Virus Bagle

Bonjour,

j'ai le virus Rookit Bagle j'aimerai savoir comment le supprimer, je ne peu plus utilisé spybot ni ad aware ni antivir! Je l'ai détecté avec malawarebytes!
J'ai vraiment besoin d'aide SVP! Merci.

--
L'homme mourra moins bête quand il aura pris conscience que nous sommes que les pions de 1% de la planète
Configuration: Windows Vista
Firefox 2.0.0.18

47 réponses

Résumé de la discussion

L'infection par un cheval de Troie rookit (Bagle) empêche l'accès normal aux outils de sécurité et peut être détectée par Malwarebytes, nécessitant une méthode de suppression adaptée sous Windows Vista. Des répondants recommandent FindyKill V4.706 comme solution principale, pour lancer l’outil et choisir l’option 2 (Suppression) après branchement des disques amovibles, avec deux redémarrages et la consultation du fichier FindyKill.txt. D'autres réponses évoquent des avis mitigés sur FindyKill et proposent des solutions comme réinstaller les applications infectées ou lancer un scan en ligne, certains signalant des difficultés d'accès aux antivirus. Le rapport FindyKill.txt est sauvegardé à la racine du disque et peut être transmis à un support technique, précisant les éléments infectés et les actions réalisées durant le processus.

Bobot (l’IA à votre service)
  1. Bonsoir,

    Désactive le « contrôle des comptes utilisateurs = UAC »
    (tu le réactiveras après ta désinfection): Ne pas oublier !!
    Désactiver l'UAC est nécessaire pour pouvoir faire fonctionner certains programmes sous Vista.
    - Vas dans Démarrer puis panneau de configuration
    - Double Clique sur l'icône "Comptes d'utilisateurs"
    - Clique ensuite sur désactiver et valide.

    ▶ Télécharges FindyKill de Chiquitine29

    ▶ Fais un clique droit sur le lien et choisis "enregistrer la cible sous ...." , destination le bureau .

    http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

    ▶ Note importante : si tu as le prg Elibagla sur ton PC , supprimes le ( risque de conflit entre les deux outils ) .

    ▶ Entre dans le dossier " FindyKill "

    ▶ Double clic sur " FindyKill.bat " (et pas sur autre chose!) pour lancer l'outil .

    ▶ Choisis l'option 1 . Puis laisses travailler ...

    ▶ Une fois terminé, postes le rapport FindyKill.txt qui est généré ...

    ( Note : le rapport est sauvegardé à la racine du disque -> C:\FindyKill.txt )
    0
    1. Je n'arrive pas à désactivé l'UAC je coche la case pourtant, windows me demande même pas de redemarrer, je l'avais pourtant déjà fait!
      0
      1. Re,

        Alors télécharge "findykill" et ensuite clic droit sur l'icône qui sera sur ton bureau et "exécute en tant qu'administrateur".

        @+
        0
        1. ----------------- FindyKill V4.706 ------------------

          * User : Squatt - PC-DE-SQUATT
          * Emplacement : C:\Program Files\FindyKill
          * Outils Mis a jours le 27/11/08 par Chiquitine29
          * Recherche effectuée à 19:45:10 le 05/12/2008
          * Windows Vista - Internet Explorer 7.0.6001.18000

          ((((((((((((((((( *** Recherche *** ))))))))))))))))))

          --------------- [ Processus actifs ] ----------------

          C:\Windows\System32\smss.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\wininit.exe
          C:\Windows\system32\csrss.exe
          C:\Windows\system32\services.exe
          C:\Windows\system32\lsass.exe
          C:\Windows\system32\lsm.exe
          C:\Windows\system32\winlogon.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\nvvsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\SLsvc.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\rundll32.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\spoolsv.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\system32\Dwm.exe
          C:\Windows\system32\taskeng.exe
          C:\Windows\RtHDVCpl.exe
          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
          C:\Program Files\Bonjour\mDNSResponder.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Common Files\LightScribe\LSSrvc.exe
          C:\Windows\System32\rundll32.exe
          C:\Windows\System32\svchost.exe
          C:\Program Files\CDBurnerXP\NMSAccessU.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\svchost.exe
          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
          C:\Program Files\Windows Media Player\wmpnscfg.exe
          C:\Windows\ehome\ehtray.exe
          C:\Program Files\Free Download Manager\fdm.exe
          C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
          C:\Windows\system32\svchost.exe
          C:\Windows\System32\svchost.exe
          C:\Windows\system32\SearchIndexer.exe
          C:\Windows\ehome\ehmsas.exe
          C:\Program Files\Windows Sidebar\sidebar.exe
          C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
          C:\Program Files\Windows Media Player\wmpnetwk.exe
          C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
          C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
          C:\Windows\system32\SearchProtocolHost.exe
          C:\Windows\system32\SearchFilterHost.exe
          C:\Program Files\Windows Live\Messenger\usnsvc.exe
          C:\Program Files\Mozilla Firefox\firefox.exe
          C:\Windows\explorer.exe
          C:\Windows\system32\conime.exe

