Allez, je poste et je reviens dans 1h, encore merci !!
Rapport pour le 2 :
RogueKiller V6.1.2 [07/10/2011] par Tigzy
contact sur
http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Remontees:
http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Demarrage : Mode normal
Utilisateur: marie [Droits d'admin]
Mode: Suppression -- Date : 13/10/2011 15:00:27
Processus malicieux: 2
[ROGUE ST] 639.exe -- c:\program files\internet explorer\4382\639.exe -> KILLED [TermProc]
[SUSP PATH] 65F43.exe -- c:\users\marie\appdata\roaming\20554\65f43.exe -> KILLED [TermProc]
Entrees de registre: 10
[SUSP PATH] HKCU\[...]\Run : vasja (C:\Users\marie\AppData\Local\Temp\wpbt0.dll) -> DELETED
[SUSP PATH] HKLM\[...]\Run : 639.exe (C:\Program Files\Internet Explorer\4382\639.exe) -> DELETED
[SUSP PATH] HKCU\[...]\Winlogon : Shell (explorer.exe,C:\Users\marie\AppData\Roaming\20554\65F43.exe) -> DELETED
[SUSP PATH] HKCU\[...]\Windows : Load (C:\Users\marie\AppData\Local\Temp\dwm.exe) -> DELETED
[PROXY IE] HKCU\[...]\Internet Settings : ProxyEnable (1) -> NOT REMOVED, USE PROXYFIX
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (http=127.0.0.1:59535) -> NOT REMOVED, USE PROXYFIX
[HJ] {20D04FE0-3AEA-1069-A2D8-08002B30309D}\ 1: -> REPLACED (0)
[HJ] HKLM\[...]\System : EnableLUA (0) -> REPLACED (1)
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)
Fichiers / Dossiers particuliers:
Driver: [LOADED]
Fichier HOSTS:
::1 localhost
Termine : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt
Rapport pour le 4 :
RogueKiller V6.1.2 [07/10/2011] par Tigzy
contact sur
http://www.sur-la-toile.com
mail: tigzyRK<at>gmail<dot>com
Remontees:
http://www.sur-la-toile.com/discussion-193725-1-BRogueKillerD-Remontees.html
Systeme d'exploitation: Windows Vista (6.0.6002 Service Pack 2) 32 bits version
Demarrage : Mode normal
Utilisateur: marie [Droits d'admin]
Mode: Proxy RAZ -- Date : 13/10/2011 15:00:58
Processus malicieux: 0
Driver: [LOADED]
Entrees de registre: 3
[PROXY IE] HKCU\[...]\Internet Settings : ProxyEnable (1) -> REPLACED (0)
[PROXY IE] HKCU\[...]\Internet Settings : ProxyServer (http=127.0.0.1:59535) -> DELETED
[PROXY FF] 3iuijebn.default\ 127.0.0.1:59535 -> DELETED
Termine : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt