Rapport de Findykill
Résolu
jbletizef
-
pimprenelle27 Messages postés 20857 Date d'inscription Statut Contributeur sécurité Dernière intervention -
pimprenelle27 Messages postés 20857 Date d'inscription Statut Contributeur sécurité Dernière intervention -
A voir également:
- Rapport de Findykill
- Plan rapport de stage - Guide
- Rapport de crash windows - Guide
- Impossible d'afficher le rapport de tableau croisé dynamique sur un rapport existant - Forum Excel
- Envoyer un rapport de bug à mi pour analyse - Forum Xiaomi
- Mise en forme conditionnelle excel par rapport à une autre cellule - Guide
4 réponses
Etape 3/
Branche toutes tes sources de données externes au PC (clés USB, disques durs externes, lecteurs mp3, iPod...) sans les ouvrir- Relance FindyKill,
- Cette fois, sélectionne l'option 2 (Suppression) au menu principal.
- Il y aura 2 redémarrages, laisse travailler l'outil jusqu'à l'apparition du message "Nettoyage effectué !"
- Ensuite poste le rapport C:\FindyKill.txt
Branche toutes tes sources de données externes au PC (clés USB, disques durs externes, lecteurs mp3, iPod...) sans les ouvrir- Relance FindyKill,
- Cette fois, sélectionne l'option 2 (Suppression) au menu principal.
- Il y aura 2 redémarrages, laisse travailler l'outil jusqu'à l'apparition du message "Nettoyage effectué !"
- Ensuite poste le rapport C:\FindyKill.txt
Merci pour votre aide et votre réponse, findykill à l'air d'avoir fonctionné je peux de nouveau accèder à mes différents DDR (efficace!!!!!!) je vous envois le rapport de ce dernier :
###################### [ FindyKill V4.714 ]
# User : Administrateur - GROS
# Executed from : E:\Program Files\FindyKill
# Update on 19/01/09 by Chiquitine29
# Start at 11:04:42 the 20/01/2009
# Windows XP - Internet Explorer 6.0.2900.2180
# [ FindyKill V4.714 - Deleting ] ###############
\\\\\\\\\\\\\\\\\\ [ Active Processes ] ///////////////////
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\csrss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\logonui.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\acs.exe
E:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\PsCtrls.exe
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\PavFnSvr.exe
E:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\pavsrv51.exe
E:\WINDOWS\System32\HPZipm12.exe
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\AVENGINE.EXE
e:\program files\panda software\panda antivirus + firewall 2008\firewall\PSHOST.EXE
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\PsImSvc.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\TPSrv.exe
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\WebProxy.exe
E:\WINDOWS\system32\userinit.exe
\\\\\\\\\\\\\\\\\\ [ Infected Files / Folders ] ///////////////////
################## [ E:\ ]
################## [ E:\WINDOWS ]
################## [ E:\WINDOWS\Prefetch ]
Deleted ! - E:\WINDOWS\prefetch\MDELK.EXE-28EE3AC4.pf
################## [ E:\WINDOWS\system32 ]
################## [ E:\WINDOWS\system32\drivers ]
################## [ E:\Documents and Settings\Administrateur\Application Data ]
################## [ c:\Temp ]
################## [ E:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5 ]
\\\\\\\\\\\\\\\\\\ [ Registry / Infected keys ] ///////////////////
\\\\\\\\\\\\\\\\\\ [ States / Restarting of services ] ///////////////////
# Services : [ Auto=2 / Request=3 / Disable=4 ]
Ndisuio - # Type of startup = 3
Ip6Fw - # Type of startup = 2
SharedAccess - # Type of startup = 2
wuauserv - # Type of startup = 2
wscsvc - # Type of startup = 2
\\\\\\\\\\\\\\\\\\ [ Cleaning Removable drives ] ///////////////////
# Informations :
C: - Lecteur fixe
D: - Lecteur fixe
E: - Lecteur fixe
# deleting files :
Deleted ! - C:\autorun.inf
Deleted ! - D:\autorun.inf
Deleted ! - E:\autorun.inf
\\\\\\\\\\\\\\\\\\ [ Registry / Mountpoint2 ] ///////////////////
-> Not found !
