voici le rapport :
RogueKiller V11.0.2.0 [Dec 7 2015] (Gratuit) par Adlice Software
email :
http://www.adlice.com/contact/
Remontées :
http://forum.adlice.com
Site web :
http://www.adlice.com/fr/logiciels/roguekiller/
Blog :
http://www.adlice.com
Système d'exploitation : Windows Vista (6.0.6001 Service Pack 1) 32 bits version
Démarré en : Mode normal
Utilisateur : karine [Administrateur]
Démarré depuis : C:\Users\karine\Desktop\RogueKiller.exe
Mode : Suppression -- Date : 12/14/2015 15:52:26
¤¤¤ Processus : 0 ¤¤¤
¤¤¤ Registre : 12 ¤¤¤
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\GPU-Z (\??\C:\Users\ADMINI~1\AppData\Local\Temp\GPU-Z.sys) -> Supprimé(e)
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet001\Services\GPU-Z (\??\C:\Users\ADMINI~1\AppData\Local\Temp\GPU-Z.sys) -> Supprimé(e)
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet002\Services\GPU-Z (\??\C:\Users\ADMINI~1\AppData\Local\Temp\GPU-Z.sys) -> Supprimé(e)
[Suspicious.Path] HKEY_LOCAL_MACHINE\System\ControlSet003\Services\GPU-Z (\??\C:\Users\ADMINI~1\AppData\Local\Temp\GPU-Z.sys) -> Supprimé(e)
[PUM.SearchPage] HKEY_USERS\S-1-5-21-3992758465-2154526597-71526748-1001\Software\Microsoft\Internet Explorer\Main | Search Page :
http://home.microsoft.com/access/allinone.asp -> Remplacé(e) (
http://go.microsoft.com/fwlink/?LinkId=54896)
[PUM.Policies] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System | ConsentPromptBehaviorAdmin : 0 -> Remplacé(e) (2)
[PUM.StartMenu] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowSetProgramAccessAndDefaults : 0 -> Remplacé(e) (1)
[PUM.StartMenu] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowHelp : 0 -> Remplacé(e) (1)
[PUM.StartMenu] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowUser : 0 -> Remplacé(e) (1)
[PUM.StartMenu] HKEY_USERS\S-1-5-21-3992758465-2154526597-71526748-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowSetProgramAccessAndDefaults : 0 -> Remplacé(e) (1)
[PUM.StartMenu] HKEY_USERS\S-1-5-21-3992758465-2154526597-71526748-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowHelp : 0 -> Remplacé(e) (1)
[PUM.StartMenu] HKEY_USERS\S-1-5-21-3992758465-2154526597-71526748-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced | Start_ShowUser : 0 -> Remplacé(e) (1)
¤¤¤ Tâches : 0 ¤¤¤
¤¤¤ Fichiers : 2 ¤¤¤
[PUP][Répertoire] C:\ProgramData\{2A12974D-FC01-481F-AB15-B2ADE099AAFC} -> Supprimé(e)
[PUP][Fichier] C:\ProgramData\{2A12974D-FC01-481F-AB15-B2ADE099AAFC}\EBP_Microsoft_MSI45\mFileBagIDE.dll\bag\Windows6.0-KB942288-v2-x86.msu -> Supprimé(e)
[PUP][Fichier] C:\ProgramData\{2A12974D-FC01-481F-AB15-B2ADE099AAFC}\EBP_Microsoft_MSI45\mFileBagIDE.dll\bag\WindowsServer2003-KB942288-v4-x86.exe -> Supprimé(e)
[PUP][Fichier] C:\ProgramData\{2A12974D-FC01-481F-AB15-B2ADE099AAFC}\EBP_Microsoft_MSI45\mFileBagIDE.dll\bag\WindowsXP-KB942288-v3-x86.exe -> Supprimé(e)
[PUP][Répertoire] C:\ProgramData\{2A12974D-FC01-481F-AB15-B2ADE099AAFC}\EBP_Microsoft_MSI45\mFileBagIDE.dll\bag -> Supprimé(e)
[PUP][Fichier] C:\ProgramData\{2A12974D-FC01-481F-AB15-B2ADE099AAFC}\EBP_Microsoft_MSI45\mFileBagIDE.dll\mFileBagEXE.dll -> Supprimé(e)
[PUP][Répertoire] C:\ProgramData\{2A12974D-FC01-481F-AB15-B2ADE099AAFC}\EBP_Microsoft_MSI45\mFileBagIDE.dll -> Supprimé(e)
[PUP][Fichier] C:\ProgramData\{2A12974D-FC01-481F-AB15-B2ADE099AAFC}\EBP_Microsoft_MSI45\{2A12974D-FC01-481F-AB15-B2ADE099AAFC} -> Supprimé(e)
[PUP][Répertoire] C:\ProgramData\{2A12974D-FC01-481F-AB15-B2ADE099AAFC}\EBP_Microsoft_MSI45 -> Supprimé(e)
[Hj.Name][Fichier] C:\Program Files\Spybot - Search & Destroy 2\explorer.exe -> Supprimé(e)
¤¤¤ Fichier Hosts : 0 [Too big!] ¤¤¤
¤¤¤ Antirootkit : 0 (Driver: Chargé) ¤¤¤
¤¤¤ Navigateurs web : 1 ¤¤¤
[PUM.HomePage][FIREFX:Config] 2gq4dt8o.default : user_pref("browser.startup.homepage", "
http://www-2.net-c.com/netc/mail/mailbo ... references"); -> Non sélectionné
¤¤¤ Vérification MBR : ¤¤¤
+++++ PhysicalDrive0: +++++
--- User ---
[MBR] 4b29b209e5de8c0e199dc7a77b3ad033
[BSP] 672a81be294f74a809639896ecafd519 : HP|VT.Unknown MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 76317 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK
+++++ PhysicalDrive2: Sony Storage Media USB Device +++++
--- User ---
[MBR] ecb3a74f59d61636d347014d690e2ea0
[BSP] a83a24340e59ea8cbbf2d8eaa19e98b0 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 63 | Size: 15423 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] Cette demande n'est pas prise en charge. )