Tout d'abord je voudrais te remercier pour ta disponibilité...
Ensuite voici le rapport:
############################## [ FindyKill V4.727 ]
# User : Propriétaire (Administrateurs) # DAEWOO
# Update on 27/04/09 by Chiquitine29
# Start at: 22:21:07 | 28/04/2009
# Website :
http://pagesperso-orange.fr/FindyKill.Ad.Remover/
# AMD Athlon(tm) XP 2400+
# Microsoft Windows XP Édition familiale (5.1.2600 32-bit) # Service Pack 3
# Internet Explorer 7.0.5730.13
# Windows Firewall Status : Enabled
# AV : avast! antivirus 4.8.1335 [VPS 090427-0] 4.8.1335 [ (!) Disabled | Updated ]
# A:\ # Lecteur de disquettes 3 ½ pouces
# C:\ # Disque fixe local # 76,32 Go (55,84 Go free) # NTFS
# D:\ # Disque fixe local # 18,99 Go (12,01 Go free) # NTFS
# E:\ # Disque CD-ROM
# F:\ # Disque fixe local # 465,76 Go (249,22 Go free) [externe] # NTFS
############################## [ Active Processes ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Fichiers communs\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
################## [ Infected Files \ Folders ]
Deleted ! C:\WINDOWS\Prefetch\121562.EXE-08BBDD7B.pf
Deleted ! C:\WINDOWS\Prefetch\193640.EXE-1B98E7B1.pf
Deleted ! C:\WINDOWS\Prefetch\199562.EXE-23DA5139.pf
Deleted ! C:\WINDOWS\Prefetch\275953.EXE-1EFFE1C7.pf
Deleted ! C:\WINDOWS\Prefetch\308453.EXE-0079C0B1.pf
Deleted ! C:\WINDOWS\Prefetch\320296.EXE-27825DF3.pf
Deleted ! C:\WINDOWS\Prefetch\327031.EXE-2ADBB4F1.pf
Deleted ! C:\WINDOWS\Prefetch\381296.EXE-0354EDDD.pf
Deleted ! C:\WINDOWS\Prefetch\399515.EXE-08CE3EB1.pf
Deleted ! C:\WINDOWS\Prefetch\409046.EXE-398CD592.pf
Deleted ! C:\WINDOWS\Prefetch\415531.EXE-24AF3FD4.pf
Deleted ! C:\WINDOWS\Prefetch\45035421.EXE-3A511B60.pf
Deleted ! C:\WINDOWS\Prefetch\558671.EXE-2C53C360.pf
Deleted ! C:\WINDOWS\Prefetch\627953.EXE-36E382F0.pf
Deleted ! C:\WINDOWS\Prefetch\FLEC006.EXE-041A0D93.pf
Deleted ! C:\WINDOWS\Prefetch\KEYGEN.EXE-0724CC33.pf
Deleted ! C:\WINDOWS\Prefetch\MDELK.EXE-1D176F91.pf
Deleted ! C:\WINDOWS\Prefetch\WINTEMS.EXE-2A563F9B.pf
Deleted ! C:\WINDOWS\Prefetch\WINUPGRO.EXE-123A473A.pf
Deleted ! C:\WINDOWS\system32\ban_list.txt
Deleted ! C:\WINDOWS\system32\mdelk.exe
Deleted ! C:\WINDOWS\system32\wintems.exe
Deleted ! "C:\Documents and Settings\Propri‚taire\Application Data\drivers\srosa2.sys"
Deleted ! "C:\Documents and Settings\Propri‚taire\Application Data\drivers\wfsintwq.sys"
Deleted ! "C:\Documents and Settings\Propri‚taire\Application Data\drivers\winupgro.exe"
Deleted ! "C:\Documents and Settings\Propri‚taire\Application Data\m\data.oct"
Deleted ! "C:\Documents and Settings\Propri‚taire\Application Data\m\flec006.exe"
Deleted ! "C:\Documents and Settings\Propri‚taire\Application Data\m\list.oct"
Deleted ! "C:\Documents and Settings\Propri‚taire\Application Data\m\srvlist.oct"
Deleted ! "C:\Documents and Settings\Propri‚taire\Application Data\drivers\downld"
Deleted ! "C:\Documents and Settings\Propri‚taire\Application Data\drivers"
Deleted ! "C:\Documents and Settings\Propri‚taire\Application Data\m\shared"
Deleted ! "C:\Documents and Settings\Propri‚taire\Application Data\m"
################## [ Infected Temp Files ]
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\4SMMQ0PL\b64[1].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\4SMMQ0PL\mxd[1].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\4SMMQ0PL\servernames[1].htm
