Virus , utisation RSIT

Bonjour,
j'ai un problème, avec windows vista, plus d'accès a certaine application en autres Avast, Ccleaner, Windows defender.
Comment poster les rapport obtenu de RSIT???

Merci d'avance
Configuration: Windows Vista
Firefox 3.0.7

17 réponses

  1. Logfile of random's system information tool 1.05 (written by random/random)
    Run by yousndi at 2009-03-15 21:14:43
    Microsoft® Windows Vista™ Édition Familiale Basique Service Pack 1
    System drive C: has 97 GB (66%) free of 147 GB
    Total RAM: 894 MB (13% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 21:14:54, on 15/03/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\hp\support\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    C:\WINDOWS\RtHDVCpl.exe
    C:\Program Files\CyberLink\PowerCinema\PCMService.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\Windows Live\Family Safety\fsui.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
    C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
    C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Windows Live\Contacts\wlcomm.exe
    C:\hp\kbd\kbd.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Windows\system32\conime.exe
    C:\Windows\system32\rundll32.exe
    C:\Windows\helppane.exe
    C:\Users\yousndi\Downloads\RSIT.exe
    C:\Program Files\trend micro\yousndi.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = https://www.bing.com/?toHttps=1&redig=5FC791212101479BAFBE1A679848B1AF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.msn.com/fr-fr?cobrand=compaq-desktop.msn.com&ocid=HPDHP&pc=CPDTDF
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O1 - Hosts: ::1 localhost
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Windows Live Family Safety Browser Helper - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
    O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [DPService] "C:\Program Files\HP\DVDPlay\DPService.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [fssui] "C:\Program Files\Windows Live\Family Safety\fsui.exe" -autorun
    O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
    O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
    O4 - Startup: MSN Pictures Displayer.lnk = C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
    O4 - Startup: Outil de notification Live Search.lnk = C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
    O9 - Extra button: Ajout Direct - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Ajout Direct dans Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
    O13 - Gopher Prefix:
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
    O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
    O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
    O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    1. Désactive le contrôle des comptes utilisateurs (tu le réactiveras après ta désinfection):

      - Vas dans "Démarrer" puis Panneau de configuration.
      - Double Clique sur l'icône Comptes d'utilisateurs et sur Activer ou désactiver le contrôle des comptes d'utilisateurs.
      - Clique sur Continuer.
      - Décoche la case Utiliser le contrôle des comptes d'utilisateurs pour vous aider à protéger votre ordinateur.
      - Valide par OK et redémarre.

      Tuto

      ensuite :

      Telecharge maintenant FindyKill sur ton bureau :

      http://sd-1.archive-host.com/membres/up/116615172019703188/FindyKill.exe

      --> Lance l installation avec les parametres par default

      --> Fais un clic droit sur le raccourci FindyKill sur ton bureau

      --> Choisi executer en tant qu administrateur

      --> Au menu principal,choisi l option 1 (Recherche)

      --> Post le rapport FindyKill.txt

      Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
      1. ok merci vient de charger findykill

        Rapport:*
        ############################## [ FindyKill V4.720 ]

        # User : yousndi (Administrateurs) # PC-DE-YOUSNDI
        # Update on 12/03/09 by Chiquitine29
        # Start at: 23:46:11 | 15/03/2009

        # AMD Athlon(tm) 64 Processor 3800+
        # Microsoft© Windows VistaT dition Familiale Basique (6.0.6001 32-bit) # Service Pack 1
        # Internet Explorer 7.0.6001.18000
        # Windows Firewall Status : Disabled

        # C:\ # Disque fixe local # 143,42 Go (93,87 Go free) [COMPAQ] # NTFS
        # D:\ # Disque fixe local # 5,63 Go (596,71 Mo free) [Recovery] # NTFS
        # E:\ # Disque CD-ROM
        # F:\ # Disque amovible
        # G:\ # Disque amovible
        # H:\ # Disque amovible
        # I:\ # Disque amovible

        ############################## [ Processus actifs ]

