Bonjour,
Depuis quelques jours j'ai remarqué que mon AV ne se lançait plus...
j'ai trouver un virus nommé flec003.exe : impossible de le supprimer !
J'ai ré a liser un rapport findykill :
############################## | FindyKill V5.044 |
# User : Proprietaire (Administrateurs) # ST-00C08FF3B5F5
# Update on 10/06/2010 by El Desaparecido
# Start at: 19:55:52 | 16/06/2010
# Website : http://pagesperso-orange.fr/NosTools/index.html
# Contact : FindyKill.Contact@gmail.com
# AMD Athlon(tm) 64 Processor 3000+
# Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Enabled
# AV : Norton Internet Security 16.0.0.125 [ Enabled | Updated ]
# FW : Norton Internet Security[ Enabled ]16.0.0.125
# C:\ # Disque fixe local # 149,04 Go (59,24 Go free) # NTFS
# E:\ # Disque amovible
# F:\ # Disque amovible
# G:\ # Disque amovible
# H:\ # Disque CD-ROM
# I:\ # Disque CD-ROM
# J:\ # Disque amovible
# L:\ # Disque amovible # 1,96 Go (830,75 Mo free) # FAT
############################## | Processus infectieux stoppés |
"C:\Documents and Settings\Proprietaire\Application Data\drivers\winupgro.exe" (528)
"C:\Documents and Settings\Proprietaire\Application Data\m\flec006.exe" (3252)
"C:\WINDOWS\wintems.exe" (3412)
"C:\Documents and Settings\Proprietaire\Application Data\hidires\flec003.exe" -run (3516)
################## | Eléments infectieux |
C:\WINDOWS\ban_list.txt
C:\WINDOWS\mdelk.exe
C:\WINDOWS\wintems.exe
C:\WINDOWS\system32\srosa2.sys
C:\WINDOWS\system32\wfsintwq.sys
C:\Documents and Settings\Proprietaire\Application Data\drivers
C:\Documents and Settings\Proprietaire\Application Data\drivers\downld
C:\Documents and Settings\Proprietaire\Application Data\drivers\winupgro.exe
C:\Documents and Settings\Proprietaire\Application Data\hidires
C:\Documents and Settings\Proprietaire\Application Data\hidires\config
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\AC_BootstrapIPs.dat
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\AC_SearchStrings.dat
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\AC_ServerMetURLs.dat
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\cancelled.met
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\clients.met
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\clients.met.bak
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\cryptkey.dat
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\emfriends.met
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\key_index.dat
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\known.met
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\known2_64.met
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\load_index.dat
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\nodes.dat
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\preferences.dat
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\preferences.ini
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\preferencesKad.dat
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\server.met
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\server_met.old
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\shareddir.dat
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\src_index.dat
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\statistics.ini
C:\Documents and Settings\Proprietaire\Application Data\hidires\config\StoredSearches.met
C:\Documents and Settings\Proprietaire\Application Data\hidires\downloads.bak
C:\Documents and Settings\Proprietaire\Application Data\hidires\downloads.txt
C:\Documents and Settings\Proprietaire\Application Data\hidires\file.exe
C:\Documents and Settings\Proprietaire\Application Data\hidires\flec003.exe
C:\Documents and Settings\Proprietaire\Application Data\hidires\flec005.exe
C:\Documents and Settings\Proprietaire\Application Data\hidires\Incoming
C:\Documents and Settings\Proprietaire\Application Data\hidires\lang
C:\Documents and Settings\Proprietaire\Application Data\hidires\names.txt
C:\Documents and Settings\Proprietaire\Application Data\hidires\server.txt
C:\Documents and Settings\Proprietaire\Application Data\hidires\skins
C:\Documents and Settings\Proprietaire\Application Data\hidires\Temp
C:\Documents and Settings\Proprietaire\Application Data\hidires\WDIR
C:\Documents and Settings\Proprietaire\Application Data\hidires\webserver
C:\Documents and Settings\Proprietaire\Application Data\m
C:\Documents and Settings\Proprietaire\Application Data\m\data.oct
C:\Documents and Settings\Proprietaire\Application Data\m\flec006.exe
