Virus , utisation RSIT

Bonjour,
j'ai un problème, avec windows vista, plus d'accès a certaine application en autres Avast, Ccleaner, Windows defender.
Comment poster les rapport obtenu de RSIT???

Merci d'avance
Configuration: Windows Vista
Firefox 3.0.7

17 réponses

  1. ok pour l antivirus :

    Passer de Avast à AntiVir :

    Désinstalle via Ajout/Suppression de Programmes (si présents) :

    * Avast!

    Télécharge et exécute le Désinstalleur d'Avast!.:

    Ceci effacera la majorité des traces du produit Avast! d'Alwil Software.

    Télécharge Ccleaner sur ton Bureau. :

    * Clique sur "download the latest version"
    * Installe-le en laissant seulement les options suivantes cochées :

    - Ajouter un raccourci sur le Bureau
    - Contrôler automatiquement les mises à jour de CCleaner

    * Lance le Nettoyage
    * Clique sur Chercher des erreurs et sauvegarde si tu le souhaites.

    plus de precision sur la configuration de ccleaner te seront donnees plus tard

    tuto : Comment utiliser CCleaner.
    ***************

    Télécharge Antivir en Francais ou :Antivir en Francais sur ton Bureau.:

    * Double clique sur l'exécutable téléchargé pour lancer l'installation.
    * À la fin de l'installation, clique sur Finish.
    * Ouvre Antivir, assure-toi qu’il soit bien à jour !
    * Dans l'onglet Protection Locale, choisis Contrôler.
    * Active la recherche de rootkits via le + de Recherche de Rootkits, puis dans Sélection manuelle, coche tout (tes partitions de disque dur).
    * Clique sur la loupe du milieu pour lancer le scan en tant qu'Administrateur.
    * Poste moi le rapport généré : Pour cela, clique sur l'onglet Aperçu, puis choisis Rapports, tu trouveras son rapport..
    * Sélectionne le rapport et clique sur l'icône "Afficher le fichier de rapport du rapport sélectionné.

    Note : Pour une éradication des menaces plus efficace, lance le scan en mode sans échec.

    Pourquoi changer ? :Avast Vs Antivir

    Tuto Antivir: Comment installer et utiliser AntiVir.

    Configuration de Antivir (Merci Nico) :

    clic droit sur son icone dans la barre des taches et séléctionner Configurer Antivir.

    cocher la case : Mode Expert.

    => Cliquer sur Scanner dans le volet de gauche :

    > Dans "Fichiers" séléctionner Tous les fichiers.

    > Dans procédure de recherche, cocher Autoriser l'arrêt, et dans "priorité scanner" séléctionner Elevé.

    > Dans "Autres réglages" cocher toutes les cases.

    NE SURTOUT PAS OUBLIER LA RECHERCHE DES ROOTKIT QUI EST TRES IMPORTANTE !

    => Cliquer sur "Recherche" dans le volet de gauche et appliquer les mêmes paramètres que précédemment.

    => Dérouler "Recherche" en cliquant sur le +. Cliquer sur "Heuristique" :

    > Cocher "Heuristique de MacroVirus" et "Heuristique fichier Win32" avec degré d'indentification ELEVE !

    => Dans le volet de gauche, dérouler "Guard" puis dérouler "Recherche" :

    > Cocher "Heuristique de MacroVirus" et "Heuristique fichier Win32" avec degré d'identification ELEVE !

    0
    1. oki jviens de faire un scan avec Malwarebytes'.

