:\Program Files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
C:\Program Files\sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Sony\VAIO Power Management\SPMService.exe
C:\Program Files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Windows\System32\svchost.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Program Files\sony\VAIO Event Service\VESMgrSub.exe
C:\Windows\system32\DllHost.exe
C:\Program Files\Sony\VAIO Update 4\VAIOUpdt.exe
################## [ Infected Files \ Folders ]
Deleted ! C:\Windows\Prefetch\157327.EXE-874CC3C2.pf
Deleted ! C:\Windows\Prefetch\265045.EXE-C4ADF83B.pf
Deleted ! C:\Windows\Prefetch\CRACK.EXE-5A884724.pf
Deleted ! C:\Windows\Prefetch\PATCH.EXE-3987DAE8.pf
Deleted ! C:\Windows\Prefetch\SERIAL.EXE-049E30C8.pf
Deleted ! C:\Windows\Prefetch\WINTEMS.EXE-85AF748B.pf
Deleted ! C:\Windows\Prefetch\WINUPGRO.EXE-B9E72D89.pf
Deleted ! C:\Windows\Prefetch\WINUPGRO.EXE-C73E3C70.pf
Deleted ! C:\Windows\system32\ban_list.txt
Deleted ! C:\Windows\system32\mdelk.exe
Deleted ! C:\Windows\system32\wintems.exe
Deleted ! C:\Windows\system32\drivers\down
Deleted ! "C:\Users\franck\AppData\Roaming\drivers\srosa2.sys"
Deleted ! "C:\Users\franck\AppData\Roaming\drivers\wfsintwq.sys"
Deleted ! "C:\Users\franck\AppData\Roaming\drivers\winupgro.exe"
Deleted ! "C:\Users\franck\AppData\Roaming\m\data.oct"
Deleted ! "C:\Users\franck\AppData\Roaming\m\flec006.exe"
Deleted ! "C:\Users\franck\AppData\Roaming\m\list.oct"
Deleted ! "C:\Users\franck\AppData\Roaming\m\srvlist.oct"
Deleted ! "C:\Users\franck\AppData\Roaming\drivers\downld"
Deleted ! "C:\Users\franck\AppData\Roaming\drivers"
Deleted ! "C:\Users\franck\AppData\Roaming\m\shared"
Deleted ! "C:\Users\franck\AppData\Roaming\m"
################## [ Infected Temp Files ]
Deleted ! C:\Users\franck\Local Settings\Temporary Internet Files\Content.IE5\AJS8ZYL9\b64[1].jpg
Deleted ! C:\Users\franck\Local Settings\Temporary Internet Files\Content.IE5\AJS8ZYL9\file[1].txt
Deleted ! C:\Users\franck\Local Settings\Temporary Internet Files\Content.IE5\BSU4ZOLF\b64_6[1].jpg
Deleted ! C:\Users\franck\Local Settings\Temporary Internet Files\Content.IE5\BSU4ZOLF\ieps[1].jpg
Deleted ! C:\Users\franck\Local Settings\Temporary Internet Files\Content.IE5\JUO8CLQK\b64_3[1].jpg
Deleted ! C:\Users\franck\Local Settings\Temporary Internet Files\Content.IE5\JUO8CLQK\b64_3[2].jpg
Deleted ! C:\Users\franck\Local Settings\Temporary Internet Files\Content.IE5\SUAKFDMG\b64_1[1].jpg
Deleted ! C:\Users\franck\Local Settings\Temporary Internet Files\Content.IE5\SUAKFDMG\ieps[1].jpg
################## [ Registry / Infected keys ]
Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
Deleted ! HKEY_CURRENT_USER\Software\bisoft
Deleted ! HKEY_CURRENT_USER\Software\DateTime4
Deleted ! HKEY_CURRENT_USER\Software\MuleAppData
Deleted ! HKEY_CURRENT_USER\Software\FFC
Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\patch
Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\serial
Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Deleted ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Deleted ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Deleted ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
################## [ Cleaning Removable drives ]
(!) Not deleted ! F:\autorun.inf
################## [ Registry / Mountpoint2 ]
# -> Not found !
################## [ States / Restarting of services ]
# Services : [ Auto=2 / Request=3 / Disable=4 ]
# Ndisuio -> # Type of startup =3
# EapHost -> # Type of startup =2
# Wlansvc -> # Type of startup =2
# SharedAccess -> # Type of startup =2
# wuauserv -> # Type of startup =2
# wscsvc -> # Type of startup =2
# WinDefend -> # Type of startup =2
# -> UAC is Enable.
################## [ Searching Other Infections ]
# Références de comparaison Bagle MD5 :
File ... : C:\Users\franck\AppData\Roaming\drivers\winupgro.exe
CRC32 .. : 3fce8d0a
MD5 .... : 1494f05cc67b211c709cca6a900635a4
Deleted ! : C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
# Taille : 790528 # MD5 : 1494F05CC67B211C709CCA6A900635A4
################## [ Corrupted files # Re-Installation required ]
C:\Program Files\Alwil Software\Avast4\ashAvast.exe
C:\Program Files\Alwil Software\Avast4\ashChest.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashLogV.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashPopWz.exe
C:\Program Files\Alwil Software\Avast4\ashQuick.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Alwil Software\Avast4\ashSimp2.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Alwil Software\Avast4\ashSkPcc.exe
C:\Program Files\Alwil Software\Avast4\ashSkPck.exe
C:\Program Files\Alwil Software\Avast4\ashUpd.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\sched.exe
C:\Program Files\Alwil Software\Avast4\VisthLic.exe
C:\Program Files\Alwil Software\Avast4\VisthUpd.exe
C:\Program Files\Sophos\Sophos Anti-Rootkit\helper.exe
################################### [ Cracks / Keygens / Serials ]
# -> Nothing found !
################## [ ! End of Report # FindyKill V4.729 ! ]