Voilà, pour répondre à Golorak59, le rpport de Findkill :
[spoiler]
###################### [ FindyKill V4.715 ]
User : J?rme et Sophie - MELIGNON
Emplacement : C:\Program Files\FindyKill
Outils Mis a jours 29/01/09 par Chiquitine29
Recherche effectuée à 17:34:47 le 30/01/2009
Windows XP - Internet Explorer 6.0.2900.2180
[ FindyKill V4.715 - Scan ]
\\\\\\\\\\ [ Processus actifs ] ///////////////////
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\WINDOWS\System32\FTRTSVC.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
c:\APPS\HIDSERVICE\HIDSERVICE.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\drivers\STDSB.exe
C:\PROGRA~1\Wanadoo\TaskBarIcon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Apps\Powercinema\PCMService.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\drivers\Icon.exe
C:\WINDOWS\RTHDCPL.EXE
C:\APPS\skype\Phone\Skype.exe
C:\Documents and Settings\Jérôme et Sophie\Application Data\drivers\winupgro.exe
C:\WINDOWS\system32\wintems.exe
C:\Program Files\Labtec NumPad\Magickey.exe
C:\PROGRA~1\Wanadoo\GestionnaireInternet.exe
C:\PROGRA~1\Wanadoo\ComComp.exe
C:\PROGRA~1\Wanadoo\Toaster.exe
C:\PROGRA~1\Wanadoo\Inactivity.exe
C:\PROGRA~1\Wanadoo\PollingModule.exe
C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE
C:\APPS\skype\Plugin Manager\skypePM.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Jérôme et Sophie\Application Data\m\flec006.exe
\\\\\\\\\ [ Processus infectieux stoppés ] ///////////////////
“C:\Documents and Settings\Jérôme et Sophie\Application Data\drivers\winupgro.exe” (468)
“C:\WINDOWS\system32\wintems.exe” (532)
“C:\Documents and Settings\Jérôme et Sophie\Application Data\m\flec006.exe” (2904)
\\\\\\\\\ [ Fichiers/Dossiers infectieux ] ///////////////////
################## [ C:\ ]
Found ! [29/01/2009 19:36] - “C:\Muestras”
Found ! [29/01/2009 22:16] - C:\InfoSat.txt
################## [ C:\WINDOWS ]
################## [ C:\WINDOWS\Prefetch ]
Found ! - C:\WINDOWS\prefetch\1069296.EXE-0F37809E.pf
Found ! - C:\WINDOWS\prefetch\1080062.EXE-2309D214.pf
Found ! - C:\WINDOWS\prefetch\1082750.EXE-0AC8E2F2.pf
Found ! - C:\WINDOWS\prefetch\1219343.EXE-259A8E29.pf
Found ! - C:\WINDOWS\prefetch\1231718.EXE-2D5D8F9A.pf
Found ! - C:\WINDOWS\prefetch\433953.EXE-102EB7E4.pf
Found ! - C:\WINDOWS\prefetch\459156.EXE-372FC4B0.pf
Found ! - C:\WINDOWS\prefetch\561843.EXE-295D5C15.pf
Found ! - C:\WINDOWS\prefetch\573312.EXE-35456C42.pf
Found ! - C:\WINDOWS\prefetch\581046.EXE-1AB67723.pf
Found ! - C:\WINDOWS\prefetch\619859.EXE-2CFB03F8.pf
Found ! - C:\WINDOWS\prefetch\657546.EXE-30F9ACDC.pf
Found ! - C:\WINDOWS\prefetch\804281.EXE-1029A9B1.pf
Found ! - C:\WINDOWS\prefetch\820531.EXE-050C5C34.pf
Found ! - C:\WINDOWS\prefetch\985078.EXE-32C36150.pf
Found ! - C:\WINDOWS\prefetch\FLEC006.EXE-38724AD4.pf
Found ! - C:\WINDOWS\prefetch\WINTEMS.EXE-2A563F9B.pf
################## [ C:\WINDOWS\system32 ]
Found ! [30/01/2009 10:41] - C:\WINDOWS\system32\mdelk.exe
Found ! [30/01/2009 10:41] - C:\WINDOWS\system32\wintems.exe
Found ! [30/01/2009 17:19] - C:\WINDOWS\system32\ban_list.txt
################## [ C:\WINDOWS\system32\drivers ]
################## [ C:\Documents and Settings\J?rme et Sophie\Application Data ]
Found ! [30/01/2009 17:16] - “C:\Documents and Settings\J?rme et Sophie\Application Data\m\flec006.exe”
Found ! [30/01/2009 17:17] - “C:\Documents and Settings\J?rme et Sophie\Application Data\m\list.oct”
Found ! [30/01/2009 17:17] - “C:\Documents and Settings\J?rme et Sophie\Application Data\m\data.oct”
Found ! [30/01/2009 17:17] - “C:\Documents and Settings\J?rme et Sophie\Application Data\m\srvlist.oct”
Found ! [30/01/2009 17:19] - “C:\Documents and Settings\J?rme et Sophie\Application Data\m\shared”
Found ! [30/01/2009 10:35] - “C:\Documents and Settings\J?rme et Sophie\Application Data\m”
Found ! [30/01/2009 10:24] - “C:\Documents and Settings\J?rme et Sophie\Application Data\drivers”
Found ! [30/01/2009 17:09] - “C:\Documents and Settings\J?rme et Sophie\Application Data\drivers\srosa2.sys”
Found ! [30/01/2009 17:09] - “C:\Documents and Settings\J?rme et Sophie\Application Data\drivers\wfsintwq.sys”
Found ! [11/09/2005 02:06] - “C:\Documents and Settings\J?rme et Sophie\Application Data\drivers\winupgro.exe”
Found ! [30/01/2009 17:23] - “C:\Documents and Settings\J?rme et Sophie\Application Data\drivers\downld”