\\\\\\\\\\\\\\\\\\ [ Searching Other Infections ] ///////////////////
\\\\\\\\\\\\\\\\\\ [ Searching Cracks / Keygen ] ///////////////////
################## [ ! End of report # FindyKill V4.714 ! ]
###################### [ FindyKill V4.714 ]
# User : Administrateur - GROS
# Executed from : E:\Program Files\FindyKill
# Update on 19/01/09 by Chiquitine29
# Start at 11:04:42 the 20/01/2009
# Windows XP - Internet Explorer 6.0.2900.2180
# [ FindyKill V4.714 - Deleting ] ###############
\\\\\\\\\\\\\\\\\\ [ Active Processes ] ///////////////////
E:\WINDOWS\System32\smss.exe
E:\WINDOWS\system32\csrss.exe
E:\WINDOWS\system32\winlogon.exe
E:\WINDOWS\system32\services.exe
E:\WINDOWS\system32\lsass.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\system32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\System32\svchost.exe
E:\WINDOWS\system32\logonui.exe
E:\WINDOWS\system32\spoolsv.exe
E:\WINDOWS\system32\acs.exe
E:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
E:\Program Files\Java\jre6\bin\jqs.exe
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\PsCtrls.exe
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\PavFnSvr.exe
E:\Program Files\Fichiers communs\Panda Software\PavShld\pavprsrv.exe
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\pavsrv51.exe
E:\WINDOWS\System32\HPZipm12.exe
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\AVENGINE.EXE
e:\program files\panda software\panda antivirus + firewall 2008\firewall\PSHOST.EXE
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\PsImSvc.exe
E:\WINDOWS\System32\svchost.exe
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\TPSrv.exe
E:\Program Files\Panda Software\Panda Antivirus + Firewall 2008\WebProxy.exe
E:\WINDOWS\system32\userinit.exe
\\\\\\\\\\\\\\\\\\ [ Infected Files / Folders ] ///////////////////
################## [ E:\ ]
################## [ E:\WINDOWS ]
################## [ E:\WINDOWS\Prefetch ]
Deleted ! - E:\WINDOWS\prefetch\MDELK.EXE-28EE3AC4.pf
################## [ E:\WINDOWS\system32 ]
################## [ E:\WINDOWS\system32\drivers ]
################## [ E:\Documents and Settings\Administrateur\Application Data ]
################## [ c:\Temp ]
################## [ E:\Documents and Settings\Administrateur\Local Settings\Temporary Internet Files\Content.IE5 ]
\\\\\\\\\\\\\\\\\\ [ Registry / Infected keys ] ///////////////////
\\\\\\\\\\\\\\\\\\ [ States / Restarting of services ] ///////////////////
# Services : [ Auto=2 / Request=3 / Disable=4 ]
Ndisuio - # Type of startup = 3
Ip6Fw - # Type of startup = 2
SharedAccess - # Type of startup = 2
wuauserv - # Type of startup = 2
wscsvc - # Type of startup = 2
\\\\\\\\\\\\\\\\\\ [ Cleaning Removable drives ] ///////////////////
# Informations :
C: - Lecteur fixe
D: - Lecteur fixe
E: - Lecteur fixe
# deleting files :
Deleted ! - C:\autorun.inf
Deleted ! - D:\autorun.inf
Deleted ! - E:\autorun.inf
\\\\\\\\\\\\\\\\\\ [ Registry / Mountpoint2 ] ///////////////////
-> Not found !