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\MFD3BYED\b64_1[1].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\MFD3BYED\b64_3[1].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\MFD3BYED\b64_3[2].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\OQLL2GLI\b64_1[1].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\OQLL2GLI\b64_1[2].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\OQLL2GLI\b64_1[3].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\OQLL2GLI\b64_1[4].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\OQLL2GLI\b64_1[5].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\X6AQZYBV\b64[1].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\X6AQZYBV\b64_1[1].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\X6AQZYBV\b64_1[2].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\X6AQZYBV\b64_3[1].jpg
Deleted ! C:\Documents and Settings\Propri‚taire\Local Settings\Temporary Internet Files\Content.IE5\X6AQZYBV\file[1].txt
################## [ Registry / Infected keys ]
Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\srosa
Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA
Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sK9Ou0s
Deleted ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_SK9OU0S
Deleted ! HKEY_CURRENT_USER\Software\bisoft
Deleted ! HKEY_CURRENT_USER\Software\DateTime4
Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\keygen
Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\run
Deleted ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Deleted ! HKEY_USERS\S-1-5-21-1993962763-1965331169-1417001333-1003\Software\FFC
Deleted ! HKEY_USERS\S-1-5-21-1993962763-1965331169-1417001333-1003\Software\MuleAppData
Deleted ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"drvsyskit"
Deleted ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"german.exe"
Deleted ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\"mule_st_key"
################## [ Cleaning Removable drives ]
################## [ Registry / Mountpoint2 ]
# -> Not found !
################## [ States / Restarting of services ]
# Services : [ Auto=2 / Request=3 / Disable=4 ]
# Ndisuio -> # Type of startup =3
# EapHost -> # Type of startup =2
# Ip6Fw -> # Type of startup =2
# SharedAccess -> # Type of startup =2
# wuauserv -> # Type of startup =2
# wscsvc -> # Type of startup =2
# Safe boot mode restored !
################## [ Searching Other Infections ]
# Références de comparaison Bagle MD5 :
File ... : C:\Documents and Settings\Propri‚taire\Application Data\drivers\winupgro.exe
CRC32 .. : a1f7a07d
MD5 .... : 1fc635eea11997dfaa632a6055d7ae9e
# -> Nothing found.
################## [ Corrupted files # Re-Installation required ]
C:\Program Files\Alwil Software\Avast4\ashAvast.exe
C:\Program Files\Alwil Software\Avast4\ashChest.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\ashLogV.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashPopWz.exe
C:\Program Files\Alwil Software\Avast4\ashQuick.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Alwil Software\Avast4\ashSimp2.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Alwil Software\Avast4\ashSkPcc.exe
C:\Program Files\Alwil Software\Avast4\ashSkPck.exe
C:\Program Files\Alwil Software\Avast4\ashUpd.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Alwil Software\Avast4\aswRegSvr.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\sched.exe
C:\Program Files\Alwil Software\Avast4\VisthLic.exe
C:\Program Files\Alwil Software\Avast4\VisthUpd.exe
C:\Program Files\GRISOFT\AVG Anti-Rootkit Free\avgarkt.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Mozilla Firefox\uninstall\helper.exe
C:\WINDOWS\PixArt\PAC207\Monitor.exe
F:\Program Files\GP Vs Superbike\Launch.exe
################################### [ Cracks / Keygens / Serials ]
C:\Documents and Settings\Propri‚taire\.housecall6.6\patch.exe
################## [ ! End of Report # FindyKill V4.727 ! ]