          --------------- [ Fichiers/Dossiers infectieux ] ----------------

          »»»» Presence des fichiers dans C:

          »»»» Presence des fichiers dans C:\Windows

          »»»» Presence des fichiers dans C:\Windows\Prefetch

          »»»» Presence des fichiers dans C:\Windows\system32

          »»»» Presence des fichiers dans C:\Windows\system32\drivers

          Found ! [05/12/2008 18:22] - C:\Windows\system32\drivers\srosa2.sys
          Found ! [21/04/2005 09:01] - C:\Windows\system32\drivers\winfilse.exe

          »»»» Presence des fichiers dans C:\Users\Squatt\AppData\Roaming

          »»»» Presence des fichiers dans C:\Users\Squatt\AppData\Local\Temp

          »»»» Presence des fichiers dans C:\Users\Squatt\Local Settings\Temporary Internet Files\Content.IE5

          Found ! [05/12/2008 17:02] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\04QK0A4P\b64_2[1].jpg
          Found ! [05/12/2008 17:01] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\04QK0A4P\b64_3[1].jpg
          Found ! [05/12/2008 08:55] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1SU7052H\b64[1].jpg
          Found ! [04/12/2008 11:43] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1SU7052H\b64_1[1].jpg
          Found ! [05/12/2008 18:25] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1SU7052H\b64_2[1].jpg
          Found ! [05/12/2008 08:54] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1SU7052H\b64_3[1].jpg
          Found ! [05/12/2008 12:58] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1SU7052H\b64_3[2].jpg
          Found ! [05/12/2008 18:00] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1SU7052H\b64_3[3].jpg
          Found ! [04/12/2008 17:09] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1SU7052H\IKPHCAQB90J1CAYQ3QM3CAG68KVZCAOZCG6RCAMJDNEYCA64MFHDCAWZUG6ACAEDZ47NCAQOWMQ3CA9O3XL9CA69EPHUCAHINDJRCAO2BMIJCAGL1NWCCAGO425FCADMEX3LCA3FBQ56CAJY9B64CAWCP2WT.jpg
          Found ! [05/12/2008 17:02] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5LE00232\b64[1].jpg
          Found ! [05/12/2008 18:25] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6RH7MURF\b64[1].jpg
          Found ! [04/12/2008 23:36] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6RH7MURF\b64[2].jpg
          Found ! [04/12/2008 15:47] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6RH7MURF\b64_1[1].jpg
          Found ! [05/12/2008 17:59] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6RH7MURF\b64_1[2].jpg
          Found ! [04/12/2008 15:48] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6RH7MURF\b64_2[1].jpg
          Found ! [05/12/2008 03:39] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6RH7MURF\b64_2[2].jpg
          Found ! [05/12/2008 18:01] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6RH7MURF\b64_2[3].jpg
          Found ! [04/12/2008 15:48] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7S6045EM\b64[1].jpg
          Found ! [05/12/2008 12:57] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7S6045EM\b64_3[1].jpg
          Found ! [05/12/2008 17:01] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GJ90LHHR\b64_1[1].jpg
          Found ! [05/12/2008 17:01] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SG7PZ00Q\b64_2[1].jpg
          Found ! [04/12/2008 17:11] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9KY5CCK\242YCAXWN0WHCAC019MMCASQ3V8GCAXYIXROCAOB64YHCANP3P2BCAFSX7FHCA1QLBB4CAYCE00CCACWTJHICAXIPYDCCA0DPPRECA6Y5XC9CA9CH85JCAUAX7PLCAJL81FCCAEHNL1ICA4OWQBJCA2WCZ5X.jpg
          Found ! [04/12/2008 15:49] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9KY5CCK\b64[1].jpg
          Found ! [04/12/2008 19:33] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9KY5CCK\b64[2].jpg
          Found ! [05/12/2008 03:40] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9KY5CCK\b64[3].jpg
          Found ! [05/12/2008 08:55] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9KY5CCK\b64[4].jpg
          Found ! [05/12/2008 18:26] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9KY5CCK\b64[5].jpg
          Found ! [04/12/2008 23:35] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9KY5CCK\b64_1[1].jpg
          Found ! [05/12/2008 03:38] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9KY5CCK\b64_1[2].jpg
          Found ! [05/12/2008 12:57] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9KY5CCK\b64_1[3].jpg
          Found ! [04/12/2008 19:32] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9KY5CCK\b64_2[1].jpg
          Found ! [04/12/2008 23:36] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9KY5CCK\b64_2[2].jpg
          Found ! [04/12/2008 19:32] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9KY5CCK\b64_3[1].jpg
          Found ! [05/12/2008 08:55] - C:\Users\Squatt\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T9KY5CCK\b64_3[2].jpg