        C:\Windows\System32\smss.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\wininit.exe
        C:\Windows\system32\csrss.exe
        C:\Windows\system32\services.exe
        C:\Windows\system32\lsass.exe
        C:\Windows\system32\lsm.exe
        C:\Windows\system32\winlogon.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\nvvsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\SLsvc.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\system32\rundll32.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\spoolsv.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
        C:\Program Files\Bonjour\mDNSResponder.exe
        C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
        C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
        C:\Program Files\Windows Live\Family Safety\fsssvc.exe
        c:\Program Files\Common Files\LightScribe\LSSrvc.exe
        C:\Windows\system32\svchost.exe
        C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
        C:\Windows\system32\svchost.exe
        C:\Windows\System32\svchost.exe
        C:\Windows\system32\SearchIndexer.exe
        C:\Windows\system32\WUDFHost.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\taskeng.exe
        C:\Windows\system32\Dwm.exe
        C:\Windows\Explorer.EXE
        C:\hp\support\hpsysdrv.exe
        C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
        C:\WINDOWS\RtHDVCpl.exe
        C:\Program Files\CyberLink\PowerCinema\PCMService.exe
        C:\WINDOWS\System32\rundll32.exe
        C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
        C:\Program Files\Windows Live\Family Safety\fsui.exe
        C:\Program Files\Windows Live\Messenger\msnmsgr.exe
        C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe
        C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
        C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
        C:\Program Files\Windows Media Player\wmpnscfg.exe
        C:\Program Files\Windows Media Player\wmpnetwk.exe
        C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
        C:\Program Files\Windows Live\Contacts\wlcomm.exe
        C:\Windows\system32\SearchProtocolHost.exe
        C:\Program Files\Internet Explorer\iexplore.exe
        C:\Program Files\Windows Live\Toolbar\wltuser.exe
        C:\hp\kbd\kbd.exe
        C:\Users\yousndi\AppData\Roaming\m\flec006.exe
        C:\Windows\system32\wbem\wmiprvse.exe
        C:\Windows\system32\conime.exe
        C:\Windows\system32\SearchFilterHost.exe
        C:\Windows\system32\wintems.exe
        C:\Windows\system32\wbem\wmiprvse.exe

        ################## [ Processus infectieux stoppés ]

        "C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe" (3064)
        "C:\Users\yousndi\AppData\Roaming\m\flec006.exe" (2148)
        "C:\Windows\system32\wintems.exe" (1264)

        ################## [ Fichiers / Dossiers infectieux C:\ ]

        ################## [ C:\Windows ]

        ################## [ C:\Windows\system32 ]

        Found ! - C:\Windows\system32\mdelk.exe
        Found ! - C:\Windows\system32\wintems.exe
        Found ! - C:\Windows\system32\ban_list.txt

        ################## [ C:\Windows\system32\drivers ]

        Found ! - "C:\Windows\system32\drivers\down"

        ################## [ C:\.. Application Data ... ]

        Found ! - "C:\Users\yousndi\AppData\Roaming\m\flec006.exe"
        Found ! - "C:\Users\yousndi\AppData\Roaming\m\list.oct"
        Found ! - "C:\Users\yousndi\AppData\Roaming\m\data.oct"
        Found ! - "C:\Users\yousndi\AppData\Roaming\m\srvlist.oct"
        Found ! - "C:\Users\yousndi\AppData\Roaming\m\shared"
        Found ! - "C:\Users\yousndi\AppData\Roaming\m"
        Found ! - "C:\Users\yousndi\AppData\Roaming\drivers"
        Found ! - "C:\Users\yousndi\AppData\Roaming\drivers\srosa2.sys"
        Found ! - "C:\Users\yousndi\AppData\Roaming\drivers\wfsintwq.sys"
        Found ! - "C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe"
        Found ! - "C:\Users\yousndi\AppData\Roaming\drivers\downld"

        ################## [ Registre / Clés infectieuses ]

