Virus , utisation RSIT

Bonjour,
j'ai un problème, avec windows vista, plus d'accès a certaine application en autres Avast, Ccleaner, Windows defender.
Comment poster les rapport obtenu de RSIT???

Merci d'avance
Configuration: Windows Vista
Firefox 3.0.7

17 réponses

  1. Logfile of random's system information tool 1.05 (written by random/random)
    Run by yousndi at 2009-03-15 21:14:43
    Microsoft® Windows Vista™ Édition Familiale Basique Service Pack 1
    System drive C: has 97 GB (66%) free of 147 GB
    Total RAM: 894 MB (13% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:14:54, on 15/03/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\hp\support\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    C:\WINDOWS\RtHDVCpl.exe
    C:\Program Files\CyberLink\PowerCinema\PCMService.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\Windows Live\Family Safety\fsui.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
    C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
    C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\hp\kbd\kbd.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\conime.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\helppane.exe
    C:\Users\yousndi\Downloads\RSIT.exe
    C:\Program Files\trend micro\yousndi.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O1 - Hosts: ::1 localhost
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
    O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
    O4 - Startup: Outil de notification Live Search.lnk = C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O13 - Gopher Prefix:
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    0
    1. Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

      - Vas dans "Démarrer" puis Panneau de configuration.
      - Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
      - Clique sur Continuer.
      - Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
      - Valide par OK et redémarre.

      Tuto

      ensuite :

      Telecharge maintenant FindyKill sur ton bureau :

      http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

      --> Lance l installation avec les parametres par default

      --> Fais un clic droit sur le raccourci FindyKill sur ton bureau

      --> Choisi executer en tant qu administrateur

      --> Au menu principal,choisi l option 1 (Recherche)

      --> Post le rapport FindyKill.txt

      Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
      0
      1. ok merci vient de charger findykill

        Rapport:*
        ############################## [ FindyKill V4.720 ]

        # User : yousndi (Administrateurs) # PC-DE-YOUSNDI
        # Update on 12/03/09 by Chiquitine29
        # Start at: 23:46:11 | 15/03/2009

        # AMD Athlon(tm) 64 Processor 3800+
        # Microsoft© Windows VistaT dition Familiale Basique (6.0.6001 32-bit) # Service Pack 1
        # Internet Explorer 7.0.6001.18000
        # Windows Firewall Status : Disabled

        # C:\ # Disque fixe local # 143,42 Go (93,87 Go free) [COMPAQ] # NTFS
        # D:\ # Disque fixe local # 5,63 Go (596,71 Mo free) [Recovery] # NTFS
        # E:\ # Disque CD-ROM
        # F:\ # Disque amovible
        # G:\ # Disque amovible
        # H:\ # Disque amovible
        # I:\ # Disque amovible

        ############################## [ Processus actifs ]

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\nvvsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\rundll32.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
        C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
        C:\Program Files\Windows Live\Family Safety\fsssvc.exe
        c:\Program Files\Common Files\LightScribe\LSSrvc.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Windows\system32\WUDFHost.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\hp\support\hpsysdrv.exe
        C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
        C:\WINDOWS\RtHDVCpl.exe
        C:\Program Files\CyberLink\PowerCinema\PCMService.exe
        C:\WINDOWS\System32\rundll32.exe
        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
        C:\Program Files\Windows Live\Family Safety\fsui.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe
        C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
        C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
        C:\Program Files\Windows Live\Contacts\wlcomm.exe
        C:\Windows\system32\SearchProtocolHost.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Windows Live\Toolbar\wltuser.exe
        C:\hp\kbd\kbd.exe
        C:\Users\yousndi\AppData\Roaming\m\flec006.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Windows\system32\wintems.exe
        C:\Windows\system32\wbem\wmiprvse.exe

        ################## [ Processus infectieux stoppés ]

        "C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe" (3064)
        "C:\Users\yousndi\AppData\Roaming\m\flec006.exe" (2148)
        "C:\Windows\system32\wintems.exe" (1264)

        ################## [ Fichiers / Dossiers infectieux C:\ ]

        ################## [ C:\Windows ]

        ################## [ C:\Windows\system32 ]

        Found ! - C:\Windows\system32\mdelk.exe
        Found ! - C:\Windows\system32\wintems.exe
        Found ! - C:\Windows\system32\ban_list.txt

        ################## [ C:\Windows\system32\drivers ]

        Found ! - "C:\Windows\system32\drivers\down"

        ################## [ C:\.. Application Data ... ]

