Bonjour,
comme bcp, g attrapé le fameux bagle qui bloque les antivirus (win 32 invalide)
G exécuté Findykill dont voici le rapport :
###################### [ FindyKill V4.715 ]
# User : Alain - SN012345678912
# Emplacement : C:\Program Files\FindyKill
# Outils Mis a jours 29/01/09 par Chiquitine29
# Recherche effectuée à 12:32:07 le 09/02/2009
# Windows XP - Internet Explorer 7.0.5730.11
Found ! [09/02/2009 12:18] - "C:\Muestras"
Found ! [09/02/2009 12:19] - C:\InfoSat.txt
################## [ C:\WINDOWS ]
################## [ C:\WINDOWS\Prefetch ]
Found ! - C:\WINDOWS\prefetch\1008437.EXE-0DE4F763.pf
Found ! - C:\WINDOWS\prefetch\1014718.EXE-29B2D776.pf
Found ! - C:\WINDOWS\prefetch\1045859.EXE-312F243D.pf
Found ! - C:\WINDOWS\prefetch\1125109.EXE-0C9D5FF2.pf
Found ! - C:\WINDOWS\prefetch\1130328.EXE-0CC51A63.pf
Found ! - C:\WINDOWS\prefetch\207984.EXE-256AA8DB.pf
Found ! - C:\WINDOWS\prefetch\214156.EXE-0D3604E8.pf
Found ! - C:\WINDOWS\prefetch\257750.EXE-377D8743.pf
Found ! - C:\WINDOWS\prefetch\303312.EXE-32ADD389.pf
Found ! - C:\WINDOWS\prefetch\372968.EXE-0E3477BA.pf
Found ! - C:\WINDOWS\prefetch\930093.EXE-1C772664.pf
Found ! - C:\WINDOWS\prefetch\FLEC006.EXE-2A63512F.pf
Found ! - C:\WINDOWS\prefetch\WINTEMS.EXE-377E42D4.pf
################## [ C:\WINDOWS\system32 ]
Found ! [09/02/2009 12:25] - C:\WINDOWS\system32\mdelk.exe
Found ! [09/02/2009 12:25] - C:\WINDOWS\system32\wintems.exe
Found ! [09/02/2009 12:26] - C:\WINDOWS\system32\ban_list.txt
################## [ C:\Documents and Settings\Alain\Application Data ]
Found ! [09/02/2009 12:12] - "C:\Documents and Settings\Alain\Application Data\m\flec006.exe"
Found ! [09/02/2009 12:14] - "C:\Documents and Settings\Alain\Application Data\m\shared"
Found ! [09/02/2009 12:18] - "C:\Documents and Settings\Alain\Application Data\m"
Found ! [09/02/2009 12:18] - "C:\Documents and Settings\Alain\Application Data\drivers"
Found ! [09/02/2009 12:10] - "C:\Documents and Settings\Alain\Application Data\drivers\wfsintwq.sys"
Found ! [05/02/2006 03:01] - "C:\Documents and Settings\Alain\Application Data\drivers\winupgro.exe"
Found ! [09/02/2009 12:26] - "C:\Documents and Settings\Alain\Application Data\drivers\downld"
Found ! - HKEY_USERS\S-1-5-21-3827332463-3573811099-851396786-1005\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_USERS\S-1-5-21-3827332463-3573811099-851396786-1005\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-3827332463-3573811099-851396786-1005\Software\FirtR
Found ! - HKEY_USERS\S-1-5-21-3827332463-3573811099-851396786-1005\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sK9Ou0s
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\FirtR
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | drvsyskit
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | german.exe
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | mule_st_key
/!\ Infection active : HKLM\SYSTEM\...\Services\srosa -> Start = 0x1
/!\ Infection active : HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1
9 févr. 2009 à 12:44
Pas de risques de passer à l'étape 2 : pas de risques d'effacer des fichiers nécéssaires? Merci
9 févr. 2009 à 13:02