        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Local AppWizard-Generated Applications\msnmsgr
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Local AppWizard-Generated Applications\run
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Local AppWizard-Generated Applications\winupgro
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\bisoft
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\DateTime4
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\FFC
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\FirtR
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\MuleAppData
        Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\msnmsgr
        Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\run
        Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
        Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
        Found ! - HKEY_CURRENT_USER\Software\bisoft
        Found ! - HKEY_CURRENT_USER\Software\DateTime4
        Found ! - HKEY_CURRENT_USER\Software\FirtR
        Found ! - HKEY_CURRENT_USER\Software\MuleAppData
        Found ! - HKEY_CURRENT_USER\Software\FFC
        Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
        Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
        Found ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
        Found ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"

        # Infection active : HKLM\SYSTEM\...\Services\srosa -> Start = 0x1
        # Infection active : HKLM\SYSTEM\...\Services\sK9Ou0s -> Start = 0x1

        ################## [ Recherche dans supports amovibles]

        # Presence des fichiers :

        ################## [ Registre / Mountpoint2 ]

        # -> Not found !

        ################## [ ! Fin du rapport # FindyKill V4.720 ! ]
        1. Branche tes sources de données externes à ton PC, (clé USB, disque dur externe, etc...) suceptible d avoir été infectés sans les ouvrir

          --> Fais clic droit sur le raccourci FindyKill sur ton bureau

          --> Au menu principal,choisi l option 2 (Suppression)

          /!\ il y aura 2 redémarrage, laisse travailler l outils jusqu a l apparition du message "nettoyage effectué"

          /!\ Ne te sert pas du pc durant la suppression , ton bureau ne sera pas accessible c est normal !

          -------> ensuite post le rapport FindyKill.txt

          Note : le rapport FindyKill.txt est sauvegardé a la racine du disque
          1. C cool! jviens de nettoyer! le PC a redémarré ensuite il ma m'y l'icone windows defender que j'avais plus depuis des jrs , la il me propose une analyse du disque.
            Pense tu que je vais pouvoir instller un antivurs maintenant , car j'avais avast et apparement pas top! le quel prendre ??

            PS: dernier rapport findykill

            ############################## [ FindyKill V4.720 ]

            # User : yousndi (Administrateurs) # PC-DE-YOUSNDI
            # Update on 12/03/09 by Chiquitine29
            # Start at: 00:05:23 | 16/03/2009

            # AMD Athlon(tm) 64 Processor 3800+
            # Microsoft© Windows VistaT dition Familiale Basique (6.0.6001 32-bit) # Service Pack 1
            # Internet Explorer 7.0.6001.18000
            # Windows Firewall Status : Disabled

            # C:\ # Disque fixe local # 143,42 Go (93,87 Go free) [COMPAQ] # NTFS
            # D:\ # Disque fixe local # 5,63 Go (596,71 Mo free) [Recovery] # NTFS
            # E:\ # Disque CD-ROM
            # F:\ # Disque amovible
            # G:\ # Disque amovible
            # H:\ # Disque amovible
            # I:\ # Disque amovible

            ############################## [ Active Processes ]

            C:\Windows\System32\smss.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\wininit.exe
            C:\Windows\system32\csrss.exe
            C:\Windows\system32\services.exe
            C:\Windows\system32\lsass.exe
            C:\Windows\system32\lsm.exe
            C:\Windows\system32\winlogon.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\nvvsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\SLsvc.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\system32\rundll32.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\spoolsv.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
            C:\Program Files\Bonjour\mDNSResponder.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
            C:\Program Files\CyberLink\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe
            C:\Program Files\Windows Live\Family Safety\fsssvc.exe
            c:\Program Files\Common Files\LightScribe\LSSrvc.exe
            C:\Windows\system32\svchost.exe
            C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
            C:\Windows\system32\svchost.exe
            C:\Windows\System32\svchost.exe
            C:\Windows\system32\SearchIndexer.exe
            C:\Windows\system32\WUDFHost.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\taskeng.exe
            C:\Windows\system32\Dwm.exe
            C:\hp\support\hpsysdrv.exe
            C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
            C:\WINDOWS\RtHDVCpl.exe
            C:\Program Files\CyberLink\PowerCinema\PCMService.exe
            C:\WINDOWS\System32\rundll32.exe
            C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
            C:\Program Files\Windows Live\Family Safety\fsui.exe
            C:\Program Files\MSN Pictures Displayer\MSN Pictures Displayer.exe
            C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Notification-LiveSearch.exe
            C:\Program Files\Windows Media Player\wmpnscfg.exe
            C:\Program Files\Windows Media Player\wmpnetwk.exe
            C:\Users\yousndi\AppData\Roaming\Microsoft\Live Search\Mise-a-jour-LiveSearch.exe
            C:\Program Files\Windows Live\Contacts\wlcomm.exe
            C:\hp\kbd\kbd.exe
            C:\Windows\system32\conime.exe
            C:\Windows\system32\wbem\wmiprvse.exe

