RogueKiller V8.8.4 [Jan 27 2014] par Tigzy mail : tigzyRKgmailcom Remontees : http://www.adlice.com/forum/ Site Web : http://www.sur-la-toile.com/RogueKiller/ Blog : http://www.adlice.com Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Demarrage : Mode normal Utilisateur : Sifou [Droits d'admin] Mode : Suppression -- Date : 01/29/2014 22:28:54 | ARK || FAK || MBR | ¤¤¤ Processus malicieux : 22 ¤¤¤ [SUSP PATH] TorchCrashHandler.exe -- C:\Users\Sifou\AppData\Local\Torch\Update\TorchCrashHandler.exe [7] -> TUÉ [TermProc] [SUSP PATH] WebPlayer.exe -- C:\Users\Sifou\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe [-] -> TUÉ [TermProc] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermProc] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] TorchUpdate.exe -- C:\Users\Sifou\AppData\Local\Torch\Update\29.0.0.5394\TorchUpdate.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] [SUSP PATH] torch.exe -- C:\Users\Sifou\AppData\Local\Torch\Application\torch.exe [7] -> TUÉ [TermThr] ¤¤¤ Entrees de registre : 10 ¤¤¤ [RUN][SUSP PATH] HKCU\[...]\Run : FLV Player (C:\Users\Sifou\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe [-]) -> SUPPRIMÉ [RUN][SUSP PATH] HKUS\S-1-5-21-3090216136-1089555751-1348982102-1000\[...]\Run : FLV Player (C:\Users\Sifou\AppData\Local\WebPlayer\FLV Player\WebPlayer.exe [-]) -> [0x2] Le fichier spécifié est introuvable. [IFEO] HKLM\[...]\bitguard.exe : Debugger (tasklist.exe [x]) -> SUPPRIMÉ [IFEO] HKLM\[...]\bprotect.exe : Debugger (tasklist.exe [x]) -> SUPPRIMÉ [IFEO] HKLM\[...]\browserdefender.exe : Debugger (tasklist.exe [x]) -> SUPPRIMÉ [IFEO] HKLM\[...]\browserprotect.exe : Debugger (tasklist.exe [x]) -> SUPPRIMÉ [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> REMPLACÉ (1) [HJ SMENU][PUM] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REMPLACÉ (1) [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REMPLACÉ (0) [HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REMPLACÉ (0) ¤¤¤ Tâches planifiées : 0 ¤¤¤ ¤¤¤ Entrées Startup : 0 ¤¤¤ ¤¤¤ Navigateurs web : 0 ¤¤¤ ¤¤¤ Addons navigateur : 0 ¤¤¤ ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤ ¤¤¤ Driver : [NON CHARGE 0x0] ¤¤¤ ¤¤¤ Ruches Externes: ¤¤¤ ¤¤¤ Infection : ¤¤¤ ¤¤¤ Fichier HOSTS: ¤¤¤ --> %SystemRoot%\System32\drivers\etc\hosts ¤¤¤ MBR Verif: ¤¤¤ +++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) TOSHIBA MK5076GSX ATA Device +++++ --- User --- [MBR] c59840215e9baa79c06a19cf6eacb30e [BSP] d2ab8ded279f5172c86bd5083bb8f3fc : Windows 7/8 MBR Code Partition table: 0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 Mo 1 - [XXXXXX] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 80325 | Size: 0 Mo 2 - [ACTIVE] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 81920 | Size: 2000 Mo 3 - [XXXXXX] LINUX-SWP (0x42) [VISIBLE] Offset (sectors): 413777920 | Size: 100000 Mo User = LL1 ... OK! User = LL2 ... OK! Termine : << RKreport[0]_D_01292014_222854.txt >> RKreport[0]_S_01292014_222128.txt