RogueKiller V12.10.4.0 (x64) [Apr 10 2017] (Gratuit) par Adlice Software email : http://www.adlice.com/contact/ Remontées : https://forum.adlice.com Site web : http://www.adlice.com/fr/download/roguekiller/ Blog : http://www.adlice.com Système d'exploitation : Windows 10 (10.0.15063) 64 bits version Démarré en : Mode normal Utilisateur : jipel [Administrateur] Démarré depuis : D:\Program Files\RogueKiller\RogueKiller64.exe Mode : Suppression -- Date : 04/15/2017 13:51:29 (Durée : 00:16:21) ¤¤¤ Processus : 1 ¤¤¤ [Adw.Elex|Tr.Zusy|PUP.Divcom] MBAMService.exe(3480) -- D:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe[7] -> Tué(e) [DrvNtTerm] ¤¤¤ Registre : 64 ¤¤¤ [PUP.Gen1] (X64) HKEY_USERS\RK_Invité_ON_G_DD79\Software\PowerPack -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_Invité_ON_G_DD79\Software\PowerPack -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\csdimedia -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\DailyPcClean -> Supprimé(e) [PUP.DownloadAssistant] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\DVDVideoSoft -> Supprimé(e) [PUP.ModGoog|PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\globalUpdate -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\ProductSetup -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\ProgSense -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Rocket Browser -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\TeleCharger -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\tstamptoken -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\csdimedia -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\DailyPcClean -> Supprimé(e) [PUP.DownloadAssistant] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\DVDVideoSoft -> Supprimé(e) [PUP.ModGoog|PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\globalUpdate -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\ProductSetup -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\ProgSense -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Rocket Browser -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\TeleCharger -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\tstamptoken -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_Invité_ON_G_DD79\Software\AppDataLow\Toolbar -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_Invité_ON_G_DD79\Software\AppDataLow\Toolbar -> Supprimé(e) [PUP.Conduit|PUP.Gen1] (X64) HKEY_USERS\RK_Invité_ON_G_DD79\Software\AppDataLow\Software\Conduit -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_Invité_ON_G_DD79\Software\AppDataLow\Software\Dealio -> Supprimé(e) [PUP.Conduit|PUP.Gen1] (X86) HKEY_USERS\RK_Invité_ON_G_DD79\Software\AppDataLow\Software\Conduit -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_Invité_ON_G_DD79\Software\AppDataLow\Software\Dealio -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AnyProtect -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BoBrowser -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Crossbrowse -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Free FLV Converter_is1 -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Max Driver Updater_is1 -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\NUIns -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Selection Tools -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\sizlsearch -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A0B0DA25-DD15-4739-92A3-62D3424F043A}_is1 -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D} -> Supprimé(e) [PUP.Gen1] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0} -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\AnyProtect -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\BoBrowser -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Crossbrowse -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Free FLV Converter_is1 -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Max Driver Updater_is1 -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\NUIns -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\Selection Tools -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\sizlsearch -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{A0B0DA25-DD15-4739-92A3-62D3424F043A}_is1 -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{C3E85EE9-5892-4142-B537-BCEB3DAC4C3D} -> Supprimé(e) [PUP.Gen1] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\{EA8FA6BE-29BE-4AF2-9352-841F83215EB0} -> Supprimé(e) [PUM.HomePage] (X64) HKEY_USERS\RK_Default_ON_G_A00C\Software\Microsoft\Internet Explorer\Main | Start Page : http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=92&bd=Pavilion&pf=cndt -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141) [PUM.HomePage] (X86) HKEY_USERS\RK_Default_ON_G_A00C\Software\Microsoft\Internet Explorer\Main | Start Page : http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=92&bd=Pavilion&pf=cndt -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141) [PUM.HomePage] (X64) HKEY_USERS\RK_Invité_ON_G_DD79\Software\Microsoft\Internet Explorer\Main | Start Page : http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=92&bd=Pavilion&pf=cndt -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141) [PUM.HomePage] (X86) HKEY_USERS\RK_Invité_ON_G_DD79\Software\Microsoft\Internet Explorer\Main | Start Page : http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=92&bd=Pavilion&pf=cndt -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141) [PUM.HomePage] (X64) HKEY_USERS\RK_UpdatusUser_ON_G_C315\Software\Microsoft\Internet Explorer\Main | Start Page : http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=92&bd=Pavilion&pf=cndt -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141) [PUM.HomePage] (X86) HKEY_USERS\RK_UpdatusUser_ON_G_C315\Software\Microsoft\Internet Explorer\Main | Start Page : http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=92&bd=Pavilion&pf=cndt -> Remplacé(e) (http://go.microsoft.com/fwlink/p/?LinkId=255141) [PUM.HomePage] (X64) HKEY_USERS\RK_Default_ON_G_A00C\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=92&bd=Pavilion&pf=cndt -> Remplacé(e) (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome) [PUM.HomePage] (X86) HKEY_USERS\RK_Default_ON_G_A00C\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=92&bd=Pavilion&pf=cndt -> Remplacé(e) (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome) [PUM.HomePage] (X64) HKEY_USERS\RK_Invité_ON_G_DD79\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=92&bd=Pavilion&pf=cndt -> Remplacé(e) (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome) [PUM.HomePage] (X86) HKEY_USERS\RK_Invité_ON_G_DD79\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=92&bd=Pavilion&pf=cndt -> Remplacé(e) (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome) [PUM.HomePage] (X64) HKEY_USERS\RK_UpdatusUser_ON_G_C315\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=92&bd=Pavilion&pf=cndt -> Remplacé(e) (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome) [PUM.HomePage] (X86) HKEY_USERS\RK_UpdatusUser_ON_G_C315\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=fr_fr&c=92&bd=Pavilion&pf=cndt -> Remplacé(e) (http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome) [PUM.SearchPage] (X64) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Internet Explorer\Main | Search bar : Preserve -> Remplacé(e) (http://search.msn.com/spbasic.htm) [PUM.SearchPage] (X86) HKEY_USERS\RK_jipe_ON_G_B0B5\Software\Microsoft\Internet Explorer\Main | Search bar : Preserve -> Remplacé(e) (http://search.msn.com/spbasic.htm) [PUM.Policies] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Remplacé(e) (2) [PUM.Policies] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Remplacé(e) (2) ¤¤¤ Tâches : 0 ¤¤¤ ¤¤¤ Fichiers : 3 ¤¤¤ [Tr.Gen0][Fichier] C:\Users\jipel\AppData\Roaming\uTorrent\updates\3.4.9_43085\utorrentie.exe -> Supprimé(e) [Tr.Gen0][Fichier] C:\Users\jipel\AppData\Roaming\uTorrent\updates\3.5.0_43580\utorrentie.exe -> Supprimé(e) [Adw.WinSec|PUP.Gen1][Répertoire] C:\Program Files\Windows Security -> Supprimé(e) au redémarrage [91] [Adw.WinSec|PUP.Gen1][Fichier] C:\Program Files\Windows Security\BrowserCore\BrowserCore.exe -> ERROR [5] [Adw.WinSec|PUP.Gen1][Fichier] C:\Program Files\Windows Security\BrowserCore\en-US\BrowserCore.exe.mui -> ERROR [5] [Adw.WinSec|PUP.Gen1][Répertoire] C:\Program Files\Windows Security\BrowserCore\en-US -> Supprimé(e) au redémarrage [91] [Adw.WinSec|PUP.Gen1][Fichier] C:\Program Files\Windows Security\BrowserCore\manifest.json -> ERROR [5] [Adw.WinSec|PUP.Gen1][Répertoire] C:\Program Files\Windows Security\BrowserCore -> Supprimé(e) au redémarrage [91] ¤¤¤ WMI : 0 ¤¤¤ ¤¤¤ Fichier Hosts : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤ ¤¤¤ Navigateurs web : 0 ¤¤¤ ¤¤¤ Vérification MBR : ¤¤¤ +++++ PhysicalDrive0: ST1000DM010-2EP102 +++++ --- User --- [MBR] e7853a48352b6c6ff706e92bab4f8e1b [BSP] b0d43f1e8a89cd4fa788886055628430 : Windows Vista/7/8|VT.Unknown MBR Code Partition table: 0 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 953867 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] User = LL1 ... OK User = LL2 ... OK +++++ PhysicalDrive1: KINGSTON SHFS37A240G +++++ --- User --- [MBR] 4609420d68f166eb01125dcc25cccfeb [BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code Partition table: 0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 450 MB 1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 923648 | Size: 100 MB 2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 1128448 | Size: 16 MB 3 - Basic data partition | Offset (sectors): 1161216 | Size: 227918 MB 4 - [SYSTEM][MAN-MOUNT] | Offset (sectors): 467937280 | Size: 450 MB User = LL1 ... OK User = LL2 ... OK +++++ PhysicalDrive2: WDC WD10 EADS-65L5B1 SCSI Disk Device +++++ --- User --- [MBR] 60aed360b3cbcfa258401aa338e77712 [BSP] 309fdfd200901d3359dd1e035123a213 : HP MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 63 | Size: 940053 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1925229600 | Size: 13813 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] User = LL1 ... OK Error reading LL2 MBR! ([1] Fonction incorrecte. )