      Rapport

      Malwarebytes' Anti-Malware 1.34
      Version de la base de données: 1855
      Windows 6.0.6001 Service Pack 1

      16/03/2009 21:54:27
      mbam-log-2009-03-16 (21-54-27).txt

      Type de recherche: Examen complet (C:\|D:\|)
      Eléments examinés: 153011
      Temps écoulé: 1 hour(s), 15 minute(s), 8 second(s)

      Processus mémoire infecté(s): 0
      Module(s) mémoire infecté(s): 0
      Clé(s) du Registre infectée(s): 0
      Valeur(s) du Registre infectée(s): 0
      Elément(s) de données du Registre infecté(s): 0
      Dossier(s) infecté(s): 0
      Fichier(s) infecté(s): 0

      Processus mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Module(s) mémoire infecté(s):
      (Aucun élément nuisible détecté)

      Clé(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Valeur(s) du Registre infectée(s):
      (Aucun élément nuisible détecté)

      Elément(s) de données du Registre infecté(s):
      (Aucun élément nuisible détecté)

      Dossier(s) infecté(s):
      (Aucun élément nuisible détecté)

      Fichier(s) infecté(s):
      (Aucun élément nuisible détecté)
      0
      1. Ah ok , jsavais pas. pourtant tout a l'air normal sauf que le démarrage de windows et un peu lent!
        Donc la je telecharge malwarebytes, et jfais quoi ensuite???
        0
        1. que tu crois mais la desinfection n est pas finie a ce stade

          et ca c est mort :

          C:\Program Files\Alwil Software\Avast4\ashAvast.exe
          C:\Program Files\Alwil Software\Avast4\ashChest.exe
          C:\Program Files\Alwil Software\Avast4\ashDisp.exe
          C:\Program Files\Alwil Software\Avast4\ashLogV.exe
          C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
          C:\Program Files\Alwil Software\Avast4\ashPopWz.exe
          C:\Program Files\Alwil Software\Avast4\ashQuick.exe
          C:\Program Files\Alwil Software\Avast4\ashServ.exe
          C:\Program Files\Alwil Software\Avast4\ashSimp2.exe
          C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
          C:\Program Files\Alwil Software\Avast4\ashSkPcc.exe
          C:\Program Files\Alwil Software\Avast4\ashSkPck.exe
          C:\Program Files\Alwil Software\Avast4\ashUpd.exe
          C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
          C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe
          C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
          C:\Program Files\Alwil Software\Avast4\sched.exe
          C:\Program Files\Alwil Software\Avast4\VisthLic.exe
          C:\Program Files\Alwil Software\Avast4\VisthUpd.exe
          C:\Program Files\Mozilla Firefox\uninstall\helper.exe
          C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
          C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
          0
          1. Au faite je n'ai pas utilisé malwarebytes, j'ai directement chargé Findykill qui a supprimé les virus , et réactivé Windows defender!!!
            0
            1. je peux avoir le rapport de malwarebytes après suppression des nuisibles s'il te plait ?
              0
              1. Slt, merci pour l'aide d'hier soir .
                Du coup j'ai pu parer a mon soucis grace a Findykill, il a bien gérer les fichiers inféctés!
                j'ai installé Antivir , mon pc a l'air de refonctionner normalement!
                +++
                0
                1. ok thanks, bon jferais ca demain, jvais aller dodoter merci encore++
                  0
                  1. non pas de suite :

                    Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

                    Télécharge MalwareByte's :
                    Malwarebytes ou :
                    Malwarebytes

                    * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

                    (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

                    * Potasse le tuto pour te familiariser avec le prg :

                    Tuto

                    ( cela dis, il est très simple d'utilisation ).

                    relance malwarebytes en suivant scrupuleusement ces consignes :

                    ! Déconnecte toi et ferme toutes applications en cours !

                    * Lance Malwarebyte's .

                    Fais un examen dit "Complet" .

                    --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
                    --> à la fin tu cliques sur "résultat" .
                    --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

                    Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

                    Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

                    0
                    1. C cool! jviens de nettoyer! le PC a redémarré ensuite il ma m'y l'icone windows defender que j'avais plus depuis des jrs , la il me propose une analyse du disque.
                      Pense tu que je vais pouvoir instller un antivurs maintenant , car j'avais avast et apparement pas top! le quel prendre ??

