RogueKiller V12.9.0.0 (x64) [Dec 26 2016] (Gratuit) par Adlice Software email : http://www.adlice.com/contact/ Remontées : http://forum.adlice.com Site web : http://www.adlice.com/fr/download/roguekiller/ Blog : http://www.adlice.com Système d'exploitation : Windows 7 (6.1.7600) 64 bits version Démarré en : Mode normal Utilisateur : USER [Administrateur] Démarré depuis : C:\Program Files\RogueKiller\RogueKiller64.exe Mode : Scan -- Date : 12/29/2016 20:18:22 (Durée : 01:11:09) ¤¤¤ Processus : 0 ¤¤¤ ¤¤¤ Registre : 26 ¤¤¤ [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\FFPluginHp -> Trouvé(e) [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\istartsurfSoftware -> Trouvé(e) [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\WdsManPro -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-506902913-3260032894-634671402-1000\Software\AutoTime -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-506902913-3260032894-634671402-1000\Software\csastats -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-506902913-3260032894-634671402-1000\Software\IM -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-506902913-3260032894-634671402-1000\Software\Installer -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-506902913-3260032894-634671402-1000\Software\ProductSetup -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-506902913-3260032894-634671402-1000\Software\AutoTime -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-506902913-3260032894-634671402-1000\Software\csastats -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-506902913-3260032894-634671402-1000\Software\IM -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-506902913-3260032894-634671402-1000\Software\Installer -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-506902913-3260032894-634671402-1000\Software\ProductSetup -> Trouvé(e) [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\ContentPush -> Trouvé(e) [PUP.Gen0|PUP.Gen1|Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\CloudPrinter (C:\ProgramData\\CloudPrinter\\CloudPrinter.exe shuz -f "C:\ProgramData\\CloudPrinter\\CloudPrinter.dat" -l -a) -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Hotfresh (C:\ProgramData\\Hotfresh\\Hotfresh.exe shuz -f "C:\ProgramData\\Hotfresh\\Hotfresh.dat" -l -a) -> Trouvé(e) [PUP.Gen0|PUP.Gen1|Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\CloudPrinter (C:\ProgramData\\CloudPrinter\\CloudPrinter.exe shuz -f "C:\ProgramData\\CloudPrinter\\CloudPrinter.dat" -l -a) -> Trouvé(e) [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Hotfresh (C:\ProgramData\\Hotfresh\\Hotfresh.exe shuz -f "C:\ProgramData\\Hotfresh\\Hotfresh.dat" -l -a) -> Trouvé(e) [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters | DhcpNameServer : 192.168.1.1 0.0.0.0 ([-][]) -> Trouvé(e) [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters | DhcpNameServer : 192.168.1.1 0.0.0.0 ([-][]) -> Trouvé(e) [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{31DED5EE-F557-43D5-9AB9-4A3FFAD59072} | DhcpNameServer : 192.168.1.1 0.0.0.0 ([-][]) -> Trouvé(e) [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Tcpip\Parameters\Interfaces\{31DED5EE-F557-43D5-9AB9-4A3FFAD59072} | DhcpNameServer : 192.168.1.1 0.0.0.0 ([-][]) -> Trouvé(e) [PUM.StartMenu] (X64) HKEY_USERS\S-1-5-21-506902913-3260032894-634671402-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Trouvé(e) [PUM.StartMenu] (X86) HKEY_USERS\S-1-5-21-506902913-3260032894-634671402-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowMyGames : 0 -> Trouvé(e) [HJ.Browser] (X64) HKEY_LOCAL_MACHINE\Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command | (default) : C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1442344087&z=a1546d32dbf249427fafa3dgazdzdodc2z9m1weo3w&from=cor&uid=ST500LT012-1DG142_S3PNX24HXXXXS3PNX24H -> Trouvé(e) [HJ.Browser] (X86) HKEY_LOCAL_MACHINE\Software\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command | (default) : C:\Program Files (x86)\Internet Explorer\iexplore.exe http://www.istartsurf.com/?type=sc&ts=1442344087&z=a1546d32dbf249427fafa3dgazdzdodc2z9m1weo3w&from=cor&uid=ST500LT012-1DG142_S3PNX24HXXXXS3PNX24H -> Trouvé(e) ¤¤¤ Tâches : 0 ¤¤¤ ¤¤¤ Fichiers : 18 ¤¤¤ [PUP.Gen0|PUP.Gen1][Répertoire] C:\ProgramData\CloudPrinter -> Trouvé(e) [PUP.Gen1][Répertoire] C:\ProgramData\Logic Handler -> Trouvé(e) [Hj.Shortcut][Fichier] C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk [LNK@] C:\PROGRA~1\INTERN~1\iexplore.exe http://kipuu.cn/ -> Trouvé(e) [Hj.Shortcut][Fichier] C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [LNK@] C:\PROGRA~2\INTERN~1\iexplore.exe http://kipuu.cn/ -> Trouvé(e) [PUP.Gen1][Répertoire] C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tencent -> Trouvé(e) [Hj.Shortcut][Fichier] C:\Users\USER\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk [LNK@] C:\PROGRA~2\INTERN~1\iexplore.exe http://kipuu.cn/ -> Trouvé(e) [Hj.Shortcut][Fichier] C:\Users\USER\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\StartMenu\Opera.lnk [LNK@] C:\PROGRA~2\MOZILL~1\firefox.exe http://kipuu.cn/ -> Trouvé(e) [Hj.Shortcut][Fichier] C:\Users\USER\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Internet Explorer.lnk [LNK@] C:\PROGRA~2\INTERN~1\iexplore.exe http://kipuu.cn/ -> Trouvé(e) [Hj.Shortcut][Fichier] C:\Users\USER\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Mozilla Firefox.lnk [LNK@] C:\PROGRA~2\MOZILL~1\firefox.exe http://kipuu.cn/ -> Trouvé(e) [PUP.Gen1][Répertoire] C:\Users\USER\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk -> Trouvé(e) [PUP.Gen0|PUP.Gen1][Répertoire] C:\ProgramData\CloudPrinter -> Trouvé(e) [PUP.Gen1][Répertoire] C:\ProgramData\Logic Handler -> Trouvé(e) [Hj.Shortcut][Fichier] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk [LNK@] C:\PROGRA~2\MOZILL~1\firefox.exe http://kipuu.cn/ -> Trouvé(e) [Hj.Shortcut][Fichier] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera.lnk [LNK@] C:\PROGRA~2\MOZILL~1\firefox.exe http://kipuu.cn/ -> Trouvé(e) [PUP.Gen3][Fichier] C:\Users\USER\AppData\Roaming\Mozilla\Firefox\Profiles\ngfh75x1.default\searchplugins\findit.xml -> Trouvé(e) [Hj.Shortcut][Fichier] C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk [LNK@] C:\PROGRA~1\INTERN~1\iexplore.exe http://kipuu.cn/ -> Trouvé(e) [Hj.Shortcut][Fichier] C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk [LNK@] C:\PROGRA~2\INTERN~1\iexplore.exe http://kipuu.cn/ -> Trouvé(e) [PUP.Gen1][Répertoire] C:\Users\USER\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tencent -> Trouvé(e) ¤¤¤ WMI : 1 ¤¤¤ [PUP.Yeahbests] instance (ActiveScriptEventConsumer) \ROOT\subscription:ActiveScriptEventConsumer.Name="ASEC" -> Trouvé(e) ¤¤¤ Fichier Hosts : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤ ¤¤¤ Navigateurs web : 5 ¤¤¤ [PUP.Gen1][Firefox:Addon] ngfh75x1.default : Fast search [amcontextmenu@loucypher] -> Trouvé(e) [PUP.Gen2][Firefox:Addon] ngfh75x1.default : Quick Searcher [{d720d64d-c71a-4316-b59e-8a41b860178f}] -> Trouvé(e) [PUM.HomePage][Firefox:Config] ngfh75x1.default : user_pref("browser.startup.homepage", "C:\ProgramData\Hotfreshs\ff.HP"); -> Trouvé(e) [PUM.NewTab][Firefox:Config] ngfh75x1.default : user_pref("browser.newtab.url", "C:\ProgramData\Hotfreshs\ff.NT"); -> Trouvé(e) [PUM.HomePage][Chrome:Config] Default [SecurePrefs] : homepage [http://%66%65%65%64.%68%65%6C%70%65%72%62%61%72.%63%6F%6D/?p=mKO_AwFzXIpYRaHdGKBRGNclVS1AC6sNoH2TlPbfGRogFok1dGdSxtSSRDeTxYkRgQEsutSwCJhN_UyMGRQBJC5aolADhufcigHczPOZDjZ9hUMj3I7reim-qzyhUO1X4FcRixPeQqQpMPIbTxGGpnOz-sMcyrkUjm0FdyJ9m68CpVhkhxz1r3ozxOcJav14CSw1inU,] -> Trouvé(e) ¤¤¤ Vérification MBR : ¤¤¤ +++++ PhysicalDrive0: ST500LT012-1DG142 ATA Device +++++ --- User --- [MBR] 795e624d8820206b5b6ab70f822fdf03 [BSP] 6e48324af22097d79c687ca62076af52 : Windows Vista/7/8|VT.Unknown MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 99900 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 204802048 | Size: 188469 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 590786560 | Size: 188469 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] User = LL1 ... OK User = LL2 ... OK