spywarefighter me detecte des virus il les mets en quarantaine
je les supprime mais ils reviennent je ne peux plus lire des fichiers audios
voici le rapport
Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows XP . (5.1.2600) Service Pack 3
[32_bits] - x86 Family 6 Model 15 Stepping 6, GenuineIntel
.
[wscsvc] STOPPED (state:1) : Security Center -> Disabled !
[SharedAccess] STOPPED (state:1) : Windows Firewall -> Disabled !
.
Internet Explorer 6.0.2900.5512
.
C:\ [Fixed-NTFS] .. ( Total:225 Go - Free:125 Go )
D:\ [CD_Rom]
E:\ [Removable]
F:\ [Removable]
G:\ [Removable]
H:\ [Removable]
.
Scan : 20:03.11
Path : C:\Documents and Settings\cerda\Local Settings\Temporary Internet Files\Content.IE5\8TA7ST63\Rooter[1].exe
User : cerda ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
______ System (4)
______ \SystemRoot\System32\smss.exe (644)
______ \??\C:\WINDOWS\system32\csrss.exe (692)
______ \??\C:\WINDOWS\system32\winlogon.exe (716)
______ C:\WINDOWS\system32\services.exe (760)
______ C:\WINDOWS\system32\lsass.exe (772)
______ C:\WINDOWS\system32\svchost.exe (948)
______ C:\WINDOWS\system32\svchost.exe (996)
______ C:\WINDOWS\System32\svchost.exe (1096)
______ C:\WINDOWS\system32\svchost.exe (1136)
______ C:\WINDOWS\system32\svchost.exe (1188)
______ C:\WINDOWS\system32\svchost.exe (1288)
______ C:\WINDOWS\system32\spoolsv.exe (1340)
______ C:\WINDOWS\Explorer.EXE (1672)
______ C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe (1808)
______ C:\WINDOWS\RTHDCPL.EXE (1844)
______ C:\WINDOWS\system32\RUNDLL32.EXE (1896)
______ C:\Program Files\HP\HP Software Update\HPWuSchd2.exe (1924)
______ C:\Program Files\Fichiers communs\AOL\1235769479\ee\AOLSoftware.exe (1932)
______ C:\WINDOWS\ehome\ehtray.exe (1940)
______ C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe (1948)
______ C:\apps\ABoard\ABoard.exe (204)
______ C:\apps\ABoard\AOSD.exe (212)
______ C:\Program Files\Fighters\SPYWAREfighter\SWPROTray.exe (220)
______ C:\Program Files\QuickTime\qttask.exe (284)
______ C:\Program Files\OFFICE One6.5\OFFICE One PDF Manager\OoPDFSettingsv6.exe (280)
______ C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (392)
______ C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (532)
______ C:\Program Files\Windows Live\Messenger\msnmsgr.exe (544)
______ C:\Program Files\GameShadow\GameShadow.exe (560)
______ C:\WINDOWS\system32\svchost.exe (1068)
______ C:\Program Files\AOL 9.0b\aoltray.exe (1080)
______ C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe (1432)
______ C:\Documents and Settings\cerda\Application Data\Microsoft\Notification de cadeaux MSN\lsnfier.exe (820)
______ C:\Program Files\OFFICE One6.5\program\soffice.exe (1628)
______ C:\PROGRA~1\FICHIE~1\AOL\ACS\AOLacsd.exe (1468)
______ C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe (1972)
______ C:\Program Files\Fichiers communs\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (2052)
______ C:\Program Files\Fichiers communs\Common Toolkit Suite\AVEngine\AVScanningService.exe (2152)
______ C:\Program Files\Bonjour\mDNSResponder.exe (2324)
______ C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterSuiteService.exe (2444)
______ C:\WINDOWS\eHome\ehRecvr.exe (2600)
______ C:\Program Files\Java\jre6\bin\jqs.exe (2688)
______ C:\WINDOWS\eHome\ehRec.exe (2716)
______ C:\WINDOWS\system32\nvsvc32.exe (2736)
______ C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe (2928)
______ C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (3004)
______ C:\WINDOWS\system32\svchost.exe (3136)
______ C:\WINDOWS\system32\svchost.exe (3220)
______ C:\Program Files\Fichiers communs\Ulead Systems\DVD\ULCDRSvr.exe (3272)
______ C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe (3332)
______ C:\WINDOWS\wanmpsvc.exe (3356)
______ C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe (3420)
______ C:\WINDOWS\ehome\mcrdsvc.exe (3444)
______ C:\WINDOWS\eHome\ehmsas.exe (3936)
______ C:\Program Files\PC Connectivity Solution\ServiceLayer.exe (4076)
______ C:\Program Files\PC Connectivity Solution\Transports\NclUSBSrv.exe (1736)
______ C:\WINDOWS\System32\svchost.exe (1592)
______ C:\Program Files\PC Connectivity Solution\Transports\NclRSSrv.exe (2256)
______ C:\WINDOWS\system32\dllhost.exe (2564)
______ C:\WINDOWS\system32\wbem\wmiapsrv.exe (1124)
______ C:\Program Files\Fichiers communs\Common Toolkit Suite\FighterLauncher.exe (2424)
______ C:\Program Files\AOL 9.0b\waol.exe (840)
______ C:\Program Files\AOL 9.0b\shellmon.exe (3812)
______ C:\Program Files\Fichiers communs\Aol\aoltpspd.exe (1480)
______ C:\Program Files\Nero\Nero 7\Nero StartSmart\NeroStartSmart.exe (1316)
______ C:\Program Files\Fichiers communs\Ahead\Lib\NMIndexingService.exe (3024)
______ C:\Program Files\Nero\Nero 7\Core\nero.exe (2724)
______ C:\Documents and Settings\cerda\Local Settings\Temporary Internet Files\Content.IE5\8TA7ST63\Rooter[1].exe (3056)
______ C:\WINDOWS\system32\imapi.exe (3596)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:8381528064)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:8381560320 | Length:241666951680)
.
----------------------\\ Scheduled Tasks
.
C:\WINDOWS\Tasks\B3CC6D14917819A8.job
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\SA.DAT
.
----------------------\\ Registry
.
Rootkit! ... [HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA]
Rootkit! ... [HKLM\SYSTEM\ControlSet001\Services\srosa]
Rootkit! ... [HKLM\SYSTEM\ControlSet002\Enum\Root\LEGACY_SROSA]
Rootkit! ... [HKLM\SYSTEM\ControlSet002\Services\srosa]
Rootkit! ... [HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA]
Rootkit! ... [HKLM\SYSTEM\CurrentControlSet\Services\srosa]
.
----------------------\\ Files & Folders
.
C:\DOCUME~1\cerda\APPLIC~1\m
C:\DOCUME~1\cerda\APPLIC~1\drivers
C:\WINDOWS\system32\mdelk.exe
C:\WINDOWS\system32\srosa2.sys
C:\WINDOWS\system32\mdelk.exe <- Hidden file !!
==> Bagle <==
.
----------------------\\ Scan completed at 20:04.04
.
C:\Rooter$\Rooter_1.txt - (10/01/2010 | 20:04.04)
merci de votre aide je ne sait plus quoi faire pour le supprimer definitivement













. M'enfin, contrairement à toi, j'ai tout de même dit bonjour 