                      PS: dernier rapport findykill

                      ############################## [ FindyKill V4.720 ]

                      # User : yousndi (Administrateurs) # PC-DE-YOUSNDI
                      # Update on 12/03/09 by Chiquitine29
                      # Start at: 00:05:23 | 16/03/2009

                      # AMD Athlon(tm) 64 Processor 3800+
                      # Microsoft© Windows VistaT dition Familiale Basique (6.0.6001 32-bit) # Service Pack 1
                      # Internet Explorer 7.0.6001.18000
                      # Windows Firewall Status : Disabled

                      # C:\ # Disque fixe local # 143,42 Go (93,87 Go free) [COMPAQ] # NTFS
                      # D:\ # Disque fixe local # 5,63 Go (596,71 Mo free) [Recovery] # NTFS
                      # E:\ # Disque CD-ROM
                      # F:\ # Disque amovible
                      # G:\ # Disque amovible
                      # H:\ # Disque amovible
                      # I:\ # Disque amovible

                      ############################## [ Active Processes ]

                      C:\Windows\System32\smss.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\wininit.exe
                      C:\Windows\system32\csrss.exe
                      C:\Windows\system32\services.exe
                      C:\Windows\system32\lsass.exe
                      C:\Windows\system32\lsm.exe
                      C:\Windows\system32\winlogon.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\nvvsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\SLsvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\system32\rundll32.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\spoolsv.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                      C:\Program Files\Bonjour\mDNSResponder.exe
                      C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                      C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                      C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                      c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                      C:\Windows\system32\svchost.exe
                      C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                      C:\Windows\system32\svchost.exe
                      C:\Windows\System32\svchost.exe
                      C:\Windows\system32\SearchIndexer.exe
                      C:\Windows\system32\WUDFHost.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\taskeng.exe
                      C:\Windows\system32\Dwm.exe
                      C:\hp\support\hpsysdrv.exe
                      C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                      C:\WINDOWS\RtHDVCpl.exe
                      C:\Program Files\CyberLink\PowerCinema\PCMService.exe
                      C:\WINDOWS\System32\rundll32.exe
                      C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                      C:\Program Files\Windows Live\Family Safety\fsui.exe
                      C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
                      C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
                      C:\Program Files\Windows Media Player\wmpnscfg.exe
                      C:\Program Files\Windows Media Player\wmpnetwk.exe
                      C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
                      C:\Program Files\Windows Live\Contacts\wlcomm.exe
                      C:\hp\kbd\kbd.exe
                      C:\Windows\system32\conime.exe
                      C:\Windows\system32\wbem\wmiprvse.exe

                      ################## [ Infected Files / Folders C:\ ]

                      ################## [ C:\Windows ]

                      ################## [ C:\Windows\system32 ]

                      Deleted ! - C:\Windows\system32\mdelk.exe
                      Deleted ! - C:\Windows\system32\wintems.exe
                      Deleted ! - C:\Windows\system32\ban_list.txt

                      ################## [ C:\Windows\system32\drivers ]

                      Deleted ! - "C:\Windows\system32\drivers\down"

                      ################## [ C:\.. Application Data ... ]

                      Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\flec006.exe"
                      Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\list.oct"
                      Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\data.oct"
                      Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\srvlist.oct"
                      Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\shared"
                      Deleted ! - "C:\Users\yousndi\AppData\Roaming\m"
                      Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers\srosa2.sys"
                      Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers\wfsintwq.sys"
                      Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe"
                      Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers\downld"
                      Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers"

                      ################## [ Registry / Infected keys ]

                      Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
                      Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
                      Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
                      Deleted ! - HKEY_CURRENT_USER\Software\bisoft
                      Deleted ! - HKEY_CURRENT_USER\Software\DateTime4
                      Deleted ! - HKEY_CURRENT_USER\Software\FirtR
                      Deleted ! - HKEY_CURRENT_USER\Software\MuleAppData
                      Deleted ! - HKEY_CURRENT_USER\Software\FFC
                      Deleted ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\msnmsgr
                      Deleted ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
                      Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\FFC
                      Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\MuleAppData
                      Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
                      Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
                      Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
                      Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
                      Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
                      Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"