        Found ! - "C:\Users\yousndi\AppData\Roaming\m\flec006.exe"
        Found ! - "C:\Users\yousndi\AppData\Roaming\m\list.oct"
        Found ! - "C:\Users\yousndi\AppData\Roaming\m\data.oct"
        Found ! - "C:\Users\yousndi\AppData\Roaming\m\srvlist.oct"
        Found ! - "C:\Users\yousndi\AppData\Roaming\m\shared"
        Found ! - "C:\Users\yousndi\AppData\Roaming\m"
        Found ! - "C:\Users\yousndi\AppData\Roaming\drivers"
        Found ! - "C:\Users\yousndi\AppData\Roaming\drivers\srosa2.sys"
        Found ! - "C:\Users\yousndi\AppData\Roaming\drivers\wfsintwq.sys"
        Found ! - "C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe"
        Found ! - "C:\Users\yousndi\AppData\Roaming\drivers\downld"

        ################## [ Registre / Clés infectieuses ]

        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Local AppWizard-Generated Applications\msnmsgr
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Local AppWizard-Generated Applications\run
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Local AppWizard-Generated Applications\winupgro
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\bisoft
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\DateTime4
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\FFC
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\FirtR
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\MuleAppData
        Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\msnmsgr
        Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\run
        Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
        Found ! - HKEY_CURRENT_USER\Software\bisoft
        Found ! - HKEY_CURRENT_USER\Software\DateTime4
        Found ! - HKEY_CURRENT_USER\Software\FirtR
        Found ! - HKEY_CURRENT_USER\Software\MuleAppData
        Found ! - HKEY_CURRENT_USER\Software\FFC
        Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
        Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
        Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"

        # Infection active : HKLM\SYSTEM\...\Services\srosa -> Start = 0x1
        # Infection active : HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1

        ################## [ Recherche dans supports amovibles]

        # Presence des fichiers :

        ################## [ Registre / Mountpoint2 ]

        # -> Not found !

        ################## [ ! Fin du rapport # FindyKill V4.720 ! ]
        0
        1. Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

          --> Fais clic droit sur le raccourci FindyKill sur ton bureau

          --> Au menu principal,choisi l option 2 (Suppression)

          /!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

          /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

          -------> ensuite post le rapport FindyKill.txt

          Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
          0
          1. C cool! jviens de nettoyer! le PC a redémarré ensuite il ma m'y l'icone windows defender que j'avais plus depuis des jrs , la il me propose une analyse du disque.
            Pense tu que je vais pouvoir instller un antivurs maintenant , car j'avais avast et apparement pas top! le quel prendre ??

            PS: dernier rapport findykill

            ############################## [ FindyKill V4.720 ]

            # User : yousndi (Administrateurs) # PC-DE-YOUSNDI
            # Update on 12/03/09 by Chiquitine29
            # Start at: 00:05:23 | 16/03/2009

            # AMD Athlon(tm) 64 Processor 3800+
            # Microsoft© Windows VistaT dition Familiale Basique (6.0.6001 32-bit) # Service Pack 1
            # Internet Explorer 7.0.6001.18000
            # Windows Firewall Status : Disabled

            # C:\ # Disque fixe local # 143,42 Go (93,87 Go free) [COMPAQ] # NTFS
            # D:\ # Disque fixe local # 5,63 Go (596,71 Mo free) [Recovery] # NTFS
            # E:\ # Disque CD-ROM
            # F:\ # Disque amovible
            # G:\ # Disque amovible
            # H:\ # Disque amovible
            # I:\ # Disque amovible

            ############################## [ Active Processes ]

            C:\Windows\System32\smss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\nvvsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\rundll32.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\spoolsv.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
            C:\Program Files\Windows Live\Family Safety\fsssvc.exe
            c:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\SearchIndexer.exe
            C:\Windows\system32\WUDFHost.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\Dwm.exe
            C:\hp\support\hpsysdrv.exe
            C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
            C:\WINDOWS\RtHDVCpl.exe
            C:\Program Files\CyberLink\PowerCinema\PCMService.exe
            C:\WINDOWS\System32\rundll32.exe
            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
            C:\Program Files\Windows Live\Family Safety\fsui.exe
            C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
            C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\Windows Media Player\wmpnetwk.exe
            C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
            C:\Program Files\Windows Live\Contacts\wlcomm.exe
            C:\hp\kbd\kbd.exe
            C:\Windows\system32\conime.exe
            C:\Windows\system32\wbem\wmiprvse.exe

            ################## [ Infected Files / Folders C:\ ]

            ################## [ C:\Windows ]

