RogueKiller V12.12.13.0 (x64) [Apr 16 2018] (Gratuit) par Adlice Software email : http://www.adlice.com/fr/contact/ Remontées : https://forum.adlice.com Site web : http://www.adlice.com/fr/download/roguekiller/ Blog : http://www.adlice.com/fr/ Système d'exploitation : Windows 10 (10.0.16299) 64 bits version Démarré en : Mode normal Utilisateur : Isabelle [Administrateur] Démarré depuis : C:\Program Files\RogueKiller\RogueKiller64.exe Mode : Scan -- Date : 04/20/2018 15:12:32 (Durée : 00:35:47) ¤¤¤ Processus : 0 ¤¤¤ ¤¤¤ Registre : 37 ¤¤¤ [PUP.Gen0] (X64) HKEY_CLASSES_ROOT\CLSID\{9C4EFBD5-1ADF-41E6-BE26-AF44326E30E4} -> Trouvé(e) [PUP.Gen1] (X64) HKEY_CLASSES_ROOT\CLSID\{A5668BCF-5E1B-7D77-6B80-0CA3D55D69DA} (C:\Program Files (x86)\CostMin\m4Yoyf.x64.dll) -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\AVG Secure Search -> Trouvé(e) [PUP.BabSolution|PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\BabSolution -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\Babylon -> Trouvé(e) [PUP.Conduit|PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\Conduit -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\Condut -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\Cr_Installer -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\ExpressFiles -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\IM -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\InstalledBrowserExtensions -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\Softonic -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\AVG Secure Search -> Trouvé(e) [PUP.BabSolution|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\BabSolution -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\Babylon -> Trouvé(e) [PUP.Conduit|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\Conduit -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\Condut -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\Cr_Installer -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\ExpressFiles -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\IM -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\InstalledBrowserExtensions -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\Softonic -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} -> Trouvé(e) [PUP.Conduit|PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\AppDataLow\Software\Conduit -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\AppDataLow\Software\ConduitSearchScopes -> Trouvé(e) [PUP.Conduit|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\AppDataLow\Software\Conduit -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\AppDataLow\Software\ConduitSearchScopes -> Trouvé(e) [PUP.Gen0] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{34A0D84B-CDDC-4EC4-AFDD-4F1DDE1D14E5} -> Trouvé(e) [PUP.Gen0] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> Trouvé(e) [PUP.Gen0] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} -> Trouvé(e) [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://fr.canoe.ca/ -> Trouvé(e) [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-812936403-3686162907-2633483560-1000\Software\Microsoft\Internet Explorer\Main | Start Page : http://fr.canoe.ca/ -> Trouvé(e) [PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {57FACD29-C60F-477B-A664-667F112AF32B} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\ExpressFiles\expressdl.exe|Name=Express Files| [x] -> Trouvé(e) [PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {6C1AA2B8-2930-475E-AB54-474E072D35A2} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\ExpressFiles\expressdl.exe|Name=Express Files| [x] -> Trouvé(e) [PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {C0BF9DD0-57F0-485D-827F-D35A9B15EA99} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|App=C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe|Name=Express Files| [x] -> Trouvé(e) [PUP.Gen1] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | {5C342834-D9E7-4BBC-8DA9-7E45435070D4} : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|App=C:\Program Files (x86)\ExpressFiles\ExpressFiles.exe|Name=Express Files| [x] -> Trouvé(e) ¤¤¤ Tâches : 3 ¤¤¤ [Suspicious.Path] %WINDIR%\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job -- C:\Windows\TEMP\{98F8B891-4B02-4FE7-A9EC-9AA03DE7E23A}.exe (--uninstall=1) -> Trouvé(e) [Suspicious.Path] \4803 -- wscript.exe (C:\Users\CLIENT~1\AppData\Local\Temp\launchie.vbs //B) -> Trouvé(e) [Suspicious.Path] \AVG-Secure-Search-Update_JUNE2013_TB_rmv -- C:\Windows\TEMP\{98F8B891-4B02-4FE7-A9EC-9AA03DE7E23A}.exe (--uninstall=1) -> Trouvé(e) ¤¤¤ Fichiers : 0 ¤¤¤ ¤¤¤ WMI : 0 ¤¤¤ ¤¤¤ Fichier Hosts : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤ ¤¤¤ Navigateurs web : 2 ¤¤¤ [PUM.HomePage][Chrome:Config] Default [SecurePrefs] : session.startup_urls [http://www.tvanouvelles.ca/actualites] -> Trouvé(e) [PUM.SearchPage][Chrome:Config] Default [SecurePrefs] : default_search_provider_data.template_url_data.keyword [yahoo.com search] -> Trouvé(e) ¤¤¤ Vérification MBR : ¤¤¤ +++++ PhysicalDrive0: ST500DM002-1BD142 +++++ --- User --- [MBR] 7d841d6213a1295dda177db3165d3e58 [BSP] b82eee0b7ae8921d0367b1b62a1e9ac9 : Windows Vista/7/8|VT.Unknown MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 460020 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 942327808 | Size: 450 MB 3 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 943249408 | Size: 16368 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] User = LL1 ... OK User = LL2 ... OK