            ################## [ Infected Files / Folders C:\ ]

            ################## [ C:\Windows ]

            ################## [ C:\Windows\system32 ]

            Deleted ! - C:\Windows\system32\mdelk.exe
            Deleted ! - C:\Windows\system32\wintems.exe
            Deleted ! - C:\Windows\system32\ban_list.txt

            ################## [ C:\Windows\system32\drivers ]

            Deleted ! - "C:\Windows\system32\drivers\down"

            ################## [ C:\.. Application Data ... ]

            Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\flec006.exe"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\list.oct"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\data.oct"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\srvlist.oct"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\m\shared"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\m"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers\srosa2.sys"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers\wfsintwq.sys"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers\downld"
            Deleted ! - "C:\Users\yousndi\AppData\Roaming\drivers"

            ################## [ Registry / Infected keys ]

            Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
            Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
            Deleted ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
            Deleted ! - HKEY_CURRENT_USER\Software\bisoft
            Deleted ! - HKEY_CURRENT_USER\Software\DateTime4
            Deleted ! - HKEY_CURRENT_USER\Software\FirtR
            Deleted ! - HKEY_CURRENT_USER\Software\MuleAppData
            Deleted ! - HKEY_CURRENT_USER\Software\FFC
            Deleted ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\msnmsgr
            Deleted ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
            Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\FFC
            Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\MuleAppData
            Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
            Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
            Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
            Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
            Deleted ! - HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
            Deleted ! - HKEY_USERS\S-1-5-21-2211071043-1393902299-1766958169-1000\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"

            ################## [ Cleaning Removable drives ]

            # Deleting files :

            ################## [ Registry / Mountpoint2 ]

            # -> Not found !

            ################## [ Searching Other Infections ]

            # Références de comparaison Bagle MD5 :

            File ... : C:\Users\yousndi\AppData\Roaming\drivers\winupgro.exe
            CRC32 .. : e435b851
            MD5 .... : 09a3f9484b015f6b094fe57edc03ead9

            # -> Nothing found.

            ################## [ PEH Corrupted ]

            C:\Program Files\Alwil Software\Avast4\ashAvast.exe
            C:\Program Files\Alwil Software\Avast4\ashChest.exe
            C:\Program Files\Alwil Software\Avast4\ashDisp.exe
            C:\Program Files\Alwil Software\Avast4\ashLogV.exe
            C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
            C:\Program Files\Alwil Software\Avast4\ashPopWz.exe
            C:\Program Files\Alwil Software\Avast4\ashQuick.exe
            C:\Program Files\Alwil Software\Avast4\ashServ.exe
            C:\Program Files\Alwil Software\Avast4\ashSimp2.exe
            C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
            C:\Program Files\Alwil Software\Avast4\ashSkPcc.exe
            C:\Program Files\Alwil Software\Avast4\ashSkPck.exe
            C:\Program Files\Alwil Software\Avast4\ashUpd.exe
            C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
            C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe
            C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
            C:\Program Files\Alwil Software\Avast4\sched.exe
            C:\Program Files\Alwil Software\Avast4\VisthLic.exe
            C:\Program Files\Alwil Software\Avast4\VisthUpd.exe
            C:\Program Files\Mozilla Firefox\uninstall\helper.exe
            C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
            C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

            ################## [ ! End of Report # FindyKill V4.720 ! ]
            1. non pas de suite :

              Imprime ces instructions car il faudra fermer toutes les fenêtres et applications lors de l'installation et de l'analyse.