          --------------- [ Registre / Startup ] ----------------

          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

          Sidebar=C:\Program Files\Windows Sidebar\sidebar.exe
          SmpcSys=C:\Program Files\Packard Bell\SetUpMyPC\SmpSys.exe
          MsnMsgr="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
          WindowsWelcomeCenter=rundll32.exe oobefldr.dll,ShowWelcomeCenter
          WMPNSCFG=C:\Program Files\Windows Media Player\WMPNSCFG.exe
          ehTray.exe=C:\Windows\ehome\ehTray.exe
          Free Download Manager="C:\Program Files\Free Download Manager\fdm.exe" -autorun
          ISUSPM="C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -scheduler

          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]

          Windows Defender="C:\Program Files\Windows Defender\MSASCui.exe" -hide
          RtHDVCpl=RtHDVCpl.exe
          <NO NAME>=
          RoxWatchTray="C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
          Google Desktop Search="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
          toolbar_eula_launcher="C:\Program Files\Packard Bell\GOOGLE_EULA\EULALauncher.exe"
          SpywareTerminator="C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
          NWEReboot=
          TkBellExe="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
          QuickTime Task="C:\Program Files\QuickTime\QTTask.exe" -atboottime
          iTunesHelper="C:\Program Files\iTunes\iTunesHelper.exe"
          HP Software Update=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
          hpqSRMon=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
          NvCplDaemon=RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
          NvMediaCenter=RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
          avgnt="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
          Adobe Reader Speed Launcher="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
          SunJavaUpdateSched="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
          Malwarebytes Anti-Malware (reboot)="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
          HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
          <NO NAME>=
          HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
          Installed=1
          <NO NAME>=
          HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
          NoChange=1
          Installed=1
          <NO NAME>=
          HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
          Installed=1
          <NO NAME>=

          [HKEY_CURRENT_USER\software\local appwizard-generated applications\Corel Snapfire 1]
          [HKEY_CURRENT_USER\software\local appwizard-generated applications\DestComp]
          [HKEY_CURRENT_USER\software\local appwizard-generated applications\playplus]
          [HKEY_CURRENT_USER\software\local appwizard-generated applications\Producer]
          [HKEY_CURRENT_USER\software\local appwizard-generated applications\SmpSys]
          [HKEY_CURRENT_USER\software\local appwizard-generated applications\vscap]
          [HKEY_CURRENT_USER\software\local appwizard-generated applications\winfilse]

          --------------- [ Registre / Clés infectieuses ] ----------------

          Found ! - HKEY_USERS\S-1-5-21-329090536-52843620-3910971160-1002\Software\Local AppWizard-Generated Applications\winfilse
          Found ! - HKEY_USERS\S-1-5-21-329090536-52843620-3910971160-1002\Software\FFC
          Found ! - HKEY_USERS\S-1-5-21-329090536-52843620-3910971160-1002\Software\FirtR
          Found ! - HKEY_USERS\S-1-5-21-329090536-52843620-3910971160-1002\Software\MuleAppData
          Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winfilse
          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
          Found ! - HKEY_CURRENT_USER\Software\FirtR
          Found ! - HKEY_CURRENT_USER\Software\MuleAppData
          Found ! - HKEY_CURRENT_USER\Software\FFC
          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s

          --------------- [ Etat / Services ] ----------------

          +- Services : [ Auto=2 / Demande=3 / Désactivé=4 ]

          /!\ Ndisuio - Type de démarrage = 4

          EapHost - Type de démarrage = 3

          Wlansvc - Type de démarrage = 3

          SharedAccess - Type de démarrage = 2

          wuauserv - Type de démarrage = 2

          /!\ wscsvc - Type de démarrage = 4

          /!\ WinDefend - Type de démarrage = 4

          --------------- [ Recherche dans supports amovibles] ----------------

          +- Informations :

          C: - Lecteur fixe

          +- presence des fichiers :

          --------------- [ Registre / Mountpoint2 ] ----------------

          -> Not found !