\\\\\\\\\\\\\\\\\\ [ Searching Other Infections ] ///////////////////
\\\\\\\\\\\\\\\\\\ [ Searching Cracks / Keygen ] ///////////////////
################## [ ! End of report # FindyKill V4.714 ! ]
c pour savoir si tu peu m'aider avec ce rapor de findykill :
###################### [ FindyKill V4.714 ]
# User : Administrateur - PC
# Emplacement : C:\Program Files\FindyKill
# Outils Mis a jours le 19/01/09 par Chiquitine29
# Recherche effectuée à 11:41:10 le 21/01/2009
# Windows XP - Internet Explorer 7.0.5730.13
# [ FindyKill V4.714 - Scan ] ##############
\\\\\\\\\\\\\\\\\\\\ [ Processus actifs ] ///////////////////
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Labtec\WebCam10\WebCam10.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\documents and settings\administrateur\local settings\application data\acoyy.exe
C:\Documents and Settings\Administrateur\Application Data\drivers\winupgro.exe
C:\WINDOWS\system32\wintems.exe
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Executive Software\Diskeeper\DkService.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LogiShrd\LComMgr\LVComSX.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\Administrateur\Application Data\drivers\downld\393875.exe
C:\WINDOWS\system32\regsvr32.exe
C:\Program Files\Alwil Software\Avast4\aswRunDll.exe
C:\Program Files\Alwil Software\Avast4\setup\avast.setup
C:\Program Files\Internet Explorer\iexplore.exe
\\\\\\\\\\\\\\\\\\ [ Processus infectieux stoppés ] ///////////////////
"C:\Documents and Settings\Administrateur\Application Data\drivers\winupgro.exe" (1172)
"C:\WINDOWS\system32\wintems.exe" (1216)
"C:\Documents and Settings\Administrateur\Application Data\drivers\downld\393875.exe" (2984)
\\\\\\\\\\\\\\\\\\ [ Fichiers/Dossiers infectieux ] ///////////////////
################## [ C:\ ]
################## [ C:\WINDOWS ]
################## [ C:\WINDOWS\Prefetch ]
Found ! - C:\WINDOWS\prefetch\01.EXE-089F848B.pf
Found ! - C:\WINDOWS\prefetch\01.EXE-1D839A1B.pf
Found ! - C:\WINDOWS\prefetch\01.EXE-29D98589.pf
Found ! - C:\WINDOWS\prefetch\01.EXE-2BB613B8.pf
Found ! - C:\WINDOWS\prefetch\01.EXE-33D8271E.pf
Found ! - C:\WINDOWS\prefetch\01.EXE-346FCE01.pf
Found ! - C:\WINDOWS\prefetch\02.EXE-055BC03F.pf
Found ! - C:\WINDOWS\prefetch\02.EXE-173D8AB0.pf
Found ! - C:\WINDOWS\prefetch\02.EXE-1B26B694.pf
Found ! - C:\WINDOWS\prefetch\02.EXE-2348C9FA.pf
Found ! - C:\WINDOWS\prefetch\02.EXE-25255829.pf
Found ! - C:\WINDOWS\prefetch\02.EXE-312C09B5.pf
Found ! - C:\WINDOWS\prefetch\02.EXE-317B4397.pf
Found ! - C:\WINDOWS\prefetch\03.EXE-1682C446.pf
Found ! - C:\WINDOWS\prefetch\03.EXE-37C15302.pf
Found ! - C:\WINDOWS\prefetch\04.EXE-387C196C.pf
################## [ C:\WINDOWS\system32 ]
Found ! [21/01/2009 11:11] - C:\WINDOWS\system32\a.bat
Found ! [21/01/2009 00:47] - C:\WINDOWS\system32\mdelk.exe
Found ! [21/01/2009 00:34] - C:\WINDOWS\system32\wintems.exe
Found ! [21/01/2009 11:11] - C:\WINDOWS\system32\winupgro.exe
Found ! [21/01/2009 11:08] - C:\WINDOWS\system32\ban_list.txt
################## [ C:\WINDOWS\system32\drivers ]
################## [ C:\Documents and Settings\Administrateur\Application Data ]
Found ! [21/01/2009 00:06] - "C:\Documents and Settings\Administrateur\Application Data\m\flec006.exe"
Found ! [21/01/2009 00:10] - "C:\Documents and Settings\Administrateur\Application Data\m\list.oct"
Found ! [21/01/2009 00:16] - "C:\Documents and Settings\Administrateur\Application Data\m\data.oct"
Found ! [21/01/2009 00:16] - "C:\Documents and Settings\Administrateur\Application Data\m\srvlist.oct"
Found ! [21/01/2009 00:44] - "C:\Documents and Settings\Administrateur\Application Data\m\shared"