C:\Documents and Settings\Proprietaire\Application Data\m\list.oct
C:\Documents and Settings\Proprietaire\Application Data\m\srvlist.oct
C:\Documents and Settings\Proprietaire\Application Data\m\shared
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\124AM22G\mxd[1].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\124AM22G\mxd[2].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\124AM22G\mxd[3].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\124AM22G\servernames[1].htm
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\I3TTMURY\mxd[10].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\I3TTMURY\mxd[1].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\I3TTMURY\mxd[2].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\I3TTMURY\mxd[3].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\I3TTMURY\mxd[4].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\I3TTMURY\mxd[5].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\I3TTMURY\mxd[6].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\I3TTMURY\mxd[7].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\I3TTMURY\mxd[8].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\I3TTMURY\mxd[9].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\I3TTMURY\servernames[1].htm
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\I3TTMURY\servernames[2].htm
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\J1A97NMD\mxd[1].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\J1A97NMD\mxd[2].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\J1A97NMD\mxd[3].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\J1A97NMD\mxd[4].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\J1A97NMD\mxd[5].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\J1A97NMD\mxd[6].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\J1A97NMD\mxd[7].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\VQO69CML\mxd[1].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\VQO69CML\mxd[2].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\VQO69CML\mxd[3].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\VQO69CML\mxd[4].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\VQO69CML\mxd[5].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\VQO69CML\mxd[6].jpg
C:\Documents and Settings\Proprietaire\Local Settings\Temporary Internet Files\Content.IE5\VQO69CML\mxd[7].jpg
################## | Registre |
[HKLM\SYSTEM\CurrentControlSet\Services\sK9Ou0s]
[HKLM\SYSTEM\ControlSet001\Services\sK9Ou0s]
[HKLM\SYSTEM\ControlSet003\Services\sK9Ou0s]
[HKLM\SYSTEM\CurrentControlSet\Services\srosa]
[HKLM\SYSTEM\ControlSet001\Services\srosa]
[HKLM\SYSTEM\ControlSet003\Services\srosa]
[HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S]
[HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S]
[HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S]
[HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
[HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
[HKLM\software\microsoft\shared tools\msconfig\startupreg\flec003.exe]
[HKCU\Software\bisoft]
[HKCU\Software\DateTime4]
[HKCU\Software\MuleAppData]
[HKCU\Software\WS4001]
[HKCR\ed2k]
[HKCU\Software\Classes\ed2k]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
[HKU\S-1-5-21-1606980848-162531612-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run] "drvsyskit"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "german.exe"
[HKU\S-1-5-21-1606980848-162531612-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run] "german.exe"
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
[HKU\S-1-5-21-1606980848-162531612-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Run] "mule_st_key"
[HKU\S-1-5-21-1606980848-162531612-725345543-1004\Software\bisoft]
[HKU\S-1-5-21-1606980848-162531612-725345543-1004\Software\DateTime4]
[HKU\S-1-5-21-1606980848-162531612-725345543-1004\Software\MuleAppData]
[HKCU\Software\Local AppWizard-Generated Applications\winupgro]
[HKU\S-1-5-21-1606980848-162531612-725345543-1004\Software\Local AppWizard-Generated Applications\winupgro]
################## | Etat |
# Affichage des fichiers cachés : OK
Clé manquante : HKLM\...\SafeBoot | Mode sans echec non fonctionnel !
# (!) Ndisuio -> Start = 4 ( Good = 3 | Bad = 4 )
# EapHost -> Start = 3 ( Good = 2 | Bad = 4 )
# (!) Ip6Fw -> Start = 4 ( Good = 2 | Bad = 4 )
# (!) SharedAccess -> Start = 4 ( Good = 2 | Bad = 4 )
# (!) wuauserv -> Start = 4 ( Good = 2 | Bad = 4 )
# (!) wscsvc -> Start = 4 ( Good = 2 | Bad = 4 )
################## | ! Fin du rapport # FindyKill V5.044 ! |
Que faire ??????