                      ################## [ Cleaning Removable drives ]

                      # Deleting files :

                      ################## [ Registry / Mountpoint2 ]

                      # -> Not found !

                      ################## [ Searching Other Infections ]

                      # Références de comparaison Bagle MD5 :

                      File ... : C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe
                      CRC32 .. : e435b851
                      MD5 .... : 09a3f9484b015f6b094fe57edc03ead9

                      # -> Nothing found.

                      ################## [ PEH Corrupted ]

                      C:\Program Files\Alwil Software\Avast4\ashAvast.exe
                      C:\Program Files\Alwil Software\Avast4\ashChest.exe
                      C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                      C:\Program Files\Alwil Software\Avast4\ashLogV.exe
                      C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                      C:\Program Files\Alwil Software\Avast4\ashPopWz.exe
                      C:\Program Files\Alwil Software\Avast4\ashQuick.exe
                      C:\Program Files\Alwil Software\Avast4\ashServ.exe
                      C:\Program Files\Alwil Software\Avast4\ashSimp2.exe
                      C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
                      C:\Program Files\Alwil Software\Avast4\ashSkPcc.exe
                      C:\Program Files\Alwil Software\Avast4\ashSkPck.exe
                      C:\Program Files\Alwil Software\Avast4\ashUpd.exe
                      C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                      C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe
                      C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                      C:\Program Files\Alwil Software\Avast4\sched.exe
                      C:\Program Files\Alwil Software\Avast4\VisthLic.exe
                      C:\Program Files\Alwil Software\Avast4\VisthUpd.exe
                      C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                      C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
                      C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

                      ################## [ ! End of Report # FindyKill V4.720 ! ]
                      0
                      1. Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

                        --> Fais clic droit sur le raccourci FindyKill sur ton bureau

                        --> Au menu principal,choisi l option 2 (Suppression)

                        /!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

                        /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

                        -------> ensuite post le rapport FindyKill.txt

                        Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
                        0
                        1. ok merci vient de charger findykill

                          Rapport:*
                          ############################## [ FindyKill V4.720 ]

                          # User : yousndi (Administrateurs) # PC-DE-YOUSNDI
                          # Update on 12/03/09 by Chiquitine29
                          # Start at: 23:46:11 | 15/03/2009

                          # AMD Athlon(tm) 64 Processor 3800+
                          # Microsoft© Windows VistaT dition Familiale Basique (6.0.6001 32-bit) # Service Pack 1
                          # Internet Explorer 7.0.6001.18000
                          # Windows Firewall Status : Disabled

                          # C:\ # Disque fixe local # 143,42 Go (93,87 Go free) [COMPAQ] # NTFS
                          # D:\ # Disque fixe local # 5,63 Go (596,71 Mo free) [Recovery] # NTFS
                          # E:\ # Disque CD-ROM
                          # F:\ # Disque amovible
                          # G:\ # Disque amovible
                          # H:\ # Disque amovible
                          # I:\ # Disque amovible

                          ############################## [ Processus actifs ]

