Après quelques lectures du fofo peut-être ce rapport effectué avec Elibagla.exe sera utile :
(19-5-2009 16:33:22)
EliStartPage v18.63 ©2009 S.G.H. / Satinfo S.L. (Actualizado el 18 de Mayo del 2009)
Lista de Acciones (por Acción Directa):
Restaurada Clave: “SafeBoot\Minimal y Network”
No detectado SP3 d
(19-5-2009 16:33:22)
EliStartPage v18.63 ©2009 S.G.H. / Satinfo S.L. (Actualizado el 18 de Mayo del 2009)
Lista de Acciones (por Acción Directa):
Restaurada Clave: “SafeBoot\Minimal y Network”
No detectado SP3 de Windows XP
Eliminadas las Paginas de Inicio y de Busqueda del IE
Eliminados Ficheros Temporales del IE
(19-5-2009 16:33:59)
EliStartPage v18.63 ©2009 S.G.H. / Satinfo S.L. (Actualizado el 18 de Mayo del 2009)
Lista de Acciones (por Exploración):
Explorando “C:”
Nº Total de Directorios: 3221
Nº Total de Ficheros: 41152
Nº de Ficheros Analizados: 17994
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
(19-5-2009 16:41:03)
EliStartPage v18.63 ©2009 S.G.H. / Satinfo S.L. (Actualizado el 18 de Mayo del 2009)
Lista de Acciones (por Exploración):
Explorando “D:”
Nº Total de Directorios: 278
Nº Total de Ficheros: 3604
Nº de Ficheros Analizados: 982
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
e Windows XP
Eliminadas las Paginas de Inicio y de Busqueda del IE
Eliminados Ficheros Temporales del IE
(19-5-2009 16:33:59)
EliStartPage v18.63 ©2009 S.G.H. / Satinfo S.L. (Actualizado el 18 de Mayo del 2009)
Lista de Acciones (por Exploración):
Explorando “C:”
Nº Total de Directorios: 3221
Nº Total de Ficheros: 41152
Nº de Ficheros Analizados: 17994
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
(19-5-2009 16:41:03)
EliStartPage v18.63 ©2009 S.G.H. / Satinfo S.L. (Actualizado el 18 de Mayo del 2009)
Lista de Acciones (por Exploración):
Explorando “D:”
Nº Total de Directorios: 278
Nº Total de Ficheros: 3604
Nº de Ficheros Analizados: 982
Nº de Ficheros Infectados: 0
Nº de Ficheros Limpiados: 0
Mon gros souci c'est que je n'arrive pas à enlever les fichiers qui mis le bordel : ils restent dans ma corbeille m'indiquant
- "impossible de supprimer le dossier backup: le dossier est vide"
- "impossible de supprimer le dossier Dd4:le répertoire n'est pas vide"
et voici le rapport findykill
############################## [ FindyKill V4.729 ]
User : Fred Et Gege (Administrateurs) # FRED-GEGE
Update on 19/05/09 by Chiquitine29
Start at: 19:12:40 | 19/05/2009
AMD Athlon™ 64 Processor 3500+
Microsoft Windows XP Professionnel (5.1.2600 32-bit) # Service Pack 2
Internet Explorer 6.0.2900.2180
Windows Firewall Status : Enabled
A:\ # Lecteur de disquettes 3 ½ pouces
C:\ # Disque fixe local # 50 Go (23,99 Go free) # NTFS
D:\ # Disque fixe local # 40 Go (4,97 Go free) [DATA] # NTFS
E:\ # Disque fixe local # 39,98 Go (15,38 Go free) [SAUVEGARDE] # FAT32
F:\ # Disque fixe local # 22,66 Go (17,94 Go free) [PARTAGE TVIX] # NTFS
G:\ # Disque CD-ROM
############################## [ Processus actifs ]
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\nvraidservice.exe
C:\Program Files\Gigabyte\ET5\GUI.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\OLITEC\UI.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Documents and Settings\Fred Et Gege\Application Data\drivers\winupgro.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Documents and Settings\Fred Et Gege\Application Data\m\flec006.exe
C:\WINDOWS\system32\wintems.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
################## [ Processus infectieux stoppés ]
“C:\Documents and Settings\Fred Et Gege\Application Data\drivers\winupgro.exe” (688)
“C:\Documents and Settings\Fred Et Gege\Application Data\m\flec006.exe” (1188)
“C:\WINDOWS\system32\wintems.exe” (416)
################## [ Fichiers / Dossiers infectieux ]
Found ! C:\WINDOWS\Prefetch\1178140.EXE-01E1FB3A.pf
Found ! C:\WINDOWS\Prefetch\1303921.EXE-2A5770E6.pf
Found ! C:\WINDOWS\Prefetch\1320734.EXE-228554AC.pf
Found ! C:\WINDOWS\Prefetch\15089968.EXE-0D460C4F.pf
Found ! C:\WINDOWS\Prefetch\15208203.EXE-28D17EEC.pf
Found ! C:\WINDOWS\Prefetch\15213312.EXE-21A6891B.pf
Found ! C:\WINDOWS\Prefetch\15230453.EXE-395FA642.pf
Found ! C:\WINDOWS\Prefetch\15496109.EXE-03EDA585.pf
Found ! C:\WINDOWS\Prefetch\1600718.EXE-1CD0A948.pf
Found ! C:\WINDOWS\Prefetch\167187.EXE-0A21183A.pf
Found ! C:\WINDOWS\Prefetch\181859.EXE-383421E9.pf
Found ! C:\WINDOWS\Prefetch\288515.EXE-19D65294.pf