          ------------------- ! Fin du rapport ! --------------------

          0
          1. Re,

            Ok:

            Findykill de chiquitine29 option 2:

            ▶ Branche tes disques amovibles à ton PC (clefs USB, disque dur externe, etc...) sans les ouvrir

            ▶ Double-clique sur le raccourci FindyKill sur ton bureau

            ▶ Au menu principal, choisis l'option 2 (Suppression)

            /!\ Il y aura 2 redémarrages, laisse travailler l'outil jusqu'à l'apparition du message "nettoyage effectué" /!\

            ▶ Ensuite, poste le rapport FindyKill.txt

            Note : le rapport FindyKill.txt est sauvegardé à la racine du disque.

            @+
            0
            1. Au risque de te parraitre bête je ne comprend pas "▶ Branche tes disques amovibles à ton PC (clefs USB, disque dur externe, etc...) sans les ouvrir"
              je les branche comment?
              0
              1. Re,

                Branche tes disques amovibles à ton PC (clefs USB, disque dur externe, etc...) sans les ouvrir

                Tu as bien des clés ou autres prises USB => tu les branches dessus (ton pc ) et tu fait le l'option 2.

                @+
                0
                1. Il ne se passe rien! Quand je fait l'option 2 y'a écris accès refuser puis l'ordi redémarre aussitôt et qu'un seule fois!!!
                  0
                  1. Re,

                    OKI.

                    Alors regarde dans poste de travail et ton disque le "dct txt de findykill" si tu ne le trouve pas recommence l'option 2 .

                    merci.

                    @+
                    0
                    1. Toujours pareil!!! Rien du tout et encore "accès refusé"
                      0
                      1. Ren

                        Bon.

                        Supprime findykill et fait ceci STP.

                        ▶ Rends toi sur ce site :
                        http://www.zonavirus.com/datos/descargas/95/elibagla.asp
                        ▶ tout en bas de cette page tu trouveras un outil
                        à télécharger,clique sur "escargar Elibagla" (le numéro de version change au fur et à mesure des mises à jour)
                        ▶ installe ce fichier sur le Bureau.
                        ▶ ensuite double-clic sur Elibagla.exe
                        ▶ laisse la case "eliminar ficheros automaticamente" coché
                        ▶ clique sur"explorar"
                        ▶ laisse-le travailler

                        ▶ Redémarre en mode sans échec,

                        *Pour cela, tu tapotes la touche F8 dès le début de l’allumage du pc sans t’arrêter.
                        Une fenêtre va s’ouvrir tu te déplaces avec les flèches du clavier sur démarrer en mode sans échec puis tape entrée.
                        Une fois sur le bureau s’il n’y a pas toutes les couleurs et autres c’est normal !
                        (Si F8 ne marche pas utilise la touche F5).

                        ▶ relance 2 fois elibagla

                        ▶ redémarre en mode normal

                        ▶ poste le rapport final qui sera dans c:\infosat.txt
                        0
                        1. Salut destrio5,te laisse finir ce nouveau cas si tu veut.

                          @+
                          0
                          1. Modérateur
                            Il a Vista donc pour lancer FindyKill, il faut cliquer droit sur FindyKill et choisir Exécuter en tant qu'administrateur.
                            0
                            1. Salut Destrio! Désolé de ne pas avoir donné suite il y a que 2 jours que j'ai internet suite à mon déménagement! Puis un manque de temps ses 2 jours! Vraiment désolé.

                              Pour le reste je ferai ça plus tard, je dois partir la! Merci à vous!
                              0
                              1. Re,

                                Oui quel bête que je suis il est sous vista !!!

                                Te laisse finir alors "destrio5".

                                @+

                                Bon courage.
                                0
                                1. Voilà j'ai donc supprimer avec findykill en tant qu'administrateur! Le rapport m'a donné ça :

                                  ----------------- FindyKill V4.706 ------------------

                                  * User : Squatt - PC-DE-SQUATT
                                  * executed from : C:\Program Files\FindyKill
                                  * Update on 27/11/08 par Chiquitine29
                                  * Start at 22:37:34 the 05/12/2008
                                  * Windows Vista - Internet Explorer 7.0.6001.18000

                                  ((((((((((((((( *** deleting *** ))))))))))))))))))

