Voici le rapport:
----------------- FindyKill V4.095 ------------------
* User : PC - LOUIS
* Emplacement : C:\Program Files\FindyKill
* Outils Mis a jours le 05/11/08 par Chiquitine29
* Recherche effectuée à 12:08:41 le 06/11/2008
* Windows XP - Internet Explorer 6.0.2600.0000
((((((((((((((((( *** Recherche *** ))))))))))))))))))
--------------- [ Processus actifs ] ----------------
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
C:\Program Files\DAP\DAP.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\HP1006MC.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\usnsvc.exe
--------------- [ Fichiers/Dossiers infectieux ] ----------------
»»»» Presence des fichiers dans C:
»»»» Presence des fichiers dans C:\WINDOWS
»»»» Presence des fichiers dans C:\WINDOWS\Prefetch
Present ! - C:\WINDOWS\prefetch\MDELK.EXE-238AA5EF.pf
»»»» Presence des fichiers dans C:\WINDOWS\system32
»»»» Presence des fichiers dans C:\WINDOWS\system32\drivers
»»»» Presence des fichiers dans C:\Documents and Settings\PC\Application Data
»»»» Presence des fichiers dans C:\DOCUME~1\PC\LOCALS~1\Temp
Présent ! - C:\DOCUME~1\PC\LOCALS~1\Temp\RarSFX0\hbedv.key
--------------- [ Registre / Startup ] ----------------
! REG.EXE VERSION 3.0
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
nwiz REG_SZ nwiz.exe /install
KernelFaultCheck REG_EXPAND_SZ %systemroot%\system32\dumprep 0 -k
NvCplDaemon REG_SZ RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
ZoneAlarm Client REG_SZ "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\OptionalComponents
! REG.EXE VERSION 3.0
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
MsnMsgr REG_SZ "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
Gestionnaire Antidote.exe REG_SZ C:\PROGRA~1\Druide\Antidote\Antidote\Gestionnaire Antidote.exe
DownloadAccelerator REG_SZ "C:\Program Files\DAP\DAP.EXE" /STARTUP
<SANS NOM> REG_SZ C:\Documents and Settings\PC\Application Data\Adobe\Player.exe
--------------- [ Registre / Clés infectieuses ] ----------------
--------------- [ Etat / Services ] ----------------
+- Services : [ Auto=2 Demande=3 Désactivé=4 ]
Ndisuio - Type de démarrage = 3
SharedAccess - Type de démarrage = 3
wuauserv - Type de démarrage = 2
/!\ wscsvc - Type de démarrage = 4
--------------- [ Recherche dans supports amovibles] ----------------
+- Informations :
C: - Lecteur fixe
F: - Lecteur de CD-ROM
+- Contenu de l'autorun : F:\autorun.inf
[autorun]
OPEN=autorun.exe
ICON=Autorun\Civ4Installer.ico
LABEL=Sid Meier's Civilization 4
[appdata]
Mutex=Civ4 21031
InstallFile=setup.exe
PlayFile=Civilization4.exe
RegKey=INSTALLDIR
[0x09]
;English
Background=Autorun\Civ4AutoRunBG.bmp
LegalPos=85,272,480
LegalColor=255,255,255
LegalShadow=0,0,0
LegalFont=MS Sans Serif,8
LegalStyle=bold
LegalText=©2005 Firaxis Games, Inc. All Rights Reserved. Manufactured and marketed by Take Two Interactive, New York, NY. All trademarks are the property of their respective owners.
ExecPos=117,201
InstallImage=Autorun\BTN01-Install.bmp
InstallHilite=Autorun\BTN01-Install_OVER.bmp
PlayImage=Autorun\BTN01-Play.bmp
PlayHilite=Autorun\BTN01-Play_OVER.bmp
ReadmePos=265,202
ReadmeImage=Autorun\BTN02-ReadMe.bmp
ReadmeHilite=Autorun\BTN02-ReadMe_OVER.bmp
ReadmeFile=Readme\English\Readme.htm
ExitPos=412,200
ExitImage=Autorun\BTN03-Exit.bmp
ExitHilite=Autorun\BTN03-Exit_OVER.bmp
[0x0c]
;French
Background=Autorun\Civ4AutoRunBG.bmp
LegalPos=85,272,480
LegalColor=255,255,255
LegalShadow=0,0,0
LegalFont=MS Sans Serif,8
LegalStyle=bold
LegalText=©2005 Firaxis Games, Inc. Tous droits réservés. Fabriqué et commercialisé par Take Two Interactive, New York, NY. Toutes les marques commerciales sont la propriété de leurs détenteurs respectifs.