            ################## [ C:\Windows\system32 ]

            Deleted ! - C:\Windows\system32\mdelk.exe
            Deleted ! - C:\Windows\system32\wintems.exe
            Deleted ! - C:\Windows\system32\ban_list.txt

            ################## [ C:\Windows\system32\drivers ]

            Deleted ! - "C:\Windows\system32\drivers\down"

            ################## [ C:\.. Application Data ... ]

            Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\flec006.exe"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\list.oct"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\data.oct"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\srvlist.oct"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\shared"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\m"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers\srosa2.sys"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers\wfsintwq.sys"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers\downld"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers"

            ################## [ Registry / Infected keys ]

            Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
            Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
            Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
            Deleted ! - HKEY_CURRENT_USER\Software\bisoft
            Deleted ! - HKEY_CURRENT_USER\Software\DateTime4
            Deleted ! - HKEY_CURRENT_USER\Software\FirtR
            Deleted ! - HKEY_CURRENT_USER\Software\MuleAppData
            Deleted ! - HKEY_CURRENT_USER\Software\FFC
            Deleted ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\msnmsgr
            Deleted ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
            Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\FFC
            Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\MuleAppData
            Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
            Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
            Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
            Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
            Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
            Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"

            ################## [ Cleaning Removable drives ]

            # Deleting files :

            ################## [ Registry / Mountpoint2 ]

            # -> Not found !

            ################## [ Searching Other Infections ]

            # Références de comparaison Bagle MD5 :

            File ... : C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe
            CRC32 .. : e435b851
            MD5 .... : 09a3f9484b015f6b094fe57edc03ead9

            # -> Nothing found.

            ################## [ PEH Corrupted ]

            C:\Program Files\Alwil Software\Avast4\ashAvast.exe
            C:\Program Files\Alwil Software\Avast4\ashChest.exe
            C:\Program Files\Alwil Software\Avast4\ashDisp.exe
            C:\Program Files\Alwil Software\Avast4\ashLogV.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashPopWz.exe
            C:\Program Files\Alwil Software\Avast4\ashQuick.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\Program Files\Alwil Software\Avast4\ashSimp2.exe
            C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
            C:\Program Files\Alwil Software\Avast4\ashSkPcc.exe
            C:\Program Files\Alwil Software\Avast4\ashSkPck.exe
            C:\Program Files\Alwil Software\Avast4\ashUpd.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\sched.exe
            C:\Program Files\Alwil Software\Avast4\VisthLic.exe
            C:\Program Files\Alwil Software\Avast4\VisthUpd.exe
            C:\Program Files\Mozilla Firefox\uninstall\helper.exe
            C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

            ################## [ ! End of Report # FindyKill V4.720 ! ]
            0
            1. non pas de suite :

              Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

              Télécharge MalwareByte's :
              Malwarebytes ou :
              Malwarebytes

              * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

              (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

              * Potasse le tuto pour te familiariser avec le prg :

              Tuto

              ( cela dis, il est très simple d'utilisation ).

              relance malwarebytes en suivant scrupuleusement ces consignes :

              ! Déconnecte toi et ferme toutes applications en cours !

              * Lance Malwarebyte's .

              Fais un examen dit "Complet" .

              --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
              --> à la fin tu cliques sur "résultat" .
              --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

              Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

              Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

              0
              1. ok thanks, bon jferais ca demain, jvais aller dodoter merci encore++
                0
                1. Slt, merci pour l'aide d'hier soir .
                  Du coup j'ai pu parer a mon soucis grace a Findykill, il a bien gérer les fichiers inféctés!
                  j'ai installé Antivir , mon pc a l'air de refonctionner normalement!
                  +++
                  0
                  1. je peux avoir le rapport de malwarebytes après suppression des nuisibles s'il te plait ?
                    0
                    1. Au faite je n'ai pas utilisé malwarebytes, j'ai directement chargé Findykill qui a supprimé les virus , et réactivé Windows defender!!!
                      0
                      1. que tu crois mais la desinfection n est pas finie a ce stade

                        et ca c est mort :

                        C:\Program Files\Alwil Software\Avast4\ashAvast.exe
                        C:\Program Files\Alwil Software\Avast4\ashChest.exe
                        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                        C:\Program Files\Alwil Software\Avast4\ashLogV.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashPopWz.exe
                        C:\Program Files\Alwil Software\Avast4\ashQuick.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\Program Files\Alwil Software\Avast4\ashSimp2.exe
                        C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
                        C:\Program Files\Alwil Software\Avast4\ashSkPcc.exe
                        C:\Program Files\Alwil Software\Avast4\ashSkPck.exe
                        C:\Program Files\Alwil Software\Avast4\ashUpd.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\sched.exe
                        C:\Program Files\Alwil Software\Avast4\VisthLic.exe
                        C:\Program Files\Alwil Software\Avast4\VisthUpd.exe
                        C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                        C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        0
                        1. Ah ok , jsavais pas. pourtant tout a l'air normal sauf que le démarrage de windows et un peu lent!
                          Donc la je telecharge malwarebytes, et jfais quoi ensuite???
                          0
                          1. oki jviens de faire un scan avec Malwarebytes'.