################## [ C:\DOCUME~1\JRMEET~1\LOCALS~1\Temp ]
\\\\\\\\\ [ Registre / Startup ] ///////////////////
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
WOOKIT=C:\PROGRA~1\Wanadoo\Shell.exe appLaunchClientZone.shl|PARAM= cnx
Skype=“C:\APPS\skype\Phone\Skype.exe” /nosplash /minimized
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\run]
WOOWATCH=C:\PROGRA~1\Wanadoo\Watch.exe
WOOTASKBARICON=C:\PROGRA~1\Wanadoo\GestMaj.exe TaskBarIcon.exe
TkBellExe=“C:\Program Files\Fichiers communs\Real\Update_OB\realsched.exe” -osboot
SynTPLpr=C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
SynTPEnh=C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
SunJavaUpdateSched=“C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe”
STDSB=C:\WINDOWS\system32\drivers\STDSB.exe
Raccourci vers la page des propriétés de High Definition Audio=HDAShCut.exe
QuickTime Task=“C:\Program Files\QuickTime\qttask.exe” -atboottime
PHIME2002ASync=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
PHIME2002A=C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
PCMService=“c:\Apps\Powercinema\PCMService.exe”
NWEReboot=
IMJPMIG8.1=“C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE” /Spoil /RemAdvDef /Migration32
igfxtray=C:\WINDOWS\system32\igfxtray.exe
igfxpers=C:\WINDOWS\system32\igfxpers.exe
igfxhkcmd=C:\WINDOWS\system32\hkcmd.exe
Icon=C:\WINDOWS\system32\drivers\Icon.exe
AzMixerSel=C:\Program Files\Realtek\InstallShield\AzMixerSel.exe
RTHDCPL=RTHDCPL.EXE
Alcmtr=ALCMTR.EXE
KernelFaultCheck=%systemroot%\system32\dumprep 0 -k
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents=
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL=
Installed=1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI=
Installed=1
NoChange=1
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS=
Installed=1
[HKEY_CURRENT_USER\software\local appwizard-generated applications\serial]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\Watch]
[HKEY_CURRENT_USER\software\local appwizard-generated applications\winupgro]
\\\\\\\\\ [ Registre / Clés infectieuses ] ///////////////////
Found ! - HKEY_USERS\S-1-5-21-2152261890-3471989487-3052476579-1006\Software\Local AppWizard-Generated Applications\serial
Found ! - HKEY_USERS\S-1-5-21-2152261890-3471989487-3052476579-1006\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_USERS\S-1-5-21-2152261890-3471989487-3052476579-1006\Software\bisoft
Found ! - HKEY_USERS\S-1-5-21-2152261890-3471989487-3052476579-1006\Software\DateTime4
Found ! - HKEY_USERS\S-1-5-21-2152261890-3471989487-3052476579-1006\Software\FFC
Found ! - HKEY_USERS\S-1-5-21-2152261890-3471989487-3052476579-1006\Software\FirtR
Found ! - HKEY_USERS\S-1-5-21-2152261890-3471989487-3052476579-1006\Software\MuleAppData
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\serial
Found ! - HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Enum\Root\LEGACY_SK9OU0S
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! - HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\sK9Ou0s
Found ! - HKEY_CURRENT_USER\Software\bisoft
Found ! - HKEY_CURRENT_USER\Software\DateTime4
Found ! - HKEY_CURRENT_USER\Software\FirtR
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | drvsyskit
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | german.exe
Found ! - [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] | mule_st_key
/!\ Infection active : HKLM\SYSTEM…\Services\srosa -> Start = 0x1
/!\ Infection active : HKLM\SYSTEM…\Services\sK9Ou0s -> Start = 0x1
\\\\\\\\\ [ Etat / Services ] ///////////////////
Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot
/!\ Mode sans echec non fonctionnel !!
Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal
/!\ Mode sans echec non fonctionnel !!
Clé manquante : HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network
/!\ Mode sans echec non fonctionnel !!
Services : [ Auto=2 / Demande=3 / Désactivé=4 ]
/!\ Ndisuio - # Type de démarrage = 4
/!\ Ip6Fw - # Type de démarrage = 4
/!\ SharedAccess - # Type de démarrage = 4
/!\ wuauserv - # Type de démarrage = 4
/!\ wscsvc - # Type de démarrage = 4
\\\\\\\\\ [ Recherche dans supports amovibles] ///////////////////
Informations :
C: - Lecteur fixe
presence des fichiers :
\\\\\\\\\ [ Registre / Mountpoint2 ] ///////////////////
-> Not found !
################## [ ! Fin du rapport # FindyKill V4.715 ! ]
[/spoiler]