Found ! C:\WINDOWS\Prefetch\29949953.EXE-25F36B02.pf
Found ! C:\WINDOWS\Prefetch\30087109.EXE-3AC60E8C.pf
Found ! C:\WINDOWS\Prefetch\30091312.EXE-0DE533E5.pf
Found ! C:\WINDOWS\Prefetch\30112421.EXE-07B3D278.pf
Found ! C:\WINDOWS\Prefetch\30368484.EXE-01083E76.pf
Found ! C:\WINDOWS\Prefetch\344968.EXE-1FDB188B.pf
Found ! C:\WINDOWS\Prefetch\349796.EXE-19A486F3.pf
Found ! C:\WINDOWS\Prefetch\353500.EXE-18CFCCB5.pf
Found ! C:\WINDOWS\Prefetch\359390.EXE-31BA37A5.pf
Found ! C:\WINDOWS\Prefetch\375640.EXE-1F169847.pf
Found ! C:\WINDOWS\Prefetch\376734.EXE-12279DAF.pf
Found ! C:\WINDOWS\Prefetch\423062.EXE-161AEA70.pf
Found ! C:\WINDOWS\Prefetch\430281.EXE-39DEE793.pf
Found ! C:\WINDOWS\Prefetch\455421.EXE-2BEB8076.pf
Found ! C:\WINDOWS\Prefetch\630140.EXE-102A65D6.pf
Found ! C:\WINDOWS\Prefetch\677500.EXE-0B357F5A.pf
Found ! C:\WINDOWS\Prefetch\775234.EXE-01F9B186.pf
Found ! C:\WINDOWS\Prefetch\FLEC006.EXE-02E42C44.pf
Found ! C:\WINDOWS\Prefetch\KEY_GEN.EXE-0ACCF1AA.pf
Found ! C:\WINDOWS\Prefetch\MDELK.EXE-1D176F91.pf
Found ! C:\WINDOWS\Prefetch\WINTEMS.EXE-2A563F9B.pf
Found ! C:\WINDOWS\system32\ban_list.txt
Found ! C:\WINDOWS\system32\mdelk.exe
Found ! C:\WINDOWS\system32\wintems.exe
Found ! C:\WINDOWS\system32\drivers\down
Found ! “C:\Documents and Settings\Fred Et Gege\Application Data\drivers”
Found ! “C:\Documents and Settings\Fred Et Gege\Application Data\drivers\downld”
Found ! “C:\Documents and Settings\Fred Et Gege\Application Data\drivers\srosa2.sys”
Found ! “C:\Documents and Settings\Fred Et Gege\Application Data\drivers\wfsintwq.sys”
Found ! “C:\Documents and Settings\Fred Et Gege\Application Data\drivers\winupgro.exe”
Found ! “C:\Documents and Settings\Fred Et Gege\Application Data\m”
Found ! “C:\Documents and Settings\Fred Et Gege\Application Data\m\data.oct”
Found ! “C:\Documents and Settings\Fred Et Gege\Application Data\m\flec006.exe”
Found ! “C:\Documents and Settings\Fred Et Gege\Application Data\m\list.oct”
Found ! “C:\Documents and Settings\Fred Et Gege\Application Data\m\shared”
Found ! “C:\Documents and Settings\Fred Et Gege\Application Data\m\srvlist.oct”
################## [ Infected Temp Files ]
################## [ Registre / Clés infectieuses ]
Found ! HKEY_USERS\S-1-5-21-2000478354-1580436667-725345543-1003\Software\Local AppWizard-Generated Applications\key_gen
Found ! HKEY_USERS\S-1-5-21-2000478354-1580436667-725345543-1003\Software\Local AppWizard-Generated Applications\winupgro
Found ! HKEY_USERS\S-1-5-21-2000478354-1580436667-725345543-1003\Software\bisoft
Found ! HKEY_USERS\S-1-5-21-2000478354-1580436667-725345543-1003\Software\DateTime4
Found ! HKEY_USERS\S-1-5-21-2000478354-1580436667-725345543-1003\Software\FFC
Found ! HKEY_USERS\S-1-5-21-2000478354-1580436667-725345543-1003\Software\MuleAppData
Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\key_gen
Found ! HKEY_CURRENT_USER\Software\Local AppWizard-Generated Applications\winupgro
Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\srosa
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\srosa
Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sK9Ou0s
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sK9Ou0s
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sK9Ou0s
Found ! HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SK9OU0S
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_SK9OU0S
Found ! HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Enum\Root\LEGACY_SK9OU0S
Found ! HKEY_CURRENT_USER\Software\bisoft
Found ! HKEY_CURRENT_USER\Software\DateTime4
Found ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\“drvsyskit”
Found ! HKEY_USERS\S-1-5-21-2000478354-1580436667-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\“drvsyskit”
Found ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\“german.exe”
Found ! HKEY_USERS\S-1-5-21-2000478354-1580436667-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\“german.exe”
Found ! HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\“mule_st_key”
Found ! HKEY_USERS\S-1-5-21-2000478354-1580436667-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\“mule_st_key”
(!) HKLM\SYSTEM…\Services\srosa -> Start = 0x1
(!) HKLM\SYSTEM…\Services\sK9Ou0s -> Start = 0x1
################## [ Recherche dans supports amovibles]
Found ! C:\InfoSat.txt
################## [ Registre / Mountpoints2 ]
-> Not found !
################## [ ! Fin du rapport # FindyKill V4.729 ! ]