ExecPos=117,201
InstallImage=Autorun\FR_BTN01-Install.bmp
InstallHilite=Autorun\FR_BTN01-Install_OVER.bmp
PlayImage=Autorun\FR_BTN01-Play.bmp
PlayHilite=Autorun\FR_BTN01-Play_OVER.bmp
ReadmePos=265,202
ReadmeImage=Autorun\FR_BTN02-ReadMe.bmp
ReadmeHilite=Autorun\FR_BTN02-ReadMe_OVER.bmp
ReadmeFile=Readme\French\Readme.htm
ExitPos=412,200
ExitImage=Autorun\FR_BTN03-Exit.bmp
ExitHilite=Autorun\FR_BTN03-Exit_OVER.bmp
[0x10]
;Italian
Background=Autorun\Civ4AutoRunBG.bmp
LegalPos=85,272,480
LegalColor=255,255,255
LegalShadow=0,0,0
LegalFont=MS Sans Serif,8
LegalStyle=bold
LegalText=©2005 Firaxis Games, Inc. Tutti i diritti riservati. Prodotto e distribuito da Take Two Interactive, New York, NY. Tutti i marchi sono di proprietà dei rispettivi detentori.
ExecPos=117,201
InstallImage=Autorun\IT_BTN01-Install.bmp
InstallHilite=Autorun\IT_BTN01-Install_OVER.bmp
PlayImage=Autorun\IT_BTN01-Play.bmp
PlayHilite=Autorun\IT_BTN01-Play_OVER.bmp
ReadmePos=265,202
ReadmeImage=Autorun\IT_BTN02-ReadMe.bmp
ReadmeHilite=Autorun\IT_BTN02-ReadMe_OVER.bmp
ReadmeFile=Readme\Italian\Readme.htm
ExitPos=412,200
ExitImage=Autorun\IT_BTN03-Exit.bmp
ExitHilite=Autorun\IT_BTN03-Exit_OVER.bmp
[0x07]
;German
Background=Autorun\Civ4AutoRunBG.bmp
LegalPos=85,272,480
LegalColor=255,255,255
LegalShadow=0,0,0
LegalFont=MS Sans Serif,8
LegalStyle=bold
LegalText=© 2005 Firaxis Games, Inc. Alle Rechte vorbehalten. Herstellung und Vermarktung durch Take Two Interactive, New York, NY. Alle Warenzeichen sind Eigentum der jeweiligen Inhaber.
ExecPos=117,201
InstallImage=Autorun\GE_BTN01-Install.bmp
InstallHilite=Autorun\GE_BTN01-Install_OVER.bmp
PlayImage=Autorun\GE_BTN01-Play.bmp
PlayHilite=Autorun\GE_BTN01-Play_OVER.bmp
ReadmePos=265,202
ReadmeImage=Autorun\GE_BTN02-ReadMe.bmp
ReadmeHilite=Autorun\GE_BTN02-ReadMe_OVER.bmp
ReadmeFile=Readme\German\Readme.htm
ExitPos=412,200
ExitImage=Autorun\GE_BTN03-Exit.bmp
ExitHilite=Autorun\GE_BTN03-Exit_OVER.bmp
[0x0a]
;Spanish
Background=Autorun\Civ4AutoRunBG.bmp
LegalPos=85,272,480
LegalColor=255,255,255
LegalShadow=0,0,0
LegalFont=MS Sans Serif,8
LegalStyle=bold
LegalText=©2005 Firaxis Games, Inc. Todos los derechos reservados. Creado y distribuido por Take Two Interactive, New York, NY. Todas las marcas comerciales pertenecen a sus respectivos propietarios.
ExecPos=117,201
InstallImage=Autorun\SP_BTN01-Install.bmp
InstallHilite=Autorun\SP_BTN01-Install_OVER.bmp
PlayImage=Autorun\SP_BTN01-Play.bmp
PlayHilite=Autorun\SP_BTN01-Play_OVER.bmp
ReadmePos=265,202
ReadmeImage=Autorun\SP_BTN02-ReadMe.bmp
ReadmeHilite=Autorun\SP_BTN02-ReadMe_OVER.bmp
ReadmeFile=Readme\Spanish\Readme.htm
ExitPos=412,200
ExitImage=Autorun\SP_BTN03-Exit.bmp
ExitHilite=Autorun\SP_BTN03-Exit_OVER.bmp
+- presence des fichiers :
Présent ! [15/10/2005 02:42][-r-------] - F:\autorun.inf
--------------- [ Registre / Moutpoint2 ] ----------------
-> Recherche négative.
------------------- ! Fin du rapport ! --------------------