                            Rapport

                            Malwarebytes' Anti-Malware 1.34
                            Version de la base de données: 1855
                            Windows 6.0.6001 Service Pack 1

                            16/03/2009 21:54:27
                            mbam-log-2009-03-16 (21-54-27).txt

                            Type de recherche: Examen complet (C:\|D:\|)
                            Eléments examinés: 153011
                            Temps écoulé: 1 hour(s), 15 minute(s), 8 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 0
                            Valeur(s) du Registre infectée(s): 0
                            Elément(s) de données du Registre infecté(s): 0
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 0

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Valeur(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Elément(s) de données du Registre infecté(s):
                            (Aucun élément nuisible détecté)

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            (Aucun élément nuisible détecté)
                            0
                            1. ok pour l antivirus :

                              Passer de Avast à AntiVir :

                              Désinstalle via Ajout/Suppression de Programmes (si présents) :

                              * Avast!

                              Télécharge et exécute le Désinstalleur d'Avast!.:

                              Ceci effacera la majorité des traces du produit Avast! d'Alwil Software.

                              Télécharge Ccleaner sur ton Bureau. :

                              * Clique sur "download the latest version"
                              * Installe-le en laissant seulement les options suivantes cochées :

                              - Ajouter un raccourci sur le Bureau
                              - Contrôler automatiquement les mises à jour de CCleaner

                              * Lance le Nettoyage
                              * Clique sur Chercher des erreurs et sauvegarde si tu le souhaites.

                              plus de precision sur la configuration de ccleaner te seront donnees plus tard

                              tuto : Comment utiliser CCleaner.
                              ***************

                              Télécharge Antivir en Francais ou :Antivir en Francais sur ton Bureau.:

                              * Double clique sur l'exécutable téléchargé pour lancer l'installation.
                              * À la fin de l'installation, clique sur Finish.
                              * Ouvre Antivir, assure-toi qu’il soit bien à jour !
                              * Dans l'onglet Protection Locale, choisis Contrôler.
                              * Active la recherche de rootkits via le + de Recherche de Rootkits, puis dans Sélection manuelle, coche tout (tes partitions de disque dur).
                              * Clique sur la loupe du milieu pour lancer le scan en tant qu'Administrateur.
                              * Poste moi le rapport généré : Pour cela, clique sur l'onglet Aperçu, puis choisis Rapports, tu trouveras son rapport..
                              * Sélectionne le rapport et clique sur l'icône "Afficher le fichier de rapport du rapport sélectionné.

                              Note : Pour une éradication des menaces plus efficace, lance le scan en mode sans échec.

                              Pourquoi changer ? :Avast Vs Antivir

                              Tuto Antivir: Comment installer et utiliser AntiVir.

                              Configuration de Antivir (Merci Nico) :

                              clic droit sur son icone dans la barre des taches et séléctionner Configurer Antivir.

                              cocher la case : Mode Expert.

                              => Cliquer sur Scanner dans le volet de gauche :

                              > Dans "Fichiers" séléctionner Tous les fichiers.

                              > Dans procédure de recherche, cocher Autoriser l'arrêt, et dans "priorité scanner" séléctionner Elevé.

                              > Dans "Autres réglages" cocher toutes les cases.

                              NE SURTOUT PAS OUBLIER LA RECHERCHE DES ROOTKIT QUI EST TRES IMPORTANTE !

                              => Cliquer sur "Recherche" dans le volet de gauche et appliquer les mêmes paramètres que précédemment.

                              => Dérouler "Recherche" en cliquant sur le +. Cliquer sur "Heuristique" :

                              > Cocher "Heuristique de MacroVirus" et "Heuristique fichier Win32" avec degré d'indentification ELEVE !

                              => Dans le volet de gauche, dérouler "Guard" puis dérouler "Recherche" :

                              > Cocher "Heuristique de MacroVirus" et "Heuristique fichier Win32" avec degré d'identification ELEVE !

                              0