Found ! [21/01/2009 00:10] - "C:\Documents and Settings\Administrateur\Application Data\m"
Found ! [21/01/2009 00:01] - "C:\Documents and Settings\Administrateur\Application Data\drivers"
Found ! [21/01/2009 11:06] - "C:\Documents and Settings\Administrateur\Application Data\drivers\srosa2.sys"
Found ! [21/01/2009 11:06] - "C:\Documents and Settings\Administrateur\Application Data\drivers\wfsintwq.sys"
Found ! [24/08/2005 02:01] - "C:\Documents and Settings\Administrateur\Application Data\drivers\winupgro.exe"
Found ! [21/01/2009 11:11] - "C:\Documents and Settings\Administrateur\Application Data\drivers\downld"
################## [ C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp ]
\\\\\\\\\\\\\\\\\\ [ Registre / Startup ] ///////////////////
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
SuperCopier.exe=C:\Program Files\SuperCopier\SuperCopier.exe
MsnMsgr="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
ctfmon.exe=C:\WINDOWS\system32\ctfmon.exe
acoyy="c:\documents and settings\administrateur\local settings\application data\acoyy.exe" acoyy
eMuleAutoStart=C:\Program Files\eChanblard\emule.exe -AutoStart
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
NeroFilterCheck=C:\WINDOWS\system32\NeroCheck.exe
SunJavaUpdateSched="C:\Program Files\Java\jre6\bin\jusched.exe"
WinampAgent="C:\Program Files\Winamp\winampa.exe"
QuickTime Task="C:\Program Files\QuickTime\qttask.exe" -atboottime
iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
LogitechCommunicationsManager="C:\Program Files\Fichiers communs\LogiShrd\LComMgr\Communications_Helper.exe"
<NO NAME>=
LogitechQuickCamRibbon="C:\Program Files\Labtec\WebCam10\WebCam10.exe" /hide
avast!=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
[HKEY_CURRENT_USER\software\local appwizard-generated applications\run]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\SuperCopier]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\winupgro]
\\\\\\\\\\\\\\\\\\ [ Registre / Clés infectieuses ] ///////////////////
Found ! - HKEY_USERS\S-1-5-21-1078081533-651377827-725345543-500\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_USERS\S-1-5-21-1078081533-651377827-725345543-500\Software\bisoft
Found ! - HKEY_USERS\S-1-5-21-1078081533-651377827-725345543-500\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-1078081533-651377827-725345543-500\Software\FFC
Found ! - HKEY_USERS\S-1-5-21-1078081533-651377827-725345543-500\Software\FirtR
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sK9Ou0s
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\FirtR
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | drvsyskit
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | german.exe
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | mule_st_key
/!\ Infection active : HKLM\SYSTEM\...\Services\srosa -> Start = 0x1
/!\ Infection active : HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1
\\\\\\\\\\\\\\\\\\ [ Etat / Services ] ///////////////////
# Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
/!\ Mode sans echec non fonctionnel !!
# Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
/!\ Mode sans echec non fonctionnel !!
# Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network
/!\ Mode sans echec non fonctionnel !!
# Services : [ Auto=2 / Demande=3 / Désactivé=4 ]
/!\ Ndisuio - # Type de démarrage = 4
/!\ SharedAccess - # Type de démarrage = 4
/!\ wuauserv - # Type de démarrage = 4
\\\\\\\\\\\\\\\\\\ [ Recherche dans supports amovibles] ///////////////////
# Informations :
C: - Lecteur fixe
# presence des fichiers :
\\\\\\\\\\\\\\\\\\ [ Registre / Mountpoint2 ] ///////////////////
-> Not found !
################## [ ! Fin du rapport # FindyKill V4.714 ! ]