0 Members and 1 Guest are viewing this topic.
RogueKiller V10.0.1.0 [Oct 10 2014] par Adlice Softwareemail : http://www.adlice.com/contact/Remontées : http://forum.adlice.comSite web : https://www.surlatoile.org/RogueKiller/Blog : http://www.adlice.comSystème d'exploitation : Windows 8.1 (6.3.9200 ) 64 bits versionDémarré en : Mode normalUtilisateur : ckylydia [Administrateur]Mode : Suppression -- Date : 10/15/2014 15:26:57¤¤¤ Processus : 0 ¤¤¤¤¤¤ Registre : 22 ¤¤¤[PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-4012679515-2461350271-2367464994-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 0 -> Remplacé(e) (0)[PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-4012679515-2461350271-2367464994-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 0 -> Remplacé(e) (0)[PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-4012679515-2461350271-2367464994-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:64828;https=127.0.0.1:64828 -> ERROR [0][PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-4012679515-2461350271-2367464994-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : http=127.0.0.1:64828;https=127.0.0.1:64828 -> ERROR [2][PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://go.microsoft.com/fwlink/p/?LinkId=255141 -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)[PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://go.microsoft.com/fwlink/p/?LinkId=255141 -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)[PUM.HomePage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://go.microsoft.com/fwlink/p/?LinkId=255141 -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)[PUM.HomePage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Start Page : http://go.microsoft.com/fwlink/p/?LinkId=255141 -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)[PUM.HomePage] (X64) HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main | Start Page : http://go.microsoft.com/fwlink/p/?LinkId=255141 -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)[PUM.HomePage] (X86) HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main | Start Page : http://go.microsoft.com/fwlink/p/?LinkId=255141 -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)[PUM.HomePage] (X64) HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main | Start Page : http://go.microsoft.com/fwlink/p/?LinkId=255141 -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)[PUM.HomePage] (X86) HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main | Start Page : http://go.microsoft.com/fwlink/p/?LinkId=255141 -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)[PUM.HomePage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://go.microsoft.com/fwlink/p/?LinkId=255141 -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)[PUM.HomePage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Start Page : http://go.microsoft.com/fwlink/p/?LinkId=255141 -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141)[PUM.SearchPage] (X64) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : http://go.microsoft.com/fwlink/?LinkId=54896 -> Remplacé(e) (http://go.microsoft.com/fwlink/?LinkId=54896)[PUM.SearchPage] (X86) HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : http://go.microsoft.com/fwlink/?LinkId=54896 -> Remplacé(e) (http://go.microsoft.com/fwlink/?LinkId=54896)[PUM.SearchPage] (X64) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : http://go.microsoft.com/fwlink/?LinkId=54896 -> Remplacé(e) (http://go.microsoft.com/fwlink/?LinkId=54896)[PUM.SearchPage] (X86) HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : http://go.microsoft.com/fwlink/?LinkId=54896 -> Remplacé(e) (http://go.microsoft.com/fwlink/?LinkId=54896)[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 0 -> Remplacé(e) (0)[PUM.DesktopIcons] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 0 -> Remplacé(e) (0)[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 0 -> Remplacé(e) (0)[PUM.DesktopIcons] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {59031a47-3f72-44a7-89c5-5595fe6b30ee} : 0 -> Remplacé(e) (0)¤¤¤ Tâches : 1 ¤¤¤[Suspicious.Path] \\5039 -- wscript.exe (C:\Users\ckylydia\AppData\Local\Temp\launchie.vbs //B) -> ERROR [0]¤¤¤ Fichiers : 0 ¤¤¤¤¤¤ Fichier Hosts : 5 ¤¤¤[C:\WINDOWS\System32\drivers\etc\hosts] 127.0.0.1 localhost[C:\WINDOWS\System32\drivers\etc\hosts] 127.0.0.1 localhost[C:\WINDOWS\System32\drivers\etc\hosts] 127.0.0.1 localhost[C:\WINDOWS\System32\drivers\etc\hosts] 127.0.0.1 localhost[C:\WINDOWS\System32\drivers\etc\hosts] 127.0.0.1 localhost¤¤¤ Antirootkit : 0 (Driver: Non chargé [0xc000036b]) ¤¤¤¤¤¤ Navigateurs web : 1 ¤¤¤[PUM.Proxy][FIREFX:Config] 2iwd5s3g.default-1384638005512 : user_pref("network.proxy.type", 4); -> Non sélectionn餤¤ Vérification MBR : ¤¤¤+++++ PhysicalDrive0: ST750LM022 HN-M750MBB +++++--- User ---[MBR] 015cec21cece8320ecbef8d89ab63348[BSP] 76ada718ff6c1e13b5a8f98a611b7923 : Empty MBR CodePartition table:0 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 1 | Size: 715404 MBUser = LL1 ... OKUser = LL2 ... OK============================================RKreport_SCN_10152014_151817.log - RKreport_DEL_10152014_152305.log - RKreport_DEL_10152014_152343.log - RKreport_DEL_10152014_152533.logRKreport_DEL_10152014_152538.log