              Télécharge MalwareByte's :
              Malwarebytes ou :
              Malwarebytes

              * Installe le ( choisis bien "francais" ; ne modifie pas les paramètres d'installe ) et mets le à jour .

              (NB : S'il te manque "COMCTL32.OCX" lors de l'installe, alors télécharge le ici : COMCTL32.OCX

              * Potasse le tuto pour te familiariser avec le prg :

              Tuto

              ( cela dis, il est très simple d'utilisation ).

              relance malwarebytes en suivant scrupuleusement ces consignes :

              ! Déconnecte toi et ferme toutes applications en cours !

              * Lance Malwarebyte's .

              Fais un examen dit "Complet" .

              --> Laisse le programme travailler ( et ne rien faire d'autre avec le PC durant le scan ).
              --> à la fin tu cliques sur "résultat" .
              --> Vérifie que tous les objets infectés soient validés, puis clique sur " suppression " .

              Note : si il faut redémarrer ton PC pour finir le nettoyage, fais le !

              Poste le rapport sauvegardé après la suppression des objets infectés (dans l'onglet "rapport/log"de Malwarebytes, le dernier en date)

              1. ok thanks, bon jferais ca demain, jvais aller dodoter merci encore++
                1. Slt, merci pour l'aide d'hier soir .
                  Du coup j'ai pu parer a mon soucis grace a Findykill, il a bien gérer les fichiers inféctés!
                  j'ai installé Antivir , mon pc a l'air de refonctionner normalement!
                  +++
                  1. je peux avoir le rapport de malwarebytes après suppression des nuisibles s'il te plait ?
                    1. Au faite je n'ai pas utilisé malwarebytes, j'ai directement chargé Findykill qui a supprimé les virus , et réactivé Windows defender!!!
                      1. que tu crois mais la desinfection n est pas finie a ce stade

                        et ca c est mort :

                        C:\Program Files\Alwil Software\Avast4\ashAvast.exe
                        C:\Program Files\Alwil Software\Avast4\ashChest.exe
                        C:\Program Files\Alwil Software\Avast4\ashDisp.exe
                        C:\Program Files\Alwil Software\Avast4\ashLogV.exe
                        C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
                        C:\Program Files\Alwil Software\Avast4\ashPopWz.exe
                        C:\Program Files\Alwil Software\Avast4\ashQuick.exe
                        C:\Program Files\Alwil Software\Avast4\ashServ.exe
                        C:\Program Files\Alwil Software\Avast4\ashSimp2.exe
                        C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
                        C:\Program Files\Alwil Software\Avast4\ashSkPcc.exe
                        C:\Program Files\Alwil Software\Avast4\ashSkPck.exe
                        C:\Program Files\Alwil Software\Avast4\ashUpd.exe
                        C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
                        C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe
                        C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
                        C:\Program Files\Alwil Software\Avast4\sched.exe
                        C:\Program Files\Alwil Software\Avast4\VisthLic.exe
                        C:\Program Files\Alwil Software\Avast4\VisthUpd.exe
                        C:\Program Files\Mozilla Firefox\uninstall\helper.exe
                        C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
                        C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
                        1. Ah ok , jsavais pas. pourtant tout a l'air normal sauf que le démarrage de windows et un peu lent!
                          Donc la je telecharge malwarebytes, et jfais quoi ensuite???
                          1. oki jviens de faire un scan avec Malwarebytes'.