                          C:\Windows\System32\smss.exe
                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\wininit.exe
                          C:\Windows\system32\csrss.exe
                          C:\Windows\system32\services.exe
                          C:\Windows\system32\lsass.exe
                          C:\Windows\system32\lsm.exe
                          C:\Windows\system32\winlogon.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\nvvsvc.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\SLsvc.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\system32\rundll32.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\spoolsv.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                          C:\Program Files\Bonjour\mDNSResponder.exe
                          C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                          C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                          C:\Program Files\Windows Live\Family Safety\fsssvc.exe
                          c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                          C:\Windows\system32\svchost.exe
                          C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
                          C:\Windows\system32\svchost.exe
                          C:\Windows\System32\svchost.exe
                          C:\Windows\system32\SearchIndexer.exe
                          C:\Windows\system32\WUDFHost.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\taskeng.exe
                          C:\Windows\system32\Dwm.exe
                          C:\Windows\Explorer.EXE
                          C:\hp\support\hpsysdrv.exe
                          C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                          C:\WINDOWS\RtHDVCpl.exe
                          C:\Program Files\CyberLink\PowerCinema\PCMService.exe
                          C:\WINDOWS\System32\rundll32.exe
                          C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                          C:\Program Files\Windows Live\Family Safety\fsui.exe
                          C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                          C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe
                          C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
                          C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
                          C:\Program Files\Windows Media Player\wmpnscfg.exe
                          C:\Program Files\Windows Media Player\wmpnetwk.exe
                          C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
                          C:\Program Files\Windows Live\Contacts\wlcomm.exe
                          C:\Windows\system32\SearchProtocolHost.exe
                          C:\Program Files\Internet Explorer\iexplore.exe
                          C:\Program Files\Windows Live\Toolbar\wltuser.exe
                          C:\hp\kbd\kbd.exe
                          C:\Users\yousndi\AppData\Roaming\m\flec006.exe
                          C:\Windows\system32\wbem\wmiprvse.exe
                          C:\Windows\system32\conime.exe
                          C:\Windows\system32\SearchFilterHost.exe
                          C:\Windows\system32\wintems.exe
                          C:\Windows\system32\wbem\wmiprvse.exe

                          ################## [ Processus infectieux stoppés ]

                          "C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe" (3064)
                          "C:\Users\yousndi\AppData\Roaming\m\flec006.exe" (2148)
                          "C:\Windows\system32\wintems.exe" (1264)

                          ################## [ Fichiers / Dossiers infectieux C:\ ]

                          ################## [ C:\Windows ]

                          ################## [ C:\Windows\system32 ]

                          Found ! - C:\Windows\system32\mdelk.exe
                          Found ! - C:\Windows\system32\wintems.exe
                          Found ! - C:\Windows\system32\ban_list.txt

                          ################## [ C:\Windows\system32\drivers ]

                          Found ! - "C:\Windows\system32\drivers\down"

                          ################## [ C:\.. Application Data ... ]

                          Found ! - "C:\Users\yousndi\AppData\Roaming\m\flec006.exe"
                          Found ! - "C:\Users\yousndi\AppData\Roaming\m\list.oct"
                          Found ! - "C:\Users\yousndi\AppData\Roaming\m\data.oct"
                          Found ! - "C:\Users\yousndi\AppData\Roaming\m\srvlist.oct"
                          Found ! - "C:\Users\yousndi\AppData\Roaming\m\shared"
                          Found ! - "C:\Users\yousndi\AppData\Roaming\m"
                          Found ! - "C:\Users\yousndi\AppData\Roaming\drivers"
                          Found ! - "C:\Users\yousndi\AppData\Roaming\drivers\srosa2.sys"
                          Found ! - "C:\Users\yousndi\AppData\Roaming\drivers\wfsintwq.sys"
                          Found ! - "C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe"
                          Found ! - "C:\Users\yousndi\AppData\Roaming\drivers\downld"

                          ################## [ Registre / Clés infectieuses ]

                          Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Local AppWizard-Generated Applications\msnmsgr
                          Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Local AppWizard-Generated Applications\run
                          Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Local AppWizard-Generated Applications\winupgro
                          Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\bisoft
                          Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\DateTime4
                          Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\FFC
                          Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\FirtR
                          Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\MuleAppData
                          Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\msnmsgr
                          Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\run
                          Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
                          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
                          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
                          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
                          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
                          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
                          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
                          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
                          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
                          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
                          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
                          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
                          Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
                          Found ! - HKEY_CURRENT_USER\Software\bisoft
                          Found ! - HKEY_CURRENT_USER\Software\DateTime4
                          Found ! - HKEY_CURRENT_USER\Software\FirtR
                          Found ! - HKEY_CURRENT_USER\Software\MuleAppData
                          Found ! - HKEY_CURRENT_USER\Software\FFC
                          Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
                          Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
                          Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
                          Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
                          Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
                          Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"

