ÿþRogueKiller V12.13.2.0 (x64) [Sep 24 2018] (Gratuit) par Adlice Software email : http://www.adlice.com/fr/contact/ Remontées : https://forum.adlice.com Site web : http://www.adlice.com/fr/download/roguekiller/ Blog : http://www.adlice.com/fr/ Système d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Démarré en : Mode normal Utilisateur : MARIE-PAULE [Administrateur] Démarré depuis : C:\Program Files\RogueKiller\RogueKiller64.exe Mode : Scan -- Date : 09/24/2018 13:54:32 (Durée : 00:47:46) ¤¤¤ Processus : 0 ¤¤¤ ¤¤¤ Registre : 22 ¤¤¤ [PUP.Gen1] (X64) HKEY_USERS\.DEFAULT\Software\IBUpdaterService -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\.DEFAULT\Software\IM -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\.DEFAULT\Software\ImInstaller -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\.DEFAULT\Software\IBUpdaterService -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\.DEFAULT\Software\IM -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\.DEFAULT\Software\ImInstaller -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-18\Software\IBUpdaterService -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-18\Software\IM -> Trouvé(e) [PUP.Gen1] (X64) HKEY_USERS\S-1-5-18\Software\ImInstaller -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-18\Software\IBUpdaterService -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-18\Software\IM -> Trouvé(e) [PUP.Gen1] (X86) HKEY_USERS\S-1-5-18\Software\ImInstaller -> Trouvé(e) [PUM.HomePage] (X64) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : http://www.bing.com/search?FORM=INCOH1&PC=IC05&PTAG=ICO-de33c4d4 -> Trouvé(e) [PUM.HomePage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Start Page : https://search.avast.com/AV772/ -> Trouvé(e) [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-241375441-1209096003-2064286218-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage_IE -> Trouvé(e) [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-241375441-1209096003-2064286218-1001\Software\Microsoft\Internet Explorer\Main | Start Page : http://r.orange.fr/r/Ohome_portail?ref=O_OI_defaultPage_IE -> Trouvé(e) [PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Page : https://search.avast.com/AV772/search/web?q={searchTerms} -> Trouvé(e) [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-241375441-1209096003-2064286218-1001\Software\Microsoft\Internet Explorer\Main | Search Page : https://search.avast.com/AV772/search/web?q={searchTerms} -> Trouvé(e) [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-241375441-1209096003-2064286218-1001\Software\Microsoft\Internet Explorer\Main | Search Page : https://search.avast.com/AV772/search/web?q={searchTerms} -> Trouvé(e) [PUM.SearchPage] (X86) HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main | Search Bar : https://search.avast.com/AV772/ -> Trouvé(e) [PUM.SearchPage] (X64) HKEY_USERS\S-1-5-21-241375441-1209096003-2064286218-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : https://search.avast.com/AV772/ -> Trouvé(e) [PUM.SearchPage] (X86) HKEY_USERS\S-1-5-21-241375441-1209096003-2064286218-1001\Software\Microsoft\Internet Explorer\Main | Search Bar : https://search.avast.com/AV772/ -> Trouvé(e) ¤¤¤ Tâches : 2 ¤¤¤ [Hj.Shortcut] \{611D0F69-502F-4D1B-9005-139792F5A42B} -- "c:\program files\internet explorer\iexplore.exe" (http://ui.skype.com/ui/0/6.11.0.102/fr/abandoninstall?source=lightinstaller&page=tsMain) -> Trouvé(e) [Suspicious.Path] \{82264C9D-AA31-4F09-8300-2E7C96B40E9B} -- C:\Users\MARIE-PAULE\AppData\Roaming\JsMediaProd\MoolineoMail\Moolineo.exe -> Trouvé(e) ¤¤¤ Fichiers : 1 ¤¤¤ [PUP.Gen3][Fichier] C:\Users\MARIE-PAULE\AppData\Roaming\Mozilla\Firefox\Profiles\dtituphj.default\searchplugins\search provided by bing.xml -> Trouvé(e) ¤¤¤ WMI : 0 ¤¤¤ ¤¤¤ Fichier Hosts : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤ ¤¤¤ Navigateurs web : 3 ¤¤¤ [PUM.HomePage][Firefox:Config] dtituphj.default : user_pref("browser.startup.homepage", "http://www.bing.com/search?FORM=INCOH1&PC=IC04&PTAG=ICO-de33c4d4"); -> Trouvé(e) [PUM.SearchEngine][Firefox:Config] dtituphj.default : user_pref("browser.search.selectedEngine", "Search Provided by Bing"); -> Trouvé(e) [PUM.SearchEngine][Firefox:Config] dtituphj.default : user_pref("browser.search.defaultenginename", "Search Provided by Bing"); -> Trouvé(e) ¤¤¤ Vérification MBR : ¤¤¤ +++++ PhysicalDrive0: ST9500325AS +++++ --- User --- [MBR] 139ea4574c443057c89692d2d463e55a [BSP] b8e681ec20f3f51e484d81d4ade624cc : Windows Vista/7/8 MBR Code Partition table: 0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 63 | Size: 22003 MB 1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 45062325 | Size: 119233 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 2 - [XXXXXX] EXTEN-LBA (0xf) [VISIBLE] Offset (sectors): 289253376 | Size: 335702 MB User = LL1 ... OK User = LL2 ... OK