RogueKiller V12.11.12.0 (x64) [Aug 28 2017] (Gratuit) par Adlice Software email : http://www.adlice.com/fr/contact/ Remontées : https://forum.adlice.com Site web : http://www.adlice.com/fr/download/roguekiller/ Blog : http://www.adlice.com/fr/ Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Démarré en : Mode normal Utilisateur : Utilisateur [Administrateur] Démarré depuis : C:\Users\Utilisateur\Downloads\RogueKiller_portable64.exe Mode : Scan -- Date : 08/30/2017 22:35:42 (Durée : 00:38:48) ¤¤¤ Processus : 0 ¤¤¤ ¤¤¤ Registre : 27 ¤¤¤ [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Babylon -> Trouvé(e) [PUP.Conduit|PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Conduit -> Trouvé(e) [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\PIP -> Trouvé(e) [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Uniblue -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\APN PIP -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\Bitberry -> Trouvé(e) [PUP.Conduit|PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\Conduit -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\GoldenGate -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\nuevos-programas.com -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\TeleCharger -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\APN PIP -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\Bitberry -> Trouvé(e) [PUP.Conduit|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\Conduit -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\GoldenGate -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\nuevos-programas.com -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\TeleCharger -> Trouvé(e) [PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2F603A45-D956-496B-81B5-50D782424976} -> Trouvé(e) [PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B85C4CB2-B352-4BD8-818C-BCE353599107} -> Trouvé(e) [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{2F603A45-D956-496B-81B5-50D782424976} -> Trouvé(e) [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{7683B745-6060-41FD-AA75-0BBB383FEAD4} -> Trouvé(e) [PUP.Gen1] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\{B85C4CB2-B352-4BD8-818C-BCE353599107} -> Trouvé(e) [PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Trouvé(e) [PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-1635545215-229434308-1925133469-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyEnable : 1 -> Trouvé(e) [PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | TCP Query User{A047E73A-AA04-4AE9-9703-21026DE58471}C:\program files (x86)\1clickdownload\1clickdownloader.exe : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\1clickdownload\1clickdownloader.exe|Name=DownloadAssistant|Desc=DownloadAssistant|Edge=TRUE|Defer=App| [x] -> Trouvé(e) [PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | UDP Query User{C0C7523D-97B3-4DAD-B75A-AC8865D23CE5}C:\program files (x86)\1clickdownload\1clickdownloader.exe : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\1clickdownload\1clickdownloader.exe|Name=DownloadAssistant|Desc=DownloadAssistant|Edge=TRUE|Defer=App| [x] -> Trouvé(e) [PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | TCP Query User{A047E73A-AA04-4AE9-9703-21026DE58471}C:\program files (x86)\1clickdownload\1clickdownloader.exe : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Public|App=C:\program files (x86)\1clickdownload\1clickdownloader.exe|Name=DownloadAssistant|Desc=DownloadAssistant|Edge=TRUE|Defer=App| [x] -> Trouvé(e) [PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | UDP Query User{C0C7523D-97B3-4DAD-B75A-AC8865D23CE5}C:\program files (x86)\1clickdownload\1clickdownloader.exe : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|App=C:\program files (x86)\1clickdownload\1clickdownloader.exe|Name=DownloadAssistant|Desc=DownloadAssistant|Edge=TRUE|Defer=App| [x] -> Trouvé(e) ¤¤¤ Tâches : 2 ¤¤¤ [PUP.Gen0|PUP.Gen1] %WINDIR%\Tasks\RegistryBooster.job -- C:\Program Files (x86)\Uniblue\RegistryBooster\rbmonitor.exe -> Trouvé(e) [PUP.Gen1] \RegistryBooster -- C:\Program Files (x86)\Uniblue\RegistryBooster\rbmonitor.exe -> Trouvé(e) ¤¤¤ Fichiers : 7 ¤¤¤ [PUP.Gen1][Répertoire] C:\ProgramData\Babylon -> Trouvé(e) [PUP.Gen1][Répertoire] C:\Users\Utilisateur\AppData\Roaming\Babylon -> Trouvé(e) [PUP.Gen1][Répertoire] C:\Users\Utilisateur\AppData\Roaming\Gameo -> Trouvé(e) [PUP.Gen1][Répertoire] C:\Users\Utilisateur\AppData\Roaming\PerformerSoft -> Trouvé(e) [PUP.Gen1][Répertoire] C:\Users\Utilisateur\AppData\Roaming\Uniblue -> Trouvé(e) [PUP.Gen1][Répertoire] C:\Users\Utilisateur\AppData\Local\PackageAware -> Trouvé(e) [PUP.Gen1][Répertoire] C:\ProgramData\Babylon -> Trouvé(e) ¤¤¤ WMI : 0 ¤¤¤ ¤¤¤ Fichier Hosts : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤ ¤¤¤ Navigateurs web : 5 ¤¤¤ [PUP.Gen2][Firefox:Addon] yhuv7s84.default : OneClickDownloader [OneClickDownload@OneClickDownload.com] -> Trouvé(e) [PUP.Gen1|PUM.HomePage][Firefox:Config] yhuv7s84.default : user_pref("browser.startup.homepage", "http://search.softonic.com/MOY00005/tb_v1?SearchSource=13&cc="); -> Trouvé(e) [PUM.SearchEngine][Firefox:Config] yhuv7s84.default : user_pref("browser.search.selectedEngine", "Search the web (Softonic)"); -> Trouvé(e) [PUM.SearchEngine][Firefox:Config] yhuv7s84.default : user_pref("browser.search.defaultenginename", "Search the web (Softonic)"); -> Trouvé(e) [PUM.HomePage][Chrome:Config] Default [SecurePrefs] : homepage [http://www.holasearch.com/?affID=121962&tt=gc_&babsrc=HP_ss&mntrId=88D80626B6E030D1] -> Trouvé(e) ¤¤¤ Vérification MBR : ¤¤¤ \\.\PHYSICALDRIVE0 Root.Sinowal -> Trouvé(e) +++++ PhysicalDrive0: Hitachi HTS545032B9A300 +++++ --- User --- [MBR] 4d14f3d539d115021a6131e154ac1fcc [BSP] 98a6181076d64be02a5e40e8e016ae96 : Root.Sinowal|VT.Unknown MBR Code [Malware!] Partition table: 0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 400 MB 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 821248 | Size: 152386 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 312907776 | Size: 152457 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] User = LL1 ... OK User = LL2 ... OK +++++ PhysicalDrive1: Generic- Multi-Card USB Device +++++ Error reading User MBR! ([15] Le périphérique n?est pas prêt. ) Error reading LL1 MBR! NOT VALID! Error reading LL2 MBR! ([32] Cette demande n?est pas prise en charge. )