                                  --------------- [ Active Processes ] ----------------

                                  C:\Windows\System32\smss.exe
                                  C:\Windows\system32\csrss.exe
                                  C:\Windows\system32\wininit.exe
                                  C:\Windows\system32\csrss.exe
                                  C:\Windows\system32\services.exe
                                  C:\Windows\system32\lsass.exe
                                  C:\Windows\system32\lsm.exe
                                  C:\Windows\system32\winlogon.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\nvvsvc.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\SLsvc.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\rundll32.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\System32\spoolsv.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Windows\system32\Dwm.exe
                                  C:\Windows\system32\taskeng.exe
                                  C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                                  C:\Program Files\Bonjour\mDNSResponder.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Program Files\Common Files\LightScribe\LSSrvc.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Program Files\CDBurnerXP\NMSAccessU.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
                                  C:\Windows\system32\svchost.exe
                                  C:\Windows\System32\svchost.exe
                                  C:\Windows\system32\SearchIndexer.exe
                                  C:\Windows\system32\SearchProtocolHost.exe
                                  C:\Windows\system32\SearchFilterHost.exe
                                  C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                                  C:\Windows\system32\wbem\wmiprvse.exe
                                  C:\Windows\system32\DllHost.exe
                                  C:\Windows\system32\runonce.exe
                                  C:\Windows\system32\conime.exe

                                  --------------- [ Infected files / folders ] ----------------

                                  »»»» Supression files in C:

                                  »»»» Supression files in C:\Windows

                                  »»»» Supression files in C:\Windows\Prefetch

                                  »»»» Supression files in C:\Windows\system32

                                  »»»» Supression files in C:\Windows\system32\drivers

                                  Deleted ! - C:\Windows\system32\drivers\srosa.sys
                                  Deleted ! - C:\Windows\system32\drivers\srosa2.sys
                                  Deleted ! - C:\Windows\system32\drivers\winfilse.exe

                                  »»»» Supression files in C:\Users\Squatt\AppData\Roaming

                                  Deleted ! - "C:\Users\Squatt\AppData\Roaming\inst.exe"

                                  »»»» Supression files in C:\Users\Squatt\AppData\Local\Temp

                                  »»»» Supression files in C:\Users\Squatt\Local Settings\Temporary Internet Files\Content.IE5

                                  --------------- [ Registry / Infected keys ] ----------------

                                  Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
                                  Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
                                  Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
                                  Deleted ! - HKEY_USERS\S-1-5-21-329090536-52843620-3910971160-1002\Software\Local AppWizard-Generated Applications\winfilse
                                  Deleted ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winfilse

                                  --------------- [ States / Restarting of services ] ----------------

                                  +- Services : [ Auto=2 / Request=3 / Disable=4 ]

                                  Ndisuio - Type of startup = 3

                                  EapHost - Type of startup = 2

                                  Wlansvc - Type of startup = 2

                                  SharedAccess - Type of startup = 2

                                  wuauserv - Type of startup = 2

                                  wscsvc - Type of startup = 2

                                  WinDefend - Type of startup = 2

                                  --------------- [ Cleaning removable drives ] ----------------

                                  +- Informations :

                                  C: - Lecteur fixe

                                  +- deleting files :

                                  --------------- [ Registry / Mountpoint2 ] ----------------

                                  -> Not found !

                                  --------------- [ Searching Cracks / Keygen ] ----------------

                                  C:\Users\Squatt\Music\Rap Fran‡ais\Assassin - Squat\Ma 6-T va cracker - ASSASSIN 'L'ile de l'inconscient'.mp3

                                  ---------------- ! End of report ! ------------------
                                  0
                                  1. Modérateur
                                    Bien.

                                    ---> Télécharge ComboFix.exe de sUBs sur ton Bureau :
                                    http://download.bleepingcomputer.com/sUBs/ComboFix.exe

                                    /!\ Déconnecte-toi du net et ferme toutes les applications, antivirus et antispyware y compris /!\

                                    ---> Clique droit sur Combofix.exe et choisis Exécuter en tant qu'administrateur.
                                    Un "pop-up" va apparaître qui dit que "ComboFix est utilisé à vos risques et avec aucune garantie...".
                                    Accepte en cliquant sur "Oui"

                                    ---> Mets-le en langue française F
                                    Tape sur la touche 1 (Yes) pour démarrer le scan.

                                    /!\ Ne touche à rien tant que le scan n'est pas terminé. /!\

                                    En fin de scan, il est possible que ComboFix ait besoin de redémarrer le PC pour finaliser la désinfection, laisse-le faire.

                                    Une fois le scan achevé, un rapport va s'afficher : Poste son contenu

                                    /!\ Réactive la protection en temps réel de ton antivirus et de ton antispyware avant de te reconnecter à Internet. /!\

                                    Note : Le rapport se trouve également là : C:\ComboFix\Combofix.txt
                                    0
                                    1. Comment je désactive mes antispyware et mon antivirus? je peu pas y accedé j'ai des messages d'erreurs à chaque fois les programmes ne s'ouvrent pas!
                                      0
                                      • 1
                                      • 2
                                      • 3