bonsoir voila le rapport j'ai pas osé cliquer sur supprimer encore
RogueKiller V9.2.8.0 [Jul 11 2014] par Adlice Software
Mail :
http://www.adlice.com/contact/
Remontées :
http://forum.adlice.com
Site Web :
http://www.surlatoile.org/RogueKiller/
Blog :
http://www.adlice.com
Système d'exploitation : Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Démarrage : Mode normal
Utilisateur : jenny [Droits d'admin]
Mode : Recherche -- Date : 08/27/2014 23:42:01
¤¤¤ Processus malicieux : 1 ¤¤¤
[Proc.Svchost] svchost.exe -- [x] - TUÉ [TermProc]
¤¤¤ Entrées de registre : 16 ¤¤¤
[Suspicious.Path] HKEY_USERS\S-1-5-21-71905463-2223446842-3904372799-1000\Software\Microsoft\Windows\CurrentVersion\Run | Fxililucipihaxi : rundll32.exe "C:\Users\jenny\AppData\Local\KBDRDMO.dll",Startup - TROUVÉ
[Suspicious.Path] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce | End_Install : C:\Users\jenny\AppData\Local\Temp\SHK0.bat - TROUVÉ
[PUM.Policies] HKEY_USERS\S-1-5-21-71905463-2223446842-3904372799-1000\Software\Microsoft\Windows\CurrentVersion\Policies\System | DisableRegistryTools : 0 - TROUVÉ
[PUM.SecurityCenter] HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center | AntiVirusDisableNotify : 0x00000000 - TROUVÉ
[PUM.SecurityCenter] HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center | FirewallDisableNotify : 0x00000000 - TROUVÉ
[PUM.SecurityCenter] HKEY_LOCAL_MACHINE\Software\Microsoft\Security Center | UpdatesDisableNotify : 0x00000000 - TROUVÉ
[PUM.StartMenu] HKEY_USERS\S-1-5-21-71905463-2223446842-3904372799-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_TrackProgs : 0 - TROUVÉ
[PUM.StartMenu] HKEY_USERS\S-1-5-21-71905463-2223446842-3904372799-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowPrinters : 0 - TROUVÉ
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-71905463-2223446842-3904372799-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {645FF040-5081-101B-9F08-00AA002F954E} : 1 - TROUVÉ
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-71905463-2223446842-3904372799-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\ClassicStartMenu | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 - TROUVÉ
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-71905463-2223446842-3904372799-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {645FF040-5081-101B-9F08-00AA002F954E} : 1 - TROUVÉ
[PUM.DesktopIcons] HKEY_USERS\S-1-5-21-71905463-2223446842-3904372799-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\HideDesktopIcons\NewStartPanel | {20D04FE0-3AEA-1069-A2D8-08002B30309D} : 1 - TROUVÉ
[PUM.HomePage] HKEY_USERS\S-1-5-21-71905463-2223446842-3904372799-1000\Software\Microsoft\Internet Explorer\Main | Start Page :
http://www.orange.fr - TROUVÉ
[PUM.SearchPage] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main | Search Page : - TROUVÉ
[PUM.SearchPage] HKEY_USERS\S-1-5-21-71905463-2223446842-3904372799-1000\Software\Microsoft\Internet Explorer\Main | Search Page : - TROUVÉ
[PUM.SearchPage] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main | Search Page : - TROUVÉ
¤¤¤ Tâches planifiées : 1 ¤¤¤
[Suspicious.Path] \\4729 -- wscript.exe (C:\Users\jenny\AppData\Local\Temp\launchie.vbs //B) - TROUVÉ
¤¤¤ Fichiers : 2 ¤¤¤
[Tr.Karagany][Repertoire] plugs -- C:\Users\jenny\AppData\Roaming\Adobe\plugs - TROUVÉ
[Tr.Karagany][Repertoire] shed -- C:\Users\jenny\AppData\Roaming\Adobe\shed - TROUVÉ
¤¤¤ Fichier HOSTS : 0 [Too big!] ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: CHARGE) ¤¤¤
¤¤¤ Navigateurs web : 2 ¤¤¤
[PUP][FIREFX:Addon] s6tcnvgw.default : 7Go [
7go@7go.com] - TROUVÉ
[PUM.HomePage][FIREFX:Config] s6tcnvgw.default : user_pref("browser.startup.homepage", "
www.google.fr"); - TROUVÉ
¤¤¤ MBR Verif : ¤¤¤
+++++ PhysicalDrive0: ST316081 5AS SCSI Disk Device +++++
--- User ---
[MBR] feb06f9c450c077aeb1a14dfc8380146
[BSP] a10dcff80d1b3c1d6c73c3db5a710b56 : Acer MBR Code
Partition table:
0 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 10240 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 20973568 | Size: 71187 MB
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 166764591 | Size: 71196 MB
User = LL1 ... OK
Error reading LL2 MBR! ([1] Fonction incorrecte. )
+++++ PhysicalDrive1: Generic External USB Device +++++
--- User ---
[MBR] c673d2b8c619816e89508f74e459a16f
[BSP] 83c9cbd1045bc1ab41fb5e6a690ecefd : Windows XP MBR Code
Partition table:
0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 238472 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] Cette demande n'est pas prise en charge. )
+++++ PhysicalDrive2: Generic Flash Disk USB Device +++++
--- User ---
[MBR] 270d9fece61dd50e33750d35cf962c5e
[BSP] da3282757247b054c0cd2c0d7cf76231 : Legit.Unknown MBR Code
Partition table:
0 - [ACTIVE] FAT16-LBA (0xe) [VISIBLE] Offset (sectors): 128 | Size: 2007 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] Cette demande n'est pas prise en charge. )