                          # Infection active : HKLM\SYSTEM\...\Services\srosa -> Start = 0x1
                          # Infection active : HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1

                          ################## [ Recherche dans supports amovibles]

                          # Presence des fichiers :

                          ################## [ Registre / Mountpoint2 ]

                          # -> Not found !

                          ################## [ ! Fin du rapport # FindyKill V4.720 ! ]
                          0
                          1. Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

                            - Vas dans "Démarrer" puis Panneau de configuration.
                            - Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
                            - Clique sur Continuer.
                            - Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
                            - Valide par OK et redémarre.

                            Tuto

                            ensuite :

                            Telecharge maintenant FindyKill sur ton bureau :

                            http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

                            --> Lance l installation avec les parametres par default

                            --> Fais un clic droit sur le raccourci FindyKill sur ton bureau

                            --> Choisi executer en tant qu administrateur

                            --> Au menu principal,choisi l option 1 (Recherche)

                            --> Post le rapport FindyKill.txt

                            Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
                            0
                            1. Logfile of random's system information tool 1.05 (written by random/random)
                              Run by yousndi at 2009-03-15 21:14:43
                              Microsoft® Windows Vista™ Édition Familiale Basique Service Pack 1
                              System drive C: has 97 GB (66%) free of 147 GB
                              Total RAM: 894 MB (13% free)

                              Logfile of Trend Micro HijackThis v2.0.2
                              Scan saved at 21:14:54, on 15/03/2009
                              Platform: Windows Vista SP1 (WinNT 6.00.1905)
                              MSIE: Internet Explorer v7.00 (7.00.6001.18000)
                              Boot mode: Normal

                              Running processes:
                              C:\Windows\system32\taskeng.exe
                              C:\Windows\system32\Dwm.exe
                              C:\Windows\Explorer.EXE
                              C:\hp\support\hpsysdrv.exe
                              C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
                              C:\WINDOWS\RtHDVCpl.exe
                              C:\Program Files\CyberLink\PowerCinema\PCMService.exe
                              C:\WINDOWS\System32\rundll32.exe
                              C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
                              C:\Program Files\Windows Live\Family Safety\fsui.exe
                              C:\Program Files\Windows Live\Messenger\msnmsgr.exe
                              C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
                              C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
                              C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
                              C:\Windows\System32\mobsync.exe
                              C:\Program Files\Windows Media Player\wmpnscfg.exe
                              C:\Program Files\Windows Live\Contacts\wlcomm.exe
                              C:\hp\kbd\kbd.exe
                              C:\Program Files\Mozilla Firefox\firefox.exe
                              C:\Windows\system32\conime.exe
                              C:\Windows\system32\rundll32.exe
                              C:\Windows\helppane.exe
                              C:\Users\yousndi\Downloads\RSIT.exe
                              C:\Program Files\trend micro\yousndi.exe

                              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
                              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
                              R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
                              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
                              R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O1 - Hosts: ::1 localhost
                              O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
                              O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
                              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
                              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
                              O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
                              O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
                              O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
                              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
                              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
                              O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
                              O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
                              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
                              O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
                              O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
                              O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
                              O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
                              O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
                              O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
                              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
                              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
                              O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
                              O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
                              O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
                              O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
                              O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
                              O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
                              O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
                              O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
                              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
                              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
                              O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
                              O4 - Startup: Outil de notification Live Search.lnk = C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
                              O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
                              O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                              O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
                              O13 - Gopher Prefix:
                              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
                              O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
                              O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
                              O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
                              O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
                              O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
                              O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
                              O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
                              O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
                              O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
                              O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
                              0