                            Rapport

                            Malwarebytes' Anti-Malware 1.34
                            Version de la base de données: 1855
                            Windows 6.0.6001 Service Pack 1

                            16/03/2009 21:54:27
                            mbam-log-2009-03-16 (21-54-27).txt

                            Type de recherche: Examen complet (C:\|D:\|)
                            Eléments examinés: 153011
                            Temps écoulé: 1 hour(s), 15 minute(s), 8 second(s)

                            Processus mémoire infecté(s): 0
                            Module(s) mémoire infecté(s): 0
                            Clé(s) du Registre infectée(s): 0
                            Valeur(s) du Registre infectée(s): 0
                            Elément(s) de données du Registre infecté(s): 0
                            Dossier(s) infecté(s): 0
                            Fichier(s) infecté(s): 0

                            Processus mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Module(s) mémoire infecté(s):
                            (Aucun élément nuisible détecté)

                            Clé(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Valeur(s) du Registre infectée(s):
                            (Aucun élément nuisible détecté)

                            Elément(s) de données du Registre infecté(s):
                            (Aucun élément nuisible détecté)

                            Dossier(s) infecté(s):
                            (Aucun élément nuisible détecté)

                            Fichier(s) infecté(s):
                            (Aucun élément nuisible détecté)
                            1. ok pour l antivirus :

                              Passer de Avast à AntiVir :

                              Désinstalle via Ajout/Suppression de Programmes (si présents) :

                              * Avast!

                              Télécharge et exécute le Désinstalleur d'Avast!.:

                              Ceci effacera la majorité des traces du produit Avast! d'Alwil Software.

                              Télécharge Ccleaner sur ton Bureau. :

                              * Clique sur "download the latest version"
                              * Installe-le en laissant seulement les options suivantes cochées :

                              - Ajouter un raccourci sur le Bureau
                              - Contrôler automatiquement les mises à jour de CCleaner

                              * Lance le Nettoyage
                              * Clique sur Chercher des erreurs et sauvegarde si tu le souhaites.

                              plus de precision sur la configuration de ccleaner te seront donnees plus tard

                              tuto : Comment utiliser CCleaner.
                              ***************

                              Télécharge Antivir en Francais ou :Antivir en Francais sur ton Bureau.:

                              * Double clique sur l'exécutable téléchargé pour lancer l'installation.
                              * À la fin de l'installation, clique sur Finish.
                              * Ouvre Antivir, assure-toi qu’il soit bien à jour !
                              * Dans l'onglet Protection Locale, choisis Contrôler.
                              * Active la recherche de rootkits via le + de Recherche de Rootkits, puis dans Sélection manuelle, coche tout (tes partitions de disque dur).
                              * Clique sur la loupe du milieu pour lancer le scan en tant qu'Administrateur.
                              * Poste moi le rapport généré : Pour cela, clique sur l'onglet Aperçu, puis choisis Rapports, tu trouveras son rapport..
                              * Sélectionne le rapport et clique sur l'icône "Afficher le fichier de rapport du rapport sélectionné.

                              Note : Pour une éradication des menaces plus efficace, lance le scan en mode sans échec.

                              Pourquoi changer ? :Avast Vs Antivir

                              Tuto Antivir: Comment installer et utiliser AntiVir.

                              Configuration de Antivir (Merci Nico) :

                              clic droit sur son icone dans la barre des taches et séléctionner Configurer Antivir.

                              cocher la case : Mode Expert.

                              => Cliquer sur Scanner dans le volet de gauche :

                              > Dans "Fichiers" séléctionner Tous les fichiers.

                              > Dans procédure de recherche, cocher Autoriser l'arrêt, et dans "priorité scanner" séléctionner Elevé.

                              > Dans "Autres réglages" cocher toutes les cases.

                              NE SURTOUT PAS OUBLIER LA RECHERCHE DES ROOTKIT QUI EST TRES IMPORTANTE !

                              => Cliquer sur "Recherche" dans le volet de gauche et appliquer les mêmes paramètres que précédemment.

                              => Dérouler "Recherche" en cliquant sur le +. Cliquer sur "Heuristique" :

                              > Cocher "Heuristique de MacroVirus" et "Heuristique fichier Win32" avec degré d'indentification ELEVE !

                              => Dans le volet de gauche, dérouler "Guard" puis dérouler "Recherche" :

                              > Cocher "Heuristique de MacroVirus" et "Heuristique fichier Win32" avec degré d'identification ELEVE !