RogueKiller V8.5.1 [Feb 20 2013] par Tigzy mail : tigzyRKgmailcom Remontees : http://www.sur-la-toile.com/discussion-193725-1--RogueKiller-Remontees.html Site Web : http://www.sur-la-toile.com/RogueKiller/ Blog : http://tigzyrk.blogspot.com/ Systeme d'exploitation : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Demarrage : Mode normal Utilisateur : Ak-Style [Droits d'admin] Mode : Suppression -- Date : 20/02/2013 22:24:31 | ARK || FAK || MBR | ¤¤¤ Processus malicieux : 1 ¤¤¤ [SVCHOST] svchost.exe -- C:\Windows\SysWOW64\svchost.exe [x] -> TUÉ [TermProc] ¤¤¤ Entrees de registre : 8 ¤¤¤ [RUN][SUSP PATH] HKCU\[...]\RunOnce : JavaInstallRetry ("C:\Users\Ak-Style\AppData\LocalLow\Sun\Java\JRERunOnce.exe" RUNONCE=1 SPONSORS=0) [7] -> SUPPRIMÉ [SHELL][SUSP PATH] HKCU\[...]\Windows : Load (C:\Users\Ak-Style\Local Settings\Temp\msltvwei.com) [-] -> SUPPRIMÉ [HJ SMENU] HKCU\[...]\Advanced : Start_ShowRecentDocs (0) -> REMPLACÉ (1) [HJ SMENU] HKCU\[...]\Advanced : Start_ShowMyGames (0) -> REMPLACÉ (1) [HJ SMENU] HKCU\[...]\Advanced : Start_TrackProgs (0) -> REMPLACÉ (1) [HJ DESK] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REMPLACÉ (0) [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REMPLACÉ (0) [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\$Recycle.Bin\S-1-5-18\$93ea70ef3139e8d013589de2480f5963\n) [-] -> REMPLACÉ (C:\Windows\system32\wbem\fastprox.dll) ¤¤¤ Fichiers / Dossiers particuliers: ¤¤¤ [ZeroAccess][FILE] n : C:\$recycle.bin\S-1-5-18\$93ea70ef3139e8d013589de2480f5963\n [-] --> SUPPRIMÉ AU REBOOT [ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-18\$93ea70ef3139e8d013589de2480f5963\@ [-] --> SUPPRIMÉ AU REBOOT [ZeroAccess][FILE] @ : C:\$recycle.bin\S-1-5-21-1996736051-1076600257-2727114610-1001\$93ea70ef3139e8d013589de2480f5963\@ [-] --> SUPPRIMÉ [Del.Parent][FILE] 00000004.@ : C:\$recycle.bin\S-1-5-18\$93ea70ef3139e8d013589de2480f5963\U\00000004.@ [-] --> SUPPRIMÉ [Del.Parent][FILE] 00000008.@ : C:\$recycle.bin\S-1-5-18\$93ea70ef3139e8d013589de2480f5963\U\00000008.@ [-] --> SUPPRIMÉ [Del.Parent][FILE] 80000000.@ : C:\$recycle.bin\S-1-5-18\$93ea70ef3139e8d013589de2480f5963\U\80000000.@ [-] --> SUPPRIMÉ [ZeroAccess][FOLDER] ROOT : C:\$recycle.bin\S-1-5-18\$93ea70ef3139e8d013589de2480f5963\U --> SUPPRIMÉ [ZeroAccess][FOLDER] ROOT : C:\$recycle.bin\S-1-5-21-1996736051-1076600257-2727114610-1001\$93ea70ef3139e8d013589de2480f5963\U --> SUPPRIMÉ [Del.Parent][FILE] 00000004.@ : C:\$recycle.bin\S-1-5-18\$93ea70ef3139e8d013589de2480f5963\L\00000004.@ [-] --> SUPPRIMÉ [Del.Parent][FILE] 76603ac3 : C:\$recycle.bin\S-1-5-18\$93ea70ef3139e8d013589de2480f5963\L\76603ac3 [-] --> SUPPRIMÉ [ZeroAccess][FOLDER] ROOT : C:\$recycle.bin\S-1-5-18\$93ea70ef3139e8d013589de2480f5963\L --> SUPPRIMÉ [ZeroAccess][FOLDER] ROOT : C:\$recycle.bin\S-1-5-21-1996736051-1076600257-2727114610-1001\$93ea70ef3139e8d013589de2480f5963\L --> SUPPRIMÉ [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_32\Desktop.ini [-] --> SUPPRIMÉ AU REBOOT [ZeroAccess][FILE] Desktop.ini : C:\Windows\Assembly\GAC_64\Desktop.ini [-] --> SUPPRIMÉ AU REBOOT ¤¤¤ Driver : [NON CHARGE] ¤¤¤ ¤¤¤ Infection : ZeroAccess ¤¤¤ ¤¤¤ Fichier HOSTS: ¤¤¤ --> C:\Windows\system32\drivers\etc\hosts ¤¤¤ MBR Verif: ¤¤¤ +++++ PhysicalDrive0: Hitachi HTS547550A9E384 SATA Disk Device +++++ --- User --- [MBR] d7a87bf23c257718018805fe56f64513 [BSP] 774f3aca7b07aeda5c6f7c5e3b907d34 : Windows 7/8 MBR Code Partition table: 0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 199 Mo 1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409600 | Size: 448697 Mo 2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 919341056 | Size: 23979 Mo 3 - [XXXXXX] FAT32-LBA (0x0c) [VISIBLE] Offset (sectors): 968450048 | Size: 4063 Mo User = LL1 ... OK! User = LL2 ... OK! +++++ PhysicalDrive1: EMTEC U3 Smart Drive USB Device +++++ --- User --- [MBR] 7a235bd1744709d07531907d7a76330f [BSP] 2f49ad36748f0dbaa4ef169767568c28 : MBR Code unknown Partition table: 0 - [ACTIVE] FAT32 (0x0b) [VISIBLE] Offset (sectors): 32 | Size: 3928 Mo User = LL1 ... OK! Error reading LL2 MBR! +++++ PhysicalDrive2: ST932032 5AS USB Device +++++ --- User --- [MBR] 1e4337b115f01c2df6af26596ef0b07f [BSP] 5b7ecfb5ee2d3e572a22a779f8f0d248 : Windows XP MBR Code Partition table: 0 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 305242 Mo User = LL1 ... OK! Error reading LL2 MBR! Termine : << RKreport[2]_D_20022013_222431.txt >> RKreport[1]_S_20022013_222229.txt ; RKreport[2]_D_20022013_222431.txt